The Insider Was the Opening Move
An insider grievance becomes a leak. The leak becomes constructed disinformation. The disinformation becomes a geopolitical amplification opportunity, then a legal crisis with an extortion edge. The attack was coupled. The response was not. That asymmetry is the whole lesson.
When a leak is not a leak, and no single discipline can see the whole thing
The first sign was a document that should not have been outside a small circle, and was. That by itself is a bad morning. What made it worse took another day to see. The material that surfaced was not simply confidential information released into the open. It was real fragments arranged around constructed falsehood, half-truths given just enough true detail to carry the weight of the lie attached to them. It did not read as a leak. It read as a case being made.
By the time I understood that, the thing was already moving. The framing was being repeated by people who had not created it and did not need to, because it fit something they already wanted to say. A hostile actor with its own reasons found in the leaked material exactly the raw texture it needed to amplify a narrative it had been pushing anyway. The insider had lit the fire for personal reasons. The geopolitical environment supplied the wind. And the client, my client, was standing in the middle of a story that was now being told about them in a language they did not choose, from fragments that were technically real, toward a false conclusion.
This is a piece about that shape. Not the specific incident, which stayed out of the news and will stay out of this article in any identifying detail, but the shape of it, because the shape is instructive and it is becoming more common rather than less. An insider grievance becomes a leak. The leak becomes constructed disinformation. The disinformation becomes a geopolitical amplification opportunity. The amplification becomes a legal and reputational crisis with an extortion edge. And at every stage, the response is slower and more fragmented than the attack, because each discipline sees only its own piece and no one is positioned to see the whole.
The threat that arrives through the front door
Most protective thinking (mine has always been more holistic), treats the insider as a category of its own: a vetting problem, an access-control problem, an HR problem. Something you screen for at hiring and then largely stop thinking about. The mid-2010 incident cured me of that. The insider is not a separate category. The insider is often the origin point of the most damaging hybrid attack a client can face, precisely because the insider already has legitimate access, credibility, and knowledge of where the client is soft. My advice: keep profiling and vetting even after the hiring period.
The literature on this is more developed than the private sector generally acknowledges. The critical-pathway model of insider risk describes a progression that my insider followed almost exactly: a personal predisposition, a set of stressors, a period of concerning behaviour, and then the hostile act, with each stage offering a window in which intervention would have been possible if anyone had been watching (Shaw and Sellers, 2015). The point of the model is that insiders do not usually snap. They travel a path, and the path is visible to an organisation configured to see it. My client's was not. There was no insider threat policy worth the name, title monitoring, no shared understanding that a trusted person with a grievance could become the origin of a strategic attack. The insider risk had been underestimated to the point of not being a category anyone owned.
That underestimation is the first failure, and it is the most common one. Insider risk sits in an organisational blind spot because it is uncomfortable. It requires treating the people inside the wall as a potential source of threat, which cuts against the trust that makes an organisation function. So it gets filed under HR, or under nothing, and the monitoring and the policy and the shared vocabulary never get built. Then the incident arrives through the front door, carrying legitimate credentials, and the perimeter that everyone invested in turns out to have been facing the wrong way.
Constructed disinformation, and why the leak was the easy part
Once the material was out, the mechanics that followed are well documented as a category, even if they are rarely named correctly when they happen to you. What I was looking at was a hack-and-leak operation in its broader form: the combination of genuine leaked material with constructed framing to produce a narrative that is credible precisely because parts of it are true (Shires, 2019). The truth in the fragments is what makes the falsehood stick. A pure fabrication can be denied. A lie wrapped around real documents cannot be cleanly denied, because the denial has to concede the real parts, and the concession reads as confirmation of the whole.
The amplification that followed matched a pattern I would later spend 2.5 academic years studying (Rifesser, 2023). The framing was repeated at volume, across channels, with the speed and the indifference to consistency that characterise what Paul and Matthews (2016) called the firehose of falsehood: high volume, multiple channels, rapid, repetitive, and unbothered by contradiction, because the goal is not to persuade through argument but to saturate until the false frame feels like established context. And because the narrative served a geopolitical actor's existing line, it received amplification that the insider could never have generated alone. This is the dimension the European institutions now formalise as foreign information manipulation and interference: the deliberate exploitation of an information vulnerability by a state-aligned actor, not necessarily by creating the content, but by recognising content that serves them and pushing it (European External Action Service, 2025). The insider made the ammunition. The state-aligned actor fired it.
The leak, in other words, was the easy part to understand. The hard part was that the leak had become the raw material for two different operations at once: the insider's personal revenge and a hostile state's strategic narrative, running through the same fragments toward compatible ends. No single lens could see that. The HR lens saw a disgruntled former insider. The legal lens saw a confidentiality breach and a potential defamation exposure. The communications lens saw a reputational fire. The geopolitical lens, which almost no one on the client's side was even looking through, saw a state-aligned amplification campaign. Each was correct. Each was a fraction of the truth.
The method: reading fragments toward the most likely explanation
What let me eventually see the whole shape was not a tool or a feed. It was a method, and it is worth naming because it is teachable and because it is the same method I later formalised in academic work.
The optimal goal of intelligence is complete foreknowledge, and that goal is essentially never reached. Conclusive proof is the exception. What you have instead is fragments, and the discipline is to reason from those fragments toward the hypothesis that, if true, would best explain them. That is abductive reasoning: not deducing a certainty from a rule, and not inducing a pattern from many cases, but inferring the most likely explanation from incomplete evidence (Johnson, 2007). It is how you work when you cannot run the experiment and cannot wait for certainty, which describes almost every real protective situation and describes this one exactly.
Two additional elements make abductive reasoning work under these conditions, and both come from the same body of intelligence-studies literature. The first is greater imagination. John Lewis Gaddis, writing about history as what he called an imaginative social science, argued that some kinds of knowledge cannot be obtained by experiment and must instead be reconstructed from the traces left behind, which requires creativity to fill the gaps in the evidential record (Gaddis, in Johnson, 2007). Stephen Marrin makes the same argument for intelligence analysis directly: because the analyst works from fragmentary material, the art of imagination is needed to fill the gaps, and the failure to do so has consequences (Marrin, in Johnson, 2007). The 9/11 Commission named a failure of imagination as a primary reason the attacks were not prevented. The lesson it drew was to use imagination deliberately, to picture how an attack might be conducted and use that picture as a starting point for collection. The second element is greater empathy: not sympathy, but the discipline of reconstructing the situation from the adversary's point of view, asking what they want, what serves them, and how the available fragments look from where they are standing (Marrin, 2012).
Applied to the incident, the method looked like this. I had fragments: a leak, a framing, an amplification pattern, a set of actors with different apparent motives. Abductive reasoning asked which single explanation best accounted for all of them, and the answer that survived was that the insider's revenge and the state-aligned actor's narrative were not two coincidental events but one coupled operation exploiting the same material. Greater imagination asked what the fully developed attack would look like if it ran to its conclusion, which let me anticipate the legal and extortion escalation before it arrived rather than after. Greater empathy asked what each actor actually wanted, which is the only way to understand that the insider wanted to hurt the client while the state-aligned actor did not care about the client at all and wanted only the narrative, and that these two motives required two different responses. The what-if scenario is not idle speculation. It is a collection and preparation tool. Run it early enough and you are ready for the move before it is made.
None of this required me to be the lawyer, the communications strategist, or the geopolitical analyst. It required me to hold the fragments from all of their domains in one place and reason across them. Which brings me to the failure that mattered most.
The response failed because it was fragmented
The attack was coupled. The response was not. That asymmetry is the whole lesson.
The legal response scaled too slowly, and here I want to be careful, because the lawyers were not wrong in their own register. Counsel is trained toward caution, toward saying as little as possible, toward not conceding, toward the long timeline of a case that can be won on the merits. Those are the correct instincts for a legal proceeding. They are close to the worst possible instincts for a live narrative attack, where silence reads as confirmation, where the false frame hardens into accepted context within days, and where the timeline that matters is the news cycle, not the litigation calendar. The lawyers were optimising for the case. The case was not the threat. The threat was the narrative, and the narrative was moving at a speed the legal response was not built for. This is not a criticism of the lawyers. It is a description of what happens when a legal response is asked to carry an incident that is only partly legal, without anyone coordinating it against the other lanes.
The same fragmentation ran through every function. Communications was managing a reputational fire without visibility into the insider dimension or the geopolitical one. The government stakeholders and the security attaché who eventually became involved held pieces that the private side could not see, and vice versa. HR held the insider's history. Nobody held the whole. And for longer than it should have taken, the person whose method was specifically suited to holding the whole, the head of security, was not in the room where the response was being decided. I had to push, repeatedly, to be brought into the meetings with the lawyers and the attaché. That detail is not a complaint. It is the structural failure made concrete: the function best positioned to read across the lanes was outside the room where the cross-lane decisions were being made, because the model did not have a place for it.
What the response should have been: one cell, one picture
The incident taught me what adequate looks like, by showing me its absence. The only response proportionate to a coupled attack is a coordinated one, assembled deliberately, drawing every relevant discipline into a single shared analysis before decisions are made rather than after.
That means, at minimum, the following in one room or one secure channel: government relations, because a state-aligned amplification is partly a diplomatic matter; legal, because the exposure and the eventual extortion are real and have to be managed within the law; communications, because the narrative has to be contested in the environment where it lives; personal security, because the physical and proximity risks that a hardened narrative can produce are real; and HR, because the insider dimension is theirs and the insider's history is the key to motive. I would go further than the conventional list. Cyber, because the leak's mechanism and the digital amplification are theirs to read, and because if there is an intelligence cell it belongs here too. And finance, because in an extortion escalation the financial dimension is not a side matter, and because following the money is often what reveals the actors behind a narrative that presents itself as organic.
Only from that shared picture can the questions that matter be answered. What is the motive, that requires HR and the empathy to reconstruct the insider's grievance and the state actor's strategy separately. Who are the actors, which requires cyber, intelligence, and finance to distinguish the person who lit the fire from the actor who fanned it. What is the strategy, which requires all of them, because the defence against a personal revenge operation and the defence against a state-aligned narrative campaign are different, and the client was facing both at once. Only an interdisciplinary analysis produces a holistic picture of the threat. Anything less produces several partial pictures that each optimise for their own lane and collectively lose.
This connects to an argument I have made before about reading across the four lanes before an incident goes kinetic. This is its counterpart. The pre-incident version is a reading capability: seeing the pathway while it is still forming. This is the live-incident version: coordinating the response once the pathway has already carried an attack into the open. Both fail the same way, in lanes. Both require the same answer, a single function or cell that holds the whole.
The unglamorous discipline that made it possible
One habit deserves its own mention, because it is the least impressive-sounding thing in this article and it was the most important. I logged everything.
Security people are trained to document, and usually we document the things that look like security: the incidents, the approaches, the anomalies. In this case I documented everything, including the details that did not obviously matter at the time. The sequence of when the material surfaced and where. The timing of each amplification relative to the client's other exposures. Which accounts moved first and which followed. The small inconsistencies in the framing suggested construction rather than organic spread. None of it looked decisive on the day it was recorded. All of it became decisive when the stakeholders finally assembled, because the person with the complete timeline is the person who can demonstrate the coordination, distinguish the insider's contribution from the state actor's, and give the interdisciplinary cell the shared factual basis it needs to reason from. Documentation is not bureaucracy. In a coupled incident it is the substrate that makes the interdisciplinary analysis possible at all. Without it, every discipline arrives with its own partial account and there is no common record to reconcile them against.
The lesson
The most dangerous hybrid attack a client faces may not come from outside. It may begin inside, with someone who already holds legitimate access and a personal reason to use it, whose leak becomes constructed disinformation, whose disinformation serves a geopolitical actor who amplifies it for their own ends, and whose damage compounds while the response fragments across disciplines that were never built to work together. The insider is not a footnote to the threat model. The insider can be the opening move.
Treating insider risk as an HR matter, a legal response as sufficient for a narrative attack, or a communications problem as separate from a security one, are all versions of the same mistake: reading a coupled attack in separate lanes. The attack does not respect the lanes. It was designed not to. The only adequate answer is to build the interdisciplinary coordination before the incident, to give the reading and the response to a single function or cell that can hold every lane at once, and to keep the person who can reason across the fragments inside the room where the decisions are made.
All of this is protective intelligence doing what it is actually for. Not the collection of feeds or the monitoring of accounts, though those matter, but the discipline of reasoning across fragments toward the shape of a threat before that shape is obvious to everyone else. The insider case was an exercise in exactly that: abductive reasoning, greater imagination, greater empathy, applied under pressure to an incident that no single discipline could read. In the next piece I want to take that discipline out of the crisis and into the ordinary week, because protective intelligence earns its keep not only in the incident that has already broken but in the quiet reading that keeps the incident from breaking at all.
Mid-2010s, I learned that lesson from the outside of that room, pushing to be let in. It is a cheaper lesson to learn from an article.
References
European External Action Service (2025) 3rd EEAS Report on Foreign Information Manipulation and Interference Threats. Brussels: European External Action Service.
Johnson, L.K. (2007) Handbook of Intelligence Studies. Abingdon: Routledge.
Marrin, S. (2012) 'Is Intelligence Analysis an Art or a Science?', International Journal of Intelligence and CounterIntelligence, 25(3), pp. 529 to 545.
Paul, C. and Matthews, M. (2016) The Russian "Firehose of Falsehood" Propaganda Model. Santa Monica: RAND Corporation.
Rifesser, B.J.F. (2023) An Interdisciplinary Analysis of the Weaponisation of TikTok: 'Everybody against everybody' warfare in the context of fifth-generation warfare. MSc thesis. Liverpool: Liverpool John Moores University.
Shaw, E. and Sellers, L. (2015) 'Application of the Critical-Path Method to Evaluate Insider Risks', Studies in Intelligence, 59(2), pp. 41 to 48.
Shires, J. (2019) 'Hack-and-Leak Operations: Intrusion and Influence in the Gulf', Journal of Cyber Policy, 4(2), pp. 235 to 256.