Showing posts with label Predictive Intelligence. Show all posts
Showing posts with label Predictive Intelligence. Show all posts

19 June 2026

Proactive: Acting in Participation...

How have you demonstrated your “Proactive” abilities this month?

Before you found your calling, were you spending wasted hours on social media or sitting places all alone.

After you became “Proactive,” the life changes were extraordinary and purposeful.

So what is the definition of PROACTIVE: “Acting in anticipation of future problems, needs, or changes.”

Whether you have joined other fellow colleagues with your Non-Profit (501c3) volunteer organization placing or picking-up hundreds of American Flags on the head stones of the “Fallen” after Memorial Day USA.

  • Whether you have volunteered your days of time to help the Safety / Security presence at a Religious or Educational organization during an important service or meeting.
  • Whether you engaged with others to attend a “Stop The Bleed” course to learn how to save other's lives.
  • Whether you burned hours of your time for your Team on creating and planning an upcoming annual event for a thousand members.

How many Proactive hours of your time and expertise have you given free this month?

Being “Proactive” gives you the ability to learn new skills, meet new people and to provide valuable services to your community.

“People who tend to react to a problem only when it's gotten serious could be called reactive people. Until recently, reactive (in this sense) didn't really have an antonym. So proactive was coined to describe the kind of person who's always looking into the future in order to be prepared for anything.”

You see, this can provide you and your “Proactive Peers” with the heart felt satisfaction that you have a truly valuable purpose.

It provides you with the ability to engage with other like-minded individuals on the actions and the “Doing” that can truly make a difference in this world…

Godspeed!

05 June 2026

OSINT: If Intelligence were a Baseball Game...

What is Open Source Intelligence (OSINT)? Why is it important to your security and safety? How can you really understand how it is the same or different than other types of intelligence? Let's use this clever baseball analogy:


If Intelligence were a baseball game....

IMINT takes a picture every day or so, trying to discern whose winning from sporadic snap-shots at different times of day, different angles of look.

SIGINT tries to bug the dug-out and discern how the game is going from comments by the players

HUMINT tries to recruit the batter, find out where he thinks he is going to hit the ball, and send a spy out to catch it if it ends up there.

MASINT tries to smell the player's armpits and the arc of the ball from leather secretly treated beforehand.

OSINT gives everyone in the audience a baseball glove, and counts the ball out if anyone in the stands catches the ball.

What's the point? OSINT is not a substitute for spies, satellites, or secrecy. It simply takes all the low-hanging fruit off the table so the secret sources and methods can focus. Put simply, OSINT changes the rules of the game--eliminates all the "home runs" by the enemy that need not occur if we harness the distributed intelligence of the audience--and allows the secret sources and methods to focus more carefully on what's left inside the playing field.

So what? Open source intelligence is available to everyone at the touch of a button, Google and others. Intelligent bots troll the net in search of its target. Looking for the answer to the algorithim created to answer the question posed by it's designer. When it finds what it is looking for it brings it home to the clandestine machine with Petabytes of RAID.


The people behind the question look for a pattern. The question or hypothesis is there to accomplish an important task. To find some relevance in a vast sea of “Zeros and Ones” beyond the human brains capability to grasp. No one person owns it and has the ability to keep it secret, forever. Somehow, someone will put this information into the open. Then it becomes OSINT.


The race isn't about keeping information safe from being stolen or revealed to others. It's about something else:


Jeff Jonas, the one time chief scientist and distinguished engineer at IBM’s entity analytic solutions group, had developed a means of sharing corporate data without revealing what that data contains.

This technology, called anonymization, effectively "shreds" information, making it possible for companies to share information about their customers with governments or other companies without giving away any personal data.

Over time, Jonas believed companies will increasingly use anonymization to defend their data, and corporate well-being, from competitors and identity thieves.

This story to be continued…

16 May 2026

Liaison Mission: When Will You Introduce Them?

As a current Chief Executive Officer or Commander across some branch or agency, who have you named as a key "Liaison?"  Who is this vital person that you have asked to be your voice, your thinking and your representative to a partner, collaborator or strategic ally?

In Chris Fussell's book One Mission:  How Leaders Build A Team of Teams, the Task Force Liaison is described as follows:
"We clearly share a determined adversary--one that, unlike our organizations, is networked and thus moves with incredible speed. In the Task Force, we are now trying to forge a new type of model based on relationships among individuals and organizations like yours--and we'd like to be more closely connected with your organization. Winning will come from leveraging our mutual strengths, sharing insights and nuanced understanding of the problems and respecting one another's positions.

To help our partnership, we would like to give you one of our best people as a liaison. I expect our liaison to be an asset to you, sharing anything we're doing, providing our most timely intelligence, and seeking out ways that we can help your organization accomplish its goals."
This idea is not a new strategy per se.  Similar derivations of the concept have been utilized for hundreds if not thousands of years.  So why is this so important now, to the current state of global and corporate affairs?

The first reason is that operating at the speed of "iMessaging" social media, will create chasms of misunderstanding.  The simple fact is that information being collected, interpreted and disseminated in your digital-based platforms will most likely have gaps.  The messaging and communications will be hard to decipher by others, who don't know all of the acronyms as just one example.

This is where an embedded "Liaison Officer" or representative can bridge the cultures and the lines of direct messaging.  This is how the speed of the combined network is increased in it's ability to pivot, to adapt and to solve problems, faster and with higher quality than the competition.

The second reason is that a key mission of the nominated Liaison is to establish, maintain and perpetuate trusted relationships.  Otherwise, how can the leaders of your two organizations gain any momentum, in the quality and the speed of the partnership that is desired as a relevant outcome?

Now think about your own organization.  Where do you have a blind spot?  What other entity, team, business unit or agency is now seen as a barrier or competitor?  Are you both after the same customer, the same target or the same outcome?  Is a partnership in place now, to even embed or exchange Liaison personnel?

Believe us when we say that your adversary has already done the same.  They are working together across boundaries to share intelligence, to exchange vital data and to work in tandem to perpetuate their cause, their ideology or their campaign.  They have their own trusted Liaison's working each day, to move faster than you are and to achieve new gains in their mission, while you are worried about the unknowns.

Who is it in your organization that you feel that you can't live without?  The one or two leaders that you rely on each day.  The personality that exhibits the way that "Adam Grant" describes a "Giver" or "Matcher," in the way they operate across the team and within the company.  This may be the best person for you to let go of and to be your next "Liaison" to that vital partner, agency or even country.

Looking across the landscape of America, you will find examples of this idea and methodology that is working.  You will find places across the globe where it is in total failure.  Yet how can you raise the odds, that the likelihood of the person you choose to be embedded with another organization, will indeed succeed?

As a current Team Leader, CEO or Commander, it means you will have to go a step farther.  It means that you will have to take this person side-by-side in many cases, into the same office, SCIF, SOC, NOC or conference room to explain it face-to-face.  Sitting across the table from this partnered organizations top executive, you say it:

"I have carefully selected "Jill or Jack" to be our Liaison with your unit or department.  It is something we know to be of great value to the ongoing mission we both face, to address the (problem-set).

 Please know that she/he knows me very well and how I think and what our organizations real capabilities are.  We will miss them, yet want her/him to work alongside your leaders to learn as fast as possible about your greatest hurdles and problems.  It is only then, that we envision a chance for our respective teams to move faster with the most effective joint solutions, to obtain and synchronize our advantage." 

This few minutes face-to-face may make all the difference on the potential for a successful and trusted relationship.  As you stand up and leave your Liaison with their new assigned organization, remember this.

Your Liaison's ability to succeed, will only be as good as the job you have done in preparing them for the assignment.  Think about all the months or years you have worked to shape their character, to instill the ethics and integrity into their daily decisions.  How many problems did you let them solve on their own?

We look forward to hearing the stories about your "Liaison's" and their respective missions to achieve decision advantage and to reach those lofty outcomes you seek...

18 April 2026

Organizational Innovation: Demonstrated Abilities on the Front Lines...

 Who is talking in the front of the room right now?

Is it the boss again or the CxO that is telling others that work in the organization what they should think and what they should be doing?

Or is it one of the members of the organization presenting their validated research, the data collected and the answers from questions to the real customer, the end user or the investor?

Leaders who are asking open ended questions from the audience and from the "Back of the Room" will be getting more clarification.  They may be also curious of the speakers motivations for their research investigations and experiments.

These same leaders who are listening and verifying information recognize that the true innovation is going to come from far outside the building.

"Future innovation and solutions will originate from outside the organization from true professionals in the area of responsibility with those that have real world problem-sets."

These problem-sets from the field, from the organizations and Critical Infrastructure entities in the same neighborhood, city, county or state shall be the true focus.

Radical transparency with data collected from the customer, the user, the inventor, or the researcher is where the hypothesis is created.

Are you still talking about what you want on the “Zoom” for the majority of the time allocated?

How will you ever discover if the hypothesis is correct?  How will you ever be able to adapt, change or refine what the real problem-set is, that requires your expertise and focus?

Innovation in your organization will be scarce while you are still up in front of the meeting talking.

meritocracy

noun

mer· i· toc· ra· cy

: a system, organization, or society in which people are chosen and moved into positions of success, power, and influence on the basis of their demonstrated abilities and merit.

What are you still doing inside the building?  Why are you still in front of the room or on the Zoom talking?

The corporations and responsible agency or other entities in your area of responsibility need you to be listening to their problem-sets.

They need you to ask them clarifying questions based upon their presentation of the issues, the possible innovation required to solve the problem.

Get out there!  Onward…

08 March 2026

ID Risk Management: Corporate Intelligence Unit (CIU)…

What is your name? Where do you live? What is your phone number? Where were you born? What is your social security number? What is your passport number? Where was it issued? What evidence do you have that this is all true? Your identity is at stake and Operational Risk Management is on the line.

These questions and more are asked of us on a regular basis to establish our true identity. The entity asking these questions is considering you to be granted access, access to what?

It could be to establish an account at a banking institution, get a drivers license or become a member of a trusted community of people. Or it could be a country deciding whether to grant you a visa to visit or work for a period of time.

Whether you are in the UK, admitting people into your country or a Global 500 company allowing someone access to your corporate facilities, digital assets or place of business; you must have ways to effectively validate who people say they are, and who they really are.

Even if you asked all of the questions above in the early stages of the company hiring process, would you really have the entire picture? This changes over time and events in a persons life. Identity Management and the use of both "known to many" and "known to few" attributes about who you are and who you know, is a reality in today's blur of global commerce.

When a country has a breach of security admitting people, who are not who they purport to be, is it any different in the context of a Defense Industrial Base company headquartered in Chicago, IL or an Investment Banking firm in Geneva, Suisse? What are different are the motives and the outcomes from the fraudulent acts.

What are the current arguments and the leading reasons why our policies, methods and tools associated with Identity Management are in a state of chaos in the United States?

"What is interesting is that the same people who are coming to work every day with their TWIC or CAC cards are also victims of ID Theft as consumers."

The same individuals who walk into the SCIF or the bank vault may very well be people who have active investigations going on regarding their identity being used to perpetrate crimes or other fraudulent motivations. So what are some of the most important issues on the Identity Management horizon?

In all of the breaches, all of the incidents there is a root cause for the failure in the people, process, systems or external factor that opened up the vulnerability for the attacker to exploit and obtain their objective.

It's called Continuous Monitoring. This issue is found in all places in Appendix G of the US NIST sp800-37 that illustrates the reason why “Continuous Monitoring” is critical especially in information systems:

Private Sector companies have a duty to invest in resources, policy refinement and new methods or tools to keep continuous monitoring as vigilant as possible:

"Conducting a thorough point-in-time assessment of the deployed security controls is a necessary but not sufficient condition to demonstrate security due diligence. A well designed and well-managed continuous monitoring program can effectively transform an otherwise static security control assessment and risk determination process into a dynamic process that provides essential, near real-time security status-related information to organizational officials in order to take appropriate risk mitigation actions and make cost-effective, risk-based decisions regarding the operation”

Much of what we know about our employees is found in their HR files, background reports (if ever done) and what co-workers say about their behaviors in the workplace.

Corporate Security, Risk Management, General Counsel, Information Technology, Public Relations and even the EAP (Employee Assistance Program) executive managers shall create, maintain and continuously operate a Corporate Intelligence Unit (CIU) and “Threat Assessment Team”.

Without it, the consequences of not knowing a persons true identity or current state of mind could cost you more than the loss of life.

It could cost you or the organizations global reputation…

01 February 2026

OSINT. "Accent on the Future"...

It was early-August of 2000 and topics of the “Dark Web” were prolific around the conference table at 8:00AM on that early Monday morning.  Our building on Wilson Blvd was just a few blocks up the hill from the Rosslyn, VA Metro Station.

Soon the dialogue turned to the weekends OSINT and the Terabytes our Cyveillance Web crawlers had retrieved across the globe.

Minding clients business on the Internet was going beyond what was visible with run of the mill browsers and growing search engines.  It had now gone dark, without the right tools, software and protocols.

Now was our opportunity to begin new strategic ventures with clients on three key “Decision Advantages”:

  • Continuity
  • Safety
  • Resilience

How as a Fortune 500 company operating across the globe could you apply these factors to increase your awareness and integrity of your content on the World Wide Web?

Where and how were your adversaries using your published information in nefarious ways to attack your organization?  To influence your product perceptions.  To launch campaigns of doubt against you.

It was now time to get on a plane to fly to the U.S. HQ of our global clients to inform them what was at stake beyond brand protection, social media monitoring and threat investigation, analysis, and response services.

  • Think about your business technology operations.  What factors could impact the continuity of your services based upon your geographic locations?
  • Think about your employees health and exposure to life threatening acts of sabotage or natural weather events.
  • Think about your organizations ability to defend itself against a spectrum of threats and to bounce back quickly to stay in competition with rivals.

Little did we know what was in our future, just about a year away in September 2001.

What if we could apply Continuity, Safety and Resilience (CSR) into our dialogue with a majority of our clients major growth initiatives?

On that Wednesday morning wake up call after a flight to O’hare the previous evening, it was thoughts of Arthur Andersen and the meeting ahead at their HQ.

That morning in a small office looking out on Chicago, we learned about the vast strategy of making a split of AA and Andersen Consulting into a new renaming on 1 January 2001.

Andersen Consulting would soon adopt the new name "Accenture". The word "Accenture" was derived from "Accent on the future”.

The question that morning was now on the “White Board”.

"Where are all the places on the Internet with the brand name “Andersen Consulting” that now needs to be changed to Accenture with a new logo?"

We can help with that business problem in a few hours.  The following day we knew that there were thousands of instances on the “Sun Microsystems” sites alone.

In July of 2001 Accenture would go public (IPO) and 8 years later move their HQ to Dublin, Ireland.  Today they have 779,000+ employees and revenue of US$69.xx billion (2025)…

08 December 2025

Linchpin: Trust in a Continuously Changing Environment...

In the early morning nautical twilight on a cold winter morning, thoughts about how the world is changing comes into clarity.  What do you believe in?

As the asymmetric threats seem to grow and our respective thoughts scan a vast Operational Risk landscape of people, processes, systems and external events; there is a mission worth pursuing.  It is a mission that is uncertain, full of unexpected change and potential catastrophes.

The outcomes that you seek will not always materialize as you wish, yet that is to be expected.  After all, what would an organization, state, region or country be like, without any substantial changes, unexpected events or new challenges?  You see, humans do not thrive in environments where behavior or events are 100% predictive.

We work best when there is a problem to solve, an environment or challenge that we can explore.  We can conquer or adapt to, in order to survive another day.  It is this ability to explore, to test, to solve problems that sets us apart from the current state of "Artificial Intelligence", for now.

Now, pivot your thoughts to the current ecosystem of people you encounter on a daily basis.  How does that environment change each day?  What mechanisms do you have in place to mitigate the risks that could create negative consequences and outcomes?  Think about all of the behaviors, tools and ways that you operate each day to deal with risks in your life.

The truth is, humans are curious and seek out risk.  Even if you get to a place where there is a perception that no risks are present, that no risks are over the horizon, we will look for new adventure, new learning and ways to adapt to a new environment.  So what really is the top priority for a parent, big brother/sister, manager, instructor, chief executive, commander or other organizational/constituent leader?

To create an environment of trust.  In a place where people have the ability to create the rules, teach the rules and operate within the rules.  Think about any environment where humans can't create the rules, or rely on the rules.  Where they are not effectively communicated or where people don't follow the rules.  Trust breaks down and uncertainty permeates our consciousness.  The decisions to trust become questionable.

Your goal, is to become a "Linchpin".  As Seth Godin has described in Linchpin:  Are you Indispensable?:
"Is there anyone in an organization who is absolutely irreplaceable?  Probably not.  But the most essential people are so difficult to replace, so risky to lose, and so valuable that they might as well be irreplaceable."
How many linchpins do you have on your team?  Guess what?  If everyone is so specialized, so vital and there is little or no backup and redundancy, you may have a single point of failure.  This is why as a linchpin, you need to be continuously training and teaching to be replaceable.  If you are not confident that you have done all you can do, to become replaced, then you as a linchpin have failed.  Your resilience factor is zero.

Your tasks will create more redundant linchpins and you shall create a consistent and highly trusted environment, physical or virtual.  A changing environment is inevitable.  Achieve a culture where trust is paramount and the team, class, cohort, company and community that creates the rules, communicates the rules, enforces the rules and follows the rules.

We as curious humans seek out unpredictable places, full of risk and simultaneously we wish the environment can be trusted?  Yes we do.

Onward!

30 August 2025

Proactive Measures: Beyond the Perimeter...

Operational Risk Management requires both proactive and passive measures that encompass a comprehensive organizational strategy. Odds are that you have devoted a majority of your time and resources to this point on the passive mode of preparedness and defense. A reactive and alert oriented focus. The time has come to change the priorities and to increase the allocation of strategy on the "Active Measures." Why?

Stuxnet is and was ground zero for a new generation of digital infrastructure cyber weapons.

The attribution game is still going on with several suspects on who actually developed, tested and deployed "Stuxnet." This is not as important as the realization that sitting back and waiting for the next variant or hybrid cyber weapon to attack your critical infrastructure assets in passive mode.

"The most advanced organizations are now taking the "Proactive" stance to not only detect changes in their environment in a more real-time mode, but they are starting to hunt down the attackers."

There is a decision point where you realize that the passive mode will not buy you time nor will it redirect your attackers to other more vulnerable assets. Your organization will continue to operate with the goal of serving your clients, members or customers yet simultaneously a "SpecOPS" team of internal experts will be monitoring, measuring and exercising tactics to legally neutralize the threat before them.

Commercial and non-governmental entities are creating the means and the capabilities to deter, detect and document who is attacking their digital systems and where they can be found. This intelligence is being shared within the private sector organizations to determine fingerprints, modus operandi and other evidence that is required to effectively hunt down the attackers. The next challenge will be how to package this and make sure that the proper authorities are notified in a timely manner.

There is no longer a solution that is wide enough or in depth enough to be distributed across a whole spectrum of companies or organizations. The answers will be specific, customized to the unique environment and infrastructure that comprises a particular enterprise.

In order for that specification to be developed internally and provided to the correct people, you have to have the internal mechanisms in place to know in real-time what is changing and how fast it is changing from the normal state.

Is your view beyond your own perimeter? Are you looking for the anomalies that are over the horizon and could impact your network soon? It's one thing to look at the changes to your own perimeter but what about the intelligence on providers and ISP's somewhere on the other side of the planet? Do you know where your packets are going and how they are being routed?

"In a savvy Operational Risk Management enterprise, the "Corporate Intelligence Unit” (CIU) is alive and thriving."

A proactive intelligence-led investigation doesn't begin with a phone call from someone who say's, "My system is down" or "What does this Blue Screen mean”?

It doesn't start when your VP, Research & Development suddenly leaves the company for no apparent reason. Intelligence-led operations will continue to be the aspiration of many, yet only possessed by a few.