A Spill Begins with a Purchase Order

The company doesn't need to experience a sophisticated cyberattack to lose control of its information. A request for quote, a purchase order, a manufacturing traveler, or a drawing sent to a plater can carry a controlled technical package out of the protected environment through the path the company's own systems made easiest, and nothing looks broken afterward. This paper follows one fictional spill at Cogswell Cogs, a composite precision machining shop, from the moment a quality manager notices a controlled drawing sitting in an ordinary supplier email.

What the investigation eventually establishes. The package remained in the purchasing employee's downloads folder, was stored in the ERP, entered mail retention and backup systems never evaluated for it, sat on a shared office computer at the plater, was forwarded to an outside estimating consultant without approval, and synchronized from the heat treater's laptop to a cloud account outside any approved workflow.

What the company knows at discovery. One drawing, one supplier, one bypassed process. Everything else surfaces only through investigation over the following days, which is why a response plan that assumes full knowledge at discovery describes an incident that doesn't happen in real life.

The Public Record

None of this is hypothetical. In February 2023, the Commerce Department imposed a $2,777,750 penalty on 3D Systems Corp., which had regularly emailed customer design documents to its then-subsidiary in China to generate price quotes, including controlled drawings for military electronics and spacecraft work, without the knowledge of the customers who requested the quotes. Discovery came when a defense contractor noticed something wrong in routine supplier correspondence, which is exactly how the fictional spill in this paper surfaces.

Enforcement without a breach. MORSECORP agreed to pay $4.6 million in a 2025 False Claims Act settlement after reporting a summary score of 104 that a consultant later measured at negative 142 (-142); the announcements establish no actual theft or disclosure. On September 1, 2026, Honeywell Aerospace agreed to pay $2,042,518 over alleged NIST SP 800-171 noncompliance, allegations only, with no determination of liability. Both cases arose from whistleblower suits.

The government's own ledger. The DoD Inspector General reported that 126 contractors reported 248 security incidents to the DoD Cyber Crime Center over a three-year span, with inadvertent disclosure listed alongside intrusions and exfiltration. The paper also explains how the government can discover a spill before the company does, including investigations that trace a recovered drawing backward to its source through title blocks, drawing numbers, and markings.

Two Responses to the Same Monday Morning

The paper runs the same facts twice. In the wrong response, purchasing calls the suppliers and asks them to delete the email, management accepts verbal assurances, IT clears the ERP attachment and the downloads folder before preserving anything, and notification waits until Friday while management tries to learn whether anyone opened the documents. Each decision costs something specific: the deletions destroy the cleanest record of what was sent while missing the copies nobody knew existed, and the wait consumes a 72-hour window that runs on elapsed hours, not business hours.

In the right response, the operations manager opens an incident record in the first hour, containment and evidence preservation proceed together, reporting is evaluated on the facts available rather than postponed for a complete investigation, and uncertainty is recorded as uncertainty. The CNC machines keep cutting the entire time, because proportionate containment doesn't take down unaffected production.

The Clock, the Portal, and the Suppliers

Where DFARS 252.204-7012 applies and its threshold is met, discovery at 9:15 a.m. Monday produces a reporting deadline of 9:15 a.m. Thursday. Subcontractors report directly through DC3's Incident Collection Format, which requires a medium assurance certificate that takes days to obtain, and preservation of affected system images and monitoring data runs at least 90 days from the report. The paper walks through the specific questions to put to the plater and the heat treater, how to work with a 12-person supplier that has no internal IT, and why supplier evidence supplements rather than replaces the preservation the clause requires.

Finding Copies and Closing Defensibly

The paper covers the practical discovery toolkit, including digital fingerprinting with its real limits: exact hashes find byte-identical copies including renamed files, drawing numbers and distinctive technical text make effective search terms, and none of it determines legal CUI status or supports a claim that every copy was found. It then works through cleanup and backups, why ordinary deletion and email recall can't establish removal, what to do with a retained backup that can't immediately be altered, and the closure record that separates containment, operational recovery, corrective action, and management's documented closure decision. Six additional scenarios get the same treatment, from drawings on a legacy CNC workstation to an upload to an unauthorized AI service.

Download the Full White Paper

The full paper covers the CUI and proprietary information distinction under 32 CFR Part 2002, the documented cases with citations to the BIS, DOJ, and DoD Inspector General announcements, the incident and both responses hour by hour, reporting mechanics through DC3's Incident Collection Format with the subcontractor direct-reporting requirement, supplier coordination questions, digital fingerprinting and its limits, cleanup, backups, and the defensible closure record, six additional spill scenarios, and prevention that fits a machine shop. Claims are supported by citations to DFARS 252.204-7012, DC3 reporting guidance, 32 CFR Part 2002, the NARA CUI Registry, and NIST SP 800-171, 800-88 Rev. 2, and 800-61 Rev. 3.

Download PDF →
Related

The CMMC Decision, Second Edition

Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.

Read More →