
When Friends Become… Less Friendly
So apparently we’re in a trade war. I don’t know how this will end, but I do think about the security considerations, both from a national security and private-sector perspective.
Canada and the United States have one of the closest intelligence-sharing relationships in the world. That relationship has always been based on the fact that we are aligned on the threats we face and can trust each other with our most sensitive information. I don’t envy my ex-colleagues in the intelligence community who now have to navigate what a more strained political relationship means for that cooperation.
With tariffs, organizations will need to think about their costs and supply chains. But they should also consider the security implications of broader trade realignment. Who has access to their information? Where is it stored? What jurisdiction is it subject to? And could new partnerships or suppliers create restrictions on who they can do business with or where their information can go?
Before You Build that Fence
We’re being brought onto a number of large infrastructure projects where designers and builders are working from tenant, industry or government security standards and guidelines. The challenge is that these can be generic, extremely broad or may not apply in every circumstance. For people without a security background, it can be difficult to interpret them and make defensible decisions about what is actually required.
On a large project, implementing controls that aren’t necessary can add millions of dollars to the cost. A security assessment considers the likelihood and potential consequences of the threats facing the site and helps determine how those requirements should be met. Natural landscaping and other security controls, for example, may provide an alternative to kilometres of costly fencing.
I get that nobody ever got fired for following the guidelines. But organizations building major projects should take the time to understand the security requirements before committing to costly controls. There may be opportunities to achieve the same security objective in a more practical and cost-effective way.
Black Flies and Bug Sweep Season
August and September seem to be good months for bug sweeps. We’ve conducted a number of technical surveillance countermeasures (TSCM) engagements over the summer and have many more lined up for the fall.
Some are regular sweeps, particularly for OSFI-regulated organizations. Others are prompted by a specific concern. We’ve been brought in following a challenging employee off-boarding, during an investigation into potential internal fraud, and because of suspicious activity around a commercial space. Even when nothing is found, a sweep can provide peace of mind and identify other vulnerabilities, including unintended audio leakage.
Late summer is also a popular time for people and organizations to move into new homes and offices. Conducting a sweep before occupying a new space provides a baseline of what is there. Future sweeps can then help identify whether anything has changed or an unidentified device has appeared.