ITMG® Consulting Experience & Client Results
We prove our capability through direct operational results. See how we help Fortune 500 organizations convert fragmented security tools and alerts into cohesive, board-ready exposure management capabilities.
Most insider-risk programs suffer from a coordination problem.
Organizations possess world-class security tools, legal policies, and HR data. But they rarely connect them. Cyber teams see network anomalies, HR understands workforce transition contexts, DLP tools flag data movements, and Legal manages compliance guardrails.
ITMG serves as the expert integration layer. We align these stakeholders, define clear governance, and build operational blueprints to reduce insider exposure before harm occurs.
Practitioner-Led Excellence
ITMG contains no generalists or junior analysts. Every engagement is staffed and led directly by elite practitioners with deep background in law, national security, and enterprise risk.
Bridges the Organizational Divide
We speak the unique languages of HR, Legal, Privacy, Cyber, and Business Executives. This allows us to align conflicting priorities and build consensus in high-sensitivity environments.
Tool-Agnostic Advisory
Because ITMG is completely independent and not tied to any hardware or software vendor, our recommendations are tailored solely to your culture, risk tolerance, and business objectives.
Living Exposure Management
We reject the 'one-and-done' static report approach. Using our RiskTKO® platform, we turn findings, assessments, policies, and remediation into a dynamic, living operating capability.
Impactful Case Studies
Explore concrete examples of how ITMG consultants resolved structural, technical, and regulatory problems for high-sensitivity enterprises.
Fortune 50 Energy Company
The Operational Landscape
A global energy infrastructure provider with over 50,000 employees lacked a cohesive, centralized mechanism to identify and manage risk across highly sensitive operational networks and corporate environments.
The Friction & Challenge
Stakeholders in cybersecurity, physical security, HR, and compliance were heavily siloed. There was no shared definition of insider risk, no steering committee, and no baseline to measure capability improvements for the board.
ITMG Expert Contribution
ITMG conducted a multi-phase capability assessment using the Insider Risk Capability Framework™ (IRCF™). We held intensive, moderated workshops with executives, performed a deep dive into existing policies and telemetry, and identified dozens of high-severity operational gaps.
Essential Deliverables
- Structured Maturity Baseline report mapping core IRCF™ component areas.
- Charter and operating model for a new Executive Insider Risk Steering Committee.
- A funded, 3-year prioritized maturity roadmap aligned with capital expenditure cycles.
Value & Outcomes
- Established a fully functional cross-company governance model within 90 days.
- Unified cybersecurity and HR telemetry into a single, high-trust investigative handoff workflow.
- Provided the CISO with defensible, Board-ready capability improvement metrics.
Representative outcomes across 300+ engagements.
ITMG does not deliver abstract high-level advice. We focus on producing practical, repeatable security controls, governance agreements, and operating metrics that empower internal program owners.
Formed executive steering committees and cross-functional governance structures.
Drafted foundational operating policies, procedures, and investigative handoff workflows.
Orchestrated existing security tech stacks (DLP, UEBA, SIEM, IAM) to maximize detection.
Defined proportional monitoring guardrails that satisfy rigorous privacy requirements.
Staffed and built specialized insider threat operations centers (ITOC) for continuous oversight.
Provided litigation-ready investigative frameworks that protect critical assets and limit liability.
Interviewed and Referenced by Forrester
Forrester analysts have interviewed Shawn Thompson and ITMG for three research reports addressing insider threat and insider risk management. The resulting research cited Shawn’s practitioner perspective and referenced ITMG in connection with specialized insider threat training, expert advisory support, and the establishment of enterprise insider threat programs.
Best Practices: Insider Risk Management
Forrester | June 30, 2023
Forrester interviewed ITMG for this research and referenced the firm as a provider of specialized training for insider threat teams.
Joseph Blankenship, Stephanie Balaouras, Alexis Tatro, and Michael Belden, “Best Practices: Insider Risk Management: Treat Insider Risk As A Human Problem, Not A Technical Issue,” Forrester, June 30, 2023.
Best Practices: Mitigating Insider Threat
Forrester | March 18, 2021
Forrester interviewed ITMG and included the firm in its “Get help from experts” guidance as an expert service provider that can help organizations establish insider threat programs.
Joseph Blankenship and Claire O’Malley, “Best Practices: Mitigating Insider Threat: Processes: The Zero Trust Security Playbook,” Forrester, March 18, 2021.
The Insider Risk Management Team Charter
Forrester | June 20, 2023
Forrester interviewed Shawn Thompson and cited his perspective on the multidisciplinary, investigative, analytical, and communication skills required for effective insider risk teams.
Joseph Blankenship, Stephanie Balaouras, Jeff Pollard, Alla Valente, Jess Burn, Alexis Tatro, and Shayna Neuburg, “The Insider Risk Management Team Charter: Build A Dedicated Insider Risk Function To Detect, Investigate, And Respond To Insider Incidents,” Forrester, June 20, 2023.
Shawn Thompson Named an Insider Risk Visionary by Teramind
Teramind named ITMG founder and CEO Shawn M. Thompson one of its “15 Insider Risk Visionaries You Must Follow,” highlighting his insider-risk, investigations, national-security, and Fortune 500 program leadership experience.
Teramind
“one of the world’s foremost authorities on insider risk and national security”
Enterprise Client Endorsements
Read how enterprise security and legal executives evaluate the organizational results and business value created by ITMG.
"ITMG provides us unmatched insider threat thought leadership and advisory services. They helped us bridge siloed stakeholders, establish a steering committee, and build a unified operating structure."
Siloed stakeholders, lack of efficient collaboration, and decentralized insider risk structure.
Executive coaching, operating structure assessment, and stakeholder working sessions.
A centralized, cohesive capability and a highly effective executive steering committee.
Global Insider Threat Director
Approved QuoteFortune 50 - Energy Client
"Money well spent. Their roadmap gave us complete visibility of how we can use our existing tech stack to identify insider activity—with absolutely zero new tool purchases required."
Massive security tech stack not orchestrated for insider threat detection and risk management.
Conducted technical stack review, mapped alerts to indicators, and built a 30-60-90 day roadmap.
Significant cost savings (no new software required) and immediate operational detection value.
Chief Information Security Officer (CISO)
Approved QuoteFortune 50 - Technology Client
"ITMG developed a robust, defensible insider threat program that allows us to protect our intellectual property while continuing to enable fast-paced engineering innovation."
Lacked a formal, defensible insider risk program, creating exposure during a workforce transition.
Conducted capability assessment, briefed the C-suite, built the operating model, and staffed initial operations.
A resilient, operational program staffed by ITMG analysts that remained in place for four years.
Chief Security Officer (CSO)
Approved QuoteFortune 100 - Retailer
"ITMG created a tremendous insider risk management program for us, ensuring compliance with our myriad regulatory and legal requirements. Their consultants are true subject matter experts."
Needed to establish a comprehensive insider threat program to satisfy regulatory compliance demands.
Conducted capability assessment, briefed senior executives, and built a fully compliant operating model.
An effective and defensible program that easily exceeded regulatory and legal standards.
SVP, General Counsel
Approved QuoteFortune 500 - Media Publishing Client
"ITMG consultants are true subject matter experts who helped us build the technical foundation and obtain the authority to operate our monitoring tools in highly regulated corporate environments."
Lacked authority to deploy User Activity Monitoring (UAM) due to sensitive privacy and legal friction.
Reviewed legal requirements, collaborated with HR/Legal, and developed oversight workflows.
Secured formal 'Authority to Operate' (ATO) while fully protecting employee privacy and trust.
Director of Insider Risk
Approved QuoteFortune 100 - Healthcare Client
"I strongly recommend Shawn and his team at ITMG to assist with building and maturing Insider Threat and Insider Risk programs. Shawn can speak from experience as a federal prosecutor and practical executive."
Required immediate program modernization based on recent intellectual property theft incidents.
Reviewed existing capabilities, built operating procedures, and designed governance models.
An optimized, compliant, and modern insider-risk operating capability.
Executive Director, Cybersecurity
Approved QuoteFortune 100 - Tech Corporation
Elite Practitioners vs. Traditional Consulting
We reject the high-overhead, low-context models of generic consulting. See how our specialized methodology compares.
Traditional Risk Consulting
- ✕Staffed by junior generalists learning on your company's bill.
- ✕Provides high-level, static reports that quickly become outdated.
- ✕Focuses strictly on checking compliance boxes or pitching proprietary tools.
- ✕Lacks deep multidisciplinary expertise in national security and law.
ITMG® Specialized Engagement
- ✓Staffed and led solely by world-class, experienced practitioners.
- ✓Delivers an active, living exposure platform via RiskTKO® orchestration.
- ✓Independent and tool-agnostic, maximizing value from your existing stack.
- ✓Unique synthesis of legal, intelligence, cybersecurity, and corporate governance.
Practitioner-Led, Advisory-Focused

Shawn M. Thompson, Esq.
Founder & CEO, ITMG® | Former FBI & NSA Advisory Lead
As a former federal prosecutor, FBI Assistant General Counsel, and NSA Insider Threat Program Manager, Shawn Thompson leads ITMG's advisory practice with an unparalleled balance of law, national security, and cyber risk experience.
View Shawn's Full Executive Profile