Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Saturday, October 3, 2009

Convergence: The Challenge of Aviation Security

Scott Stewart
September 16

On Sept. 13, As-Sahab media released an audio statement purportedly made by Osama bin Laden that was intended to address the American people on the anniversary of the 9/11 attacks. In the message, the voice alleged to be that of bin Laden said the reason for the 9/11 attacks was U.S. support for Israel. He also said that if the American people wanted to free themselves from “fear and intellectual terrorism,” the United States must cut its support for Israel. If the United States continues to support Israel, the voice warned, al Qaeda would continue its war against the United States “on all possible fronts” — a not so subtle threat of additional terrorist attacks.

Elsewhere on Sept. 14, a judge at Woolwich Crown Court in the United Kingdom sentenced four men to lengthy prison sentences for their involvement in the disrupted 2006 plot to destroy multiple aircraft over the Atlantic using liquid explosives. The man authorities claimed was the leader of the cell, Abdulla Ahmed Ali, was sentenced to serve at least 40 years. The cell’s apparent logistics man, Assad Sarwar, was sentenced to at least 36 years. Cell member Tanvir Hussain was given a sentence of at least 32 years and cell member Umar Islam was sentenced to a minimum of 22 years in prison.

The convergence of these two events (along with the recent release of convicted Pan Am 103 bomber Abdel Basset Ali al-Megrahi and the amateurish Sept. 9 hijacking incident in Mexico using a hoax improvised explosive device [IED]) has drawn our focus back to the topic of aviation security — in particular, IED attacks against aircraft. As we weave the strands of these independent events together, they remind us not only that attacks against aircraft are dramatic, generate a lot of publicity and can cause very high body counts (9/11), but also that such attacks can be conducted simply and quite inexpensively with an eye toward avoiding preventative security measures (the 2006 liquid-explosives plot.)

Additionally, while the 9/11 anniversary reminds us that some jihadist groups have demonstrated a fixation on attacking aviation targets — especially those militants influenced by the operational philosophies of Khalid Sheikh Mohammed (KSM) — the convictions in the 2006 plot highlight the fact that the fixation on aviation targets lives on even after the 2003 arrest of KSM.

In response to this persistent threat, aviation security has changed dramatically in the post-9/11 era, and great effort has been undertaken at great expense to make attacks against passenger aircraft more difficult. Airline attacks are harder to conduct now than in the past, and while many militants have shifted their focus onto easier targets like subways or hotels, there are still some jihadists who remain fixated on the aviation target, and we will undoubtedly see more attempts against passenger aircraft in spite of the restrictions on the quantities of liquids that can be taken aboard aircraft and the now mandatory shoe inspections.

Quite simply, militants will seek alternate ways to smuggle components for IEDs aboard aircraft, and this is where another thread comes in — that of the Aug. 28 assassination attempt against Saudi Deputy Interior Minister Prince Mohammed bin Nayef. The tactical innovation employed in this attack highlights the vulnerabilities that still exist in airline security.

Shifts

The airline security paradigm changed on 9/11. In spite of the recent statement by al Qaeda leader Mustafa Abu al-Yazid that al Qaeda retains the ability to conduct 9/11-style attacks, his boast simply does not ring true. After the 9/11 attacks there is no way a captain and crew (or a group of passengers for that matter) are going to relinquish control of an aircraft to hijackers armed with box cutters — or even a handgun or IED. A commercial airliner will never again be commandeered from the cockpit and flown into a building — especially in the United States.

Because of the shift in mindset and improvements in airline security, the militants have been forced to alter their operational framework. In effect they have returned to the pre-9/11 operational concept of taking down an aircraft with an IED rather than utilizing an aircraft as human-guided missile. This return was first demonstrated by the December 2001 attempt by Richard Reid to destroy American Airlines Flight 63 over the Atlantic with a shoe bomb and later by the thwarted 2006 liquid-explosives plot. The operational concept in place now is clearly to destroy rather than commandeer. Both the Reid plot and the 2006 liquid-bomb plot show links back to the operational philosophy evidenced by Operation Bojinka in the mid-1990s, which was a plot to destroy multiple aircraft in flight over the Pacific Ocean.

The return to Bojinka principles is significant because it represents not only an IED attack against an aircraft but also a specific method of attack: a camouflaged, modular IED that the bomber smuggles onto an aircraft in pieces and then assembles once he or she is aboard and well past security. The original Bojinka plot used baby dolls to smuggle the main explosive charge of nitrocellulose aboard the aircraft. Once on the plane, the main charge was primed with an improvised detonator that was concealed inside a carry-on bag and then hooked into a power source and a timer (which was disguised as a wrist watch). The baby-doll device was successfully smuggled past security in a test run in December 1994 and was detonated aboard Philippine Air Flight 434.

The main charge in the baby-doll devices, however, proved insufficient to bring down the aircraft, so the plan was amended to add a supplemental charge of liquid triacetone triperoxide (or TATP, aptly referred to as “Mother of Satan”), which was to be concealed in a bottle of contact lens solution. The plot unraveled when the bombmaker, Abdel Basit (who is frequently referred to by one of his alias names, Ramzi Yousef) accidentally started his apartment on fire while brewing the TATP.

The Twist
The 2006 liquid-bomb plot borrowed the elements of using liquid explosives and disguised individual components and attacking multiple aircraft at the same time from Bojinka. The 2006 plotters sought to smuggle their liquid explosives aboard using drink bottles instead of contact lens solution containers and planned to use different types of initiators. The biggest difference between Bojinka and more recent plots is that the Bojinka operatives were to smuggle the components aboard the aircraft, assemble the IEDs inside the lavatory and then leave the completed devices hidden aboard multi-leg flights while the operatives got off the aircraft at an intermediate stop. The more recent iterations of the jihadist airplane-attack concept, including Richard Reid’s attempted shoe bombing and the 2006 liquid-bomb plot, planned to use suicide bombers to detonate the devices midflight. The successful August 2004 twin aircraft bombings in Russia by Chechen militants also utilized suicide bombers.

The shift to suicide operatives is not only a reaction to increased security but also the result of an evolution in ideology — suicide bombings have become more widely embraced by jihadist militants than they were in the early 1990s. As a result, the jihadist use of suicide bombers has increased dramatically in recent years. The success and glorification of suicide operatives, such as the 9/11 attackers, has been an important factor in this ideological shift.

One of the most recent suicide attacks was the Aug. 28 attempt by al Qaeda in the Arabian Peninsula (AQAP) to assassinate Saudi Prince Mohammed bin Nayef. In that attack, a suicide operative smuggled an assembled IED containing approximately one pound of high explosives from Yemen to Saudi Arabia concealed in his rectum. While in a meeting with Mohammed, the bomber placed a telephone call and the device hidden inside him detonated.

In an environment where militant operational planning has shifted toward concealed IED components, this concept of smuggling components such as explosive mixtures inside of an operative poses a daunting challenge to security personnel — especially if the components are non-metallic. It is one thing to find a quantity of C-4 explosives hidden inside a laptop that is sent through an X-ray machine; it is quite another to find that same piece of C-4 hidden inside someone’s body. Even advanced body-imaging systems like the newer backscatter and millimeter wave systems being used to screen travelers for weapons are not capable of picking up explosives hidden inside a person’s body. Depending on the explosive compounds used and the care taken in handling them, this method of concealment can also present serious challenges to explosive residue detectors and canine explosive detection teams. Of course, this vulnerability has always existed, but it is now highlighted by the new tactical reality. Agencies charged with airline security are going to be forced to address it just as they were previously forced to address shoe bombs and liquid explosives.

Actors

Currently there are three different actors in the jihadist realm. The first is the core al Qaeda group headed by bin Laden and Ayman al-Zawahiri. The core al Qaeda organization has been hit hard over the past several years, and its operational ability has been greatly diminished. It has been several years since the core group has conducted a spectacular terror attack, and it has focused much of its effort on waging the ideological battle as opposed to the physical battle.

The second group of actors in the jihadist realm is the regional al Qaeda franchise groups or allies, such as al Qaeda in the Arabian Peninsula, Jemaah Islamiyah and Lashkar-e-Taiba. These regional jihadist groups have conducted many of the most spectacular terrorist attacks in recent years, such as the November 2008 Mumbai attacks and the July 2009 Jakarta bombings.

The third group of actors is the grassroots jihadist militants, who are essentially do-it-yourself terrorist operatives. Grassroots jihadists have been involved in several plots in recent years, including suicide bomb plots in the United States and Europe.

In terms of terrorist tradecraft such as operational planning and bombmaking, the core al Qaeda operatives are the most advanced, followed by the operatives of the franchise groups. The grassroots operatives are generally far less advanced in terms of their tradecraft. However, any of these three actors are capable of constructing a device to conduct an attack against an airliner. The components required for such a device are incredibly simple — especially so in a suicide attack where no timer or remote detonator is required. The only components required for such a simple device are a main explosive charge, a detonator (improvised or otherwise) and a simple initiator such as a battery in the case of an electric detonator or a match or lighter in the case of a non-electric detonator.

The October 2005 incident in which a University of Oklahoma student was killed by a suicide device he was carrying demonstrates how it is possible for an untrained person to construct a functional IED. However, as we have seen in cases like the July 2005 attempted attacks against the London Underground and the July 2007 attempted attacks against nightclubs in London and the airport in Glasgow, grassroots operatives can also botch things due to a lack of technical bombmaking ability. Nevertheless, the fact remains that constructing IEDs is actually easier than effectively planning an attack and successfully executing it.

Getting a completed device or its components by security and onto the aircraft is a significant challenge, but as we have discussed, it is possible to devise ways to overcome that challenge. This means that the most significant weakness of any suicide-attack plan is the operative assigned to conduct the attack. Even in a plot to attack 10 or 12 aircraft, a group would need to manufacture only about 12 pounds of high explosives — about what is required for a single, small suicide device and far less than is required for a vehicle-borne explosive device. Because of this, the operatives are more of a limiting factor than the explosives themselves, as it is far more difficult to find and train 10 or 12 suicide bombers.

A successful attack requires operatives not only to be dedicated enough to initiate a suicide device without getting cold feet; they must also possess the nerve to calmly proceed through airport security checkpoints without alerting officers that they are up to something sinister. This set of tradecraft skills is referred to as demeanor, and while remaining calm under pressure and behaving normal may sound simple in theory, practicing good demeanor under the extreme pressure of a suicide operation is very difficult. Demeanor has proven to be the Achilles’ heel of several terror plots, and it is not something that militant groups have spent a great deal of time teaching their operatives. Because of this, it is frequently easier to spot demeanor mistakes than it is to find well-hidden explosives.

In the end, it is impossible to keep all contraband off aircraft. Even in prison systems, where there is a far lower volume of people to screen and searches are far more invasive, corrections officials have not been able to prevent contraband from being smuggled into the system. Narcotics, cell phones and weapons do make their way through prison screening points. Like the prison example, efforts to smuggle contraband aboard aircraft can be aided by placing people inside the airline or airport staff or via bribery. These techniques are frequently used to smuggle narcotics on board aircraft.

Obviously, efforts to improve technical methods to locate IED components must not be abandoned, but the existing vulnerabilities in airport screening systems demonstrate that emphasis also needs to be placed on finding the bomber and not merely on finding the bomb. Finding the bomber will require placing a greater reliance on other methods such as checking names, conducting interviews and assigning trained security officers to watch for abnormal behavior and suspicious demeanor. It also means that the often overlooked human elements of airport security, including situational awareness, observation and intuition, need to be emphasized now more than ever.

Tuesday, March 10, 2009

Security Implications of the Global Financial Crisis


Fred Burton and Scott Stewart
Stratfor.com
March 4


Global Security and Intelligence Report


As anyone with a stock portfolio knows, it is a rough time for the markets. With many portfolios down 50 percent or more, this large loss of equity and wealth has been very difficult on individuals and corporations. The problems, of course, have not been confined to the stock markets. With property values plunging and variable-rate mortgages ballooning, many homeowners are also caught in a bad situation — the number of homeowners behind in their mortgage payments has been increasing and the number of foreclosures has grown. Unemployment is also an issue. According to the Bureau of Labor Statistics, in January 2009 there were 2,227 mass layoff actions in the United States involving 237,902 workers.

Significantly, the financial crisis is not just restricted to the United States — it is a global event that is also having a severe impact on economies in Europe, Asia and the developing world. Things are tough all over, and this financial strain will create some large security problems for corporations and governments.


Threats to the Bottom Line


During times of financial hardship, companies often have to make cuts like the aforementioned layoffs. When companies plan cuts, they often focus on eliminating those corporate functions that do not appear to be contributing to the company’s profitability. And one of the first functions cut during tough times often is corporate security. A security department typically has a pretty substantial budget (it costs a lot for all those guards, access-control devices, cameras and alarms), and security is usually viewed as detracting from, rather than contributing to, the company’s bottom line. The “fat” security budget is seen as an easy place to quickly reduce costs in an effort to balance the profit-and-loss statement.

This view of security is due to a number of factors. First, it must be recognized that there are certainly some security programs that are indeed bloated and ill-conceived that have consumed far too many corporate resources for the results they produce. Furthermore, there is a long tradition of corporate security directors who are not good communicators and who do not take the effort to educate upper management about ways their programs contribute to corporate goals. However, even when a security director has an effective program and is a good communicator, it can be very difficult to quantify the losses that the corporation did not suffer due to the presence of effective security measures. The lack of losses and incidents due to a robust security program can be interpreted by some to mean that there is no threat to guard against. Indeed, effective security can make it appear that there is no need for security, a paradox we have also seen in the historical pattern of U.S. government security funding — a pattern that has resulted in a number of disastrous attacks against U.S. embassies.

In times of economic hardship, the relentless focus on operating expenses and even corporate cutbacks can lead to definite security challenges. As we discussed last November, one of these problems is workplace violence, but during times when people are hurting financially, issues such as employee theft, fraud and product theft by non-employees must also be carefully monitored.

However, while the theft of a tractor-trailer full of computers or flat screen televisions can quickly get someone’s attention, there is a far more subtle, and no less dangerous, threat lurking just under the surface. That threat is espionage — both corporate and state-sponsored.


The Human-Intelligence Process


Espionage is always a problem corporations must face. Competitors, criminals and even foreign governments often seek ways to gather proprietary information from companies, sometimes to boost their own operational capacities (e.g., to apply critical or emerging technologies to their weapons programs) and sometimes to sell on the open market.

Once a company has been identified as having the information sought, the first thing the human-intelligence practitioner will do is look for weak links in the targeted company’s operations. If the required information is readily available, there is no need to undertake a time-intensive and costly operation to retrieve it. Indeed, it is shocking to see the amount of sensitive and critical information that is openly available on the Internet and in research libraries, or that is freely given out at technical conferences.

When open source collection efforts fail, more invasive measures must be employed. Sometimes the required information can be obtained via technical surveillance. A faulty information technology system, for example, can expose the company’s secrets via remote electronic intrusion conducted from a continent away. Other times, information can be obtained by eavesdropping on telephone calls made by corporate leaders or by using other technical surveillance measures.

However, technical surveillance has its limitations, and sometimes critical information must be obtained through human intelligence, which means obtaining the required data from an employee working within the targeted company. Due to human nature, human-intelligence practitioners use the same time-tested principles in the recruitment of corporate sources that they use when recruiting sources in the government sector. (The risks associated with obtaining unclassified proprietary information from private companies are often far less than those associated with obtaining classified information from government agencies or national research laboratories.)

The first step in the human-intelligence process is called spotting. This is when the human-intelligence practitioner attempts to identify those workers who have access to the required information. Then the practitioner conducts a thorough examination of the backgrounds and situations of the employees who have that access in an effort to determine which employee is most vulnerable to exploitation. Employees who are in dire need of extra cash to maintain extravagant lifestyles or to support drinking, drug or gambling habits, or those who are hiding extramarital affairs or other secrets that can be used for blackmail, make prime candidates. A background check might also reveal that a certain worker is angry with his or her employer over issues of salary or placement in the company. There also are employees who disagree ideologically with the product their company makes or the process the company uses to produce it. Finally, there are the employees whose egos are so big that they might be willing to risk committing industrial espionage just to prove they can get away with it. Robert Hanssen, an ex-FBI special agent accused of selling secrets to Russia, was motivated by the belief that he was above the system and could commit espionage without being caught.

Of the four major motivations for committing espionage — money, ideology, compromise and ego (known to security officials as MICE) — money has proven to be the No. 1 motivation, though two or more motivations can be used to turn an employee. More often than not, simple bribery is sufficient to obtain the desired information, especially if the employee is living beyond his or her means for one reason or another. Outside agents looking to turn an employee can also use blackmail (“compromise” in the MICE acronym). Demanding proprietary information in exchange for not exposing a personal secret, for instance, is a cost-effective approach that also allows the agent to return again and again to the same source. This method is a bit riskier, however, since it can cause more resentment than other means and make the source more likely to rebel. However, sexual entrapment and blackmail is still widely used as a recruitment tactic, one that has been used with great success in recent years by the Chinese government against targets such as Japanese and Taiwanese government officials, FBI special agents — and foreign businessmen.


Emphasizing the ‘M’


Once the practitioner has identified the weakest link, decided on the approach to take and made a specific plan on how to proceed, the next step in the human-intelligence process is to actually approach the employee and “pitch” him or her. This step is often a gradual effort to establish a relationship of trust between the practitioner and the employee, and contact can begin gradually with requests for small, seemingly harmless bits of information such as internal phone numbers. In this approach, known as the “little hook,” the employee is offered “gifts” in exchange for these favors. The requests gradually become greater in scope until the targeted information is obtained. Other times, the pitch is far more blatant and the human-intelligence practitioner does not take the time to establish a relationship or gradually recruit the target. Instead the practitioner makes a flat-out cash offer for the required goods or shows the target the evidence that will be used for blackmail.

In the current economic environment, with many 401(k) plans now more like 201(k)s, stock options severely underwater and homeowners facing foreclosure, cold hard cash — the M in MICE — is an even more attractive approach. In fact, with employees seeing their investment accounts decline dramatically, and perhaps even facing the possibility of home foreclosure, it is not at all unreasonable to anticipate that companies and foreigners will face a windfall of walk-in sources who will volunteer to sell critical information — and in such a buyer’s market, information can often be bought at fire-sale prices. Employees attempting to sell proprietary information are somewhat common; one of the most publicized examples of this in recent years was the disgruntled Coca-Cola Co. employee who was arrested in July 2006 after attempting to sell Coke’s recipe to rival soft drink company Pepsi.

Mass layoffs also complicate the equation, especially when some of the employees being laid off have access to critical information. If measures are not taken to ensure that the information is protected, the information could easily find itself in the hands of competing companies or even foreign intelligence services.


Not Just a Corporate Concern


The current financial crisis — and vulnerability to espionage — is not just confined to the private sector. There are many federal government employees in the United States who have watched their investments in the stock-based funds of the government’s Thrift Savings Plan wither on the vine over the past two years, and judging from the performance of foreign stock exchanges, the investments of employees in other governments have followed suit. Additionally, government employees tend to live in places with very expensive real estate, like Washington, London, Paris and Tokyo. This means that a foreign intelligence officer armed only with a briefcase full of dollars, euros or yen can make a substantial amount of money. With many corporate security departments being cut to the bone, many internal security services focused on the counterterrorism mission and many law enforcement agencies chasing white-collar criminals, it is a good time to be in the intelligence business.

One day we will look back on this time through a counterintelligence lens and see that, although it was a time of bear stock markets, it was a tremendous bull market for practitioners of human intelligence.

Wednesday, February 18, 2009

Mexico: The Third War


Fred Burton and Scott Stewart
February 18
Stratfor.com


Global Security and Intelligence Report


Mexico has pretty much always been a rough-and-tumble place. In recent years, however, the security environment has deteriorated rapidly, and parts of the country have become incredibly violent. It is now common to see military weaponry such as fragmentation grenades and assault rifles used almost daily in attacks.

In fact, just last week we noted two separate strings of grenade attacks directed against police in Durango and Michoacan states. In the Michoacan incident, police in Uruapan and Lazaro Cardenas were targeted by three grenade attacks during a 12-hour period. Then on Feb. 17, a major firefight occurred just across the border from the United States in Reynosa, when Mexican authorities attempted to apprehend several armed men seen riding in a vehicle. The men fled to a nearby residence and engaged the pursuing police with gunfire, hand grenades and rocket-propelled grenades (RPGs). After the incident, in which five cartel gunmen were killed and several gunmen, cops, soldiers and civilians were wounded, aut horities recovered a 60 mm mortar, five RPG rounds and two fragmentation grenades.

Make no mistake, considering the military weapons now being used in Mexico and the number of deaths involved, the country is in the middle of a war. In fact, there are actually three concurrent wars being waged in Mexico involving the Mexican drug cartels. The first is the battle being waged among the various Mexican drug cartels seeking control over lucrative smuggling corridors, called plazas. One such battleground is Ciudad Juarez, which provides access to the Interstate 10, Interstate 20 and Interstate 25 corridors inside the United States. The second battle is being fought between the various cartels and the Mexican government forces who are seeking to interrupt smuggling operations, curb violence and bring the cartel members to justice.

Then there is a third war being waged in Mexico, though because of its nature it is a bit more subdued. It does not get the same degree of international media attention generated by the running gun battles and grenade and RPG attacks. However, it is no less real, and in many ways it is more dangerous to innocent civilians (as well as foreign tourists and business travelers) than the pitched battles between the cartels and the Mexican government. This third war is the war being waged on the Mexican population by criminals who may or may not be involved with the cartels. Unlike the other battles, where cartel members or government forces are the primary targets and civilians are only killed as collateral damage, on this battlefront, civilians are squarely in the crosshairs.


The Criminal Front


There are many different shapes and sizes of criminal gangs in Mexico. While many of them are in some way related to the drug cartels, others have various types of connections to law enforcement — indeed, some criminal groups are composed of active and retired cops. These various types of criminal gangs target civilians in a number of ways, including, robbery, burglary, carjacking, extortion, fraud and counterfeiting. But of all the crimes committed by these gangs, perhaps the one that creates the most widespread psychological and emotional damage is kidnapping, which also is one of the most underreported crimes. There is no accurate figure for the number of kidnappings that occur in Mexico each year. All of the data regarding kidnapping is based on partial crime statistics and anecdotal accounts and, in the end, can produce only best-guess estimates. Despite this lack of hard data, however, there is little doubt — based even on the low end of these estimates -that Mexico has become the kidnapping capital of the world.

One of the difficult things about studying kidnapping in Mexico is that the crime not only is widespread, affecting almost every corner of the country, but also is executed by a wide range of actors who possess varying levels of professionalism — and very different motives. At one end of the spectrum are the high-end kidnapping gangs that abduct high-net-worth individuals and demand ransoms in the millions of dollars. Such groups employ teams of operatives who carry out specialized tasks such as collecting intelligence, conducting surveillance, snatching the target, negotiating with the victim’s family and establishing and guarding the safe houses.

At the other end of the spectrum are gangs that roam the streets and randomly kidnap targets of opportunity. These gangs are generally less professional than the high-end gangs and often will hold a victim for only a short time. In many instances, these groups hold the victim just long enough to use the victim’s ATM card to drain his or her checking account, or to receive a small ransom of perhaps several hundred or a few thousand dollars from the family. This type of opportunistic kidnapping is often referred to as an “express kidnapping”. Sometimes express kidnapping victims are held in the trunk of a car for the duration of their ordeal, which can sometimes last for days if the victim has a large amount in a checking account and a small daily ATM withdrawal limit. Other times, if an express kidnapping gang dis covers it has grabbed a high-value target by accident, the gang will hold the victim longer and demand a much higher ransom. Occasionally, these express kidnapping groups will even “sell” a high-value victim to a more professional kidnapping gang.

Between these extremes there is a wide range of groups that fall somewhere in the middle. These are the groups that might target a bank vice president or branch manager rather than the bank’s CEO, or that might kidnap the owner of a restaurant or other small business rather than a wealthy industrialist. The presence of such a broad spectrum of kidnapping groups ensures that almost no segment of the population is immune from the kidnapping threat. In recent years, the sheer magnitude of the threat in Mexico and the fear it generates has led to a crime called virtual kidnapping. In a virtual kidnapping, the victim is not really kidnapped. Instead, the criminals seek to convince a target’s family that a kidnapping has occurred, and then use threats and psychological pressure to force the family to pay a quick ransom. Although virtual kidnapping has been around for several years, unwitting families continue to fall for the scam, which is a source of easy money. Some virtual kidnappings have even been conducted by criminals using telephones inside prisons.

As noted above, the motives for kidnapping vary. Many of the kidnappings that occur in Mexico are not conducted for ransom. Often the drug cartels will kidnap members of rival gangs or government officials in order to torture and execute them. This torture is conducted to extract information, intimidate rivals and, apparently in some cases, just to have a little fun. The bodies of such victims are frequently found beheaded or otherwise mutilated. Other times, cartel gunmen will kidnap drug dealers who are tardy in payments or who refuse to pay the “tax” required to operate in the cartel’s area of control.

Of course, cartel gunmen do not kidnap only their rivals or cops. As the cartel wars have heated up, and as drug revenues have dropped due to interference from rival cartels or the government, many cartels have resorted to kidnapping for ransom to supplement their cash flow. Perhaps the most widely known group that is engaging in this is the Arellano Felix Organization (AFO), also known as the Tijuana Cartel. The AFO has been reduced to a shadow of its former self, its smuggling operations dramatically impacted by the efforts of the U.S. and Mexican governments, as well as by attacks from other cartels and from an internal power struggle. Because of a steep decrease in smuggling revenues, the group has turned to kidnapping and extortion in order to raise the funds necessary to keep itself alive and to return to prominence as a smuggl ing organization.


In the Line of Fire


There is very little chance the Mexican government will be able to establish integrity in its law enforcement agencies, or bring law and order to large portions of the country, any time soon. Official corruption and ineptitude are endemic in Mexico, which means that Mexican citizens and visiting foreigners will have to face the threat of kidnapping for the foreseeable future. We believe that for civilians and visiting foreigners, the threat of kidnapping exceeds the threat of being hit by a stray bullet from a cartel firefight. Indeed, things are deteriorating so badly that even professional kidnapping negotiators, once seen as the key to a guaranteed payout, are now being kidnapped themselves. In an even more incredible twist of irony, anti-kidnapping authorities are being abducted and executed.

This environment — and the concerns it has sparked — has provided huge financial opportunities for the private security industry in Mexico. Armored car sales have gone through the roof, as have the number of uniformed guards and executive protection personnel. In fact, the demand for personnel is so acute that security companies are scrambling to find candidates. Such a scramble presents a host of obvious problems, ranging from lack of qualifications to insufficient vetting. In addition to old-fashioned security services, new security-technology companies are also cashing in on the environment of fear, but even high-tech tracking devices can have significant drawbacks and shortcomings.

For many people, armored cars and armed bodyguards can provide a false sense of security, and technology can become a deadly crutch that promotes complacency and actually increases vulnerability. Physical security measures are not enough. The presence of armed bodyguards — or armed guards combined with armored vehicles — does not provide absolute security. This is especially true in Mexico, where large teams of gunmen regularly conduct crimes using military ordnance. Frankly, there are very few executive protection details in the world that have the training and armament to withstand an assault by dozens of attackers armed with assault rifles and RPGs. Private security guards are frequently overwhelmed by Mexican crimi nals and either killed or forced to flee for their own safety. As we noted in May 2008 after the assassination of Edgar Millan Gomez, acting head of the Mexican Federal Police and the highest-ranking federal cop in Mexico, physical security measures must be supplemented by situational awareness, countersurveillance and protective intelligence.

Criminals look for and exploit vulnerabilities. Their chances for success increase greatly if they are allowed to conduct surveillance at will and are given the opportunity to thoroughly assess the protective security program. We have seen several cases in Mexico in which the criminals even chose to attack despite security measures. In such cases, criminals attack with adequate resources to overcome existing security. For example, if there are protective agents, the attackers will plan to neutralize them first. If there is an armored vehicle, they will find ways to defeat the armor or grab the target when he or she is outside the vehicle. Because of this, criminals must not be allowed to conduct surveillance at will.

Like many crimes, kidnapping is a process. There are certain steps that must be taken to conduct a kidnapping and certain times during the process when those executing it are vulnerable to detection. While these steps may be condensed and accomplished quite quickly in an ad hoc express kidnapping, they are nonetheless followed. In fact, because of the particular steps involved in conducting a kidnapping, the process is not unlike that followed to execute a terrorist attack. The common steps are target selection, planning, deployment, attack, escape and exploitation.

Like the perpetrators of a terrorist attack, those conducting a kidnapping are most vulnerable to detection when they are conducting surveillance — before they are ready to deploy and conduct their attack. As we’ve noted several times in past analyses, one of the secrets of countersurveillance is that most criminals are not very good at conducting surveillance. The primary reason they succeed is that no one is looking for them.

Of course, kidnappers are also very obvious once they launch their attack, pull their weapons and perhaps even begin to shoot. By this time, however, it might very well be too late to escape their attack. They will have selected their attack site and employed the forces they believe they need to complete the operation. While the kidnappers could botch their operation and the target could escape unscathed, it is simply not practical to pin one’s hopes on that possibility. It is clearly better to spot the kidnappers early and avoid their trap before it is sprung and the guns come out.

We have seen many instances of people in Mexico with armed security being kidnapped, and we believe we will likely see more cases of this in the coming months. This trend is due not only to the presence of highly armed and aggressive criminals and the low quality of some security personnel, but also to people placing their trust solely in reactive physical security. Ignoring the very real value of critical, proactive measures such as situational awareness, countersurveillance and protective intelligence can be a fatal mistake.