Every control on the perimeter assumes the people inside it are trustworthy and trained. That assumption needs a program behind it: vetting, awareness, post orders, and a clear path for reporting concerns before they become incidents.
Insider risk sits at the intersection of security, behavior, and investigations, ground that HR teams and screening vendors rarely cover. Virga's programs are built on real federal insider-threat and workplace-violence-prevention experience, including chairing the federal committee that writes the standard.
Coordination and standards for screening at hire and at role change, scaled to the sensitivity of the position, not one policy for every role.
Training people actually remember, built around real scenarios rather than an annual click-through.
What to watch for, how to report it, and how reports get handled: a program, not a suggestion box.
Written, current post orders that define exactly what a guard force is responsible for at each post, not a stack from the last vendor.
Threat assessment and intervention protocols built to federal Interagency Security Committee standards.
What comes back, what gets revoked, and how fast: the CUI/PS.L2-3.9.2 requirement most programs miss, covered under Policy, Compliance & Governance.
An assessment of your vetting, training, and reporting programs, measured against federal standards, sized to your organization.