When a Defense Intelligence Agency employee with Top Secret clearance spends three days hand-copying classified documents at his desk, then hides the pages in his socks before leaving work, your monitoring program should catch it. Nathan Vilas Laatsch's case shows what happens when insider threat controls exist on paper but fail in practice.
This checklist covers the technical and procedural controls needed to detect insider threats before they lead to unauthorized disclosure. It's based on the detection requirements in NIST SP 800-53 Rev 5 Program Management (PM) controls and the behavioral indicators that distinguish routine access from data exfiltration.
Prerequisites
Before implementing this checklist, confirm your organization has:
Formal insider threat program charter, Not just a security awareness slide deck. A documented program with authority, resources, and reporting lines that bypass the employee's direct management chain.
Legal and privacy review, Employee monitoring triggers privacy obligations under the Privacy Act and OMB Circular A-130. Document what you're monitoring, why it's necessary for mission protection, and how you'll handle false positives.
Baseline user activity metrics, You can't detect anomalies without knowing what normal looks like for your environment. Establish baseline metrics for document access patterns, printing volume, removable media use, and after-hours access.
Detection Controls Checklist
1. Physical Access Monitoring
□ Video surveillance covers all workstations with access to classified systems
Your monitoring must capture the desk surface, not just the doorway. Laatsch's hand-copying activity was visible on DIA video surveillance. Ensure coverage is sufficient to observe document handling, screen activity, and what employees place in bags or pockets when leaving.
□ Surveillance retention meets incident investigation timelines
Laatsch copied documents over multiple days between May 16 and May 27, 2025. If your retention window is 72 hours, you've lost the evidence thread. Aim for a minimum 90-day retention for classified workspace surveillance, with longer retention for flagged anomalies.
□ Exit point inspection procedures are documented and enforced
Laatsch concealed handwritten notes in his socks and lunchbox. Random bag checks won't catch that. Implement specific procedures for inspecting common concealment locations when behavioral indicators warrant, not relying solely on metal detectors.
2. Technical Activity Monitoring
□ Database query logging captures user, timestamp, query content, and data volume
When an IT specialist starts accessing intelligence products outside their normal job function, you need a record. Logs should show what Laatsch queried, not just that he logged in. Implement PM-14 (Testing, Training, and Monitoring) requirements for audit log review.
□ Printing and copying activity generates alerts for volume thresholds
Hand-copying documents suggests Laatsch knew print jobs were monitored. Your controls should detect both. Set alerts when an employee spends unusual time viewing documents without a corresponding work ticket, even if they don't print.
□ Removable media usage is logged per AU-2 requirements
Laatsch delivered classified material on a thumb drive during the dead drop operation. That drive either bypassed your USB controls or your monitoring didn't flag the data transfer. Ensure technical controls block unauthorized removable media (MP-7) and log all approved exceptions.
□ Email monitoring flags external addresses in sensitive domains
Laatsch initiated contact by emailing an account associated with a foreign government. Implement automated flagging when employees with classified access email non-.gov/.mil addresses, especially foreign domains, with manual review before blocking to avoid false positives.
3. Behavioral Indicator Detection
□ Documented process for reporting employee statements indicating discontent
Laatsch wrote that he disagreed with administration values and intended to act. Someone may have heard similar statements before he emailed a foreign government. Establish clear reporting channels that protect reporters from retaliation and escalate concerning statements to your insider threat team, not just HR.
□ Correlation rules link technical anomalies to behavioral changes
One unusual database query isn't espionage. Unusual queries plus foreign travel plus financial stress plus expressed discontent forms a pattern. Conduct regular case reviews where technical monitoring data and behavioral indicators are analyzed together, documented per PM-16 (Threat Awareness Program).
□ After-hours access generates review when combined with other indicators
Set automated alerts for after-hours classified system access, with mandatory review when the employee has no documented reason for the access or when it coincides with other risk factors.
4. Incident Response Integration
□ Insider threat indicators trigger defined response protocols
The FBI received a tip about Laatsch's interest in sharing information. Your program needs a process for acting on tips, not just technical alerts. Develop written procedures for investigating tips, coordinating with counterintelligence, and escalating to law enforcement when warranted.
□ Evidence preservation procedures protect investigation integrity
Document the chain of custody for surveillance footage, Audit Logging, and physical evidence. Your procedures should assume criminal prosecution, not just administrative action.
Common Mistakes
Monitoring without analysis, Generating logs isn't detection. Laatsch's activity was visible in DIA systems, but detection requires someone reviewing the data with trained eyes and correlation tools.
Treating all clearance holders identically, An IT specialist accessing intelligence products needs different baseline monitoring than an analyst whose job requires that access. Risk-based monitoring under PM-9 means different thresholds for different roles.
Ignoring low-tech exfiltration, Your data loss prevention tools won't catch handwritten notes in socks. Physical monitoring and exit procedures remain relevant even in digital environments.
Delaying law enforcement coordination, By the time Laatsch arrived at the second dead drop location, the FBI had enough evidence to arrest him. Early coordination with counterintelligence lets professionals handle the investigation before the damage escalates.
Next Steps
This checklist addresses detection. Prevention requires a separate control set covering personnel security continuous evaluation (NIST SP 800-53 PS-7), security awareness training specific to insider threat indicators, and supply chain risk management when contractors have classified access.
If your current program can't answer "yes" to each item above, prioritize technical monitoring gaps first, they provide the evidence base for investigation. Then address behavioral indicator processes, which require more organizational change but catch threats that bypass technical controls.
The Laatsch case ended with FBI interception before classified information reached a foreign government. Your program needs to catch the threat at the hand-copying stage, not the dead drop.



