What’s the problem with conflicts of interest?

What are conflicts of interest?

At their core, conflicts of interest are about integrity. ‘Conflict of interest‘ arise in situations where employees or third party legal entities such as vendors or business partners (including employees of those third parties) could be influenced, or where it could be perceived that they are influenced, by a ‘personal’ interest in carrying out their duty (Commonwealth Ombudsman 2017).

In this sense, ‘personal’ interest refers to perceived or actual benefits being derived, ranging from money to relationships or reputation. There are three forms of conflicts of interest (Commonwealth Ombudsman 2017):

  • Actual conflict – where a direct conflict arises between an individual or entity’s personal interest and their fiduciary duties
  • Perceived conflict – situations where others might perceive a conflict (even if an actual conflict does not exist)
  • Potential conflict – situations which in the future could give rise to an actual or perceived conflict of interest but have not yet happened

Are conflicts of interest fraud?

Conflicts of interest are considered one of four ‘corruption schemes‘ by the Association of Certified Fraud Examiners (ACFE), the other three being bribery, illegal gratuities, and economic extortion. However, unlike some types of fraud, an actual conflict of interest only becomes fraudulent if it is not declared.

Photo by Brett Jordan on Pexels.com

Declaring a conflict of interest (whether actual, perceived or potential) provides an opportunity for it to be managed, which could include the conflicted party recusing themselves from the conflicting situation or decision, or declaring this conflict to peers (such as where a board member is conflicted through multiple interests).


Does this article resonate with you? Please vote below or subscribe to get updates on my future articles


How do conflicts of interest arise?

Conflicts of interest arise can either intentionally or unintentionally (Commonwealth Ombudsman 2017) :

  • Intentional conflicts occur where an individual or legal entity knowingly puts itself in a conflicting situation. This could arise where a potential conflict is entered into with the full knowledge of all affected parties (and appropriately managed), or where the party gaining a personal benefit attempts to conceal the conflict (fraud)
  • Unintentional conflicts arise from poor management or awareness by affected parties, such as where employees do not recieve conflicts of interest awareness training, employers do not have conflicts of interest policies or require attestations.
Photo by Jopwell on Pexels.com

Declarations – a key part of conflicts management

Conflicts of interest are all about transparency, or the lack thereof. Declarations are a key component of managing conflicts. Irrespective of whether an employee, contractor, supplier or potential business associate, businesses need to understand what (if any) potential conflicts they may have and work through a process to evaluate them.

Typically, the easiest way of managing conflicts of interest is avoiding them, but this is not always possible. Where a conflict does or may arise, it must be evaluated – sometimes this process can be quite onerous.

The U.S. National Academies of Sciences (NAS) notes that “conflicts are not binary (present or absent)”, and that they “can be more or less severe”. The NAS identifies two factors to assist decision makers when evaluating a conflict of interest declaration, being (a) the likelihood of undue influence by the secondary interest, and (b) the seriousness of the outcome. The NAS presents this useful rubric for assessing confict of interests:

Likelihood of undue interestSeverity of potential harm
What is the value of the secondary interest?What is the value of the primary interest?
What is the scope of the relationship?What is the scope of the consequences?
What is the extent of discretion?What is the extent of accountability?
NAS (2009) – Chapter 2 Principles for Identifying and Assessing Conflicts of Interest

Depending on severity or perceived harm, treating a conflict of interest may require removing the conflicted individual / entity from the decision making process, or in other cases severing the business relationship entirely. Exactly how you need to manage a conflict depends on the situation (noting that in some cases there may be applicable legislation which will also govern this).

Good practice requires organisations to collect information on conflicted individuals or entities regularly – there is no set timeframe for this, but an annual declaration coupled with voluntary event-based disclosures by the affected party if they arise, makes sense for most organisations. Any more frequent and the program can be difficult to manage, whilst a longer gap between declarations can give employees the impression that conflicts aren’t important, as well as meaning the organisation is working on out of date information.

Once conflicts are identified and confirmed, managers of those employees or affected contracts (e.g. vendor managers) must be made aware of the conflict and charged with managing the risk in accordance with the organisation’s agreed treatment plan.

The challenge of detecting undeclared conflicts

Managing declared conflicts can be challenging enough for large organisations, however detecting them is something different altogether. Without a properly structured approach it is possible to spend a lot of time, effort and money without identifying anything conclusive.

Photo by cottonbro on Pexels.com

In the absence of an allegation, such as a tip-off from a whistleblower or competing vendor, organisations seeking to be proactive in detecting potential undeclared conflicts should focus their resources on the business units, processes, people or vendors of highest risk. The ACFE identifies three main types of conflict of interest scheme (Wells, 2007):

  • Purchasing Schemes – where a conflicted party manipulates the victim’s purchasing process to the benefit of the entity to which they are conflicted
  • Sales Schemes – where the conflicted party negotiates discounts or processes write-offs to benefit the entity to which they are conflicted
  • Other schemes – where the conflicted party diverts funds, clients / sales leads, and / or resources such as equipment from their employer to the entity to which they are conflicted for the conflicted entity’s benefit

Each of these categories of scheme is comprised of a number of typologies (perhaps best thought of as variations), some of which are more easily detected than others.

As you can see, conflicts of interest schemes can arise amongst employees in sourcing and procurement or sales and marketing roles; however, this is not exclusively the case. Conflicts of interest are generally quite complex to both detect and investigate. Typical methods of detecting conflicts include fraud data analytics (fraud detection) and investigative techniques including (Wells, 2007):

  • Supplier vetting or due diligence (and comparison of ownership data with employee and contractor names and other indicators, such as phone numbers)
  • Matching of supplier / vendor and employee identifiers (eg.g. Address, phone number data)
  • Identification of employees who are take up employment with a vendor after termination
  • Tipoffs and complaints, including from other disaffected vendors who are losing work as a result of the corruption scheme as well as employees who notice inconsistencies or favouritism

A well designed integrity program, inclusive of appropriate internal controls in key areas (such as purchasing), awareness programs and annual attestations can help mitigate the risk of these insider threats. Perhaps most importantly though, these same practices must extend to third parties, whether a vendor, business partner or other classification. A third party’s employees or contractors in positions which place the contracting entity at risk must be managed and monitored closely, sometimes with even more scrutiny than may be applied to the contracting entities staff – this decision is dependent on where the risk lies, and the inherent and residual rating of that risk.

Further reading

DISCLAIMER: All information presented on ForewarnedBlog is intended for general information purposes only. The content of ForewarnedBlog should not be considered legal or any other form of advice or opinion on any specific facts or circumstances. Readers should consult their own advisers experts or lawyers on any specific questions they may have. Any reliance placed upon ForewarnedBlog is strictly at the reader’s own risk. The views expressed by the authors are entirely their own and do not represent the views of, nor are they endorsed by, their respective employers. Refer here for full disclaimer.

Business espionage – the sale of intellectual property on the dark web

What is the dark web?

For those who are new to this, concept, the dark web is the third part of the internet which is not indexed by ordinary search engines and requires a specific web browser (a ‘TOR’ browser) to access. The other two parts of the internet are the surface web (what we all think of when we hear the term ‘internet’), and the deep web, which comprises often proprietary databases and data holdings which sit behind a firewall and generally require a subscription or password to access. A database of media articles is one example.

Photo by Pixabay on Pexels.com

There are a number of illicit markets on the dark web selling everything and anything which is illegal in an anonymised way. These illicit markets also include illicit payment mechanisms for financial transactions which bypass the global financial system. Whilst it makes sense that IP would be sold here, until now this is not something I had heard much about aside from the sale of counterfeit products – shoes, medicine, passports etc. My working hypothesis is that much of the stolen IP on the dark web which is not counterfeit product is likely derived from ‘business espionage’.


Does this article resonate with you? Please vote below or subscribe to get updates on my future articles


What is business espionage?

We all know that information is power, but these days it is also a global currency. According to Forbes Magazine, innovation and intangible assets today comprised around 80% of a business’ value in 2014 (Juetten). In recognition of their value, the International Accounting Standards Board (IASB) adopted IAS 38 Intangible Assets in 2001 to prescribe the accounting treatment for intangible assets.

For simplicity here, I refer to all types of valuable business information, intangible assets or intellectual assets as ‘IP’. Business espionage is a term that I have borrowed from Bruce Wimmer (2015) to refer to the theft of commercial information from businesses including ‘industrial espionage’ (companies spying on their competitors) as well as ‘economic espionage’ (theft of IP by nation states for national security purposes).

Photo by cottonbro on Pexels.com

The types of IP that is stolen includes:

Research dataPricing data
Confidential informationCustomer lists
Trade SecretsProduct development data
Engineering schematicsSales figures
Proprietary software codeStrategies and Marketing plans
Chemical formulasCost analyses
‘Know how’Personnel data
Examples of IP targeted by business spies – Nasheri (2005)

If I think about it simplistically, my hypothesis is there are two main ways someone could obtain this IP for sale: licit and illicit. The licit route would arise where a party has access to the IP and is authorised to copy or use that IP for a permitted purpose (such as under license or terms of confidentiality), but then chooses to use that information for a non-permitted purpose. Examples here could include:

  • Where IP is provided to an outsourced service provider or business partner, such as a Contract Research Organisation, Contract Manufacturing Organisation, or IT managed services provider. When a contractual arrangement ceases the IP may not be properly destroyed, and could be used for unauthorised purposes later (such as to win a new contract with a previous customer’s competitor).

In contrast, the illicit route refers to cases where IP is stolen and then onsold. There are a number of potential vectors here including:

  • Theft and / or exfiltration by trusted insiders (such as employees, contractors or suppliers)
  • Targeting of business travellers in hotels, bars, etc
  • Cyber criminals and hackers breach secured networks
  • Opportunistic individuals who find valuable information on an unsecured corporate network
  • Plus other similar examples

So, to recap, we have the scenario where commercially valuable information (IP) has been stolen – sometimes employees steal IP from an employer as they see it as ‘theirs’ and feel they are the legitimate creater or owner of this information, despite typically having assigned their moral rights to their employer via their employment contract. In this scenario, my experience is that employees rarely sell this information to a third party – but they will often use this information for personal advantage in future roles or positions. However, this is not the focus of this post. In this post, we are referring to the theft and sale of commercially valuable information on a large scale.

Photo by Kindel Media on Pexels.com

Is there a criminal value chain behind the illicit market for stolen IP?

It makes sense that someone who has access to sensitive IP which is valuable in the market and who has ulterior motives would want to sell it, but how does this work? Do they sell it exclusively to the highest bidder at auction? Do they sell it multiple times to multiple parties? If you are the highest bidder at auction, how do you guarantee you are the only buyer? Also, how do you guarantee the authenticity or quality of the information?

“It does little good to steal intellectual property if you do not have the expertise to use it”

James Lewis, SVP and director of the Center for Strategic and International Studies’ (CSIS) Technology Policy Program in Gates (2020)

I have so many unanswered questions here, but the presenter I referred to earlier mentioned the prices some buyers pay for stolen IP on these illicit marketplaces is in the millions of US dollars, and that about 90% of the IP on these illicit markets is authentic. These illicit market dynamics mean this is clearly something worth examining further. As a security consultant, part of my job involves ‘thinking like a criminal’ to identify how such a scheme would work – I have developed my hypothesis below based on my experience and knowledge of how other illicit markets work:

© Paul Curwell, 2022

In my hypothesis shown above, I have assumed there is a degree of criminal specialisation in the stolen IP market, as there is in other aspects of cyber crime and cyber fraud. Just with legitimate online marketplaces, if I were a buyer I wouldn’t trust sellers I don’t know or who other people I trust haven’t verified, and I’m not going to pay anything more than a trivial amount or take the risk to buy IP which hasn’t been verified either as authentic (i.e. stolen from the company alleged to have produced it) or not fictional (i.e. garbage content). For a good overview of how online review systems work, look at this Harvard Business Review article from Donaker et al (2019).

In my mind, there must be information brokers who play a ‘trusted intermediary’ role and offer an independent validation and verification services – for a fee. However, this would also require access to pool of experts who would be paid to perform this work (e.g. scientists, doctors or engineers who are specialists in their field and open to a side hustle). Presumably some are complicit and know what they are doing, but are some also told this is legitimate and have no cause to question further? And what about the companies that are happy to take the risk both that the info might be fake and that they might get caught? As it stands I have more questions than answers, but the one thing I know is this is something I will be looking into further.

Further reading

DISCLAIMER: All information presented on ForewarnedBlog is intended for general information purposes only. The content of ForewarnedBlog should not be considered legal or any other form of advice or opinion on any specific facts or circumstances. Readers should consult their own advisers experts or lawyers on any specific questions they may have. Any reliance placed upon ForewarnedBlog is strictly at the reader’s own risk. The views expressed by the authors are entirely their own and do not represent the views of, nor are they endorsed by, their respective employers. Refer here for full disclaimer.

What is an ‘IP Audit’ anyway?

Intangible Assets – easily overlooked

I still remember performing my first ever Intellectual Property (IP) audit on my consulting journey. I had just graduated from business school which had opened my eyes to the world of commercialisation and IP assets, and how they could be exploited or misplaced. My client was a large player in global airport infrastructure services, and as part of their work the Executive Officer to the CEO thought it was important to identify and map their IP asset holdings. As I worked my way through the organisation, interviewing staff and cataloguing their IP, I still remember stumbling across the engineering laboratory hidden in one corner of a floor, out of sight.

As I spoke to the team members there, I discovered not only did they maintain specialised electronic components for equipment used in delivery of their services, but in their spare time and with discretionary budget the team of engineers worked to invent their own solutions to airport infrastructure problems. This activity flew completely under the radar of the organisation’s executive, meaning not only did their work potentially miss out on dedicated funding which might generate a revenue stream or licensing opportunity for the organisation, but the IP was not properly protected – including from theft should those employees decide to resign and move to a competitor or start their own business.

This type of situation is encountered time and time again in Australian businesses. Our level of awareness and maturity in relation to IP is relatively low in most sectors, and my experience has been that in sectors which are aware of the fundamental concepts, IP assets are either managed very selectively or in many cases not at all. As an advanced economy with a strong STEM-based population and research capability, we need to get better at protecting our IP if we are to compete and thrive as a nation in a knowledge-driven world. Completing an IP Audit is one of the first steps to doing this.


Does this article resonate with you? Please vote below or subscribe to get updates on my future articles


What are intellectual assets?

Intellectual Assets are intangibles that have value to an enterprise including but not limited to “information, intellectual property, credibility and reputation, and brand identity”. Whilst the term ‘intellectual property’ is often used to commonly refer to sensitive information, six types of IP are recognised by the World Intellectual Property Organisation (WIPO):

  • Patents
  • Trade Marks
  • Copyright
  • Industrial designs
  • Geographical Indicators (e.g. ‘champagne’)
  • Trade Secrets

In Australia, we have another category of IP called ‘Plant Breeders Rights‘, and Geographical Indicators are registered under our ‘Certification Trade Mark system‘. Unlike other jurisdictions such as the U.S., Australian law does not explicitly recognise ‘trade secrets’ as a category of IP – instead, ‘trade secrets’ are considered a category of ‘Confidential Information’ (Dighe & Lewis, 2020, Twobirds.com). More on this in a future post.

According to IP Australia, “a trade secret can be any confidential information of value. Unlike other IP rights, trade secrets are protected by keeping them a secret, and are not registered with IP offices. The protection of a trade secret will cease if the information is made public, and trade secrets do not prevent other people from independently inventing and commercialising the same product or process”.

What is an IP audit?

According to the Queensland Government, “an IP audit is a review of the IP owned, used or acquired by an organisation. It aims to find out what IP is within an organisation, who owns it, the value of that IP, its legal status, and what to do with it“. Once identified, in addition to focusing on the legal status of your IP, you also need to understand whether it is adequately protected. For example:

  • Which threat actors might seek to steal or sabotage your intellectual assets? Employees, competitors, nation states (‘economic espionage’) or someone else?
  • What are the actual risks posed by these threat actors? Examples include theft, sabotage and IP infringement.
  • What internal controls do you have in place in terms of your holistic security programs to address the identified threats and risks? These may need to address insider threats, supply chain threats, and external threats (e.g. competitors).
Photo by Mark Stebnicki on Pexels.com

How are IP audits performed?

Once you have decided to undertake an IP audit, you need to develop your scope and methodology. This starts with developing your audit plan and audit team. I find its easier to divide the audit into two or three parts, as follows:

  • Step1 – data collection: systematically catalogue confirmed or potential IP and confidential information in a register. I use the organisation chart as a starting point for this.
    • Tip: its easy to get bogged down and start to catalogue every document. Instead, focus on categories of information (e.g. financials) and then narrow down in key areas.
  • Step 2 – initial assessment: once you’ve compiled your initial register, assess it to remove all unnecessary content by ensuring each entry meets the criteria for an asset. If not relevant, delete it. Hopefully you’re left with a relatively small number of manageable entries, the output of which is your register of ‘critical information assets’.
  • Step 3 – commercial evaluation: use your register of ‘critical information assets’ to review potential commerical opportunities (e.g. licensing), develop monitoring programs for infringement, or even sell the IP Rights to another party if no longer used or relevant to your strategy.
  • Step 4 – risk management: review your register of critical assets to ensure the information is adequately protected. This includes legal provisions (e.g. patents), employment contracts (e.g. non-disclosure and IP assignment clauses), information security programs, and supply chain or third party risk programs. Make sure your critical information assets are appropriately marked, secured (e.g. encrypted), access is controlled, and unauthorised dissemination is limited.
Photo by picjumbo.com on Pexels.com

Using the findings of your IP audit to better protect these assets

All to often, businesses take a purely legalistic approach to protecting their IP and Confidential Information assets. It is important to remember that just because your research is patented or because you have a non-disclosure agreement in place with your suppliers or employees it is not completely protected. Particularly in the case of confidential information, courts expect businesses to have implemented appropriate security programs to safeguard their information – it is not sufficient to rely purely on legal protections in the courts if something happens. Further, this sort of reactive response is not productive, is very expensive, and consumes substantial amounts of time from your board, executives and senior staff – time that could be more productively spent elsewhere.

Prevention and early detection is the key, but to do this you need to understand what your IP assets are (such as via the IP audit process), work out where their associated vulnerabilities or exposures lie (are they limited to your employees or do you divulge this information to your third parties too? if so, who has access…). Then you can wrap a combination of cybersecurity (e.g. networks, systems, encryption) and what I refer to as ‘non-cyber information security’ programs around this to build your protective bubble. These relationships are illustrated below:

As you can see, there is more to protecting your IP and Confidential Information than patents, copyright and design rights. If you’re unfamiliar with how to build a program to protect your confidential information, take a look at my previous post here.

Further reading

DISCLAIMER: All information presented on ForewarnedBlog is intended for general information purposes only. The content of ForewarnedBlog should not be considered legal or any other form of advice or opinion on any specific facts or circumstances. Readers should consult their own advisers experts or lawyers on any specific questions they may have. Any reliance placed upon ForewarnedBlog is strictly at the reader’s own risk. The views expressed by the authors are entirely their own and do not represent the views of, nor are they endorsed by, their respective employers. Refer here for full disclaimer.

Understanding the risk of organised crime infiltration in your business

What is Serious Organised Crime anyway?

The concept of organised criminal infiltration into your business or supply chain is interesting. I’ve worked with a number of critical infrastructure operators in Australia who have this concern: the nature of their business provides a unique opportunity for criminals to exploit their business, or the employees position, to facilitate their own or others criminal activity. Before we start to get carried away that serious groups like the mafia are infiltrating your business, it’s worth understanding key elements of the ‘spectrum of crime’ which forms a basis for any Threat Assessment:

  • Criminal enterprise – a group of individuals with an identified hierarchy, or comparable structure, engaged in significant criminal activity (FBI)
  • Opportunistic individuals – individuals who take advantage of internal control gaps or weaknesses and opportuinities of circumstance to perpetrate criminal and / or unethical activity (e.g. fraud or business espionage) (Curwell, 2022)
  • Organised criminals – “small, organised networks of entrepreneurial offenders, often transitory in nature, that develop to exploit particular opportunities for illegal profit. These groups vary from temporary associations created to commit a time-limited series of offenses, to enduring businesses that invest in on-going criminal activities” (Eck & Clark, 2013, p28).
  • Organised crime (organised criminal group) – “a structured group of three or more persons, existing for a period of time and acting in concert with the aim of committing one or more serious crimes or offences established in accordance with this Convention, in order to obtain, directly or indirectly, a financial or other material benefit” (Smith 2018 in United Nations 2004: 5).
  • Transnational Organised Crime – those self-perpetuating associations of individuals who operate transnationally for the purpose of obtaining power, influence, and monetary and/or commercial gains, wholly or in part by illegal means, while protecting their activities through a pattern of corruption and/or violence, or while protecting their illegal activities through a transnational organisational structure and the exploitation of transnational commerce or communication mechanisms (FBI)
Photo by Anugrah Lohiya on Pexels.com

Its important to remember that not all crime that happens somewhere like a border, port or airport will be perpetrated by serious organised crime. Anecdotally, a lot of the crime I come across day to day involves opportunistic individuals and organised criminals. These risks are managed through employment screening and internal controls (which might include detection programs – see What can be done about it? below).

Photo by Anete Lusina on Pexels.com

Common activities of serious organised crime – is there a nexus with your business?

Understanding the types of activities which commonly involve serious organised crime groups can help businesses assess their likely exposure to this activity. In the following list, I have compiled a list of offences based on information published by the FBI and ACIC:

  • Bribery
  • Currency Counterfeiting
  • Embezzlement
  • Fraud schemes
  • Cybercrime
  • Investment and financial market fraud
  • Revenue and tax fraud
  • Credit card fraud
  • Superannuation fraud
  • Money Laundering
  • Murder for Hire
  • Drug Trafficking
  • Prostitution
  • Exploitation of Children
  • Organised retail crime
  • Human Trafficking and Slavery
  • Intellectual Property Crime – including Counterfeit Goods
  • Illegal Sports Betting
  • Cargo Theft
  • Sale and distribution of stolen property
  • Murder
  • Kidnapping
  • Gambling
  • Arson
  • Robbery
  • Extortion
  • Tobacco and firearms smuggling
  • Vehicle theft

Does this article resonate with you? Please vote below or subscribe to get updates on my future articles


What we know about Serious Organised Crime in Australia today

Access to detailed assessments of the nature and sophistication of serious organised crime in Australia are not publicly available. However, one of the most useful reports is the periodic assessment of Serious Organised Crime released approximately every 5 years by the Australian Criminal Intelligence Commission. This report provides a useful outline of serious organised criminal markets in Australia, as follows:

Illicit CommoditiesSerious Financial CrimeSpecific Crime MarketsCrimes Against the Person
NarcoticsCybercrimeVisa & Migration FraudExploitation of Children
Illicit Pharmaceuticals & AnaestheticsInvestment & Financial Market FraudEnvironmental CrimeHuman Trafficking & Slavery
Performance Enhancing Drugs (e.g. steroids)Revenue & Taxation FraudIntellectual Property Crime
llicit TobaccoSuperannuation Fraud
Illicit FirearmsCredit Card Fraud
ACIC (2017). Serious Organised Crime in Australia, Canberra

Understanding whether your business, including your supply chain, has a nexus with any of these criminal markets will help inform your threat and risk assessment process in relation to organised criminal infiltration. As with assessing physical security of your office premises or facilities, you may not have a direct nexus with organised crime but your suppliers or neighbouring businesses might. This creation of an indirect nexus should also be considered, as this could have adverse reputation, safety and disruptive effects on your business, employees or customers.

The role of criminal enablers

Some organisations may not be directly of interest to OCG, but they may be recognised as having something or someone who can enable or facilitate their objectives. Examples here include access to information, professional facilitators (eg. lawyers, accountants, trust & company service providers), systems (eg being able to change a database record in a third party system), or sub-leasing warehouse or storage space.

The Australia Criminal Intelligence Commission identifies six enablers of serious and organised crime (ACIC, 2017):

  • Money laundering
  • Technology
  • Professional facilitators
  • Identity crime
  • Public Sector corruption
  • Violence and intimidation

Enablers can be targeted by organised crime either directly (eg group leases warehouse space for its own activities) or in relation to employees in key positions. Employees who have some sort of vulnerability, either at home or at work, may be coerced, bribed, intimidated or extorted to perform acts at the direction of a group.

Photo by ThisIsEngineering on Pexels.com

What can be done about the risk of organised criminal infiltration?

So far in this post, we’ve demystified what constitutes serious organised crime, the types of activities (offences) commonly associated with this activity, the criminal markets where organised crime groups are found, and the professional intermediaries and enablers who might knowingly (or unknowlingly) support them. The next question is what to do about it.

The starting point for any business leader concerned about potential organised criminal infilitration in their business is a thorough, objective and factual assessment of the threats and risks, and their associated likelihood and consequence. Once understood, a proper security plan can be implemented to mitigate these risks.

With infiltration by organised crime there is a potential insider threat. This can materialise within both the employee and contractor / third party populations, including within the extended supply chain. This also needs to be considered when scoping any assessments. Suggested actions for businesses concerned about organised criminal infiltration include:

  1. Perform a Threat Assessment to map your ‘threat universe‘ (i.e. who is likely to target your organisation), and why
  2. Undertake a Security Risk Assessment, which incorporates identifying critical assets, vulnerabilities (control gaps), consequence and likelihood (i.e. which of your assets might serious organised crime groups actually consider attractive) for the various threats identified in the Threat Assessment. For risk such as product theft or product diversion, don’t forget to assess if your products are CRAVED.
  3. Undertake a Personnel Security Risk Assessment – this is commonly separate to your Security Risk Assessment, but identifies high risk positions and roles in the organisation which give acceess to your critical assets, and the types of employment screening (background investigation) and continous insider threat detection programs that may be required to mitigate the risk
  4. Perform due diligence on prospective and current employees, contractors, suppliers and business partners / third parties based on the risks idenitifed in your Security Risk Assessment and Personnel Security Risk Assessment.
  5. Develop a robust intelligence and security program to monitor for ongoing changes to your organisation’s threat landscape (including building capabilities such as media monitoring), and where appropriate, develop partnerships with police and security agencies to help mitigate the risk to within your organisation’s risk appetite.

Following these steps will ensure you know where you need to focus your security effort and resources. It may be that your greatest risk is that of opportunistic individuals and organised criminals (including trusted insiders and employees or contractors of your third parties or business partners) and not serious organised crime, requiring a different treatment strategy. If in doubt, seek assistance from an appropriately qualified professional who is licenced by the State Police to give security advice in the relevant Australian jurisdiction. If in doubt, have a read of this advice from ASIAL, the Australian Security Industry Association.

Further Reading

DISCLAIMER: All information presented on ForewarnedBlog is intended for general information purposes only. The content of ForewarnedBlog should not be considered legal or any other form of advice or opinion on any specific facts or circumstances. Readers should consult their own advisers experts or lawyers on any specific questions they may have. Any reliance placed upon ForewarnedBlog is strictly at the reader’s own risk. The views expressed by the authors are entirely their own and do not represent the views of, nor are they endorsed by, their respective employers. Refer here for full disclaimer.

HUMINT cycle and the recruitment of insiders

Author: Paul Curwell

Introduction

Employees are an organisation’s most important asset: they are what enables organisations to generate value, respond to opportunities and threats in the operating environment, and create a positive culture which attracts other would-be employees and potential customers. Employees are also crucial to security: when conditions are right, employees help build a positive security culture which enables management to quickly identify and respond to security threats.

In the same manner that security would not be necessary if people did not exist, a security program cannot be successful without the support and active participation of its employees. It goes without saying then that an employee who ‘goes rogue’ and becomes malicious (i.e. intends to do harm), or an employee who doesn’t care about their employer or its security practices (i.e. a complacent employee) can do real harm if approached by an external individual or group wishing to gain ‘inside access’ to the organisation and its assets.

What is the HUMINT cycle and who uses it?

Human Intelligence, or HUMINT, techniques are an example of the tactics typically deployed in this scenario to exploit human vulnerabilities. HUMINT refers to the collection of intelligence by humans – principally spies and agents using methods that involve 1:1 contact.

The HUMINT cycle involves four main steps (illustrated below) which might commence with a broad scan of all employees at an organisation, for example, but rapidly narrow down to one or more individuals with both (1) the access to the desired assets or information and (2) the personal characteristics or ideological sympathies which make them amenable to recruitment (See Sano, 2015)

Importantly, undertaking HUMINT and the use of HUMINT techniques is not limited to governments, but also commonly employed in business by ‘competitive intelligence’ practitioners or ‘Private Intelligence Collectors’. ‘Private Intelligence Collectors’ and unscrupulous competitive intelligence professionals often use HUMINT techniques, as well as any other intelligence collection mediums in their toolbox, to collect confidential information that will either be sold to another party (such as the highest bidder) on commission, or which is collected under the paid instruction of the intended recipient.

For a classical HUMINT example, consider a woman who seduces a male chemist at a pharmaceutical company to provide, or facilitate access to, details of a new blockbuster drug compound under development by the pharmaceutical company (referred to in the trade as a ‘honey trap‘). Other threat actors who use HUMINT techniques include organised crime groups, issue motivated groups and terrorists.

How can the HUMINT cycle be leveraged for insider threats?

Once the HUMINT collector has identified (spotted) their target, they begin engaging with them to build a rapport and develop a relationship. Importantly with HUMINT, it may not be necessary to actually recruit the target (or someone who has access to the ultimate target) in order to achieve their objectve. In some instances, the required information can be obtained without the need for a formal and risky recruitment pitch.

It is particularly important to incorporate these learnings into any insider threat awareness training, as employees who are aware of steps taken by HUMINT collectors are more likely to be aware to them, and to be able to seek help early. Examples of ways (vectors) HUMINT collectors might obtain the information they require can include:

  • Infiltration – getting an ‘agent’ or sympathiser of the HUMINT collector (or their cause) into the organisation through standard recruitment processes, as a contractor, or via a supplier
  • Elicitation – refers to techniques used by HUMINT collectors to obtain information from a target without them knowing or realising it, which results in them volunteering the information rather than being asked directly
  • Social engineering – involves the use of deception to manipulate someone into disclosing confidential information, either in a business or personal context
  • Spear Phishing and Phishing scams – can involve the use of legitimately-appearing emails (or even SMS messages, in the case of vishing) to introduce malware into an otherwise secure computer network, allowing later exfiltration of that information. Unlike Phishing which is more general, Spear Phishing is highly targeted and focused on an individual with access to the target, such as a senior executive

There are a variety of forums in which HUMINT collectors operate, including via ‘official’ or business-events, and through social personal interaction. These might include:

  • Conferences and trade shows
  • Professional Associations
  • Clubs and social associations
  • Universities
  • Social Media platforms
  • Emails
  • Unsolicited phone calls

When performing any insider threat or security related risk assessments, organisations need to consider what are their most critical assets, who might be interested in them, and how might they obtain them (i.e. what forums, mediums or platforms). Once this is thoroughly understood, awareness training and incident reporting mechanisms can be clearly established and targeted.

What can organisations do to manage this threat vector?

Complacency is a big driver of insider threat incidents, so it is critical that organisations develop a good security culture and that ‘at risk’ employees have a good understanding of the threats and tactics which may be used against them.

The regular use of security awareness training across the organisation as a whole, supported by targeted training for ‘at risk’ teams, is critical to ensuring these threats remain front of mind.

Staff in ‘at risk’ teams, as well as managers, should be familiar with insider threat behavioural indicators which can suggest an employee or contractor is experiencing some difficulty in their personal life, which might make them vulnerable to exploitation. Early identification of these problems, when raised properly (such as through employee wellbeing programs), might mitigate these risks.

Photo by Sora Shimazaki on Pexels.com

Good security culture is also critical for organisations, ensuring employees understand why security is important, what the threats may be to their organisation, and what they can do to help protect their organisation. For employees to play their part, they often also need to feel trusted and engaged with their employer, otherwise complacency may set in and potential threats selectively ignored.

The preceding paragraphs focus on what organisations can do to mitigate insider threats once they are already in the organisation (i.e. employed or contracted), however equally important is the use of employment screening (‘background investigations’ or ‘background checks’) to prevent individuals with vulnerabilities or unwanted character traits joining the organisation in the first place. Any discussion on background checks is an article in itself, and will be addressed through a future post, however readers who want to more detail (including a model process) can read the chapter on ‘due diligence’ in my recent book co-authored with Oliver May.

Further Reading

Sano, J. (2015). The Changing Shape of HUMINT, AFIO’s Intelligencer Journal, Vol. 21, No. 3, Fall/Winter 2015. www.afio.com

DISCLAIMER: All information presented on PaulCurwell.com is intended for general information purposes only. The content of PaulCurwell.com should not be considered legal or any other form of advice or opinion on any specific facts or circumstances. Readers should consult their own advisers experts or lawyers on any specific questions they may have. Any reliance placed upon PaulCurwell.com is strictly at the reader’s own risk. The views expressed by the authors are entirely their own and do not represent the views of, nor are they endorsed by, their respective employers. Refer here for full disclaimer.

When values collide: employee / employer values conflicts as a source of insider threat

Author: Paul CurwellIn this article, we will discuss the important topic of Employee Employer Values and how they impact workplace culture.

The role of employee / employer values in the workplace

Within any organisation, it is typical to find employees with a diverse range of views on all manner of political and social issues. The rise of social media has made it easier for us to share our views, both inside and outside of the workplace, creating potential for employees to post material or views which may conflict with their employer’s policies, contract of employment, or even their fiduciary duties as an employee. Additionally, we are in an era of increasing global consciousness around big-ticket items, such as climate change, corruption and personal freedoms (e.g. Arab Spring) and social / economic equality (e.g. Occupy Wall Street) which are serving to rally people to behind a cause.

low angle photograph of the parthenon during daytime
Photo by Pixabay on Pexels.com

Importantly, there is nothing wrong with each of us having these views and sharing them appropriately, such as in public debate. However, in my view it is inevitable that at some point, conflict will arise between the employee and their employer unless they are broadly aligned in terms of views and values. As an individual and as a people leader, I have always maintained it is essential that employees be able to identify with the values and mission of their employer, otherwise employee engagement and satisfaction will decline.

Values can also change over time, and it may be that the values alignment which existed upon commencement of employment is not there some years later. Increasingly in Australia, we are seeing cases where employees or contractors disagree with fundamental positions of their employer, and are proactively doing something about it which is in breach of their legal obligations to their employer. This activity constitutes an ‘insider threat’ which needs to be managed carefully.

So sort of issues are we referring to here?

The landscape of these causes is continually evolving as society evolves. Historically, those causes with a tendency to commit crimes (sometimes serious crimes such as murder) in the name of what they feel is important have been referred to as “issue motivated groups” (IMGs), however I note this term is no longer mentioned in recent annual reports or in the ASIO Act. In 2011, then Director General of Security, Mr. David Irvine AO, defined it as follows in response to a question posed within the Australian Parliament:

“Issue motivated groups is a term we use within ASIO to describe those groups who conduct activities that might lead to violence or to activities that are prejudicial to security”

Mr David Irvine AO, 18 October 2011. See below for full citation.

Every single human is an individual, and we all express a diversity of views which makes our global society what it is today. There is nothing wrong with each of us having our own views, but it gets complicated in terms of insider threats when (1) our views put us in direct conflict with those of our employer, or (2) we start to use violence or extreme violence (e.g. methods commonly associated with terrorist acts) to promote our causes. This form of insider threat is particularly pernicious given the potential ways an insider threat can manifest, including:

  • Workplace sabotage – either to data, systems, physical assets, or reputation, with the aim of having the organisation stop doing something or to draw public attention to it
  • Information leaks / unauthorised disclosure – including providing information on business activities, staff movements, senior staff personal details (e.g. home addresses), or security measures which would make the organisation more vulnerable to attack
  • Espionage-like activities – where the employee is effectively a mole or plant willing to act on the instruction of an external party. This includes the intentional infiltration of highly motivated threat actors into an organisation through the recruitment process or supply chain
  • Soft issues’ – such as ‘go slows’ (e.g. in-action) in the workplace which effectively means the employer is hindered in achieving its objectives by its workforce
people rallying carrying on strike signage
Photo by Martin Lopez on Pexels.com

This challenge is not limited to employers and their contractors, it is also pervasive throughout the supply chain which substantially increases their vulnerabilities, as illustrated by this quote:

Ben Pennings from Galilee Blockade said they now had almost “too much information” from insiders after their “dob in a contractor” campaign.

Robertson, J. (2019). Adani mining insider reveals she is leaking material to environmental activists, ABC News. See below for full citation.

Often, contracting organisations (employers) limit the scope of their involvement or oversight in their suppliers security to a few lines in a contract, stating the supplier should have a security or risk management program. Mature organisations will prescribe security standards for their suppliers, and even more mature organisations will audit this compliance through standard vendor auditing programs.

So what types of causes have historically attracted this type of focus?

The spectrum of causes and issues which can result in insider threats of this nature are broad and constantly evolving. Examples of some of these issues include:

  • Environmental protection and climate change
  • ‘Right to life’ movements
  • ‘Occupy Wall’ Street
  • Social equality movements
  • Animal rights and animal testing
  • Fossil fuels

To reiterate once again before a reader shoots me down, there is nothing wrong with exercising your democratic rights to freedom of speech and peaceful protest. This does become an issue, however, when violence or other criminal acts are involved, including within the workplace. Typically these sorts of issues can be plotted on a spectrum, and an employee may move from left to right (and back again) on this spectrum over time as their views and the actions of their employer evolve. My interpretation of this spectrum is illustrated below:

Created by Paul Curwell (2021), copyright.

Organisations which are involved in socially or politically contentious policies or activities will almost certainly know this, but it is common to find these considerations not incorporated into a threat or risk assessment. Even rarer is consideration of these matters within contracts with vendors and supply chain risk.

Any work performed in this area should have oversight from a diverse management committee and not be driven by a security function alone. Whilst a security team might have the best of intentions and undertake work in this area that is fair and balanced, perceptions of those not involved in the process may be different which could undermine the outcome and ultimately have a detrimental effect on employee satisfaction and performance more broadly.

What can organisations do to manage this issue?

Firstly, its important that employers have clear policies and guidance available for staff (and suppliers) on these matters, and that they are regularly communicated and fairly enforced. To maximise employee support, transparency and employee consultation for any new policies are critical. These principles are standard for any workplace policy. Policies should extend to conflicts of interest (actual and perceived) for employees, particularly those who are active outside of work in forums or associations where they are exercising their democratic rights. These employees, in particular, need clear guidance and management support to ensure they do not unintentionally stray into the orange zone of the spectrum (see above). It is also important that employers develop and clearly communicate a policy and framework for how any workplace incidents will be managed.

Secondly, employers need to have a clear understanding of the risks including:

  • Assets (information, people, systems, facilities, products, reputation) that need protecting
  • What the risks actually are and how they may manifest
  • The likelihood of them manifesting, which will change over time and therefore require regular oversight
  • The coverage of internal controls and the effectiveness of these controls (i.e. are there gaps and do these gaps create unacceptable vulnerabilities)
  • Are there any teams / unique positions that are more at-risk than others? For example, someone with strong views but who is not in a position to do harm in the workplace may need to be managed differently to someone with strong views who is in a position to do harm
two women in front of dry erase board
Photo by Christina Morillo on Pexels.com

Third, insider threat management starts before the employment contract is signed and continues after an employee or contractor has left the organisation until the potential for harm can be satisfactorily reduced. This means:

  • You need to consider this risk when designing your Employment Screening / Employee Due Diligence program.
  • Employee Screening should be undertaken before a contract of employment is issued, periodically during employment (e.g. annually), in response to a workplace incident or other trigger (i.e. by exception), and upon termination of employment (to understand what, if any, risks the recently departed employee may post).
  • Don’t forget suppliers, vendors and contractors pose similar risks (potentially more if they have access to critical assets / processes and no oversight). This requires consideration starting with vendor selection through to contracting, operations, and termination of a supplier contract.
  • Insider Threat Detection programs need to be designed to focus on critical assets and the organisation’s highest risks. Not all parts of an organisation may require the same control coverage or risk mitigation.
  • Independence may be critical to ensuring employee support on key initiatives such as ongoing due diligence. You may need to use an independent, objective third party to perform your due diligence to ensure only those findings involving employees which are material to any threat assessment make it onto an employer’s records.
  • Employers should ensure they, and any service providers, comply with the Privacy Act 1988 (Cth) and its Permitted General Situations (Chapter C) when performing this work.

Lastly, ensure your Insider Threat Program incorporates views from a diverse range of stakeholders. The need for this diversity highlights the importance of having an Insider Threat Management Committee made up of representatives from different functional areas, including the business and center functions such as HR, legal, IT and security, rather than actions being driven by security or fraud functions alone.

Further Reading

DISCLAIMER: All information presented on @ForewarnedBlog is intended for general information purposes only. The content of @ForewarnedBlog should not be considered legal or any other form of advice or opinion on any specific facts or circumstances. Readers should consult their own advisers experts or lawyers on any specific questions they may have. Any reliance placed upon @ForewarnedBlog is strictly at the reader’s own risk. The views expressed by the authors are entirely their own and do not represent the views of, nor are they endorsed by, their respective employers. Refer here for full disclaimer.

Product Tampering: A form of workplace sabotage

Author: Paul Curwell

Sabotage, as it is in general use today, means “to damage or destroy equipment, weapons, or buildings in order to prevent the success of an enemy or competitor” (Cambridge Dictionary) and is commonly associated with war or nation state espionage. However, the origin of the word reportedly comes from the industrial revolution, where exploitation of workers was rife with underpayment (or non-payment) of wages and poor industrial safety conditions. French shoemakers wearing sabots reportedly rebelled, damaging and / or destroying their employer’s manufacturing equipment it in the process, becoming ‘saboteurs’.

Since this time, there have been countless instances of sabotage outside of war, particularly relating to either industrial or environmental action. Some acts of industrial sabotage are caused by employees, contractors or suppliers (trusted insiders), whilst others have been perpetrated by customers or unrelated parties as outlined in an interesting article from CNBC in Canada.

So what is product tampering anyway?

‘Product Tampering’ is a form of sabotage, and refers to actions taken to interfere with a product designed for use, or consumption, by the general public. Many industrial cases of product tampering involve food, pharmaceutical or medical products. Product Tampering can occur during or after manufacture (i.e. at any point in the supply chain until it reaches the End User), and is addressed under at least two pieces of Australian Legislation:

  • The Therapeutic Goods Act 1989 (Cth) defines both to ‘tamper’ and ‘product tampering’ in the context of manufacturers failing to report and / or recall. In Australia, the definition of ‘therapeutic goods’ includes medicines, medical devices, disinfectants and other goods such as blood products.
Therapeutic goods can be subject to tampering.
Photo by Karolina Grabowska on Pexels.com

  • Tamper therapeutic goods are tampered with if: (a) they are interfered with in a way that affects, or could affect, the quality, safety or efficacy of the goods; and (b) the interference has the potential to cause, or is done for the purpose of causing, injury or harm to any person (Therapeutic Goods Act 1989 Section 3, Australia).
  • Meaning of actual or potential tampering  – in relation to therapeutic goods, means: (a)  tampering with the therapeutic goods; or (b)  causing the therapeutic goods to be tampered with; or (c)  proposing to tamper with the therapeutic goods; or (d)  proposing to cause the therapeutic goods to be tampered with.
  • The offence of contaminating goods (actual or threatened) with the intent to cause public alarm or anxiety is captured under Part 9.6 – Contamination of Goods of the Criminal Code Act 1995 (Cth), which creates three categories of offence, each of which can potentially result in up to 15 years imprisonment:
    • Contaminating Goods (Section 380.2)
    • Threatening to Contaminate Goods (Section 380.3)
    • Making false statements about Contaminated Goods (Section 380.4)
  • Australia’s food system is defined as part of our ‘Public Infrastructure‘ under Division 82 of the Criminal Code Act 1995 (Cth), which pertains to Sabotage offences primarily in relation to National Security.

2018: the year Australian’s found sewing needles in their strawberries

On 9th September 2018, media reports started to emerge with stories claiming punnets of Australian strawberries were found on the shelves of Australian supermarkets with metal sewing needles stuck in the fruit. If consumed by an unsuspecting customer, the sewing needles could cause severe injury, potentially worse.

Australia was subject to a product tampering incident involving strawberries in 2018.
Photo by Pixabay on Pexels.com

Initial reports of the contaminated berries came from a small number of shops, suggesting the tampering could have happened locally (i.e. by a person walking into a number of stores and inserting the needles without being detected). However, as the incident evolved, consumers and stores across multiple states started reporting tampered products, indicating contamination occurred much earlier in the supply chain either at the point of manufacture and packaging (i.e. the strawberry farm) or at some distribution point.

Media reports quote Police as having identified somewhere between 186 and 230 instances of contaminated strawberries. On 11 November 2018, a 51-year old female supervisor at a Queensland strawberry farm was arrested, and subsequently charged with 7 counts of Contaminating Goods under the Crimes Act 1995 (Cth). At a bail hearing, the Magistrate was quoted by the media as stating the Crown alleged the perpetrator was “motivated by spite or revenge” over a “workplace grievance”. Whilst I couldn’t find any court documents indicating the case had proceeded to trial at the time of this article, readers who are interested in learning more about the case can find a collection of related articles here.

woman standing in front of assorted fruits displayed
Photo by Clem Onojeghuo on Pexels.com

So what can (should) businesses do to manage the threat of product tampering by trusted insiders?

Australia’s 2018 Strawberry Tampering incident was described by Food Standards Australia and New Zealand as a “best case scenario as the tampering was evident and the product packaged” (p. 8). Much of this ‘follow-up report to Government‘ focused on vulnerabilities in the Supply Chain, and the need for improved Supply Chain Security in the Food Sector. However, the report is silent on this incident being caused by an allegedly disgruntled employee, and is silent on this incident being effectively an insider threat.

For companies that make products, implementing a Supply Chain Security Program, such as that outlined in ISO 28000:2007, is critical to helping manage risks from the stage of ‘raw material / ingredient’ inputs through to manufacturing, distribution, transportation, retailing, and ultimately the End User. Additional guidance can also be sought from Product Liability Insurers: Liberty Specialty Markets is a leader in Australian product contamination insurance through their Crisis Management cover. However, I am yet to encounter a Supply Chain Security Program which incorporates prevention and detection aspects such as ‘behavioural indicators’ found in an Insider Threat Program when considering security risks arising from employees and contractors.

For example, could greater awareness of the behavioural indicators associated with disaffected or aggrieved employees have enabled line managers in Australia’s strawberry tampering to spot the employee’s changing behaviour? Based on the outcomes of research into many other types of insider threat, I suspect the answer would be yes. To effectively manage the risk of workplace sabotage in the form of product tampering, organisations which create or deal in things (‘products’) as opposed to services need to combine elements of a traditional Supply Chain Security Program with the missing elements of an Insider Threat Program. Unfortunately, all to often product tampering issues are viewed from a purely supply chain lens which overlooks the involvement by a trusted insider.

Further Reading

  • 9 News (n.d.). Strawberry Needles: Food Recall, Collections Page, 9news.com.au
  • Australian Associated Press (2018). Women charged with strawberry needle contamination sought revenge, court told. Published 12 November 2018, The Guardian
  • BBC News (2018). Australia strawberry scare: Accused saboteur ‘motivated by spite’, 12 November 2018. BBC News
  • Criminal Code Act 1995 (Cth), Federal Register of Legislation.
  • Food Standards Australia and New Zealand (2019). Strawberry tampering incident Debrief 1 May 2019: Follow-up report to Government, www.foodstandards.gov.au
  • International Standards Organisation (2007). ISO 28000:2007 Specification for security management systems for the supply chain, www.iso.org.
  • Liberty Specialty Markets Australia (2021). Crisis Management Insurance.
  • Schwartz, D. (2012). 5 major product tampering cases. CBC News Canada
  • Therapeutic Goods Act 1989 (Cth), Federal Register of Legislation

DISCLAIMER: All information presented on @ForewarnedBlog is intended for general information purposes only. The content of @ForewarnedBlog should not be considered legal or any other form of advice or opinion on any specific facts or circumstances. Readers should consult their own advisers experts or lawyers on any specific questions they may have. Any reliance placed upon @ForewarnedBlog is strictly at the reader’s own risk. The views expressed by the authors are entirely their own and do not represent the views of, nor are they endorsed by, their respective employers. Refer here for full disclaimer.