I don't have to explain how dangerous this data is in the right hands; so protecting it should be a GDA's day to day and they could coordinate with whom ever else is about to make a big burse to ICE up that node until is cycles out (say after a week or so). There'd also be ways to put out fake intel this way because it would just be the request, not whether or not it was approved so a savvy corpsec could seed a node with data to frame or deceive evil hackers, but at the risk of annoying the Accounting Dept with frivolous burses.
IC call it 'dynamic oversight initiative' or just hit that corpo jargon button until a good name comes up. The biggest challenge I see is that you'd probably need to recycle the device ID after a hack is discovered, or rotate them regularly like the work keys, otherwise one hack is all it would take to have the data in perpetuity.