Most security teams know early warning signs of emerging threats can appear online. The challenge is finding credible intelligence amidst millions of posts spanning an increasingly fractured social media landscape.
AlertMedia recently expanded its Social Intelligence solution with new enhancements designed to improve visibility, streamline analysis, and help organizations identify risks before they escalate.
In this episode, AlertMedia’s Vice President of Risk Intelligence Neil Spencer explains what’s new in Social Intelligence, why these capabilities matter for modern security teams, and how organizations can turn online conversations into actionable intelligence.
Listen in to learn about the latest Social Intelligence enhancements:
Learn more about AlertMedia’s enhanced Social Intelligence capabilities.
The Employee Safety Podcast is hosted by Peter Steinfeld, SVP of Safety Solutions at AlertMedia.
Get every episode delivered straight to your inbox by subscribing at https://www.alertmedia.com/podcast/.
Hello and welcome to the Employee Safety podcast from Alert Media, where you'll hear advice from industry leaders on how to protect your people and business. I'm Peter Steinfeld.
In the wake of several high profile incidents targeting executives, monitoring the digital landscape has become a key focus for many security teams.
While it's long been understood that early warning signals often emerge online before they surface in the physical world, cutting through the noise to identify credible threats has gotten harder as conversations happen across an ever growing number of social platforms, fringe communities, and online forums. Last year, Alert Media launched social intelligence to help security teams more easily identify, monitor, and act on these conversations.
So today I've asked Neil Spencer, Alert Media's Vice president of risk intelligence, to join the show to talk more about what's new and why it matters.
In this episode, Neil not only explains how the new social intelligence capabilities help organizations gain greater visibility into emerging risk signals, but also why a more proactive approach to monitoring digital channels should be a critical component of security operations moving forward. Let's listen in. Hey, Neil, thanks for being here.
Neil Spencer:Hey, Peter, thanks very much for having me.
Peter Steinfeld:All right, let's start at a high level. What is social intelligence really?
Neil Spencer:In simple terms, social intelligence is the collection of data from the online domain. So the mainstream social media would be the likes of Instagram, Facebook, TikTok, those that have billions of users.
Fringe social media are really much smaller, lesser used platforms. So in these mainstream, in these fringe groups, you start to see polarization of that content, polarization of conversations.
And that's why it's incredibly important to be aware of where they are, what they're doing, and the sorts of conversations that are taking place in those locations.
So as part of that emerging social media, deep and dark web, really the online space, and enabling organizations to easily understand conversations that might impact their business operations and turn what is essentially data into intelligence. And that's a really important part of what we're doing with social intelligence.
So it's not just the aggregation of data, it's that overlay of what that means to your business and business operations. And importantly for Alert Media, it also ties back into the overall risk intelligence portfolio.
And so understanding those conversations in the online space is really one pillar, if you will, of that risk intelligence portfolio, which is where we have a strong specialist team of global intelligence analysts that detect events across the world, be it as they emerge or be it proactively. And those are the bangs and booms, if you will, those kinetic events that might impact business continuity.
And the social intelligence element really rounds that out as being that proactive, forward looking piece of risk and understanding those conversations around your brand, around your executives, around potential controversial topics that your organization may be caught up in. Misinformation, disinformation campaigns.
Some of that future horizon, scanning the longer tail of threat intelligence, if you will, which really enables security organizations to be aware as soon as possible of potential threats that might be heading towards their organization.
So the goal here is really to enable organizations to get an understanding of the online domain and do that easily and have that overlaid with the understanding of what that means.
Peter Steinfeld:Why is this important to an organization? What core problem is social intelligence designed to solve for?
Neil Spencer:There are over 6 billion social media users in the world and really that traverses the breadth of content that we've just touched on. So from mainstream through to fringe and so and so forth, that's two out of three people in the world that have access and are using social media.
So that's a lot of intelligence, that's a lot of information out there. And again, that content can consist of threat intelligence, direct threats made against the organization, misinformation, disinformation campaigns.
And if you imagine security teams trying to sift through all of that content, either you need something like social intelligence, a product like social intelligence, to do that in an automated fashion, or you need a small army of people, frankly, to go to all of those sites, all of those locations, those hundreds of sites that are out there, and start to sift through manually collecting that. So social intelligence from alert media is really designed to take what is almost an unachievable task and make that incredibly achievable.
So when we speak to customers and when they look at their social intelligence capabilities and the programs that they're using today, we often hear them talk about major concerns. So major concerns include alerts, overload and fatigue noise.
There's so much content out there, We've just touched on the billions of data points that are generated a day.
And really getting the signal from the noise is incredibly important to organizations, especially those organizations that have limited resources and then limited source coverage. You know, there are platforms out there that are just singular in their collection, singular source.
And there are other platforms out there that are designed primarily for monitoring just mainstream. There are some platforms out there that are just designed for monitoring fringe social.
And so how do you make sure that as an organization you are getting the best coverage that you can, having the greatest amount of contact with the threat landscape out there.
And that really comes with the benefit of automation, the benefit of automated collection across the breadth of data that is available in the alert media platform and then also cumbersome workflow. So we hear so often from organizations of the swivel chair effect.
And so you are in a security environment, you are trying to do so many things at once, especially in the event of a crisis. And how do we make sure that users of social intelligence have a platform that streamlines their workflows?
Time is critical when crises are emerging or in, frankly in the day to day life of a security team. And therefore, how do we reduce cumbersome workflows? How do we reduce the swivel chair effect?
How do we make sure that users of a tool like social intelligence can be within one platform and doing everything that they need to do from within one tool? So reducing those workflows, ensuring that they have the coverage that they need, and frankly increasing the signal to noise ratio.
Peter Steinfeld:Alert Media introduced social intelligence last year as part of its risk intelligence suite. So since then you've continued investing in the solution. Well, what's changed with these latest upgrades?
Neil Spencer:Obviously, you know, nobody puts a product into the market and then stops, especially in the SaaS world and especially in the security world. The security world is forever changing, therefore, so are the tools that the practitioners need to adapt to the changing world.
And so we launched social intelligence last year and realistically, you know, as you say, this is not a new launch, this is an enhancement, this is an expansion of the capabilities. And so really we're rolling out expanded source coverage. So we believe that we have some of the best sources in the market.
The best coverage in the market, again for the reasons we spoke to earlier, really, data collection, data aggregation and source coverage is part of the DNA of the AlertMeo platform. We pride ourselves on the coverage that we have and what that means and what that enables our customers to access.
And so next up is our upgraded user insights. So the goal of this is really to enable practitioners to quickly and easily assess authority threat that they might detect within the social sphere.
And then also we've added our social intelligence capability to our threat management workflow. And what that means is this enables or reduces the element of the swivel share effect that we spoke to.
So it's all of in the alert media platform enables users to triage content, task content and really manage their threats as they come through and keep users in the platform to ensure that when time is of the essence, that work distribution is structured and those workflows enable users to go from point A to point B as quickly and easily as possible.
Peter Steinfeld:Those are all incredibly beneficial. So let's break them down just a bit. What does expanded source coverage add to social intelligence?
Neil Spencer:As we've discussed, the social media domain is growing, fragmenting almost on a weekly basis. Those conversations are moving from fringe to mainstream, mainstream, back to fringe, sometimes from fringe into the deep and dark web.
And so what this means is that we are providing organizations with that broader visibility of early indicators and warnings, misinformation, cybercrime chatter, and really where any coordination might appear in that online domain.
So detecting that as soon as possible, understanding that as soon as possible, understanding the business impact is critical to that data source expansion.
So really it's around expanding the breadth of those sources, the depth of those sources, and making sure that we enable, as much as we can, our users to collect data in both an ethical and also a programmatic way that reduces the effort a user may take to collect those sources. And so our social media collection now includes 65 plus singular sources across those mainstream fringe and dark web sources.
And we're analyzing about 15 million records a day. And so that is a huge volume of data that we are bringing in.
And really, again, the goal here is that whilst we are expanding the connectivity with the threat landscape, we want to make sure that that volume of data is both accessible but also digestible.
And so we are ensuring that our users reduce their blind spots within that intelligence framework, within the intelligence landscape, but at the same time making sure that that signal to noise ratio is high and also making sure that the data collection is targeted and meaningful to our users.
And frankly, it is reducing the need that we've seen in the past of using separate tools or, or manual processes that mean hopping from one platform to one platform in one browser to another web browser.
Peter Steinfeld:And why does such broad source coverage matter so much in this category?
Neil Spencer:The conversations that we see online are growing and fragmenting consistently into these fringe groups. And those conversations tend to move from fringe social networks into the mainstream domain.
What that means is that understanding conversations, when they take place in smaller forums, in ideologically driven forums, in echo chambers, having those early insights and detection in those spaces before they make the leap into mainstream is incredibly important for security practitioners.
And when we see some recent events across the world of executive targeting and the 300% increase in violent threats targeting executives, beyond some of the information narratives that we see around particular brands in the world, again, understanding why the conversations take place and where conversations take place, and what that means to the organization, to your executives, to the people you're protecting, to your business continuity is incredibly Important.
So having that breadth of coverage, having that depth of coverage across multiple, more than just mainstream social and into the fringe and into the emerging social media sites, means that you can get that detection early, understand the narrative, understand the potential impact of the threats being made or the conversation taking place before it reaches the mainstream, before it amplifies even further.
Peter Steinfeld:So broad is clearly critical, but so is deep. And another upgrade that you mentioned is User Insights, which I think addresses that. So what does that help customers do?
Neil Spencer:When you're going through this threat detection process, one of the key things that you're concerned about is, okay, is this threat real? Is it a bot? Is it something that I should be paying attention to? How do we escalate that?
And the goal of User Insights is really to enable practitioners very quickly, very easily, really understand what this means to an organization. What does this threat mean to an organization? Is it credible? Is it a real world individual, or is it there's just a bot?
What is the potential post history look like and what does that mean from a threat assessment? Is there ideation about the brand? Is there violent ideation? Are there other concerning elements within some post history that we should be flagging?
And as security practitioners can quickly help to understand whether or not this particular threat is arguably viable or that whether we should dismiss and move on because somebody is having a bad day on a particular channel of choice. So the goal of User Insights is not to be a full blown investigative platform really.
It's for a SOC operator, somebody who's doing that first initial triage, to assess, understand triage, what a potential online threat might mean to the organization and what they should do next of them. So what we're not doing is taking data elements like PII and using that to, to ingest into the platform.
But what we are doing is really making sure that we can look through some of the post history to look for relevant indicators and warnings and as I mentioned, really assess intent capability and other actionable elements that we can use to inform our team, our stakeholders about where we go next with this.
And part of that is to be able to create shareable artifacts that we can share internally with our stakeholders so that then they can escalate from there.
Peter Steinfeld:Yeah, what next is really important, especially with the volume of stuff that's coming in. So how does the integration with the alert media threat management capability change the workflow?
Neil Spencer:Yeah, absolutely. And so we spoke to that world of, okay, so we've got a threat now what?
So once we've assessed or even once we've had that initial threat detection phase. So we want to start to loop other team members into this. We start to want to bring out that potential threat into a workflow that makes sense.
And so what that means is we are now moving it into a Kanban process. Okay, what are we investigating? What are we currently working through? What needs to be worked through? Who is working through that?
Who is taking the next step? So assigning individuals, assigning priority, adding notes to a potential threat so that a team can very quickly collaborate.
When we're looking at operations where time is of the essence, having the visibility across a team of a particular threat, understanding who is owning that threat, and understanding where they are in that threat triage process is incredibly important.
So that simple Kanban goes from something that seems like such a simple workflow into an incredibly powerful deliverable that enables people to streamline their work. And it's not just about our social intelligence deliverable either. It's also really combining our social intelligence with our threat intelligence.
So not now users have a single workflow that is easily repeatable, very familiar to users, and it means that users from one location can work through that detection, through to potentially dissemination workflow if they need to. If they need to trigger an alert or trigger an instant from a single.
Peter Steinfeld:Workflow, you've covered a lot. But stepping back just a little bit, how is social intelligence different from existing social listening or monitoring tools?
Neil Spencer:You know, a lot of people listening to this podcast will be familiar with social listening and many will have the lens of marketing tools. You know, many an organization has a very well established social listing capability for brand management purposes versus brand protection purposes.
And really those tools are designed far more for understanding, you know, sentiment around product launches, the reach that the product launch is having. And so the lens of a traditional social listening tool is very, very different to what we're doing with alert media.
So within alert media, our social intelligence tool is really built for security practitioners and that means a few different things. So it is built for the purpose of detecting threats that are business continuity threats.
We've spoken to why that is important within the fringe space and why coverage of locations like fringe media, dark web, but also the mainstream web, that holistic view is incredibly important. But they also have spoken to some of the workflows that we've touched on.
So having that single view of threat intelligence and risk intelligence overlaid into the workflows that enable a user to really take a threat from detection through to resolution, and that resolution and that action could be sending a massive killer communications. It could be creating an incident within the Alert Media platform. Having all of those workflows within one tool is incredibly important.
And then equally important is the ability to highlight those signals. So signals for a security team are very different to what a signal might mean for a brand protection team or a marketing team.
So sentiment classifiers, some of the AI work that we've been doing around highlighting some of the signals and noise are very much around security driven workflows and security driven outcomes. And so that's why Alert Media's social intelligence capability is a very different offering from something that might be used in a marketing team.
The social intelligence capability within Alert Media is there to help security teams detect, assess, escalate, and then respond within a single platform.
Peter Steinfeld:I'm glad you mentioned AI, because it's really top of mind for just about everyone out there right now. So how is Alert Media using AI specifically within social intelligence?
Neil Spencer:Yeah, it's tough to escape it these days, right? And Alert Media, this isn't something new to Alert Media.
So Alert Media has had AI in the tech stack for years at this stage, and really what we're doing is harnessing AI in a slightly new way within the social intelligence world to help elevate content in the platform that otherwise would be manual.
So we've heard from customers, from users, that other platforms they may have used involve scrolling through page after page of post to try and find content that is concerning. And so within Alert Media, we've really been mindful about where we utilize AI, because AI isn't just.
You can't just throw AI at anything and make it better. You have to be meaningful and purposeful as to how you're using AI.
So one of the first challenges that we hear from our customers is, hey, it's hard to build searches. It's hard to build meaningful searches.
And that's why we've implemented AI into our search builder to help people who may not be building Boolean searches every day build a meaningful and purposeful search that collects good data and enables them to get contact with the threat landscape, but without overwhelming. And so that's an important piece of the puzzle here. And likewise, once that data is into the platform, well, how do we summarize that?
How do we take those summaries and enable users again to quickly understand, without reviewing every single post, what's going on in that search, what sort of results have come back, what does that mean to our organization? And are there any particular posts in this search that I should be paying attention to over others?
What potential critical content Should I be paying attention to? And again, what does it mean to our business?
And likewise, so when we look at the language used, language in the online domain is very interesting facet of social intelligence.
And so highlighting and understanding, sure, negative sentiment around a particular topic, that's always a useful threat indicator for understanding if particular organizations might be concerned about what's being said about them online. But also threatening content, violent content, content that contains hate speech.
And so again, surfacing those threat indicators to practitioners, to users of the platform without them having to go and dig for it is incredibly powerful.
We hear from our users constantly that it saves them significant time, in some cases hours of their day, certainly minutes every time they log into the platform. And that starts to add up after a while.
Peter Steinfeld:Well, we've talked about what we do and why we do it, but let's talk examples. Can you share a real world scenario where social intelligence helped an organization better understand risk?
Neil Spencer:So, you know, when we tie together all these pieces of the threat landscape and the overlay of AI, be it to build the initial search or indeed build the outcomes, understand the outcomes, a particular example springs to mind. So there is an automotive manufacturer whose name is commonly used in the online discourse.
So for them, it was very hard to really start to understand where their brand name was being used within broader conversational online discussions, or whether or not there was a real threat attached to that name in that particular brand. What they found was that it was incredibly overwhelming for them to find that signal from the noise.
They were just finding noise, constant, constant noise, when they were using generic keyword searches. That noise to signal ratio, the noise was far, far too high.
When this particular organization adopted social intelligence, really, they started to break out and bring in content that was meaningful to them. How did they do that?
They started to refine their searches, started to use some of the AI support to help them build their searches, started to use those sentiment filters that I spoke about, surfacing meaningful content rather than content that was just using their name. So surfacing violent content, surfacing threatening content, surfacing hate speech.
And again, using those AI summaries to maybe if there's a little bit of noise in there, sometimes you can't always avoid all the noise. But if there is a little bit, those AI summaries really enable you to surface the content that is meaningful to you.
So there's that threefold approach of the AI summaries, the sentiment filters and the search building approach that enabled an organization to take something that was almost, almost impossible even with a technology platform.
And once Made the switch to using Love Media social intelligence tool, started to produce relevant insights and in this instance started to truly save them hours of work and some review of content. So it's not a lack of information that sometimes that they see.
So in the first instance, before making the change, this particular organization had all the information in the world. But how do you really take that information? How do you take that data and turn it into meaningful insights and not just too much information?
Peter Steinfeld:Well, looking ahead, how do you see social intelligence changing the way that security teams operate?
Neil Spencer:You know, if you go back 10 years ago, social intelligence, open source intelligence really was the purview of potential government organizations. I suppose really that's where this particular domain was most heavily adopted.
You know, you go back five years ago, really this was the purview of very sophisticated user security teams that maybe had a lot of resources and also had the threat landscape to have a meaningful social intelligence program.
I think as time moves on and we're starting to see this today, the efficiencies that we are building with our social intelligence tool means that smaller teams, more efficient teams, can really benefit from social intelligence and what that means to an organization.
So getting better insight into what's going on in the world and what's going on in the digital space and what that means to their organization, not only what that means for their organization, what does that mean for their industry peers? And so again, all those things were very, very hard for smaller teams to do in the past.
Social intelligence really enables the efficiencies to be created to, as I think I mentioned at the top of this call, make something that is incredibly powerful, but in the past has been incredibly complex to achieve or time and resource intensive to access in the past, now is becoming incredibly achievable by teams that need it, but historically haven't been able to do it.
So with social intelligence, we are really enabling those users, those smaller teams and larger enterprise teams alike, to achieve powerful outcomes and time efficiencies that in the past they've not been able to. So that's near term in the future. You know, how do we enable organizations to do more of the same?
So no organization out there, sadly, is necessarily throwing huge amounts of money at their security teams. We hear it constantly from our customer base.
And so how do we enable our security practitioners to have even more of an impact with the same resources?
Touch more of the Internet, understand what more of the threat landscape with the same resources, how do we make sure that those workflows are incredibly efficient? How do we make sure that those insights can be claimed even faster.
And how do we make sure that we're maintaining content connectivity with the threat landscape?
And so, yeah, efficiency, connectivity to the landscape and making sure that not just the most sophisticated teams have access to a tool like social intelligence.
Peter Steinfeld:Yeah, I guess you could say that we're essentially democratizing this capability and it's something Alert Media really is good at historically.
Neil Spencer:Absolutely. Yeah. It is not an exquisite capability.
It is something that should be usable by anybody within a security organization, be it a Fortune 100 or be it a smaller SMP organization. Democratization is absolutely the goal of what we're working on here.
Peter Steinfeld:Last question before we wrap up. How can listeners learn more about social intelligence?
Neil Spencer:You can find [email protected] where you can request a demo.
And we also just released a white paper that covers many of the topics we've discussed today, and that's called the Definitive Guide to Misinformation and Disinformation that can be found on the website. It's a great read and always reach out if you want to learn more.
Peter Steinfeld:Neil, thanks again for joining us and for walking through what these social intelligence upgrades mean for security teams.
Neil Spencer:Peter, thanks family. Looking forward to doing again sometimes.
Peter Steinfeld:To learn more about Alert Media's enhanced social intelligence capabilities, click the links in the episode description. You can also watch the video Highlights on Alert Media's YouTube channel. Don't forget to subscribe, rate and review the show.
Wherever you get your podcasts, stay safe out there. Thank you for listening to the Employee Safety Podcast from Alert Media, the world's leading provider of risk intelligence and response solutions.
To learn more about how to protect your patients, people in business during critical incidents, visit alertmedia.com.