Showing posts with label Critical Infrastructure. Show all posts
Showing posts with label Critical Infrastructure. Show all posts

Friday, September 11, 2026

Remembering 9/11: 2026-Teaching the Children...

Where were you on the morning of September 11th, 2001? Everyone seems to remember...

On a cool sky blue morning, 25 years ago in Northern Virginia, we are sitting in a Reston Town Center Hyatt hotel restaurant having breakfast around 8:00AM with a business colleague. A little over 40 minutes into our discussion, we heard some people talking quite loud in the bar next to us as they were then watching CNN to see the World Trade Center Twin Towers attack. As cell phones rang around us, they were all loved ones checking in and urging us to hurry home.


Walking to the parking lot, the proximity of our kids elementary school and middle school to the CIA campus created a feeling of great internal anxiety and it soon turned to fear.


Unknown to us at that moment, five terrorists were also onboard American Airlines Flight 77 that had already departed from Dulles (IAD) at 8:20AM headed to Los Angeles (LAX).


Little did we know that the AAL77 hijackers onboard that Boeing 757 flight had slept the night before a half mile from us in a Herndon, VA motel.  30 or so minutes into the flight over Ohio, with the terrorists now in control and the aircraft transponder off, it would make its turn back to Washington, DC to attack the West side of the Pentagon at 9:37AM.


We could now see the smoke rising in the distance on the Eastern horizon.


What this September 11th day is about every year beyond these memories, is the renewed vow of vigilance. A time to revisit all the reasons why you have made the decisions you have since that Tuesday morning twenty-five years ago. Never Forget that day. Never Forget why you wake each morning.


9/11 vigilance is about being adaptive. It is about resilience.


For those of us who have never paid the same price as those who have served, supported and are the mothers, fathers, brothers, sisters or relatives of those who have, we can never know or really feel what they have. We can only pledge our vigilance in continuing our respective missions.


Most of all. The mission is not America's alone and the entire planet understands this. As they teach the history of 9/11 in the schools of New York City, Haiti, Chile, Pakistan, India and even Saudi Arabia, what do you think the lesson is about?


If it is not about vigilance and resilience, then we are doing our children a disservice. We must be preparing them for the future threats that this globe will be facing in the years and decades before us.


Whether it is the wrath of "Mother Nature" or the evil planning of AI or ordinary people does not matter. We can never predict exactly the day the hour or when and where the next attack will occur. Whether it will impact our buildings, bridges, rivers, schools or the Internet is unknown.


If all of us on this 3rd rock from the sun, have done our job teaching our kids about “Vigilance and “Resilience”, then we should all be able to have a peaceful nights sleep. Devoid of nightmares.


Remember that Tuesday in September across the globe, for the lessons we have all learned since that infamous day in New York City, Washington, DC and Shanksville, Pennsylvania.


For the children, teach them the truth…


Friday, August 28, 2026

9/11 Revisited: The Homeland Security Practitioner...

We are approaching the 9/11 anniversary and the images and memories will be revisited.


Many of us will shed a tear and millions will recall where they were and what they were doing, on that unforgettable Tuesday morning in September, 2001. 


The education of "Homeland Security" is taking place on a daily basis in the popular press and on the new social media platforms that have risen and now dominate the digital content since 9/11.


The academic and government institutions have strived for improving the standards, processes, rule sets and protocols for anti-terrorism policy. By education, we also need to explore what we are doing to collaborate at the academic institution level on a global basis, not just on a government basis. 


The "Homeland Security" curriculum at universities in the EU and the United States will soon be converging on several fronts and for good reason. The generation that will be starting their 1st year (freshmen) in college were not even born yet in 2001.


Their perception of what Homeland Security is today and the future for a life long career must be designed on a global basis, because this remains a global issue. 


The students who pursue an education in languages, political science, international affairs, history and science have just as much a stake in the future of Homeland Security as others. Those who are now getting a degree in emergency management, criminal justice or risk management, or information security are well on their way, yet still may lack the knowledge and tools their liberal arts colleagues have learned to be better analysts, intel targeters or linguists. 


A flash back to this article on "Homeland Security Intelligence" (HSI) , reminds us that regardless of the university education one receives, the future of effective strategies across the world will stem from intelligence: 


(27 February 2011 HSI: Homeland Security Intelligence…)

“What is the modern definition of U.S. Homeland Security Intelligence (HSI)? Many would differ on the jurisdiction, sources and nexus with specific intelligence that falls outside U.S. borders. The future of sharing relevant pieces of the vast mosaic of information may well lie with the definition and the interpretation of Homeland Security Intelligence.

One thing is certain about this topic of debate. If the information is being utilized to determine the nature of a threat within the confines of the U.S. Homeland, then that information will be treated according to the laws of the United States. This brings us to the next question. Are the current laws an impediment to more effective Homeland Security Intelligence (HSI) processes, methods and outcomes? The following areas must be addressed in order to get closer to the truth. 

  • Governance
  • Policies
  • Regulatory and Statutory Concerns
  • Civil rights and Liberties

Yet the question begs the discussion on the structure and the purpose of the Intelligence Community (IC) itself.”

Whether the homeland security incident is a natural catastrophe or a man-made threat, there are several components that all people pursuing a profession in the discipline should be developing with increased competency, including risk mitigation, legal framework, ethics, communication/collaboration, alternative analysis, supply chain, critical infrastructure, emergency/crisis management and terrorism. 


Those kids who were not even born yet on 9/11, may have a different perspective on what might be important these days in order to detect another attack of the same magnitude during these times of heightened digital and mobile awareness.


They grew up with the Internet and they don't need a class in Social Media 101 or how to use TikTok. They might however, also need some training in AI or the Deep Web, if they want to support the HSI infrastructure, or understand the adversaries modus operandi. 


The definitions of Homeland Security Intelligence (HSI) and what comprises the spectrum of relevant and legally obtained information may differ from country-to-country and state-to-state.


Is it legal to perform digital triage on an iPhone that has been part of a lawful search and seizure in the State of Ohio, USA? 


The education for Homeland Security professionals beginning with the university must take into consideration the requirements that exist for collecting, analyzing and sharing relevant and legally obtained information. The next step is to determine the correct skills that must be developed, before the newly minted student is filling out their first job applications or interviewing for their first internship. 


As we reflect on the 9/11 25 year milestone, we can all admit the journey has not been easy. It is still far from over.


Let the next decade produce our next generation of Homeland Security professionals who may decide that Social Media and Internet AI expertise is just as vital to the curriculum as Privacy and Civil Liberties.


Watch this area to converge dramatically over the course of the next few years and for the Supreme Court in the United States to make some landmark decisions…

Saturday, August 15, 2026

Virtual Truth: False Information Risk...

How does "False Information" impact the risk to your organization? 


Decisions based upon faulty or inaccurate information is the root of many of the systemic failures of catastrophic history. The Titanic, Challenger Shuttle and Three Mile Island nuclear incident can all be attributed to the integrity of vital information.


Fast forward to the financial crisis and the past decades of consumer credit expansion strategies. What data have you been collecting from US consumers or clients about their personal identifiable information attributes?


The Information Age has drawn us into a more dangerous business operating environment as these digital assets have become another commodity to be sold in an international market place, to the highest bidder. Are you ready when the federal "Suits" or the local LEO's (Law Enforcement Officer) knock on your door in pursuit of the truth:


The Fair Credit Reporting Act (FCRA) spells out rights for victims of identity theft, as well as responsibilities for businesses. Identity theft victims are entitled to ask businesses for a copy of transaction records — such as applications for credit — relating to the theft of their identity. Indeed, victims can authorize law enforcement officers to get the records or ask that the business send a copy of the records directly to a law enforcement officer. The businesses covered by the law must provide copies of these records, free of charge, within 30 days of receiving the request for them in writing. This means that the law enforcement officials who ask for these records in writing may get them from your business without a subpoena, as long as they have the victim’s authorization.

The financial integrity of your future as a business and as a consumer is at stake. Christopher Burns brings this to light in a dramatic fashion in his book; Deadly Decisions:



"First, it is often extremely difficult to validate, corroborate, or verify the information we are dealing with, except by comparing it to the other information we are dealing with. And often the whole system is contaminated by misunderstanding, bad data and false assumptions that are hard to spot. The truth test rarely works. And second, the real issue of truth is not whether you or I should believe this or that, it is what we believe together. The truth that matters is group truth, and where we get into trouble is when a whole organization--a company, a community, a nation--starts to act on information that has been gathered from many sources and processed by many people but has come to contain significant elements that are false.”


Trusted Information is at the core of current global trading, business transactions and the fabric of our own personal identities. False information and knowledge is what creates operational risk factors that can change a whole company or the integrity of a whole nation.

Systems that comprise vast databases of "so called" trusted information are at our fingertips being utilized to make coherent and effective decisions. Yet what may be the more catastrophic Operational Risk beyond the simple stealing of information is the potential opportunity for the destruction of vital information.

The vulnerability of our institutions and the critical infrastructure of the United States economy is ever more at risk of a systemic loss. While our stolen data will continue to be sold to the highest bidder on a global platform for trading, the 4GW "Non-State" actors will change their modus operandi. This is a given.

Trusted Information systems that have certified integrity and the oversight controls to ensure the highest level of virtual truth is the "Holy Grail.”

The degree to which these same systems include false knowledge is our most complex problem for business and government in the next decade…

Saturday, July 11, 2026

Continuous Continuity (C2): Organizational Survivability...

The modern enterprise that effectively manages the myriad of potential threats to its people, processes, systems and critical infrastructures stands to be better equipped for sustained continuity. A Business Crisis and Continuity Management (BCCM) program is a dynamic change management initiative that requires dedicated resources, funding and auditing. Corporate Directors must scrutinize organizational survivability on a global basis. 

Corporate Directors are ultimately responsible for Continuous Continuity (C2) of the Enterprise and Organizational Survivability is a Board Room issue. 

Since effective BCCM analysis is a 24/7 operation, it takes a combination of factors across the organization to provide what one might call C2, or "Continuous Continuity". A one-time threat or risk assessment or even an annual look at what has changed across the enterprise is opening the door for a Board of Directors worst nightmare. These nightmares are "Loss Events" that could have been prevented or mitigated all together.

According to the risk management best practices from sources such as the Turnbull Report1 and specifically Principle 13 of the Basel II Capital Accord, the Board of Directors and corporate management are responsible for the effectiveness of the Business Crisis and Continuity Management of an organization.

Certainly the largest organizations realize that the external threats are taking on new and different forms than the standard fire, flood, earthquake and twister scenarios. These historically large catastrophic external loss events have been insured against and the premiums are substantial. 

What it is less easy to analyze from a threat perspective are the constantly changing landscapes and continuity postures of the internal facets of the organization having to do with people, processes and systems. 

Corporate Boards of Director’s are now being consistently subjected to regulatory scrutiny across the globe to ensure the continuity and survivability of the enterprise. It is their duty and responsibility to their shareholders to make sure this occurs on a continuous basis.

The world can only hope that our Global 500 companies are well on their way to achieving C2 already...

Saturday, May 09, 2026

Business Resilience: Beyond Readiness...

The Continuity-of-Operations-Plan (COOP) for your Communications operations is an operational risk that in many cases is underestimated until a significant business disruption occurs.


When Comms are down, this means a combination of voice and data services that serve your business enterprise may not be available.


The resilience of both the voice and data communications is the holy grail of continuity of operations and disaster recovery professionals on a global basis.


Business Resilience and the ability to effectively anticipate or absorb the impact of an incident, whether man made or as a result of a natural phenomenon differentiates your suppliers.


When is the last time you tested your Tier I service supplier for a mission critical business process to determine the ability to keep their voice and data services running during a time of crisis?


And maybe more important, is your own enterprise “Incident Command” system survivable so that you can provide voice leadership to your "Incident Commanders" where ever they may be located on the globe.


When it comes to planning for the next Hurricane Katrina or the "Tip of the Spear" overseas operations readiness, resilient business organizations need to implement robust planning, immersive exercises and systems to be able to overcome the asymmetric “Operational Risks” that are now before them.


Power blackouts are the catalyst for many risks to the “Critical Infrastructure” including Transportation, Internet, Voice communications and even those services that you take for granted, like pumping gas at the local petrol station or emergency services at the local hospital.


Cyberspace as we know it is so deeply embedded into most of the mission essential aspects of business today that our readiness factor needs to go well beyond redundant power supplies and battery back ups just for power.


Cyber-Readiness is a key component of any organizations plan to stay resilient in the face of a Distributed Denial of Service Attack (DDOS) and other cyberspace exploits that may disrupt our operations.


Do you think you're spending too much time with your team planning and training?


You haven’t.

The organizations whose teams have planned for every possible scenario and trained together in live immersive simulations will become the most successful in their strategy execution.

Their missions will be accomplished on time and within budget.


Incidents of different severity and frequency are happening all around you and your organization every day.


Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?


Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things will go wrong…

Saturday, May 02, 2026

Critical Infrastructure Protection: Resolve to be Ready...

Terrorism Risk includes the risk from attackers both “Internal and External” to our organizations.


These attackers are still using conventional (incendiary explosive devices IED) or Active Shooters and unconventional (Digital Advanced Persistent Threat (APT) methods to disrupt the operations and economic well being of corporate organizations, the real estate finance industry and most of our Critical Infrastructures.


The process and systems for managing Terrorism Risk are rapidly changing as the commercial real estate finance and building owners strive to establish new standards.


Critical Infrastructure Protection (CIP) is now again a national priority. 


The key catalysts for change could further motivate infrastructure owners to implement new risk reduction programs and measures. 


Some of the key catalysts that remain for change are:

·Insurance – those institutions that are sharing risks that a building owner faces.

·Finance – banks, REIT’s (Real Estate Investment Trusts), and others such as pension funds that provide the capital for investments in commercial infrastructure.

·Regulation – Federal, State and Local jurisdictions that regulate building design, construction and operations.

Overall Terrorism Risk reduction begins with these key catalysts in concert with owners of critical infrastructure, whether that is a corporate office building, a hospital, a mall, a school, religious facility, subway, or a hotel.


These soft targets are where the risk management decision-making is again already taking new directions.


In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners and operators.


Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety.


Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen.


Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future.


First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.


The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures.


The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure.


"In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles."


These need to be exercised on a continuous timetable with extensive documentation, training and reporting.


In order for insurance brokers to accurately represent their buyers mitigation programs and measures to the direct insurers they must have a foundation of knowledge about the structures physical vulnerabilities.


However, even more essential is the understanding of the operational and human attributes of the building that are contributing to the proactive tactics to prevent losses and further exposures to potential terrorism risk.


If this step takes place, the insurers can better evaluate these operational and human elements to determine the value and effectiveness of these tactics so that they can be considered for premium reductions.


The building itself, two miles from The White House, 10 Downing Street or the Eiffel Tower, has little chance of moving outside the high-risk zone for terrorist events. 


The only methods for reducing risk exposures are to dramatically impact the operational and human elements of the building to mitigate hazards and increase the survivability of the people and systems that are resident.


As landlords and other interested real estate finance industry partners move towards updated standards to mitigate terrorism risk and protect critical infrastructure, the necessity for state-of-the-art tools and systems to mitigate those risks is paramount.


CxO’s in corporate enterprises are ever more concerned about emergency preparedness and the continuity of their enterprises.


Now that threats to government and business operations are becoming ever more prevalent, organizations must plan for every type of business disruption from hardware and communications failures, to natural disasters, to internal or external acts of terrorism...