Unauthorized disclosures rarely begin with bad intentions. More often, they happen during quick conversations, fast moving emails, working in the wrong system, or assuming everyone in the room already has the appropriate need to know.
For those of us supporting the National Industrial Security Program (NISP), protecting classified information and Controlled Unclassified Information (CUI) is part of our daily responsibilities. While cyber and physical security tend to get most of the attention, routine interactions can create risks if we aren’t careful.
Understanding Unauthorized Disclosure
An unauthorized disclosure occurs any time classified information or CUI ends up somewhere it shouldn’t—whether shared with someone without proper access, stored on the wrong system, discussed in an uncontrolled environment, or otherwise mishandled.
Authorization requires more than simply holding a clearance. The recipient must have:
- The appropriate level of clearance (if classified)
- A valid need to know
- Authorization to access the specific information
If any one of these elements is missing, the disclosure is NOT authorized. Let’s clear up a common misconception.
Myth: “If someone has a clearance, I can discuss classified information with them.”
Fact: A clearance alone is not enough. Access requires a demonstrated need to know and any program specific authorizations.
CUI: A Frequently Overlooked Risk
Many personnel are comfortable spotting risks involving classified information but overlook CUI—material protected by law, regulation, or government wide policy even though it isn’t classified.
A few examples include, but are not limited to:
- Procurement sensitive information
- Export controlled data
- For Official Use Only (FOUO) or Sensitive but Unclassified (SBU) material
- Controlled technical information
- Privacy information (PII)
CUI does not require a clearance, but it does require authorized access, approved systems, and proper safeguarding. We should treat CUI with the same level of care we apply to preventing classified spills.
Everyday Risks: Classified & CUI
Unauthorized disclosures often come from ordinary activities and habits:
- Forgetting to check if an email thread contains CUI before hitting “Reply All”
- Pulling up sensitive documents during virtual meetings without verifying participants
- Mixing classified and CUI discussions without confirming what can be shared
- Copying/pasting project details into public facing documents
- Uploading CUI to unapproved collaboration tools or storage locations
Small oversights can create big vulnerabilities.
How Unauthorized Disclosures Happens
Here are a few real world situations we may encounter:
- Mentioning a milestone schedule in front of visitors, not realizing it is CUI
- Receiving a draft with embedded CUI that wasn’t marked
- Getting a “quick context” question from someone whose access level is unclear
- Moving between networks and saving sensitive files in the wrong location
None of these feel reckless, but they still count as unauthorized disclosures.
Unauthorized disclosures can also occur in everyday environments:
- Discussing sensitive work in public places such as airports, restaurants, or elevators
- Forwarding emails without confirming all recipients are authorized
- Using the wrong collaboration platform or distribution list
- Leaving sensitive material visible during virtual meetings or screen sharing
- Assuming a coworker “already knows” without verifying need to know
Most of these situations are preventable with a brief pause to verify before sharing.
Good Habits for Preventing Unauthorized Disclosure
Before sharing sensitive information, ask yourself:
- Who is receiving this information?
- Do they have the appropriate authorization and need to know?
- Is this the correct communication method?
- Am I sharing only what is necessary for the task?
A few simple behaviors go a long way:
- Check classification and CUI markings when opening, editing, or sharing documents
- Verify access and need to know—even when you think someone is read in
- Keep sensitive conversations in controlled spaces and on approved systems
- Slow down before sending emails, especially cross organization
- Properly mark CUI according to DoD or agency specific guidance
- When uncertain, pause and ask—your security team is here to support you
These habits take only seconds and help prevent reportable security incidents.
Reporting Mistakes
Mistakes happen—and fast reporting is critical.
If you believe protected information may have been disclosed to an unauthorized person:
- Stop any additional sharing
- Preserve any relevant information
- Notify your Facility Security Officer (FSO) immediately
- Avoid trying to resolve the issue on your own
Prompt reporting allows your security team to assess the situation, limit potential damage, and meet mandatory reporting requirements.
Final Thought
Protecting information isn’t about making work harder—it’s about ensuring sensitive information reaches only those who are authorized to receive it. A quick verification today can prevent a security incident tomorrow.
This Month’s Challenge: Before sending your next sensitive email or discussing a protected project, take five seconds to verify the recipient, the need-to-know, and the communication method. Small habits make a big difference.
Want to Learn More?
Resources and Additional Learning
CDSE Unauthorized Disclosure of Classified and CUI
CDSE Unauthorized Disclosure Student Guide
CDSE Unauthorized Disclosure Toolkit
National Archives Unauthorized Disclosure Prevention and Reporting
32 CFR Part 147 (Adjudicative Guidelines)
As always, if you have any questions…ask your FSO! Your company’s FSO is the best person to help you navigate any questions you have about security compliance, briefing, and reporting requirements. As security professionals, we are here to help you navigate all things security and ensure you fulfill all security requirements.

