Black Cube Defence (Pty) Ltd · Reg. 2017/254145/07 · South Africa DSM-SOC · Digital Social Media Security Operations Centre
Black Cube Defence (Pty) Ltd · Sovereign Capability

Intelligence,
not monitoring.

Anyone can count mentions. Black Cube Defence builds and operates the DSM-SOC — a Digital Social Media Security Operations Centre that watches the public information environment around a head of state, a ministry or a national programme 24×7, turns raw noise into graded, decision-ready intelligence, counters manufactured narratives with lawful measured response, and — once the evidence justifies it — anticipates the next surge before it breaks. Where the public record runs out, a separate human-domain practice takes the question further — lawfully, and with the boundaries stated.

Public sources only Region-resident data Human-authorised output Audit-complete
SEE · RESPOND · ANTICIPATE ONE SPINE · THREE PHASES · NO REBUILDS
01

Evidence, not assertion.

Every judgment carries its confidence, its sources and its audit trail. Probability words are bound to numeric ranges. Attribution is tested against rival hypotheses, never declared. Any claim the client repeats in public can be traced to its evidence within the hour.

02

Lawful by construction.

Public sources only — asserted in the collection code and tested in continuous integration, not promised in a policy document. No fake accounts, no covert messaging, no private-life monitoring. A response that would be indefensible if it came to light is a liability, not a capability.

03

Anticipation, earned.

The platform is specified from your own casework — which is why it is aimed at your real threats and not a brochure's. Nothing is bought on faith: each phase opens only when the record of the last one justifies it.

The problem

A manufactured storm is not
an opinion problem.

An unverified allegation is seeded by an anonymous account. It lies dormant for twenty-six hours. Then two hundred and fourteen purpose-built accounts — created months earlier, dormant until first use — launch it in a synchronised wave. Within an hour it is running at 9,412 mentions per hour, mainstream outlets are covering the accusation rather than the facts, and the office of the principal is reading about it on social media.

By the time a communications team convenes, the framing is set. The question a government actually faces is not how many people are talking. It is: is this real, who built it, is it lawful to say so, and what is the defensible thing to do in the next hour?

DSM-SOC exists to answer that. It separates what is observed from what is assessed, grades every source, tests attribution against competing hypotheses, and hands the principal a decision — with its confidence, its evidence and its audit trail attached.

Screen 01 · Phase 1 · The watch floor

The week in one look.

The executive dashboard as leadership meets it: eight tiles, the narratives that matter with a one-line analyst read, and the decisions requested — each with a recommended answer and a date. Every tile drills to its evidence.

Confidential — client use only Specimen — fictitious data DSM-SOC · 24×7
Black Cube Defence · DSM-SOC · Executive Dashboard

The week in one look

Live snapshot of the monitoring picture · companion to Weekly Intelligence Report WIR-2026-031 · every figure human-validated against 13 analytic standards · 1,412 items validated this week · false-positive rate 3.2%

Live · 60s Week 27 Jul – 02 Aug 08:00 SAST
Composite risk indexElevated
68/100
▲ +9 w/w · crossed ELEVATED threshold (65) on 30 Jul
Total public mentions
247.9k
▲ +18.6% w/w · spike-driven 30–31 Jul
Potential reach
41.2M
▲ +12.4% w/w · amplification-inflated
Engagements
3.9M
▲ +22.1% w/w · concentrated on 2 narratives
Unique authors
96.4k
▲ +9.8% w/w · incl. 2,214 inauthentic
Positive share
29.7%
▼ −2.9 pts · crowding-out effect
Negative share
28.4%
▲ +6.1 pts · 63% from N-04 / N-06
Alerts issued1 open crit
3
1 CRITICAL · 2 ELEVATED · all inside SLA
Top narratives by share of voice
Colour = net sentiment · movement vs last week · analyst one-line read on each
N-04 · Water-tanker tender allegations26% ▲+310%
Unverified claim, amplified; respond to procurement facts, not the hashtag
N-01 · Khanyisa rollout delays (E. Cape)19% ▲+22%
Organic and specific — fixable with ward-level delivery dates
N-06 · #MokoenaMustAccount17% ▲new
65% inauthentic at peak; cluster dormant since 01 Aug — tripwired
N-02 · Limpopo electrification milestone13% ▲peaked
Best-performing positive this quarter — reuse the proof-point
N-03 · Sizanani Youth Works placements9% — stable
Reliable positive baseline; beneficiary voices carry it
Decisions requested from leadership
Each with a recommended answer and a date — never buried in analysis
!
Authorise platform escalation of cluster CL-2026-019
Evidence pack BC-EV-2026-019 ready · takedown lead time 5–10 working days  Yes — by 05 Aug
!
Approve tender-process explainer for publication
Plain-language procurement facts page + spokesperson bridge lines  Yes — by 05 Aug
Confirm executive briefing attendance — monthly report
06 Aug, 10:00 SAST · MER-2026-007 walk-through  By 05 Aug
Open alert — ALR-2026-0142 (CRITICAL)
Daily situational updates · day 4
Watch — #KhanyisaSA hijack
Hostile share vs 30% trigger — currently 18%
BC-DSM-EDB-2026-031 · printable snapshot issues Mondays 08:00 with the weekly report Every tile drills to its evidence · every judgment carries its source grade

What leadership actually receives. The composite risk index crossing its ELEVATED threshold is the story of the week — and the two narratives driving it are separated into one that is organic and remediable, and one that is 65% manufactured. Specimen figures throughout; the scenario is a fictitious ministry used to demonstrate format and standard.

The commercial architecture

Three deliberate steps — each proven by the last.

No phase is bought on faith. Each is smaller than the one before, and each opens only when the evidence from the previous phase justifies it. By the time the platform is commissioned, its specification has been written by the client's own results.

Phase 1 · See Running

Visibility and graded intelligence

The watch floor. Sentiment split into real and manufactured, every storyline registered and graded, coordinated activity proven behaviourally, attribution tested rather than asserted.

  • 4 recurring products + 24×7 alerting
  • Narrative register with escalation tripwires
  • CIB cluster proof — behaviour, not allegation
  • ACH attribution board
  • Delivered by analysts and tools

Commitment — current retainer

Phase 2 · Respond Month 3 gate

Lawful, measured counter-narrative

Intelligence turned into action inside agreed rules of engagement. Claims graded against evidence within four hours; verified facts published faster than falsehood spreads; inauthentic networks removed through the platforms' own rules.

  • Response cell board · playbooks per narrative
  • Verification workspace — 4-hour turnaround
  • Takedown & enforcement tracked to conclusion
  • Effectiveness measured with honest attribution
  • Executive digital protection & hardening

Commitment — modest retainer uplift · no capex

Phase 3 · Anticipate Month 12+ gate

Foresight, detection and command

The platform. Narrative forecasting trained on the client's own observed lifecycles, cross-platform influence-network mapping calibrated on documented casework, deepfake detection tuned to the principal's consented voiceprint, and an election command mode for the highest-tempo fortnight.

  • Executive threat command centre
  • Predictive narrative analytics · 5-week horizon
  • Synthetic media detection · caught in 40 minutes
  • Automated executive risk scoring
  • AI oversight console — nothing unreviewed

Commitment — evidence-justified build

The standing rule. The platform never forks per phase. Capabilities land behind client-configuration flags on the one append-only spine — reversible and auditable — so the same machine that watches this week's storm is, unchanged underneath, the platform that forecasts the next one.

Measured, not asserted

What a response is worth, in numbers the client can check.

Every campaign is measured before and after against a modelled unassisted-decay baseline, with conservative attribution. Specimen results from the demonstration scenario — the format is what matters.

26→7%
Hostile narrative share of voice, across a 14-day response
−47 pts
Allegation-led media framing, 71% down to 24% in one news cycle
74%
Of a 214-account inauthentic cluster removed through platform rules
11 min
Analyst confirmation to client notification on a CRITICAL event · SLA ≤15
40 min
Fabricated audio of the principal detected, at three accounts and ~1,200 plays
3.2%
False-positive rate on machine classification, published monthly · SLA ≤5%
100%
Of high-impact items human-validated before they reach a report
99.92%
Monitoring availability, held to a published service level with credits
Specimen notice. All names, organisations, accounts, narratives, events and statistics shown across this site continue a fictitious demonstration scenario. They illustrate format and analytic standard only. Real engagements produce the same structures against the client's own environment.
The restraint is the product

A response that would be indefensible if it came to light is a liability, not a capability.

This is not a values statement. It is contractual, asserted in the collection code, and tested in continuous integration — a regressed permission fails the build.

Read the full framework

Never done, by design

No fake accounts, sock puppets or manufactured personas — ever

No covert messaging or amplification disguised as organic

No private accounts, private messages or authenticated content

No device surveillance, interception or private-life monitoring of any person

No candidate polling — issue-mood only, and the boundary is contractual

No protected attributes in any model — race, religion, health, orientation excluded at the feature layer and verified at every model change

No machine output reaching the client without a named human decision

Why it matters commercially. Phase 2 counters manipulation the way a credible institution should — anything else would make the response indistinguishable from the operation it exists to expose.

The second domain

A platform cannot tell you which of your own people is briefing the journalist.

Open-source analysis reaches a limit no amount of processing can pass. It can establish that 214 accounts are coordinated; it cannot establish who paid for them. It can show a tender was steered; it cannot get a former employee to explain how.

Black Cube Defence's human-domain line answers the questions the public record does not contain — with investigative and field capability delivered alongside Maximum Notion, a licensed South African private-investigations practice, and the boundaries stated on the page rather than discovered later.

The human domain
HTI

Human threat intelligence

Mobilisation and protest assessment, targeting indicators, event and route threat pictures, grievance mapping — produced to support a protective decision.

ITP

Insider threat programme

Designed, stood up and governed: lawful basis, indicator framework, reporting routes people will use, and an investigation protocol that can close a matter as unfounded.

Vetting

Advanced vetting

Three tiers from baseline verification to standing assurance on sensitive posts. Consent-based, with adverse findings put to the subject before they are reported.

HUMINT

Human-source collection

Lawful source development, structured debriefing, field verification and in-country enquiry — graded on the same Admiralty scale, held separately from the platform spine.

Commissioning

Phase 1 can be running inside thirty days.

A capability briefing walks the running watch floor, the response doctrine and the evidence standard — then leaves the decision where it belongs: with the record of what the service actually produced.