Who plans for worst-case scenarios? Whole cleared companies can engage in this kind of planning event, like military organizations that regularly practice disaster scenarios before they happen.

Threat Assessment

You know the threat assessment you received once you were identified as a company protecting classified information? That assessment is basically, “Who’s out to get you, and how?” This threat list of adversaries includes nations, corporate competitors, intelligence brokers, activists, and spies who steal your secrets to sell them to others. Furthermore, disaffected insiders, terrorists, social adversaries such as environmental radicals, and others can be on that list of your adversaries. How do you protect yourself against such a wide array of troublemakers? First, consult those whose job it is to know the threat against you. Identify first what is already known about the threat to your company’s activities. Your professional analysts are your first stop in understanding who’s out to get you.

Befriend your threat analysts. If you have contact with your government analysts, make it your business to meet them personally. Ask them how they collect the data they later share with you. How often do they collect such information? Does it change the overall assessment you received at the beginning? What would cause a change that would, in turn, cause your company to do something more or differently to defend its cleared personnel and classified programs? How often would such plan-changing notices occur?

Addressing Threat

Try this. If you see your company is particularly susceptible to, say, AI and other cyber threats, consider sending a team member to a specialist course. The government Center for the Development of Security Excellence (CDSE) offers many courses geared toward understanding and combating active threats. For instance, they offer the ‘Insider Threat Detection Analysis Course.’ All companies need to have someone versed in this. Someone who knows who among a company’s population might want to satisfy their anger, disaffection, or social conscience by compromising your secrets?

Recent cases include a young military member trying to impress people he met online. So he published official information he worked with to astound outsiders. Then several disenchanted employees wanted to expose their companies’ wrongdoing and passed alleged secrets along to the world. These wholesale internal threats might betray entire systems. Consider the famous case of Edward Snowden, who revealed vast tracts of American classified information to the world. He now resides in Russia.

“Impacts of Artificial Intelligence and Emerging Technologies on the Cybersecurity Landscape” is a whole college course these days. Know what the threat assessment means when dealing with this topic. You must provide constant updates to anyone on your team whose job description includes this defensive posture. They must stay current on newer collection methods used by adversaries in this field. After all, your employees can be recruited or exploited without even knowing it. Few know ahead of time that the free USB picked up at the conference could be installed with malware that will send your data to a bad actor.

Plan for Attack

In such courses, you’ll learn what to look for to see if something is developing, as well as what laws govern how you can monitor for such threats. The latter is critical, because no one wants to fail to stop an adversary because of illegally collected evidence. In law, gathering information illegally is called “fruit of the poisoned tree.” If done, the collector is a candidate for a jail cell, as is the pursued party.

Trained security personnel can then provide the company with ongoing training on what they’ve learned. They can offer up “wargaming” scenarios. With the right personnel in the meeting, attendees can decide whether the company is ready to take on and counter the identified threats.

Denial of service attack? Which agency of the company will deal with that? False-flag articles in local newspapers (in a foreign language) that reveal your company is secretly testing something? Who will you need to involve to protect against or mitigate this attack? The list goes on and on. Know who’s out to get you, and how. Prepare your own people to defend your cleared personnel and programs.

Related News

John William Davis was commissioned an artillery officer and served as a counterintelligence officer and linguist. Thereafter he was counterintelligence officer for Space and Missile Defense Command, instructing the threat portion of the Department of the Army's Operations Security Course. Upon retirement, he wrote of his experiences in Rainy Street Stories.