Closing Insider Threat Gaps: How Continuous Vetting Transforms Cleared Workforce Security

From IC Insider TechnoMile
By Lisa MacGlashing, TechnoMile
The national security community is undergoing one of its most significant workforce security transformations in decades: the shift from periodic reinvestigations to continuous vetting under the Trusted Workforce 2.0 (TW 2.0) framework. This change is fundamentally reshaping how federal agencies and contractors manage cleared personnel, monitor risk, and maintain compliance.
Yet while policy has evolved, many organizations are still relying on fragmented systems, siloed data, and manual processes that were built for an entirely different era of personnel security.
I remember applying for my first Secret clearance in my early twenties. The process seemed to take forever. Like many first-time clearance applicants, I found myself wondering what could possibly be causing the delay and whether investigators had uncovered something unexpected. What I didn’t realize at the time was that my experience was part of a much larger problem.
By June 2018, the federal personnel vetting system faced a backlog of more than 725,000 pending investigations, creating significant delays in hiring and onboarding cleared personnel. Once clearance was granted, individuals typically would not undergo another in-depth review for five to ten years, depending on the sensitivity of their position. During that time, significant life changes could occur with little visibility until the next scheduled investigation.
For decades, the federal government’s personnel security model relied heavily on periodic reinvestigations. While effective for its time, the approach was designed for a world where information moved more slowly, threats evolved less rapidly, and workforce mobility was far more limited.
What Five Years Can Hide
Consider how much can change in a person’s life over five years. Financial distress, foreign travel, arrests, workplace misconduct, concerning online behavior, or other risk indicators can emerge long before the next reinvestigation cycle begins. Under the legacy model, those developments might not be identified until years later.
The case of Joseph Daniel Schmidt shows exactly how that gap plays out in practice. Schmidt, a former Army intelligence sergeant who served at Joint Base Lewis-McChord from 2015 to 2020, pleaded guilty in June 2025 to attempting to deliver U.S. military secrets to China. After leaving the Army, he reportedly contacted Chinese government representatives offering insight into American surveillance and intelligence capabilities, then traveled to Hong Kong still in possession of a secure-access device and a set of classified military briefings. He had passed his initial clearance screening without issue; nothing in that process was built to catch what happened five years later. That’s the exact gap continuous vetting is meant to close – surfacing behavioral and access risks in near real time, rather than treating a clearance as a credential granted once and never revisited.
As insider threats became more sophisticated and security risks increasingly dynamic, it became clear that a periodic review process was no longer sufficient. A string of high-profile breaches, including Chelsea Manning (2010), Edward Snowden (2013), Harold T. Martin III (2016), and Reality Winner (2017), underscored how much damage a single cleared insider could do before anyone noticed. Together, they made the case that the government needed a model capable of identifying potential issues in near real time rather than relying on snapshots taken every several years.
The Emergence of TW 2.0
That need drove the launch of Trusted Workforce 2.0 (TW 2.0) in 2018.
TW 2.0 was designed to modernize personnel vetting across the federal government by replacing outdated, investigation-centric processes with a more agile, risk-based approach focused on continuous evaluation and workforce mobility. The initiative seeks to:
- Improve hiring speed and reduce onboarding delays.
- Enable greater reciprocity between agencies.
- Improve insight into workforce risk indicators.
- Replace periodic reinvestigations with continuous vetting.
- Strengthen national security through ongoing assessment of trust and suitability.
At the center of this transformation is Continuous Vetting (CV), which shifts personnel security from a point-in-time investigation model to an ongoing risk-monitoring model. Rather than waiting five or ten years to reassess an individual’s eligibility, automated data checks help identify changes that may warrant additional review. This allows organizations to detect potential concerns earlier while reducing the administrative burden associated with large-scale reinvestigation cycles.
When the Gap Becomes the Breach
The cost of getting this wrong keeps climbing and accelerating. The average annual cost of insider risk has grown from $15.4 million in 2022 to $19.5 million in 2025, according to the Ponemon Institute’s Cost of Insider Risks Global Report, with the pace of increase picking up each year. And that figure only captures what can be measured. It doesn’t account for compromised case files, leaked sensitive information, a damaged reputation, or a client who doesn’t come back – costs that don’t show up on an invoice but are often the hardest to recover from.
The 2025 breach at government contractor Opexus is a stark illustration of what’s at stake when vetting and access controls fail. Opexus hired twin brothers as engineers in 2023 and 2024, despite a decade-old federal conviction for wire fraud and hacking the U.S. State Department – a background check gap the company later admitted to. Their history only surfaced in February 2025, when one of the brothers applied for an unrelated role that required a check, and the other agency flagged them both as insider threats. Opexus moved to terminate them, but minutes into that termination meeting, one brother used his still-active access to delete an estimated 33 to 96 federal databases, spanning FOIA records, investigative files, and personal data, while allegedly copying roughly 1,800 files to a USB drive. It’s a case that touches nearly every layer this framework is meant to address background screening that should have caught a public conviction at the point of hire, and immediate, automated access termination at the point of firing, not access that survives the meeting where someone is being let go.
However, implementing continuous vetting requires more than simply changing policy. Agencies and contractors must be able to collect, manage, analyze, and act on personnel security information from multiple systems and sources. Many organizations continue to struggle with disconnected technologies and manual workflows that make it difficult to gain a complete picture of workforce risk.
The government’s own experience illustrates the point. DCSA has spent years developing the National Background Investigation Services (NBIS); the IT system meant to serve as the backbone for continuous vetting across the federal government. Some pieces have landed: cleared industry and federal agencies fully transitioned onto the NBIS eApplication (eApp) for initiating background investigations back in October 2023, a shift that touched more than 100 federal agencies and 11,000 cleared companies, and DCSA has continued building on top of it – as of March 2026, applicants now get a link to a new Individual Engagement Platform that lets them track their case status in near real time.
But the harder parts of NBIS – the pieces that continuous vetting actually depend on – are still years out. DOD originally expected the full system to be complete in 2019; after missing that and subsequent targets, DCSA paused development entirely in 2024 to revise its approach, and the Pentagon is now aiming to execute a full transition by the end of fiscal 2028. The agency isn’t standing still on this either: DCSA recently awarded ICF a spot on a new five-year, multiple-award blanket purchase agreement worth up to $800 million to modernize NBIS using cloud-native design, zero trust architecture, and AI-driven automation. But that’s real money aimed at a system still years from delivery. If the agency running continuous vetting is still years from finishing the infrastructure built to support it – even with fresh investment behind it – it’s a safe bet most contractors are, too.
The scope of this problem is also growing. CMMC’s rollout extends continuous-monitoring and access-control expectations well beyond the traditional cleared workforce, pulling a much broader swath of the defense industrial base into the same conversation. At the same time, AI-driven anomaly detection is starting to show up as a serious tool for spotting behavioral patterns that used to only surface at the next scheduled review: unusual access, unexplained travel, and atypical data movement. The direction is clear: continuous, automated visibility isn’t a niche cleared workforce concern anymore. It’s becoming the baseline expectation for anyone handling sensitive government data.
As Trusted Workforce 2.0 continues to mature, success will depend not only on the government’s ability to modernize vetting policies, but also on organizations’ ability to modernize the processes and technologies that support them. Continuous vetting is not merely a compliance requirement. It is a fundamental shift toward a more proactive, data-driven approach to workforce security that helps close insider threat gaps before they become national security incidents.
Closing the Gap for Real
Even today, some companies still track foreign travel, reinvestigation schedules, and personnel access through separate email chains: a real insider threat risk when the data is fragmented across HR, security, and clearance systems.
Closing that gap doesn’t mean layering more policy onto already-strained processes: it means giving security teams one reliable system of record for the risk indicators that matter – cleared personnel status, foreign travel, facility access, reportable life events, and reinvestigation timelines – all in one place instead of scattered across inboxes and spreadsheets.
This is where platforms like TechnoMile SIMS come in. Built specifically for NISPOM, 32 CFR Part 117, SAP, and SCI environments, SIMS unifies personnel, physical, and information security into a single system of record, replacing the email-chain approach with continuous, automated visibility into the same risk indicators that TW 2.0 is designed to monitor. That includes reportable events – divorce, financial hardship, arrest, foreign contact, and other life changes cleared personnel are already required to disclose – captured directly in the system rather than buried in a form that never makes it to the person who needs to see it. Instead of security teams manually stitching together travel logs, access records, reportable-event disclosures, and reinvestigation schedules, that data lives in one place and stays current, turning continuous vetting from a policy mandate into something a security team can actually operate day to day. SIMS also automatically notifies the right people the moment action is needed: a foreign travel or contact report requiring review, a newly submitted reportable event, or an emerging insider-threat concern – rather than leaving it to be caught at the next scheduled check.
That’s the difference between continuous vetting as a checkbox and continuous vetting as an actual defense.
It’s worth noting that no system of record catches every scenario – someone like Schmidt, who had already separated from the Army before he acted, falls outside what reportable events or reinvestigation timelines are built to catch, since there’s no longer a clearance-holding employer in the loop to receive that disclosure. But for the far more common case – the cleared employee who’s still on the books, still has access, and simply isn’t being watched between scheduled reviews – that’s exactly the gap continuous automated visibility is designed to close.
Continuous vetting is only as effective as the workforce data and processes supporting it. If you’re evaluating how your organization tracks foreign travel, access, reportable events, and reinvestigation timelines today, it’s worth taking a look to see how SIMS closes that gap.
About TechnoMile
TechnoMile is the newly combined organization formed by the merger of TechnoMile and SIMS Software. Together, the company delivers integrated, AI-enabled solutions that support mission-critical operations end-to-end – from identifying government contract opportunities through compliant, secure execution. TechnoMile’s unified solution connects growth, contracts, and security workflows for GovCon, Defense, and Public Sector organizations to strengthen compliance, reduce risk, safeguard brand reputation, boost efficiency, and drive mission success. Learn more at technomile.com or follow us at linkedin.com/company/technomile.
About IC Insiders
IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.







