
Introduction: The Crossover between Espionage and Corporate Security While Working as a Canadian Intelligence Officer (A Canadian Spy).
I spent a decade working as an intelligence officer with the Canadian Security Intelligence Service (CSIS). My journey has been one of intrigue, challenges, and often fun with the ultimate goal of safeguarding national interests. As someone who once specialized in covert technical surveillance operations, I have unique insights into the vulnerabilities I used to exploit. The lessons I’ve learned during my time in the shadows have direct applications for those responsible for their organization’s security with a mandate to protect their critical assets, people, and sensitive information from both physical and cyber threats.
In this blog post, I’ll share ten essential lessons from my hands-on experiences that can guide corporate security measures and empower individuals to protect themselves from the ever-changing and challenging threat landscape. Remember, security is a collective effort, and it’s through shared knowledge and collaboration that we can build a resilient and secure environment for individuals, organizations, and countries alike.
1. How Do You Create a Plan for an Organization or Business Security in Canada if You Don’t Have an Accurate Picture of Your Threats and Risks?
The mandate of the Canadian Security Intelligence Service (CSIS) is to collect, analyze and advise the government on threats to the security of Canada. As an Intelligence Officer (Canadian spy), I was in the threat identification business, providing information to government partners like the RCMP (Royal Canadian Mounted Police), CBSA (Canada Border Services Agency), and other Government Ministries so they could make risk-informed decisions with all available relevant information. The cases I have worked on have led to criminal charges, deportations, and government policy changes where our country and national interests were found exposed, vulnerable to attack, or at risk of compromise.
Far too often, in the corporate security world, I see organizations making security decisions blind to the threats they face and the vulnerabilities of their existing defences. This leads to corporate security programs that are not optimized, consistent, or aligned to protect themselves from an ever-evolving threat landscape.
A Threat, risk, and vulnerability assessment is a foundational component of a security program. It is a systematic approach to understanding and categorizing critical assets, evaluating the most likely threats and risks, assessing the existing security measures in place, and then making recommendations to mitigate any identified vulnerabilities. A TRA from a trusted 3rd party reviewer has the benefit of giving an insight into the threats and benchmarking against industry standards to optimize a corporate security program in Canada. It’s a way to enhance your organization’s overall security posture and demonstrate to clients, staff, and regulators that you take the safety of your people, security of assets, and integrity of customer information seriously. Without knowing your risks and vulnerabilities you have no way to know if you’re protected against the most likely or impactful threat events.
2. Training Matters – Rising to the Occasion Through Preparation.

In the world of espionage, every mission requires meticulous training and preparation. We often had minutes to conduct very tense and challenging tasks where mistakes could have serious consequences on the operation’s success. In those extreme moments of stress, the adage “we don’t rise to the moment; we sink to our level of training” holds true. This is the same for intelligence operations and the realm of corporate security.
Security infrastructure, policies, processes and procedures are important. To maximize their effectiveness and ensure consistent application, it is essential to continue to train your staff simulating real-world scenarios that test the resilience of the security program delivery and identify any operational deficiencies. A physical security penetration test is a way to see if the current security operational plans will hold or if they will fall apart under the first hint of stress.
3. People Are an Organization’s Greatest Strength and can also be the biggest Vulnerability.
When spies are looking for information on threats to the security of Canada we often go out to knock on doors looking for people with access information and who would be willing to share it with us. These aren’t often “bad” people but individuals who by nature of their employment, friends, organizational affiliations may be able to provide insight into potential threat actors, events, or supporters.
Organizations’ most valuable employees and resources often have similar privileged access to their most private and commercially sensitive information. Nation States, organized criminal organizations and other nefarious threat actors will target them and those around them to get unauthorized access to what they hold. These actors aren’t looking for terror attack plans but for valuable research, financial information, budgetary plans, or other information from which they could ransom or otherwise profit. Most executives would never willingly compromise their organizations; however, they can still be vulnerable to phishing campaigns, computer theft, and eavesdropping in their cars or executive offices.
Those responsible for corporate security need to build comprehensive plans for their key executives, including burner devices and training for international travel, regular sweeps of corporate offices, and enhanced monitoring of devices with regular assessments of their online profile and physical spaces. The benefit of building resilience among executives is that they can champion corporate security throughout the organization. An executive who takes measures to protect themselves and safeguard their organization will set an example for others and raise the security culture and posture of the organization. As a former Canadian Intelligence Officer, I can tell you – the groups who took their security seriously from the top were often the toughest groups to penetrate.
4. We Create Vulnerabilities Online That Can Materialize Into Physical Security Threats.
Personally Identifiable Information (PII) is information specific to us. It’s a trail we leave through our activities online that others can use to identify and target us. Some information we put out about ourselves, like social media accounts and posts. Some information is collected about us without our explicit knowledge, through the apps and online services we use. The greater the PII, the more vulnerable the individual is to cyber or physical compromise. As a Canadian spy, I was often amazed at the personal information available about someone I could find.
- Their corporate work experience, business associates and even projects or IT systems they work on are on LinkedIn.
- Their friends, family, and close associates are on Facebook, indicating the depth of the relationship by how many likes, comments, shares and friends’ photos on the profiles.
- Every thought they’ve ever had is on X (“formerly Twitter”), including views on current events, organizations they support and political affiliations.
I could then use this information to build a pretty comprehensive profile of who this individual was, what information they may have, and how to approach them to build instant rapport. Do we both have kids? Like dogs? Support a benevolence society?
Additional information may include daily activities or routines, secondary residences and even the types of security available at each. Threat actors can use the PII available about us to paint a very comprehensive picture of our profile, activities, and areas in which we may be vulnerable in the physical world. Is the individual of interest going out of town or on the weekend at the cottage? Are there photos of their home from a previous online listing? Could we build a pattern of behaviour from these digital clues to plot a physical security operation?
Private individuals and those responsible for executives need to monitor online digital profiles to ensure that online activities are not creating vulnerabilities in the physical space. Digital exposure creates real vulnerabilities that can affect us in our physical world.
5. You Would Be Amazed at What People Say When They Think Nobody is Listening.
Collecting sensitive information is often about being in the right place at the right time. And that time and place is anywhere people put their guard down, whether eavesdropping on indiscrete phone conversations on the go train, sitting behind someone doing work on a long flight, or listening through a covert microphone in a corporate boardroom. A large majority of my spy career was attempting to identify those opportunities where people let their guard down and speak freely – then placing a human or technical asset to collect that information.
Our adversaries are trying to gain access to our most private and commercially sensitive information for nefarious purposes. Training staff on discretion, the need-to-know principle, Principal of least privilege, and strict confidentiality, as well as conducting regular technical surveillance countermeasures (TSCM or “bug sweeps”) of boardrooms, executive offices, private vehicles and planes, prevents private conversations from becoming public liabilities.
6. It Doesn’t Matter if You’re Hacked or a Corporate Laptop is Stolen Out of Your Parking Lot – a Data Breach is a Data Breach.

The special operation security team consisted of technologists (“techs”) who were experts in collecting information. There were the close access “techs” who could get their hands on paper in an open filing cabinet or desk, copy it and return it as you’d never know it was moved. There were also remote access techs who could ‘hack’ into technology in place, such as phones or desktop computers. The reality is we didn’t care about style points. Hacking a computer was great, but sometimes getting someone’s computer they leave in their hotel room when they use the hotel gym is often easier and more efficient.
The same goes for sensitive corporate information. You may see spies getting access to a corporate server in the movies – it is just as effective to get classified information through in the trash rather than forgetting to place it in a secure shredding bin.
I often tell corporate security directors in Canada that there is a nexus between physical and cyber security when discussing information security. Secure printing and shredding policies, restricted physical server access, clean desk policies and other access controls complement network or logical security controls. A server that is left on the floor and is damaged in a flood can have just as devastating an impact as a data breach or ransomware attack. Cyber is a serious buzzword, and IT / Network security is crucial. It is also important to consider your physical security when evaluating your overall information security and operational resilience.
7. An Effective Security Culture is When Everyone Feels Empowered to Say ‘no’.
The biggest risk to some of my most important covert operations was often a very junior front line staff member that took their job seriously. A security guard that did frequent rounds. A receptionist that demanded to see identification. A property manager that had their building trained to confront anyone attempting to tailgate. We would operate with a cover story. And to be honest, my Canadian spy cover story didn’t have to be great as long as my belief in it was stronger than the skepticism of the person challenging it. Sometimes I would meet my match and it wasn’t always who you suspected.
It’s often said that if you look like you belong and stick to your cover story, there aren’t too many places you can’t get access to. I’ve tested this theory on many occasions. Whether it was simply wearing a blazer to get a meeting with an executive who wasn’t expecting me or carrying two large paper towel rolls and walking urgently through a corporate office, our desire to be helpful and non-confrontational is a wonderful human characteristic and a devastating security vulnerability.
This is magnified in an age where large percentages of our workforce are working from home. Our relationships with our co-workers are not as strong as once, and we may be more reluctant to challenge a visitor as a lack of familiarity would be normal. We need to reinforce a security culture where it is okay to say ‘no’. Where people at all levels feel empowered to enforce the rules, this starts with leadership at the top as well as regular training and testing.
8. The More Access You Give Someone, the More Due Diligence and Checks They Should Be Subjected to

It took me approximately 15 months from my online application to getting a contract offer from CSIS. In that period, I was interviewed, went through a psychological assessment, an extensive background check, a polygraph test and swore an oath to keep everything sensitive that I would learn and do secret for the rest of my life. This was all required because as an intelligence officer I would be given access to the most classified and secret information collected by our government.
Similarly, for companies, corporate insiders and those closest to them have access to some of the most sensitive information. For individuals, when we enter into a financial or personal relationship with someone, in many cases, we entrust our reputation to them. It is, therefore, important that the level of due diligence conducted is commensurate with the access and potential for harm that a break in this relationship could cause.
Basic due diligence should be conducted based on the level of access and potential for compromise. In advance of a partnership where you now have reputational risk. A contractor who will have access to your personal items or a tenant who may have been involved in countless nuisance lawsuits. It’s important to conduct diligence in advance to save yourself the potential time, energy and money it takes to sever or recover from a commercial or personal relationship when things go wrong.
9. The World is Changing Fast, and the Threats of Yesterday Aren’t the Challenges of Today or Tomorrow.
Sometimes I wish I had paid more attention to the ‘techs’. While I was in CSIS, there was an explosion of technological tools and resources available to target individuals. I often left this to the techs. I would tell them what we needed to accomplish, and they would tell me how they planned to do it. That could be hacking a phone or even wiring a car with a listening device. I used to take their solutions for granted, not realizing how much work went into ensuring we were using the most effective equipment and were one step ahead of our adversaries, who were also using technology to defend themselves.
It is so important to be aware of the latest security technology and solutions. I think back of those times I used to break into cars in people’s driveways while they were home sleeping. I think about that sometimes when my video doorbell sends me an alert at 2 in the morning. I’m not sure we could do that anymore. Or if they are, they have to be able to account for the possibility of being detected. The number of security tools that people are using has changed the game.
We used to have to put a camera pretty close to a location we wanted to monitor – new systems with better quality resolution and analytics that will help point, direct and alert have also changed what is possible. It was a constant game of cat and mouse, and we were always looking to build the better mousetrap. Both sides still are.
The days of setting it and forgetting it security are gone. A security program that is not regularly reviewed and tweaked misses opportunities to optimize and enhance itself. Just as the tools available to threat actors evolve, there are also opportunities to protect ourselves. Video analytics, advanced biometric card readers, new Bluetooth TSCM equipment. It’s a lot to keep up on and for stretched security teams, it’s important to have impartial third parties who can advise on industry standards and benchmarks as well as the latest security tools and resources available.
10. No One Can Do It Alone
The greatest misconception the movies perpetrate about the world of espionage is that super spies like James Bond and Jason Bourn can do it all themselves. In reality it takes a team made of people with different experience, capabilities and training. On some jobs, there were often very large multi-disciplinary teams, including surveillants, close and remote access technologists, communications analysts, intelligence officers and special operations security members, all working together to conduct a single operation against a target. With that many resources directed against one individual, we were able to give ourselves the best chance of success.
Now imagine that in reverse. In the corporate security world, I often meet a single individual with responsibilities for physical and cyber security, as well as issuing access cards and keeping the lights on and the elevator from breaking down. It’s too much for one person. Given the diverse number of threat actors targeting organizations and the breadth of the threat surface, they need a similarly diverse and deep bench of dedicated security professionals to assist. Often they simply do not have those in-house resources.
Few organizations keep a bug sweep team on staff. Or maintain a license to conduct private investigations. It is, therefore, important to build a network of security partners with the capacity and capabilities your team may be lacking. Just as no single intelligence agency could counter all threats alone, no corporate security director should navigate the complex landscape of security in isolation.
I hope the experiences and insights I gained from working as a Canadian Intelligence Officer (Canadian Spy) can offer lessons for enhancing security practices in any organization. The world of espionage provides a unique perspective on risk management, threat identification, and strategic planning that can be applied to protect assets, people and information. By understanding the challenges and strategies of working as an IO, security professionals can better prepare for and mitigate potential threats from people like me, ultimately creating a safer and more secure environment for individuals, businesses, and nations alike. Stay safe everyone.