radicalisation and insider threat

27
Sushil Pradhan MitKat Advisory Services 22 nd July 2016

Upload: pradhansushil

Post on 12-Apr-2017

62 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Radicalisation and Insider Threat

SushilPradhanMitKatAdvisoryServices22ndJuly2016

Page 2: Radicalisation and Insider Threat

§  Radicaliza=onandreligiousindoctrina=on

§  Counteringradicaliza=on

§  IslamicStateintheIndianSub-con=nent

§  Insiderthreat

§  SocialEngineering

TheThreatWithin

Page 3: Radicalisation and Insider Threat

Radicaliza=onandreligiousindoctrina=on

Page 4: Radicalisation and Insider Threat

CaseStudy–MansoorPeerbhoy,IndianMujahideen(IM)

Loca%on:Pune

Organisa%on:Yahoo!

Who was he?: Mansoor Peerbhoy was a soOwareengineer working at the Pune office of the Yahoo!India-ownedfirmZimbra.Hisfatherownedabusinessof wholesale grocery supplies to the Indian Army’sSouthernCommand.

Ac%vi%es:Hewas IM’sallegedmediawinghead.Hesentemailspreceding theserial blasts in Delhi and Ahmedabad. He had reportedly sent the mails byhackingtheWi-Fiaccountsofunsuspec=ngtargets,includingaUSci=zen.

Whatdidheachieve?:Heallegedlyhelpedhandle the IMpropagandathroughsocialmediaandemails.

Page 5: Radicalisation and Insider Threat

CaseStudy–IOCLManagerwithallegedlinkstoIS

Loca%on:Jaipur

Organisa%on:IndianOilCorpora=onLimited(IOCL)

Whowashe?:MohammedSirajuddinwasworkingasanassistantmanagerwiththeIOCLinJaipurandlivedwithhiswifeandtwochildren.

Ac%vi%es: Inves=ga=on revealed evidences of his incrimina=ng chats, posts,videos, images and comments on Facebook,WhatsApp, Telegram and Twi^er(which were) shared and circulated in groups and channels on various socialnetworkingsites.

Whatdidheachieve?:Changedthepercep=onofincreasedinsiderthreatriskinlargeorganiza=onsandcorpora=ons.

Page 6: Radicalisation and Insider Threat

CaseStudy–@Shamiwitness,apro-ISTwi^eraccount

Loca%on:Bengaluru

Organisa%on:ITC

Who was he?:Mehdi Biswas was a manufacturingexecu=ve at food produc=on company ITC un=l hisarrest.

Ac%vi%es:Twi^eraccountby thepseudonymof 'ShamiWitness’was linked toMehdiBiswas,basedinBengaluru.@shamiwitnessandisreportedtohavesent1.2lakhtweetsalongwith11,000directmessages;theaccounthadover17,000followers. On Twi^er @ShamiWitness was recorded praising martyred Bri=shfightersofIslamicStatefortheirdedica=onandsacrifice.

What did he achieve?: Triggered the threat of radicaliza=on of well-educatedengineersandtechniciansbyIS.

Page 7: Radicalisation and Insider Threat

§  Whenanindividualadoptsextremepoli=cal,social,religiousideasandaspira=ons

§  Perpetratesandmo=vatesviolentbehaviour

§  Inthereligiouscontext–equatesviolencetoatestofreligiouscommitment

§  Greatestthreatisfroma‘HomegrownViolentExtremist(HVE)’–apersonwhowasonceassimilatedinto,buthasrejectedtheculturalvaluesandbeliefsofthena=on’sdemocra=cfibreinfavourofaviolentextremistideology.

WhatisRadicaliza=on?

Page 8: Radicalisation and Insider Threat

•  Radicaliza=onandreligiousindoctrina=onarenolongerthemonopolyofthepoorandtheoppressed.–  IslamicStatehasanumberofprofessionalsfromacrosstheworldwhoare

managingthegroup’ssophis=catedcommunica=on,banking,andotherinfrastructuralrequirements

–  AlQaedachief,Aymanal-Zawahiriwasatrainedsurgeonbeforehejoinedtheterroristorganisa=on

–  Lashkar-e-Taibahasbeenknowntohireengineers,doctors,technicians,andotherprofessionalsinthepast

–  InIndia,theIndiaMujahideen,andlatelytheIslamicState,havedrawnrecruitsfromurbanandeducatedbackgrounds.

•  Around21peoplefromdifferentpartsofKeralaarethoughttohavejoinedtheIslamicStateaOertheywentmissing-mostofthemwererecentconvertstoIslamfromHinduismandChris=anity.

§  Addi=onalconcernsfromagrowingsenseofHinduradicaliza=onacrossthecountryagainstminori=es

Radicaliza=onandReligiousIndoctrina=on

Page 9: Radicalisation and Insider Threat

§  Psychologicalstate–rejec=on,pressure,failure,imageincommunity

§  Influenceofsocialnetworks–peerpressure

§  Feelingofaliena=on

§  Grievancesagainstapoli=calparty–Gujarat,Assam?

§  Externalevents–violenceinIndiaasareac=ontoa^acksinMyanmar

Whatarethefactorsthatassistinradicaliza=on?

Page 10: Radicalisation and Insider Threat

•  Beingincreasinglysecre=veabouttheirhabits•  Displayingfeelingsofisola=onandexpressionsof“usandthem”mentality•  Becomingmoreargumenta=veordomineeringintheirviewpoints•  Beingquicktocondemnthosewhodisagree•  Ignoringviewsthatcontradicttheirown•  Ques=oningtheirfaithoriden=ty•  Downloading or promo=ng extremist content, such as clips, manuals or

literature•  Expressingextremistviews,orseekingoutthecompanyofthosewhodo•  Losinginterestinac=vi=estheyusedtoenjoy•  Distancingthemselvesfromfriendsandsocialgroups•  Havingachangedstyleofdressand/orpersonalappearance•  Abnormalrou=nesortravelpa^ernsCau=onisalwaysrecommendedinreachingjudgments!

SignsofRadicaliza=on

Page 11: Radicalisation and Insider Threat

•  Engagingandworkingwithcivilsociety•  Educa=onprograms•  Promo=nginter-culturaldialogues•  Tacklingeconomicandsocialinequali=es•  Counteringradicaliza=onontheinternet•  Legisla=onreforms•  Rehabilita=onprograms•  Developing,sharing,anddissemina=nginforma=on•  Trainingofagenciesinvolvedincounter-radicaliza=onpolicies

CounteringRadicaliza=on

Page 12: Radicalisation and Insider Threat

Bangalore 09972 001 260 NCR +91 9999 689 502, Mumbai +91 9820 126 761, Pune +91 9049 011 353

Page 13: Radicalisation and Insider Threat

Bangalore 09972 001 260 NCR +91 9999 689 502, Mumbai +91 9820 126 761, Pune +91 9049 011 353

Page 14: Radicalisation and Insider Threat

Bangalore 09972 001 260 NCR +91 9999 689 502, Mumbai +91 9820 126 761, Pune +91 9049 011 353

Page 15: Radicalisation and Insider Threat

Bangalore 09972 001 260 NCR +91 9999 689 502, Mumbai +91 9820 126 761, Pune +91 9049 011 353

Page 16: Radicalisation and Insider Threat

§  It’sthemostpotentandmedia-savvyterroristoupitglobally§  Usesthemediaasarecruitmentandpropagandatool

§  OnlyahandfulfromIndiahavejoinedISascomparedtosomewesternandmiddleeasterncountries

§  IncreasingtrendofreligiousintoleranceinthecountrymaypushsomeMuslimyouthintoradicalisa=on

§  WemaysuffereffectsofBangladesh&Pakistanevents/efforts§  Unemploymentandmarginalisa=onarealsoimportantfactors

§  Increasingly,affluentandeducatedpeoplearejoiningup

§  Thethreatisnowimminent!

ShouldIndiaworryabouttheIslamicState?

Page 17: Radicalisation and Insider Threat

ShouldIndiaworryabouttheIslamicState?

•  FouryouthfromMumbaileOforSyriatojointheISinMay2014.Onereturnedandwasarrested.

•  AnISrecruitfromGreaterMumbai(AreebMajeed)wasinterceptedinTurkeyinNovember2014,andtheninterrogatedandarrestedbyNIA.Suspectedofkillingupto55people,heallegedlyleObecausetheydidn’tpayenough,treatedSouthAsiansbadlyandabusedwomen.

•  FahadShaikh,oneofthefourKalyanyouthswhoranawayandjoinedhasgotintouchwithhisfamily,butrebuffedcallstoreturn,saying"Iamhappywithmyjihadiwork,Iwon'tcomebacktoIndia”.

•  AnMNCexecu=veMehdiMasroorBiswaswasarrestedinBangaloreforrunningapro-IStwi^erhandle.

•  SalmanMouinuddin,aHyderabadbasedengineerwasarrestedfromtheairport,whenhewasenroutetoSyria.

•  FirstIslamicState‘module’busted,5heldinMadhyaPradesh(May2015)•  ThereisanimminentdangerofIndianyouthsmovingtotheconflictzone(Iraq-

Syria),andthenemergingasrolemodels.

Page 18: Radicalisation and Insider Threat

It’sspreadingquickly!

IslamicStatePresenceinIndiaJ&K:•  ISwantsKashmirunderits'caliphate'

ratherthanPakistanortheLeT•  NIAclaimedforterrorlinksina

chargesheetagainstIndianOilofficialMohammadSirajuddinarrestedlastDecember

•  ISflagshavealsorou=nelycroppedupintheValleyatprotests

Maharashtra:•  Manyyoungstershavegonemissing

overthepastfewyearsandlikelytobeinSyria&IraqwithIS.Amongthem,themosttalkedofareAarifMajid,AmanTandel,FahadShaikhandSaleemTankifromKalyan.

•  AnISrecruitfromGreaterMumbai(AreebMajeed)wasinterceptedinTurkeyinNovember2014

•  Intherecentpast,IS-relatedarrestshavebeenmadeinPuneandParbhani.

•  ZakirNaik

Karnataka:In2014,policearrestedMehdiMasroorBiswas,amanagementexecu=veinanMNC,fromBangalore.HeallegedlyworkedasanISpropagandaac=vist.

Kerala:21people,including4children,missingfromthestate.TheymayhavejoinedIS.Themissingincludesadoctor'sfamilyandacomputerengineer,hiswifeandhisfriends.

UBarPradesh:•  TwoUPmenfeaturedinanISTVgrabinMay:AbuRashidAhmad

andMohd'Bada'Sajid.Rashid,fromAzamgarh,movedtoMumbai&isasuspectinIndianMujahideenblastsbetween2005and2008SajidwentmissingaOerthe2008BatlaHouseencounterinDelhi.IntheISvideo,thetwothreatenterrorstrikesinIndia.

•  AnotherAzamgarhyouthtoojoinedISinIraq.HecontactedhisfamilylastOctobersayinghenowwantedtoreturn.

WestBengal:•  SuspectedterroristMohammedMusiruddin,

arrestedinKolkatathisJuly4,wasinKashmirtotrainforterrorgroupssuchasISandJamaatul-MujahideenBangladesh.

•  ThesecurityestablishmentisworriedaOertheriseinIS-linkedterrorinBangladesh.

Telangana:•  In2014Telanganapoliceintercepted17youngstersfrom

differentpartsofthecountrywhiletheyweretryingtocrossovertoBangladesh.AnothergroupwascaughtatNagpur.SomeweretryingtocatchaflighttoSrinagarandenterPOKandAfghanistan.

•  In2013,thefamilyofanAdilabadengineer,MdA=fWaseem,27,whohadgonetoLondonforanMSandlaterbeganworkinginDubaiwasinformedthathehaddiedinSyriafigh=ngforIS.

MP:FiveMadhyaPradeshmenarrestedfromthetownofRatlamwerepartofanIslamicState(IS)-linkedjihadcellplanningstrikesinIndia

Page 19: Radicalisation and Insider Threat

Bangalore 09972 001 260 NCR +91 9999 689 502, Mumbai +91 9820 126 761, Pune +91 9049 011 353

Page 20: Radicalisation and Insider Threat

Whatcancompaniesdo?

•  Acquaintyourselfwiththeboththeglobalandlocalthreatlevelsofterrorism•  Inves=gatewhataspectscanmakethecompanya^rac=vetoterrorists,and

considerspecificrisksthecompanymaybevulnerableto•  Drawupaperiodicthreatvulnerabilityanalysis•  Formulateasecurityandcounter-radicaliza=onplan,andencouragethe

employees’awarenesswithregardtoissuesofsecurityandradicaliza=on•  Operateaproperaccesspolicyandensuretheimplementa=onofproperaccess

controlmethods•  Checkreferenceswhentakingonnewstaff;makesureyouaredealingwith

reliablecompanieswhenhiringthird-partyemployees•  Aresponsemechanismneedstobedesignedtocounteranysitua=onwhere

organiza=on'sreputemightbeatstakeduetotheemployees•  Policyontacklingextremismandradicaliza=onmustbecommunicatetoall

managers/employees,andhastobepromptlyfollowedaspertheguidancewhenissuesarise

Page 21: Radicalisation and Insider Threat

InsiderThreat

Page 22: Radicalisation and Insider Threat

Aninsiderthreatariseswhen:§  Apersonwithauthorizedaccesstotheorganiza=on’sresources,§  Whichincludesincludespersonnel,facili=es,informa=on,

equipment,networks,andsystems,§  Usesthataccesstoharmthesecurityorreputa=onofthe

organiza=on.Whoarethetrustedpeople?§  Managers

§  Opera=onspersonnel§  Securitypersonnel§  Vendorstaff§  Part=meworkers

InsiderThreat

Page 23: Radicalisation and Insider Threat

Thisa^ackcouldbecarriedoutby:§  Infiltra=ngthecompanyforana^ack,or

§  Becomingradicalisedwhileinthecompanyalready

§  Beingblackmailedorcoercedintosuchac=vityThepersoncould:

§  A^ackdirectly,or§  Facilitateana^ackThisa^ackcouldbe:

§  Violent,or§  Non-violent–recruitment,propaganda

InsiderThreat

Page 24: Radicalisation and Insider Threat

•  Unauthorized disclosure of sensi%ve informa%on - A short-term contractorleakedprivilegedinforma=onfromhisemployer

•  Processcorrup%on-Themanager,withanover-inflatedsenseofhisownvalueand contribu=on to the organiza=on, increased his own salary and claimedover=mepaymentswithoutoversightorauthoriza=onfromanotheremployee

•  Facilita%on of third party access to an organiza%on's assets - An agencyemployeefacilitatedaccesstoanex-employeewithlinkstoorganizedcriminalsforthepurposeofcommizngmajorfraud

•  Physical sabotage - A temporary employee working as a security guardpurposefully tampered with equipment vital to the opera=on of theorganiza=on

•  ElectronicorITsabotage-Anemployeesabotagedtheautoma=caccesssystemathisworkplace

InsiderThreat–typicalexamples

Page 25: Radicalisation and Insider Threat

•  Athoroughbackgroundcheckofallemployees–  Suspiciousgapsinresumes–  Travel–  Socialmediapresence–  Historyofmentalillness

•  Developcriteriafordenialofhiring•  Educatepersonnelonwhatindicatorstowatchoutfor•  Confiden=alinternalrepor=ngprocedure•  Behaviouralprofiling•  UseCCTV,remoteCCTV•  Thoroughaccesscontrolchecks•  Nowaivers,includingforsecuritypersonnel•  Developresponseprocedures

Bestprac=cestocounterinsiderthreat

Page 26: Radicalisation and Insider Threat

•  Companiesareconsistentlyoutsourcingandarecommizngmoreandmoreresourcestothecloud,topayrollservices,andtoothervendorstostreamlinetheirbusinesses.

•  Inthisnewbusinessclimate,canassetsbetrulysafe?•  Mul=-vendoroutsourcingarrangementsaremorecomplicatedbecauseservices

canveryrarelybeperformedinisola=onfromotherservices•  Third-partyvendorscouldbetheweaklinksinmanagingtheorganiza=on's

securityasthereisnodirectmonitoringmechanismofthethird’sparty’ssecuritysystemorpossibletohaveathoroughbackgroundofitsemployees

•  Third-partybreachcancauseseriousreputa=onalandfinancialdamage

Therefore:•  HaverobustSLAswithallvendors•  Vezngoftheirstaffisasimportantasthatofyourownstaff•  Ensureallprocessesapplytothemtoo

ThirdPartyLiability

Page 27: Radicalisation and Insider Threat

ThankYou