In Defense of Facts: Setting Standards Against Information Threats

Unknown

Black Hat USA 2024 · Day 1 · Briefing

Overview

In an increasingly complex digital landscape, the lines between traditional cybersecurity threats and the broader dangers of information manipulation are blurring. This talk, "In Defense of Facts: Setting Standards Against Information Threats," delivered by Lester Godsey, CISO of Maricopa County, dives into the critical and often overlooked realm of misinformation, disinformation, and malinformation (MDM). Godsey argues passionately that MDM is not merely a societal problem but a potent threat vector with profound implications for an organization's financial stability, reputation, physical security, and cyber resilience.

Watch on YouTube

Visual summary for In Defense of Facts: Setting Standards Against Information Threats by Unknown
Visual summary for In Defense of Facts: Setting Standards Against Information Threats by Unknown

Key moments

  1. 0:00 Introduction: Why defense of facts is a needed conversation
  2. 2:20 Real-world impact: Doxing election staff and physical threats
  3. 4:10 Misinformation impacts all organizations, not just government
  4. 5:40 CISO's unexpected focus: preventing physical harm from misinformation
  5. 6:15 Overview of talk: challenges, discovery, and organizational actions
  6. 6:50 Maricopa County's team monitors social media for threats

In Defense of Facts: Setting Standards Against Information Threats

Speakers: Lester Godsey, CISO, Maricopa County

Conference: Black Hat USA

YouTube: https://www.youtube.com/watch?v=o1NG6Pecewg

Overview

In an increasingly complex digital landscape, the lines between traditional cybersecurity threats and the broader dangers of information manipulation are blurring. This talk, "In Defense of Facts: Setting Standards Against Information Threats," delivered by Lester Godsey, CISO of Maricopa County, dives into the critical and often overlooked realm of misinformation, disinformation, and malinformation (MDM). Godsey argues passionately that MDM is not merely a societal problem but a potent threat vector with profound implications for an organization's financial stability, reputation, physical security, and cyber resilience.

The presentation provides a stark, real-world perspective from Maricopa County, the fourth-largest county in the United States, which has found itself on the front lines of combating information threats, particularly in the context of election integrity. Godsey outlines numerous instances where false narratives and manipulated content online directly translated into physical threats against staff, operational disruptions, and heightened security risks. This talk serves as a urgent call to action for security professionals to expand their threat models, integrate MDM into their defensive strategies, and collectively work towards establishing industry standards for quantifying and mitigating these pervasive information-based attacks.

Godsey's insights challenge the conventional boundaries of cybersecurity, pushing attendees to consider how their organizations can proactively defend against narratives designed to sow discord, incite harm, and undermine trust. The necessity of this conversation stems from the tangible, often violent, consequences that MDM can unleash, transforming abstract online rhetoric into concrete dangers for individuals and institutions alike.

Background

▶ Watch: Introduction: Why defense of facts is a needed conversation (0:00)

Maricopa County, Arizona, with its population of approximately 4.6 million residents, stands as a microcosm of the challenges faced by governmental entities in an era rife with information warfare. Lester Godsey, a veteran IT professional with 27 years of experience, many of them in cybersecurity, openly admits that he never envisioned his role as CISO evolving to primarily confront MDM threats to prevent physical harm. This shift underscores the dramatic and unexpected evolution of the threat landscape, where digital narratives now directly fuel real-world kinetic events.

The county's experiences, particularly surrounding election processes, serve as vivid illustrations of MDM's impact. Godsey recounted several alarming incidents:

  • Doctored Images: A seemingly innocuous social media post questioned Maricopa County's transparency by sharing a manipulated image of a streaming camera feed from the recorder's office. The image falsely depicted a piece of paper on a wall with a router name and password, implying a severe security vulnerability. Maricopa County's team, using third-party software, proved the image was doctored, as no such paper existed in the facility.
  • Physical Stalking Based on Falsehoods: Social media posts generated a call to action, alleging that a truck being loaded at the recorder's facility contained ballots or voting apparatus being illegally disposed of. This led to individuals physically staking out the facility and following the truck. In reality, the truck was transporting old multifunction printer devices for salvage, and the driver was a sheriff's deputy. This incident highlighted the immediate physical danger posed by unchecked online speculation.
  • Doxing and Threats Against Election Staff: An election staff member was doxxed online, leading to their personal information being exposed. This resulted in an individual showing up at the employee's home in the middle of the night, caught on a Ring camera. The employee, fortunately, was out of town, but the incident directly contributed to her resignation due to the constant threats.
  • Physical Intrusions: Individuals engaged in "dumpster diving" at county facilities, attempting to piece together discarded materials in search of "evidence of malfeasance."
  • Armed Intimidation at Ballot Drop Boxes: In 2022, ballot drop box locations were staked out by individuals in tactical gear and armed, creating an intimidating and potentially dangerous environment for voters.

These incidents demonstrate that MDM is not confined to the digital sphere but has tangible, often severe, consequences, impacting financial stability, organizational reputation, and critically, the physical safety of personnel. For organizations, whether public or private, the motivations may differ – government often seeks to maintain public trust and democratic integrity, while private entities focus on profit – but the destructive power of MDM remains universal.

Key Findings

▶ Watch: Misinformation impacts all organizations, not just government (4:10)

Lester Godsey's presentation illuminated several critical findings regarding the nature and impact of MDM, challenging conventional cybersecurity paradigms:

  1. MDM as a Direct Threat Vector: The most significant finding is the unequivocal assertion that misinformation, disinformation, and malinformation constitute a direct and potent threat vector. The examples from Maricopa County vividly demonstrate how online narratives translate into physical security risks, reputational damage, and potential cyber vulnerabilities, moving beyond abstract concerns to concrete, actionable threats.
  1. Inadequacy of Current Risk Frameworks: A central challenge identified is the complete absence of industry standards or existing frameworks for measuring and quantifying MDM risk. Unlike traditional cybersecurity, which benefits from established methodologies like NIST, FAIR (Factor Analysis of Information Risk), and CVSS (Common Vulnerability Scoring System) for vulnerabilities, there is no equivalent for information threats spread via traditional or social media platforms. This lack of a standardized measurement system makes it exceedingly difficult for organizations to assess, prioritize, and allocate resources effectively against MDM.
  1. Difficulty in Quantifying MDM Risk: The difficulty in quantifying MDM risk stems from the inherent complexity of identifying reliable independent and dependent variables that can predict the spread and impact of false information. Without these foundational elements, applying statistical methods, such as Monte Carlo analysis, to model and forecast MDM events becomes virtually impossible. This gap leaves security professionals without the predictive tools common in other risk domains.
  1. Challenges in Reducing Mean Time To Discovery (MTTD): Directly linked to the quantification problem, Godsey highlighted the immense difficulty in reducing the Mean Time To Discovery (MTTD) for media-based threats. Without clear standards to delineate what constitutes a threat on social and traditional media, security teams struggle to effectively identify, analyze, and respond to MDM incidents in a timely manner. This increases the window of opportunity for harmful narratives to spread and escalate.
  1. Social Media as a Leading Indicator for Kinetic Events: A crucial insight shared is that social media, and by extension traditional media, often serves as a more accurate and earlier indicator of impending reputational attacks or physical (kinetic) events than purely cyber-focused intelligence. While social media posts might sometimes indicate heightened cyber risk, their primary utility for Maricopa County's SOC team has been in predicting and mitigating physical threats and reputational damage.
  1. Responsible Public Monitoring is a Viable Strategy: Maricopa County's experience demonstrates that ethical intelligence gathering through monitoring publicly accessible social media platforms can be a powerful defensive tool. By focusing solely on public data and avoiding identity correlation, organizations can gather critical threat intelligence without infringing on privacy or eroding public trust. This approach allows for proactive measures to be taken in collaboration with law enforcement and other relevant agencies.

Technical Deep Dive

▶ Watch: CISO's unexpected focus: preventing physical harm from misinformation (5:40)

The technical challenge presented by MDM is not in exploiting software vulnerabilities or network misconfigurations, but rather in the absence of robust methodologies and frameworks to measure, predict, and mitigate information-based threats. Godsey specifically addressed the significant hurdles in applying traditional risk quantification techniques to MDM.

In conventional cybersecurity, professionals are well-versed in established industry standards and frameworks designed to measure risk. Tools like NIST (National Institute of Standards and Technology) frameworks, FAIR (Factor Analysis of Information Risk), and CVSS (Common Vulnerability Scoring System) scores provide a common language and quantifiable metrics for assessing vulnerabilities and risks. When a vulnerability is disclosed with a CVSS score, security teams immediately understand its severity and how it was derived, enabling rapid and informed decision-making.

However, for information threats disseminated through social and traditional media, an equivalent system for measuring risk is "non-existent." Godsey illustrated this by referencing Monte Carlo analysis, a statistical method used for predictive modeling and risk assessment in various fields. A Monte Carlo simulation typically involves three basic steps:

  1. Creating a predictive model: Identifying both dependent and independent variables relevant to the scenario.
  2. Determining probability distributions: Assigning probabilities to the identified variables.
  3. Running simulations: Executing the model multiple times with random inputs based on the probability distributions to generate a range of possible outcomes.

The fundamental difficulty in applying Monte Carlo analysis, or any similar statistical method, to MDM lies in the first step: identifying the independent and dependent variables that predict the occurrence and impact of misinformation, disinformation, and malinformation. What specific variables can reliably predict the spread, virality, or real-world consequences of a false narrative? This question, Godsey emphasized, presents a "huge problem" and a significant challenge. The dynamic, often emotionally driven, and rapidly evolving nature of online discourse makes it exceptionally hard to isolate and quantify these predictive factors. Without a clear understanding of these variables and their distributions, any attempt at statistical modeling becomes speculative and unreliable.

This lack of quantifiable metrics directly impacts the ability to reduce Mean Time To Discovery (MTTD) for media threats. In traditional cyber incidents, a well-defined alert, a detected intrusion, or a vulnerability scan result triggers a known response protocol. For MDM, the "signal" is often ambiguous – a social media post, a comment, a shared image – and differentiating genuine threats from "white noise" is a constant struggle. Without a standardized way to delineate what specifically constitutes a threat on these platforms, and without a framework to assess its potential impact, security teams face an uphill battle in rapidly identifying and responding to emerging information threats.

Maricopa County's operational response, though not a "technical deep dive" into new protocols or code, represents a practical technical approach to this challenge:

  • SOC-Driven Monitoring: The county's Security Operations Center (SOC) team is tasked with monitoring social media. This demonstrates a shift in SOC responsibilities to include open-source intelligence (OSINT) gathering specifically for MDM threats.
  • Resource Constraints: The monitoring is not a 24/7 dedicated service but rather a rotation-based responsibility within the existing SOC team, highlighting the resource limitations faced by many organizations.
  • Publicly Accessible Platforms: A strict technical and ethical boundary is maintained: monitoring is limited exclusively to publicly accessible platforms. The team does not attempt to access private chats, forums, or conversations. This is a crucial technical constraint that informs their data collection and analysis.
  • No Identity Correlation: The intelligence gathering explicitly avoids correlating specific online accounts with individuals, unless there is a credible threat against a county employee. This further reinforces the ethical and legal boundaries of their technical operations, ensuring they do not "trample on constitutional rights" by acting as law enforcement.
  • Intelligence Dissemination: Collected intelligence is disseminated to the Arizona fusion center and other appropriate law enforcement agencies. This process ensures that potentially actionable threat intelligence reaches those equipped to respond, leveraging existing inter-agency information sharing mechanisms.
  • Employee Watchlist: While general identity correlation is avoided, the county maintains a "watch list" for its own employees if they are identified as credible targets of threats. This involves heightened awareness and continued monitoring for evidence of targeting, demonstrating a specific, justified technical focus on protecting internal personnel.

In essence, the "technical deep dive" into MDM reveals a critical void in security standards and a need for innovative, ethically bound approaches to data collection and analysis to bridge the gap between information threats and traditional security operations.

Demo / Proof of Concept

▶ Watch: Overview of talk: challenges, discovery, and organizational actions (6:15)

The presentation by Lester Godsey did not include a live demonstration or a formal proof of concept of a specific tool or system. Instead, the talk focused on illustrating the problem of MDM through numerous real-world examples experienced by Maricopa County and discussing their strategic and operational approaches to address these challenges. The "proof" lay in the tangible, often severe, consequences of MDM that the county had already faced, such as the doctored images, physical stalking incidents, and the doxing of election officials. Godsey's narrative itself served as evidence of the urgent need for better defensive strategies against information threats.

Defensive Implications

▶ Watch: Maricopa County's team monitors social media for threats (6:50)

The insights from Maricopa County's experiences with MDM carry significant defensive implications for organizations across all sectors. Security professionals must expand their traditional threat models to encompass the full spectrum of information threats, recognizing that MDM is not merely a public relations issue but a direct precursor to cyber, physical, reputational, and financial risks.

  1. Integrate MDM into Threat Intelligence: Security Operations Centers (SOCs) and threat intelligence teams should incorporate monitoring of social and traditional media into their routines. While 24/7 dedicated MDM analysts may not be feasible for all organizations due to resource constraints, a rotational responsibility or a structured protocol for monitoring publicly accessible platforms is essential. This integration helps in identifying emerging narratives that could pose threats.
  1. Develop MDM-Specific Incident Response Plans: Just as organizations have plans for cyber incidents, they need clear protocols for responding to MDM events. This includes processes for verifying information, assessing potential impact, coordinating with internal stakeholders (legal, communications, HR), and engaging with external partners like law enforcement or industry-specific fusion centers.
  1. Prioritize Ethical Intelligence Gathering: Any MDM monitoring efforts must strictly adhere to ethical and legal boundaries. Focusing solely on publicly accessible information and avoiding attempts to access private communications or correlate identities (unless legally mandated and specifically targeting credible threats to personnel) is paramount. Maintaining public trust, especially for government entities, is a critical component of defense against information threats.
  1. Advocate for Industry Standards and Frameworks: The cybersecurity community needs to collaborate on developing standardized frameworks for quantifying MDM risk. This includes defining independent and dependent variables for predictive modeling, establishing metrics for impact assessment, and creating a common language akin to CVSS scores for information threats. Such standards would enable more effective risk management and resource allocation.
  1. Train for MDM Recognition and Response: Security teams, particularly those in the SOC, require training to recognize the indicators of MDM, understand its potential for escalation into kinetic events, and differentiate between "white noise" and credible threats. This training should emphasize critical thinking, source verification, and the potential real-world consequences of online narratives.
  1. Protect Personnel from Targeted MDM: Organizations must establish clear policies and support mechanisms for employees who become targets of doxing or other forms of MDM. This includes providing resources for personal security, legal advice, and mental health support, as well as actively monitoring for threats against specific individuals on publicly accessible platforms.
  1. Foster Cross-Functional Collaboration: Effective defense against MDM requires collaboration beyond the security team. Legal counsel, public relations, human resources, and even executive leadership must be involved in understanding, preparing for, and responding to information threats. This holistic approach recognizes that MDM impacts multiple facets of an organization.

By proactively addressing these defensive implications, organizations can begin to build resilience against the growing and increasingly sophisticated threat of misinformation, disinformation, and malinformation, safeguarding their operations, reputation, and, most importantly, their people.

Key Takeaways

  • MDM is a Universal Threat: Misinformation, disinformation, and malinformation are not exclusive to government or political spheres; they pose significant financial, reputational, physical, and cyber risks to all types of organizations.
  • Social Media as a Critical Threat Vector: Traditional and social media platforms have emerged as primary threat vectors and crucial sources of intelligence, often serving as leading indicators for physical and reputational attacks.
  • Urgent Need for Standardization: There is a pressing need for industry standards and frameworks to delineate what constitutes a threat on social and traditional media, and to quantify MDM risk, similar to existing cybersecurity risk models (NIST, FAIR, CVSS).
  • MTTD Challenges without Standards: Without established standards for identifying and measuring MDM threats, reducing the Mean Time To Discovery (MTTD) for media-based incidents becomes exceptionally difficult, hindering timely and effective responses.
  • Responsible Monitoring is Key: Ethical intelligence gathering, limited to publicly accessible platforms and avoiding identity correlation, can provide vital threat intelligence without infringing on privacy or eroding public trust.
  • Focus on Kinetic and Reputational Impacts: While MDM can have cyber implications, it is often a stronger indicator of potential physical violence and significant reputational damage, requiring a broader security perspective.

About the Speaker(s)

Lester Godsey is the CISO (Chief Information Security Officer) for Maricopa County, Arizona. With an extensive career spanning 27 years in IT, a significant portion of which has been dedicated to cybersecurity, Godsey brings deep technical and leadership experience to his role. His current focus on combating misinformation, disinformation, and malinformation (MDM) represents a critical evolution in the CISO's responsibilities, driven by the necessity to protect people and critical infrastructure from real-world threats stemming from online narratives. Maricopa County, being the fourth largest county by population in the United States with approximately 4.6 million residents, provides Godsey with a unique and challenging vantage point from which to address these pervasive information threats.

All talks from Black Hat USA 2024