Menu

Core practice

Counterintelligence and Insider Threat

Analytic support to counterintelligence and insider threat programs, from analysts who have worked the mission.

The work

Counterintelligence and insider threat programs generate more signal than any team can run down, and most of it is innocent. The analytic problem is deciding what deserves attention, and being able to explain that decision afterwards to people who will scrutinize it.

This is support to a customer program. The customer owns the program, the decisions, and the equities. Analysts provide the assessment underneath them.

Where it meets the supply chain

A supplier relationship is an access path. A vendor with legitimate reason to be inside a network, a facility, or a bill of materials is a counterintelligence question as much as a procurement one, and the two practices ask the same question from different ends. Running both in one firm means the analyst assessing a vendor already thinks in those terms.

What this covers

  • Counterintelligence analytic support
  • Insider threat program support
  • Threat and vulnerability assessment
  • Operational planning and exercise support
  • Policy development supporting program stand-up and maturity

Deliverables

What you receive

A finished product, not a data extract. Each of these is written to be read by someone who has to make a decision.

  • Assessments

    Written analysis of a threat, a vulnerability, or an anomaly, with the reasoning and the confidence level attached.

  • Program support

    Analytic capacity inside an existing customer program — working the customer’s process, on the customer’s equities.

Context

What drives the requirement

The obligations below are why federal buyers and their suppliers need this work. Each is public regulation or published federal guidance, summarized here in general terms.

Regulatory drivers

National insider threat policy Federal departments and agencies with access to classified information are required to operate insider threat programs, which creates a standing need for analytic capacity to run them rather than simply to design them.

Evidence

Why this firm

Each claim below is paired with what makes it true. The content model requires the pairing, so a claim cannot be published on its own.

Analysts who have worked the mission
The majority of employees have military backgrounds, most with operational deployment experience.
Recognized analytic work
Employees have received individual and team Director of National Intelligence awards.
Supporting the mission since 2006
Continuous analytic support to the Department of Defense, the Department of Homeland Security, national-level agencies, and combatant commands.

Procurement

How this is ordered

As an SBA-certified SDVOSB, the firm is eligible for sole-source and set-aside award under FAR Subpart 19.14 — no vehicle required — and it takes subcontracts on programs a prime already holds.

SDVOSB eligibility, NAICS and PSC codes, UEI, CAGE, and the independent verification routes are all on how to buy from us.

Next step

Two ways in

Government

Describe the requirement and we will come back with scope and a named analyst lead. Quote requests reach a principal directly.

Government inquiry

Primes and platform vendors

Software vendors delivering federal task orders routinely need cleared analytic services partners. Socioeconomic status, codes, and vehicles are on one page.

Teaming information

Unresolved — not published

Release approval for the Counterintelligence and Insider Threat capability page — reviewed against the OPSEC checklist and dated

Source
Carl McDonald, President (named release authority)
Blocks
/capabilities/counterintelligence-insider-threat/

The page is written and complete. What is missing is the sign-off itself: releaseApprovedBy is set, releaseApprovedDate is null, and approving is meant to be a deliberate act rather than a default. Nothing customer-facing publishes without it.

Last reviewed 26 August 2026.