They need to rethink their development systems and code promotion strategies. Contractors like this should NEVER have access to data like this.
They should also have systems that monitor all data downloads and encryption, and checks to see if key words exist in that data that would only exist on Classified or Secret documents.
They only found out because they were investigating time card fraud. Then they started looking at his network path on his computer and discovered he had downloaded many files to a device.
DUH???? Why isn’t their IT tracking who is downloading what and why isn’t an alert given to IT on devices and downloads from contractors, employees. Wow how many other people are doing what he did and not getting caught?