Unauthorized Disclosure: It’s Not Always Intentional

Unauthorized Disclosure

Unauthorized disclosures rarely begin with bad intentions. More often, they happen during quick conversations, fast moving emails, working in the wrong system, or assuming everyone in the room already has the appropriate need to know.

For those of us supporting the National Industrial Security Program (NISP), protecting classified information and Controlled Unclassified Information (CUI) is part of our daily responsibilities. While cyber and physical security tend to get most of the attention, routine interactions can create risks if we aren’t careful.

Understanding Unauthorized Disclosure

An unauthorized disclosure occurs any time classified information or CUI ends up somewhere it shouldn’t—whether shared with someone without proper access, stored on the wrong system, discussed in an uncontrolled environment, or otherwise mishandled.

Authorization requires more than simply holding a clearance. The recipient must have:

  • The appropriate level of clearance (if classified)
  • A valid need to know
  • Authorization to access the specific information

If any one of these elements is missing, the disclosure is NOT authorized. Let’s clear up a common misconception.

Myth: “If someone has a clearance, I can discuss classified information with them.”

Fact: A clearance alone is not enough. Access requires a demonstrated need to know and any program specific authorizations.

CUI: A Frequently Overlooked Risk

Many personnel are comfortable spotting risks involving classified information but overlook CUI—material protected by law, regulation, or government wide policy even though it isn’t classified.

A few examples include, but are not limited to:

  • Procurement sensitive information
  • Export controlled data
  • For Official Use Only (FOUO) or Sensitive but Unclassified (SBU) material
  • Controlled technical information
  • Privacy information (PII)

CUI does not require a clearance, but it does require authorized access, approved systems, and proper safeguarding. We should treat CUI with the same level of care we apply to preventing classified spills.

Everyday Risks: Classified & CUI

Unauthorized disclosures often come from ordinary activities and habits:

  • Forgetting to check if an email thread contains CUI before hitting “Reply All”
  • Pulling up sensitive documents during virtual meetings without verifying participants
  • Mixing classified and CUI discussions without confirming what can be shared
  • Copying/pasting project details into public facing documents
  • Uploading CUI to unapproved collaboration tools or storage locations

Small oversights can create big vulnerabilities.

How Unauthorized Disclosures Happens

Here are a few real world situations we may encounter:

  • Mentioning a milestone schedule in front of visitors, not realizing it is CUI
  • Receiving a draft with embedded CUI that wasn’t marked
  • Getting a “quick context” question from someone whose access level is unclear
  • Moving between networks and saving sensitive files in the wrong location

None of these feel reckless, but they still count as unauthorized disclosures.

Unauthorized disclosures can also occur in everyday environments:

  • Discussing sensitive work in public places such as airports, restaurants, or elevators
  • Forwarding emails without confirming all recipients are authorized
  • Using the wrong collaboration platform or distribution list
  • Leaving sensitive material visible during virtual meetings or screen sharing
  • Assuming a coworker “already knows” without verifying need to know

Most of these situations are preventable with a brief pause to verify before sharing.

Good Habits for Preventing Unauthorized Disclosure

Before sharing sensitive information, ask yourself:

  • Who is receiving this information?
  • Do they have the appropriate authorization and need to know?
  • Is this the correct communication method?
  • Am I sharing only what is necessary for the task?

A few simple behaviors go a long way:

  • Check classification and CUI markings when opening, editing, or sharing documents
  • Verify access and need to know—even when you think someone is read in
  • Keep sensitive conversations in controlled spaces and on approved systems
  • Slow down before sending emails, especially cross organization
  • Properly mark CUI according to DoD or agency specific guidance
  • When uncertain, pause and ask—your security team is here to support you

These habits take only seconds and help prevent reportable security incidents.

Reporting Mistakes

Mistakes happen—and fast reporting is critical.

If you believe protected information may have been disclosed to an unauthorized person:

  • Stop any additional sharing
  • Preserve any relevant information
  • Notify your Facility Security Officer (FSO) immediately
  • Avoid trying to resolve the issue on your own

Prompt reporting allows your security team to assess the situation, limit potential damage, and meet mandatory reporting requirements.

Final Thought

Protecting information isn’t about making work harder—it’s about ensuring sensitive information reaches only those who are authorized to receive it. A quick verification today can prevent a security incident tomorrow.

This Month’s Challenge: Before sending your next sensitive email or discussing a protected project, take five seconds to verify the recipient, the need-to-know, and the communication method. Small habits make a big difference.

Want to Learn More?

Resources and Additional Learning

CDSE Unauthorized Disclosure of Classified and CUI

CDSE Unauthorized Disclosure Student Guide

CDSE Unauthorized Disclosure Toolkit

DNI Unauthorized Disclosure

National Archives Unauthorized Disclosure Prevention and Reporting

CDSE Case Studies

Security Awareness Games

32 CFR Part 117 (NISPOM Rule)

32 CFR Part 147 (Adjudicative Guidelines)

As always, if you have any questions…ask your FSO! Your company’s FSO is the best person to help you navigate any questions you have about security compliance, briefing, and reporting requirements. As security professionals, we are here to help you navigate all things security and ensure you fulfill all security requirements.

Related Articles

AI Driven Social Engineering

AI Driven Social Engineering: The New Threat Targeting Federal Contractors

Artificial intelligence driven social engineering is no longer a theoretical concern. It is already being used by adversaries to target federal contractors because of the sensitive information, predictable workflows, and publicly visible roles common in this environment. It is important to understand why this threat deserves your attention and how it affects every cleared and uncleared individual.

Read More
Mental health

Mental Health & Security Clearances

Mental health is a critical component of readiness, resilience, and long‑term performance in the federal contracting workforce. Yet one of the most persistent misconceptions is the belief that seeking mental health care jeopardizes a security clearance. The security clearance system evaluates mental health through the lens of judgment, reliability, and trustworthiness. It does not penalize individuals for seeking help. Adjudicators look for signs of stability, insight, and responsible behavior — all of which are demonstrated when someone proactively manages their mental health.

Read More

Learn how FSO PROS® can help
support your security program

Let’s discuss how we can help support your security and compliance needs.
Secret Link