People are the other half of the surface.
A platform can tell a government what is being said, who is amplifying it and whether it is manufactured. It cannot tell them which of their own people is briefing a journalist, whether the man about to be appointed to a sensitive post has an undeclared interest, or what a protest organiser intends to do on Thursday. That work is human, and it is a different discipline with a different governance frame.
Black Cube Defence holds the mandate and the analytic standard; investigative and field capability is delivered with Maximum Notion, a licensed South African private-investigations practice. One contracting counterparty for the client, one evidence standard across both domains.
Human threat intelligence.
The threat that people pose to a principal, a programme, a facility or an event — assessed the same way the digital picture is assessed: graded sources, tested judgments, stated confidence. Collection answers a protective question that leadership actually asked. It never wanders.
The discipline. HTI supports a protective decision — a route, a venue, a posture, a briefing. If an assessment does not change what somebody does, it should not have been commissioned.
What it covers
- Mobilisation assessment
- Protest and demonstration intent, organiser capability, likely numbers, escalation indicators and the difference between a lawful gathering and a staged confrontation.
- Targeting indicators
- Hostile reconnaissance, pattern-of-life exposure, publicly available detail that narrows a principal's routine, and the specific grievances attaching to a named individual.
- Event & route pictures
- Threat assessment for summits, site visits, launches and campaign appearances — produced to a deadline the protective team can actually use.
- Grievance mapping
- Which communities, unions, suppliers or interest groups hold a live grievance against a programme, what would resolve it, and which are being organised by someone else.
- Escalation warning
- Standing indicators with agreed thresholds, so a shift from rhetoric toward physical-world action produces an alert rather than a retrospective explanation.
Insider threat programme.
Most losses that matter — a leaked cabinet memo, a tender steered before it was advertised, a database walked out the door — involve somebody who was supposed to be there. An insider threat programme is the standing capability that makes those detectable early and addressable lawfully. Black Cube Defence designs it, stands it up, and can run it or hand it over.
Policy & lawful basis
What may be monitored, by whom, on what authority, with what retention — documented before a single indicator is collected, and reviewed with counsel.
Indicator framework
Behavioural and access-based indicators with agreed weights and thresholds. Convergence triggers review; a single signal never does.
Routes people will use
A reporting channel staff actually trust, protected disclosure handling, and a triage process that closes the loop with the person who raised it.
Investigation protocol
Who investigates, what evidence standard applies, when HR, legal or law enforcement enter, and how a matter is closed — including when it is closed as unfounded.
The three ways these programmes fail
Every one of them is a governance failure, not a technical one — which is why the design work carries more weight than the tooling.
It becomes a surveillance function. Scope creeps from access anomalies to reading people's messages. Staff find out. The programme dies and takes trust with it.
It becomes a witch-hunt. Indicators drift toward personality, politics or protected characteristics. The first unfair outcome ends the programme in litigation.
It becomes a filing cabinet. Reports arrive, nothing is triaged, nothing is closed. When the real case comes, the signal is already in the pile, unread.
Convergence board — open reviews
Behavioural and access indicators only · no single signal opens a review · every state change is an audit event
| Ref | Converging indicators | Stage | Standard |
|---|---|---|---|
| ITP-041 | Bulk export outside role scope · after-hours access · unreported external interest | Review · two-person | HR + legal |
| ITP-039 | Repeated access to a tender file after recusal | Escalated | Counsel led |
| ITP-038 | Anomalous printing volume · single signal only | Closed — unfounded | Subject informed |
| ITP-036 | Protected disclosure — procurement irregularity | Triaged · day 2 | Discloser protected |
Excluded from every indicator set: protected characteristics, union membership, political affiliation, lawful off-duty conduct, private communications. Excluded at the feature layer, not by policy alone.
Know who you are appointing, before you appoint them.
Most vetting is a criminal-record check and a phone call to a referee. That catches almost nothing that matters at senior level, where the risk is an undeclared interest, a beneficial ownership two companies away, or a professional history that has been quietly rewritten. Vetting is conducted with the subject's written consent, on a documented lawful basis, and adverse findings are put to the subject for reply before they are reported.
Confirm who they are
- Identity and right-to-work verification
- Qualification verification at source
- Employment history, gaps explained
- Criminal record and civil judgments
- Directorship and disqualification search
- Sanctions, PEP and adverse-media screening
Find what was not declared
- Beneficial ownership tracing through nominees and trusts
- Conflict-of-interest mapping against the appointing body
- Related-party and supplier-connection analysis
- Litigation and regulatory history across jurisdictions
- Professional-reputation enquiry with named referees
- Open-source footprint and exposure assessment
Standing assurance
- Everything in Tier 2, plus structured interview
- Financial-pressure and integrity assessment
- Foreign-connection and influence review
- Periodic reassessment on an agreed cycle
- Aftercare: declared-change reporting obligations
- Supplier and counterparty vetting to the same standard
Right of reply. A vetting report can end a career. Adverse findings are put to the subject before the report is issued, their response is recorded in full, and the report states clearly what was verified, what was inferred and what could not be established. A finding we cannot evidence does not appear.
What open sources suggest, corroborated on the ground.
Open-source analysis reaches a limit that no amount of processing can pass. It can establish that 214 accounts are coordinated; it cannot establish who paid for them. It can show a tender was steered; it cannot get a former employee to explain how. Human collection answers questions that the public record does not contain — and it is governed accordingly.
What it involves
- Source development
- Identifying and engaging people with genuine access to the question at hand, on a consenting basis, with their motivation understood and recorded.
- Structured debriefing
- Trained interviewers working to a collection plan, with accounts tested for internal consistency and against the documentary record.
- Field verification
- Establishing on the ground what cannot be settled online — whether a site exists, whether a company operates from its registered address, whether a delivery was made.
- In-country enquiry
- Lawful enquiry through local practitioners, registries, courts and professional networks in jurisdictions where the record is not online.
- Source grading
- Every source graded on the same Admiralty scale used across the platform, with access, motivation and corroboration stated. An ungradeable source is reported as a claim, never as fact.
The boundaries, stated
These are contractual. They are also the reason a finding survives a courtroom, a commission of enquiry or a journalist's questions — which is the only kind of finding worth paying for.
No impersonation of police, regulators, officials or any person holding legal authority
No entrapment, and no inducement of any person to act unlawfully
No interception of communications, no surveillance devices, no unlawful access to data
No trespass, no unlawful entry, no covert recording where the jurisdiction forbids it
No payment for information a source is under a legal duty not to disclose
No method that would be unlawful in the jurisdiction where it is conducted — local counsel confirms before, not after
No approach to a person we assess as vulnerable, or where the approach itself would place them at risk
Separation from the platform. Human-source product is separately commissioned, separately authorised and held separately. It does not enter the DSM-SOC evidence spine. Where a human-source finding bears on a platform judgment, it enters as a distinctly graded input with its provenance stated on the face of the report — so the platform's traceability guarantee, that any number can be walked back to a public post within the hour, remains true without exception.
One question, two domains.
The specimen scenario shows where the digital picture stops and the human one begins — and why a client is badly served by a vendor who only has one of them.
214 accounts, coordinated and inauthentic
Six converging behavioural indicators. Creation clustering, template replication, temporal synchronisation, a closed follower ring. Attribution tested against four hypotheses and held at MODERATE because the evidence is behavioural. The report says plainly: specific-actor attribution is not possible from public data alone.
Who commissioned it, and how it was paid for
One strongly diagnostic item — an infrastructure payment, a contracted agency, a former employee's account of the brief — changes the leading hypothesis. That item is not on the internet. It is obtained lawfully, graded on the same scale, and reported with its provenance visible, or it is not reported at all.