National Capital RegionVA DCJS License No. 99-613042
Deetz Consulting

File 05. Compliance

The National Capital Region threat picture: a Q1 2026 briefing.

A quarterly read on the threat indicators most relevant to corporate operations and principal exposure across Washington, DC, Northern Virginia, and Maryland.

January 29, 202610 min read

This is the first of what will be a quarterly read on the threat indicators most relevant to corporate operations and principal exposure across the National Capital Region — Washington, DC, Northern Virginia, and Maryland. It is not a comprehensive intelligence product. It is a working brief from a regional security advisor on the indicators that warrant attention from boards, executive teams, family offices, and the counsel who serve them.

Three indicators have moved during the opening weeks of 2026 in ways that warrant comment.

— I. Workplace-violence indicators in corporate operations.

Reporting from regional HR and security functions through the latter half of 2025 indicates a sustained upward drift in workplace-violence-adjacent incidents — threats made by departing employees, escalations during termination interviews, post-termination incidents reaching restraining-order thresholds, and confrontation events involving spouses or former partners of employees on company premises.

The pattern is not unique to the National Capital Region; it is part of a national trend that began in 2022 and has not reversed. But the regional pattern has two distinctive features. First, the share of incidents involving employees of federal contractors and federally adjacent firms is higher than the share in comparable urban regions — a function of the region's workforce composition and the heightened personal exposure these roles can produce. Second, the gap between the institution's awareness of the threat and the institution's operational readiness to handle it has remained wide.

Practical inference for boards: the workplace-violence prevention program is one of the lowest-cost, highest-leverage governance items currently available to a regional employer. The investment required to design a credible cross-functional threat assessment team is modest. The reputational and operational exposure of not having one — at this moment, in this region — is not.

— II. Insider-threat indicators among federal-adjacent personnel.

The second indicator is more subtle, and it warrants a careful read by general counsel of firms with federal contract exposure. Reporting through the back half of 2025 suggests a higher-than-baseline rate of insider matters originating among personnel who hold or recently held federal clearances and are now in private-sector roles. The matters span data handling, vendor relationships, and conflict-of-interest disclosures.

The likely driver is structural rather than malicious. Personnel transitioning from clearance environments into private roles carry, by training and habit, a different posture toward information and access than personnel native to the private sector. The transition is rarely accompanied by formal retraining on private-sector norms. The result is a meaningful population of senior personnel operating within private firms while internalizing investigative and information-handling reflexes calibrated for a different operating context. The mismatch is not deception. It is unexamined inheritance.

Practical inference for boards and general counsel: insider-threat programs in National Capital Region firms with significant federal-adjacent populations should explicitly contemplate this transition population, with onboarding language and ongoing compliance touchpoints calibrated for it. Most existing programs do not.

— III. Principal-exposure indicators in the post-election environment.

The third indicator concerns principal exposure. The post-election environment in the region — and in 2026 specifically — has produced a sustained elevation in the threat picture for corporate principals whose firms have visible policy positions, regulatory exposure, or public-facing political involvement of any kind.

The indicator that matters here is not the rate of credible threats against specific principals, which remains low in absolute terms. It is the rate at which credible threats are surfacing against categories of principals — executives of firms in named industries, board members of named institutions, family-office principals associated with named donors. The category-based exposure is structurally different from individual exposure, and it requires different protective architecture.

Individual exposure responds well to traditional executive protection: detail, advance, residential. Category-based exposure responds less well. The protective requirement is more about reducing predictability — of routine, of public exposure, of family presence at predictable events — than about hardening any single venue or movement.

Practical inference for principals and family offices: the executive protection program designed during a quieter period may not be calibrated for category-based exposure. A program review at this moment, with explicit attention to predictability rather than to perimeter, is reasonable governance. It is the discipline of executive protection at federal-grade — the same discipline applied to political principals during periods of elevated category-based threat.

— IV. A note on what this briefing is not.

This brief is not classified, not derived from any privileged source, and not a substitute for the formal threat intelligence products produced by federal agencies and reputable commercial providers. It is a working observation from a regional advisor — informed by thirty years inside federal protection and corporate enterprise security — about what is moving in the threat picture this quarter, framed for the audience this firm serves.

The next briefing publishes in early Q2. Readers who wish to be notified may subscribe by sending a brief email to info@deetzconsulting.com. The subscription list is held privately and used only to send the next File.

Until then: the indicators above warrant attention. The disciplines that address them are well understood. The decision to engage them sits, as it always sits, with the people responsible for the institutions and the principals at stake.

David O. Deetz, Jr., Founder & Principal Advisor

David O. Deetz, Jr.

Founder & Principal Advisor · Deetz Consulting, LLC

Former U.S. Secret Service Special Agent in Charge of the Inspection Division. Former Senior Director of Enterprise Corporate Security at Trellix & Skyhigh Security. U.S. Marine Corps Counterintelligence veteran with thirty-five years in protection, investigation, and corporate security across federal and private sectors.

For matters where the cost of error is not measured in dollars.