newsfilter.io
Panel, Conference Presentation

Coming In from the Cold: Espionage in Today's Geopolitics | Global Conference 2025

  • Russia's Strategic Disadvantage to the West

    • Russia perceives itself to be in a "hot war" with the West, whereas Western nations continue to operate under a paradigm of Russia as a "normal" country, creating a critical perception gap.
    • Leaked internal Russian intelligence documents confirm a state doctrine treating the US and Western Europe as enemies and justifying continuous aggression.
    • Russia has commercialized intelligence and kinetic operations (assassinations, terrorism), creating a decentralized market where private actors compete with state security arms (FSB, GRU, SVR) for favor with the Kremlin.
    • This model includes state-funded private military companies (e.g., Wagner/Prigozhin) and oligarchs running independent intelligence agencies without direct budget oversight to perform influence operations.
    • Western adversaries possess no equivalent mechanism for privatized, competitive intelligence operations, placing them at a structural disadvantage.
  • Corporate Threat Landscape and Targeting

    • Corporate C-suite executives are explicitly targeted by state actors (Russia, China, North Korea, Iran) and non-state actors, not just as primary targets but via vectors like vendors and disgruntled employees.
    • North Korean operatives are noted for successfully infiltrating US markets with minimal budgets, guidance, or personnel.
    • Disgruntled employees with access to sensitive codes or secrets are identified as significant threats, equal to foreign state actors in capability to compromise organizations.
    • Cybersecurity threats predominantly originate from social engineering, with 92% of novel attacks starting via phishing emails.
    • Attackers are leveraging AI to increase the velocity, sophistication, and complexity of phishing campaigns.
    • Darktrace advises a dual-approach to security: "attack-centric" (defending against known threats) combined with "business-centric" (defining and protecting against internal anomalies).
    • Due diligence for mergers and acquisitions must verify if a target company possesses a "business-centric" cybersecurity posture that understands its specific operational normalcy.
  • The Impact of Digital Footprints on Espionage

    • Social media and internet proliferation have expanded the surveillance surface for intelligence agencies, requiring physical security resources to be matched or exceeded by digital security efforts.
    • Adversaries now recruit targets more easily by identifying "weak points" (disgruntlement, motivations) via public online activity rather than physical surveillance.
    • Open-source intelligence (OSINT) and digital trails allow adversaries to create motivations for individuals or exploit existing ones without traditional human intelligence (HUMINT) recruitment.
  • Democratic Oversight and Intelligence Efficacy

    • Democratic intelligence agencies often hoard collected data on enemy states rather than sharing it proactively with law enforcement or the public to prevent attacks.
    • The failure to detect the Salisbury poisoning assassins for seven years was attributed to a lack of basic data cross-referencing (e.g., checking visa applicants against real-world databases).
    • Public shaming by investigative journalists and NGOs (e.g., Bellingcat) forces intelligence agencies to become more diligent and proactive in exposing malign operations.
    • Western nations lack the capacity to fully counter state-privatized intelligence models, relying instead on private initiative and transparency rather than direct operational parity.
  • Financial Countermeasures and Restitution

    • Restitution Capital operates as a "sword" element (active recovery) complementing traditional defensive "shield" measures, using litigation funding and private equity to recover stolen assets.
    • Illicit financial flows from kleptocracy and corruption in Africa and Asia are estimated at $100 billion to $150 billion annually, destabilizing both national economies and global financial systems.
    • "Gray money" (fraud, tax evasion) rapidly transitions into "dark money" funding serious organized crime, terrorism, and wildlife trafficking.
    • Investigations rely heavily on whistleblowers, document dumps (e.g., Panama Papers), and mapping financial flows via SWIFT data to identify illicit havens.
    • The panel advocates for closing financial loopholes in Western hubs (specifically the UK) that serve as havens for stolen wealth.
    • The speaker notes that fixing illicit flows could turn Africa into a net creditor, as reversing these flows would fund essential services currently dependent on aid.
  • Open Source Intelligence (OSINT) Capabilities

    • Successful OSINT (e.g., Bellingcat) relies on obsessive attention to detail, collaborative crowdsourcing, and a willingness to share results rather than claiming ownership.
    • The core advantage of OSINT is the realization that state actors are not perfect; they make mistakes, leave digital loopholes, and suffer from internal corruption (e.g., a GRU officer funding a child via a shell company that becomes a vulnerable infrastructure node).
    • Executives must codify OSINT capabilities within their organizations to avoid falling behind in assessing competitors, markets, and risks.
    • Many large media organizations now maintain their own OSINT units to identify data protection failures in government and corporate systems.
  • Cybersecurity Innovation and Ecosystem Cooperation

    • Darktrace was founded by mathematicians and intelligence officials to protect networks by establishing a baseline of "normal" behavior rather than just tracking known threats.
    • The company advocates for an "ecosystem effort" where competitors share vulnerability data directly rather than exploiting it or publicizing it for gain.
    • Darktrace recently disclosed a vulnerability to a competitor directly to ensure broader protection of the global cybersecurity fabric.
    • Governments should foster an environment that encourages collaboration between private defense tech firms and state actors to combat nation-state threats.
    • The panel suggests that corporations ignoring shared defense protocols make themselves a strategic disadvantage against adversaries who control companies.
  • Soft Power and Aid in Africa

    • Cuts to Western aid (US, UK) are removing key sources of soft power and influence in Africa, particularly in sectors like healthcare where USAID provides up to 70% of care in Western Africa.
    • Reversing illicit financial flows (mispricing, tax evasion, license non-payment) presents a more sustainable alternative to aid for stabilizing African economies.
    • The panel highlights the potential to return "stranded assets" and historical assets to African nations as a method to build trust and economic stability without relying on direct aid.