On Tuesday evening, I found myself surrounded by classical British History in the prestigious rooms of the National Liberal Club. This is the Whitehall members’ club William Gladstone founded in 1882, and I’m not sure it’s decoratively changed much since then - it hasn’t needed to. My antique hunting alter-ego couldn’t help but wonder if some of the tiles were uranium-glazed, possibly.
The open-source intelligence firm Valinor Intelligence hosted the evening to mark the book launch of Private Sector Intelligence: How Corporations Navigate Geopolitical and Security Risk.

One of its authors, Lewis Sage-Passant, is Global Head of Intelligence for a major pharmaceuticals company and teaches intelligence at Sciences Po. His co-authors are Maria Robson-Morrow of Harvard’s Intelligence Project and Angela Miller Lewis, a senior adviser at Sibylline and a former CIA officer.
Lewis spoke about the central idea behind the book, that intelligence has never belonged only to governments and that companies have always needed ways to understand threats to their interests. He made the historical case in his earlier book, Beyond States and Spies. There are a great deal of lessons to follow between public and private.
By coincidence, the same day, UK Prime Minister Andy Burnham used his first address to the UN General Assembly to announce a National Centre for Information Defence, which he asked security chiefs to begin building to “detect, attribute and disrupt” hostile state information attacks.
I’ve included a link to the BBC report on the event below, where he told delegates that Russian agencies had used bots, fake websites, falsified newspaper articles and the forged branding of 28 British organisations, including universities and the BBC, and warned that AI will multiply the threat. This isn’t a surprise for me, given this is an issue I’ve been developing technology and advisory approaches around since 2019.
Both of these events reaffirm that information threats no longer just concern governments, but the entire private sector. Everything now is about national defence.
Companies have always had to manage instability
We often hear that the world has suddenly become more dangerous. I don’t think that is quite right - but for younger generations it’s an easy mistake to make. Political instability, propaganda, commercial espionage, conflict and disrupted trade have shaped corporate decisions for centuries.
The unusual part was the relatively calm period in which many Western companies could treat geopolitical risk as occasional. Globalisation allowed businesses to mistake an exceptional stretch of stability for the natural order of things. That period has ended, and strategic competition has returned to the centre of commercial life. As I regularly write about, sovereignty continues to be a key topic for not just debate, but strategic long-term decisions.
Amongst this is the ever-changing role of communications. This isn’t just a press release writing media pushing discipline, but a strategic function that speaks at board level. Advisory across the communications landscape has never been as important as this moment right now.
AI has made deception cheaper and reliable sources harder to reach
We all know that Generative AI has sharply reduced the cost of producing convincing text, images, audio and video. In 2023, I personally managed to create a deepfake of a CEO (as a test…) using only open-source solutions. The technology has drastically improved since then, including commercial frontier models with weak privacy checks.
Automated social media accounts can create the appearance of momentum, and networks of imitation news sites can make a claim look independently corroborated. Forged branding lets a false story borrow trust from organisations that had nothing to do with it, which is what the Prime Minister described happening to 28 British organisations. At the same time, only on Monday I published an extensive article about how the AI race is moving faster than the governance meant to control it; hostile actors exploit that gap.
Research by my team at Kekst CNC, where I co-lead the Intelligence function, points to a further weakness. Last month, we analysed the Gen AI policies of 4,467 news titles across 105 markets and 72 languages and found that 96.9% did not publicly disclose their position on access by generative AI models. Among the lead-market publications we examined, 32.2% blocked at least one model from sourcing their content.
Stakeholders increasingly form their view of a company and the issues around it through AI systems, and those systems do not necessarily have consistent access to authoritative information. Communications teams now have to consider what those systems can see, as well as what journalists and audiences read.
Hostile narratives are already reaching companies
In recent work, we identified 1,300 brand mentions across 170 unreliable publications. Many were politically motivated alternative publications or state-affiliated sources within the Pravda network, a group of pro-Kremlin sites. The analysis identified two potential routes to damage: either an existing issue accelerated by an external event, or a coordinated network sustaining a narrative until it moved towards more credible sources.
In another live case, a false story about a company circulated through a different disinformation network in English, Spanish and French. We assessed the network as comprising approximately 280 anonymously owned sites, and the story was then amplified by a mix of pro-Russian bots and real accounts.
A hostile narrative can damage a company long before most people have heard of it, if it worries investors, unsettles employees, alarms customers or draws the attention of journalists and regulators. Communications teams are usually among the first to be asked what that means for the business.
Companies need to know who is driving a story
Companies already monitor news and social media, and a dashboard (increasingly vibe-coded these days…) can show that a story is being shared. Intelligence asks who is driving it, whether their activity is coordinated, how quickly the narrative is travelling, which communities are carrying it and what might push it into the mainstream.
That requires visibility beyond established media and the major social networks. Relevant activity may emerge in fringe publications, forums, Telegram channels, dark-web environments or clusters of seemingly unconnected accounts. It then has to be classified by threat type and severity and tracked for how fast it is spreading, with human judgement applied before anyone makes a recommendation.
No single platform provides a complete view, because news licensing, social data, private channels and specialist sources remain fragmented. Effective intelligence combines these sources and applies editorial and analytical judgement to decide which mentions matter. The reality is that intelligence still depends upon human community, as it’s private conversations that take insights a step further.
Readiness has to be in place before an attack
From what I can see, the larger corporate weakness is a tendency to confuse awareness with readiness. A company cannot improvise an intelligence capability in the first hours of an information attack. Readiness requires persistent visibility across the information environment and human assessment of intent and likely impact. It also means preparing scenarios before a threat starts spreading quickly, and agreeing in advance how communications, security, legal, risk and senior leadership will work together.
Internal AI governance matters too. The same technologies that let hostile actors create and distribute deceptive material can open vulnerabilities inside companies if permissions, data controls, ownership and escalation routes are not properly understood.
The National Centre for Information Defence is a signal to every major organisation. If the Government believes information attacks must be continuously detected, attributed and disrupted, companies should ask whether their own approach can still begin only once the damage is visible.

The world has returned to its more normal level of geopolitical risk, with faster technology and less certainty about what is authentic. When the next information attack reaches a company, its communications team will be asked what is happening and what to do. The test will be whether the intelligence, relationships, governance and decision-making structures needed to answer were already in place.
Thanks to Valinor Intelligence for hosting, and to Lewis Sage-Passant for the conversation. If you’re working through any of this in your own organisation, the comments are open, and so is my inbox.


Of the Prime Minister's three verbs (detect, attribute, disrupt), the middle one is where companies should be most careful. A government can name a hostile state. A company that does so has taken a side in a contest it cannot control, and the story becomes the accusation rather than the lie. The stronger position is usually to establish and publish what is true about its own business, quickly, and leave attribution to the state, with the evidence handed over quietly.
Which is one more argument for your case. The intelligence has to be good enough to know who is behind it, precisely so the company can choose not to say so.