Skip to content
BriefingsRSS · DSI
Series · Part 23 of 62
The Chokepoint Doctrine
You Did Not Fire Your Developer. You Created Your Adversary.
Insider ThreatJune 1, 202616 min read

You Did Not Fire Your Developer. You Created Your Adversary.

Atlassian terminated sixteen hundred employees on the eleventh of March 2026. Six weeks later an eight-year veteran of the edge infrastructure team uploaded a thirty-eight-minute YouTube video walking through the company's entire production architecture. Some viewers called it the best free system design lesson on the platform. They were also describing, in different words, a complete operational security disclosure for any actor that wanted to attack the company. The AI replacement doctrine has produced the largest involuntary supply of high-context insider threats in the history of the industry, and the demographic concentration is in the cohort that holds the most institutional memory. The DSI reading of what comes next.

~26 min

The AI replacement doctrine has produced the largest involuntary supply of high-context insider threats in the history of the industry. The DSI reading of what comes next.

An Eight-Year Edge Infrastructure Engineer Sat Down and Hit Record

On the eleventh of March 2026, Atlassian terminated one thousand six hundred employees. Ten percent of the global workforce. More than nine hundred of the eliminated roles were in software research and development. The chief executive, Mike Cannon-Brookes, notified affected staff via a four-minute pre-recorded video and a blog post. Termination emails arrived approximately twenty minutes after the video went live. Affected employees were given six to twelve hours of Slack access to say goodbye to colleagues before authentication was revoked. The stated reason was self-funding further investment in AI and enterprise sales. The company added that AI was not directly replacing its people, while also noting that it would be disingenuous to pretend AI did not change the mix of skills required.

Six weeks later, Vasilios Syrakis, an eight-year veteran of Atlassian’s edge infrastructure team, uploaded a thirty-eight-minute video to YouTube. In it he walked through Atlassian’s production architecture: the systems responsible for routing internet traffic, provisioning infrastructure, managing proxies, handling authentication, and scaling services across thousands of deployments. The technical depth was the depth of someone who had built and operated those systems for nearly a decade. Some viewers framed the video as one of the best free practical system design lessons on YouTube. They were correct on the framing. They were also describing, in different words, a complete operational security disclosure package for any actor that wanted to attack Atlassian. The framing was both. The discomfort is admitting both.

Syrakis did not sell the knowledge. He did not auction credentials. He did not approach a competitor. He recorded a video that any of those actors could now watch for free. He restrained himself in every dimension where the law restricts ex-employees, and was free in the one dimension where the law does not: he explained how the system works. The next engineer in the same position will not necessarily be that restrained, and the reason the next engineer will not be is the subject of this analysis.

The Doctrine That Built the Threat

The Chokepoint Doctrine series opened the same week with the GISI piece on the Gulf coalition breaking at one hundred and thirty-eight dollars a barrel. The ARIA piece on the AI replacement doctrine followed, mapping three simultaneous failure modes: the token cost spiral, the permission architecture gap, and the workforce reversal that the Careerminds data shows is already underway. The DSI piece you are reading now names the specific operational consequence of the workforce failure mode that the ARIA piece treated at the governance level.

The numbers are not subtle. In the United States alone, fifty-five thousand AI-attributed layoffs were announced in 2025. The first four months of 2026 added forty-nine thousand more, with eighty-thousand-plus AI-attributed layoffs across the global tracker in the first half of 2026. Atlassian’s sixteen hundred is one entry in a list that includes Block, Freshworks, Microsoft Experiences and Devices, and approximately three hundred and fifty-four other named employers. Layoffs.fyi aggregates the public events. GitGuardian’s State of Secrets Sprawl reported twenty-eight million six hundred and forty-nine thousand twenty-four new secrets exposed in public GitHub commits across 2025 alone, a thirty-four percent year-on-year increase and the largest annual jump in the report’s history. The credential supply curve is rising in lockstep with the layoff supply curve. The two curves are connected by the offboarding process that hurried termination produces.

Supply and demand curves of the insider threat market: AI-attributed layoffs as supply, Initial Access Broker pricing as demand, intersection at the offboarding email
The supply curve of high-context insider threats is the cumulative AI-attributed layoff count. The demand curve is the Initial Access Broker market and the nation-state recruitment surface. The two curves intersect at the offboarding email. Most organisations have not yet noticed that this market clears every Tuesday.

The Age Curve Nobody Is Naming

The 2025 layoff wave concentrated demographically in a way that materially changes the threat analysis. Court filings from the Nicholas Franchet age-discrimination lawsuit against Meta document that in the February 2025 layoff round, employees over fifty were two and a half times more likely to lose their jobs than employees under forty. Employees over forty were one and a half times more likely. The Equal Employment Opportunity Commission’s tracking data shows the share of United States high-tech workers over forty contracted from fifty-six percent to fifty-two percent between 2014 and 2022, and contemporary reporting suggests the contraction accelerated through 2025 and 2026 under AI cover. IBM, Google, HP, Broadcom, and now Meta have all faced age-discrimination filings tied to layoff rounds. Atlassian has not yet been named in such a filing, but the demographic pattern of the March 2026 cut is consistent with the pattern documented at peer employers.

The age concentration is not a separate moral story from the security story. It is the security story, told through the demographic that makes it most acute. The fifty-five-year-old principal engineer carries two and a half decades of architectural memory that the company spent two and a half decades manufacturing. She knows which load balancer rule was added in 2009 to work around a vendor bug that was never patched. She knows which service-account password was rotated last in 2017 because the engineer who held the rotation runbook left the company and the runbook was never updated. She knows which API endpoint still accepts unauthenticated requests because the deprecation timeline was pushed three times and then forgotten. She knows where the secrets she warned the security team about are buried. She wrote the post-mortem that nobody read. She watched the next post-mortem repeat it.

Bar chart comparing layoff probability by age cohort, drawn from the Meta v. Franchet court filings showing 2.5x probability for over-50 employees and 1.5x for over-40
Layoff probability by age cohort. Drawn from the Franchet v. Meta filings on the February 2025 Meta layoff round. The two-and-a-half-times multiplier on the over-fifty cohort is the demographic concentration of institutional memory loss, and it is also the demographic concentration of the insider threat the doctrine manufactures.

When the company terminates her, her contribution to the company’s defensive posture leaves with her. So does her contribution to the company’s offensive surface, which is the same contribution viewed from the other side of the perimeter. The discipline of security engineering is the discipline of knowing which doors exist, who holds the keys, when the keys were last rotated, and which keys are forgotten and still work. The fifty-five-year-old principal engineer is the person who knows this. She is also the person being terminated at two and a half times the rate of the twenty-eight-year-old who took her stand-up slot. The institutional memory loss is not metaphorical. It is the actual contents of the actual incident response runbook that the new engineer will read for the first time when the actual incident occurs.

Three Categories of Detection Blindness

The security architecture of most enterprises is not configured to detect the threat categories the AI replacement doctrine has manufactured. Three categories matter most.

DSI Advisory

Need intelligence like this on a decision you're facing?

DSI Advisory Services helps boards, business leaders, defence institutions, and security leaders understand threats before they reach the horizon — where cyber, geopolitics, and business risk converge.

Commission a bespoke intelligence productExplore advisory