News

Syteca on Corporate Espionage: Detection & Prevention 2026

News | 25.09.2026

Years of R&D, product roadmaps, source code and customer lists can leave your organization in a few clicks. Corporate and industrial espionage is no longer a spy-movie scenario — it is a growing business risk driven by trusted insiders, compromised privileged accounts and third-party access. Syteca has published an in-depth guide explaining what corporate espionage is, how modern campaigns unfold, and how security teams can detect and prevent trade secret theft before it hits the balance sheet.

A practical framework for CISOs to counter insider-driven espionage across the full access lifecycle.

What was announced

Syteca released a comprehensive analysis of corporate, industrial and economic espionage covering legal frameworks (US Economic Espionage Act, EU Directive 2016/943, UK National Security Act 2023), current attack methods and recent enforcement cases. The guide references the 2025 Insider Risk Report by Cybersecurity Insiders, which found that 93% of organizations consider insider threats as difficult or more difficult to detect than external attacks.

The publication highlights three landmark cases: the March 2025 Rippling vs. Deel lawsuit, where an insider ran more than 6,000 Slack searches and accessed customer lists on 600+ occasions; the January 2026 conviction of former Google engineer Linwei Ding for stealing 2,000+ pages of confidential AI technology; and the August 2026 verdict against former Philips engineer Chih-Yee Jen for stealing proprietary X-ray technology.

Why this matters

For CIOs, CISOs and procurement leaders, espionage translates directly into loss of competitive advantage, reputational damage, legal exposure and — in regulated sectors — compliance fines. Industries with heavy R&D investment (semiconductors, IT, automotive, aerospace, energy, biotech, chemicals) and long product cycles are the primary targets, alongside finance, retail and the public sector.

Modern espionage campaigns follow a predictable pattern: target selection, initial access, lateral movement, data collection and exfiltration, and covering tracks. Attackers increasingly rely on valid credentials, dormant privileged accounts and vendor access, which makes traditional perimeter defenses insufficient. Detecting misuse requires visibility into what privileged users actually do after authentication.

Technical details

  • Risk assessment: map trade secrets, owners, access paths and third-party handlers to prioritize protection.
  • Zero Trust and MFA: continuously validate identity before granting access to critical resources.
  • Privileged account discovery: identify unmanaged and dormant accounts that can become backdoors after employee termination.
  • Session monitoring and alerts: track file uploads, shadow AI usage, unauthorized USB connections, off-hours access and attempts to disable security tools.
  • Least privilege and JIT access: replace standing privileges with just-in-time permissions that expire when the task ends.
  • Incident response plan: define containment, evidence preservation of logs and session recordings, and escalation to legal counsel.
  • Warning signs to monitor: abnormal search activity, bulk downloads, screenshots, mass printing, transfers to personal email or cloud, and access retention after role change or termination.

Softprom and Syteca

Softprom is the official distributor of Syteca. Our team supports customers with licensing, deployment, integration and technical enablement of Syteca's insider security platform — covering privileged access management, identity threat detection and response, user activity monitoring, forensic investigation and endpoint security.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.