“GET THIS USELESS GIRL OUT!” the new CEO screamed, throwing my security badge into the garbage while his three advisers burst into laughter. I stood perfectly still in the conference room. “Are you officially terminating my employment?” I asked. He slammed his fist against the table. “YES! EFFECTIVE IMMEDIATELY!” I smiled, picked up my purse, and walked away. Within forty minutes, his company’s largest government contract was suspended.
My name is Rachel Morgan. I’m thirty-eight years old, and for eleven years, I worked at Westbridge Technologies, a cybersecurity company headquartered in Virginia. My official title was Director of Regulatory Compliance. Most executives considered my department boring, but our government contracts depended on the security certifications my team maintained.
Three weeks earlier, our founder, Thomas Bennett, had retired after selling his controlling interest to a private investment group. His replacement was thirty-two-year-old Derek Lawson, a wealthy investor’s son who had never managed a cybersecurity company. He arrived with expensive suits, arrogant advisers, and a promise to eliminate unnecessary expenses.
During his first week, Derek dismissed two senior engineers and replaced our experienced finance director with his college roommate. Then he demanded that every department justify its existence. When my turn came, I presented the company’s forty-seven active security authorizations and explained their reporting requirements.
Derek barely glanced at my presentation. “So you basically fill out government paperwork?” he asked. His advisers chuckled. I explained that my department monitored mandatory controls, coordinated audits, and maintained the approvals required for our federal contracts. Without those authorizations, Westbridge could lose eligibility to perform certain projects.
He interrupted me. “I pay lawyers millions. Why would I need you?” I explained that outside counsel handled legal advice, while our internal compliance personnel performed operational responsibilities. Derek leaned back, smirking. “Sounds like you’re protecting your paycheck.”
The following morning, I received an invitation to an emergency executive meeting. When I entered, Derek was sitting beside three advisers. He demanded my resignation, accusing me of wasting company resources. I refused because my employment agreement required written notice and specific procedures for termination.
That’s when he exploded, grabbed my badge, and threw it into the garbage. After confirming that he was firing me, I asked whether he intended to appoint someone qualified to assume my designated compliance responsibilities. “Absolutely not,” he snapped. “We’re eliminating your entire department.”
I requested written confirmation. His chief of staff emailed it before I reached the elevator. I forwarded the message to my personal attorney, then sent a factual departure notice through the company’s approved compliance channel, identifying the vacant responsible-official position and outstanding reporting obligations.
Forty minutes later, the contracting officer responsible for our largest federal project issued an immediate stop-work instruction pending clarification of our compliance status. Derek called me twelve times. I answered the thirteenth call. He shouted, “WHAT DID YOU DO?” I replied, “Exactly what your company procedures required. Now you need to explain why you eliminated the people responsible for keeping your contracts compliant.”
Derek’s voice shook with anger. “You sabotaged my company!” I was standing outside the building, waiting for my attorney to return my call. “I didn’t sabotage anything,” I replied. “Your decision created a reportable compliance change. I documented it accurately. The contracting officer decided what action was necessary.” Derek threatened to sue me personally before hanging up.
My attorney, Rebecca Collins, called twenty minutes later. She had reviewed my employment agreement, the termination email, and the compliance reporting procedures. “Rachel, do not communicate with Derek again without counsel,” she instructed. “His company has serious problems, but we need to make sure every action you took was authorized and properly documented.”
The situation was worse than Derek understood. Westbridge’s largest federal contract required continuous compliance with specific cybersecurity controls, qualified oversight, and prompt notification of material changes. My departure alone did not automatically invalidate our authorizations. However, eliminating the entire compliance department while leaving unresolved audit findings created substantial concerns.
Two days before my termination, I had warned Derek about seventeen outstanding corrective actions identified during an internal review. Three involved subcontractor access to sensitive government information. Derek had ordered me to postpone the remediation work until the next quarter because he wanted stronger financial results before an investor presentation.
I had refused to falsify our compliance status. Instead, I documented the unresolved issues in the internal tracking system and escalated them to the board’s audit committee. Derek apparently believed firing me would make those problems disappear. He hadn’t realized that the audit committee already possessed my reports.
By Monday morning, the consequences were spreading. The contracting officer requested documentation demonstrating that Westbridge could still satisfy its contractual security requirements. Two additional federal customers initiated reviews. A major subcontractor suspended certain data exchanges until Westbridge identified an authorized security contact.
Then Derek’s general counsel discovered another problem. My employment agreement contained a change-of-control provision negotiated years earlier, when I had been recruited to manage the company’s federal compliance program. Because Derek had terminated me without cause within twelve months of the acquisition, I was entitled to eighteen months of salary and benefits.
The agreement also required reimbursement of reasonable legal expenses incurred to enforce its terms. My annual compensation was $218,000. The severance obligation alone exceeded $327,000 before benefits and any disputed additional payments. Derek’s lawyers had reviewed the acquisition documents, but apparently nobody had explained my individual employment protections to him.
On Tuesday afternoon, Rebecca received a settlement proposal offering me $40,000 in exchange for releasing all claims and signing a broad confidentiality agreement. She rejected it. The proposal also demanded that I withdraw my compliance report, something I could not properly do because the reported facts remained accurate.
That evening, Thomas Bennett, the retired founder, called me. He sounded exhausted. “Rachel, the board has finally reviewed your warnings,” he said. “Derek told them everything was under control.” Then he revealed something unexpected. An independent director had requested an emergency board meeting, and Derek was being ordered to explain why he had dismissed the company’s designated compliance officer while critical security issues remained unresolved.
The emergency board meeting began Thursday morning. I wasn’t invited, but my attorney had provided the audit committee with copies of my earlier warnings, the termination confirmation, and the relevant contractual provisions. Derek entered expecting the directors to defend him. Instead, they questioned him for nearly three hours about his decisions and the inaccurate assurances he had given investors.
According to the formal findings later shared with my attorney, Derek claimed I had refused to cooperate with management. The directors asked him to produce evidence. He couldn’t. My emails showed that I had repeatedly requested funding, additional technical support, and written authorization to address the outstanding security problems.
One director asked why Derek had eliminated the compliance department without appointing replacements. Derek reportedly answered, “Our lawyers were supposed to handle that.” The company’s general counsel explained that legal advice could not replace technical security monitoring, audit remediation, or the operational responsibilities assigned to qualified employees.
Meanwhile, the government contracting officer extended the stop-work instruction until Westbridge demonstrated adequate controls. The company wasn’t automatically disqualified from every contract, but the disruption was expensive. Employees assigned to the suspended project faced reassignment, and several customers demanded independent assessments before approving further work.
On Friday, the board placed Derek on administrative leave pending an external investigation. His three advisers were removed from compliance-related decision-making. An experienced interim CEO was appointed, and the company hired an independent cybersecurity firm to evaluate its outstanding obligations and develop a corrective-action plan.
Derek reacted by sending me an angry email accusing me of destroying his career. Rebecca instructed me not to respond. She forwarded the message to his attorneys and reminded them that their client had personally confirmed my termination in front of witnesses. His threats could not erase the company’s contractual obligations.
Three weeks later, Westbridge offered a settlement consistent with my employment agreement, including the required severance, continued benefits, and reimbursement of approved legal expenses. After reviewing the terms with Rebecca, I accepted. The agreement did not restrict truthful cooperation with government authorities or require me to change any compliance findings.
The external investigation eventually concluded that Derek had ignored documented security concerns, misrepresented the readiness of the compliance program, and made significant staffing decisions without understanding their consequences. The board permanently removed him as CEO. His father, despite being a major investor, could not persuade the independent directors to reverse their decision.
Westbridge gradually restored its suspended work after implementing corrective measures and satisfying the contracting officer’s requirements. I declined the interim CEO’s invitation to return. Instead, I accepted a position as Vice President of Security Governance at another Virginia technology company, with a higher salary and authority to build an independent compliance team.
Six months later, I attended an industry conference in Washington, D.C. Someone mentioned that Derek had quietly left the technology sector. I didn’t celebrate his downfall. I remembered the moment he threw my badge into the garbage and laughed with his advisers. He thought he was removing a useless employee. What he actually removed was the person who had spent eleven years warning his company about risks he refused to understand.



