James M. Olson’s counterintelligence principles, what they originally meant, and how government, defence and corporate leaders should interpret them in 2026.
By Navid Sobbi, Founder and CEO, NSI Global
ORIGINAL PUBLICATION: 5 May 2020 REVISION COMPLETED: 21 September 2026 AEST
James M. Olson’s “Ten Commandments of Counterintelligence” were written for professional intelligence practitioners, but their central message remains highly relevant to corporate counterintelligence more than two decades later: organisations cannot protect sensitive information by relying on passive security controls alone. Counterintelligence requires threat awareness, skilled people, analysis, institutional authority, historical perspective and the persistence to investigate what does not fit.
Olson, a former chief of CIA counterintelligence who served 31 years in the Central Intelligence Agency, published the principles in the Fall-Winter 2001 edition of the CIA journal Studies in Intelligence. He described them as personal observations drawn from experience, not as definitive rules handed down as formal CIA doctrine.
That distinction matters. Olson was writing primarily for national intelligence services operating in an espionage environment. A corporation, university, law firm, infrastructure operator or defence-industry company cannot simply copy state counterintelligence tradecraft. The useful question is therefore not “How can a business behave like an intelligence service?” It is: “Which underlying principles can be translated into lawful, proportionate protective-security practice?”
What Are Olson’s Ten Commandments?
Olson’s ten principles are:
- Be Offensive
- Honor Your Professionals
- Own the Street
- Know Your History
- Do Not Ignore Analysis
- Do Not Be Parochial
- Train Your People
- Do Not Be Shoved Aside
- Do Not Stay Too Long
- Never Give Up
The original NSI Global article correctly listed the ten principles, but it blended Olson’s counterintelligence paper with discussion of his separate book Fair Play: The Moral Dilemmas of Spying. This updated article treats them separately. The Ten Commandments were published in Studies in Intelligence in 2001; Fair Play is a different work focused on ethical dilemmas in intelligence operations.
What Corporate Counterintelligence Means for Modern Organisations in 2026
Corporate counterintelligence in 2026 operates in an environment that has changed dramatically since 2001. Sensitive information now moves through cloud platforms, mobile devices, collaboration tools, third-party providers and globally distributed workforces. Social media and commercial data can support targeting. Artificial intelligence can accelerate analysis, deception and influence activity. Cyber operations can reach information without requiring physical access, while insider risk, travel exposure and technical surveillance remain persistent concerns.
What has not changed is the counterintelligence problem: an adversary seeks access to information, people, capabilities, relationships or decision-making that provide an advantage. ASIO’s public NITRO guidance states that foreign intelligence services target government, defence, academia and business, and that information which appears innocuous in isolation can become valuable when combined with other information.
ASIO’s 2025 Cost of Espionage report describes the espionage threat as being at extreme levels and expected to worsen as technology develops and strategic competition increases. PSPF Release 2026 likewise updates Australian Government protective-security controls for current and emerging threats, including foreign-interference training and obligations concerning emerging technology.
The Ten Commandments: Original Meaning and Modern Organisational Translation
| Olson’s Principle | Original Intelligence-Service Lesson | Modern Organisational Translation |
| 1. Be Offensive | Counterintelligence cannot succeed if it only waits for hostile activity to reveal itself. | Be proactive: identify what matters, assess likely threats, hunt for anomalies, test controls and investigate credible indicators before a crisis. |
| 2. Honor Your Professionals | Counterintelligence specialists need institutional respect, resources and career support. | Give security, intelligence, forensic and investigative specialists authority, access to decision-makers and independence to deliver uncomfortable findings. |
| 3. Own the Street | A service must understand and operate effectively in the real environment where adversaries act. | Understand the organisation’s actual operating environment: people, facilities, travel, suppliers, communications, access pathways and digital/physical interfaces. |
| 4. Know Your History | Past espionage cases reveal recurring methods, vulnerabilities and institutional failures. | Use case history, incident reviews and lessons learned to avoid repeating known failure modes. |
| 5. Do Not Ignore Analysis | Operations without rigorous analysis can miss patterns or misread the adversary. | Connect HR, IT, legal, cyber, access, travel, intelligence and forensic information rather than treating each alert as an isolated event. |
| 6. Do Not Be Parochial | Counterintelligence must look beyond organisational boundaries and narrow professional silos. | Break down departmental silos, include third-party and supply-chain risk, and seek external expertise when the threat crosses disciplines or jurisdictions. |
| 7. Train Your People | Counterintelligence competence is built through sustained specialist training. | Train specialists deeply and teach the wider workforce how to recognise, preserve and escalate relevant indicators. |
| 8. Do Not Be Shoved Aside | CI scrutiny can be inconvenient, but it must not be excluded from sensitive operations. | Give counterintelligence and protective-security functions a defined governance role in high-risk projects, transactions, travel, facilities and incidents. |
| 9. Do Not Stay Too Long | Long tenure in CI can create fatigue, overfamiliarity or distorted judgement. | Use rotation, peer review, independent challenge and periodic external assessment to preserve objectivity and avoid a culture where suspicion becomes the default. |
| 10. Never Give Up | Serious counterintelligence cases can require patience and persistence. | Investigate credible concerns methodically, revisit assumptions as evidence changes and document why enquiries are continued, escalated or closed. |
1. Be Offensive
Olson’s first principle argues that passive, purely defensive counterintelligence is insufficient. In the intelligence-service context, he was advocating proactive operations against hostile services rather than waiting for penetrations to be discovered after damage had occurred.
That language must be translated carefully for a corporation. “Offensive counterintelligence” does not give a commercial organisation licence to recruit foreign intelligence officers, conduct clandestine operations against competitors or intrude into systems or communications without authority. The lawful corporate equivalent is anticipatory security: identify likely intelligence requirements against the organisation, understand who might value the information, test vulnerable pathways, monitor credible threat indicators and investigate anomalies before they mature into loss.
What “Be Offensive” Can Mean for a Corporation
- Threat-led intelligence and geopolitical monitoring rather than relying only on historical incidents.
- Enhanced due diligence on high-risk counterparties, suppliers, investors and strategic partners.
- Risk-based TSCM before or around highly sensitive meetings, transactions and events.
- Forensic readiness and preservation plans before an insider, cyber or misconduct investigation begins.
- Communications-security controls for executives and teams exposed to elevated targeting risk.
- Independent testing of security assumptions rather than waiting for a breach to disprove them.
The dividing line is clear: proactive does not mean unlawful. Corporate counterintelligence should operate under documented authority, legal oversight, proportionality and evidence-based decision-making.
2. Honor Your Professionals
Olson observed that counterintelligence practitioners often deliver unwelcome messages. Their success can be difficult to measure because preventing compromise is less visible than responding to one. His second principle is fundamentally about institutional respect for the people whose job is to challenge comfortable assumptions.
Modern organisations face the same governance problem. A security specialist who identifies an insider-risk indicator, a due-diligence concern, a suspicious device, a compromised account or a weakness in a high-profile project may delay a transaction or create friction. If leadership treats that scrutiny as an obstacle rather than a control, the security function will eventually be bypassed.
Counterintelligence capability therefore needs senior sponsorship, access to decision-makers, defined escalation pathways and the ability to present adverse findings without pressure to dilute them.
3. Own the Street
For Olson, “the street” was the operational environment in which espionage activity occurred. His point was that a counterintelligence service could not understand or counter an adversary from behind a desk alone.
For a modern organisation, the principle is broader: understand the environment where people, information and access actually move. That includes offices, boardrooms, remote-work locations, executive travel, conferences, hotels, vehicles, suppliers, data centres, cloud platforms, collaboration systems and personal devices used for work.
Owning the environment does not mean surveilling staff indiscriminately. It means knowing the legitimate baseline well enough to recognise what is unusual: who should have access, which devices should be present, what data flows are expected, which vendors are authorised, and where sensitive conversations occur.
4. Know Your History
Counterintelligence repeatedly punishes organisations that assume a new technology or a new geopolitical environment has made old lessons irrelevant. Olson’s fourth principle is a warning against institutional amnesia.
Historical cases reveal recurring themes: trusted insiders abusing access, organisations rationalising anomalies, fragmented reporting, warning signs that make sense only when combined, and controls that exist on paper but fail in practice. The technology changes; the human and organisational vulnerabilities often recur.
A mature organisation should maintain lessons learned from security incidents, investigations, near misses and external case studies, then feed those lessons into policy, training, access control and risk assessments.
5. Do Not Ignore Analysis
This is one of the most important principles for corporate counterintelligence. Data is not intelligence merely because it has been collected. Individual alerts, access logs, travel information, due-diligence findings, forensic artefacts, HR concerns and security incidents may look insignificant until they are analysed together.
The analytic function tests competing explanations. Is unusual access evidence of misuse, a legitimate operational requirement or a systems issue? Does a relationship identified during due diligence materially change the risk? Is an anomalous wireless device malicious, misconfigured or simply undocumented? Good counterintelligence analysis reduces both missed threats and false accusations.
This is why security, IT, cyber, legal, HR, investigations and intelligence functions need a governed mechanism to share relevant information where lawful and proportionate.
6. Do Not Be Parochial
Olson warned against narrow organisational thinking. Modern counterintelligence risks are rarely confined to one department or one geography.
A sensitive project can involve internal staff, external counsel, accountants, contractors, cloud providers, technology vendors, logistics partners, overseas subsidiaries and government stakeholders. Each participant extends the trust boundary. A technically secure headquarters can still be exposed through a third party with weaker controls or through an executive travelling with sensitive devices.
The practical lesson is to assess the entire information and relationship ecosystem rather than treating cyber security, physical security, personnel security, TSCM, intelligence and due diligence as unrelated disciplines.
7. Train Your People
Counterintelligence is a specialist discipline, but the specialist team cannot see every interaction. Staff, executives, contractors and advisers are often the first people to notice something that does not fit.
Training should therefore operate at two levels. Specialists need deep technical and investigative capability. The wider workforce needs enough awareness to recognise and report indicators without being encouraged to diagnose espionage themselves.
Useful awareness topics can include:
- Unusual attempts to obtain information outside a person’s legitimate need-to-know.
- Requests to move sensitive discussions to personal or less-controlled communications channels.
- Unexplained access to sensitive areas, systems or documents.
- Unexpected electronic devices in controlled or sensitive spaces.
- Repeated efforts to build relationships around privileged access or sensitive projects.
- The correct reporting and evidence-preservation pathway when something concerning occurs.
ASIO’s NITRO guidance publishes similar classes of indicators while stressing the importance of context. A single behaviour is not proof of espionage; patterns and circumstances matter.
8. Do Not Be Shoved Aside
Counterintelligence can be inconvenient precisely when it matters most: before a major transaction, during a high-profile project, when an executive wants to travel quickly, when a supplier is commercially attractive or when an internal investigation may affect senior personnel.
A security function that can be bypassed whenever scrutiny becomes uncomfortable is not a control. Organisations should define when counterintelligence, due diligence, TSCM, legal review or forensic preservation is mandatory, who can accept residual risk and how exceptions are documented.
The objective is not to give security unlimited veto power. It is to prevent risk decisions from being made without the relevant intelligence being heard.
9. Do Not Stay Too Long
This principle is easy to misread. Olson was warning about the psychological and professional effects of remaining too long in an environment where deception, penetration and hidden motives are constant concerns.
For a corporate program, the useful translation is institutional freshness. Counterintelligence practitioners should be capable of scepticism without allowing suspicion to become the default explanation for ordinary behaviour. Rotation, peer review, legal oversight, multidisciplinary case review and independent external assessment help maintain objectivity.
A healthy counterintelligence culture protects the organisation from hostile activity without turning the organisation itself into a hostile environment for employees.
10. Never Give Up
Serious counterintelligence problems can take time to understand. The absence of an immediate explanation does not automatically make a concern irrelevant, but persistence must remain disciplined.
Modern investigations should define the question, preserve evidence, document hypotheses, identify what would confirm or weaken each explanation, and record why the matter is escalated, paused or closed. Persistence is valuable when it is evidence-led; it becomes dangerous when an investigator becomes committed to proving a predetermined conclusion.
Counterintelligence Starts With Anomalies, Not Accusations
ASIO’s public guidance identifies behaviours that can be associated with hostile intelligence activity, including unexplained removal of information, inappropriate electronic devices in sensitive areas, unusual efforts to elicit information and access patterns that do not fit legitimate requirements. These are indicators for assessment, not proof that a person is acting for a foreign power.
That distinction is central to corporate counterintelligence. A good program asks whether several independent facts form a meaningful pattern and tests innocent as well as adverse explanations. It avoids treating nationality, background, political views or personal relationships as substitutes for evidence.
What a Modern Counterintelligence Program Actually Protects
| Domain | Counterintelligence Question | Examples of Protective Controls |
| People | Who has access, influence, opportunity or unusual interest in sensitive information? | Personnel security, insider-risk governance, reporting pathways, investigations and role-based access. |
| Information | What information would be valuable to a competitor, hostile actor or foreign intelligence service? | Classification, need-to-know, information handling, monitoring, retention and compartmentation. |
| Technology | Which devices, systems, accounts and communications pathways could expose sensitive information? | Digital forensics, cyber controls, COMSEC, mobile security, identity and access management. |
| Physical Environment | Where do sensitive conversations and activities occur, and who can access those spaces? | TSCM, access control, secure meeting practices, visitor management and facility security. |
| Third Parties | Which suppliers, advisers, contractors, investors or partners extend the trust boundary? | Enhanced due diligence, contractual controls, third-party risk assessment and ongoing monitoring. |
| Intelligence & Governance | Who connects separate indicators and decides when risk requires action? | Threat intelligence, analytic review, escalation criteria, board reporting and independent assurance. |
Ten Questions Boards Should Ask About Counterintelligence Risk
- What information, capability or relationship would an adversary consider most valuable?
- Who has legitimate access to that information, and who has indirect or temporary access?
- Which suppliers, contractors, advisers and partners extend our trust boundary?
- Where do our most sensitive conversations occur, and how are those environments protected?
- What behaviours, access patterns or technical indicators would trigger an insider-risk review?
- Who is responsible for combining intelligence across security, cyber, HR, legal, IT and investigations?
- How do we assess counterparty, foreign ownership/control/influence and relationship risk before major transactions?
- How are executives protected during sensitive travel, communications and high-value negotiations?
- What is the escalation and evidence-preservation process when suspicious activity is identified?
- When was our counterintelligence posture last independently tested rather than internally assumed?
How Corporate Counterintelligence Translates Into NSI Global Capability
NSI Global’s current service structure reflects the multidisciplinary nature of modern counterintelligence. Its public service pages bring together counterintelligence, TSCM, digital forensics, investigations, enhanced due diligence, communications security, global intelligence and risk advisory rather than treating each as a standalone technical issue.
Technical Surveillance Counter Measures (TSCM) – protecting sensitive physical and communications environments from covert technical surveillance.
Digital Forensics – preserving and examining digital evidence in insider, misconduct, cyber and other authorised investigations.
Communications Security (COMSEC) – protecting sensitive communications and addressing telecommunications-security risks.
Enhanced Due Diligence and Background Checks – examining counterparties, relationships, interests and risk indicators before trust is extended.
Corporate Investigations – establishing facts in fraud, misconduct, IP, insider and corporate-security matters.
Global Intelligence Services – providing strategic and tactical intelligence for evolving threat environments.
Security Master Planning – integrating people, process and technology controls into a coherent security program.
The commercial lesson from Olson’s principles is therefore not that a private organisation should imitate a state intelligence service. It is that serious corporate counterintelligence requires more than one tool. Intelligence identifies the threat; due diligence examines relationships; TSCM examines the environment; COMSEC protects communications; digital forensics reconstructs activity; investigations establish facts; and governance determines what the organisation does with the result.
Frequently Asked Questions
Who Created the Ten Commandments of Counterintelligence?
James M. Olson, a former chief of CIA counterintelligence who served 31 years in the CIA, published the principles in the Fall-Winter 2001 edition of Studies in Intelligence.
Are the Ten Commandments Official CIA Policy?
They should not be described as universal CIA doctrine. Olson presented them as personal professional observations drawn from his counterintelligence experience. The CIA hosts the article through its Center for the Study of Intelligence.
Are the Ten Commandments Still Relevant Today?
Many of the underlying principles remain relevant: proactive threat awareness, skilled practitioners, analysis, historical learning, cross-functional cooperation, training, institutional authority and persistence. The way they are implemented must reflect current law, technology, governance and organisational context.
What Is Corporate Counterintelligence?
Corporate counterintelligence is the lawful identification, assessment and mitigation of intelligence-related threats to an organisation’s people, information, technology, relationships and operations. Depending on risk, it can draw on threat intelligence, due diligence, insider-risk controls, TSCM, communications security, digital forensics and investigations.
How Is Counterintelligence Different From Cybersecurity?
Cybersecurity focuses primarily on protecting digital systems, data and services from cyber threats. Counterintelligence asks a wider adversary-focused question: who may be seeking access or influence, what do they want, which human, technical, physical or third-party pathways could be used, and what evidence suggests that targeting is occurring? Cybersecurity is one important component of that broader picture.
How Is Counterintelligence Different From TSCM?
TSCM is a specialist technical discipline focused on detecting and mitigating covert surveillance threats in physical and communications environments. Counterintelligence is broader and can include threat intelligence, personnel and insider risk, due diligence, investigations, digital forensics, communications security and governance as well as TSCM.
What Are Common Indicators of Espionage or Insider Risk?
There is no single definitive indicator. ASIO’s public guidance lists examples such as unexplained removal of sensitive information, inappropriate electronic devices in sensitive areas, attempts to elicit information, unusual copying or printing and access patterns that do not fit legitimate needs. Indicators must be assessed in context and should not be treated as proof by themselves.
Does Every Organisation Need a Dedicated Counterintelligence Team?
Not necessarily. The appropriate capability depends on exposure. Organisations holding strategically valuable IP, government information, sensitive legal or commercial material, critical-infrastructure knowledge or high-value research may need more formalised counterintelligence governance than a low-risk organisation. Some functions can be retained internally while specialist assessment is obtained when the threat or matter requires it.
Conclusion: Corporate Counterintelligence Is a Discipline, Not a Product
Olson’s enduring contribution was to describe counterintelligence as an active professional discipline rather than a collection of defensive security products. Fences, access controls, cyber tools and secure communications all matter, but they are effective only when an organisation understands the threat, analyses anomalies, empowers competent specialists and keeps testing whether its assumptions remain valid.
For modern organisations, effective corporate counterintelligence is not operational imitation of an intelligence service. It is disciplined protective security: anticipate rather than merely react, integrate information rather than leave it in silos, distinguish indicators from proof, and give counterintelligence concerns a lawful path from observation to analysis to decision.
Sources and Further Reading
- James M. Olson – The Ten Commandments of Counterintelligence, CIA Center for the Study of Intelligence – Original CIA-hosted article and publication details.
- CIA – Studies in Intelligence, Fall-Winter 2001 – Issue containing Olson’s article.
- ASIO NITRO – Recognising Hostile Intelligence Activity – Current Australian guidance on foreign intelligence targeting and example indicators of hostile intelligence activity.
- ASIO / Australian Institute of Criminology – The Cost of Espionage – 2025 assessment of the economic and national-security impact of espionage in Australia.
- Protective Security Policy Framework – PSPF Release 2026 – Australian Government update addressing current and emerging protective-security risks.
- NSI Global – Counterintelligence, Digital Forensics, Global Intelligence and Risk Advisory – Current NSI Global service positioning and integrated capability structure.
- NSI Global – Communications Security – Current communications-security capability.
- NSI Global – Security Master Planning – Current risk advisory and security master planning capability.