Does Your Workplace Need Counterintelligence? Start With What You Need to Protect

An ordinary workplace can benefit from a counterintelligence approach when it needs to protect valuable information, understand who has access, or examine a suspected disclosure.

By Mike Lowery, Owner of Oddfellow Investigations

9/25/20267 min read

Does Your Workplace Need Counterintelligence? Start With What You Need to Protect

When most people hear "counterintelligence," they picture foreign spies, embassies, and classified programs. I spent 22 years doing that work in the U.S. Army, and I can tell you the core of it isn't cloak-and-dagger. It's a disciplined way of answering three questions: What do we have that someone else wants? Who has access to it? And how could it get out?

Every business has something worth protecting. A contractor's bid pricing, a customer list, a vendor's pricing, an expansion plan, payroll records, or even the owner's travel schedule can all be valuable to a competitor, a disgruntled employee, a fraudster, or a criminal. You don't need a security department to think like a counterintelligence officer. You just need to start with the right question: what information would hurt your business if the wrong person got it?

The Threat Is Closer Than Most Owners Think

Business owners tend to picture threats as hackers somewhere far away. The data tells a different story. Verizon's 2025 Data Breach Investigations Report analyzed more than 22,000 security incidents and found that a human element was involved in roughly 60% of breaches. The share of breaches involving a third party, such as a vendor, contractor, or business partner, doubled in a single year, from 15% to 30%.

In other words, most problems come in through people and relationships, not through someone breaking down the digital door.

The insider picture is just as clear. The 2026 Cost of Insider Risks Global Report from the Ponemon Institute found that insider incidents cost organizations an average of $19.5 million a year in 2025, a 20% increase over two years. Those figures come from large organizations, but the lesson applies at any size: most of the damage isn't caused by villains. Negligent employees or contractors were the root cause of 53% of insider incidents, compared with 27% for malicious insiders, and the remaining 20% came from credential theft, where an outside attacker uses an insider's legitimate login.

That's actually good news for small business owners. If most exposure comes from carelessness and weak processes rather than traitors, most of it can be fixed with better habits.

The Most Expensive Mistake Is a Payment You Can't Get Back

Few threats hit small and midsize businesses harder than business email compromise, where criminals impersonate an owner, employee, or vendor to redirect a payment. It cost Americans $3 billion in reported losses in 2025, according to the FBI.

These schemes are intelligence operations in miniature. The criminal studies who approves payments, which vendors you use, when the owner is traveling, and how your team writes emails. Then they send a convincing message at exactly the right moment: new bank details for a vendor invoice, or an urgent wire request from the "boss" who's supposedly boarding a plane. The information that makes it work usually came from your own website, social media posts, a compromised email account, or a helpful employee who answered a phone call.

The best defense is simple and costs nothing. Never change payment instructions based on an email alone. Verify by calling a phone number you already have on file, not one listed in the message.

What This Looks Like in an Everyday Workplace

Take a construction company preparing a competitive bid. Its pricing, subcontractor arrangements, and schedule get shared with estimators, project managers, outside vendors, subcontractors, and prospective partners. If a competitor learns the number, the bid is lost. If a subcontractor who worked on the last three bids still has access to the shared folder, the company doesn't really control its own pricing.

Here's something many Florida contractors don't realize: if you submit proprietary information to a government agency, as you would on a public bid, you may need to clearly label it as confidential in writing. A Florida appeals court held that a business that failed to label its trade secret, or specify in writing when submitting it to a state agency that it was confidential, had not taken reasonable steps to protect it. The court also found that simply telling a state employee wasn't enough to keep the information from being released under a public records request.

The same questions apply everywhere. A medical or professional office has client records. A retail operation has supplier pricing and security procedures. A small service company has customer lists and staff schedules. Shared passwords, unattended paperwork, casual conversations in public places, unescorted visitors, and former employees with active logins all create openings.

These are examples of exposure, not proof of espionage. Counterintelligence thinking helps you see how information could be obtained or misused. Ordinary security habits close the gaps.

Why "Reasonable Measures" Matters Legally

Protecting your information isn't just good practice. In Florida, it can decide whether you have legal protection at all. Florida's Uniform Trade Secrets Act only protects information that is the subject of efforts that are reasonable under the circumstances to maintain its secrecy. To win a misappropriation case, a business generally has to prove not only that it had a trade secret and that it was taken, but that it took reasonable steps to protect it in the first place.

That means if your customer list sits in an unprotected shared folder that every employee and three former subcontractors can open, you may struggle to argue in court that it was secret. The steps in this post protect your business twice: they make theft less likely, and they preserve your legal options if it happens anyway.

This isn't legal advice, and you should talk with a business attorney about your situation. But the connection between good security habits and legal protection is one every owner should understand.

Where to Start: Three Questions

What needs protection? Make a short list of the information, relationships, and processes that would hurt the most if they got out or were compromised: pricing and bids, customer and vendor lists, financial and banking information, employee records, proprietary methods, and plans for expansion, acquisitions, or major contracts. Be specific. "Everything" isn't an answer, and trying to protect everything equally means protecting nothing well.

Who can access it? List everyone who can reach each item, including employees, contractors, vendors, IT providers, cleaning crews, and former workers whose access may still be active. Most owners are surprised by how long this list is. Then ask whether each person's access matches their current job. The bookkeeper doesn't need the bid files, the estimator doesn't need payroll, and the subcontractor who finished last spring doesn't need anything.

How could it leave? Think about every route: email, shared drives and cloud folders, printed documents, personal phones and USB drives, personal email accounts, photos of whiteboards, and plain conversation. In my experience, the most common leak isn't a digital theft. It's someone talking too freely to the wrong person, often because they didn't realize the information was sensitive.

Practical Steps That Close Most of the Gaps

Grant access based on job duties, and review it on a schedule, at least quarterly and every time someone changes roles.

End access completely and immediately when someone leaves, including email, cloud accounts, building keys and codes, vendor portals, and company phones. Make it part of a written offboarding checklist so it doesn't depend on someone remembering.

Use multi-factor authentication on email and every system that holds money or sensitive data. Stolen credentials are one of the leading ways attackers get in.

Label sensitive documents as confidential, and use nondisclosure agreements with employees, contractors, and business partners who handle sensitive information.

Set clear rules for verifying outside requests. Any request to change payment details, share employee records, or release sensitive information should be confirmed through a known phone number, no matter how legitimate it looks.

Control physical access. Know who's in your building, escort visitors, lock up paperwork at the end of the day, and shred what you throw away.

Train your team once a year, briefly and practically. People who know how these schemes work are much harder to fool.

Finally, give employees a simple, non-punitive way to report concerns, like an odd phone call, an unusual request, or a document that turned up somewhere it shouldn't. A good security culture relies on alert employees, not suspicious ones. The goal is a workplace where people speak up because it's normal, not one where everyone feels watched.

When a Concern Needs a Closer Look

A specific, documented incident deserves more attention than a rumor. Examples include confidential material turning up outside the company, a competitor who seems to know your bid numbers, repeated requests for information that has nothing to do with someone's job, unexplained access to restricted records, or large downloads right before an employee resigns.

None of these automatically proves misconduct. Honest mistakes, unclear responsibilities, and weak procedures can create the same signs. In counterintelligence, we're trained to consider alternative explanations before reaching conclusions, because a wrong accusation does real damage. It can destroy trust, expose the business to legal liability, and let the real problem continue.

If something happens, record what you know: dates, times, what was seen, and who was involved. Preserve the evidence, including emails, access logs, devices, and documents, and don't let anyone wipe, reset, or reassign a device involved in the concern. Keep the circle small, and avoid confronting anyone or making accusations before the facts are reviewed. Bring in the right people: management, your IT provider, legal counsel, and when needed, a qualified investigator.

One important caution: how you investigate matters as much as what you find. Florida generally requires the consent of everyone involved to record a private conversation, and monitoring employees' personal devices or accounts raises serious legal issues. Evidence gathered the wrong way can be thrown out and may create liability for the business. Talk to counsel before taking any investigative step you're unsure about.

How Oddfellow Investigations Can Help

My 22 years in U.S. Army counterintelligence shape how I approach every business concern: establish what's actually known, identify what's still uncertain, consider every reasonable explanation, and follow the facts wherever they lead, including when they point to a broken process rather than a bad actor.

Oddfellow Investigations helps businesses in Pensacola and across the Emerald Coast in two ways. Before a problem, we assess how your sensitive information is handled, who has access to it, and where the gaps are, and we give you practical, affordable recommendations sized to your business. After a concern arises, we investigate reported incidents, review business relationships and backgrounds, and document our findings in a way that's useful to management, attorneys, and law enforcement. For businesses worried about electronic eavesdropping in offices, vehicles, or meeting spaces, we also provide technical surveillance countermeasures (TSCM) inspections.

Every engagement starts with a clearly defined scope, and ends with plain-language findings and recommendations you can act on.

I started Oddfellow to help people who can't help themselves. For many small business owners, a business represents years of work and a family's livelihood, and they don't have a security department to turn to. That's who we're here for. If something in your business doesn't add up, call us. The conversation is confidential.

Oddfellow Investigations LLC | Veteran-owned | Pensacola, FL | (850) 426-3901
Florida Agency License A 3500096

Sources: Verizon 2025 Data Breach Investigations Report; Ponemon Institute/DTEX 2026 Cost of Insider Risks Global Report; FBI Internet Crime Complaint Center 2025 Annual Report; Florida Statutes Chapter 688 (Uniform Trade Secrets Act); Sepro Corp. v. Florida Department of Environmental Protection, 839 So. 2d 781 (Fla. 1st DCA 2003).

Learn more about our counterintelligence consulting services, or call (850) 426-3901 to discuss your concern.

LICENSED | INSURED

Florida Private Investigators License #C 3500090

Florida Agency License #A 3500096

Pensacola, Florida. Serving Escambia, Santa Rosa, Okaloosa and Walton counties in Northwest Florida, and Baldwin County in South Alabama.

© 2026. All rights reserved.

Timeless Tradecraft. Relentless Truth.