Friday, August 28, 2026

9/11 Revisited: The Homeland Security Practitioner...

We are approaching the 9/11 anniversary and the images and memories will be revisited.


Many of us will shed a tear and millions will recall where they were and what they were doing, on that unforgettable Tuesday morning in September, 2001. 


The education of "Homeland Security" is taking place on a daily basis in the popular press and on the new social media platforms that have risen and now dominate the digital content since 9/11.


The academic and government institutions have strived for improving the standards, processes, rule sets and protocols for anti-terrorism policy. By education, we also need to explore what we are doing to collaborate at the academic institution level on a global basis, not just on a government basis. 


The "Homeland Security" curriculum at universities in the EU and the United States will soon be converging on several fronts and for good reason. The generation that will be starting their 1st year (freshmen) in college were not even born yet in 2001.


Their perception of what Homeland Security is today and the future for a life long career must be designed on a global basis, because this remains a global issue. 


The students who pursue an education in languages, political science, international affairs, history and science have just as much a stake in the future of Homeland Security as others. Those who are now getting a degree in emergency management, criminal justice or risk management, or information security are well on their way, yet still may lack the knowledge and tools their liberal arts colleagues have learned to be better analysts, intel targeters or linguists. 


A flash back to this article on "Homeland Security Intelligence" (HSI) , reminds us that regardless of the university education one receives, the future of effective strategies across the world will stem from intelligence: 


(27 February 2011 HSI: Homeland Security Intelligence…)

“What is the modern definition of U.S. Homeland Security Intelligence (HSI)? Many would differ on the jurisdiction, sources and nexus with specific intelligence that falls outside U.S. borders. The future of sharing relevant pieces of the vast mosaic of information may well lie with the definition and the interpretation of Homeland Security Intelligence.

One thing is certain about this topic of debate. If the information is being utilized to determine the nature of a threat within the confines of the U.S. Homeland, then that information will be treated according to the laws of the United States. This brings us to the next question. Are the current laws an impediment to more effective Homeland Security Intelligence (HSI) processes, methods and outcomes? The following areas must be addressed in order to get closer to the truth. 

  • Governance
  • Policies
  • Regulatory and Statutory Concerns
  • Civil rights and Liberties

Yet the question begs the discussion on the structure and the purpose of the Intelligence Community (IC) itself.”

Whether the homeland security incident is a natural catastrophe or a man-made threat, there are several components that all people pursuing a profession in the discipline should be developing with increased competency, including risk mitigation, legal framework, ethics, communication/collaboration, alternative analysis, supply chain, critical infrastructure, emergency/crisis management and terrorism. 


Those kids who were not even born yet on 9/11, may have a different perspective on what might be important these days in order to detect another attack of the same magnitude during these times of heightened digital and mobile awareness.


They grew up with the Internet and they don't need a class in Social Media 101 or how to use TikTok. They might however, also need some training in AI or the Deep Web, if they want to support the HSI infrastructure, or understand the adversaries modus operandi. 


The definitions of Homeland Security Intelligence (HSI) and what comprises the spectrum of relevant and legally obtained information may differ from country-to-country and state-to-state.


Is it legal to perform digital triage on an iPhone that has been part of a lawful search and seizure in the State of Ohio, USA? 


The education for Homeland Security professionals beginning with the university must take into consideration the requirements that exist for collecting, analyzing and sharing relevant and legally obtained information. The next step is to determine the correct skills that must be developed, before the newly minted student is filling out their first job applications or interviewing for their first internship. 


As we reflect on the 9/11 25 year milestone, we can all admit the journey has not been easy. It is still far from over.


Let the next decade produce our next generation of Homeland Security professionals who may decide that Social Media and Internet AI expertise is just as vital to the curriculum as Privacy and Civil Liberties.


Watch this area to converge dramatically over the course of the next few years and for the Supreme Court in the United States to make some landmark decisions…

Saturday, August 22, 2026

Innovation: Truth in Data Provenance...

For years mathematicians and computer scientists have written about the trustworthiness of “Data Provenance”.


Relying on the integrity of data collection, transport and of course the source of data is a real science.  Our modern day zeros and ones span all aspects of our lives and Operational Risk Management (ORM) professionals have encountered the questions surrounding trust and the process of decision making long before the invention of computing machines.


At the root of decision making with integrity the source of data is questioned.  The reliability and history of previous data from the source.  As the data was transported from Point A to Point B was there any possibility that the data was altered, modified or corrupted.


Couriers and the use of a "Hawala" type system have been used by traders and terrorists for hundreds of years.


"Truth in Data Provenance" is the question mark that enables trust decisions.  This is why modern day cryptography is at the center of so many arguments and debates, when it comes to the topic of trusted information.  Yet hundreds of years ago, long before telecom and ICT was invented, the trustworthiness of data provenance was a vital factor.  The use of transposition ciphers were in use by the ancient Greeks.


So what?  In 2026 what does the truth in data provenance have to do with our business commerce, our transportation, our banking, even our abilities as governments to maintain our defense against attack?


The topic is vast and deep and worth exploration at the top level of human decision-making.  Yes, it is vital that our computing machines have high-assurance data integrity, in order for our global systems to operate day-to-day.


Yet what impact does trusted information have with humans in an environment of work and daily collaboration?  How does truth in data provenance, affect our decision making and the environments we work in?


In a report by LRN, the subject of trust in the work environment as a motivator has become more apparent:


Another fascinating result of the study had to do with two squishy-sounding characteristics of a company: character and trust. Companies deemed by employees to have both strong character and inspired trust performed almost four times better, using the metrics mentioned earlier, than those that had other positive cultural attributes, such as collaboration and celebrating others. (This applied to all three types of companies, though, naturally, culture and trust were much more prevalent in the self-governing ones) What’s more, “high trust” organizations were 11 times as likely to be called more innovative than their competitors. Trust, the How Report suggests, is more important than virtually any other characteristic.

How organizations address the trustworthiness of data provenance is still a new frontier in this day and age.  The use of new sensors, sophisticated analysis of "Big Data" by computer algorithms (AI) and the pace at which new data is generated by the "Internet of Things" (IOT) makes this a significant area of focus for our current executives and enlightened organizational leadership.


Why?


But what does that really mean? How does one measure the absence or presence of something as abstract as trust? The How survey defines it as “a catalyst that enhances performance, binds people together, and shapes the way people relate to each other.” High trust groups encourage risk-taking, which in turn is what is necessary for true innovation to occur. When innovation fails, it’s because companies don’t put enough faith in employees to let them take risks. The industries with the highest amount of trust were “computers/electronics,” followed by “software/Internet.” Coming in last? Government.

At the most fundamental level, the culture you are operating in has all to do with the trust that exists or is absent.


It has all to do with the trustworthiness of data provenance.  Leadership in any organization, must see the relevance between trust and innovation.  Between innovation and risk-taking. 


Your future and your culture depends on it...

Saturday, August 15, 2026

Virtual Truth: False Information Risk...

How does "False Information" impact the risk to your organization? 


Decisions based upon faulty or inaccurate information is the root of many of the systemic failures of catastrophic history. The Titanic, Challenger Shuttle and Three Mile Island nuclear incident can all be attributed to the integrity of vital information.


Fast forward to the financial crisis and the past decades of consumer credit expansion strategies. What data have you been collecting from US consumers or clients about their personal identifiable information attributes?


The Information Age has drawn us into a more dangerous business operating environment as these digital assets have become another commodity to be sold in an international market place, to the highest bidder. Are you ready when the federal "Suits" or the local LEO's (Law Enforcement Officer) knock on your door in pursuit of the truth:


The Fair Credit Reporting Act (FCRA) spells out rights for victims of identity theft, as well as responsibilities for businesses. Identity theft victims are entitled to ask businesses for a copy of transaction records — such as applications for credit — relating to the theft of their identity. Indeed, victims can authorize law enforcement officers to get the records or ask that the business send a copy of the records directly to a law enforcement officer. The businesses covered by the law must provide copies of these records, free of charge, within 30 days of receiving the request for them in writing. This means that the law enforcement officials who ask for these records in writing may get them from your business without a subpoena, as long as they have the victim’s authorization.

The financial integrity of your future as a business and as a consumer is at stake. Christopher Burns brings this to light in a dramatic fashion in his book; Deadly Decisions:



"First, it is often extremely difficult to validate, corroborate, or verify the information we are dealing with, except by comparing it to the other information we are dealing with. And often the whole system is contaminated by misunderstanding, bad data and false assumptions that are hard to spot. The truth test rarely works. And second, the real issue of truth is not whether you or I should believe this or that, it is what we believe together. The truth that matters is group truth, and where we get into trouble is when a whole organization--a company, a community, a nation--starts to act on information that has been gathered from many sources and processed by many people but has come to contain significant elements that are false.”


Trusted Information is at the core of current global trading, business transactions and the fabric of our own personal identities. False information and knowledge is what creates operational risk factors that can change a whole company or the integrity of a whole nation.

Systems that comprise vast databases of "so called" trusted information are at our fingertips being utilized to make coherent and effective decisions. Yet what may be the more catastrophic Operational Risk beyond the simple stealing of information is the potential opportunity for the destruction of vital information.

The vulnerability of our institutions and the critical infrastructure of the United States economy is ever more at risk of a systemic loss. While our stolen data will continue to be sold to the highest bidder on a global platform for trading, the 4GW "Non-State" actors will change their modus operandi. This is a given.

Trusted Information systems that have certified integrity and the oversight controls to ensure the highest level of virtual truth is the "Holy Grail.”

The degree to which these same systems include false knowledge is our most complex problem for business and government in the next decade…

Friday, August 07, 2026

Reputation Risk: Organizational Stewardship Revisited...

Reputation risk is becoming more of a topic of discussion these days. The loss of reputation results in several outcomes both economic and personal. The fact is that most of the time organizations are "Reacting" to a crisis, news leak or some other corporate failure.

You don't have to name names of people or companies to understand the impact that reputation has on the success or demise of an organization. What has to change to lower the severity and likelihood of loss events associated with "Reputation"?

First you have to ask yourself a couple of key questions:

  1. What is your reputation worth?
  2. Are you being Proactive or Reactive in managing and safeguarding your reputation?

The PR and marketing communications processes in your organization may have certain facets of the solution to better reputation risk management. However, these processes are designed with out the consciousness of proactive threat anticipation, detection, prevention and remediation.

What has become more clear to executives in proactive oriented companies is the requirement for a specific and strategic approach to Reputation Risk Management. This approach encompasses an emerging theme from the early nineties pioneered by author Peter Block. We call it Organizational Stewardship.

Organizational Stewardship as a core guiding principle is the cornerstone in managing an institutional reputation risk management process. It has three components that support this rekindled idea of applying the concepts of stewardship to the organization:

  • Economic Accountability
  • Information Management
  • Business Integrity

Reputation Risk Management is about the proactive monitoring and management of a portfolio of threats in the organization. Several categories include:

  1. Intellectual Property and Information Assets
  2. Demonstrations, planned boycotts and social activism
  3. Physical infrastructure including employees and suppliers
  4. Legal threats including class actions, insider trading or whistle-blowers

Microsoft closed its free Internet chat rooms in 28 countries many years ago because of threats from pedophiles and junk e-mailers. This is an example of proactive reputation risk management. Unfortunately, this has opened the door to another related threat of hackers hijacking other Social Media accounts.
"Organizational Stewardship is a guiding principle. Once it is embedded into the organization it begins to permeate the mindsets of the individuals who are responsible for the conscious reputation risk management processes. Over time, these individuals help influence the corporate mindset, philosophy and ethics to a new found level."
Someday soon the executives in the board room will realize that managing reputation is not about keeping secrets and fighting fires. 

They will realize that they need to find a proactive, preventive and relevant strategy for achieving Organizational Stewardship in their company.

Sunday, July 26, 2026

Trust Decisions: Future Risk Architecture...

Leadership within the enterprise requires "Trust Decisions" that they can count on.  Operational Risk Officers have a fiduciary duty to provide top executives with the confidence that the data and information they provide is trusted.

So how do you assist any corporate leader, who has the responsibility and accountability to the Board of Directors to make informed and sound decisions?  The answer is, that it depends on how willing the CxO's in the enterprise are to engineer a "Trust Decision" model and framework for the business.

The truth is, most executive managers have their own way of doing this.  The process that the CEO makes decisions, is quite different from how the CFO makes decisions and the COO may have a documented and tested way to make their decisions.  The point is, that major "Trust Decisions" for the good and welfare of the enterprise are being made by people who are each doing it differently.  These human decision makers are relying on a number of ways to get to the final answer.  The decisions from leadership are not as trusted and reliable as they could be.

As an Operational Risk executive charged with making timely and correct decisions you have no choice but to have the tools and the trusted sources to enhance your situational awareness.  The safety and security of the facility, information or peoples lives are at stake.  That is why you test and continually improve the process so your analytics dashboard, intelligence feeds and data sensors are all operating with integrity and in real-time.

You are relying on information that changes by the nanosecond and a system designed to provide decision support.  Intelligence-led investigations or reacting to the latest incident requires systems designed and tested to support human "Trust Decisions."  Now back to the executive leadership and their process for decision-making.  What is it?  How does the CEO make the final decisions for the future wealth of the company and it's stakeholders?  Are they trustworthy?

Unless you have seen the "Trust Decision" process and trusted data framework engineered for your enterprise, then probably not.  Think about all of the leadership level projects and how they turned out.  How did executive leadership decide to buy that other company or merge with their favorite supplier?  What process did they use to ensure all of the due diligence data was correct?  Why are the sources of data trusted?

We have the opportunity to improve and to arrive at a point where we make "Trust Decisions" our priority and a prerequisite.  After all, our employees, customers, shareholders and even mankind deserve it.  The challenge begins.

Whenever you encounter your next major business decision with your CxO, ask them how they arrived at the decision.  Ask them to explain the process they used and the sources of trusted data they relied on.  Ask them why they think the architecture of the decision at hand, is the most sound and trusted decision that can be made with the time available.

You are now well on your way to better understanding the power and the future risk architecture of TrustDecisions.

Saturday, July 18, 2026

Asymmetric Warfare: Board Room to Battlefield...

The planet Earth is experiencing a multitude of historical and 21st century "Asymmetric Wars" from the Board Rooms of the Global 500, Internet Cafes of Third World countries and the Miranshah.

Operational Risk Management (ORM) doctrine will continue to be a factor:

a·sym·met·ric

  [ey-suh-me-trik, as-uh-]  Show IPA
adjective
1.
not identical on both sides of a central line;
"Asymmetric warfare" can describe a conflict in which the resources of two belligerents differ in essence and in the struggle, interact and attempt to exploit each other's characteristic weaknesses. Such struggles often involve strategies and tactics of unconventional warfare, the "weaker" combatants attempting to use strategy to offset deficiencies in quantity or quality.[1] Such strategies may not necessarily be militarized.[2] This is in contrast to symmetric warfare, where two powers have similar military power and resources and rely on tactics that are similar overall, differing only in details and execution.
The Irish Republican Army (IRA) perfected the car bomb against the British.  Now "Improvised Explosive Devices" (IED) and suicide bombers continue to be the single greatest threat to U.S. troops in Afghanistan as we withdrew and in Iraq as we engage once again. The Middle East has been embroiled in conflicts with the modern use of "Social Media" and an asymmetric rebel element to initiate change in labor laws or to overthrow a nation states leadership.

A laymen may not understand the relevance of "Asymmetric Warfare" on the corporate battlefield. Some would describe the age old tactic of industrial espionage, competitive intelligence or even patent litigation as a method for a small unknown company to gain an advantage over a much larger and established institution. This is a strategy of Asymmetric Warfare, nothing new.

In any case, the perception is that the small and agile still have the means, tools and tactics to defeat the large and overbearing with the benefit of time, resources and the will of the people.

So what are some good examples of modern day asymmetric conflicts:
  • Apple vs. Google
  • NATO vs. Putin
  • Sunni vs. Shiite
  • BMW vs. Jaguar
  • Earth vs. Anonymous
  • Taliban vs. Afghans
  • United States vs. Jones
Each of these represent a conflict between two able parties, regardless of the perception of who is the "David" and who is the "Goliath". So what can your organization or nations state do to prepare yourself for the inevitable risks that will be associated with doing business or operating your enterprise across countries and in hostile environments?

By providing your employees and stakeholders the best education, research, training and exercise programs; technology test and evaluation and capability improvement programs that your resources can offer.  Why?  In a few words, to make faster and more informed "Trust Decisions".

The desire to Deter, Detect, Defend and Document is prudent doctrine in Operational Risk Management (ORM). You may call these steps or tactics by other names in your particular process; such as Observe, Orient, Decide Act (OODA). What matters most is that the environment and landscape for the "Asymmetric Threats" and "Asymmetric Warfare" will continue to be challenging and dynamic.
BY ASSOCIATED PRESS June 16 2014
WASHINGTON — Judges around the country are grappling with the ripple effects of a 2-year-old Supreme Court ruling on GPS tracking, reaching conflicting conclusions on the case’s broader meaning and tackling unresolved questions that flare in a world where privacy and technology increasingly collide. 
The January 2012 opinion in United States v. Jones set constitutional boundaries for law enforcement’s use of GPS devices to track the whereabouts of criminal suspects. But the different legal rationales offered by the justices have left a muddled legal landscape for police and lower-court judges, who have struggled in the last two years with how and when to apply the decision — especially at a time when new technologies are developed at a faster rate than judicial opinions are issued. 
The result is that courts in different jurisdictions have reached different conclusions on similar issues, providing little uniformity for law enforcement and judges on core constitutional questions. Technological advancements are forcing the issue more and more, a development magnified by a heightened national debate over privacy versus surveillance and the disclosure of the National Security Agency’s bulk collection of Americans’ telephone records.

Saturday, July 11, 2026

Continuous Continuity (C2): Organizational Survivability...

The modern enterprise that effectively manages the myriad of potential threats to its people, processes, systems and critical infrastructures stands to be better equipped for sustained continuity. A Business Crisis and Continuity Management (BCCM) program is a dynamic change management initiative that requires dedicated resources, funding and auditing. Corporate Directors must scrutinize organizational survivability on a global basis. 

Corporate Directors are ultimately responsible for Continuous Continuity (C2) of the Enterprise and Organizational Survivability is a Board Room issue. 

Since effective BCCM analysis is a 24/7 operation, it takes a combination of factors across the organization to provide what one might call C2, or "Continuous Continuity". A one-time threat or risk assessment or even an annual look at what has changed across the enterprise is opening the door for a Board of Directors worst nightmare. These nightmares are "Loss Events" that could have been prevented or mitigated all together.

According to the risk management best practices from sources such as the Turnbull Report1 and specifically Principle 13 of the Basel II Capital Accord, the Board of Directors and corporate management are responsible for the effectiveness of the Business Crisis and Continuity Management of an organization.

Certainly the largest organizations realize that the external threats are taking on new and different forms than the standard fire, flood, earthquake and twister scenarios. These historically large catastrophic external loss events have been insured against and the premiums are substantial. 

What it is less easy to analyze from a threat perspective are the constantly changing landscapes and continuity postures of the internal facets of the organization having to do with people, processes and systems. 

Corporate Boards of Director’s are now being consistently subjected to regulatory scrutiny across the globe to ensure the continuity and survivability of the enterprise. It is their duty and responsibility to their shareholders to make sure this occurs on a continuous basis.

The world can only hope that our Global 500 companies are well on their way to achieving C2 already...

Friday, July 03, 2026

USA 250: Trusted Decisions…

 Over the course of the past week navigating new neighborhoods in Virginia and old hiking trails near Great Falls on the Potomac River, the thoughts of 250 years as the United States of America (USA) was evident.

When you are watching the grand display of Fire Works on July 4th…what do you think about?


Our country remains increasingly resilient and our continuous mission remains so relevant.


We have supported the foundation of our “Founding Fathers” hopes and prayers for the past (250 x 365) 91,250 days.


Each day the sun rises across our 50 states of America, we know we have made the rest of the world curious about our history.


When you are old enough, you must read about our history.  You must have the true context of our days before the document was created and agreed upon.


The “Declaration Of Independence” has been studied for 250 years.  It remains our mission forever.


Watching the flowing water of the Potomac River in Great Falls, VA and thinking about all that has been created, discovered and protected as a result of one document, is simply faithful.


You and your life here, is all up to you.


The decisions you make everyday in the USA will provide you with all that you were destined to become here.


Looking back on your particular journey so far, have your life “Trusted Decisions”provided you with all that you have ever dreamed of…


Why?


On July 5th, as you enter your own particular place of Worship somewhere across your town in the United States of America, look up…


Godspeed!

Friday, June 19, 2026

Proactive: Acting in Participation...

How have you demonstrated your “Proactive” abilities this month?

Before you found your calling, were you spending wasted hours on social media or sitting places all alone.

After you became “Proactive,” the life changes were extraordinary and purposeful.

So what is the definition of PROACTIVE: “Acting in anticipation of future problems, needs, or changes.”

Whether you have joined other fellow colleagues with your Non-Profit (501c3) volunteer organization placing or picking-up hundreds of American Flags on the head stones of the “Fallen” after Memorial Day USA.

  • Whether you have volunteered your days of time to help the Safety / Security presence at a Religious or Educational organization during an important service or meeting.
  • Whether you engaged with others to attend a “Stop The Bleed” course to learn how to save other's lives.
  • Whether you burned hours of your time for your Team on creating and planning an upcoming annual event for a thousand members.

How many Proactive hours of your time and expertise have you given free this month?

Being “Proactive” gives you the ability to learn new skills, meet new people and to provide valuable services to your community.

“People who tend to react to a problem only when it's gotten serious could be called reactive people. Until recently, reactive (in this sense) didn't really have an antonym. So proactive was coined to describe the kind of person who's always looking into the future in order to be prepared for anything.”

You see, this can provide you and your “Proactive Peers” with the heart felt satisfaction that you have a truly valuable purpose.

It provides you with the ability to engage with other like-minded individuals on the actions and the “Doing” that can truly make a difference in this world…

Godspeed!