Intelligence,
not monitoring.
Anyone can count mentions. Black Cube Defence builds and operates the DSM-SOC — a Digital Social Media Security Operations Centre that watches the public information environment around a head of state, a ministry or a national programme 24×7, turns raw noise into graded, decision-ready intelligence, counters manufactured narratives with lawful measured response, and — once the evidence justifies it — anticipates the next surge before it breaks. Where the public record runs out, a separate human-domain practice takes the question further — lawfully, and with the boundaries stated.
Evidence, not assertion.
Every judgment carries its confidence, its sources and its audit trail. Probability words are bound to numeric ranges. Attribution is tested against rival hypotheses, never declared. Any claim the client repeats in public can be traced to its evidence within the hour.
Lawful by construction.
Public sources only — asserted in the collection code and tested in continuous integration, not promised in a policy document. No fake accounts, no covert messaging, no private-life monitoring. A response that would be indefensible if it came to light is a liability, not a capability.
Anticipation, earned.
The platform is specified from your own casework — which is why it is aimed at your real threats and not a brochure's. Nothing is bought on faith: each phase opens only when the record of the last one justifies it.
A manufactured storm is not
an opinion problem.
An unverified allegation is seeded by an anonymous account. It lies dormant for twenty-six hours. Then two hundred and fourteen purpose-built accounts — created months earlier, dormant until first use — launch it in a synchronised wave. Within an hour it is running at 9,412 mentions per hour, mainstream outlets are covering the accusation rather than the facts, and the office of the principal is reading about it on social media.
By the time a communications team convenes, the framing is set. The question a government actually faces is not how many people are talking. It is: is this real, who built it, is it lawful to say so, and what is the defensible thing to do in the next hour?
DSM-SOC exists to answer that. It separates what is observed from what is assessed, grades every source, tests attribution against competing hypotheses, and hands the principal a decision — with its confidence, its evidence and its audit trail attached.
The week in one look.
The executive dashboard as leadership meets it: eight tiles, the narratives that matter with a one-line analyst read, and the decisions requested — each with a recommended answer and a date. Every tile drills to its evidence.
The week in one look
Live snapshot of the monitoring picture · companion to Weekly Intelligence Report WIR-2026-031 · every figure human-validated against 13 analytic standards · 1,412 items validated this week · false-positive rate 3.2%
What leadership actually receives. The composite risk index crossing its ELEVATED threshold is the story of the week — and the two narratives driving it are separated into one that is organic and remediable, and one that is 65% manufactured. Specimen figures throughout; the scenario is a fictitious ministry used to demonstrate format and standard.
Three deliberate steps — each proven by the last.
No phase is bought on faith. Each is smaller than the one before, and each opens only when the evidence from the previous phase justifies it. By the time the platform is commissioned, its specification has been written by the client's own results.
Visibility and graded intelligence
The watch floor. Sentiment split into real and manufactured, every storyline registered and graded, coordinated activity proven behaviourally, attribution tested rather than asserted.
- 4 recurring products + 24×7 alerting
- Narrative register with escalation tripwires
- CIB cluster proof — behaviour, not allegation
- ACH attribution board
- Delivered by analysts and tools
Commitment — current retainer
Lawful, measured counter-narrative
Intelligence turned into action inside agreed rules of engagement. Claims graded against evidence within four hours; verified facts published faster than falsehood spreads; inauthentic networks removed through the platforms' own rules.
- Response cell board · playbooks per narrative
- Verification workspace — 4-hour turnaround
- Takedown & enforcement tracked to conclusion
- Effectiveness measured with honest attribution
- Executive digital protection & hardening
Commitment — modest retainer uplift · no capex
Foresight, detection and command
The platform. Narrative forecasting trained on the client's own observed lifecycles, cross-platform influence-network mapping calibrated on documented casework, deepfake detection tuned to the principal's consented voiceprint, and an election command mode for the highest-tempo fortnight.
- Executive threat command centre
- Predictive narrative analytics · 5-week horizon
- Synthetic media detection · caught in 40 minutes
- Automated executive risk scoring
- AI oversight console — nothing unreviewed
Commitment — evidence-justified build
The standing rule. The platform never forks per phase. Capabilities land behind client-configuration flags on the one append-only spine — reversible and auditable — so the same machine that watches this week's storm is, unchanged underneath, the platform that forecasts the next one.
What a response is worth, in numbers the client can check.
Every campaign is measured before and after against a modelled unassisted-decay baseline, with conservative attribution. Specimen results from the demonstration scenario — the format is what matters.
A response that would be indefensible if it came to light is a liability, not a capability.
This is not a values statement. It is contractual, asserted in the collection code, and tested in continuous integration — a regressed permission fails the build.
Read the full framework →Never done, by design
No fake accounts, sock puppets or manufactured personas — ever
No covert messaging or amplification disguised as organic
No private accounts, private messages or authenticated content
No device surveillance, interception or private-life monitoring of any person
No candidate polling — issue-mood only, and the boundary is contractual
No protected attributes in any model — race, religion, health, orientation excluded at the feature layer and verified at every model change
No machine output reaching the client without a named human decision
Why it matters commercially. Phase 2 counters manipulation the way a credible institution should — anything else would make the response indistinguishable from the operation it exists to expose.
Every surface of the service, shown — not described.
The watch floor, the response cell, the intelligence platform, the back office that makes it defensible, and the build views the engineering team works from. Real fields, real rules, real states — fictitious data.
The Watch Floor
Sentiment split real vs manufactured, the narrative register, the cluster proof, the diffusion map, structured attribution and the CRITICAL alert.
The Response Cell
The response command picture, one narrative's playbook, claims graded in four hours, takedowns tracked to conclusion, effectiveness measured.
The Intelligence Platform
One command screen, narrative surges forecast five weeks out, a deepfake caught in forty minutes, the hidden network reconstructed and graded.
Back Office & Build
PIR-driven collection, the validation queue, the QA release chain, the graded source register, the evidence vault — and the architecture behind it.
A platform cannot tell you which of your own people is briefing the journalist.
Open-source analysis reaches a limit no amount of processing can pass. It can establish that 214 accounts are coordinated; it cannot establish who paid for them. It can show a tender was steered; it cannot get a former employee to explain how.
Black Cube Defence's human-domain line answers the questions the public record does not contain — with investigative and field capability delivered alongside Maximum Notion, a licensed South African private-investigations practice, and the boundaries stated on the page rather than discovered later.
The human domain →Human threat intelligence
Mobilisation and protest assessment, targeting indicators, event and route threat pictures, grievance mapping — produced to support a protective decision.
Insider threat programme
Designed, stood up and governed: lawful basis, indicator framework, reporting routes people will use, and an investigation protocol that can close a matter as unfounded.
Advanced vetting
Three tiers from baseline verification to standing assurance on sensitive posts. Consent-based, with adverse findings put to the subject before they are reported.
Human-source collection
Lawful source development, structured debriefing, field verification and in-country enquiry — graded on the same Admiralty scale, held separately from the platform spine.
The surfaces we do not hold ourselves.
The information environment is one surface of national exposure. Black Cube Defence delivers alongside partners who hold the others: the human domain, the technical perimeter, and the infrastructure the data itself runs on.
Licensed private investigations. The field and investigative capability behind human threat intelligence, insider threat programmes, advanced vetting and lawful human-source collection.
maximumnotion.co.za →Exposure and vulnerability management — attack surface management, penetration testing as a service, threat intelligence, credential-breach monitoring and identity security.
outpost24.co.za →Infrastructure and AI security — confidential computing, confidential AI, sovereign data residency and production AI implementation. The data in use, protected.
canarybit.co.za →Phase 1 can be running inside thirty days.
A capability briefing walks the running watch floor, the response doctrine and the evidence standard — then leaves the decision where it belongs: with the record of what the service actually produced.