Showing posts with label OSINT. Show all posts
Showing posts with label OSINT. Show all posts

Friday, August 28, 2026

9/11 Revisited: The Homeland Security Practitioner...

We are approaching the 9/11 anniversary and the images and memories will be revisited.


Many of us will shed a tear and millions will recall where they were and what they were doing, on that unforgettable Tuesday morning in September, 2001. 


The education of "Homeland Security" is taking place on a daily basis in the popular press and on the new social media platforms that have risen and now dominate the digital content since 9/11.


The academic and government institutions have strived for improving the standards, processes, rule sets and protocols for anti-terrorism policy. By education, we also need to explore what we are doing to collaborate at the academic institution level on a global basis, not just on a government basis. 


The "Homeland Security" curriculum at universities in the EU and the United States will soon be converging on several fronts and for good reason. The generation that will be starting their 1st year (freshmen) in college were not even born yet in 2001.


Their perception of what Homeland Security is today and the future for a life long career must be designed on a global basis, because this remains a global issue. 


The students who pursue an education in languages, political science, international affairs, history and science have just as much a stake in the future of Homeland Security as others. Those who are now getting a degree in emergency management, criminal justice or risk management, or information security are well on their way, yet still may lack the knowledge and tools their liberal arts colleagues have learned to be better analysts, intel targeters or linguists. 


A flash back to this article on "Homeland Security Intelligence" (HSI) , reminds us that regardless of the university education one receives, the future of effective strategies across the world will stem from intelligence: 


(27 February 2011 HSI: Homeland Security Intelligence…)

“What is the modern definition of U.S. Homeland Security Intelligence (HSI)? Many would differ on the jurisdiction, sources and nexus with specific intelligence that falls outside U.S. borders. The future of sharing relevant pieces of the vast mosaic of information may well lie with the definition and the interpretation of Homeland Security Intelligence.

One thing is certain about this topic of debate. If the information is being utilized to determine the nature of a threat within the confines of the U.S. Homeland, then that information will be treated according to the laws of the United States. This brings us to the next question. Are the current laws an impediment to more effective Homeland Security Intelligence (HSI) processes, methods and outcomes? The following areas must be addressed in order to get closer to the truth. 

  • Governance
  • Policies
  • Regulatory and Statutory Concerns
  • Civil rights and Liberties

Yet the question begs the discussion on the structure and the purpose of the Intelligence Community (IC) itself.”

Whether the homeland security incident is a natural catastrophe or a man-made threat, there are several components that all people pursuing a profession in the discipline should be developing with increased competency, including risk mitigation, legal framework, ethics, communication/collaboration, alternative analysis, supply chain, critical infrastructure, emergency/crisis management and terrorism. 


Those kids who were not even born yet on 9/11, may have a different perspective on what might be important these days in order to detect another attack of the same magnitude during these times of heightened digital and mobile awareness.


They grew up with the Internet and they don't need a class in Social Media 101 or how to use TikTok. They might however, also need some training in AI or the Deep Web, if they want to support the HSI infrastructure, or understand the adversaries modus operandi. 


The definitions of Homeland Security Intelligence (HSI) and what comprises the spectrum of relevant and legally obtained information may differ from country-to-country and state-to-state.


Is it legal to perform digital triage on an iPhone that has been part of a lawful search and seizure in the State of Ohio, USA? 


The education for Homeland Security professionals beginning with the university must take into consideration the requirements that exist for collecting, analyzing and sharing relevant and legally obtained information. The next step is to determine the correct skills that must be developed, before the newly minted student is filling out their first job applications or interviewing for their first internship. 


As we reflect on the 9/11 25 year milestone, we can all admit the journey has not been easy. It is still far from over.


Let the next decade produce our next generation of Homeland Security professionals who may decide that Social Media and Internet AI expertise is just as vital to the curriculum as Privacy and Civil Liberties.


Watch this area to converge dramatically over the course of the next few years and for the Supreme Court in the United States to make some landmark decisions…

Friday, June 05, 2026

OSINT: If Intelligence were a Baseball Game...

What is Open Source Intelligence (OSINT)? Why is it important to your security and safety? How can you really understand how it is the same or different than other types of intelligence? Let's use this clever baseball analogy:


If Intelligence were a baseball game....

IMINT takes a picture every day or so, trying to discern whose winning from sporadic snap-shots at different times of day, different angles of look.

SIGINT tries to bug the dug-out and discern how the game is going from comments by the players

HUMINT tries to recruit the batter, find out where he thinks he is going to hit the ball, and send a spy out to catch it if it ends up there.

MASINT tries to smell the player's armpits and the arc of the ball from leather secretly treated beforehand.

OSINT gives everyone in the audience a baseball glove, and counts the ball out if anyone in the stands catches the ball.

What's the point? OSINT is not a substitute for spies, satellites, or secrecy. It simply takes all the low-hanging fruit off the table so the secret sources and methods can focus. Put simply, OSINT changes the rules of the game--eliminates all the "home runs" by the enemy that need not occur if we harness the distributed intelligence of the audience--and allows the secret sources and methods to focus more carefully on what's left inside the playing field.

So what? Open source intelligence is available to everyone at the touch of a button, Google and others. Intelligent bots troll the net in search of its target. Looking for the answer to the algorithim created to answer the question posed by it's designer. When it finds what it is looking for it brings it home to the clandestine machine with Petabytes of RAID.


The people behind the question look for a pattern. The question or hypothesis is there to accomplish an important task. To find some relevance in a vast sea of “Zeros and Ones” beyond the human brains capability to grasp. No one person owns it and has the ability to keep it secret, forever. Somehow, someone will put this information into the open. Then it becomes OSINT.


The race isn't about keeping information safe from being stolen or revealed to others. It's about something else:


Jeff Jonas, the one time chief scientist and distinguished engineer at IBM’s entity analytic solutions group, had developed a means of sharing corporate data without revealing what that data contains.

This technology, called anonymization, effectively "shreds" information, making it possible for companies to share information about their customers with governments or other companies without giving away any personal data.

Over time, Jonas believed companies will increasingly use anonymization to defend their data, and corporate well-being, from competitors and identity thieves.

This story to be continued…

Sunday, February 01, 2026

OSINT: "Accent on the Future"...

It was early-August of 2000 and topics of the “Dark Web” were prolific around the conference table at 8:00AM on that early Monday morning.  Our building on Wilson Blvd was just a few blocks up the hill from the Rosslyn, VA Metro Station.

Soon the dialogue turned to the weekends OSINT and the Terabytes our Cyveillance Web crawlers had retrieved across the globe.

Minding clients business on the Internet was going beyond what was visible with run of the mill browsers and growing search engines.  It had now gone dark, without the right tools, software and protocols.

Now was our opportunity to begin new strategic ventures with clients on three key “Decision Advantages”:

  • Continuity
  • Safety
  • Resilience

How as a Fortune 500 company operating across the globe could you apply these factors to increase your awareness and integrity of your content on the World Wide Web?

Where and how were your adversaries using your published information in nefarious ways to attack your organization?  To influence your product perceptions.  To launch campaigns of doubt against you.

It was now time to get on a plane to fly to the U.S. HQ of our global clients to inform them what was at stake beyond brand protection, social media monitoring and threat investigation, analysis, and response services.

  • Think about your business technology operations.  What factors could impact the continuity of your services based upon your geographic locations?
  • Think about your employees health and exposure to life threatening acts of sabotage or natural weather events.
  • Think about your organizations ability to defend itself against a spectrum of threats and to bounce back quickly to stay in competition with rivals.

Little did we know what was in our future, just about a year away in September 2001.

What if we could apply Continuity, Safety and Resilience (CSR) into our dialogue with a majority of our clients major growth initiatives?

On that Wednesday morning wake up call after a flight to O’hare the previous evening, it was thoughts of Arthur Andersen and the meeting ahead at their HQ.

That morning in a small office looking out on Chicago, we learned about the vast strategy of making a split of AA and Andersen Consulting into a new renaming on 1 January 2001.

Andersen Consulting would soon adopt the new name "Accenture". The word "Accenture" was derived from "Accent on the future”.

The question that morning was now on the “White Board”.

"Where are all the places on the Internet with the brand name “Andersen Consulting” that now needs to be changed to Accenture with a new logo?"

We can help with that business problem in a few hours.  The following day we knew that there were thousands of instances on the “Sun Microsystems” sites alone.

In July of 2001 Accenture would go public (IPO) and 8 years later move their HQ to Dublin, Ireland.  Today they have 779,000+ employees and revenue of US$69.xx billion (2025)…

Saturday, February 15, 2020

Open-Source Intel: Future Preemption...

Flashback fourteen years ago...

The methods of Intelligence gathering and sharing for the 17+ agencies that comprise the DNI is evolving to new Web 2.0 capabilities. In fact, they are putting these new tools to work to break down the silo's and connect the dots faster than the embedded and legacy systems have been capable of in the past.
Intelligence heads wanted to try to find some new answers to this problem. So the C.I.A. set up a competition, later taken over by the D.N.I., called the Galileo Awards: any employee at any intelligence agency could submit an essay describing a new idea to improve information sharing, and the best ones would win a prize. The first essay selected was by Calvin Andrus, chief technology officer of the Center for Mission Innovation at the C.I.A. In his essay, “The Wiki and the Blog: Toward a Complex Adaptive Intelligence Community,” Andrus posed a deceptively simple question: How did the Internet become so useful in helping people find information?
Yet even those who have implemented the use of new Web 2.0 collaboration and social networking to try and break through those typical information sharing barriers have another problem. Getting everyone to make a seachange and cultural shift to the use of these new tools and processes. The question is that even if you get everyone to use it and there is not anything "Secret" for fear of it ever being known by the wrong person, will it work? Thomas Fingar, the patrician head of analysis for the D.N.I.:
Fingar says yes, for an interesting reason: top-secret information is becoming less useful than it used to be. “The intelligence business was initially, if not inherently, about secrets — running risks and expending a lot of money to acquire secrets,” he said, with the idea that “if you limit how many people see it, it will be more secure, and you will be able to get more of it. But that’s now appropriate for a small and shrinking percentage of information.” The time is past for analysts to act like “monastic scholars in a cave someplace,” he added, laboring for weeks or months in isolation to produce a report.

Fingar says that more value can be generated by analysts sharing bits of “open source” information — the nonclassified material in the broad world, like foreign newspapers, newsletters and blogs. It used to be that on-the-ground spies were the only ones who knew what was going on in a foreign country. But now the average citizen sitting in her living room can peer into the debates, news and lives of people in Iran. “If you want to know what the terrorists’ long-term plans are, the best thing is to read their propaganda — the stuff out there on the Internet,” the W.M.D. analyst told me. “I mean, it’s not secret. They’re telling us.”
The amount of self-publishing on "Blogs" and "Wiki" applications is here to stay and now it is just a matter of having the right analysts using the correct tools. The point is that new search technologies and all of the "bots" and "crawlers" can try and keep up with the new content, but it is not likely. Intelligence analysis will continue to take far more grey matter than we have people trained and able to do so. This fact alone, should bring us back to square one. There is no such possibility as 100% security. Prevention and Preemption are both elusive goals and will be our "Holy Grail" for some time to come.
Today’s spies exist in an age of constant information exchange, in which everyday citizens swap news, dial up satellite pictures of their houses and collaborate on distant Web sites with strangers. As John Arquilla tells Clive Thompson a contributing writer to the New York Times, if the spies do not join the rest of the world, they risk growing to resemble the rigid, unchanging bureaucracy that they once confronted during the cold war. “Fifteen years ago we were fighting the Soviet Union,” he said. “Who knew it would be replicated today in the intelligence community?”

Saturday, November 16, 2019

Intelligence Fusion: The Race Against Time...

 Human intelligence may be the most sought after way to prevent new threats to your organization.

Yet that is never enough to give you total peace of mind. You have to implement multiple collection points for real-time and relevant information.

The front line of intelligence analysis begins far in advance of the actual event or incident taking place. Companies like "Quid" have provided some of the tools to detect the presence of new and relevant information in the hundreds of millions of active web sites across the Internet.

You may also see Dataminr in the corporate Security Operations Center (SOC) and even the local Fusion Center for more Real-Time information.

They assist CxO's in navigating their operational risk strategy execution across a competitive and increasingly threatening global landscape.

The fusion of intelligence from the Internet and broadcast media requires not only sophisticated software, hardware and talented Intelligence Analysts, it requires good old fashioned investigative tactics. And when you combine all of these to create the closest version of reality, then you have found true "Integrity."

Keeping information truely confidential is a difficult task. Assurance that the information will be there when you need it, is also equally important. Yet it is the "Integrity" of the information that we are in constant pursuit of.

Data fusion involves the exchange of information from different sources—including "John Q. Public" with his mobile phone, Ring and other IoT sensors, Law Enforcement, Public Safety, and especially the Private Sector—and, with analysis, can result in meaningful and actionable intelligence and information.
In a wide-ranging hearing on the myriad threats to the U.S. homeland, from white supremacist terrorists, border security, school shooters, and cyber attackers, the director of the FBI gave a glimpse of how the agency is using technology to blunt one of those threats.

FBI Director Christopher Wray, testifying before the Senate Homeland Security and Governmental Affairs Committee, said his agency has implemented a new threat-sharing capability on its Law Enforcement Enterprise Portal (LEEP).
The fusion process turns this information and intelligence into actionable knowledge. Fusion also allows for relentless reevaluation of existing data, in context with new data in order to provide constant updates.

The Private Sector is still the biggest challenge. Trusted relationships need to be continually fostered. New mechanisms for public-private coordination are consistently being discussed.

Fusion Center's are not the only answer. It still remains a significant piece of a very complex operational security challenge, that we will be facing for still years to come...

Sunday, October 02, 2016

Homegrown Violent Extremism: Vigilance of Intelligence...

Since the Boston Marathon terrorist attack on Patriots Day, April 15th, 2013 the spectrum of Operational Risks that have descended upon the region and the country are vast.  People, processes, systems and external events are the state-of-play.  If you own a backpack and you are taking it on public mass transit or to a public event soon, remember this.  The new normal has finally arrived in the United States of America, again.

What does the face of terrorism look like?  London understands.  Oslo now understands.  FOB Chapman understands.  New York City.  San Bernardino.  Orlando.  Dallas.  Even as we begin the analysis of this latest U.S. based event in context with all the similarities of past episodes of terror, we are left with one absolute known.  Operational Risk Management is essential, no matter who you trust and how much you trust them.  The public now understands this once again and regardless of how much we may want to continue to enjoy our civil liberties and privacy, you never know when or how this will happen again.

Why is it that Israel and other nations that are so far more advanced in their Operational Risk strategies, still witness numerous incidents of terror?  Because it is impossible to eliminate.  It is only possible to mitigate the risks and likelihood of occurrence.  Public safety and security incidents of this magnitude are the visible metric we all judge to make sense of our progress.  Our only hope is better intelligence.  Lisa Ruth explained this over four years ago:

Intelligence is the best, the only, way to defeat the terrorists. To tackle the terrorist threat, we need all the weapons in our intelligence arsenal. That starts with intelligence requirements from the entire community that are well-focused and well-targeted. It means funding and a mandate to succeed. It means strong collection. We need human intelligence, which comes from case officers recruiting sources on the ground to give us information. We need electronic information, including telephone intercepts and static listening devices. We need overhead photography. We also need open source information such as web sites, facebook pages and other publicly available information. We need analysis, putting the pieces together. And we need decision makers who trust the intelligence services and listen to what they are saying. Washington Times, 9/14/2012

So in the dark shadows and behind closed doors, the whispers continue to debate how Boston Patriots Day 2013 could have happened?  How On December 2, 2015, 14 people were killed and 22 were seriously injured in a terrorist attack at the Inland Regional Center in San Bernardino, California, which consisted of a mass shooting and an attempted bombing.  Why didn't the intelligence we had already, provide the warning in time, in the midst of a glaring yellow or red flag?  As the analysis continues and the best and the brightest determine the lessons learned, we can only pray, that our process changes take place and citizens behaviors are modified.  Erroll Southers explains why we have more work ahead of us:
 At the same time, the radicalization process is not brief. Extremism smolders like a hot coal, an idea that grows into a violent fire fueled by anger, conflicts of identity, feelings of humiliation and marginalization.. It is important for the public to understand that removing any one of these elements cannot fully disrupt radicalization. All of these and other root causes need to be addressed in the effort to not just apprehend terrorists, but dissuade the radicalization that leads to terrorism.
There will be numerous accounts of heroism, people who saw or reported details that could have helped stop any of these Homegrown Violent Extremist (HVE) events.  What matters most from this point forward is that "John Q. Citizen" realizes the importance of being ever vigilant.  Having a continuous sense of personal vigilance is our only hope.  Whether in the crowd at the next marathon or in a lonely office cube, off Route 123 does not matter.  The goal is the same and we must not lose sight of our mutual responsibilities and unified purpose.
Godspeed America!
  1. An expression of good will when addressing someone, typically someone about to go on a journey or a daring endeavor.

Saturday, August 20, 2016

Strategic Foresight: Risk Leadership into the Future...

When you really start to think long and deep on the discipline of the agile startup community,  you keep coming back to a single word.  Improvise.  The more you analyze what it takes to get an idea from "Zero to One" to a Minimum Viable Product (MVP), the more you need Operational Risk Management (ORM).  At the same time, this thought might question the notion of previous planning or preparedness:
im·pro·vise [im-pruh-vahyz] Show IPA verb, im·pro·vised, im·pro·vis·ing.
verb (used with object) 
1.  to compose and perform or deliver without previous preparation; extemporize: to improvise an acceptance speech.
2.  to compose, play, recite, or sing (verse, music, etc.) on the spur of the moment.
3.  to make, provide, or arrange from whatever materials are readily available.
Yet what the true startup and ORM professional understands is the origin of the word:
Origin:

1820–30; French improviser, or its source, Italian improvisare (later improvvisare ), verbal derivative of improviso improvised; Latini mprōvīsus, equivalent to im- im-2 + prōvīsus past participle of prōvidēre to see before hand, prepare, provide for (a future circumstance). See proviso
And so this brings us to the importance today of utilizing the power of "Strategic Foresight."
Strategic foresight is a fairly recent attempt to differentiate "futurology" from "futures studies". It arises from the premise that:
  • The future is not predictable;
  • The future is not predetermined; and
Future outcomes can be influenced by our choices in the present. [1]  Strategic foresight may be used as part of the corporate foresight in large companies.[2] It is also used within various levels of Government and Not for Profit organizations. Many concepts and tools are also suited to 'personal futures' thinking.
The "Asymmetric Attributes" of enterprise risk and "Big Picture Security" today is making predictability a major task going forward.  So what do improvising and strategic foresight have to do with startups and Operational Risk Management?  Everything.  Let's go back in the "Time Machine" for a minute:
The 2010 eruption of Eyjafjallajökull were volcanic events at Eyjafjallajökull in Iceland which, although relatively small for volcanic eruptions, caused enormous disruption to air travel across western and northern Europe over an initial period of six days in April 2010. Additional localised disruption continued into May 2010. The eruption was declared officially over in October 2010, when snow on the glacier did not melt. From 14–20 April, ash covered large areas of northern Europe when the volcano erupted. About 20 countries closed their airspace (a condition known as ATC Zero) and it affected more than 100,000 travellers.
"As the crisis ran its course it went on to paralyze or seriously limit air traffic in 23 countries around the EU and its periphery bringing 300 airports to a standstill and cancelling 100,000 flights, representing three-quarters of all European traffic. Ten million individuals were affected and had to cancel their trips or find alternative travel arrangements at serious economic cost for the passengers, carriers, and insurers involved."
So what?  So the future state of a High Risk X Low Frequency event is unlikely to get the attention it requires.  The 1-in-100 year probability of an event occurrence, has been so integrated with insurance industry underwriting group think, it often falls on deaf ears.  Resources and attention are increasingly directed towards potential crisis events, that are considered High Risk X High Frequency.

Could the EU have imagined the impact of volcanic ash from an erupting volcano in Iceland?  Most certainly.  Did the EU have the strategic foresight to know what to do when and if this happened?  The point is that sometimes improvising and the success of improvisation is a result of having devoted resources and time towards the planning and behavioral prediction of future outcomes.  Influenced by our choices in the present.  The impact to the organization, enterprise, nation state or individual is going to be a factor of how much is devoted to strategic foresight initiatives.

It is also imperative that we discern the risk of natural incidents caused by mother nature, to human threat actors. We must continue to evaluate the characteristics of other threat vectors related to our daily Operational Risk spectrum.  Using only the imagination of low-tech, less sophisticated and tried-and-true methods, our human adversary has a "Modus Operandi" with a continued low-risk of failure.  That low tech lower risk of failure, is still one of our greatest vulnerabilities:
The Joint Improvised Explosive Device Defeat Organization (JIEDDO, pronounced like "ji-dough") is a jointly operated organization of the U.S. Department of Defense established to reduce or eliminate the effects of all forms of improvised explosive devices used against U.S. and coalition forces.[4]
  • Formed February 14, 2006
  • Headquarters The Pentagon
  • Employees 435 government civilians and military personnel; ~1,900 contract personnel
  • Annual budget $1.6 billion for fiscal year 2013 [1]
JIEDDO is making a difference and the metrics prove that our Operational Risk Management professionals here, need to continue the course.  Not just for what has happened overseas on foreign soil, but for the surging wave on our own U.S. Homeland:  Boston, MA is one recent and relevant example.

Be Vigilant America!  Use Strategic Foresight to imagine such interdependent, unpredictable scenarios.  These growing interdependencies, are becoming ever more so prevalent:

• Rapid global economic growth
• Industrial development of non-OECD nations
• Interlinked global supply chains
• Increased worldwide awareness
• Increased media reach and individual power

These five interdependencies will be the catalyst of our future High Risk X Low Frequency incidents.
The future success ratio of agile startups and the ability for new innovation to pivot effectively, will be determined by an Operational Risk Management maturity factor. 

Saturday, February 07, 2015

Frames of Mind: The Risk of Analytic Convergence...

Are there growing Operational Risks to our national security and private sector enterprises as our intelligence communities (IC) continues it's path of convergence?

We are using the tools and software to automate as much of the collection and the work flow as possible before the human "Grey Matter" is necessary to the final analysis. The fact that 80% of the time is spent on collection/searching and 20% on actual human processing, tells us that we have a long way to go.

Getting to the point where we are spending even more than half of the time doing actual human analysis is a long way off in to the future. Software systems are getting automated crawlers to pull more relevant OSINT into the "Big Data" bases for unstructured query, yet what about the front line observer who is the witness to an incident. They must process this by interfacing with a paper based report that is filled in with a #2 pencil or an electronic form on a PDA to check boxes and select categories that best describe the observed event that risk managers, watch commanders and operations directors need for more effective decision support.

It dawned on us again that perhaps the most vulnerable area of our entire mission is the actual analytical process. We have highlighted the "Analysis of Competing Hypotheses" (ACH) methodology in the past:
Use ACH when the judgment or decision is so important that you can't afford to be wrong. Use it to record and organize relevant evidence prior to making an analytical judgment or decision. Use it to identify and then question assumptions that may be driving your thinking, perhaps without realizing it. Use it when the evidence you are working with may be influenced by denial and deception. Use it when gut feelings are not good enough, and you need a more systematic approach that raises questions you had not thought of. Use it to prevent being surprised by an unforeseen outcome. Use it when an issue is particularly controversial and you want to highlight the precise sources of disagreement. Use it to maintain a record of how and why you reached your conclusion.
To our own demise, how much time are we teaching people how to create .csv files and excel spreadsheets so they can be imported into a link analysis chart or tool. Getting the correct, clean and accurate data into the tool is very important. Once the intel analysts take over and start the Who, What, When, Where exercises to gain a visual picture of the incidents, actors and cues and clues associated with the "Modus Operandi" (MO) people start to get way to excited about the possible outcomes. That is when it's time to stop, assess and use ACH.

Utilizing an analytic process that incorporates the use of tools and other aides to the human decision maker to increase accuracy is only prudent if you have the time to insure a decision without error. In the absence of time, human intelligence is the only answer. We should not under estimate the "Theory of Multiple Intelligences" put forth by Howard Gardner in his book Frames of Mind.

As you read this book from 1983 and begin to apply the history of what we have learned about human cognition and then use this in the context of an analytic process for intelligence communities, suddenly our current state of the IC and it's attempt to reform itself seems crystal clear. What if we organized the competencies of intelligence organizations more closely to the multiple intelligences that Gardner has been researching for multiple decades?

The people selected, trained and leveraged for their "Grey Matter" would be more closely aligned with what we know about the brain and the way that humans have evolved from a biological perspective in their cognitive capacities. Is it possible that we have the wrong people working in the wrong Intel agencies and the wrong roles?
  • Linguistic Intelligence
  • Musical Intelligence
  • Logical-Mathematical Intelligence
  • Spatial Intelligence
  • Bodily-Kinesthetic Intelligence
  • Personal Intelligence
Is it possible to develop an analytic process that puts the right people in the right sequence of the process so that the outcomes are closer to what we really are seeking?

The answer may lie on one of these pages. They may be the best place to start in order to understand what each of our IC entities is all about at this point in the intelligence analysis and outcomes evolution.

Saturday, April 25, 2009

Human Factors: Early-Warning System...

Predictive Intelligence And Analytics From 1SecureAudit Provides Transnational Organizations With A Preemptive Human Factors Early-Warning System

According to Managing Director and Chief Risk Officer of 1SecureAudit, Peter L. Higgins, the complexity of today's extended global enterprises requires a new governance lens to view hidden insider risks and to guide management executives to achieving a defensible standard of care.

"Our newest consulting practice accelerates the time line in identifying employee insider risks and potential threats associated with international client transactions," said Higgins. "Ms. Marcia Branco is launching our new client offering with more than a decade of experience identifying the complex connections between human behavior and corporate operational risk responsibility."

Advocating a "People First" approach, Ms. Branco, vice president, practice director of the Predictive Intelligence and Analytics practice, believes corporate personnel; partners and suppliers represent a tremendous asset and simultaneously a significant legal liability to a business. "People are the primary focal point to better understanding and resolving systemic risk problems within the walls of the enterprise and beyond to the extended supply-chain," said Branco.

The Association of Certified Fraud Examiners affirms "U.S. organizations lose an estimated seven percent of annual revenues to fraud," and insider negligence is the highest cause of data breaches, reports the Ponemon Institute & PGP Corporation. The complexity and quantity of insider threats is growing at the same time as businesses are facing shrinking budgets and mounting pressures to maintain and grow profits with fewer resources. "How successful has your company been at identifying and swiftly addressing issues, conflicts and preventing malfeasance? Whether originating internally from an employee or contractor or at your extended border of partners, suppliers and clients, predictive intelligence is essential?" asks Higgins.

1SecureAudit provides critical assessments, internal investigations, strategy execution and program development. These proactive governance and advisory services generate positive change to business culture, operations and bottom line.

"Our distinctive 'People First' approach examines your organization's human capital assets to gain unique insights on corporate culture, company issues and the workforce's attitude about management and business initiatives. We convert these human factor data into predictive intelligence to preemptively determine how to best shape current and new corporate strategies. Our clients are able to take advantage of short-lived opportunities, attract and retain employees, partners and customers, demonstrate a more defensible standard of care and promote a trustworthy corporate reputation," stated Branco. "Does your organization consistently adhere to and enforce corporate policies, ethical standards and procedures that value your employees and respond to shareholder advocates?"

Working with 1SecureAudit to integrate predictive intelligence in any business strategy and practices is a sound investment that directly contributes to corporate management's, Board of Directors', and shareholders' peace of mind. For more information, visit 1SecureAudit.com or e-mail RDU (at) 1SecureAudit.com.

Wednesday, April 01, 2009

4GW: Irregular Warfare in the Homeland...

Why is the US House Armed Services Subcommittee holding a hearing soon that is entitled: "Terrorism, Unconventional Threats and Capability on Terrorism and the New Age of Irregular Warfare: Challenges and Opportunities"?

Here is one good reason:

Baitullah Mehsud, the leader of the Pakistani Taliban recently claimed responsibility for the deadly attack that took place at a police academy on Monday in Lahore, Pakistan. But that’s not all. According to Mehsud, the next attack is going to be much closer to home. In a phone interview with the Associated Press, Mehsud indicated that his terrorist organization was planning a devastating attack on Washington D.C. that would “amaze” the world. Heritage analyst James Phillips told Fox News:

It should be taken seriously because [Mehsud] has ordered the deaths of many Pakistanis and Afghans and has a close alliance with Al Qaeda. It’s not too much of a stretch to think he might be involved in an attack on the U.S. if he’s able to get his followers inside the United States. He’s a militant extremist whose threats cannot be ignored.

Though most Americans associate terrorist attacks with bombings, armed ground assaults can just as deadly and disruptive. The most dramatic recent example was the Terrorist attacks that took place in Mumbai, India last November, killing almost 200 people.

Ground assaults are not just a terrorist tactic that might happen over there. Over here, it has been less than two years since six terrorists were thwarted in their attempt to assault Fort Dix in New Jersey.


The 4GW (Fourth Generation Warfare) strategy is well over five years old. We are glad to see that one of the best on this topic will be at the Armed Services hearing on Capitol Hill. Let's hope John Robb gets an opportunity to outline the following:

Differences
Many of the methods used in 4GW aren't new and have robust historical precedent. However, there are important differences in how it is applied today. These include:

  • Global -- modern technologies and economic integration enable global operations.
  • Pervasive -- the decline of nation-state warfare has forced all open conflict into the 4GW mold.
  • Granularity -- extremely small viable groups and variety of reasons for conflict.
  • Vulnerability -- open societies and economies.
  • Technology -- new technologies have dramatically increased the productivity of small groups of 4GW warriors.
  • Media -- global media saturation makes possible an incredible level of manipulation.
  • Networked -- new organizational types made possible by improvements in technology are much better at learning, surviving, and acting.
Corporations, Government Agencies and owners of strategic critical infrastructures owned by the private sector are continuing their vigilance in light of the 4GW emergence. More than ever the need for effective OSINT (Open Source Intelligence) gathering at the street level is imperative. Yet all the Humint and sensor based collection of data will not change the myopia of insight unless there is a rapid adoption of the new mantra: "Responsibility to Provide."

The "Responsibility to Provide" statement is rapidly replacing the old and ineffective rule of "Need to Know". Our adversaries realize that our "Need to Know" mentality is one of our greatest vulnerabilities and they will continue to exploit this weakness. Washington, DC is has just emerged from a period of coordination, cooperation and unprecedented effectiveness across legal, political and jurisdictional boundaries. The fact is that the 44th Presidential Inauguration bound together thousands of people across the country to keep our Nations Capital safe and secure in January. This mission was accomplished and the result has been ever so felt by those who were in the middle of the operational command centers, such as WRTAC, the Washington Regional Threat and Analysis Center.

WRTAC provides DC Metro partner agencies and local jurisdictions with a watch command, plus an Open Source Daily Brief of current news articles relating to terrorism, homeland security, critical incident response and public safety. The key factor here is "Relevance" on the ground level to your own community and the local assets needed to raise situational awareness.

If Baitullah Mehsud is telling the truth, then it is not so much a matter of "what" 4GW tactics will be utilized, it is a matter of "when."

Tuesday, September 16, 2008

EO 12333: Open Source Intelligence...

As the headlines continue to shout for more oversight, regulation and legal actions in the aftermath of chaos in global financial markets; the corporate investigations and security departments are at full capacity. Outsourcing the investigations is not anything new, and it makes even more sense in times when an independent point of view is essential:

A blend of advanced technology, increased litigation and rising fears about trade secret theft and financial fraud is driving law firms and corporate counsel to the doors of former FBI agents and ex-prosecutors with a knack for solving crimes.

These private investigators report that calls for help from law firms and corporate general counsel have increased substantially in recent years.

Attorneys are looking for assistance on a wide range of problems, including: corporate espionage, intellectual property theft and workplace discrimination claims.

At the core of many of these problems, lawyers note, is a mountain of computer evidence too technical and too overwhelming for attorneys to dissect on their own.

"Most lawyers do not have the technological experience or the accounting expertise to do almost any of the stuff that these guys do," said attorney Alan Brudner, head of litigation and investigations of the U.S. division of UBS Securities LLC, an international financial services firm.


Corporate Counsel should be reinvesting in the consistent lawful monitoring of employees, contractors and suppliers as it pertains to Executive Order 12333. This has been recently amended and clearly spells out the refocus on our intelligence efforts to address the following threats to our corporate trade secrets and national security:


(c) Intelligence collection under this order should be guided by the need for information to respond to intelligence priorities set by the President.

(d) Special emphasis should be given to detecting and countering:

(1) Espionage and other threats and activities directed by foreign powers or their intelligence services against the United States and its interests;

(2) Threats to the United States and its interests from terrorism; and

(3) Threats to the United States and its interests from the development, possession, proliferation, or use of weapons of mass destruction.

(e) Special emphasis shall be given to the production of timely, accurate, and insightful reports, responsive to decision makers in the executive branch, that draw on all appropriate sources of information, including open source information, meet rigorous analytic standards, consider diverse analytic viewpoints, and accurately represent appropriate alternative views.


Suffice it to say that more than ever, "Open Source" information is becoming the starting point for all intelligence collection activities. In the context of the corporate policy regarding the use of systems, most if not all companies have the right to monitor all applications for "Red Flag" indicators of fraud, espionage or other violations of state and federal laws. Corporations are using "Open Source" information to determine the initial profile of potential candidates for open positions including the analysis of FaceBook, MySpace and LinkedIn social networking sites.

Executive Order 12333 emphasizes US citizens rights:

The Executive Order maintains and strengthens existing protections for Americans' civil liberties and privacy rights. The Executive Order retains and reinforces the provisions in place in the original Executive Order 12333 to ensure that all intelligence activities are conducted in a manner that protects the civil liberties and privacy rights of Americans. All collection, retention, and dissemination of information regarding United States persons must be conducted in accordance with procedures approved by the Attorney General.


Executive Management and Boards of Directors will be reexamining the current state of their policies regarding the monitoring of employees and other stakeholders. Essential tools and operational risk management methodologies must not only be utilized to safeguard our corporate secrets from theft and economic espionage, they must simultaneously protect our privacy and civil rights. There are mechanisms in place for "Joe Citizen" to address his identity and the right to correct any information that is incorrect or in error. However, in this age of Wiki's, social networking sites and sophisticated data mining techniques it's possible that one's identity could be associated with other information that is derogatory, disparaging or can damage a persons reputation.

Managing your own identity and reputation in a vast sea of "Open Source" information is imperative. In a world of intelligence collection, analysis and production the integrity of data is just as important as the confidentiality and the assurance of the data. Making sure that Lexis Nexis, TransUnion, Experian and Equifax are using the correct information associated with your identity could make the difference in critical facets of your life, both personal and professional.

Who is managing your identity today? Private and law enforcement investigators may start with "Open Source" information to develop a profile, yet that is only the beginning. Vetting sources and individuals who provide information is a key part of the process. Certifications, training, regulation and continuous oversight will ensure that people are continuously improving their skills, techniques and processes. The rest, is up to you.