Search This Blog

Showing posts with label corporate espionage. Show all posts
Showing posts with label corporate espionage. Show all posts

Tuesday, 27 October 2009

Countering Espionage - A modern threat

Corporate Espionage was once thought of as a risk that only affects the richest of companies in high-risk sectors or emerging markets, the latest trends suggest that this is far from the truth.

The history of espionage, thought by some as the second oldest profession in the world, can be traced back to biblical times with more than 100 references in the Old Testament. Sun Tzu's book "The Art of War", written around 500BC deals specifically with intelligence networks and intelligence gathering. Unfortunately as is often the case, history has not taught us the most basic of lessons; that intelligence is power, whether in business or war, he who has intelligence has the upper hand.

Many are naive enough to think that espionage comes straight out of the pages of Ian Fleming's James Bond, confined to Governments and the largest of corporations. They are very much mistaken.

No one wants to be a victim, least of all admit to being a victim, yet the rewards for those carrying out espionage far outweighs the risks or expense involved. Sad as it may seem, a simple device bought for as little as two hundred pounds can cost a company millions through lost corporate intelligence. At the lower end of the scale there is the office refuse, if this is not disposed of in the correct manner it can be yet another source of leaked information within companies or organisations.

Directors, management and IT personnel of many companies fail to understand the fundamental basics of countering espionage and the techniques employed by those carrying out such activities.

Millions of pounds are spent each year on eavesdropping transmitters, computer keystroke loggers and telephone recording systems. Everyone wants to know what everyone else is doing in business, and for some it makes sense to have a budget for "intelligence" prior to entering into litigation suits, hostile takeovers or mergers and acquisitions.

Litigation, for example, is an area of complex issues, cross border or otherwise, where technical surveillance has in the past, been used to affect the outcome of a given case. When a case is worth £500 million, spending £50,000 on winning makes sense to many companies, and far outweighs the risks of becoming the loser.

The level of the risks involved in Corporate Espionage is all relative to the financial rewards. The level of the technology employed is relative to the investment.

It is more and more evident that few security companies fully understand the technology involved, how communications operate or are intercepted/manipulated, leaking vital corporate intelligence to competitors.

Some Technical Surveillance Counter Measures TSCM firms are so far behind that the advice that they pass on to their clients is often futile. With budgets in the tens of thousands of pounds, a telephone can be intercepted miles away from the target location and monitored from the other side of the world, live. Each call is time and date stamped, in turn recorded on a computer for later evaluation.

The fact of the matter is, in some cases a TSCM sweep is of no use when technical surveillance can be so remote. Better understanding is needed, both of the modus operandi and of the latest technology. Few TSCM firms understand just how far an espionage budget of £20k can go.

TSCM sweeps as part of a security housekeeping policy do make sense if carried out to include computer systems, rooms and telephone lines to local exchange level. It is true to say that the basic technical principles of espionage technique have not changed too much over the past twenty years since the end of the cold war. However the movement in technology and with the vast use of communications spanning the world has lead the public into a false sense of security and apathy when employing these communication techniques.

Any type of electronic communication can be intercepted at one level or another; the role of the TSCM firms should be best utilised identifying the areas of weakness and employing measures to combat these possible areas of weakness.

Office Security

Many large companies fall foul of size and general lack of in-house security policies, making espionage far easier and easier still with inside information.

The placement of bugging devices in offices or boardrooms is not always the first option for espionage; often the logistical problems involved in a live covert device far outweigh the benefits. However, should access have been gained via inside information or chance, many of those carrying out espionage prefer to install hardwired GSM based devices, solving power and distance issues. Cat5 cabling for example is a good carrier for installing covert microphones. A GSM device being located elsewhere in the complex acts as a "voice activated transmitter" and is almost impossible to locate during a TSCM sweep of the given boardrooms or offices.

Having a good internal security policy will aid a company and deter potential offenders. Staff should challenge visitors not displaying a visitors badge; visitors should be met at reception and not left unattended. Workmen also should not be left unattended and all companies should employ a clean desk policy where possible.

Landlines

A device placed on the telephone line can be as far as five miles away prior to the line entering the local exchange. A simple device that tests line voltage or impendence will not detect hi-tech devices unavailable to the general public. These varieties of device are normally of GSM type and utilise the power from other sources within the local exchange/cabinet. They are nigh on impossible to detect without a physical check of the line up to the local cabinet (green roadside cabinet) level.

Securing an external landline to the property need not be an expensive encryption system; replacing an analogue system with digital ISDN/ADSL system will ensure that the line is far more secure. Fibre-optic cables cannot be tapped into with ease unlike a twisted copper pair; a "pod-splitter" and true line identification are required.

Cellular telephones

The fact is, that while it costs in excess of £250k for the necessary equipment for intercepting a cell phone, jamming the phone's signal costs less than a tenth of that price and is far easier on an operational basis. A target uses a cellular telephone because she/he thinks that it is the most secure way of communicating. A cellular jammer can be deployed to jam the cellular telephone, forcing the target to use the landline that is intercepted. Keeping it simple counts, low risk and high gains.

Computer Systems/Email

Trojan Viruses sent to targets via email can contain complex keystroke logging programmes or open back doors to computer systems. At the lower end of the scale, there are many of such programmes freely available on the Internet, at a low cost or for no cost at all. At the higher end of the scale there can be hackers targeting a business/director in order to gain given intelligence on sensitive financial matters. The cost of the latter option, whilst in the thousands of pounds mark is, as I have previously covered, worth the risk in the larger cases.

New, off-the-shelf, computers are not as secure as users might think; the default settings are insecure and need to be configured prior to connection to the outside world. The most basic of steps should always be taken, updating anti-virus software on a weekly basis, backing up networks and installing a hardware firewall are just some of the easiest options to employ as a counter measure.

The best answer to computer security is file and email encryption, this though, only providing that the computer system is firewall protected.

Bluetooth™ and Wireless connections

Wireless computer connections are high risk and can, if not set up correctly be intercepted at ease by external attack. This risk has been highly reported over the past two years, but many manufacturers have still failed to change the default settings of their devices, thus enabling other "attacking" systems to connect and download vital information such as address books and other files; all without the user's knowledge.

Overall what must be taken on board is that no one wants to work in a locked down environment, but in a secure one. All security recommendations need to be both affordable and workable, the simpler the better, realistic and in keeping with the level of possible threat.

Sunday, 25 October 2009

Spies in the boardroom

Not a week goes by without our offices receiving one or more telephone calls from around the world asking if something is technically possible.

Almost anything is technically possible in espionage when you are dealing with multi-billion pound litigation cases, mergers and accusations or intellectual property rights. A budget of £100k will buy a package of email interception and telephone tapping for a month; while this amount sounds quite high, when involved in a hostile takeover or litigation worth hundreds of Millions of pounds it makes good financial sense to some when they are involved in takeover or litigation worth hundreds of millions of pounds.

Many working within the public security sector or defence industry understand little about espionage or the little that they do know is well out of date. Espionage is a very fast moving sector. Each innovation in communications leads to another way of interception, every time microprocessors get smaller and faster covert eavesdropping devices get smaller and smarter.

Almost every day, we at International Intelligence Limited asked how people can communicate safely and our answer always remains the same – “you are far safer talking over your fence to your neighbour than you are making a telephone call, sending an email or fax. All forms of electronic communication can be intercepted at some level or another”.

This may sound a little over the top or scare mongering, but the fact is that a low cost covert transmitter placed within a company’s boardroom can cost the target company millions in lost deals, legal cases or intellectual property theft.

Understanding the basic principles of espionage and human nature is a good start for secure working practices and a basis of an organisations housekeeping policy.

Corporate responsibility
Many organisations and companies fall at the very first hurdle and lack basic internal and external security. For example, can you be certain how many members of your staff would challenge a stranger walking around the office with a clip board under arm or wearing a hard hat and workman’s vest?

It is a good start therefore to have a basic policy of staff identity cards worn at all time is a good start, it is the duty of all staff to make this policy work. What’s the use of having a security policy that is costly, difficult to implement and impractical?

One firm that we recently visited had a sound security policy, CCTV and static security guards checking everyone at reception. Great, you may think, yet we gained access to the offices and boardroom via the fire escape that was propped open by a chair that gave workers access to a place to have a quick smoke.

At the end of the day a security policy is only as good as the staff within the building – it is everyone’s responsibility, from Cleaner and Typist to the CEO.

Espionage is on the increase in the UK and is on the increase, over the past five years, there have been a number of public cases that have involved accusations of bugging, email interception, telephone tapping or waste theft.

Espionage and the Law
In the UK there are no specific laws that cover espionage and therefore any prosecutions have to be carried out under other laws. For example if you were caught tapping a telephone line you could be arrested under a number of acts, you could be arrested under Article 8 of the Convention on Human Rights, Interception of Communication Act 1995/ Regulation of Investigatory Powers Act 2000 or the Protection from Harassment Act 1997. You might be prosecuted for theft of electricity from the telephone provider and trespass.

Company’s which employ investigators in support of litigation cases may run into problems over how intelligence gained is going to be used in court. As all evidence has to be disclosed to the opposition in the case, any which has been obtained unlawfully may be discounted by a judge and action taken against the party submitting it. This happened in the Dubai Aluminium case, when an investigator was employed to obtain bank details in breach of the Data Protection Act 1984 which was then in force.

A recent case where telephone tapping/interception took place was St Merryn Meats Ltd and others vs. Hawkins and Others ([2001 ALL ER (D) 355) where evidence was gained by bugging a person’s home telephone. The court held that this was unlawful, as it constituted an offence under the Interception of Communications Act 1995 which has been replaced by the Investigatory Powers Act 2000.

It is, therefore, probably more sensible and less stressful to avoid the need for litigation in the first place and there are ten basic steps that any organisation can take to secure its operations. These are easy to follow and, far more importantly, easy to implement.

Steps to counter espionage
The first step to counter espionage is to identify the strengths and weaknesses within your organisation or company in order to help develop a sound security policy, based on findings.
  • All departments’ should have cross shredding type shredders because the waste from strip shredders can be placed back together with a little work.
  • All documents should be locked away in secure cabinets prior to the end of each day.
  • Programmes for encryption of email and files to government standards can be downloaded free from the Internet.
  • Documentation concerning sensitive issues, mergers or takeovers should never leave the workplace unless signed out and secured.
  • A CCTV system giving internal and external coverage will put off any illegal activities and deter the opportunist.
Never open email attachments from unknown sources as these may contain Trojan viruses that can be used to attach your computer from within. Always update your anti virus software and make sure all staff are aware of this risk as viruses can spread on networked systems at speed.
  1. Changing from analogue to digital or normal copper pair to fibre-optic telecommunications will foil attempts to intercept telephone or fax lines.
  2. The wearing of Staff and Visitor ID will enable all workers to identify persons that do not belong in a given sector or are unaccompanied.
  3. A Technical Surveillance Counter Measures (TSCM) Sweep of offices should always form part of a good housekeeping policy as it is designed to find any devices placed within communications systems or offices.
During the course of a year, we hear the same excuses from people who are convinced that their companies’ security policies are adequate and that they need to take no action to update their systems. These include the old myths such as their company not being a target, phone tapping being too expensive to worry about and the belief that they are safe because they work from home.

They ignore the fact that no organisation is too large or too small to be targeted. The very nature of business competitiveness means that people will want to know your secrets, what your new product is, who your clients are and what you charge them.

They ignore the fact that directors who work from home are softer targets for telephone and email interception.

What they should be doing is working out what their last contract was worth and what it would mean to them if they lost it to Joe Bloggs up the road.