OPSEC — Operations Security
OPSEC — what it is, where it comes from, and how private organisations apply it to protect sensitive operations and information.
OPSEC — Operations Security — is a systematic process for identifying, controlling, and protecting information that could be used by adversaries to harm an organisation's operations, personnel, or assets. Originally a military discipline, OPSEC is now applied across governmental, corporate, and private security contexts.
Definition and origin
OPSEC was formalised by the US military during the Vietnam War as a process to prevent adversaries from collecting and exploiting information about planned operations. The core insight — that individually non-sensitive pieces of information can, when aggregated, reveal sensitive operational details — remains the discipline's foundation. OPSEC has since been adopted across NATO, governmental agencies, and the private sector.
The classic OPSEC case study is Operation Purple Dragon — the Vietnam-era US military investigation that found North Vietnamese forces were anticipating US operations with improbable accuracy. The investigation revealed that individually unclassified information about equipment movements, personnel schedules, and supply deliveries was being aggregated by adversary intelligence to predict operational plans. None of the individual data points were classified; in combination they were decisive. The aggregation problem remains the central insight of OPSEC.
The five-step OPSEC process
- 1. Identify critical information — what information, if obtained by an adversary, would damage operations, personnel, or competitive position?
- 2. Analyse threats — who are the potential adversaries, what is their capability and intent, and what are they trying to collect?
- 3. Analyse vulnerabilities — where are the gaps between the critical information and the protection currently in place?
- 4. Assess risk — which vulnerabilities, if exploited, would cause the most significant harm?
- 5. Apply countermeasures — what controls, procedures, or technical measures reduce the identified vulnerabilities to acceptable levels?
OPSEC in the private sector
For private organisations, OPSEC discipline typically addresses: control of information in public communications (job postings, LinkedIn profiles, conference presentations, social media); meeting and communication security (who attends, what is discussed where, what channels are used); supply chain and vendor information sharing; and M&A or legal process information control, where strategic information is necessarily shared with external parties.
Common OPSEC failures
- Oversharing in job postings — revealing technology stack, security architecture, or operational procedures
- Social media disclosure by employees — publishing location data, meeting participants, or internal information
- Predictable patterns — fixed routes, schedules, and meeting locations that allow adversaries to plan and position
- Inadequate need-to-know controls — sharing sensitive information beyond the minimum required audience
- Insecure communications channels — discussing sensitive matters on platforms not appropriate for the classification of the information
Social media OPSEC — the aggregation problem
Social media represents the most widespread and systematically underestimated OPSEC vulnerability in corporate environments. Individual posts are typically harmless in isolation; the pattern they collectively reveal is the problem.
Gym check-ins establish morning routine — a regular 06:30 check-in at a specific facility defines a predictable daily departure time and location. Conference speaking engagements confirm presence at a specific city on specific dates, with a speaking topic that reveals strategic priorities. Team photographs published on LinkedIn reveal staffing levels, reporting structures, and the identities of individuals who might not otherwise be publicly associated with sensitive programmes. Conference networking photographs expose strategic relationships and partnership discussions before they are announced. Job postings reveal technology stack, planned capability expansions, and security architecture gaps (a posting for a "zero-trust network architect" signals that existing architecture is not zero-trust).
The documented case of how social media enabled targeting intelligence collection against diplomatic and military personnel is now extensive. The lesson for corporate environments is identical: the aggregation of individually innocuous posts creates a surveillance package that an intelligence professional — or a well-resourced private investigator — can exploit systematically.
Counter-measures at the individual level include: review of all public-facing profiles for pattern-revealing content; prohibition on posting from sensitive facilities even without facility identification; prohibition on photographing or naming meeting participants; and specific training on what categories of information create aggregation risk.
M&A and transaction OPSEC
The due diligence process for mergers, acquisitions, and major transactions creates a structured intelligence collection window. Dozens of advisers — investment banks, law firms, accountancies, technology consultants — receive access to sensitive financial, operational, and strategic information. Each of these firms has broad commercial relationships that create potential information leak surfaces.
Information room access logging is a basic control: who accessed which documents, when, and how many times. Anomalous access patterns — repeated access to specific documents, access at unusual hours, bulk download attempts — can indicate intelligence gathering rather than legitimate due diligence.
The adviser network itself is a known leak surface in high-profile transactions. Investment banking teams working on competing mandates, legal teams with relationships across the counterparty landscape, and accountancy firms with broad corporate advisory relationships all create potential for inadvertent or deliberate disclosure. Compartmentalisation of information — ensuring that each adviser sees only what they need for their specific role — is the primary control.
Employee behaviour changes during a transaction — unusual meeting patterns, travel to unannounced locations, changes in communication security posture — can signal transaction activity to an observant adversary before any public announcement. This is an OPSEC vulnerability specific to transactions and should be managed through explicit communication controls and need-to-know restriction on transaction knowledge within the organisation.
Regulatory filing triggers are an unavoidable public signal in some jurisdictions — competition notification filings, major shareholding disclosures, and similar mandatory disclosures reveal transaction activity that would otherwise be private. These filings should be made as late as legally permissible, and their content should be the minimum required by the regulatory obligation.
Legal proceedings OPSEC
Commercial litigation, arbitration, and regulatory proceedings create a structured channel through which an adversary can compel disclosure of sensitive information. Understanding and managing this channel is an OPSEC function, not just a legal one.
Litigation strategy is a high-value intelligence target. An adversary who knows the legal theory your counsel is pursuing, the witnesses you intend to call, and the documents you consider most important can prepare responses, identify counter-arguments, and — in commercial contexts — adjust their commercial behaviour to undermine your position before trial.
Expert witness preparation involves disclosing information to an expert that the other side will have the right to explore in cross-examination. The scope of that disclosure should be carefully managed so that only information necessary for the expert's opinion is shared. Expert reports, once served, become a permanent record of the information your team considered important.
Court filings are public records in most jurisdictions. Even heavily redacted filings reveal the structure of a dispute, the identities of key witnesses, the categories of documents in dispute, and the legal framework being argued. Adversaries with no direct involvement in the proceedings can read these filings and extract intelligence. The OPSEC implication is that court filings should contain the minimum information required by the procedural rules — no more.
Mediation and arbitration venue selection has an OPSEC dimension. Shared facilities with other parties to sensitive commercial relationships, venues with known surveillance vulnerabilities, and locations in jurisdictions with compelled disclosure obligations can all create information exposure risks that private mediation venues or arbitration centres in neutral jurisdictions do not.
Travel OPSEC
Business travel creates a set of OPSEC vulnerabilities that the fixed-location office environment does not. The conference circuit is the most predictable: the same senior executives appear at the same events year after year, in the same cities, staying in the same hotels, attending the same dinner circuits. This predictability makes them easy to locate, approach, and surveil — without any technical collection.
Business travel booking patterns are visible to airline staff, hotel staff, executive lounge attendants, transport providers, and travel management company personnel — a wide surface of individuals with knowledge of a traveller's itinerary before departure. The OPSEC control is to treat the travel itinerary as sensitive information, with distribution on a need-to-know basis and booking arrangements handled by the minimum number of people.
Loyalty programme data aggregates travel patterns over time. An adversary with access to loyalty programme records — whether through breach, insider, or legal compulsion — can reconstruct years of travel history including dates, cities, hotels, and airlines. This is particularly relevant for individuals who have been the subject of intelligence collection operations: their historical travel patterns can be reconstructed even after they have adopted stricter OPSEC.
Conference name badge visibility creates a public identification surface at events that may not be intended to be public. Photographed badges, tagged social media posts from other attendees, and published attendee lists all aggregate into a presence confirmation. The OPSEC control is to be deliberate about which events are attended under the organisation's name versus under a less identifying representation.
Business lounge conversations are conducted in facilities designed to create a sense of privacy while being surrounded by other business travellers. Sensitive calls and sensitive conversations should not be held in business lounges, aircraft cabins, or hotel lobbies. These environments are not private — they are merely comfortable.
Physical OPSEC
Physical environment OPSEC addresses the information that can be collected from an organisation's physical spaces without any technical surveillance capability.
Clean desk policy: documents left on desks overnight, in meeting rooms after meetings, or in printer trays create an immediate collection opportunity for cleaning staff, visitors, and maintenance contractors. Enforcement is the challenge — documented policy without consequences does not change behaviour. Regular physical audit of sensitive areas, combined with consequences for violations, is required for the policy to have effect.
Document disposal: cross-cut (confetti-cut) shredding is the minimum standard for sensitive documents — strip shredders can be reassembled by a patient adversary. Bulk document disposal events — annual clear-outs, office moves — are a particularly high-risk period. Documents accumulate over time; disposal events process them in volume, typically by a third-party contractor with limited vetting. Sensitive document disposal should use on-site shredding with verified destruction certificates, not off-site collection with assumed destruction.
Whiteboard hygiene is systematically neglected. Whiteboards in meeting rooms facing windows can be photographed with a telephoto lens from outside the building. Whiteboards in rooms accessible to cleaning staff are typically cleaned overnight — but cleaning staff enter the space and have direct access to any content that has not been erased. The OPSEC control is simple: erase whiteboards after every meeting that addresses sensitive topics. Photography of whiteboards before erasure, rather than note-taking, is a good practice — but photographs are then sensitive documents that require handling discipline.
Visitor control in sensitive areas: visitor management systems that log entries are standard; controlling what visitors can see, hear, and access during a visit is less consistently managed. Visitors waiting in reception areas can observe personnel, read displayed materials, and identify personnel by name from desk labels and screens. Escorted movement through sensitive areas should be enforced, not just policy.
Maintenance and contractor access is a primary insertion vector for surveillance devices — and for human intelligence collection. Maintenance contractors typically have unsupervised access to sensitive areas, outside normal hours, often carrying equipment that could conceal surveillance hardware. The OPSEC control combines: pre-access vetting of contracting companies and named individuals; supervision requirements for access to the most sensitive areas; and post-access TSCM sweeps for environments with elevated threat profiles.
Building an OPSEC programme
OPSEC programme ownership is the most common structural failure in corporate OPSEC. OPSEC is not an IT function, not a physical security function, and not a compliance function — though it touches all three. It is a strategic function, because the critical information being protected is strategic information. Without senior leadership ownership and active engagement, OPSEC programmes produce policy documents and training completion metrics without changing operational behaviour.
Policy framework: an effective OPSEC policy identifies the categories of critical information specific to the organisation, designates information owners for each category, defines the need-to-know controls, and specifies the channels through which different categories of information may be discussed. Generic "protect sensitive information" policies do not change behaviour because they require the reader to make difficult judgements about what is sensitive. Specific, category-driven policies are more effective because they remove that judgement burden.
Training cadence: OPSEC training delivered once at hire and then annually is insufficient to maintain behaviour change in a dynamic threat environment. Regular short-form awareness interventions — monthly reminders tied to specific, concrete examples — maintain awareness more effectively than periodic long-form training. Scenario-based training that gives personnel realistic examples from their own work context is significantly more effective than abstract principle teaching.
Threat actor profiling makes OPSEC specific rather than generic. An organisation that has identified its most likely threat actors — foreign intelligence services, commercial competitors, litigants, activist groups — can design OPSEC countermeasures targeted at those actors' known collection methods. Generic OPSEC is inefficient; threat-specific OPSEC is proportionate and effective.
Audit mechanisms: periodic OPSEC reviews assess whether policies are being followed in practice, whether new vulnerabilities have emerged (new social media channels, new partnership arrangements, new premises access patterns), and whether the threat environment has changed in ways that require countermeasure updates. OPSEC audits should cover all five domains: digital, physical, personnel, procedural, and communications.
Incident reporting: OPSEC incidents — information disclosures, suspected collection operations, observed surveillance — should have a clear reporting channel and a no-blame culture for good-faith failures. Fear of blame suppresses reporting; unreported incidents cannot be investigated, and undetected collection operations continue. The OPSEC programme should make it easy and safe to report a suspected incident, and should close the loop with the reporter on what action was taken.
Frequently Asked
Request a Security Assessment
Operational engagements start with a vetted conversation. Mission Support responds inside one working day for governmental and Tier-1 enquiries.
Continue to service brief