Showing posts with label Fusion Center. Show all posts
Showing posts with label Fusion Center. Show all posts

15 February 2025

Infinistructure: Who Knew What When...

Who knew what when? This is the question of the last few months as we now embark on the path towards recovery.

The Operational Risks that have plagued our aging county, state and federal institutions are growing and the convergence factor has brought us even bigger systemic organizations "Too Big To Fail."

While many will be side tracked by the need to deal with the toxic assets still on the books or in sinking agencies the "Zero's and One's" don't lie.

The information, digital evidence and just pure data audit trails will remain for many to be caught, charged, indicted and then sent before a jury to decide their fate.

Managing risks in the enterprise today takes on many flavors and within several departmental or enterprise domains of expertise.

Whether it be the C-Suite, legal department, the IT department, Internal Audit, Security department or even the Operational Risk Management Committee the "Zero's and One's" don't lie.

Think about how much time the people behind organizational malfeasance spend on trying to cover their tracks, clean up the digital "Blood Trail" of their crimes and wrong doing all the while knowing that someday, a smart investigator or forensic examiner will connect the dots. Game over.

Regardless if you are two paid-off programmers who have been enforcing the "Business Rules" in their software by the boss or an internal threat actor does not matter.

Whether they are copying, stealing, altering or damaging the digital information within the organization does not matter; these Operational Risks still remain constant.

The resources and the money devoted to continuous due diligence, monitoring and preemptive strategy to Deter, Detect and Defend the digital assets of the enterprise need to grow dramatically to stay ahead of the curve.

The best way to figure out “What to do” and “How to do it” will require outside assistance. Moving your digital assets to be professionally managed makes sense for economic and other financially prudent reasons.

Yet this migration away from large numbers of people managing and maintaining your information technology infrastructure internally and on your payroll is just the standard "outsourcing" strategy right?

It has it's own set of 3rd party supply chain set of risks. After your next incident who will be asking: Who knew what when?

Many private sector and government enterprises who are augmenting their COOP and the economic strategy of "Cloud Computing" have realized the smart course of implementing and migrating to managed services and infrastructure suppliers.

"How can the utilization of an "Infinistructure" with the knowledge and application of a legal compliance ecosystem in your enterprise mitigate the risks associated with bad actors, unprepared personnel and the digital loss of key evidence?"

Stay tuned for more on this later. In the mean time remember this.

All of the newest technology, fastest AI computers and neural networks enabled with encryption and secured physical locations will not be enough to save your institution from Operational Risks.

It is just one more piece of the total risk management mosaic, that will still require the smartest people and the most robust policy and processes imaginable.

Who knew what when? This will continue to be the biggest question of the next decade.

01 February 2025

Team Learning: Innovation Navigators...

The discipline of “Team Learning” has been present with sports and education, corporations and small businesses since the collaboration of people who have engaged in mutual dialogue.

“In a remarkable book, Physics and Beyond: Encounters and Conversations, author Werner Heisenberg argues that “Science is rooted in conversations. The cooperation of different people may culminate in scientific results of the utmost importance.” By Peter M. Senge The Fifth Discipline - The Art & Practice of The Learning Organization page 238

How will you excel into the future and continue to learn within the ranks of your particular organization?

  • By sitting in a classroom?
  • By watching a lecture?
  • By working alone on a project?
  • By creating outcomes without any potential beneficiaries feedback?

Before the “Learning Organization” was born, these kinds of activities and behaviors were the key ways people were educated and taught new skills.

As time passed and the benefits of “Team Learning” began to evolve, each participant was proactive in several key behaviors and activities.

After discovering the benefits of mutual dialogue and discussion with small groups of people who could actively participate together, the “Learning Organization” was launched.

How might you and your team of fellow leaders work together to learn from each other?

You see, if you are engaging in a true dialogue with trusted colleagues in a small group there are tremendous advantages in creating collaborative hypotheses.

The hypothesis building together creates the pathways and navigation for innovation.

“Innovation Navigators” working side-by-side on the testing of a mutual question gives each other the opportunity to learn from the relevant expertise of each other. The IQ of the team is now greater than just the individual."

What journey will you now embark on with your “Learning Team?

A new solution. A new product. A new method. To solve what?

That is not up to you to start the process.

It shall rely upon the answers from potential beneficiaries and how effective you are in asking questions with others on your team.

What is the problem to be satisfied? What is the problem to be solved?

Once your team truly knows the problem-set, the “Team Learning” shall begin…

10 February 2024

Analytic Priorities: Crossing the Digital RubiCON...

The governance of information within the government enterprise or the private sector enterprise remains very much the same. Both are subjected to a myriad of laws to help protect the civil liberties and privacy of U.S. citizens. Yet the data leaks, breaches and lost laptops keep both private sector and government organizations scrambling to cover their mistakes and to keep their adversaries from getting the upper hand. Again, the governance of information is the core capability that must be addressed if we are to have effective homeland security intelligence sharing to defeat the threats to the homeland 100% of the time.

The stakeholders in the information sharing environments will say that they have all the laws they need to not only protect information and also to protect the privacy of and liberties of U.S. citizens. What they may not admit, is that they do not have the assets within the context of their own organizations to deter, detect, defend and document the threats related to too much information being shared or not enough. These assets are a combination of new technologies, new education and situational awareness training and the people to staff these respective duties within the enterprise architecture.

Operational Risk Management is a continuous process in the context of our rapidly expanding corporate environments. What is one example? People traveling to emerging markets to explore new business opportunities or new suppliers that will be connected by high speed Internet connections to the supply chain management system. These boundaries of managing operational risk, have not only expanded, they have become invisible.

Ru·bi·con
1. a river in N Italy flowing E into the Adriatic

2. Rubicon, to take a decisive, irrevocable step

This "Digital Rubicon" before us, to take on a more "Active Defense" in navigating the risk across international waters of e-commerce, privacy and legal jurisdictions will forever shape our future. The decisions made on what constitutes an adversarial attack in the cyber domain, will not be as easy as the dawn of the nuclear age. Policy makers today have to weave the potential implications into a sophisticated decision tree that crosses the complex areas of intelligence, diplomacy, defense, law, commerce, economics and technology.

The new digital "Rule Sets" are currently being defined by not only nation states but the "Non-State" actors who dominate a segment of the global digital domains. The same kinds of schemes, ploys, communication tactics and strategies are playing out online and what has worked in the physical world, may also work even better in the cyber-centric environment. Corporations are increasingly under estimating the magnitude of the risk or the speed that it is approaching their front or back door steps.

The private sector is under tremendous oversight by various regulators, government agencies and corporate risk management. Yet the "public-private" "tug-of-war" over information sharing, leaks to the public press and Wikileaks incidents has everyone on full alert. As the government has outsourced the jobs that will take too long to execute or that the private sector already is an expert, operational risks have begun to soar.

As the private sector tasks morph with the requirements of government you perpetuate the gap for effective risk mitigation and spectacular incidents of failure. Whether it is the failure of people, processes, systems or some other clandestine event doesn't matter. The public-private paradox will continue as long as the two seek some form of symbiosis. The symbiotic relationship between a government entity and a private sector supplier must be managed no differently than any other mission critical resource within an unpredictable environment.

Once an organization has determined the vital combination of assets it requires to operate on a daily basis, then it can begin it's quest for enabling enterprise resiliency. The problem is, most companies still do not understand these complex relationships within the matrix of their business and therefore remain vulnerable. The only path to gaining that resilient outcome, is to finally cross that "Digital Rubicon" and realize that you no longer can control it.

The first step in any remediation program, is first to admit the problem and to accept the fact that it exists. Corporate enterprises and governments across the globe are coming to the realization that the only way forward is to cooperate, coordinate and contemplate a new level of trust.

09 October 2022

Mosaic: Launching New Solution Navigators…

There are countless people and organizations who are articulating the problems that exist in your agency, your business or your non-profit.


Some international entrepreneurs are assisting those who have not developed their own concept selection and development team with solving the identified and validated problems.


The challenge in most entities has been enough resources and the correct people dedicated to defining the problem-sets and then applying a proven methodology for creating a solution space with a mission to deliver potential prototypes for testing.


How fast does your organization move from “Problem Definitions” to “Deliverable Solutions” ?


Well that is going to depend on what business or industry you are competing in across your geographic area. Are you in a small business? A regional enterprise. The national leader in ordering stuff online made by someone else and then delivering it to your customers household doorsteps?


Or are you in a services institution that invents and delivers new process designs. New intellectual capital. New creative ideas. New real-time OSINT information.


Moving from a past historical era where “Problem-space to “Solution-space” may take years, now our 2022 world is witnessing this time line whittled down to days, hours or even seconds.


In our current digital environment, utilizing Quantum capabilities, the problem may be solved in a minute or a second or two.


If you are trying to launch the next space craft to the Moon or Mars or beyond, it could take longer.

Yet what does all of this focus on true innovation really mean to “John Q. Citizen”?


So what?


Do you remember the first time you used Mosaic? What about the Netscape Navigator?


If you do remember, then you have a substantial set of real context on the topic of and history of creative innovation. Solving real-problems.


You actually understand and witnessed the speed at which people are capable of creating “New”.


Defining problem-sets to creating new solution-sets was a daily process for all of those "Digital Navigators" with electronic keyboards and modems in the early 1990’s.


Utilizing our Earths new World Wide Web technologies and capabilities, provided so many with the ability to explore, experiment and test, then to deliver new product solutions for those who did not even know they had a problem yet.


For those so interested in the future of our world and so eager to be innovators in 2022, sometimes you just have to study the past for a lesson. Maybe even read up on Mosaic on Wikipedia.


This journey has been epic. Now get out there and “Do” what you have a passion for and that will make a difference on this rock!

16 July 2022

Exceptional: Accelerating to Wisdom…

 Why will you use your ability to discern a course of action that is wise and insightful?

You were born with it and even at the earliest stages of your life, it was soon known that you were exceptional. Rare. Superior.

Over the course of your lifetime, you have possessed the ability to see what others can not. You have the abilities to recall and decide faster with extraordinary accuracy.

How might you utilize your God given talents and the DNA you were born with, to make a real difference here?

Your IQ and your particular part of the spectrum, is an asset that you shall utilize your entire life, in order to benefit others.

The problem-sets you discover in front of your organization, your agency, your business, and your family, are counting on your continuous wisdom.

Even with these abilities and your peer group superiority, you still remain unknown. 

Unpretentious.

Learning more than you already know and applying your deep experience, is still your passion.

What did you read this day, or this week that made you even more curious? 

Who wrote the words that sparked your insightful questions and increased your own appetite for finding out more? Yourself?

"Now you will analyze, you shall create the models and use the tools, to better Understand, Decide and Act."

The vast amount of data and the velocity of the technological innovations before us, will remain our greatest challenge. Our greatest opportunity.

How might you act, to make a difference for the benefit of those you really care about in life?

It begins with your own wisdom. Your own particular talents and your abilities, that will continue to remain exceptional.

Now get out there and make a real difference…

20 February 2022

Fortitude: Presidents to U.S. First Responders...

On the 3rd Monday of February in the United States, our country takes a day to reflect. To remember, and acknowledge and to honor our American Presidents.

It is a federal holiday specifically honoring George Washington, who led the Continental Army to victory in the American Revolutionary War, presided at the Constitutional Convention of 1787, and was the first president of the United States.

Teachers in schools may focus on student projects around our US Presidents and the dawn of our Republic. A form of government in which “supreme power is held by the people and their elected representatives”.

This day of pause, celebration or study of history shall also include a tribute to all of our “First Responders” across our great nation. Those men and women on the front lines of our democracy that are always on watch. Those who are in action each day, to defend our freedom and our Republic from disasters and evil.

As the pace of the economy across the globe includes new inventions, new technology and new laws; our governments must work in synchronized step with all of our First Responders.

Those individuals who are consistently scanning the horizon, analyzing dashboards of continuous streams of new sensor data, researching the changes in our respective environments and Areas of Responsibility (AOR) to better understand.

Yet these individuals require more. The First Responders who 24 hours x 365 days are continuously Understanding, Making Decisions and Acting in order to address the continuous integrity and constant peace of our great nation, require more.

"Our U.S. First Responders require a continuous set of resources, innovative new tools and training to apply the leading solutions for the United States security, response and resilience. From Liberty Crossing to NORAD. From Pennsylvania Ave to Pacific Coast Highway.
How might a small group of First Responders gather in a particular geographic area of our country to research, develop and deliver new valuable innovations to protect our Republic?"

How might we include industry and academia in an acceleration of information exchange and testing of new prototypes?

One good example is the Advanced Naval Technology Exercise (ANTX) that is again taking place primarily in Southern California over the next six months. Activities will focus on the examination of capabilities by public and private sector stakeholders in the following areas:

  • 
Critical infrastructure security, threat mitigation, and incident response
  • 
In-service engineering, maintenance, and sustainment of surface fleet and expeditionary combat systems
  • Port and maritime domain awareness, data fusion, and decision support
  • 
Augmented and virtual reality modeling, simulation, and digital engineering
  • 
Unmanned systems applications, implementation, and countermeasures

Yet whether we are creating new learning environments for our First Responders on Land, Sea, Space and Cyber domains, we shall always remember.

On this Presidents Day 2022, Americans who are true First Responders will continuously seek out new opportunities to learn more.

They will collaborate to test and innovate their own new ideas and inventions to preserve our Republic. To make their own neighborhood even more safe and secure.

They will act with bravery and their own fortitude, just as George Washington did and all those who have followed him…

09 August 2020

Intelligence-led Investigations: DecisionAdvantage...

"Whoever wishs to foresee the future must consult the past; for human events ever resemble those of preceding times. This arises from the fact that they are produced by men who ever have been, and ever shall be, animated by the same passions, and thus they necessarily have the same results." --Machiavelli

Operational Risk incidents are surrounding us on a global basis. The continuity of operations in the rescue and relief efforts in Beirut. The security of privacy information and Internet politics with Google and 3+ other global companies. A growing threat while Islam converts continuously flock from across the globe, to conflict zones. The economic integrity of global banking with new rule-sets and continuous funds transfer oversight.

All of these Operational Risk Management (ORM) challenges, require the same intelligence-led investigations, to establish the ground truth and then to enable an effective "DecisionAdvantage."

When does information that is collected, become a violation of a persons privacy or legal rights? At the point it is collected from a source or at the point in time when it is analyzed by a human?

Intelligence-led investigations today include the use of Artificial Intelligence (AI) automated Internet Bots, to troll the Internet and Open Source content (OSINT) for the collectors to find what they are looking for. This begins with a hypothesis and then the development of an algorithm, to carry out the automated mechanism for collection.

These Intelligence-led investigations also include the use of new forensically sound methods and proven procedures for collection of digital data, from a myriad of technology platforms including laptops, IoT's and cell phones.

These methods have been proven and certified in the forensic sciences for decades and follow many of the legally bound and court tested rules associated with evidence collection, preservation and presentation.

Digital Forensic tools and 21st century capabilities enable global enterprises, law enforcement and governments to not only discover what they are looking for, but to use this in a court of law to verify the truth.

The monitoring and collection of information associated with people begins various intersections with the context, relevance and legality of storing it, analyzing it and when to destroy it. What is at stake?  The ability to do this effectively inside the walls of the global enterprise corporate headquarters, the Regional Fusion Center or buildings off Rt. 123.

"DecisionAdvantage" is a term that promotes the connotation of competition, safety or defeating an adversary, yet only one will apply as you begin to understand the environment and the circumstances under which information is being utilized for one or the other.

If you are making decisions on the most safe and ideal drop points for water, food and medical triage supplies in a Middle East or an African nation, decisions are being made with information collected from satellites, humans, and perhaps the national geological scientists at CalTech.

It isn't until you take all of these elements into context and establish relevancy with human brainpower, that you will make an informed decision to give you an advantage of improved safety and security to achieve your objectives.

Investigators or Analysts are leveraging the use of 21st century software, hardware and telecommunications cloud infrastructure to more efficiently arrive at the answers,.  They utilize the hard hypothesis or questions being asked, and must improve their training, education and awareness to the associated human factors.

Predicting human behavior is difficult if not impossible.

What is more realistic is the utilization of AI systems to assist the human in trying to achieve "DecisionAdvantage".
"History, by appraising...[the students] of the past, will enable them to judge of the future." --Thomas Jefferson

10 August 2019

Fusion Center: A Top Line Opportunity...

Operational Risk Management (ORM) is about managing a jigsaw puzzle of vulnerabilities and threats, that expose those weak points in community or organizational operations.

How can a U.S. community such as Las Vegas, NV, Dallas, TX, San Bernardino, CA, Dayton, OH or El Paso, TX in concert with law enforcement, public safety, emergency management and private sector entities, embrace a collaborative process to improve intelligence sharing?

Together and ultimately, to increase the ability to deter, detect, and prevent domestic terrorism while safeguarding our homeland, sometimes you have to tell a story and create a narrative.

Fusion centers bring all the relevant partners together, to maximize the ability to prevent and respond to workplace violence, terrorism and other major criminal acts. By embracing this concept, these entities are able to effectively and efficiently safeguard our homeland and maximize anti-crime efforts.

Who knew, what and when?  Even before 9/11, the private sector has embraced the idea of "Fusion Centers" and for good reason.

It has often been labeled the Security Operations Center (SOC), that includes the convergence of both the physical and information-based risk management professionals, taking place to mitigate a spectrum of risks and new opportunities.
As a Board Director or Executive Committee member of your public or private organization, the economic reasons for doing this are many and the benefits of greater insight and more rapid response are a continuous mandate.
A fusion center is an effective and efficient mechanism to exchange information and intelligence, maximize resources, streamline operations, and improve the ability to mitigate internal and external risk events, by analyzing data from a variety of internal and external sources.

When you begin to coordinate the company departments or government entities, the rules of the game calls for agreements, contracts and memorandums of understanding (MOU).  These are required to help facilitate coordination and cooperation. Here are some of the elements that should be considered:
  • Involved parties
  • Mission
  • Governance
  • Authority
  • Security
  • Assignment of personnel (removal/rotation)
  • Funding/costs
  • Civil liability/indemnification issues
  • Policies and procedures
  • Privacy
  • Terms
  • Integrity control
  • Dispute resolution process
  • Points of contact
  • Effective date/duration/modification/termination
  • Services
  • De-confliction procedure
  • Code of conduct for contractors
  • Special conditions
  • Protocols for communication and information exchange
Regardless of how much planning goes into the establishment of the corporate or the public domain fusion center, the challenges are similar. Funding, resources and attention by the power base of leadership.

One way to keep the Fusion Center at the center of the CEO's or Mayor's daily progress review comes back to economics. The top line revenue discussions here are no different than the same arguments that the head of Marketing has for the advertising budget.  The bottom line.

The Chief Marketing Officer (CMO) is consistently getting a robust piece of the budget pie because they have done an effective job of convincing everyone that advertising/branding is what generates sales leads.

Sales leads convert to top line revenue. So the question is, how many dollars produce a sales lead and what is the ratio of the number of leads generated to the number that close new revenue business.

What is the argument for the head of the Fusion Center? How does this become a top line revenue opportunity and not just a cost?

The same way advertising is justified to create leads is the same way the Fusion Center creates a different yet equally valuable risk management lead.

In either case, the data and information required to generate a lead in advertising and to generate a lead in mitigating risk begins with a hypothesis.

At today's speed of business and commerce, both are generated from raw data and information either collected internally or purchased externally to the organization. The answer lies in the Information Economics analysis exercise of generating each and the value to the community and continuous operations of the organization.

In the end, you may find that both are equally important and now it's a matter of fine tuning the ratio of budget dollars devoted to the Fusion Center vs. the Marketing Department.

If you are a Chief Risk Officer (CRO), Chief Information Security Officer (CISO), or Chief Security Officer (CSO), the answer to consistently funding your Fusion Center just might be found in how timely data and information is utilized.

What is the true value to the continuous livelihood and resilience of your community or enterprise...

15 July 2018

Enterprise Risk: The Future of Public Private Partnerships...

When it comes to the overall Business Resilience in a city or geographic region, there are a plethora of Public Private Partnerships that have been in development for decades between government entities and the private sector.

The goal for some, is the simple exchange of information on relevant topics of community and local or federal jurisdictions. Others have a very distinct role and measurable outcomes designed into their structure, to achieve a mutual purpose. The Houston Ship Channel Security District is a rare example:
The Houston Ship Channel Security District, a unique public-private partnership, improves security and safety for facilities, employees and communities surrounding the Houston Ship Channel.
There are other Public Private Partnerships (PPP) that help address the safety and security of the United States, including the FBI's InfraGard program. This is an approach to engaging with private and public sector individuals in a region or sector of critical infrastructure, as opposed to a specific business entity.

The combination of an individual-based intelligence sharing organization of subject matter experts, combined with a more business owner-operator and city, county and state governments model, is one that needs continuous care and oversight to remain effective.

There are hundreds of other local and national models that converge on the goal of a true public private partnership, that never achieve excellence. They continuously miss the mark from several levels of information exchange, coordination, cooperation and collaboration.

These failed attempts at getting the private sector working in concert with government, still comes back to one key criteria for success; people. Regardless of whether you have the funding resources or not, a single or handful of motivated, dedicated and smart people, can and will make the relationship work.

Simultaneously, people can also be the roadblock, the resistance or the problem in getting a public private partnership working as effectively as it could be, to achieve the mission. This is when the mechanisms of governance, oversight and common sense are needed to guide the respective initiatives and operations of the entity either public or private, in the right direction.

You only have to look at the leadership in many cases to understand why there is continuing success in achieving SMART objectives or why there is failure. Service before self-interest is what becomes a major facet of why many of these organizations perish and then you have to examine who is really the beneficiary of the work being done by these dedicated volunteers.

Another effective public private example is the Intelligence National Security Alliance (INSA):
"INSA provides a nonpartisan forum for collaboration among the public, private, and academic sectors of the intelligence and national security communities that bring together committed experts in and out of government to identify, develop, and promote practical and creative solutions to national security problems."
When you are able to converge the thought leaders from a particular vertical discussion area, to produce the best thinking on an Operational Risk topic, the output is extraordinary. The key is to keep these same set of thought leaders together long enough and often enough, for the trust factors to build and for the true sense of collaboration to emerge.

INSA has accomplished this with the "Homeland Security Intelligence Council". Formed in 2010 and now renamed the "Domestic Security Council" and working continuously on a monthly and even bi-weekly basis, they have produced several valuable outcomes from their work together. One example is the white paper produced soon before the tenth and also the fifteenth anniversary event of 9/11.

Homeland Security Intelligence is a discipline that depends on the successful fusion of foreign and domestic intelligence to produce the kind of actionable intelligence necessary to protect the homeland. INSA is one private private organization that realizes this more than others.
The key to public private partnerships in the U.S., the "Enterprise" is not just government when it comes to intelligence and situational awareness. One only has to look at the number of iPhones and camera enabled devices being carried around by hundreds of millions of people to understand this today. Social Media and global real-time information discovery will remain our continuous situational awareness challenge.

The private sector companies, who in many cases are the owners of critical infrastructure assets in the nation remain the power base. The willingness or reluctance to share the right information at the most appropriate time from government and combine it with private sector capabilities, will always be the largest challenge for the public private enterprise going forward.

15 April 2018

Social Strategy 140: Direct Action #Risk...

Twitter real-time direct action (DA) "Information Warfare" between nation states is a daily task. Current and future Operational Risk Management (ORM) priorities will encompass the imperative to staff "Corporate Intelligence Unit" Fusion Centers.

A prudent Operational Risk strategy, shall include a "Big Data" capability combined with deep social intelligence analysis. Here is a historical FLASHBACK in time, to one example of why leadership is devoting new resources and investment to these internal risk management capabilities:
New Diplomatic Avenue Emerges, in 140-Character Bursts
By SOMINI SENGUPTA October 3, 2013
UNITED NATIONS — "Countries all over the world, dictatorships and democracies alike, have in the last few years sought to tame — or plug entirely — that real-time fire hose of public opinion known as Twitter. 
But on the sidelines of the General Assembly meeting over the last couple of weeks, ministers, ambassadors and heads of state of all sorts, including those who have tussled with Twitter the company, seized on Twitter the social network to spin and spread their message. 
At the height of the diplomatic negotiations last week over a United Nations Security Council resolution that would require Syria to turn over its stockpile of chemical weapons, the American ambassador to the United Nations, Samantha Power, used Twitter to preempt criticism of the measure as lacking teeth because it had no automatic enforcement provision."
What does this mean for the global enterprise, who circumnavigates the planet to initiate and manage daily business operations?  It means that "Information Warfare" and intelligence collection and analysis for the enterprise continues, as a top strategic and operational function.  It requires continuous Operational Risk strategy oversight.

How an organization directs personnel and manages daily decisions, is more mobile information-centric than ever before.  Just stand at any major sidewalk intersection in a major city across the world and count the number of people looking at their "Smart Phones" as they cross the street.

The speed of business that is fueled by leaders commenting via social media, can even influence commodity traders in futures markets and operational planners in the "E-ring."

Leadership has the ability to by-pass the traditional media juggernauts to get their message heard in seconds.   The President of a major stock exchange or of a G20,  has a "Duty of Care" to it's constituents to make the correct public decisions.  At the same time, a moral and ethical context begins to evolve, in the vast battle space of 140 digital characters.

The use of a social media post or Tweet from the Board Room to the Court Room; from San Francisco to Tehran, or from Wall Street to Hong Kong, is a risk-oriented asymmetric information tactic delivered in plain sight.

Those social tactics, visual in the landscape of our modern day quest for influence, notoriety or outcry, shall forever shape the breadth of our enterprise digital risk management spectrum...

13 January 2018

Situational Awareness: Reality in ORM...

Situational Awareness has always been a key factor in effective Operational Risk Management and Real-Time Incident Command.

Situational awareness (SA) involves being aware of what is happening around you to understand how information, events, and your own actions will impact your goals and objectives, both now and in the near future. Lacking SA or having inadequate SA has been identified as one of the primary factors in accidents attributed to human error .

What you know and when you know it, can make the difference between life and death in the context of real-time emergency management and tactical response operations.  However, it can also provide you with the intelligence you need to save lives and avoid new risks as a more sudden and real-time threat unfolds.

Whether it's the active shooter, disgruntled employee or an international hotel under siege, it should not matter. Let's take a minute and look at a sample time line on the Mumbai attacks in India November 26th, 2008 as one example from a situational report:
  • Two terrorists have barricaded themselves in the Oberoi Hotel; 3 dead and 25 injured. 11/26/08 10:31 PST
  • Terror strikes at 12 places in Mumbai. Up to 20 hostages held at Oberoi Hotel. 11/26/08 11:57 PST
  • Several British and American civilians among hostages at two hotels. Explosion reported at Taj Hotel. 11/26/08 13:59 PST
  • Explosions and fire reported at Oberoi Hotel; clashes continue in multiple locations across Mumbai. 11/27/08 07:23 PST
  • Indian elite commando chief is reporting that the Oberoi-Trident Hotel has been cleared of terrorist threat. 11/28/08 01:03 PST
  • Counter-terrorism operations declared over; at least 195 killed in attacks. An investigation is underway. 11/29/08 16:06 PST
Look at the time stamps and the lag time between each one. The person writing these bullets for a "Flash" message to subscribers or people asking for text based updates, was either not using all of the potential assets available to them, or they just did not think there was any relevance of the other information unfolding. This example of 2008 "Situational Awareness" reporting is not only dangerous and a thing of the past, it's letting the "Grey Matter" get in the way.

So what about the public? Is Periscope and #NEWS hash tags the answer?

The problem with most "Situational Awareness" capabilities is that the subject matter experts, commanders in the SOC/NOC, or the business CEO 2,000 miles away, are letting the "interpreters" on the street in the heat of the crisis, determine what is important. The second issue and until the past few years, is that the information is not "Real-Time":

Seamless and secure tracking and communication among mission planners, field personnel, and central command elements are essential to mission success. Raytheon's Blackbird Technologies Gotham™ system is a comprehensive back-end solution for monitoring, operating, and managing tagging, tracking, and locating (TTL) devices and viewing associated geospatial data. 

A Common Situational Picture for Military and Emergency Operations


With the ability to track assets and targets — and to communicate with team members and devices — Gotham enables networked team decision-making, control of resources, shared resource dispatching, and adaptability to change based on operational requirements.

In a disaster, communication among emergency responders and control of needed assets are vital to the safety and security of personnel and the public, as well as the effective execution of the disaster response mission.


Your Operational Risk Management tool box is now enhanced.  Pay it forward...

02 December 2017

Situational Awareness: Battlefield to Board Room...

Creating a "Common Operational Picture" for your organization is an elusive yet attainable goal for your senior management and the Board of Directors. How at a moments notice does the organization provide leadership with the answers to Operational Risk questions such as:
  1. How many employees from our company are currently traveling outside your home country?
  2. What are their modes of transportation and where do they plan to stay each night?
  3. What employees from our "Red Zone" list have left the company in this past week?
  4. How many of these employees left suddenly without any warning?
  5. What employees were asked to resign or were fired from their position?
  6. What controls have failed in the process for closing deals within our standard time period?
  7. How much has our sales pipeline increased or decreased over the past quarter?
  8. What is the total number of network access points (Points of Presence) our company currently believes are available for employees to connect to the Internet?
  9. How many known incidents occurred over the past week related to malicious software attacks or Denial of Service attempts on our network?
  10. How many employees started work with the company who have been added to the "Red Zone?"
  11. What are the names of the local liaison officials for our water, power, telecom and data carrier suppliers? Who is their deputy?
  12. How often has the company exercised a plan for major business crisis or disruption in the past year?
  13. What is the current forecast for severe weather in the corporate headquarters region in the next week?
These questions and more should be able to be answered at a moments notice. Any senior manager or member of the Board of Directors should have an information dashboard they can view with these situational awareness questions at their finger tips.
If you don't have the latest Operational Risk Quotient in your enterprise it may be a clear indicator that the people, process, systems or external events are a severe threat.The corporate landscape or battlefield if you will requires that the commanders in the field have the intelligence they require to make split second decisions.
These Directors, Managers, Supervisors that drive the business forward each day need leadership to give them split second answers, especially in the midst of a crisis. There is not time for a Q & A session or for an extended report to give leadership the view they need to steer the enterprise out of harms way.

Operational Risk Managers rely on a combination of real-time feeds from internal sources and outside the organization to provide this level of situational awareness. CCTV feeds, access controls, intrusion detection, and many more are part of the Corporate Intelligence Unit's own Fusion Center.

Why is this a prudent business practice to assist you in "Achieving a Defensible Standard of Care" for your employees? Because without it you are flying blind and trying to operate without the awareness and predictive ability to mitigate risks as they unfold before you.

Whether it is on the battlefield or your own organization does not matter. Your people need to understand their role in providing this vital aspect of the risk management solution. Without hourly by the minute or second intelligence about your people, processes, systems and external events you are destined for a future either known or unknown. You make the choice.

20 August 2017

Alternative Analysis: Intelligence-Led Methodologies...

Operational Risk Management (ORM) is about the consideration of past failures and the possibility of unknown future failures of people, processes, systems and external events. The analysis of the likelihood and implications of those loss events, requires different methodologies to assist in the mitigation strategies to prevent or avoid the risks of failure. In light of the nature and complexity of transnational asymmetric threats, this requires the use of alternative methods of analysis.

Intuitive decision making and sense-making— can be combined into a framework for categorizing the residual thought processes of intelligence analysts. This is called "intelligence sense-making".

This process involves the application of expertise, imagination, and conversation and the benefit of intuition without systematic, consideration of alternative hypotheses. Compared to traditional methods of analysis, intelligence sense-making is continuous rather than discrete, informal rather than formal, and focused more on issues that don't have normal constraints.

Employing alternative analysis means that you can't “afford getting it wrong” and then you challenge assumptions and identify alternative outcomes. However, it may be of little use in today's growing non-state transnational threats and for ongoing criminal enterprise complexities. This is because there are so many considerable outcomes, consistent and perpetual changes, and contingencies for any single risk management process to be effective all the time.

Web-logs 3.0 are the future for some effective transnational alternative analysis. Combined with such machine learning threat intelligence systems such as Recorded Future, the open source analyst can operate with increasing pace and context. Unlike more formal published papers, intelligence Web-logs are a more free flowing “unfinished” production, whereby both human intuitions and more formal arguments are posted, and then challenged by those with alternative ideas.

Indeed, Web-logs are the mechanism for a facilitated contextual dialogue— the electronic equivalent of out loud sense-making.
"On September 11th, about half of the hijackers had been flagged for scrutiny at the gate before boarding the ill-fated flights. Had the concerns of the Phoenix FBI office about flight training not only been shared broadly within the government but also integrated into a mindfulness-focused inter- agency process—featuring out loud sense-making, Web-log type forums, computer-generated references to extant scenarios for crashing airplanes into prominent targets—might at least some of the detentions been prolonged, disrupting the plan? --“Rethinking ‘Alternative Analysis’ to Address Transnational Threats,” published in Kent Center Occasional Papers, Volume 3, Number 2.
In our modern day era of Twitter, Facebook and "Crowd Sourcing" technologies perhaps the tools are already in place. Platforms such as Ushahidi are geocoding the information origin, providing ground truth situational awareness and providing context on issues that are unbounded. How often does the published press currently use these tools to get their original leads, potential sources or new ideas for a more formal story? This story then takes on the formal journalistic requirements for confirmation from trusted and vetted sources, before it makes the final deadline and is delivered on printed paper to our doorstep each morning.

The doctrine of analysis for transnational threats and homeland security intelligence, are still evolving in this accelerating digital ecosystem. The alternative methods and tools that we will utilize to examine, refute or justify our thoughts remains endless. The degree to which we are effectively operating within the legal rule-sets for our particular country, state or locality, remains the ultimate privacy and civil liberties challenge. These respective governance guidelines particularly with regard to intelligence record systems and liability issues, must remain paramount:
  • Who is responsible for entering information into the Intelligence Records System?
  • Who is the custodian of the Intelligence Records System that ensures all regulations, law, policy and procedures are followed?
  • What types of source documents are entered into the Intelligence Records System?
  • Does the retention process adhere to the guidelines of 28 CFR Part 23 in the United States?
Finally, community-based policing has developed skills in many law enforcement first responders, that directly support new domestic counterterrorism responsibilities. Intelligence-led policing (ILP) provides strategic integration of intelligence, into the overall mission of the larger "Homeland Security Intelligence" enterprise. It involves multiple jurisdictions, is threat driven and incorporates the citizens of the community to cooperate when called upon, to be aware of your surroundings and report anything suspicious.

So what types of information do street officers need from an Intelligence Unit?
  1. Who poses threats?
  2. Who is doing what with whom?
  3. What is the modus operandi of the threat?
  4. What is needed to catch offenders / threat actors?
  5. What specific types of information are being sought by the intelligence unit to aid in the broader threat analysis?
Alternative analysis is designed to hedge against human behavior. Analysts, like all human beings, typically concentrates on data that confirms, rather than discredits existing hypotheses. Law enforcement is constantly focused on the key evidence to prove who committed the crime.

Alternative analysis shall remain part of the intelligence tool kit, for more formal policy level work. Imagine the use of Intelligence-led methodologies such as "intelligence sense-making" combined with secure Web 3.0 collaborative applications, at the finger tips of our Homeland Security first responders. Now think about that "lone wolf" or "sleeper cell" lying in wait.

Proactive and preventative risk management requires the right tools, with the right information in the hands of the right people.

23 October 2016

Intelligence-led Enterprise: CIU Success Factors...

Intelligence-led processes applied within the corporate global enterprise, continues its relevance for reasons being published in the popular press. "Operational Risk Management (ORM) Specialists" utilize these processes, to mitigate a growing spectrum of domestic and transnational threats:
Developing relevant intelligence to run daily business decisions in your institution may seem like an important task day to day. The question is, how embedded is the "Corporate Intelligence Unit" in developing the relevant intelligence your decision makers need every few minutes or hours to steer the organization away from significant losses? Is your internal web-enabled "Corporate Daily News" or "ABC Company Post" being updated in real-time by the employees in each department or business unit?
Do you have an organized, synchronized media and communications function working within your Corporate Intelligence Unit (CIU), to continuously post the correct content and manage the RSS feeds from each global business unit? Why not?
The "Information Operations" (IO) of your company are the lifeblood of how your employees will make relevant decisions on where to steer clear of significant risk.  Based upon what other business units are doing or what is going on in the external environment of your state, sector or geography, consider these scenarios:
If the internal RSS Feed for the IT department reported that there was a Distributed Denial of Service  (DDos) Attack going on at the moment, how might that impact the decision by the marketing department to delay the posting of the new product release information to the Twitter site? The synchronization of intelligence-led processes is lead by the head of the Corporate Intelligence Unit. The CIU is staffed with people who have a tremendous understanding of the corporate enterprise architecture and have the skills and talents to operate as effective operational risk management professionals.

If the internal RSS Feed for the Facilities Security department reported the presence of a "White Truck Van" with blacked-out windows trolling the perimeter of the corporate parking lot, how might this change the decision for the CEO to leave that minute for her scheduled trip to the airport? Skilled CIU staff within would quickly notify the CEO via the "Corporate 9-1-1 Alert" App embedded in every employees iPhone. Under cover corporate security personnel would then be immediately approaching the vehicle for a recon drive by.

If the internal RSS Feed reported the recent change in industry legislation that would change the way the Federal Trade Commission defined the elements regarding consumer privacy, how might this affect the latest strategy on how the institution was going to encrypt it's data in servers and on laptops? The CIU staff would advise the Chief Information Officer and other Information Security Risk staff to step up the roll-out for the latest version of PGP for the enterprise.
And the list goes on. The modern day intelligence-led Corporate Intelligence Unit (CIU), in concert with other highly specialized Operational Risk Management professionals in the enterprise can keep you safe, secure and keenly aware of new threats to your corporate assets. The degree to which you provide the right resources, funding and continuous testing/exercising of your capabilities will determine your likelihood for loss outcomes.

If your organization has been impacted by loss outcomes that continuously put your employees, stakeholders or assets at risk, then look hard and deep at your "Operational Risk" quotient, to determine if you are the best you can be...

23 July 2016

ECPA: Reality of Homegrown Violent Extremism...

In the United States, Operational Risk Management Executives in the private sector are consistently balancing the legal requirements for public safety and their customers right to privacy. The Internet Service Provider (ISP) General Counsel's duty to facilitate the rule of law within the private sector organization, has been on a collision course with protecting the homeland for over a decade since 9/11.

One of the critical tools for Homeland Security Intelligence (HSI) is the "Electronic Communications Privacy Act (ECPA) and for good reason. The law provides the tools for law enforcement and national security intelligence analysts while simultaneously protecting the privacy interests of all Americans. In a 2011 statement before the Committee on Judiciary, United States Senate, Associate Deputy Attorney General - James A. Baker outlines the basis for ECPA:
"ECPA has never been more important than it is now. Because many criminals, terrorists and spies use telephones or the Internet, electronic evidence obtained pursuant to ECPA is now critical in prosecuting cases involving terrorism, espionage, violent crime, drug trafficking, kidnappings, computer hacking, sexual exploitation of children, organized crime, gangs, and white collar offenses. In addition, because of the inherent overlap between criminal and national security investigations, ECPA’s standards affect critical national security investigations and cyber security programs."
The criminal elements and their organized syndicates are leveraging modern day technologies and capabilities of the private sector. The legal first responders for our 21st century homeland threats don't always wear a badge and drive a Crown Vic on patrol around our city streets. Many spend their hours on patrol in cyberspace or analyzing terabytes of data online with sophisticated software to determine the what, who, why and how of the current threat stream.

The US government has a fiduciary and legal duty to protect the privacy and civil liberties of all US citizens. Parallel to this task is the rapidly changing use of communications and other mobile technologies to facilitate and support the activities and operations of individuals and networks of people, who exploit the design, configuration or implementation of our countries homeland defense architecture.

Whether this architecture includes the utilization of 72 Fusion Centers or the methods for collecting "Suspicious Activity Reports" (SARS) from those first responders, the fact remains that the pursuit of national security threats is a lofty task. This is happening today, on the ground and in the digital domain. Therefore, the speed that these individuals can legally obtain the data they require to make informed decisions is at stake and so we must eliminate any new impediments put before them. From Mr. Bakers statement on "Government Perspectives on Protecting Privacy in the Digital Age" he explains further:
Addressing information associated with email is increasingly important to criminal investigations as diverse as identity theft, child pornography, and organized crime and drug organizations, as well as national security investigations. Moreover, email, instant messaging, and social networking are now more common than telephone calls, and it makes sense to examine whether there is a reasoned basis for distinguishing between the processes used to obtain addressing information associated with wire and electronic communications. In addition, it is important to recognize that addressing information is an essential building block used early in criminal and national security investigations to help establish probable cause for further investigative techniques. Congress could consider whether this is an appropriate area for clarifying legislation.
Any changes to the ECPA laws should be considered carefully with not only the government but the private sector. The combination shall work together to find the correct balance between national security requirements and the privacy of the customers of mobile communications, e-mail, and social networking entities. The time that it takes our first responders to rule-in or rule-out a person of interest in an ongoing investigation can mean the difference between a failed or successful attack on the homeland. The private sector shall determine the prudent cost to the government for providing the legally obtained information of non-telephone records such as a name, address and other metadata. By the way, has anyone noticed that the criminals, terrorists, spies and other malicious actors have decided to use Telegram, or WhatsApp instead of their mobile telephone?

Homeland Security Intelligence (HSI) first responders will be the first to tell you that the crime syndicates and non-state actors have gone underground and have stopped using the tools that leave the data more easily accessible by law enforcement. Now, they are creating and operating their own private and secure infrastructures within the confines of private sector companies. These clandestine groups have organized hierarchy and specialized skills and therefore, the US government must continue to step up the pace, legally.

What does this all mean? It means that there will be a lower chance of under cover law enforcement officers becoming members of the these organized crime syndicates that in many cases are the genesis for homegrown violent extremism (HVE).

Homegrown extremists can be individuals who become violently radicalized, perhaps after exposure to jihadi videos, sermons and training manuals available on the Internet, security officials say. Such plotters are harder for counterterrorism officials to spot because they have few links with known terrorist operatives and often don’t travel overseas for training.


Another implication is that there is a higher chance that private sector researchers will understand the new trade craft of HVE actors, long before law enforcement and national security intelligence analysts. This is because the standard approach to the "Seven Signs of Terrorism" have been focused on the physical infrastructure. Organizations in the private sector have been researching, tracking and profiling since the late 1990's on the methods and modus operandi of the digital extremists who have plagued our banks and other financial institutions with cyber crime.

The time is now for these two distinct disciplines and professionals to converge. The public as eyes and ears combined with the legal tools to extract the timely information from technology providers is part one. Part two is the integration of intelligence analytic training with the curriculum of the police and fire academies for new recruits. Providing these first responders with the methods, tools and capabilities to be more effective collectors on the street level, will provide the fusion centers with a more robust set of relevant information streams. Here is an example from a graduate certificate class in criminal intelligence analysis from AMU:

The graduate certificate in Intelligence Analysis provides you with a fundamental understanding of the issues, problems, and threats faced by the intelligence community. This online graduate program helps you develop a comprehensive knowledge of how intelligence agencies in the U.S. assess and counter international threats in order to guard U.S. global interests and protect U.S. national security from adversaries. Knowledge from this certificate program is applicable to many career fields within the military, security companies, government contractors, or federal agencies.

We have a choice to provide our first responders with the correct training and OPS Risk education for today's Homeland Security Intelligence (HSI) mission. Our national policy makers have a choice to assist them in getting the information they need to do their jobs quickly, efficiently and while protecting civil liberties. The choices that we make fifteen years after 9/11, will define the landscape for homegrown extremism and the legal framework for ensuring the safety and security of all Americans for years to come.

20 February 2016

Predictive Intelligence: Data or Precogs...

The use of the term "Predictive Intelligence" has been around for a few years in the Operational Risk Management (ORM) community.  Born from the marketing collateral of the Business Intel (BI) vendors, it essentially requires hundreds of gigabytes or even terabytes of historical data and then is analyzed or data mined for so called insight.  The question is, why is this "Predictive Intelligence" and not just more "Information" in a different context?

Now introduce the nexus of our own "Trust Decisions" and the "Human Factors" associated with the science of cognitive decision making.  How do we as humans make our decisions to trust vs. how computers make their decisions to trust?  Are they not executing rules written by humans?  When is it information in a different format as opposed to true intelligence?

Christian Bonilla may be on to something here:
"Professionals in the foreign intelligence community take pains to distinguish between information and bona fide intelligence. Any piece of knowledge, no matter how trivial or irrelevant, is information. Intelligence, by contrast, is the subset of information valued for its relevance rather than simply its level of detail. That distinction is often lost in sector of the enterprise technology industry that is somewhat loosely referred to as Business Intelligence, or BI. This has become a bit of a catchall term for many different software applications and platforms that have widely different intended uses. I would argue that many BI tools that aggregate and organize a company’s information, such as transaction history or customer lists, more often provide information than intelligence. The lexicon is what it is, but calling something “intelligence” does not give it any more value. In order to sustainably outperform the competition, a company needs more than a meticulously organized and well-structured view of its history. Decision makers at all levels need a boost when making decisions amidst uncertainty and where many variables are exerting influence. They need what I would call predictive intelligence, or PI – the ability to narrow down the relevant variables for analysis and accurately measure their impact on the probability of a range of outcomes."
What does the fusion of human factors have to do with predictive intelligence?  That depends on how much you value the kind of innuendo and messages in the Tom Cruise movie, Minority Report.  Many aspects of the original Philip K. Dick story were adapted in its transition to film that was filmed in Washington, DC and Northern Virginia.  Is it possible to predict someone's future behavior even before they commit a crime or even become violent?
Set in the year 2054, where "Precrime", a specialized police department, apprehends criminals based on foreknowledge provided by three psychics called "precogs".
Cruise plays the role of John Anderton who is part of the experimental police force known as "Precrime."  These aspects of clairvoyance and precognition has many skeptics and their use for predicting future events or a related term, presentiment, refers to information about future events which is said to be perceived as emotions.
Regardless of terms, beliefs or whether the software analytics are using historical data, the science of "Predictive Intelligence" is about forecasting the future.  Based upon the recent global events that missed the forecast of economic implosion based upon historical data, maybe it's time to start introducing more human factors to the equation.

The interviews with people who have gone on record to predict a future historical event will probably be right at some point in time. How long will you be around to wait?  The demise of the banking sector and the extinction of Lehman Brothers, Bear Stearns and maybe even AIG were most likely predicted by someone, somewhere in 2007/2008 time frame.  The point is that you have to have context and relevance to the problem being solved or the question being asked.
The real story of the crash began in bizarre feeder markets where the sun doesn't shine and the SEC doesn't dare, or bother, to tread: the bond and real estate derivative markets where geeks invent impenetrable securities to profit from the misery of lower--and middle--class Americans who can't pay their debts. The smart people who understood what was or might be happening were paralyzed by hope and fear; in any case, they weren't talking.
Predictive analytics extracts relevant information from data and attempts to forecast the future. It relies on capturing relationships between explanatory variables and the predicted variables from past occurrences, and exploiting it to predict future outcomes.  Is it possible that there was and is too much reliance on the numbers and not enough on people's cognitive intuition?

This blog has documented the "11 Elements of Prediction" in the past.  Now it's time to utilize the combination of these human factors in close collaboration with the data analytics and raw numbers. Effective execution of both will provide corporate management the situational awareness they seek within the time line they wish.

The future state of Predictive Intelligence will combine the science of "Trust Decisions" with the art of "Data Analytics" to achieve our desired outcomes.

25 October 2015

4GW: An Act of Valor in the Private Sector...

Fourth Generation Warfare (4GW) is a stark reality in 2015 and beyond. Are American business interests as prepared as they could be, for the growing Operational Risks in the 21st century?  How many employees do you now have working outside the Homeland?

4GW involves the following key elements:
  • Are complex and long term 
  • Terrorism (tactic) 
  • A non-national or transnational base—highly decentralized 
  • A direct attack on the enemy's culture 
  • Highly sophisticated psychological warfare, especially through media manipulation and lawfare
  • All available pressures are used - political, economic, social and military 
  • Occurs in low intensity conflict, involving actors from all networks 
  • Non-combatants are tactical dilemmas 
  • Lack of hierarchy 
  • Small in size, spread out network of communication and financial support 
  • Use of Insurgency and guerrilla tactics
There are a number of methods that a private sector company can utilize to exercise its own "Business Continuity Plan" in concert with the public sector here in the United States.  Operational Risk Management (ORM) associated with people, process, systems and other potential external events can be shared with local first responders, to establish awareness or alert protocols with your particular organizations incidents. As a private sector business, you should be asking yourself how often your internal incident commanders visit your local fire station or police precinct, to share mutually relevant information. Do you invite these vital community preparedness and response professionals to engage in your own company "Continuity of Operations" and crisis planning and exercises, even if it is just a table top review?

Through public-private collaboration, government and the private sector can:
  • Enhance situational awareness 
  • Improve decision-making 
  • Access more resources and capabilities 
  • Expand reach and access for disaster preparedness and relief communications 
  • Improve coordination 
  • Increase the effectiveness of emergency management efforts 
  • Maintain strong relationships, built on mutual understanding 
  • Create more resilient communities and increase jurisdictional capacity to prevent, protect against, respond to, and recover from major incidents 
Around the country there are certain metro areas that have annual readiness and preparedness exercises because of where they are located. In some cases there are federal laws that mandate these exercises such as seaports. Norfolk, VA, Houston, TX or even the only deep water port between Los Angeles and San Francisco; Port Hueneme, CA have annual tests of their readiness and resources. Each of these seaports are significant assets to our continuous economic well being. They are surrounded by the private sector businesses who supply them with fuel, electric utilities and other critical infrastructure components that play their vital role in these regions.

Beyond the ability for these private sector organizations to engage with local first responders to exercise their continuity planning, is the ability to test new technologies, methods and even research possible ways to improve overall resilience, on a spectrum of new found asymmetric threats. These tests determine our ability to adapt or to utilize new tools in our current 4GW environment. We must remain adaptive during irregular operations by small insurgent groups such as those that have occurred in Mexico, Mumbai, India or the growing real possibility of devastating cyber attacks to our energy and telecommunication sectors.

Why are we encountering these threats on a higher frequency around the globe? You only have to look as far as the foreign published press to find the answer to this question. Or if you haven't got the time to read and translate to your native language what is being said, then make sure you see the movie "Act of Valor" to better understand what lies before us. What follows is from a foreign press article:
"The inability of the majority of the world's countries in the current circumstances to fight globalization's most powerful military machine (primarily the United States) on equal terms has led in recent years to an increase in the number of terrorist acts, armed conflicts, and local wars. Their coalescence into a single antagonistic system is giving rise to a phenomenon designated asymmetric operations by military-political theoreticians (asymmetrical conflicts and even asymmetric wars)."
As a result, we must adapt. The Naval Postgraduate School (NPS) has several educational, training and research centers that are dedicated to the readiness of the military and to the public private partnership mechanism in the United States. The one center that stands out to help us become more adaptive on small conflicts and irregular activities is "The Center for Asymmetric Warfare (NPSCAW)."
The Center for Asymmetric Warfare, or CAW, was established in 1999 as a part of the Naval Air Systems Command to support U.S. military forces, as well as local, state, and federal organizations, in identifying, countering, and controlling the effects of asymmetric warfare in the nation’s Global War on Terrorism. CAW’s initial focus was the development and conduct of multi-agency, multi-jurisdictional homeland security and homeland defense exercise and training programs, in addition to test and evaluation programs for developmental first response technologies. 
Since its inception, CAW has matured into a recognized leader in its field, by providing comprehensive education, training, and exercise programs; technology integration, test, and evaluation programs; and capability assessment and improvement programs to partners across a wide spectrum of jurisdictions. These programs include participation by Department of Defense; local, state, and federal government agencies; private sector and non-governmental organizations; academia; and international government agencies. 
In 2008, CAW was realigned as a satellite division of the Naval Postgraduate School’s National Security Institute, headquartered at Naval Base Ventura County, in Point Mugu, California. Harnessing the capabilities of the four institutes and four schools that comprise NPS, CAW can capitalize on the expertise and experience of a continuously expanding number of alumni, faculty, and students.
The U.S. private sectors proximity to high value targets are many times overlooked. Where on the West coast of the U.S., is the largest concentration of undersea telecom cables coming ashore? You might guess San Francisco or Seattle. Think again. This map will give you an idea what areas of the coastline could be more important to protect and to continuously prepare for, a future attack on these assets. The answer is San Luis Obispo.

As an Operational Risk professional in your private sector organization, make it a priority to get engaged with your local community. Visit your local first responders soon. Reach out to the Regional Fusion Center and other entities designed to facilitate a smooth information sharing process.

This should occur with government and the most valuable assets owned and operated by our private sector constituents. It all comes down to two words. Continuous Vigilance.