Erik Wittreich is Chief Executive Officer of Veilant.gettyFor decades, digital privacy has focused on keeping attackers out. Firewalls, endpoint protection and zero-trust architecture have evolved to prevent unauthorized access to company systems and data.While those systems remain essential, organizations today face a growing challenge not addressed by cybersecurity: Data no longer needs to be stolen for competitors to access and leverage it.Every connected device, cloud service, AI platform, collaboration tool and third-party integration increases the number of places where sensitive information can be observed, collected or reconstructed.On top of the risks created by company-run systems and devices, individuals are increasingly monitored. Data from your employees’ phones, vehicles, apps, smartwatches, smart-home devices, financial records, travel patterns, fitness data, social media, professional profiles, public records and commercial data can all be collected, aggregated, purchased, analyzed and exploited. In today’s adtech economy, data brokers can sell this information directly to nearly anyone, including potentially your competitors.This is the reality of ubiquitous technical surveillance (UTS): the persistent collection and exploitation of data generated by people, devices, platforms, infrastructure and commercial systems. It is the background condition of modern life, and companies must adjust their approach to security to address this growing reality. Companies still need to answer, “Can someone break into our systems?” But they also need to know: “What can others learn about us without ever breaching our network?”Based on my experience helping companies protect their digital footprint, here are four key steps organizations should take before developing a UTS strategy:1. Establish what information is critical to your business.The data organizations must protect extends far beyond personally identifiable information or financial records. Intellectual property, operational processes, executive discussions, customer activity and other forms of institutional knowledge that create competitive advantage are all at risk of being collected, analyzed and leveraged by competitors.Determining early on what information you’d like to protect is the core of establishing a strategy that supports your goals. Organizations cannot protect everything equally, so they must identify the people, assets and activities that matter most to their mission and business objectives. In short, define what exposure would create the greatest harm, then build controls around those risks.2. Assume adversaries are collecting more than they need.In today’s digital threat landscape, adversaries collect everything, not just what seems obvious.The location of a CEO’s phone can reveal a private meeting with a confidential client. A conversation with an employee wearing smart glasses can be recorded and leveraged. The search history on an employee’s work-issued computer or personal device can reveal insights into business strategy.On their own, these pieces of information may appear insignificant, but collectively, they reveal remarkably detailed pictures of organizational priorities. With AI accelerating analysis capabilities, signals that would have been meaningless five years ago can now reveal strategic insights when pieced together.Organizations must operate under the assumption that information being generated today may become useful to an adversary later. Think beyond immediate threats and consider how routine data trails can be exploited over time.3. Audit what’s already being collected.Before organizations can reduce exposure, they need to understand where exposure already exists.This requires looking beyond internal systems. A meaningful UTS audit should evaluate company devices, employee devices, collaboration platforms, vendor tools, connected vehicles, public records, social media, professional directories and other sources that may reveal information about the organization or its people.A thorough audit should also include third-party vendors and partners. Many organizations have strong internal security practices, but limited visibility into what their vendors collect, retain, share or expose. Every tool that touches company data, employee behavior, customer activity or operational workflows should be evaluated through the lens of visibility.4. Determine what you want visible.Not all visibility is bad. Companies need to communicate with customers, recruit employees, build partnerships and maintain public credibility. The goal of a UTS strategy is simply to control what is visible and to whom.Organizations should deliberately decide what they want the market, competitors, vendors, customers, employees and potential adversaries to see. This may include public messaging, executive visibility, employee profiles, office activity and relationships with clients or vendors.A strong UTS strategy helps organizations separate intentional visibility from accidental exposure. It allows leaders to continue operating, communicating and growing while reducing unnecessary risk.Looking AheadUbiquitous technical surveillance is the operating environment for every modern organization. The companies that succeed will be those that recognize visibility as something to manage. In an era where every digital interaction creates a signal, competitive advantage will increasingly belong to organizations that control not only their data, but what others can learn from it.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
How Businesses Can Prepare For Ubiquitous Technical Surveillance
Companies need to answer, “What can others learn about us without ever breaching our network?”








