Contributor

Competitive intelligence versus industrial espionage

Opinion
Aug 15, 20083 mins

Every organization should be aware of the types of techniques competitors use to gather intelligence on their business or operations.  It sometimes catches you by surprise to learn of the types of activity your competitors engage in.  A friend of mine once interviewed at one of the Big Four accounting firms (PwC, KPMG, E&Y, Deloitte.) The person she interviewed with was ex-agency (CIA, NSA, FBI). The questions she had to answer were very telling: reported last week that he believes he has found such an attempt registered out of China.  

1.    You are sitting on an airplane next to a consultant from a competing organization. He has his laptop open and is working on a proposal. Do you lean back and read that proposal?

2.    The airline passenger gets up to go to the bathroom, leaving a folder of documents on his seat. Do you leaf through it?

3.    You find some key documents in a hotel lobby relating to a competitor’s bid on the same project you are working on. Do you keep the documents or turn them in to the hotel unread?

Yes, large companies do employ people who are charged with gathering this type of information.  There are some great tools online for gathering competitive intelligence.  Knowing what Google keywords your competitor is purchasing as well as what their total spend is can be useful.  Page rank, Alexa data, banner ad programs are useful as well.

While some of this data cannot be hidden from snooping competitors there are some precautions you should be taking.  

1.    Make sure that you have no “unpublished” pages on your website. Directories such as /stage, /temp, /index2, /new, are easily discoverable.

2.    Configure your email servers so they do not bounce emails sent to unknown users.  Legitimate emails can be discovered by a lack of response from a brute force emailing to all combinations of first name – last name.

3.    Check regularly for registrations of domain names that are simple misspellings of your primary domain.

This last point is an interesting one.  Say an attacker is hoping to harvest interesting documents sent to your organization. Purchase orders, invoices, reports from your accountants, etc.?   They can register a domain that is a common misspelling of yours and collect any emails accidently sent to it.  A researcher at Symantec

There may be a fine line between competitive intelligence gathering and industrial espionage. In my mind, information that is in the public domain is legit for CI while internal documents are not.  You should protect yourself from the gathering of both types of intelligence.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author