Riku Ruokolahti: Reputation is a key force against information manipulation

In the information war, the battle is fought for people’s minds, and democracy as a system is based on people’s minds. It is precisely for this reason that democracy, with all its institutions, is particularly vulnerable when an information influencer strikes. An organization’s reputation, in turn, is shaped by the shared perceptions people hold about each organization. This article explores information and cyber influence from the attacker’s perspective, as well as how organizational reputation relates to the issue.

From a cyberattacker’s perspective, it is essentially a matter of machines and people, as well as the relationships of trust between them—and, more specifically, the exploitation of those relationships of trust for the attacker’s benefit.

 



 

Let’s take an example. You receive a message from your child’s teacher that seems surprising but harmless. The message recaps what’s been happening in class. You reply to the message and mention some health-related issues concerning your child that the teacher already knows about. Except that they don’t. They don’t know because the sender of the message isn’t the teacher, but a malicious attacker who knows you all too well. You’ve just revealed more personal information to them by mentioning your child’s health condition. The next message contains an attachment related to this very health condition, which you open despite your computer’s warnings. Of course you open it. Very few people wouldn’t.

You guessed right. The attachment is a sophisticated piece of malware.

The attacker in this case has done his reconnaissance and carefully prepared for the attack. He has exploited your vulnerabilities as well as the relationship of trust between you and your teacher, and now he is exploiting the computer’s relationship of trust with its administrator. As the administrator, you opened the attachment despite the warnings. At this point, the attacker has gained access to your computer and is exploiting the trust relationships between the computer’s internal interfaces. And once access was granted as a trusted entity, the computer no longer questions those trust relationships as easily. Somewhere deep within your computer lies a lesser-known programming flaw that the attacker continues to exploit between your computer’s programs and your workplace’s internal network. After all, there is a trust relationship between your workplace’s internal network and your computer. Whether we’re talking about computers or people, trust is at the heart of an attacker’s work.

If you encounter an attack that has been prepared with such care, you are likely dealing with confidential information or an organization of interest to the attacker. The ultimate target of an advanced attack is rarely a single person.

As we saw in the previous example, the cyber world isn't just focused on affecting machines; a key aspect of cyberattacks is also messing with people.

This leads us naturally to the information environment and, further, to the influence of information. At T-Media, we once conducted a longitudinal study that delved deeply into Finnish values. This was by no means a hastily cobbled-together set of questions; rather, in qualitative interviews, we heard from a very wide range of key opinion leaders (including the archbishop, the office of the president, state secretaries, influential figures in the arts and culture, senior citizens’ organizations, labor unions, think tanks, business representatives, young people, and representatives of various minority groups). Based on this groundwork, we created a quantitative metric that delved deeply into the values prevailing among Finns and their future changes. The study was given a name that did justice to the effort that went into it. The study was named “The People’s Values.”

 


[:fi]People's Values logo[:]

THE "PEOPLE'S VALUES" STUDY
The “People’s Values” study, developed and conducted by T-Media, was part of the Economic Information Agency (TAT)’s efforts to assess changes in its operating environment. This extremely interesting study was cut short due to a lack of funding when the Economic Information Office TAT refined its strategy and shifted its focus to young people. Along the way, the name also changed: the Economic Information Office TAT is now known as “Economy and Youth TAT.”

 

Various public opinion polls and their interpretation are standard tools for intelligence services. They can be used, for example, to anticipate social changes or, at their most extreme, to attempt to predict how Ukrainians might react to a potential occupier. Research data is also an important tool in information operations. The “People’s Values” research report would have been a real treasure trove for a malicious attacker. The study revealed more than just values and how they are changing. It revealed the polarization of values—that is, the issues on which citizens strongly disagree with one another. It is precisely this information that is valuable to an aggressor in the context of information warfare.

When an attacker identifies social divides, they can effectively stir up discord among people. By intensifying this discord, people are driven apart and mistrust is sown, which in turn undermines national unity and further impairs the nation’s ability to make decisions and take action. This destabilizes entire nations. One need only read the news or look around to understand just how effective this is. American democracy creaked at the seams during the last two presidential elections and their aftermath. Information influence is also said to have played a key role in Britain’s exit from the EU.

 


NEW WORDS AS PART OF INFORMATION INFLUENCE
An attacker might, for example, slip terms and neologisms into our everyday language through online discussions, causing polarization and discord. These terms slip unnoticed into our everyday language, and a determined information influencer can watch the terminology they’ve coined take on a new life in the mouths of politicians, on talk shows, and even on TV news. It is difficult to trace the true origin of these terms later on, especially since information influence is a long-term endeavor: these purposeful words may have been in use for over a decade. We may even use the language of the information war ourselves without realizing it. For example, before the war in Ukraine, anyone who argued on behalf of NATO was very easily labeled a “NATO hawk,” while criticism of the Russian government has, in turn, been attempted to be labeled as “Russophobia.”

 

The functioning of institutions depends on the trust of individuals

Society consists not only of people but also of institutions. In this context, “institutions” refers to specific organizations operating within the sphere of public authority, and they represent fertile ground for a malicious attacker. Citizens’ trust in their institutions is an absolute prerequisite for a functioning society. It is, however, in the attacker’s interest to undermine citizens’ trust in the social system.

At this stage, we’ll take the attacker’s perspective alongside the defender’s and also look at things through the eyes of a mediator. We’ve already become quite cunning at this point, and it’s high time we started building trust around us alongside our destructive efforts.

As part of T-Media’s Reputation&Trust, we measure the level of stakeholder support among citizens for each public-sector organization. This stakeholder support encompasses citizens’ trust in the organization, trust during a crisis, a desire to hear the organization’s views, a willingness to support the organization through tax dollars, a willingness to work for the organization, and the likelihood of speaking positively about the organization.

These forms of trust and behavior on the part of individuals in relation to a publicly funded organization are, in a word, the social conditions for that organization’s operation. And from the perspective of information influence, it is precisely these operating conditions that an attacker seeks to undermine and that we, as members of society, want to defend.

 

How can an organization's operational capabilities be defended in an information war?

In order to build—and, when necessary, defend—an organization’s operating conditions, it is essential to understand where they come from. The purpose and history Reputation&Trust center precisely on this question. In developing the model, we sought to identify, isolate, and articulate the generic perceptions associated with organizations that are linked to stakeholder support—that is, the operating conditions for a public-sector entity.

Reputation&Trust anseende models an organization’s anseende based on eight different factors. Learn more about the model.

Reputation&Trust has been widely applied to public sector organizations for years. The number Reputation&Trust individual Reputation&Trust in the public sector is impressive. This body of consistently conducted surveys provides an opportunity to view the collected data as a whole and delve deeper into the subject.

The accompanying meta-analysis shows us the link anseende the operating conditions of the public sector. The meta-analysis yields a statistical model indicating that anseende affect stakeholder support for the public sector by a factor of 1.11 on average. Based on this study, it can be confidently argued that reputation is a key factor for the operating conditions of institutions and, by extension, society. By building their reputation, institutions earn the trust of citizens and increase their resilience in the event that attempts are made to undermine their operating conditions.

The observed slope is, of course, an opportunity for both the attacker and the defender: Even anseende undermines the conditions for action when the slope is positive. Similarly, proactive reputation management builds crisis resilience when the slope is positive.

 


 

A Meta-Analysis of Public Sector Reputation&Trust Studies
Each point in this figure represents a public administration organization analyzed Reputation&Trust between 2018 and 2021. The position of each point in the figure is based on the organization’s statistically modeled reputation and stakeholder support. The horizontal axis represents the organization’s reputation, and the vertical axis represents stakeholder support. Stakeholder support is derived from the average of the organizational operating conditions measured as described above (trust, willingness to speak positively, and so on). Reputation, in turn, is the organization’s reputation statistically modeled using Reputation&Trust. The statistical margin of error for each individual survey (a point on the map) depends on the standard deviation of the responses in that survey, but for all the surveys presented here, it falls between 0.04 and 0.06 on the 1–5 scale shown in the figure. The data set includes a large number of different Finnish public sector organizations.

 

Visibility is part of the defense

A representative of an institution might now be tempted to think that reputation issues are irrelevant to the general public if the organization is not very well known. This could be a dangerous way of thinking. I’ll explain why below.

The following illustrates the brand awareness of two different organizations.

 

Very few people are familiar with Organization A, whereas almost every Finn knows Organization B, at least by name. And when someone says they know an organization by name, they probably already know considerably more about it than just a combination of letters. A name isn’t easily remembered unless it’s associated with a specific thing or image.

From an attacker's perspective, these organizations are very different from one another. The public has a clear image of one organization, while very few people are even aware that the other one exists.

Does this mean, then, that Organization A—which is relatively unknown—doesn’t need to worry about its reputation from the perspective of information influence? Unfortunately, this is not the case. In fact, from the perspective of information influence, Organization A may be an easier target than Organization B.

When there are virtually no preconceived notions, perceptions associated with an organization can quickly arise at the initiative of someone other than the organization itself. This may have been the case, for example, with the National Audit Office (VTV). I am not claiming that the events surrounding VTV’s reputation crisis were specifically driven by an information influencer, but VTV is a good example of how the public perception of a little-known institution can very quickly become dominated by negative perceptions. Today, VTV is a well-known organization.

The phenomenon described above is, of course, an opportunity for an attacker. In a way, one might think that it would make sense for a publicly funded, nationally significant institution to keep citizens informed, at least to some extent, about the institution’s existence, activities, and objectives.

I suggested that, from an attacker’s perspective, Organization A might be an easier target than Organization B, but this is not a given. The situation depends on Organization B’s reputation. Being well-known in and of itself does not equate to direct defensive capability. Let’s imagine that Organization B were the National Audit Office (VTV) with its current level of public recognition. Any new negative information about the organization—whether true or false—would fall on fertile ground from the attacker’s perspective. The reception of new information would be influenced by confirmation bias: citizens would be quite willing to believe new negative claims about VTV as well, because they would reinforce their existing perceptions of the organization. Consequently, it would be considerably easier to undermine the VTV’s ability to function than, say, that of the police.

Given its reputation, Organization B could, for example, be the police, which enjoys a fairly strong reputation and public trust. From the attacker’s perspective, this is precisely why it is difficult to undermine the police’s standing. Negative information about a reputable organization is not readily believed, even if it is true.

This phenomenon, in turn, is cognitive dissonance. In short, it refers to the uncomfortable feeling that arises when we receive information that does not align with our own worldview. We easily dismiss such information and move on. In such cases, cognitive dissonance arises anseende strong anseende and is, in itself, a key defense mechanism. After all, as communication consultants often say, “Reputation carries you through crises.” And that may very well be true!

Just to be clear, organizations A and B are not the National Audit Office (VTV) or the police. The awareness surveys refer to example organizations, which remain anonymous in this context.

From the perspective of information influence, low visibility poses a risk to an institution, even though visibility in and of itself does not create resilience for the organization. Resilience in information influence stems anseende good anseende , and a good reputation must be earned and built even before problems arise, so that the buffer of trust and reputation can withstand disruptions caused by unexpected situations.

 


WHAT, IS FINLAND A CORRUPT KLEPTOCRACY?
Even if it were difficult to undermine a key institution, this does not mean that attempts to do so would not continue. Time is on the attacker’s side. Over the long term, every organization will encounter mistakes or problems that a persistent attacker can exploit by stepping up their ongoing information operations.
We Westerners view the Russian political system as a corrupt kleptocracy. Right now, in the spring of 2022, an attacker with the will, resources, and timing afforded by an accurate assessment of the situation could effectively destabilize the Finnish system from the very perspective we ourselves have created. By leaking real or fabricated allegations of corruption from the National Audit Office and linking these—using the Jari Aarnio case—to a narrative of police corruption, a sophisticated attacker could take advantage of this window of opportunity and sow the seeds of doubt among the public that that our own system is a corrupt kleptocracy.

 

anseende is extremely sensitive information

Let’s return to the cyber world for a moment. Silverskin Information Security tests various systems by attacking them systematically—but with permission, or rather, at the request of the organizations involved. Intensive penetration testing is sure to be noticed. At the very least, alarm bells should go off when an attacker tries everything possible—and impossible—at the same time.

Based on the events of the penetration test, a report is prepared for the client that reviews all the attack techniques and methods tested. The report also includes information on which methods got past the defenses and how far they got. Corrections are recommended for any security vulnerabilities found. Take a guess: is the report described above considered sensitive information? From an attacker’s perspective, the report is essentially a guide on how to gain access to the target system reliably, elegantly, and undetected. And if something has been fixed, the report also reveals exactly how it was fixed.

anseende organization-specific anseende based on statistics is, from the perspective of the information war, a report of exactly the same value. The impact analysis is based on correlation and regression analyses, and it directly reveals which organization-specific perceptions have the greatest impact on the operating conditions of that particular institution. The analyses also reveal which perceptions are weaker—that is, which areas of the organization’s reputation people know the least about or on which perceptions they strongly disagree. A sophisticated attacker would use the report in the following way:

 

  1. Based on the impact analysis, identify the factors that most build and undermine trust in the target organization.
  2. It would examine the polarization analysis of anseende components and select the anseende that exhibits both the strongest disagreement and the greatest lack of knowledge.
  3. It would target a massive information campaign with surgical precision at precisely that anseende the target organization’s anseende where influence, disagreement, and ignorance converge.

 

By doing so, an attacker could undermine the trust placed in the target institution with incredible effectiveness. All the blows would land precisely where the armor is weakest or nonexistent, and where a vital internal organ lies beneath the armor.

From an attacker’s perspective, the final report of a penetration test and the impact analysis Reputation&Trust are essentially the same thing. They are like ready-made strategies guaranteed to succeed. They are the same for the defender as well, but from the defender’s perspective, success is not as certain, and the defender cannot afford to wait for the right moment. In many ways, breaking the rules is easier and faster than systematically building something beautiful. That is precisely why crisis resilience must be built—both in the cyber world and in the world of reputation—continuously, purposefully, and, above all, during times of peace.

 


 

Sometimes completely different paths can lead to the same destination

This time, cybersecurity and reputation ended up in the same parking spot, reflects the author of this article, Riku Ruokolahti, Head of Development at T-Media and lead developer Reputation&Trust . In addition to anseende , Riku has made anseende in various behind-the-scenes roles related to cybersecurity. Most notably, he has served on the board of the cyberattack firm Silverskin Information Security Oy for over ten years and has worked as an investor and management advisor at Cyber Intelligence House, a company specializing in dark web intelligence.

Silverskin’s core philosophy is to enhance the overall security of businesses and societies by examining institutions from an attacker’s perspective and proposing corrective measures based on this analysis. CIH, in turn, collects information and monitors phenomena, events, crimes, and data breaches that occur under the cover of anonymous networks. Law enforcement agencies (including INTERPOL), societies, and companies utilize the data collected by CIH to prepare for and respond to threats.

The article’s content and attack scenarios were reviewed by cybersecurity expert Mikko S. Niemelä. Mikko founded the cyberattack firm Silverskin and Cyber Intelligence House, which specializes in cyber intelligence. In addition, Mikko teaches cybersecurity at the National University of Singapore and serves as an advisor to organizations such as the United Nations Office on Drugs and Crime (UNODC) and INTERPOL.

 

Similar Posts