HLSS523Wk2
30 JUNE 2020 / SECURITY / SecurityMagazine.com
ISIS and al-Qaeda used to reach the younger population and radicalize people,” says Paul Goldenberg, a highly decorated law enforcement and national security professional. Through his work as a member of the U.S. Department of Homeland Security Advisory Council (HSAC), he has played a key role in setting domestic and international policy for the legislation and investigation of hate crimes, insider threat, countering violent extremism and information sharing. Goldenberg is also a Senior Fellow with the Rutgers University Miller Center for Community Protection and Resilience, Distinguished Visiting Fellow for Global Security for the University of Ottawa and former head of Office for Security and Cooperation in Europe (OSCE) transnational policing program. “This radicalization process does not happen overnight. These extremist groups reach the young and disenchanted from around the country and across Europe to carry messages of hate,” Goldenberg notes. How have social media and the Internet provided extremist and radical groups the means to spread their ideologies? And what are the challenges with identifying and countering these groups and what threat assessment tools are available that may aid in detecting radicalized individuals?
A Breeding Ground According to Goldenberg, extremist groups are leveraging social media and the
Internet to radicalize people. “As wonderful and as useful as the Internet is, it has become a ‘breeding ground’ for those who are seeking to further their messages of hatred, bigotry and violence,” he adds. “Many of the recent mass shootings in the U.S. took place in mosques, synagogues and churches. All of the perpetrators involved in these mass shootings clearly shared their manifestos and their inten- tions on websites such as The Daily Stormer, Stormfront and 4chan. Even more concerning, during the actual massacres, they videotaped or livestreamed their actions to further leverage the web to reach a wider audience,” he says. The Internet has and continues to transform many aspects of radicaliza- tion, says Daniil Davydoff, who leads the intelligence service line at AT-RISK International. Davydoff ’s team is charged with conducting open-source intel-
By Maria Henriquez, Associate Editor
The rapid growth of extremist groups provides many challenges for enterprise security.
L ess than 20 minutes before the El Paso, Texas massacre began, the shooter is believed to have posted a racist, anti-immigrant screed to the dark website 4chan, popular within
white supremacy circles. The screed also cited, as inspiration, the March 2019 mass shooting in Christchurch, New Zealand, that killed doz- ens of Muslim residents of that country. Many claim that the incident is a symptom of a much larger problem. “A deeply concerning issue in the U.S. is the rise of white suprema- cist extremism. The white supremacist groups are emulating and using the same tactics that
Leadership & Management
The Rise of Extremism
030-31, 42_Extremist - Feat.indd 30 5/19/20 1:19 PM
31SecurityMagazine.com / SECURITY / JUNE 2020
ligence (OSINT) investigation, analyzing global trends, developing and staffing intelligence programs and delivering on- demand consulting projects pertaining to security and risk issues. “The Internet is an easy-to-access source of information for anyone interest- ed in extremist ideas,” he says, “and a place in which communication and collabora- tion between radicalized individuals from around the world – both likeminded and not – can take place without much effort.” Davydoff adds that in conducting research on “incel” message boards about a year ago, he saw a very friendly conversation between a person who believed in extreme right-wing ideas and a supporter of radical Islamic tenets. “This kind of odd-pairing and exchange is less and less unusual.”
Challenges with Extremism Many of the trends associated with virtualization of extremist ideologies create difficulties for security professionals, claims Davydoff. “Identifying ideologies and their tactics has become tougher because they are now fluid,” he says. “Ecofascism, for instance, is a hodgepodge of ideas that were not actively paid attention to until after the 2019 Christchurch mosque shooting in New Zealand. The rapid growth in extremist online material generally makes detection difficult.” Identifying individuals and tracking conversations has also become challenging as supporters of extremism are increas- ingly careful with their online privacy and many use systems of code and lingo that require serious study to spot, he says. “The mainstream social media platforms have tried to keep up by booting extremist indi- viduals and groups off their systems, but it is an uphill battle. What is more, there is now an universe of alternative online and messaging platforms as well as the dark web, which are utilized for conversing and crowdfunding. In many cases, dialogue in these virtual meeting spaces is restricted to members and is hard to access for security professionals,” he adds. These challenges become particu- larly acute when it comes to counter- ing planned attacks, he says. “Extremists now tend to borrow tactics from each other, meaning that attack types are harder to predict and can range from the low- tech (vehicle ramming) to the high-tech (cyberattacks). There may also be less of a warning than before. Some recent attacks were preceded by an online announcement minutes before they occurred,” he adds.
Goldenberg says the “If You See Something, Say Something®” campaign needs to be much better conveyed and embedded within the American workforce and those in the security industry, particu- larly individuals who are responsible for large security enterprises. “There needs to be infrastructure in place to train and teach people to immediately report or share concerns or information with others when they feel that their co-workers are becoming radicalized.”
“Enterprise security has the opportunity to now train their workforces, constituents and employees with tabletop scenarios,” he says. “What we need to do is very much like a virus – immunize our population against viral hatred and provide them with the tools and resources to empower them- selves to understand how they can prevent violent acts.”
Risk Assessment According to Davydoff, there are count- less academic and government studies that have identified radicalization or extrem- ist risk factors among individuals. These range from the political, to the socio-eco- nomic, to the psychologic. “Study of such research is important for understanding past patterns, but there is no predictive profile,” he notes. “The mix of factors that leads an individual down the path
from holding extremist beliefs to commit- ting violence is highly individualized, so security professionals should evaluate on a case-by-case basis. This is where threat assessment can be helpful because it looks in a holistic way at clusters of behaviors, as well as the external environment and context shaping them.” There are, however, many criteria that professionals can consider when assessing a threat. These include, among others, “a previous history of violence, substance abuse issues, mental health or disorder concerns, and the nature of the griev- ances and the threats made. There are also observable behaviors that may indicate an individual is getting closer to committing violence,” Davydoff adds. “Such behaviors might be making concrete plans to attack, committing smaller violations in prepara- tion for a more significant act, as well as communicating that violence has become the only option,” he says. It’s important that none of these criteria should be looked at in isolation, he warns. “The best way to learn how they interact is probably to join the Association of Threat Assessment Professionals (ATAP) – an organization devoted to sharing best practices on making threat determina- tions. The professionals in that group are experts in deciding whether the threat is just “posed” or real.” Some other resources available to secu- rity professionals that may aid in assessing risk or early detection of radicalization include social media intelligence man- agement platforms, such as Echosec, LifeRaft Navigator and ONTIC, he says. “Intelligence teams can wade through online threats on their own, but these tools make consistent long-term monitoring much easier, especially for enterprises that extremists or others may seek to target.” On the assessment side, he says, there are tools such as the Terrorist Radicalization Assessment Protocol (TRAP-18), a guide that can help enterprise security evalu- ate the threat posed by lone wolf actors. “There are also many other assessment protocols for workplace violence and vio- lence risk generally, such as the HCR-20 and WAVR-21,” Davydoff says. Although, he warns, both intelligence and risk assess- ment tools should be used by trained pro- fessionals, as both the language of threats and individual violence risk factors are very easy to misinterpret. Goldenberg argues that security profes- sionals need to be empowered and better
Paul Goldenberg
Daniil Davydoff
continues on page 42
030-31, 42_Extremist - Feat.indd 31 5/19/20 1:19 PM
Education & Training
42 JUNE 2020 / SECURITY / SecurityMagazine.com
and, similar to the Illinois BIPA, a right of action for consumers to sue for money damages.
Proactive Strategies to Mitigate Data Privacy Concerns
For the above reasons, companies involved in the creation of innovative products or services that use biometrics data, including AI-based inventions, will want to adhere to existing and developing data privacy laws and regulations for those states or jurisdictions where the company’s targeted customers are expected to reside. As exemplified here, such data privacy laws can include pitfalls for the unwary, resulting in money damages.
It is expected that the regulatory land- scape governing biometrics data will con- tinue to grow. Given this, companies, even those outside of states or jurisdictions with data privacy laws, should be cautious when developing new products or services that use biometrics data.
While data privacy laws may differ
across territories, many of them share common regulatory themes. These include consumer-facing requirements, such as acquiring informed consent from an user before collecting biometric data, inform- ing the user of the specific purpose or use of his or her biometrics data, and providing the user with a means to request destruction of his or her biometrics data (the right to be forgotten). Other require- ments involve protecting personal data once received, which include securing the biometric data and setting up procedures for notifying authorities if a data breach occurs.
In view of these regulatory themes, a company utilizing biometric data could position itself for data privacy issues that may arise by developing written policies addressing how the company will collect, use, distribute and destroy biometric data; setting up systems to record informed consent received from employees and cus- tomers regarding the use of their bio- metric data; securing and encrypting
biometric data; storing only the biometric data that is needed (e.g., less than 100 percent captured); limiting the access of biometric data to only those systems or individuals (need to know); reviewing and updating any consumer facing contracts to address biometric data; and/or reviewing any general commercial liability insurance and whether it provides adequate coverage for data privacy risks.
Companies developing innovative products and services that use biometrics data will also want to work with legal counsel knowledgeable about both IP and data privacy laws and regulations in order both to protect their innovations and to stay abreast of the growing data privacy landscape.
About the Author Ryan N. Phelan is a registered patent attorney at Marshall, Gerstein & Borun, LLP, located in Chicago, who counsels and works with clients on intellectual property matters, with a focus on patents. Phelan
039-42_Edu & Training - 0620 - Col.indd 42 5/20/20 7:36 AM
Reproduced with permission of copyright owner. Further reproduction prohibited without permission.