Countering Espionage - A Modern Threat

Corporate Espionage was once thought of as aThe placement of bugging devices in offices or
risk that only affects the richest of companies inboardrooms is not always the first option for
high-risk sectors or emerging markets, the latestespionage; often the logistical problems involved in
trends suggest that this is far from the truth.a live covert device far outweigh the benefits.
The history of espionage, thought by some asHowever, should access have been gained via
the second oldest profession in the world, can beinside information or chance, many of those
traced back to biblical times with more than 100carrying out espionage prefer to install hardwired
references in the Old Testament. Sun Tzu's bookGSM based devices, solving power and distance
"The Art of War", written around 500BC dealsissues. Cat5 cabling for example is a good carrier
specifically with intelligence networks andfor installing covert microphones. A GSM device
intelligence gathering. Unfortunately as is often thebeing located elsewhere in the complex acts as a
case, history has not taught us the most basic of"voice activated transmitter" and is almost
lessons; that intelligence is power, whether inimpossible to locate during a TSCM sweep of the
business or war, he who has intelligence has thegiven boardrooms or offices.
upper hand.Having a good internal security policy will aid a
Many are naive enough to think that espionagecompany and deter potential offenders. Staff
comes straight out of the pages of Ian Fleming'sshould challenge visitors not displaying a visitors
James Bond, confined to Governments and thebadge; visitors should be met at reception and not
largest of corporations. They are very muchleft unattended. Workmen also should not be left
mistaken.unattended and all companies should employ a
No one wants to be a victim, least of all admit toclean desk policy where possible.
being a victim, yet the rewards for those carryingLandlines
out espionage far outweighs the risks or expenseA device placed on the telephone line can be as
involved. Sad as it may seem, a simple devicefar as five miles away prior to the line entering
bought for as little as two hundred pounds canthe local exchange. A simple device that tests line
cost a company millions through lost corporatevoltage or impendence will not detect hi-tech
intelligence. At the lower end of the scale there isdevices unavailable to the general public. These
the office refuse, if this is not disposed of in thevarieties of device are normally of GSM type and
correct manner it can be yet another source ofutilise the power from other sources within the
leaked information within companies orlocal exchange/cabinet. They are nigh on
organizations.impossible to detect without a physical check of
Directors, management and IT personnel of manythe line up to the local cabinet (green roadside
companies fail to understand the fundamentalcabinet) level.
basics of countering espionage and the techniquesSecuring an external landline to the property need
employed by those carrying out such activities.not be an expensive encryption system; replacing
Millions of pounds are spent each year onan analogue system with digital ISDN/ADSL
eavesdropping transmitters, computer keystrokesystem will ensure that the line is far more
loggers and telephone recording systems.secure. Fibre-optic cables cannot be tapped into
Everyone wants to know what everyone else iswith ease unlike a twisted copper pair; a
doing in business, and for some it makes sense to"pod-splitter" and true line identification are
have a budget for "intelligence" prior to enteringrequired.
into litigation suits, hostile takeovers or mergersCellular telephones
and acquisitions.The fact is, that while it costs in excess of
Litigation, for example, is an area of complex£250k for the necessary equipment for
issues, cross border or otherwise, where technicalintercepting a cell phone, jamming the phone's
surveillance has in the past, been used to affectsignal costs less than a tenth of that price and is
the outcome of a given case. When a case isfar easier on an operational basis. A target uses a
worth £500 million, spending £50,000 oncellular telephone because she/he thinks that it is
winning makes sense to many companies, and farthe most secure way of communicating. A cellular
outweighs the risks of becoming the loser.jammer can be deployed to jam the cellular
The level of the risks involved in Corporatetelephone, forcing the target to use the landline
Espionage is all relative to the financial rewards.that is intercepted. Keeping it simple counts, low
The level of the technology employed is relativerisk and high gains.
to the investment.Computer Systems/Email
It is more and more evident that few securityTrojan Viruses sent to targets via email can
companies fully understand the technologycontain complex keystroke logging programmes
involved, how communications operate or areor open back doors to computer systems. At the
intercepted/manipulated, leaking vital corporatelower end of the scale, there are many of such
intelligence to competitors.programmes freely available on the Internet, at a
Some Technical Surveillance Counter Measureslow cost or for no cost at all. At the higher end
(TSCM) firms are so far behind that the adviceof the scale there can be hackers targeting a
that they pass on to their clients is often futile.business/director in order to gain given intelligence
With budgets in the tens of thousands of pounds,on sensitive financial matters. The cost of the
a telephone can be intercepted miles away fromlatter option, whilst in the thousands of pounds
the target location and monitored from the othermark is, as I have previously covered, worth the
side of the world, live. Each call is time and daterisk in the larger cases.
stamped, in turn recorded on a computer forNew, off-the-shelf, computers are not as secure
later evaluation.as users might think; the default settings are
The fact of the matter is, in some cases a TSCMinsecure and need to be configured prior to
sweep is of no use when technical surveillance canconnection to the outside world. The most basic
be so remote. Better understanding is needed,of steps should always be taken, updating
both of the modus operandi and of the latestanti-virus software on a weekly basis, backing up
technology. Few TSCM firms understand just hownetworks and installing a hardware firewall are just
far an espionage budget of £20k can go.some of the easiest options to employ as a
TSCM sweeps as part of a security housekeepingcounter measure.
policy do make sense if carried out to includeThe best answer to computer security is file and
computer systems, rooms and telephone lines toemail encryption, this though, only providing that
local exchange level. It is true to say that thethe computer system is firewall protected.
basic technical principles of espionage techniqueBluetooth and Wireless connections
have not changed too much over the pastWireless computer connections are high risk and
twenty years since the end of the cold war.can, if not set up correctly be intercepted at ease
However the movement in technology and withby external attack. This risk has been highly
the vast use of communications spanning thereported over the past two years, but many
world has lead the public into a false sense ofmanufacturers have still failed to change the
security and apathy when employing thesedefault settings of their devices, thus enabling
communication techniques.other "attacking" systems to connect and
Any type of electronic communication can bedownload vital information such as address books
intercepted at one level or another; the role ofand other files; all without the user's knowledge.
the TSCM firms should be best utilised identifyingOverall what must be taken on board is that no
the areas of weakness and employing measuresone wants to work in a locked down
to combat these possible areas of weakness.environment, but in a secure one. All security
Office Securityrecommendations need to be both affordable and
Many large companies fall foul of size and generalworkable, the simpler the better, realistic and in
lack of in-house security policies, making espionagekeeping with the level of possible threat.
far easier and easier still with inside information.