BlackLeafwatch the watchmen
Federal Reserve Board of Governors -- insider risk management and counterintelligence oversight

The Fed's Insider-Risk Fix Sat Open for a Decade

Summary

In November 2016 the Federal Reserve's own inspector general told the Board of Governors to build a unified program for catching insider risks. In July 2026, the same watchdog found it still hadn't -- the same week a former senior adviser was sentenced to 38 months in prison for lying about sharing restricted Fed information with Chinese intelligence operatives he'd been in contact with since 2017.

By Augustus · July 16, 2026

In November 2016, the Federal Reserve's own inspector general told the Board of Governors' Division of Information Technology to "develop and implement an agency-wide insider threat strategy for sensitive but unclassified Board information." Ten years later, a July 15, 2026 OIG evaluation found that program still doesn't exist -- the Board's insider risk activities "do not proactively or effectively identify and manage risks to the agency's information and assets," the report concluded, superseding the decade-old recommendation with nine new ones.

The same day, the Justice Department announced that John Harold Rogers, a former senior adviser in the Fed's Division of International Finance, had been sentenced to 38 months in prison for lying to investigators about sharing restricted Fed information with a Chinese intelligence operative he'd been meeting since 2017 -- squarely inside the window the 2016 recommendation was meant to close.

A recommendation superseded, not fixed

The 's 2016 audit found the Board was building an insider-threat program for classified information but had not decided which parts should extend to the far larger universe of sensitive-but-unclassified material -- interest-rate deliberations, bank-supervision data, unpublished economic analysis. The Board did not engage a third-party vendor to even begin designing that unclassified strategy until November 2024, eight years after the recommendation was made.

A senior Board official told the the delay reflects a deliberate choice: the Board "has been resistant to adopting a comprehensive insider risk program because the current ad hoc approach allows each division to respond to incidents based on its own security needs." The 2026 report treats that ad hoc approach as the core problem, not a defensible design.

Years the Fed's first insider-risk fix stayed open
10
from the OIG's Nov. 2016 recommendation to the July 2026 report that finally supersedes it with nine new ones
Board insider-risk programs with a dedicated budget
0 of 4
despite the four covering classified material, FOMC rate deliberations, bank-supervision data, and personal information
Staff time guarding FOMC rate-decision deliberations
0.35 FTE
the category of information a Fed adviser is accused of passing to a Chinese intelligence contact starting in 2017
Four Fed programs guard against insider risk. None has a dedicated budget.
Dedicated staff by program, Board of Governors, per the OIG's July 2026 report
Division of IT (cybersecurity incidents)
5
IINS (classified information)
3
Supervision & Regulation (bank exam data)
1
FOMC Secretariat (rate-decision deliberations)
0.4
Source: Federal Reserve / CFPB Office of Inspector General, The Board Needs a More Robust Insider Risk Management Program, 2026-MO-B-010R, July 15, 2026, Table 1
View data as table
None of the four programs has a dedicated budget, per the OIG's Table 1. Each was built independently by its own division; the report found no centralized coordination, oversight, or shared decision-making body across them.
Division of IT (cybersecurity incidents)55 full-time staff -- the largest of the four, and the one the other three lean on for detection tools
IINS (classified information)33 part-time staff -- the Board's only fully accredited insider-threat program
Supervision & Regulation (bank exam data)11 full-time staff
FOMC Secretariat (rate-decision deliberations)0.40.35 full-time-equivalent -- guarding the category of information Rogers is accused of passing to China beginning in 2017

Four silos, no shared budget

Instead of one program, the Board runs four: a classified-information Insider Threat Program with 3 part-time staff; the Division of IT's Incident Response Program with 5 full-time staff; the Division of Supervision and Regulation's Security Incident Management Program with 1 full-time staff; and the FOMC Secretariat's Program for Security of FOMC Information -- the office guarding interest-rate deliberations before they're public -- staffed at 0.35 of a full-time position. None of the four has a dedicated budget, per the report's Table 1, and the found no individual or committee accountable for the four collectively.

By contrast, the report says an unnamed peer federal financial regulatory agency already runs "a centralized hub with a dedicated program manager and policies and procedures, including reporting metrics, training, and records retention requirements." The Fed does not.

The incident the report doesn't name

Buried in a redacted sidebar, the report describes "a then-Board employee, now retired, [who] shared sensitive Board and FOMC information and other documents with Chinese security and intelligence operatives beginning in 2017." The report does not name him. But the timeline matches the Rogers prosecution point for point: says Rogers, who worked at the Fed from 2010 to 2021, began a clandestine relationship that year with Hummin Lee, a Chinese intelligence operative he met at a conference in China, and used the guise of teaching academic "classes" in Chinese hotel rooms to pass along Fed information Lee had specifically requested.

says Rogers understood China could trade profitably on advance knowledge of Fed rate decisions in its roughly $1.5 trillion holdings of U.S. Treasury securities. When Fed investigators asked him directly, on February 4, 2020, whether he'd ever shared restricted information outside the Board, Rogers answered: "Never." A federal jury convicted him of that lie on February 3, 2026 -- while acquitting him of the more serious charge of conspiracy to commit economic espionage. Prosecutors had sought 60 months; Judge Dabney Friedrich imposed 38, plus 12 months of supervised release.

The report is heavily redacted, and it does not identify the employee in its sidebar by name -- this piece can confirm the timeline overlap (a Board employee sharing FOMC information with Chinese operatives beginning in 2017) and cannot confirm from the report itself that the sidebar describes the Rogers case specifically, though 's own account of Rogers' conduct matches it. Separately, the report's redactions mean the true count and cost of insider-risk incidents across the Board's four programs cannot be independently verified beyond what the report discloses; this piece describes only the staffing, budget, and governance gaps the documented on the record.

  • The Fed's inspector general recommended a unified insider-risk program in November 2016; a July 15, 2026 report found it still wasn't built, superseding the decade-old recommendation with nine new ones.
  • The Board runs four separate, uncoordinated insider-risk programs -- 3 part-time, 5 full-time, 1 full-time, and 0.35 full-time-equivalent staff respectively -- and none has a dedicated budget, per the 's Table 1.
  • A senior Board official told the the Fed has been 'resistant' to a comprehensive program, preferring each division's own ad hoc response.
  • The report's redacted account of a Board employee who shared FOMC information with Chinese operatives beginning in 2017 matches the timeline laid out in sentencing former adviser John Harold Rogers to 38 months in prison the same week the report published.
Sources(4) ▾
  • Office of Inspector General, Board of Governors of the Federal Reserve System and Consumer Financial Protection Bureau, The Board Needs a More Robust Insider Risk Management Program (2026-MO-B-010R) (2026-07-15)The 's evaluation, publicly released July 15, 2026, of the Board's insider risk management (IRM) activities. Supplies the nine recommendations and five findings, Table 1's staffing/budget breakdown across the Board's four separate IRM programs (p.13), the 2016 recommendation this report supersedes (p.9, footnote 7), the November 2024 third-party vendor engagement (p.9), the senior-official 'resistant' quote (p.9), the peer-agency benchmarking (p.10), and the redacted sidebar describing a 2017 insider exfiltration incident (p.8). oig.federalreserve.gov · original document
  • Office of Inspector General, Board of Governors of the Federal Reserve System and Consumer Financial Protection Bureau, 2016 Audit of the Board's Information Security Program (2016-IT-B-013) (2016-11-10)The original November 10, 2016 audit whose Recommendation 1 (p.8) told the Division of Information Technology to 'develop and implement an agency-wide insider threat strategy for sensitive but unclassified Board information.' The 2026 report confirms this recommendation remained open until superseded by its own nine recommendations. oig.federalreserve.gov · original document
  • U.S. Department of Justice, Office of Public Affairs, Former Adviser to Federal Reserve Board of Governors Sentenced to Federal Prison Term (2026-07-15)'s own account of the sentencing of John Harold Rogers, a former Federal Reserve senior adviser, to 38 months in prison for lying to investigators about sharing restricted Fed information with Chinese intelligence operatives. Supplies his 2010-2021 employment dates, the 2017 start of his contact with operative Hummin Lee, his February 4, 2020 false statement to Fed investigators, the February 3, 2026 jury verdict, the 38-month sentence against a 60-month prosecution request, the 12-month supervised release term, and the $1.5 trillion Chinese Treasury-holdings detail. Archive.org's Save Page Now returned a 520 error on capture attempt (2026-07-16); no Wayback snapshot exists yet, so this citation carries no one-click capture -- reachable directly at the url above. justice.gov
  • Bloomberg Law, Ex-Fed Adviser Found Not Guilty of Stealing Data for China (2026-02-04)Reports the split verdict 's own sentencing release does not restate: the same jury that convicted Rogers of false statements acquitted him of the more serious charge of conspiracy to commit economic espionage. Also gives his January 2025 arrest date. Archive.org's Save Page Now returned a 429 (rate-limited) on capture attempt (2026-07-16); no Wayback snapshot exists yet, so this citation carries no one-click capture -- reachable directly at the url above. news.bloomberglaw.com
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account