Showing posts with label The Cipher Brief. Show all posts
Showing posts with label The Cipher Brief. Show all posts

Monday, February 21, 2022

The Real Power of Intelligence ‘Auxiliaries’


The democratization of intelligence is changing how espionage is done – and by whom. How can states best achieve their aims in an age of silo-spotting, open source sleuths and other “intelligence auxiliaries”?  


EXPERT PERSPECTIVE — Late in the summer of 2021, researchers affiliated with the Federation of American Scientists (FAS) discovered evidence that China was upgrading its ballistic missile silo count in what they described as “the most significant expansion of the Chinese nuclear arsenal ever.” To reach this conclusion, the analysts relied on open source intelligence (OSINT) techniques, including commercial satellite imagery and unclassified knowledge about Chinese missile technology, that has become commonplace in recent years.

FAS’ research did not go unnoticed by the US government. In response to the findings, Admiral Charles Richard of USSTRATCOM used a press conference to rhetorically ask the researchers, “If you enjoy looking at commercial satellite imagery or stuff in China, can I suggest you keep looking?”

Admiral Richard’s deadpan aside, his comment raises interesting questions about the future of public-private partnerships in intelligence. What happens when sophisticated intelligence capabilities exist outside of government? What intelligence functions should only be performed by states – and which should be done by non-state actors? And most pressingly, what tools can we give leaders like Admiral Richard so that they can stop “suggesting” and start working effectively with outside groups to achieve common policy objectives?

Since Admiral Richard’s comment, we have seen yet more examples of how the “democratization of intelligence” is creating new opportunities for private sector and NGO groups to provide insight on important geopolitical questions. Today, as Russia marshals its forces to widen its existing invasion of Ukraine, OSINT practitioners are continually scanning for new troop movements, giving policymakers ways to discuss publicly what once would have been secret intelligence. More broadly, across government and the think tank world, there has been widespread recognition of the increasing sophistication of open source intelligence capabilities. Most recently, we have also seen intelligence leaders, including most prominently MI6 Chief Richard Moore, comment on the exciting possibilities of public-private partnerships founded in part on open source techniques.

But so far, we have seen few new ways of working designed to actually capture this potential. Typically, the conversation about open source centers on how government can do more – rather than on how the public sector can forge innovative partnerships. As a result, national security professionals who wish to work with a burgeoning non-state intelligence sector are often left with unclear guidance. There has been plenty of work on integrating OSINT tools into state arsenals; but less toward creating the new policies, procedures, and ways of working needed to actually leverage non-state OSINT capability.

This is a missed opportunity. The IC should articulate new ways of working that effectively leverage the activities of non-state “intelligence auxiliaries” to help achieve national priorities. Such auxiliaries, whether they are directly tasked, paid, or integrated into the IC’s structure or not, have proven that they can make vital contributions to important tasks in mission awareness and information operations.

Leveraging intelligence auxiliaries is not without risk, and should be engaged in with care and according to a transparent and understandable framework. But intelligence auxiliaries are not going away – the state’s option is not whether to engage with them, but instead how.

Intelligence Auxiliaries in History

Intelligence Auxiliaries are not new – non-state intelligence activity has been a part of the world’s “second oldest profession” since the beginning.

Historically, the idea that non-state actors should work on the frontlines of intelligence would hardly have seemed out of place. Private individuals in ancient Rome were prolific practitioners of intelligence. European religious orders were famous collectors of intelligence – a long-standing tradition that continues today. Journalists have long been adjuncts, wittingly and unwittingly, to intelligence work – Napoleon was a famous consumer of British newspapers for information on troop movements, relying on them more than secret intelligence.

Moreover, states often collaborated with non-state intelligence gathering networks to supplement their own awareness. In the ancient Aztec empire, intelligence networks organized by merchants were often leveraged by the state. In the age of European expansion, commercial actors regularly engaged in espionage for private as well as state gain – with European commercial actors famously stealing the techniques for processing tea leaves and for making porcelain from China. The East India Company, itself a commercial actor, routinely made use of pre-existing espionage networks to inform its policy before the handover to the Crown in 1858.

For most of human history, states didn’t necessarily hold better espionage technology than did non-states – but they were still able to out-perform and effectively leverage non-state intelligence actors because, by virtue of being states, they possessed certain abilities that non-states could not hope to equal. These “enduring state characteristics” helped ensure that, even when non-states had superior information, states were still able to remain the most important players in the espionage market.

  • States had control over the information environment. The state’s historical ability to publish, censor, or encourage the production of information shaped the intelligence-gathering environment. Historical censorship of the press during times of conflict, such as during Britain’s Boer War, shows how states have used control over the information environment to achieve objectives related to their own or foreign actors’ espionage. Today, China’s ability to control information leaving its borders is a continuation of the exercise of this power.
  • States had agenda-setting ability. In times of peace or conflict, the state’s ability to guide non-state practitioners toward common outcomes was a major lever through which it exercised indirect control over non-state auxiliaries. Historically, mission-definition was an important way for states to guide the activities of private groups such as privateers, explorers, missionaries, and private trading corporations.
  • States had fiat power. States could simply declare activities or types of information legal or illegal, and could engage in activities that they made illegal for others without fear of punishment. This historical ability to “live above the law”, whether through law courts or secret police, gave states powerful levers to compel the production of information.
  • States had superior historical memory. One of the single most important advantages of historical intelligence bureaucracies was their ability to develop and sustain large archives. Archeological evidence of intelligence archives has attested to the importance that this state advantage had even in ancient times. Though less relevant today with the development of large-scale information storage in the private sector, state advantages in collecting and classifying information still persist today.
  • States had market-making ability. States could incentivize or de-incentivize the production of information through their market-making power. Not only were states the largest players in information markets – they have had the ability to set the rules by which other players engage in market activity. This gave states the ability to offer bounties or create attractive commercial partnerships for information.
  • Direct Contracting Ability. Finally, states could and did directly commission private groups to conduct intelligence work on their behalf. While not unique to states, this ability nonetheless is a major way that states have been able to leverage capabilities possessed by non-state actors throughout history.

The Rise and Fall of Information Overmatch

During the Cold War, states could rely on qualitatively better information than non-states. As this advantage recedes, “intelligence auxiliaries” are coming back on the scene.

The Cold War saw the technological gap between states and non-state “intelligence auxiliaries” widen. During this period of rapid advances in technology, states added a new intelligence advantage vis a vis non-states – the simple ability to reliably access and exploit information that far outclassed in quantity and type that available to non-states. As this advantage erodes in the modern day, the difference between the classified and non-classified worlds is diminishing – and with it a way of working based on information overmatch.


Access The Us is Engaging in a Strategy to Share Intelligence on Russia more broadly.  Is it Worth the Risk?  This is content reserved for Subscriber+ Members

  Upgrade your access to Subscriber+ today


Today’s premier intelligence bureaucracies were largely formed during the “long” 20th century. This was an era when states increasingly came to enjoy privileged access to intelligence based on capabilities that non-states could not match, at least not reliably. During the long 20th century, as war and intelligence-gathering became more mechanized and technological, militaries and intelligence agencies became increasingly invested in industrial development and production as a way of securing the necessary materials to win wars. With the private sector unlikely to support the cost of expensive investments in military and intelligence technology on its own, “the role of the state [became] vital because it was the state that provided the critical financial resources required to take embryonic technologies and develop them at a speed unlikely to be matched by the civilian market.”

This sponsorship gave rise to sophisticated intelligence technologies such as computers, satellites, maritime domain awareness tools, unmanned aerial vehicles, and more. With sponsorship came control, and for most of the long 20th century states were the only entities with access to sophisticated espionage technology. Groups outside of government were largely restricted to low-grade versions of the same technology, or to classic “first generation” OSINT sources such as media and grey literature collection. While some non-state groups had significant impact on events throughout the Cold War, top-tier intelligence activities were largely restricted to states.

This state monopoly on access to top-tier information began to break down at the beginning of the 21st century. As the price of computing continued to fall, the state’s role as the principal investor in military and intelligence technology became less important. As a result, private companies increasingly took the lead in creating, and funding, technologies that transformed the practice of intelligence, such as the internet, social media, and artificial intelligence.

In place of the government monopoly on espionage technology, today there is a boisterous bazaar of information and data vendors. These companies sell a wide variety of social media intelligence tools, earth observation capabilities, large-scale information storage and processing, mobile phone location data, global HUMINT platforms, and sophisticated telemetry intelligence capabilities. This private market has changed the game. Today, with enough money and focus, a small group of dedicated individuals can leverage private sector capability to rival a well-funded intelligence agency. For example, the following capabilities are all within easy, legal reach for any government or non-governmental organization (so long as the budget is right):

  • An on-call satellite imagery service from providers such as Planet, Maxar, IceEye, or others. Today, non-government researchers can access reams of satellite imagery on any area in the world, often at time increments of less than 24 hours for refresh. This means that together with sophisticated, openly available image recognition algorithms, a small team can scour the desert for Chinese siloes – or monitor North Korea’s nuclear program, and study deforestation trends globally.
  • A flexible HUMINT capability that can source insights from anywhere on the globe. While journalism could always have been considered “OSINT-enabled HUMINT,” today a range of social media intelligence tools or distributed online survey platforms that allow a user to query “sources” all over the globe. Finally, natural language processing platforms allow anyone to conduct a sophisticated, global information-gathering operation completely out of the box.
  • Finally, all of this is supported by a diverse, evolving, and multi-participant marketplace for both data and AI/ML capabilities, many of which are hungry for non-governmental researchers to show, in unclassified spaces, the power of their tools.

This only scratches the surface of the tools available. New low and no-cost OSINT platforms are consistently replicating capabilities once held only by top-tier spy agencies – for anyone to use. From NGOs to private companies to non-state terrorist groups and hacker collectives, the increasing sophistication and scope of OSINT capabilities has meant that states no longer have reliable information overmatch vis a vis non-states.

How to Work with Intelligence Auxiliaries

During the Cold War, it simply wasn’t possible for, say, the Bacardi corporation to charter U2 overflights of Cuba to provide snapshots of ongoing missile deployments, or for a group of disaffected Soviet emigres to conduct large-scale online surveys on food availability in supermarkets. Today, similar groups routinely use capabilities such as the tools highlighted above to produce impactful reporting on global issues of crime, corruption, and conflict around the world.

While profit is part of the equation, for many of these organizations, a dedication to mission is a key motivation. This new generation of intelligence auxiliaries combines the mission-motivation of a non-profit with the nimble structure of a startup and the technological reach of an intelligence agency. These groups rapidly collect, analyze, and disseminate research products to audiences both inside and outside of government. Because they often work almost entirely with publicly available information (PAI), such groups frequently have more flexibility than government bodies in whom they hire, how they work, what tools they use, and how they leverage their research, giving them the ability to move faster than any state actor.

States can leverage this energy by recognizing the existence of intelligence auxiliaries aligned with their goals, and looking at how they can enable these groups. Loosely speaking, state responses to the capability of intelligence auxiliaries can be arrayed on a spectrum control, borrowed from principles of agency law. On the “loosest” end of the spectrum, states can engage in Admiral Richard’s “opportunistic enlistment” of an intelligence auxiliary. He (presumably) was not aware of FAS’ research before it was published, learned about it in the news, and was pleased that it happened to align well with his mission priorities. He chose to amplify the research through independent, uncoordinated strategic communications. The defining feature of this model is a total absence of control and coordination.

On the “tightest” side of the spectrum, states can exercise a “direct control” style tasking of auxiliaries, as one might do with a traditional defense contractor. Under this model, a state actor directly contracts with an outside organization to conduct an activity on the state’s behalf, subject to conditions which the state imposes. Different degrees of control over working methods, personnel, timelines, and requirements may be imposed by the state under this model, but its defining feature is a high degree of control over methods and tools of work.

Between these two ends of the spectrum, however, are a variety of ways of interacting with intelligence auxiliaries. These ways of working aren’t based on information overmatch, but instead on long-term, enduring capabilities that states have had throughout history. A hypothetical spectrum of options based on these “enduring state functions” might look something like this:

  • Opportunistic Enlistment of Intelligence Auxiliaries. Relying on the fact that intelligence auxiliaries pursue their activities independently from the State, states can simply observe their production and choose to amplify it when convenient, with little to no coordination between the two. This looks much like the case of Admiral Richard, or of other policymakers who seek to leverage emerging news stories.
  • Using the Information Environment as Intelligence Terrain. States have the ability to define what information is open and what isn’t – and can do so with an eye to granting intelligence auxiliaries more access to mission-important information. For instance,  the US has recently enacted new beneficial ownership laws, changing what information companies must provide when incorporating themselves. Information in public registers is a gold mine for intelligence auxiliaries working on anti-corruption issues; if states act to change laws with the idea that information disclosed will be used by intelligence auxiliaries for citizen OSINT policing, then they’re shaping the environment for good in a way that frees up state resources.
  • Using Mission-Definition Power to Signal What is Important. Intelligence auxiliaries depend for funding and credibility on their ability to achieve important missions. There are many ways that policymakers can help guide intelligence auxiliaries toward important goals without revealing classified information or exercising direct control. This might take the form of an expanded campaign of academic outreach or of embedding select personnel within non-governmental intelligence auxiliary groups. In one example, the government could expand ongoing efforts to bring commercial expertise into mixed unclassified and classified spaces.  Alternatively, states might create common information spaces virtually: instant messaging spaces could be created for trusted intelligence auxiliaries to join and share ongoing research and leads. Such groups could also serve as impromptu coordinating spaces for quick reaction OSINT monitors, as they are currently doing for Ukraine contingencies.
  • Using Fiat Power to Empower Auxiliaries. States could simply declare activities or types of information legal or illegal depending on the identity of the actor. A simple example of this in action is how Bank Secrecy Act (BSA) Section 314(b) gives financial institutions the ability to share sensitive information with one another “in order to identify and report activities that may involve terrorist activity or money laundering.” An expanded version of this law could expand 314(b)’s safe harbor to chosen intelligence auxiliaries, giving banks a way to collaborate with trusted outside experts to better combat money laundering.
  • Using Historical Memory to Feed Private Efforts. States have significant troves of information, both classified and unclassified, that they often find difficult to truly leverage. If more of these resources are given to non-states, the burden on states to create value from data can be more widely shared. This can (but doesn’t have to) mean selective declassification. Government departments such as Commerce and CBP have significant amounts of unclassified trade and corporate data that could help identify human traffickers, proliferators, and other bad actors.
  • Using Market-Making Ability to Create Information Marketplaces. States have significant ability to create markets for information, both as participants and as rule-setters. They can use this power to incentivize groups to work together toward state goals. States can both signal priorities and make market connections among non-state actors by hosting short term surges or “hackathons” designed to temporarily gather expertise and tooling to answer an important question. Governments could incentivize private sector tech providers to make “in kind” donations of capability for set periods of time to boost intelligence auxiliaries, with the results of a short-term surge going to support policymaker awareness or strategic communications campaigns. Hackathons often offer more direct control than do similar “open data” initiatives, making them more attractive for sensitive missions.
  • Using Commissioning Power to Task Directly. Finally, states can pursue familiar, tried and true models of direct tasking. This model can be effective in certain circumstances, but often is slow and laborious to implement.

The above are not new ways of working – in nearly every case, there are examples of government leveraging similar models to achieve important goals. But thinking of intelligence auxiliaries and the ways of working with them together as part of a single toolkit can help clarify the operational and legal issues at play. Rather than try to be overly prescriptive with how states can engage with non-state intelligence auxiliaries, policymakers should focus on creating a playbook of workable collaboration frameworks that can be relied on by intelligence professionals at different levels in government to engage with outside organizations. Without such models, commanders are likely to improvise – which may lead to good outcomes in some cases and bad ones in others.

These are far from the only models possible – and which model is appropriate will depend on the specifics of a given situation. Just as there is no one-size fits all approach to a given intelligence question, so there will not be an appropriate universal model for collaboration between state actors and non-state intelligence auxiliaries.


Read also Open Source Intelligence and Uncovering Secrets Hidden in Plain Sight in The Cipher Brief


Not whether, but how

Ultimately, the method of interacting with an intelligence auxiliary will be situation-dependent. Should it be covert or overt? Paid or unpaid? Public or private? Short-term or long-term? Policymakers will have to negotiate these questions with reference to specific facts.

But they should not have to negotiate them without functioning models. Admiral Richard is far from the only policymaker who has identified an outside capability that he has no tools to use. We must give intelligence officials, policymakers, and commanders flexible, clear, and transparent ways of working with intelligence auxiliaries. A failure to define the rules of engagement will not deter interaction, but instead leave it less clear and more likely to lead to uncontrollable outcomes. Without clear rules, a government actor could collaborate with an intelligence auxiliary in ways that endanger civil liberties or even lives.

But doing nothing is also a strategy. Policymakers do not get to negotiate the existence of intelligence auxiliaries. Intelligence technology is likely to continue to develop outside the walls of government, and private groups will continue to leverage this technology either in pursuit of a self-defined charitable mission, or for private gain. For non-authoritarian countries with strong civil societies and robust data governance regimes, the rise of intelligence auxiliaries is likely to be a significant force-multiplier vis a vis authoritarian rivals. The question for states is not whether they engage with outside intelligence capability, but how.

Read additional expert perspectives on open source intelligence in The Cipher Brief

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The Cipher Brief may receive a small commission for products purchased via links

The post The Real Power of Intelligence ‘Auxiliaries’ appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/xfjRc4b
via IFTTT

Wednesday, February 16, 2022

The US is Engaging in a Strategy to Share Intelligence on Russia More Broadly. Is it Worth the Risk?

“The Cipher Brief has become the most popular outlet for former intelligence officers; no media outlet is even a close second to The Cipher Brief in terms of the number of articles published by formers.” – Sept. 2018, Studies in Intelligence, Vol. 62 No.

Access all of The Cipher Brief’s national-security focused expert insight by becoming a  Cipher Brief Level I Member .      

The post The US is Engaging in a Strategy to Share Intelligence on Russia More Broadly. Is it Worth the Risk? appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/2487zS0
via IFTTT

Wednesday, February 9, 2022

The Intelligence Game is Changing. Are We Ready?

EXPERT PERSPECTIVE — As retirees of the Clandestine Service at the CIA, we worked for decades in the shadows around the world, at ease in that space where we quietly served. Recently, we found ourselves in an uncomfortable public space, compelled to be vocal on social media regarding data and the need for the U.S. government to embrace commercially sourced intelligence, CSINT, as a foundational and critical component of national security.  

Data is ubiquitous, dynamic, and has the potential to inform analysis and decision-making on issues ranging from climate change to terrorism to critical national infrastructure, and everything in between. CSINT is a complement to HUMINT (human intelligence) and other national technical means of collection, not a substitute. CSINT plus these other collection tools is the equation for success in gaining strategic advantage. 

CSINT is not OSINT (open source intelligence). Whereas OSINT is a reference to any information that can be legally gathered from free, public sources, CSINT is data that is produced by people throughout the world and is collected and sold by a variety of firms to others to make informed decisions.  Examples of CSINT include; pharmaceutical sales in the era of Covid, vehicle telematics data, geospatial insights, weather trends, and website cookies that inform retailer strategies for targeting consumers for advertisements based on their internet browsing history. 

And yes, we see the irony of HUMINT-ers extolling the virtues of CSINT – a new INT. 

We are in the midst of the fourth industrial revolution. And data – that data that we, as citizens, generate on a daily basis – is the commodity of value. We would liken it to the value of oil and oil’s role in the third industrial revolution, but oil is a finite resource and data is not. In fact, commercial data is growing at an exponential rate through our daily personal and professional interactions. Many businesses leverage this data to improve their bottom lines and grow their businesses. Likewise, some governments are exploiting commercially sourced data to achieve their objectives as well.

Take the People’s Republic of China (PRC) for example. Open source articles document the investments the PRC continues to make to build data centers and develop their artificial intelligence (AI) and machine learning (ML) models to allow them to more quickly derive value from data. The PRC government put into place laws that require Chinese companies, even when operating outside of China, to funnel data they collect by virtue of doing business, back to Chinese data centers. A new law in the PRC also requires foreign firms doing business in China to turn over their data to the PRC government. The PRC is concurrently locking down data from its citizens as a defensive measure.

The PRC has a data strategy to attempt to win supremacy in the fourth industrial revolution. The key components to their strategy are a wide variety of commercially sourced data, AI/ML models and computing power that speed the time from data to value/insights. The quality of the AI/ML models and the speed of compute power are critical components of this daisy chain, but the data is arguably the most critical.


Cipher Brief Subscriber+ Members receive exclusive expert briefings from members of our expert network.  Upgrade to Subscriber+ today.


This paradigm does not cease to exist at the gates of intelligence agencies. We believe that commercially sourced data is a cornerstone to the future of intelligence. CSINT is the radical innovation that will launch intelligence services and businesses alike ahead of their adversaries, leapfrogging in essence, the status quo to establish a new order. Classified data sets and information that is clandestinely acquired, remain extremely valuable and cannot be replaced. CSINT does not seek to replace classified data; it seeks to enhance and complement it.

The paradigm of valuing classified data above all else is archaic and must be modernized in order to adapt to the data-driven world. If the US government continues to value classified data at the expense of embracing commercially sourced data, we run the risk of the United States losing ground to its adversaries. 

And that begs the question, what is the USG’s Data Strategy? While that is not readily clear, what is clear is that there is a big role for CSINT to play.

There is no rules-based order on the playing field of the fourth industrial revolution when it comes to data. In our techno-democracy, there is a lot of concern around privacy – and appropriately so. This complicates the development of a national data strategy akin to the PRC model.  While many grapple with how to optimize commercially sourced data and balance privacy concerns, we would propose that the United States and likeminded techno-democracies impose our values in defining how data will be utilized in the future.

If we cede the playing field to our adversaries to define the rules, rest assured they will not meet our democratic values. We must lean into this difficult conversation, find common cause with our likeminded techno-democratic partners, and create a framework that balances creating value from commercially sourced data on one hand and privacy concerns on the other.   

It is time for the U.S. to embrace commercially sourced data, modernize our laws to allow for the effective storing and computing of data, and invest in AI and ML tools and models to derive value at scale and at speed of mission. It is time for the U.S. to embrace CSINT.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post The Intelligence Game is Changing. Are We Ready? appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/DqE8O3x
via IFTTT

Friday, February 4, 2022

The Outlier: What if Putin’s Real Target isn’t Ukraine?

EXPERT PERSPECTIVE — We have a long history of misreading Russian intentions. The classic example was the judgement by the British Joint Intelligence Committee (JIC) that Russia would not invade Czechoslovakia in 1968; based on a westernised view that it would not be in Moscow’s interests. Similar misjudgements were made in the prelude to Putin’s annexation of the Crimea in 2014.

Vladimir Putin calculated this winter as the ideal time to confront the West over those parts of the former Soviet Union which he believes should still be in Moscow’s sphere of influence. Winter inevitably puts Europe’s energy market under stress. Meanwhile NATO has just made a humiliating and chaotic exit from Afghanistan led by a United States president who is struggling in the polls.

Having identified the best moment Putin followed up by mobilising an army of some 130,000 troops in midwinter, distributed in pockets along Ukraine’s borders with Russia and Belarus. Putin never places great belief in diplomacy but he is willing to go through the motions because he does set store by assembling retrospective justification for any future action. In the unlikely event of a major Western concession, he would be willing to stand down the army but the strong probability is that he will use it to facilitate a tangible political and military result.

The assumption of everyone in the West is that Ukraine is the target for either an invasion or an incursion. However, none of the options looks particularly good. Yes, Russian troops could probably dash the 240 miles from Belarus to Kiev and seize the capital. But they would be unable to subjugate the whole of Ukraine, especially west of Kiev, and the invasion could lead to a long and costly insurgency. Alternatively, Putin could try and capture Ukraine’s coast and the port of Odessa but it would leave a long strip of land to defend against future Ukrainian counter-attacks.

The other problem with attacking Ukraine is that it lets NATO and the West off too lightly. President Biden made it very clear at an early stage of this crisis that NATO would not fight to defend Ukraine. Instead, all the talk has been of economic and financial sanctions. This approach has made it easier for Western countries to show a reasonably united front against Putin, although differences exist over supplying weapons to Ukraine and the exact nature of the sanctions.

So, the focus on Ukraine has not worked for Putin. Although some of the responses have been divisive the overall tendency has been to unite Western leaders. It has also enabled them to undertake some showboating with Macron engaging directly with Putin in diplomatic talks and others making high-profile trips to Kiev.

But Ukraine may not be Putin’s main target. Putin’s beef is with NATO which, he believes, has made more inroads into central and eastern Europe than was ever agreed following the collapse of the Soviet Union. In fact the two draft treaties which Russia published on 17th December last year demanded that NATO withdraw its forces and weapons from any country which joined NATO since 1997. That would include Hungary, Poland, Romania, the Czech Republic, Slovakia, Bulgaria, Croatia, Montenegro and North Macedonia. It also embraces the three Baltic States (Lithuania, Latvia and Estonia) whose secession from the old Soviet Union particularly rankles with Putin.

There are two operations which Russia could launch against the Baltic States which would send NATO into a tailspin. Article V of the NATO treaty stipulates that “an armed attack against one [member] shall be considered an attack against them all” In other words NATO would be obliged to employ armed force. If any Russian incursion were deft, limited in scope and did not kill too many NATO soldiers or local inhabitants this would undoubtedly lead to severe divisions in the Western alliance. Any subsequent failure by NATO to deploy armed force would undermine faith in the alliance and would send a powerful message to aspirant members like Ukraine and Georgia.


Cipher Brief Subscriber+ Members receive exclusive expert briefings from members of our expert network.  Upgrade to Subscriber+ today.


The easier of the two options for Putin would be to annex Narva on Russia’s border with Estonia. It is a majority Russian-speaking town and there has, in the past, been some cultural tension with the government in Tallinn. Putin would ask his intelligence agencies to manufacture a plea for Russian intervention. The annexation could be undertaken by Russian Special Forces. Post facto the Russian line would be that Narva was an exceptional case which should never have been located in Estonia and certainly not worth an armed conflict with NATO. Several European capitals would doubtless agree. But Britain would be in a particularly difficult position as the “lead nation” of NATO’s Enhanced Forward Presence (EFP) with some 1,100 troops based at Tapa 100 miles to the west.

The second option would be riskier but potentially more valuable to Moscow. An attempt to link Belarus with the Russian enclave of Kaliningrad through the so-called Suwalki Corridor would sever any land border between NATO and EU countries and the three Baltic States. The EFP in Lithuania is led by the Germans who would be reluctant to contest a Russian incursion for reasons which Chancellor Scholz has already outlined. Troops from Kaliningrad could complete the task supported from Belarus. Again, the post facto justification would be about the unfairness of Kaliningrad’s separation from the motherland. This too might be enough for some European nations to argue for negotiations rather than combat, especially if Russia’s incursion were only in the Lithuanian portion of the Corridor and not in Poland.

Many Western commentators will argue that Putin would not be so foolish as to attack a NATO member. Actually, it makes far more sense than invading Ukraine. It would divide NATO and would serve as yet another of Putin’s unresolved conflicts which become valuable bargaining chips for the future. His key calculation seems correct; that Europe (and the US) has no appetite for war with Russia.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post The Outlier: What if Putin’s Real Target isn’t Ukraine? appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/YFnahfs
via IFTTT

Wednesday, January 26, 2022

How Iran is Winning, One Attack at a Time

EXPERT PERSPECTIVE — This week, U.S. Central Command (CENTCOM) issued a statement confirming that “U.S. forces at Al Dhafra Air Base, near Abu Dhabi in the United Arab Emirates (UAE), engaged two inbound missile threats with multiple Patriot interceptors coincident to efforts by the armed forces of the UAE in the early morning hours of Jan. 24, 2022. The combined efforts successfully prevented both missiles from impacting the base. There were no U.S. casualties.”

A few weeks before that, military bases in Iraq and Syria that house U.S. troops also were attacked. In December of last year, the U.S. embassy in Baghdad was hit when two rockets landed in the Green Zone. Luckily, like the Jan. 24 Houthi attack on the UAE, there were no U.S. casualties (though the Houthi strike of Jan. 17 did kill two Indian nationals and one Pakistani).

What these attacks and many others in the region have in common is Iran’s irrefutable involvement. They may have different local contexts and their perpetrators, all loyal to Iran, may have different motivations, but every single one of those attacks was possible only because Iran provided either the weapons or the know-how to assemble and use them.

This network of Iranian proxies in Iraq, Syria, Yemen, Lebanon, Bahrain, and possibly elsewhere is what makes Tehran so deadly in the region. It’s a clever method of power projection, honed over decades, because it allows the Iranians to weaken their adversaries and achieve their strategic aims with the fewest costs possible. Iran will fight to the last Iraqi, Syrian, Yemeni, Lebanese, and Bahraini. 

The Iranians have every intention of continuing to rely on their indirect approach because it has paid strategic dividends. Their hope is that we will continue to play their game and go after only their proxies whenever we are attacked. In the case of the Houthis, for example, Tehran expects us and our regional partners to hit the Houthis — and only the Houthis — every time they lob missiles at Al Dhafra. And in many ways, that’s exactly what we’ve been doing. In January 2020, we did eliminate Iran’s top military commander and architect of this proxy network, Gen. Qassem Soleimani, but we were careful to do it in the region, not on Iranian soil.


Cipher Brief Subscriber+ Members receive exclusive expert briefings from members of our expert network.  Upgrade to Subscriber+ today

Join us on Wednesday, February 2 for a briefing on U.S. business opportunities in the Middle East with Cipher Brief Expert Vice Admiral Kevin Donegan (Ret.)


U.S. kinetic strikes on Iranian proxies, while necessary, clearly are insufficient. Simply put, there are more militias under Iran’s command in the region than there are American bombs. To reestablish deterrence against Iran, we have to place our tactical/operational activities, at which we’re incredibly effective, at the service of a broader strategy. We need to make it clear to the Iranians that their asymmetric playbook, especially when it targets U.S. personnel and interests, has a steep price. 

We’ve communicated those red lines before, and successfully so. In Iraq, we held Iran accountable for the attacks its Iraqi proxies often perpetrated against our troops using improvised rocket-assisted munitions (IRAMs) and explosively formed penetrators (EFPs). Those tools killed at least 196 American soldiers and wounded nearly 900 between 2005 and 2011. 

But now, it’s not IRAMs and EFPs that Iran is providing, it’s ballistic missiles, cruise missiles, and weaponized unmanned aerial systems (UASs). Those are much more powerful weapons of war that could cause considerable physical damage to cities and critical infrastructure and kill a lot of people. 

We have to nip this Iranian tactic in the bud before things really escalate — or next time we might not be so lucky and those missiles could lead to significant casualties. This is not just about defending our partners, as crucial as that responsibility is. This is about protecting our own military and diplomatic personnel in the region, as well as our core interests in that still vital part of the world to global commerce and international security.

It’s never an easy conversation when we discuss any potential use of force. But we’re under attack, quite literally and regularly, and nuclear diplomacy alone, no matter what happens in the talks in Vienna, will not fix or effectively manage this growing problem. We have every right to defend ourselves and our collective security interests. 

From an operational standpoint, this requires consulting our carefully crafted Iran target list. We don’t need to specify to the Iranians what we would hit inside Iran, or how, if they attack us again, but it’s vital that we communicate that threat credibly. The worst thing we could possibly do is issue that threat but fail to follow through. Our credibility in the region has already been jeopardized over the years because of the lack of U.S. response to various acts of aggression and intimidation by Iran. Let’s at least not further weaken it and ideally bolster it partly through the measures described above.

In addition to sending a crystal-clear message to Tehran about the consequences of another potential attack (this is the deterrence-by-punishment element), we need to upgrade our defenses (this is the deterrence-by-denial element). We can do that by establishing a fusion cell based on the Houthi missile and UAS threat to provide Gulf Arab partners intelligence of activities that are a precursor to future attacks along with a real-time warning of the launch of those attacks.

We currently have a fusion cell with the Emiratis, but it is focused on al-Qaeda and the Islamic State, not the Houthis. Creating this cell will require U.S. resources, but nothing we cannot afford or that would distract from security priorities in other key theaters. Such resources could include two or three Predator tails and other national intelligence assets that would provide persistent, high-quality intelligence and warning of planned or impending attacks on U.S. personnel and bases or on those of our Saudi and Emirati partners.

More broadly speaking, while immediate tactical solutions to help our regional partners deal with Houthi attacks are required, only the United States can create the kind of sophisticated regional enterprise, both military and non-military, necessary to confront the rapidly growing power of Iranian proxies across the region, including the Houthis. The question is whether Washington has the political appetite to do any of this.

There are American voices who might call such potential U.S. responses escalatory, even reckless. While there’s always risk in any U.S. response that could include the use of force, the risk of inaction is far greater because it will invite further Iranian aggression, at which point it would be virtually impossible for the United States not to strike the Iranians hard and deep.

It is precisely such a scenario we should try to prevent, and it all starts with reestablishing deterrence. Most important of all in this equation — something more risk-averse advocates should never forget — is that Iran is the aggressor and it still has a say over what we choose to do. It can decide to stop its strategic weapons shipments to its proxies and deescalate, or it can continue with its vastly irresponsible approach but suffer the consequences.

This piece was first published by the Washington-based think tank MEI

Join The Cyber Initiatives Group for the first Summit of 2022 with Principal’s including General Keith Alexander, The Hon. Susan Gordon, Dmitri Alperovitch, General David Petraeus, founding CISA Director Chris Krebs and more. Registration is free for this February 9th virtual event. Come prepared to think differently.  Reserve your seat today.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post How Iran is Winning, One Attack at a Time appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3nVmtAb
via IFTTT

Sunday, January 23, 2022

Putin’s Risky Options in Ukraine

EXPERT PERSPECTIVE — It is still more probable than not that Russian President Vladimir Putin will employ military force in the coming weeks. He is not going to obtain sufficient diplomatic concessions from the United States and NATO. He cannot keep his large army mobilised in mid-winter indefinitely and he may wish to seize the moment when the West looks weak and divided after the Afghan fiasco. And with an energy crisis in Europe, Putin may calculate that the European appetite for harsh sanctions against Moscow will diminish when the implications for gas supplies becomes obvious.

The Russian President’s primary objective seems to be to return Ukraine to the Russian sphere of influence or, failing that, to reduce its viability as a threat to Russia.

Putin’s dream option would be a variation on recent Kazakh events. Local disturbances in Kiev would lead to a request from “patriotic forces” for Russia’s assistance. In the absence of a Tokayev figure, the Russians would have to persuade someone senior in Kiev to issue the request; a union leader, oligarch or even a cabinet minister. That should not be beyond the capabilities of the local GRU and SVR Residents to arrange. In his dreams, Putin’s troops would then enter peacefully badged as CSTO “peacekeepers”. In reality, he must know they would have to fight their way in.

The Northern Option

Thanks to “joint exercises” with Belarus, Russia now has forces just 240 miles due north of Kiev. This provides the option of a quick dash to the Ukrainian capital to remove the Zelensky government and install a pro-Kremlin candidate. Such an operation would be reminiscent of the successful invasion of Afghanistan at Christmas 1979, when Soviet troops took Kabul within 3 days and installed Babrak Kamal as president. The operation involved 25,000 troops and 280 transport aircraft and went like clockwork.

Such a dash to Kiev might be possible. Most of Ukraine’s hardened troops are deployed in the east of the country. The Russians would soon establish complete air dominance. However, Kiev is not Kabul. It is a large modern city and the Ukrainians might well fight for it street by street. The Zelensky government is less popular than it once was but it is unlikely to crumble. Even if a puppet regime could be installed, what then?

Russia might be able to pacify much of the area east of the Dnieper but in Kiev itself and to the west, there is a good chance of popular resistance. Ukraine could be split in two and any Russian short-term success might develop into a longer-term nightmare.


Cipher Brief Subscriber+ Members receive exclusive expert briefings from members of our expert network.  Upgrade to Subscriber+ today.


Putin’s Lesser Options

There is a plethora of lesser options along Ukraine’s eastern border. Russia could easily make incursions to carve out additional pieces of territory. One possibility would be the industrial city of Kharkiv. The problem is that the gains would be too insubstantial for all the political risk that Putin has taken in recent weeks. It would not fundamentally change Ukraine’s economic or political viability as a country and could actually increase its determination to join the European Union and NATO.

However, the seizure of Odessa could be a game-changer. It is Ukraine’s third largest city with a population of over one million and includes a vital seaport. The port handles the vast majority of Ukraine’s maritime cargo and serves as headquarters for Ukraine’s navy. Much of its population is Russian speaking. However, it would be a demanding overland operation using the forces massed at Rostov-on-Don and in the Crimea, whilst also using air-power and naval and amphibious forces.

Rostov-on-Don to Odessa is 500 miles. It could take several days of fighting and is not without risk but once Russia had established aerial superiority, it should be manageable. Only a hundred more miles beyond Odessa would provide Russia with a land route to Moldova which Putin also sees as part of his sphere of influence.


Listen to The Cipher Brief’s Open Source Report Podcast – a weekday open source collection of the stories impacting national security with your hosts Brad Christian and Suzanne Kelly.  Subscribe wherever you listen to podcasts.


The loss of its ports on the Sea of Azov and the Black Sea would be a crushing blow for Ukraine and would hugely affect the viability of a country that is already struggling economically. It would have the additional benefit of providing Russia with a second land-route to Crimea and a much more substantial one than the bridge over the Kerch Strait which was completed in 2019, five years after the annexation of Crimea. But the long strip of occupied territory from Rostov to Moldova would not be easy to defend from future Ukrainian counterattacks.

Putin’s Politically Risky Options

Finally, Putin has two options which are politically much riskier because they would directly challenge NATO members’ territory and, in the former case, might result in killing NATO troops. One would be to seize the Suwalki Gap between Belarus and the Russian enclave of Kaliningrad. This would mean annexing a small piece of either Poland or Lithuania. The other would be to carve out a town from one of the three Baltic States. The obvious contender would be Narva in Estonia which has a Russian-speaking majority. To the Western way of thinking, this would be needlessly provocative but Putin could be attracted for that very reason. It would also test whether the West is truly willing to fight for a small slice of territory belonging to one of its members. And Putin will not want to stand down his troops without some tangible gain.

Read more expert-driven national security perspectives, insights and analysis in The Cipher Brief

The post Putin’s Risky Options in Ukraine appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3fNbpka
via IFTTT

Monday, January 17, 2022

Anticipating Russia’s Next Move in Ukraine

“The Cipher Brief has become the most popular outlet for former intelligence officers; no media outlet is even a close second to The Cipher Brief in terms of the number of articles published by formers.” – Sept. 2018, Studies in Intelligence, Vol. 62 No.

Access all of The Cipher Brief’s national-security focused expert insight by becoming a  Cipher Brief Level I Member .  

 

 

The post Anticipating Russia’s Next Move in Ukraine appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3Kj9EsZ
via IFTTT

Tuesday, January 4, 2022

The Value of a Well-Placed Spy in Moscow

EXPERT PERSPECTIVE — “I hope CIA has an agent like Dmitry Polyakov operating in Moscow right now,” writes Cipher Brief Expert and former Deputy Director of Counterintelligence at CIA, Mark Kelton.    

Access all of The Cipher Brief’s national-security focused expert insight by becoming a  Cipher Brief Level I Member .      

The post The Value of a Well-Placed Spy in Moscow appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3sYgL3U
via IFTTT

Tuesday, December 14, 2021

The Afghan Debacle Should Prompt China to Revise its South Asian Policy

This piece was first published by RUSI in London.  The views do not represent those of RUSI.

EXPERT PERSPECTIVE — While China has tried to rebalance its relations between India and Pakistan before, recent developments in Afghanistan should give it fresh impetus to do so.  Any future Cold War between the United States and China would be entirely different to the previous version for several reasons of which the most obvious is the economic and financial inter-dependency between the two countries. However, one similarity could survive in the form of proxy conflicts such as those seen in Angola, Afghanistan and Nicaragua in the 1980s.

A proxy conflict in South Asia would be extremely dangerous both because of the numerous geopolitical fissures which opposing sides would seek to exploit and the fact that India and Pakistan now have nuclear weapons and the means of delivery. In the previous Cold War neither New Delhi nor Islamabad had credibly deployable nuclear weapons and, although India leant clearly towards the Soviet Union and Pakistan towards the West, there was no proxy war in the Subcontinent, only further north-west in Afghanistan.

Relations between India and Pakistan are already dangerous enough without being drawn into a new Cold War. The Balakot episode of 2019 took both countries to the brink of war and was de-escalated more through luck than good judgement. Since then, China has become an active participant through its hostile operations along its disputed border with India in the Himalayas and, most recently, by appearing to endorse Pakistan’s preference for a Taliban-only government in Afghanistan.

I am told confidentially that China did question the wisdom of Pakistan’s judgement in August just as the Ashraf Ghani government collapsed but, crucially, it did not press the point. Beijing may have calculated that the Pakistan army could not have forced the Taliban to form an inclusive administration and that the influential Corps Commanders in Pakistan might even have resisted Chinese pressure at such a seminal moment.

Following the US withdrawal, Beijing will surely now recognise that it needs its own policy on Afghanistan; it can no longer outsource decisions to Pakistan. There is too much at stake including the threat from Uighur militants, Chinese investments in the mining sector and possible future Belt and Road Initiative (BRI) projects.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Beijing will also know that the Indian government is infuriated by its loss of agency in Afghanistan after 20 years of political and economic investment there. Following what looks (at first sight) like a stunning victory for Pakistan, India will inevitably wish to make Islamabad pay a price. New Delhi is not short of options. It will doubtless see opportunities in the growing dissent in Baluchistan (and Gwadar in particular) against the BRI, and in the increasing disenchantment amongst Pashtuns in Khyber Pakhtunkhwa (formerly North West Frontier Province) and in the huge port-city of Karachi where Pashtuns represent some 20% of the population. India will also push its maximalist position on Kashmir by which Gilgit-Baltistan (through which several BRI projects traverse) is claimed as part of India.

China may also reflect on the cost/benefit of its activity along India’s northern border. In the long run China has much to lose by stirring up a region which offers India (and potentially the United States) a direct route via the Aksai Chin into China’s two least contented regions; Tibet and Xinjiang. It could be argued that, in the new era of hybrid warfare and imaginative cyber operations, direct access to a territory is less essential for a campaign of disruption. Possibly.  But China would be wise not to throw stones in such an extensively glazed region.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


All of this argues for China to review its South Asia strategy with a view to a degree of rebalancing between India and Pakistan. The continuation of existing policy will see Afghanistan decline back to its pre-2001 status as an economic and social wasteland. It could witness Pakistan increasingly undermined by radical Islamist groups operating from Afghanistan, the tribal borderlands and inside the cities of the Punjab and Sind. It will see a frustrated India taking ever less flexible positions on regional issues and on Chinese access to its huge markets. And access to Himalayan waters will become the dominant theme in the region.

It is often forgotten that China attempted to rebalance its relations between India and Pakistan in 1996 in a remarkable speech delivered on 2nd December by President Jiang Zemin in Islamabad.  After a number of standard paragraphs about the “profound friendship” between China and Pakistan, Jiang then turned to the importance of ‘South Asia’ to Beijing and then, to an increasingly appalled audience, began praising the “the multi-dimensional exchanges and cooperation between China and the various South Asian countries”. The name of India never passed his lips but it was clear to all that China intended to rebalance its Indian and Pakistani relationships.

To grasp the ambition behind the speech two passages are worth repeating; “China and South Asian countries are all members of the developing world dedicated… to developing their economies and improving their peoples’ livelihood. They all need a peaceful and stable international environment and, particularly, a favourable surrounding environment.”

And “China will, as always, support South Asian regional cooperation, support the proposal and initiative for the establishment of South Asia Nuclear Free Zone and Indian Ocean Zone of Peace, and support all efforts designed to serve peace, stability and development in the South Asian region.”

The Indian nuclear tests just 18 months later killed the rebalancing in its infancy but the sentiments are arguably truer today than in 1996. If Pakistan and Afghanistan are to survive they need to open their borders with India and become transit routes to Central Asia. Now that the US has departed the stage only China can facilitate such ambitions. The alternative is more terrorism and instability in an area where there are far too many nuclear weapons. Even without a new Cold War Beijing’s current course is too dangerous.

Read more expert-driven national security insights perspective and analysis in The Cipher Brief

The post The Afghan Debacle Should Prompt China to Revise its South Asian Policy appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3IRJsor
via IFTTT

Monday, December 13, 2021

The Supply Chain is the Perfect Asymmetric Target

Robert Hannigan is a Principal Member of The Cyber Initiatives Group, powered by The Cipher Brief.

EXPERT PERSPECTIVE — Asked recently what risk he worried about most, alongside Taiwan and Ukraine, Cipher Brief Expert, General Stanley McChrystal said it was cyber security, particularly in the supply chain.

General McChrystal is part of a growing group of the most senior operational and strategic US commanders that include former Chairman of the Joint Chiefs of Staff, Admiral Mike Mullen, in seeing the supply chain threat as existential. Unless the supply chain can be secured, the whole infrastructure on which Western economies rest, not to mention their military defences, will be compromised.

Two factors have brought the otherwise dry subject of supply chain security to the top of the political risk table. One has been the pandemic, in which we have become painfully aware of the fragility of supply chains and the over-dependence of Western countries on external providers, particularly in China. We have also realised how little we actually understand about our supply chains: which companies are in them, who owns them, who controls them and how they can be disrupted.

The other factor has been the SolarWinds attack, almost exactly a year ago. The sophistication of this compromise of the software supply chain, which had probably been active for at least a year before it was discovered, captured headlines around the world. This was partly because SolarWinds Orion was in use by a whole range of government agencies and major companies. More acutely than many other earlier third-party compromises, it illustrated why supply chain companies are such attractive targets: their security is often poor and they represent a softer way into a vast range of customers, including many companies that would in themselves be a hard target. The supply chain is the perfect asymmetric attack.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Interest in this is leading to some positive focus.

There are two challenges. The first is visibility. Governments and companies need to understand what the security of their tens of thousands of vendors looks like in real time. That means having the same attitude to the ecosytem of third parties as they would to their own networks. It also means understanding ownership and control and a range of other dependencies. It requires constant monitoring of the supply chain, not occasional compliance exercises. In the end, this will probably need to be required by regulation, but there is no need to wait for that.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


Beyond visibility and understanding there needs to be action. We have to move from assessing the risk and admiring the problem to fixing it. This means taking a range of actions from helping vendors to remediate weaknesses to addressing issues of ownership. The UK’s new legislation giving government greater powers to intervene in mergers and acquisitions on national security grounds is long overdue and brings it into line with other Western countries. But these assessment processes will need to become dynamic and constant to reflect the ever-shifting nature of modern vendor ecosystems.

The complexity of the global supply chain is the creation of open economies and democratic societies; but unless it is secured it will ultimately undermine them.

Read more expert-driven national security insights perspective and analysis in The Cipher Brief

The post The Supply Chain is the Perfect Asymmetric Target appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3DKkSSM
via IFTTT

Tuesday, December 7, 2021

The Urgency of the Moment for Congress on AI and National Security

(Editor’s Note: This article is the fifth and final article in a series first published by our friends at Just Security that is dives into the foundational barriers to the broad integration of AI in the IC – culture, budget, acquisition, risk, and oversight. This article considers a modified approach to congressional oversight of the IC. The author’s full report examining all of the topics in this series in greater depth is available here.)

Throughout this series, I have explored the most pressing foundational issues impacting the Intelligence Community’s (IC) ability to meet the urgency of this moment in the global artificial intelligence (AI) race. The current bipartisan support for taking bold action to drive national security use of AI is key to the IC’s success. That support must propel change in the priority areas I have already identified: modernizing the IC’s budget and acquisition processes and enabling a risk-tolerant culture with a new IC AI risk assessment framework that helps IC officers navigate the uncertainty that necessarily accompanies technological innovation. There is one other area, however, that cannot be ignored if the IC is to keep pace with our nation’s adversaries and provide policymakers with accurate, timely, and impactful insights: congressional oversight.

Congressional oversight of the IC is critical. Congress is the eyes and the ears of the American people. Among other things, it is charged with evaluating IC program performance, and ensuring the IC is efficiently and effectively spending taxpayer dollars and properly executing national security activities consistent with statutory requirements and legislative intent.

But intelligence oversight is complicated and has not sufficiently evolved with the times. When it comes to assessing progress of IC programs, standard oversight processes typically track defined, pre-determined requirements, cost, and timelines. These metrics have worked reasonably well for large programs like the acquisition of satellites and buildings, for which there is a clear beginning, middle, and end, with easily identifiable milestones and a definite budget. However, AI is different; its development moves back and forth across a spectrum of activities often without discrete steps, and failure is a necessary part of the process as the technology evolves and matures. Traditional metrics are, therefore, less effective for AI, as the value (or lack thereof) of certain milestones may only become clear partway through the development process and desired end-states may shift.

The IC has four primary congressional oversight committees. In addition to the House Permanent Select Committee on Intelligence (HPSCI) and the Senate Select Committee on Intelligence (SSCI), which have oversight jurisdiction over the IC, the House Appropriations Committee Defense Subcommittee (HAC-D) and the Senate Appropriations Committee Defense Subcommittee (SAC-D) provide the IC’s money. These four committees (hereinafter collectively “Committees”) must consider a more adaptive approach to oversight, measuring progress and failure through metrics that are less rigid and better tailored for AI and other emerging technologies. In doing so, the Committees may lose a measure of certainty that impacts their most powerful lever – fiscal control over the IC. For that reason, the Committees and the IC must simultaneously build a greater degree of trust, transparency, and ultimately partnership.

Adaptive Oversight

Much like AI itself, congressional oversight of AI activities must evolve and adapt to the world of emerging technology. While there are a variety of rules that govern Congress’ oversight responsibilities, Congress has considerable latitude and discretion in the execution of that oversight, including how they measure executive branch progress. To improve IC oversight engagements, Congress and the IC must start with a shared strategic vision for what a successful AI project looks like and create an approach to oversight that is tailored to achieve this goal.

Current measures and metrics often focus on ensuring projects stay on track in terms of cost and schedule; there are well-defined outputs, such as number of tools built, and static timelines for delivery. Such demonstrable deliverables are objective, consistent, and easy to measure, but they are ill-suited to AI, the underlying technology for which is still evolving. To take full advantage of AI’s emerging possibilities, the IC must have the ability to test, adjust, and pivot as new algorithms and capabilities are developed and applied to different problem sets.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


Recognizing that detailed requirements and program schedules are not well-suited to measuring the success of software, which is the core of AI, the Defense Department is already considering changes to related oversight. Research by Google and others indicates that metrics aligned with DevSecOps, the industry best practice for rapid, secure software development, can better predict the performance of software teams. DevSecOps seeks to unify software development (Dev), security (Sec), and operations (Ops). Its metrics allow teams to focus on outcomes while adjusting for multi-dimensional, dynamic, and continuous improvement in technology along the way. Teams can move quickly, respond rapidly to user needs, and produce reliable software – all critical when it comes to scaling AI in the IC.

In addition, AI-related metrics must focus on key performance indicators that track the progress of how AI tools evolve rather than on only the final product to both create the opportunity for, and reflect the expectation of, value to the user earlier based on strong communication and feedback loops. Performance evaluation should center on delivery of incremental capabilities, drilling down on speed and functionality together in phases and time-boxing segmented activities, from staffing to new releases to bug-fixes.

The IC and the Committees must learn from industry best practices related to DevSecOps and software, and together develop relevant and adaptive metrics that can be consistently applied but are more aligned with AI’s attributes. This joint process would itself serve as an opportunity for learning and trust building. Once developed, the metrics must continue to drive accountability and demonstrate value, and if timelines slip, the IC must quickly inform the Committees and produce new targets. The IC should expect to use the new metrics first on low-risk activities and ensure the Committees understand the standards and benchmarks the IC is using so they can evaluate programs accordingly.

While pivoting to new metrics is a good start, the IC and the Committees also must remain open to iteration, allowing oversight to change if the initial approach is less than optimal.

Trust, Transparency, and Partnership

There is no dearth of oversight today – each year, there are hundreds of written reports, in-person briefings, phone calls, hearings, and other engagements between congressional overseers and the IC. However, current oversight engagements suggest a lack of confidence and trust in the IC; they are often excessively tactical and focused on execution details that provide neither a strategic perspective on the health of a program nor an understanding of potential long-term opportunities and risks. These engagements drive a continuous cycle of meetings and briefings, requesting deeper levels of detail, in an effort to achieve the desired understanding. Unfortunately, layering detail on top of detail does not produce strategic insight, and this approach is ultimately ineffective – the Committees do not feel sufficiently informed and the IC does not feel sufficiently supported, steering the relationship toward one that is more adversarial than collaborative.

Current oversight processes were not designed to be overly burdensome or act as roadblocks to progress. They were designed to give Congress appropriate insight and confidence that executive branch activities and spending are being carried out efficiently, effectively, and consistently with the law. Unfortunately, the processes have become onerous due to a history of issues that have undermined Congress’ trust and confidence in the IC. The IC must rebuild trust with Congress so overseers can step back from day-to-day operational details and engage with the community at a more appropriate strategic level.

The relationship between a Board of Directors (Board) and a Chief Executive Officer (CEO) in the private sector is a helpful model. The Board has ultimate responsibility for ensuring the organization is appropriately stewarding the resources entrusted to it, while the CEO manages the execution of a company’s day-to-day activities. According to the KPMG Board Leadership Center, the key to a healthy relationship between a Board and the organization it oversees is trust and transparency, where the Board has constructive conversations with the leadership team about significant decisions and issues as well as the opportunity to provide meaningful input before decisions are made, and the leadership team receives valuable feedback. It is not the Board’s role to “see every scrap of paper that the management team sees,” and it should not wade into tactical details of an issue unless the issue is related to strategy or risk.

Of course, the analogy is not perfect, but it can be instructive. The Committees, which are like the IC’s Board, have the responsibility to ensure the IC is appropriately stewarding its resources. In doing so, they also have the responsibility to leverage their knowledge and expertise to provide strategic advice and direction rather than diving into many levels of detail. But, as with the private sector, without the requisite trust and transparency it is difficult for the Committees to operate at the strategic level.

To rebuild trust, the IC and the Committees must fundamentally alter the nature of their interaction, engaging not only in formal ways but also increasingly in informal engagements to better manage expectations and reduce the element of surprise. The IC should seek the Committees’ views on significant activities before final decisions are made and work to incorporate their feedback when possible to build stronger support and buy-in from the Committees. Formal engagements are important, but informal engagements create relationships that lead to true partnerships.

IC Actions

As the IC seeks additional flexibility from the Committees, it should increase trust and transparency through a more informal and open posture with Congress that includes accommodation from deliberative process privilege as needed. This would require a significant cultural shift but, if done carefully, would pay enormous dividends.

Specifically, the DNI should propose two informal, private engagements with the Committees: 1) semi-annual conversations between Committee staff and high-priority AI project leads for conversation and feedback on progress, issues, concerns, and requirements; and 2) periodic IC leadership “coffee catch-ups” with Committee members to better drive the strategic relationship, provide the benefit of each other’s thinking at that moment, and develop a sense of partnership. These engagements should not track metrics or seek to accomplish specific tasks, but rather should create mutual understanding, open dialogue, and build trust around AI activities. AI project leads should share what is known and unknown about projects, potential outcomes, and any changes in spending the Committees may see in the coming months. The IC leadership coffees would, of course, produce benefits well beyond the IC’s AI activities.

It is unlikely that the information shared in these engagements would implicate the executive branch’s deliberative process privilege, which reflects the president’s constitutional authority to withhold certain information from Congress before a final decision has been made within the executive branch, because these discussions would not be tied to specific decision points. Nevertheless, to help navigate these conversations the DNI should clearly set expectations with the Committees that these conversations are not formal notifications and must not be used to later reprimand the IC. The DNI should also create IC legislative engagement principles to help IC officers appropriately engage. To the extent the IC does seek pre-decisional views from the Committees, the IC should look to the accommodation process, which allows the executive branch to provide information that might otherwise be privileged if necessary to facilitate the legitimate needs of the legislative branch.

Leaning forward in this way does come with risk that the Committees will inappropriately interfere in executive branch matters. Therefore, to truly build trust, the Committees must agree to be judicious in these engagements, focus on insightful strategic and risk-based questions reflective of their extensive experience and expertise, and not misuse the information to obstruct the executive branch’s authority to execute the law. Any actions to the contrary will undermine the progress made and likely end this more open dialogue. However, with agreed upon guidelines and parameters, these informal engagements would improve the AI dialogue between the IC and Congress, leading to deeper Committee understanding and, ideally, strengthening Committee support for legislation and funding of AI activities, even in times of loss or failure.

Committee Actions

As the Committees introduce more agility into their processes and adjust their oversight to accommodate AI, they should consider the following steps to increase their confidence in the IC’s activities.

First, to expand their capacity and institutional expertise, the Committees should re-organize staff along functional lines, as has already been done in some committees. Such a change would allow staff to develop a deeper understanding of various AI tools and technologies, apply that understanding strategically across IC elements, and get a more holistic cross-IC view of AI coordination and activities. While the more common model of organizing staff by IC element makes logical sense, expecting staff to understand everything an IC element does is unrealistic and unreasonable, especially given they are often single-threaded in their roles. Refocusing staff on specific functional areas and allowing them to become experts would greatly benefit not only the Committees’ oversight of those activities, but the IC elements they oversee. In addition, as many have recommended, Congress should recreate the Office of Technology Assessment – a congressional agency that provided impartial analyses of technology and science issues – to provide the Committees with access to deep technical experts when needed.

Second, the Committees should hold formal semi-annual closed substantive briefings on high-priority AI projects. In these briefings, the IC should provide enough detail for the Committees to understand progress against the new metrics and ask questions about the strategic direction of the programs, areas of risk, concerns, unexpected issues, and future legislative and funding requirements. These briefings would provide an official mechanism for the IC to show forward movement and elevate significant issues, and for the Committees to track high-priority AI activities across the IC.

Third, if the IC receives no-year or multi-year funding for AI, the Committees should hold a focused annual review of AI spending during the previous year. This review should include an understanding of what is going well and what did not go as expected so the Committees can provide a timely and critical check on the use of that money. If the funding has been executed in accordance with congressional direction – even if some of the activities have failed – the money should continue to flow. If the funding has not been executed properly or consistently with congressional direction, the Committees should have the ability to stop the funding immediately.

Conclusion

The executive branch has significant work to do to speed and scale AI into the IC: it must reform budget and acquisition processes; create an IC AI risk assessment framework to encourage reasonable and informed risk-taking; and build an IC culture that supports innovation and accepts a level of failure. But the IC’s success will be hard-fought and fleeting if the IC’s congressional oversight committees do not simultaneously re-examine their supervision of the IC.

The Committees, similar to a corporate board, provide an important check on the IC’s activities. To be successful in this new world of AI and emerging technology, the Committees must embrace a strategic reset, increased flexibility, and an adaptive approach to oversight. In return, the IC must lean forward with open and informal dialogue with the Committees. These adjustments will take practice to get right but, if successful, will dramatically change the IC’s partnership with the Committees for the better, providing the Committees with earlier and improved insights and leading to greater support and backing for the IC.

The issues highlighted in this series are not new; countless others have raised them and good people have worked hard to solve them over many years. We cannot wait any longer for implementation to take hold. China and other adversaries are at our doorstep, and the IC must move immediately to embrace the reality of a world awash in data moving at the speed of emerging technology. Now is the time to take advantage of the groundswell of support, remove unnecessary bureaucratic barriers, and take decisive action.

Additional detail and implementation steps in all of the areas discussed in this series can be found in The Integration of Artificial Intelligence in the Intelligence Community: Necessary Steps to Scale Efforts and Speed Progress, a full-length report produced through the American University Washington College of Law Tech, Law & Security program.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post The Urgency of the Moment for Congress on AI and National Security appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3GqDBoj
via IFTTT

Thursday, December 2, 2021

CIA Deputy for Digital Innovation Talks Mission, Partnerships and Espionage Challenges

CIA Deputy Director for Digital Innovation Jennifer Ewbank said recently “the cyber forces and other threats that we confront across the digital landscape are formidable and they are changing the very nature of the intelligence business.” 

Ewbank, who spent much of her career with the Agency running overseas operations, noted at The Cipher Brief Threat Conference, not only how U.S. adversaries have upped their digital game, but also how the agency has been “grappling with how to manage the explosion in volume and variety of data fueled by technological change,” saying, “It has transformed the intelligence business in many of the same ways it’s transformed the commercial marketplace and the global economy as a whole.

Below is her perspective on the evolving digital landscape, the hazards and opportunities within and what it means for the organization she leads at CIA. Her comments have been lightly edited for clarity. 


Jennifer Ewbank, Deputy Director for Innovation, CIA

Jennifer Ewbank is the Deputy Director of CIA for Digital Innovation, responsible for accelerating the development and integration of digital and cyber capabilities across all of CIA’s mission areas. She also focuses on enterprise information, technology, cyber operations and analysis, data strategy, artificial intelligence, open source collection, and reporting.


The cyber forces and other threats that we confront across the digital landscape are formidable and they are changing the very nature of the intelligence business. They represent a real danger to our national and economic security, but they’re not really a surprise. Six years ago, the CIA stood up a new Directorate of Digital Innovation. That’s the part of the organization that I now have the honor of leading. It was a move to redesign the intelligence enterprise to meet emerging threats in the digital domain, and to leverage these new capabilities for operational advantage and analytic insights.

The espionage business, as I see it is, is often thought of as the dark side, but it’s really about the art of the possible. Success requires creativity, ingenuity, dogged determination, and a healthy dose of optimism. You have to believe that you can do things that – at their core – may seem impossible. The Directorate of Digital Innovation (DDI) is charting the course for CIA’s art of the possible in the cyber and digital realm.

Today, DDI represents a multidisciplinary fusion of cyber offense, cyber defense, open-source collection, data science, artificial intelligence, and enterprise information technology, all of which are increasingly essential for the CIA’s success in a world of ubiquitous sensing, cyber threats, and the exponential increase of data.

Our enduring mission in DDI is to integrate CIA’s human, technical, and digital operations at scale, which is an important characteristic to counter our foreign adversaries at the speed of mission. To make this happen, we are charged with raising the digital acumen of CIA’s workforce to position the agency for success long into the future. However, DDI tackles none of this alone- it’s all about partnerships within the agency, with partners across the national security community, and with patriotic Americans.

I’ll share something I learned coming from the director of operations into this new directorate a few years ago: our workforce is tremendously skilled, capable, and highly agile. They work as integrated teams each day taking on some of our most daunting intelligence challenges: technologically, operationally, and analytically. We sit at the nexus of technological threats and the data explosion, and I believe our work becomes only more critical to the agency’s success with each passing day.

Personally, it’s a huge pleasure and an honor to lead the agency’s digital workforce. It’s an incredible team brimming with talent, creativity, and dedication. However, when we talk about the threats and opportunities across the digital landscape and their intersection with defensive and offensive operations, I speak to you as more than the head of a large organization in Washington. I have spent most of my own intelligence career overseas running operations and I’ve seen firsthand what our adversaries are capable of, as well as the power of integration. It’s a bit of a buzzword at times, but it is an extremely powerful thing.

I was there when we combined these new areas of digital expertise with our traditional strengths in technology and science, all in partnership with our core human intelligence tradecraft. I’ve been part of successes, large and small and have certainly seen my share of setbacks along the way. So, our discussion today of what’s happening in the digital landscape, the explosion of data in a highly-connected world of ubiquitous sensing, the onslaught of cyber threats we face from hostile actors, and how we as a service and as a country respond is more than just theoretical for me. It’s personal.

When the CIA was created in 1947, our principal rivals were the Soviets and their surrogates across Eastern Europe. In those early years, the agency dueled with the KGB on the streets of Moscow and the Stasi on the streets of Berlin and those kind of gritty and determined first generation officers operated under extremely challenging conditions, sparring with their Eastern Block foes while dodging surveillance and evading checkpoints. Tensions ran very high at that time. In 1956, when the east Germans discovered a CIA/MI6 tunnel under the streets of Berlin, our legendary base chief at the time went down there himself and from behind a machine gun, made sure that no unauthorized person was going to cross over into the American sector. Obviously now, the only tunneling most base chiefs and station chiefs are doing these days are struggling to set up VPNs on their MacBook, but some of the most consequential threats we face today are in the digital domain.

In recent years, we’ve experienced a seismic shift in the contours of that environment and with our mission responsibilities at CIA becoming progressively more challenged by these shark infested waters of the information environment, our agency has been grappling with how to manage the explosion in volume and variety of data fueled by technological change. It has transformed the intelligence business in many of the same ways it’s transformed the commercial marketplace and the global economy as a whole.

Challenge is present for everyone but for those of us in the intelligence arena, the stakes are particularly high. Our long-time strains continue with Russia and China has emerged as our most significant and daunting challenge but beyond the great power competition, there are lots of other state and non-state actors alike vying for power and influence too, and every single one of them is using these new technologies to support their cause. In the final analysis, our own competitiveness as an intelligence service and an intelligence community will depend on how fast we turn this evolving digital landscape to our own advantage relative to our adversaries.

As we know, foreign states have leveraged their cyber capabilities to steal information, influence foreign populations, and menace private industry with physical and digital infrastructure being favorite targets. We also know that data analytics and artificial intelligence capabilities being developed by digital autocracies to monitor and control their own societies are now arrows in their own quiver to target us. So, although an increasing number of others are dabbling in cyber, China, Russia, Iran, North Korea remain the core antagonists. Each is at the controls of highly developed, well-resourced cyber programs pointed like daggers at U.S. interests at home and abroad. Joining this fray as of late are the criminal ransomware outfits who have monetized hacking and are plotting as we speak to hold U.S. networks hostage at digital gunpoint just as they did with the recent Colonial Pipeline and JBS attacks.

The Chinese are clearly formidable players in the digital underworld and that’s something that had, for a few years, evaded much public notice. Barely concealing its ties to criminal hackers, the Chinese government views its competition with the west as a zero-sum equation where China’s rise must come at the expense of America’s decline. This has fueled brazen aggression lately as China saturates our networks with disruptive intrusions designed to undermine the security and competitiveness of our nation. Their systemic industrial level theft of our personal information and intellectual property is both shameless and unrelenting and part of a concerted campaign to chip away at our prosperity and diminish our economic might. China presents a prolific and very effective cyber espionage threat, a growing influence threat, and considerable, substantial cyber-attack capabilities.

China’s cyber espionage program is particularly formidable in two respects: its sheer size and its vast ungoverned, contract hacker ecosystem. Beijing also sees cyber as a primary means for conducting political warfare. A concept that includes virtually all means short of war, to achieve its national objectives.

One aspect of China’s influence campaign that’s particularly noteworthy and reflects this theme of scale is the broad array of languages and media used to disseminate Beijing’s messaging. In recent years, we’ve seen vast Chinese spam networks who have posted videos on YouTube in order to influence audiences both in the U.S. and around the globe.

Russia, too, remains a significant cyber threat. It has unleashed increasingly sophisticated espionage influence and attack capabilities against the West and Russian regional rivals. The Russians consider cyber hacks an acceptable tool for deterring adversaries and prosecuting conflicts and they view cyber espionage as routine business. We saw this with the recent software supply chain operation against Solar Winds where Russia’s foreign intelligence service executed a cyber espionage campaign against the U.S. by placing malicious code in broadly distributed software products. This was a brash demonstration of Moscow’s capabilities and proof if anyone needed it, that public and private organizations in the U.S. remain in Moscow’s crosshairs.

Alas, the Russians and the Chinese are not alone. Iran’s technical expertise and zeal for aggressive cyber operations further jeopardize the integrity of the United States and our allies’ networks. The Iranian track record includes attacks on critical infrastructure, which are particularly worrisome as demonstrated by their multiple cyber-attacks last year against Israeli water facilities. Iranian hackers recently targeted dozens of U.S. and Israeli defense firms according to press reports. So, it’s fair to say that Tehran is responsible for lots of other nefarious activities on the net, but we’ll leave it there.


The Cipher Brief hosts private briefings with the world’s most experienced national and global security experts.  Become a member today.


North Korea’s cyber program remains troublesome as well. The notoriously mercurial Pyongyang likely possesses the expertise to disrupt critical infrastructure and business networks in the United States judging by their track record. North Korean hackers also have long posed a very significant threat to the integrity and stability of the international financial system and have engaged in a variety of illicit activities to include cybercrime to generate revenue for the regime.

Last, but certainly not least, are cyber criminals motivated by simple financial gain. Their goal is to compromise our personal, financial, and health data to leverage it on underground black markets. Ransomware is just the latest incarnation and U.S. consumers and businesses alike remain susceptible to traditional fraud, extortion, and credit card theft proving that even criminals are leveraging digital innovation. The recent appearance of ransomware as a service has made ransomware available on a scale never before seen and when we consider the potential impact of ransomware attacks on critical infrastructure or government networks in the United States, the potential impact is really clear.

On the whole, our national and economic security are put at risk by all of these threats. There is, however, a flip side to this coin and technology as always is a two-way street. There are windows of opportunity for our organization and others in the intelligence community to strike back and turn the tables on rivals and competitors to gain the strategic advantage we need to succeed in the 21st century.

A central pillar of our strategy at the Director of Digital Innovation is to outmaneuver adversaries in the digital sphere which requires a wholesale embrace of the power of innovation. That power has become the bedrock of our organization underpinning so much of the mission success that we have been able to achieve. Adapting to this kind of shifting intelligence landscape has long been encoded in the very DNA of the Central Intelligence Agency. For us in DDI, it is foundational to everything we do and it’s why we put innovation in the name of the directorate. In a constantly evolving battle space where the rules of the road are rewritten with head spinning speed, we must embrace risk and we must embrace experimentation as the key to innovation and the process of unlocking new insights.

The coming decade will bring an unprecedented set of national security challenges that will demand an unprecedented response and to ensure CIA’s readiness for long term success, we made a few smart adjustments to our priorities regarding China, technology, our people, and partnerships to optimize the agency’s ability to confront future threats. We do all of this while maintaining our focus on never taking our eye off enduring challenges such as counter-terrorism and Russia. Perhaps for us, a useful guiding principle, comes from a Latin proverb made famous by the Roman poet Virgil, “Fortune favors the bold.”

Indeed, to prevail against 21st century foes whose technical mastery is matched only by their malicious intent, it’s imperative that we boldly develop new tradecraft, new tools, new platforms, and other mission solutions that provide decisive operational advantages. Every day we fail to innovate, fail to take chances, or fail to challenge ourselves and our conventional wisdom, we risk mission failure or worse, irrelevance. Innovation is not just the core of our mission; it is the life blood of American industry and any organization today enduring to be even modestly successful in this new digital landscape.

To illustrate the point: what is blue and gold, once owned by almost everyone and today no longer exists? Those of us old enough will remember that was a Blockbuster Video Membership Card. The collapse of this one-time empire is a cautionary tale for all of us and reveals the fate of any organization that fails to innovate in a hypercompetitive and data driven digital world. Blockbuster had a rapid collapse from the top of its industry to complete irrelevance in the span of just six years, all because it failed to innovate as others aggressively leveraged new technology and rapidly expanding digital infrastructure.

The Blockbuster story reflects in some ways the crossroads that we in the espionage business have reached today. However, it’s not a choice between dooming ourselves to Blockbuster’s fate or following some proven route already mapped out by others. It’s about our willingness to be explorers ourselves and to chart a very new course. Teams of cutting-edge designers and engineers at Netflix, Apple, Disney, and Amazon don’t sit around tinkering with their platforms just to meet a customer’s needs today and modernization is not the act of upgrading an inventory from VHS to DVD.

Success, in this new world, in this digital world, hinges on our ability to project requirements and solutions well into the future, to look out beyond the horizon, to anticipate and gamble on the future, as uncertain as it may be and the same holds true for the art of espionage in a world of dramatically fewer real secrets.

Social media, online digital news platforms, ubiquitous sensing, commercial collection, on land, at sea, in the air, and the internet itself mean that we don’t really lack insight even in far flung corners of the globe. The price of fuel in Moscow, the conditions at a port on the coast of Africa, the size of a pro-democracy demonstration in Hong Kong, it’s all available at our fingertips on our mobile devices while secrets, plans and intentions of despots and terrorists – the things that have yet to happen – are increasingly more difficult to uncover by traditional means.

Success can be unlocked through innovation and partnerships. We’re not alone in pursuing the technological solutions of tomorrow, and yes, being first does matter. Ask those in the Manhattan project, ask NASA, ask Netflix, ask China.  They aim to be the first to lead in the digital world as shown in the Made in China 2025 program and their complete commitment to AI dominance by 2030.

The Secret Service has a saying about schedules: if you’re early, you’re on time; if you’re on time, you’re late; if you’re late, just don’t bother coming. Similarly, we can’t think about catching up with the Chinese, the Russians, the hackers, hacktivists, or any of the others are out there trying to do us harm because at the moment when we’ve caught up, we’re already falling behind again. The race for decisive advantage in this digital realm is not about keeping pace, it’s about outpacing and about beating your competitor to the finish line. Innovation and partnership will help us do that.

Safeguarding the national and economic security of the United States is paramount to all of us. That’s why our organization values smart partnerships with fellow patriotic innovators in the private sector. Such partnerships promote greater exchanges of information, more efficient use of resources, and bring a broader range of expertise to problem solving. While our specific equities may differ, we can each say unequivocally that we all want the same thing fundamentally and we’re all on the same team. We all want to see the United States succeed and flourish and remain a global leader, all while reflecting the Western democratic ideals that we hold so dear. The private sector has always been America’s engine for innovation and change and it’s one of our greatest strengths as a nation.


Go beyond the headlines with expert perspectives on today’s news with The Cipher Brief’s Daily Open-Source Podcast.  Listen here or wherever you listen to podcasts.


Certainly, government and industry must be partners in innovation, but in the 21st century, technological innovation is mostly going to emerge from the private sector. Look no further than the artificial intelligence and machine learning realms where private sector innovation is helping us harness the power of data. More than any development in this fourth industrial revolution where the boundaries between the physical and digital worlds are blurring, artificial intelligence holds one of the keys to the future of espionage. It will help us manage this data tsunami at machine speed and will help free up humans for the higher order cognitive functions that are still only possible with the biological, not a digital brain.

In the artificial intelligence arena, the intelligence community must now learn how to be a fast follower with industry. They have to learn to not be the primary creators of cutting-edge technologies predominantly developed by the private sector. They must be fast followers. That’s why deep and sustainable partnerships with private industry and academia are so vital for the CIA and the intelligence community as a whole. They allow both sides to best serve America’s interests and adapt to these constantly changing waves of new technologies.

The DDI is taking steps to strengthen collaboration within the industry. One major component of our approach to industry partnerships is our creation of innovation hubs. We are focused on identifying best commercially available solutions, especially in the artificial intelligence and machine learning areas, and exploring how we can rapidly leverage these new solutions to mission problems. By working in an unclassified and collaborative laboratory space, our innovation hubs can bring new technologies to mission more rapidly, enable faster investment decisions about digital technologies, and ultimately reduce the time from ideas to solutions.

As I’ve said to our workforce on far too many occasions to count, I want us to get out of the U.S. government’s business of bringing yesterday’s technology to you tomorrow. Therefore, an enduring aspect of our mission as CIA’s digital Sherpas, is to stay informed of new commercial technologies and position CIA to be that fast follower with industry. This is why in 2017, we opened up CIA’s Silicon Valley Innovation Outpost which facilitates engagement with companies in the tech sector and academics in Silicon Valley. Just last year, during the pandemic, we launched the Northern Virginia Innovation Exchange, a space for knowledge sharing and problem solving where we work side by side with partners in industry.

Though I hate to admit it, despite our best efforts, we are a large government organization. And so we must address the impediments that stand in the way of bringing new technologies rapidly into the CIA; we’re working on that.

We’re working on speeding up our accreditation process, looking for new acquisition authorities, and doing as much as we can in the unclassified space where we can adopt new ideas and new solutions at a much more rapid pace. We’re engaging industry across the investment spectrum to leverage their expertise and knowledge of the marketplace and to promote a culture of continuous innovation in a large government organization that’s not hardwired to do that. Through outreach to companies and by working with Silicon Valley based accelerators, we are able to discover new technologies in the marketplace to meet our sometimes very unique mission needs in the CIA. It is pretty good progress in the first six years for an organization, but we are far from finished. Innovation is a process, it’s not an event. However, there is no finish line. The end of any innovation journey just signals the beginning of the next uncharted course. No one these days is flying kites in lightning storms, but that’s the type of entrepreneurial spirit that we’re seeking in our ranks. It’s the foundation I believe for our future as an agency and it’s a future that the DDI, as a transformative element of CIA in the digital age, eagerly embraces.

The challenges ahead are formidable, but with a whole of nation approach encouraging closer partnerships between government and industry, we can defend our values against those adversaries who wish us harm.

As for the DDI, we can accelerate the adoption of emerging digital technologies and integrate them with CIA’s traditional strengths in human intelligence and technical intelligence to counter threats to our nation and the shared interests of our allies around the world. Only one question remains for my team and CIA’s Directorate of Digital Innovation: if fortune indeed favors the bold, just how bold can they be? I have seen this amazing team in action, and I know that they will bring the fight to our adversaries across the digital landscape.

Jennifer Ewbank is Deputy Director for Digital Innovation at the CIA.  Her comments were made in late October at The Cipher Brief’s Annual Threat Conference.

Read more expert-driven national security insights, perspective and analysis in The Cipher Brief

The post CIA Deputy for Digital Innovation Talks Mission, Partnerships and Espionage Challenges appeared first on The Cipher Brief.



from The Cipher Brief https://ift.tt/3rJZDhN
via IFTTT

https://pieces-auto-maroc1.blogspot.com/

 https://pieces-auto-maroc1.blogspot.com/