Panel, Conference Presentation
Coming In from the Cold: Espionage in Today's Geopolitics | Global Conference 2025
Milken InstituteSimon Radford, Darrell Blocker, Anthony Camerino, Christo Grozev, Katherine Mulhern, Jill Popelka, Nick Schifrin, Alyssa
Russia's Strategic Disadvantage to the West
- Russia perceives itself to be in a "hot war" with the West, whereas Western nations continue to operate under a paradigm of Russia as a "normal" country, creating a critical perception gap.
- Leaked internal Russian intelligence documents confirm a state doctrine treating the US and Western Europe as enemies and justifying continuous aggression.
- Russia has commercialized intelligence and kinetic operations (assassinations, terrorism), creating a decentralized market where private actors compete with state security arms (FSB, GRU, SVR) for favor with the Kremlin.
- This model includes state-funded private military companies (e.g., Wagner/Prigozhin) and oligarchs running independent intelligence agencies without direct budget oversight to perform influence operations.
- Western adversaries possess no equivalent mechanism for privatized, competitive intelligence operations, placing them at a structural disadvantage.
Corporate Threat Landscape and Targeting
- Corporate C-suite executives are explicitly targeted by state actors (Russia, China, North Korea, Iran) and non-state actors, not just as primary targets but via vectors like vendors and disgruntled employees.
- North Korean operatives are noted for successfully infiltrating US markets with minimal budgets, guidance, or personnel.
- Disgruntled employees with access to sensitive codes or secrets are identified as significant threats, equal to foreign state actors in capability to compromise organizations.
- Cybersecurity threats predominantly originate from social engineering, with 92% of novel attacks starting via phishing emails.
- Attackers are leveraging AI to increase the velocity, sophistication, and complexity of phishing campaigns.
- Darktrace advises a dual-approach to security: "attack-centric" (defending against known threats) combined with "business-centric" (defining and protecting against internal anomalies).
- Due diligence for mergers and acquisitions must verify if a target company possesses a "business-centric" cybersecurity posture that understands its specific operational normalcy.
The Impact of Digital Footprints on Espionage
- Social media and internet proliferation have expanded the surveillance surface for intelligence agencies, requiring physical security resources to be matched or exceeded by digital security efforts.
- Adversaries now recruit targets more easily by identifying "weak points" (disgruntlement, motivations) via public online activity rather than physical surveillance.
- Open-source intelligence (OSINT) and digital trails allow adversaries to create motivations for individuals or exploit existing ones without traditional human intelligence (HUMINT) recruitment.
Democratic Oversight and Intelligence Efficacy
- Democratic intelligence agencies often hoard collected data on enemy states rather than sharing it proactively with law enforcement or the public to prevent attacks.
- The failure to detect the Salisbury poisoning assassins for seven years was attributed to a lack of basic data cross-referencing (e.g., checking visa applicants against real-world databases).
- Public shaming by investigative journalists and NGOs (e.g., Bellingcat) forces intelligence agencies to become more diligent and proactive in exposing malign operations.
- Western nations lack the capacity to fully counter state-privatized intelligence models, relying instead on private initiative and transparency rather than direct operational parity.
Financial Countermeasures and Restitution
- Restitution Capital operates as a "sword" element (active recovery) complementing traditional defensive "shield" measures, using litigation funding and private equity to recover stolen assets.
- Illicit financial flows from kleptocracy and corruption in Africa and Asia are estimated at $100 billion to $150 billion annually, destabilizing both national economies and global financial systems.
- "Gray money" (fraud, tax evasion) rapidly transitions into "dark money" funding serious organized crime, terrorism, and wildlife trafficking.
- Investigations rely heavily on whistleblowers, document dumps (e.g., Panama Papers), and mapping financial flows via SWIFT data to identify illicit havens.
- The panel advocates for closing financial loopholes in Western hubs (specifically the UK) that serve as havens for stolen wealth.
- The speaker notes that fixing illicit flows could turn Africa into a net creditor, as reversing these flows would fund essential services currently dependent on aid.
Open Source Intelligence (OSINT) Capabilities
- Successful OSINT (e.g., Bellingcat) relies on obsessive attention to detail, collaborative crowdsourcing, and a willingness to share results rather than claiming ownership.
- The core advantage of OSINT is the realization that state actors are not perfect; they make mistakes, leave digital loopholes, and suffer from internal corruption (e.g., a GRU officer funding a child via a shell company that becomes a vulnerable infrastructure node).
- Executives must codify OSINT capabilities within their organizations to avoid falling behind in assessing competitors, markets, and risks.
- Many large media organizations now maintain their own OSINT units to identify data protection failures in government and corporate systems.
Cybersecurity Innovation and Ecosystem Cooperation
- Darktrace was founded by mathematicians and intelligence officials to protect networks by establishing a baseline of "normal" behavior rather than just tracking known threats.
- The company advocates for an "ecosystem effort" where competitors share vulnerability data directly rather than exploiting it or publicizing it for gain.
- Darktrace recently disclosed a vulnerability to a competitor directly to ensure broader protection of the global cybersecurity fabric.
- Governments should foster an environment that encourages collaboration between private defense tech firms and state actors to combat nation-state threats.
- The panel suggests that corporations ignoring shared defense protocols make themselves a strategic disadvantage against adversaries who control companies.
Soft Power and Aid in Africa
- Cuts to Western aid (US, UK) are removing key sources of soft power and influence in Africa, particularly in sectors like healthcare where USAID provides up to 70% of care in Western Africa.
- Reversing illicit financial flows (mispricing, tax evasion, license non-payment) presents a more sustainable alternative to aid for stabilizing African economies.
- The panel highlights the potential to return "stranded assets" and historical assets to African nations as a method to build trust and economic stability without relying on direct aid.