scieee AI-readable full text Open interactive document viewer

Cyber HUMINT In Cybersecurity: A Content Analysis

Koivula, Juho Hermanni

Full text

Juho Koivula CYBER HUMINT IN CYBERSECURITY: A CONTENT ANALYSIS JYVÄSKYLÄN YLIOPISTO INFORMAATIOTEKNOLOGIAN TIEDEKUNTA 2024 TIIVISTELMÄ Koivula, Juho Cyber HUMINT In Cybersecurity: A Content Analysis Jyväskylä: Jyväskylän yliopisto, 2024 Turvallisuus ja strateginen analyysi, pro gradu -tutkielma Ohjaaja: Moilanen, Panu Tutkimuksen aihe on englanninkielinen termi ”cyber HUMINT”. HUMINT tarkoittaa henkilötiedustelua, joka on ihmisten avulla ja/tai ihmisiltä kerättyä tietoa. Kyber-etuliite termissä ”cyber HUMINT” tarkoittaa, että sitä toteutetaan kyberavaruudessa, joka on keinotekoinen ympäristö. Sen mahdollistavat toisiinsa kytketyt järjestelmät ja verkot. Tutkimuksessa tarkasteltiin analysoimalla yksityisten kyberturvallisuusorganisaatioiden verkkosisältöä vastaamalla kysymykseen: ”mitä on cyber HUMINT kyberturvallisuudessa?” Tutkimuksessa käytetään sisällönanalyysiä ja hyödynnetään erilaisia akateemisia lähteitä sen selvittämiseksi, miten henkilötiedustelu toimii perinteisesti ja digitaalisella aikakaudella. Tutkimusmenetelmäksi on valittu laadullinen sisällönanalyysi, joka on systemaattinen lähestymistapa analysoida ja tulkita eri verkkosisällön tarjoajien sisältöä ”cyber HUMINT” -toiminnasta kyberturvallisuudessa. Lähestymistapa noudattaa amerikkalaista perinnettä, ja siinä ryhmitellään samankaltaista ja osiin purettua sisältöä ja luodaan siten hierarkkinen rakenne, jossa suuremmat samankaltaiset ryhmät muodostavat kokonaisuuden. Ensimmäinen alakäsiteluokka kattaa tekniikat, joilla saadaan tietoa uhkatoimijoiden aikeista ja kehittyvästä uhkakuvasta. Toisessa kategoriassa korostetaan proaktiivisen kybertiedustelun keräämisen merkitystä mahdollisten kyberuhkien tunnistamisessa ennen kuin ne aiheuttavat vahinkoa. Jälkimmäisessä korostetaan ”cyber HUMINT” -toiminnan roolia kyberuhkatiedustelussa ja painotetaan sen merkitystä torjuntastrategioiden muodostamisessa kyberuhkakuvan avulla. Kokonaisuudessaan kyseessä on proaktiivinen lähestymistapa ihmiskeskeisessä kyberuhkatiedustelussa. Tutkimuksen johtopäätöksenä on, että ”cyber HUMINT” on merkittävässä asemassa uhkatietojen keräämisessä henkilölähteiltä kyberturvatoimien tehostamiseksi. Tutkimuksessa korostui kyberturvallisuuden, kybertiedustelun ja kyberavaruudessa ja digitaalisessa maailmassa tapahtuvan toiminnan inhimillinen osa-alue. Tutkimuksessa syvennyttiin siihen, miten teknologia muuttaa henkilötiedustelumenetelmää kyberturvallisuuden viitekehyksestä. Tärkeinä näkökulmina nousivat esiin automatisaatio operaatioiden skaalaamiseksi, toiminnan eettisyys ja lain noudattaminen ihmiskeskeisyyden vuoksi. Avainsanat: cyber HUMINT, henkilötiedustelu, HUMINT, kyberturvallisuus, kyberuhkatiedustelu ABSTRACT Koivula, Juho Cyber HUMINT In Cybersecurity: A Content Analysis Jyväskylä: University of Jyväskylä, 2024 Security and Strategic Analysis, Master’s Thesis Supervisor: Moilanen, Panu The subject of the study is "cyber HUMINT." HUMINT means human intelligence collected by humans and/or from humans. The cyber prefix in the term "cyber HUMINT" means that it is conducted in cyberspace, an artificial environment. Interconnected systems and networks enable it. The study analyzed the online content of private cybersecurity organizations by answering the question, “What is cyber HUMINT in cybersecurity?” The study uses content analysis and draws on various academic sources to explore how human intelligence works in the traditional and digital era. The research method chosen is qualitative content analysis, a systematic approach to analyzing and interpreting the content of various online content providers' "cyber HUMINT" on cybersecurity. The approach follows the American tradition of grouping similar and disaggregated content to create a hierarchical structure where larger similar groups form a whole. The first subcategory covers techniques to gain insight into the intentions of threat actors and the evolving threat landscape. The second category highlights the importance of proactive cyber intelligence gathering to identify potential cyber threats before they cause damage. The latter highlights the role of "cyber HUMINT" in cyber threat intelligence and emphasizes its importance in forming preventive strategies based on the cyber threat landscape. Overall, this is a proactive approach to human-centered cyber threat intelligence. The study concludes that cyber HUMINT plays a significant role in gathering threat information from human sources to enhance cyber security measures. The study highlighted the human dimension of cybersecurity, cyber intelligence, and operations in cyberspace and the digital world. The study delved into how technology is transforming the method of human intelligence from a cybersecurity perspective. Automation to scale up operations, the ethics of operations, and compliance with the law due to human-centricity emerged as important perspectives. Keywords: Cyber HUMINT, Cyber Threat Intelligence, Human Intelligence Collection, HUMINT, cybersecurity TABLES TABLE 1 The data-driven content analysis process ............................................... 31 TABLE 2 Examples of content analysis, from Citations to Reductions ............... 35 TABLE 3 Examples of grouping of Lower classes .................................................. 35 TABLE 4 Categorization of Classes towards Main Combined Class ................... 37 INDEX TIIVISTELMÄ ................................................................................................................. 2 ABSTRACT ...................................................................................................................... 3 TABLES ............................................................................................................................ 4 INDEX .............................................................................................................................. 5 1 INTRODUCTION ................................................................................................. 7 1.1 Research Purpose ......................................................................................... 8 1.2 Research Problem and Question ............................................................... 9 1.3 Research Structure ..................................................................................... 10 1.4 Research Concepts ..................................................................................... 11 1.4.1 What is intelligence? ........................................................................ 11 1.4.2 What is an intelligence collection discipline? ............................... 12 1.4.3 What is cyber espionage? ................................................................ 13 1.5 Research Literature .................................................................................... 14 2 LITERATURE REVIEWS ON TRADITIONAL AND CYBER HUMINT .... 16 2.1 What is Human Intelligence (HUMINT)? .............................................. 16 2.1.1 How is HUMINT defined? ............................................................. 16 2.1.2 What is an agent-acquisition cycle? ............................................... 17 2.1.3 What are the covers for clandestine and covert HUMINT? ....... 18 2.1.4 What are the costs and the benefits of HUMINT? ....................... 19 2.2 What is meant by cyber-prefix in the context of cyber HUMINT? .... 20 2.2.1 What is Cyber-HUMINT? ............................................................... 21 2.2.2 What is Cybernetic HUMINT? ....................................................... 23 2.2.3 What is Cyber-enabled HUMINT? ................................................ 24 2.2.4 What is HUMINT in the Cyber Age and Hybrid Intelligence? . 24 2.2.5 What is the human domain in cyberespionage? .......................... 25 2.3 How do traditional and cyber HUMINT differ from each other? ...... 25 2.4 Summary ..................................................................................................... 27 3 RESEARCH METHOD AND PROCESS .......................................................... 29 3.1 Research Data ............................................................................................. 30 3.2 Research Method ....................................................................................... 30 3.3 Research Process ........................................................................................ 31 4 PROACTIVE CYBER HUMAN THREAT INTELLIGENCE ........................ 37 4.1 Covert Human Threat Intelligence Professionality .............................. 38 4.1.1 Exploiting the Human Attack Vector ............................................ 38 4.1.2 Denial and Deception ...................................................................... 39 4.1.3 Threat Intelligence Process ............................................................. 39 4.1.4 Professionals ..................................................................................... 39 4.1.5 Conclusion ......................................................................................... 40 4.2 Proactive, Compliant, and Scalable Cyber Intelligence Tool .............. 40 4.2.1 Proactive Intelligence Methodology .............................................. 41 4.2.2 Benefits, Potentiality, and Challenges ........................................... 41 4.2.3 Cyber Intelligence Tool.................................................................... 42 4.2.4 Conclusion ......................................................................................... 43 4.3 Proactive Cyber Human Threat Intelligence ......................................... 43 5 DISCUSSION ....................................................................................................... 45 6 CONCLUSION .................................................................................................... 49 REFERENCES ................................................................................................................ 50 1 INTRODUCTION This study is called “Cyber HUMINT in Cybersecurity: A Content Analysis.” HUMINT means human intelligence collection. Human intelligence is processed information gathered by humans and/or from humans. Cyber-prefix indicates HUMINT being conducted in cyberspace, an artificial environment made possible by interconnected systems and networks. The context of cyber HUMINT in this study is cybersecurity. Content analysis is the chosen research method. The content comprises private cybersecurity and security companies and organizations providing consultancy and/or learning courses on cyber HUMINT. This study aims to examine the digitization of human activities related to security. The focus is understanding how human intelligence collection and espionage operate in a digitalized world. While cyber espionage heavily relies on technology, it is important to remember that humans are the primary users of the internet and other interconnected networks. Espionage is considered the ”second oldest profession” (Lowenthal, 2020, p. 125). Spying methods have adapted through the ages (Musco, 2017). Lucas Kello (2017) thinks we are in a cyber revolution that cuts through the whole human domain. In Kello’s estimation, we are in an age of cyber revolution, as evidenced by the rapid expansion of cyberspace into nearly every facet of human activity and the disruptive rebalancing of actors and their activities in the international order,[...]. (Kello 2017, Gioe et al., 2020) Kenneth Geers (2015) emphasizes the growing significance of cyber espionage as more individuals, devices, and networks interconnect. Cyber espionage has become a highly organized and intensified activity. Various means of cyber influence can be utilized for different purposes, which are the spy's tools for gathering information. (Lehto & Neittaanmaki, 2015, pp. 73–83). Cyber advances intelligence collection and, at the same time, adversarial espionage. Emergent technologies have enabled the field of intelligence collection to have a vast global reach from a distance. Gioe (2018) suggests enabling intelligence collection types with another type and gives “HUMINT-enabled cyber-operations” and “cyber-enabled 8 human intelligence” as examples in the literature (Gioe, 2018). The term “HUMINT” means human intelligence, which is a type of intelligence-gathering discipline involving human sources. Merriam-Webster defines the word enable as follows (Merriam-Webster, 21.3.2023): • “to provide with the means or opportunity” • “to make possible, practical, or easy” • “to cause to operate” • “to give legal power, capacity, or sanction to.” Cyber technology and digitalization enable traditional human intelligence collection to work with digital technology and in cyber environments. Digitalization and cyber affect intelligence collection across the field. Lowenthal asks whether cyber espionage is, for example, a form of human intelligence or a new form of intelligence collection (Lowenthal, 2017, p. 153). Lowenthal (2020) gives the following perspective on a methodology (refers to INT as a collection discipline) and technology: The view here is that cyber in and of itself is not an INT. It is a technology that makes various types of intelligence, just as satellites do, for example. The types of intelligence provided by cyber may fall into several different categories, but cyber itself does not define an INT. (Lowenthal, 2020) Information on human intelligence is obtained from human sources (Lowenthal, 2017, p. 143). Through cyber, one can conduct all the so-called “INTs.” Cyber cuts through all collection disciplines as a technology. Every collection discipline works interconnectedly through networks. This research was motivated by how human intelligence collection adapts in a cyber age. 1.1 Research Purpose Next, I will explain the purpose of the research. The research is exploratory because the topic has yet to be defined under one concept. It elaborates on technology adoption in conventional human activity, which is a particular example of a general digitalization trend. The research also highlights the gap between two research frameworks: intelligence and cybersecurity. As the research's approach is exploratory, it examines human activity in a new emerging environment. The motivation is to explore the phenomenon of cyber HUMINT in cyber security. Devanny and others (2021) state that there is a need for further research in the field of cyber-related human intelligence (Devanny et al., 2021). Amit Steinhart (2014) explains why research literature on HUMINT and cyber HUMINT is scarce as follows: Many HUMINT success stories are understandably classified, and even those that are public are regularly censored, omitting key details regarding the modus operandi, 9 technologies, and precise strategies used. It is hard to locate credible literature dealing with HUMINT, both academic and popular literature [18]. Often, HUMINT literature is touched with disinformation for the obvious reason of safeguarding “secrets of the trade”. (Steinhart, 2014) Researching this topic helps us to understand how technology enables human activity on a more conceptual level. On a more practical level, this research would help recognize new threats to organizational security (state, corporate, etc.) and new ways to counter those threats. Gioe (2017) weights the future of technology-enabled HUMINT as follows: In the cyber era, HUMINT will become even more complex, and case officers, their managers, and their political masters will need to understand the significant role of technology in their operations, the creative and persistent counterintelligence threats, and how intelligence collection is evolving faster than ever before. (Gioe, 2017). The research is focused on a topic that involves two different frameworks. If cybersecurity and intelligence operations are not studied together, an unseeable gap could exist. As an intelligence collection discipline, HUMINT has a framework that is different from that of cybersecurity. Cyber security is technically oriented, while human intelligence is process-oriented. This research focuses on the human side of cyber security through human intelligence collection. 1.2 Research Problem and Question Next, I will introduce the research problem and the research question. The research problem concerns digitalization and traditional human activity in the realm of security. The research question is a specific query about how the more general research problem is solved, particularly regarding cyber HUMINT in the context of cybersecurity. The research problem is how human intelligence collection as a traditional human activity instantiates in a digitalized world. According to Merriam-Web- ster, digitalization means “the process of converting something to digital form” (Merriam-Webster, no date). When information is increasingly available digitally, know-how and means should adapt to meet contemporary demands if one aims to acquire the required information in the digitalized world. Without digital information-gathering methods, much data remains out of reach. One of the problems was that there was no consensus on definitions of digitalized human intelligence collection. There are differing views on whether it is a new discipline in total, a subcategory, or an expansion. The research problem and the research literature guided the forming of the research questions. The frameworks behind the research question were the methodology of human intelligence collection (HUMINT) and cyberspace as a milieu of cyber espionage. Multiple concepts denote human intelligence collection and human-targeting espionage in cyberspace or other digital milieus. Here, cyber 16 2 LITERATURE REVIEWS ON TRADITIONAL AND CYBER HUMINT 2.1 What is Human Intelligence (HUMINT)? 2.1.1 How is HUMINT defined? Next, I will explain the definition of HUMINT as an intelligence collection discipline. Here, I will explain how it involves humans as intelligence operatives and agents as intelligence sources, including the recruiting process. I will also explain other measures in addition to the recruiting process. Targeted sources in human intelligence are, by name, humans (ICD Stottlemyre, 2015). Human intelligence (HUMINT) is a collection discipline. Loch Johnson (2010) defines “narrowly” that HUMINT targets and recruits people with access to restricted, classified, or confidential information. Johnson (2010) adds that HUMINT includes any directly collected information by ”human beings”. He also includes “clandestine acquisition of documents and other secrets”. Human intelligence also includes seeking information and planting spying devices. (Johnson, 2010). When a representative of a human intelligence organization exchanges information with a human intelligence colleague from another country, the human source is a foreign liaison (Johnson, 2010; Lowenthal, 2020, p. 129). HUMINT includes collecting information via interviewing and interrogating (Dando & Ormerod, 2020). Johnson (2010) calls the direct acquirement of information by intelligence operatives from targets “the James Bond Approach” (Johnson, 2010). Information can thus be obtained from individuals without agent acquisition. Robert D. Steele (2010) holds that clandestine and covert HUMINT are a small part of the whole of HUMINT, but they are the key activities when used correctly. When open sources are not enough, then clandestine and covert HUMINT sources should be activated (Steele, 2010). Acquiring information illegally means espionage (Johnson, 2010). Steele (2020) references Gen. (retired) Anthony Zinni that only a small minority of sources used to support his own decision-making are actually “classified” (Zinni; Steele, 2010). In this thesis, I will concentrate on clandestine and covert HUMINT. Acquiring information illegally means espionage (Johnson, 2010). Even though HUMINT is a small part of the larger picture of intelligence collection, it has a key feature. That is obtaining an understanding of the opponent’s intention (Johnson, 2010). Kyle Cunliffe (2021) names strategic-level sources as “hard targets”. These are sources that have a very high level of access to information and to the inner circle of government or non-governmental organizations. Althoff (2016) includes military, economic, and political leaders, government officials, and decision-makers, as well as individuals involved in planning, implementing, and reporting on issues in various sectors that are of strategic value to the intelligence organization (Lowenthal & Clark 2016, p. 45-46). 17 Magee (2010) adds lower-tier targets of relevant organizations. They are being targeted, for example, by “terrorist” and “criminal” organizations to support their operational purposes (Magee, 2010). The targeted source is what fits the request for information (RFI). Human intelligence is gathered either directly from targets or indirectly via technical devices or non-technically via recruited agents. Next in focus are human intelligence methods. 2.1.2 What is an agent-acquisition cycle? Next, I will explain what an agent-acquisition cycle is. There are two perspectives on what an agent-acquisition cycle in human intelligence collection includes. Two different perspectives are given by Michael Althoff and Mark M. Lowenthal. Althoff (2016) describes the process of human intelligence as an agent-acqui- sition cycle with the following stages: • targeting; • evaluation; • development; • recruitment. Before acquiring agents, there is a need to target people who have access to the information they seek. Then, the target’s suitableness is evaluated as a potential agent. Once the target has been approved, a recruiter begins to develop a “relationship” with the recruitable person. The duration of this phase varies greatly. The process can even last for years. The progression of the cycle does not mean, for example, that the assessment is finished. The recruiter must find out if the recruit is a so-called “dangle,” which means a counter-espionage lure, to either catch HUMINT recruiters or leak false information to an adversary. The assessment is made to see if the person is even willing to give out information. Ways of recruiting a spy include bribery and blackmail. The best-case scenario is that the agent is spying willingly without coercion. After the recruitment process, information is acquired from recruited agents (Lowenthal & Clark 2016, p. 61-63). Magee (2010) adds that organizations – who are willing to take “risks” to acquire information - are more likely to use coercive and aggressive measures (Magee, 2010). Althoff’s (2016) cycle ends with the actual decision to recruit. It is made by the personnel with the given authority when a sufficient assessment of the recruit is done. The decision is based on whether the recruiter will accept the so-called “offer” (Lowenthal & Clark, 2016, pp. 61-63). Lowenthal (2020) proposes a five-stage agent-acquisition cycle: • targeting/spotting; • assessment; • recruitment; • handling; 18 • termination. The first task is finding potential sources based on information needs. Next in line is an analysis of the target's knowledge and propensity to be recruited. When considered recruitable, the target is offered an incentive to become an agent. After the accepted offer, the agent will act and be guided as an intelligence source. The agent no longer acts as a source of human intelligence when the operation ends or is seen as disposable for intelligence purposes (Lowenthal, 2020, p. 138). Lowenthal's recruitment process includes handling and source termination compared to Althoff's recruitment process. Lowenthal (2020 holds continuous and long-term rapport between operative and informant as “developmental” in that he is not involved in the cycle as Althoff (2016) does but sees it as a tradecraft of an operative (Lowenthal, 2020, p. 126; Lowenthal & Clark, 2016). Next, I conclude the process. The recruitment process involves targeting potential sources in relevant positions, analyzing the potentiality of the target as a source, offering the target a reason (either positive or negative incentive) for being a source, turning the target into a source, processing the source for information, and ending the source status if necessary. The acquisition cycle indicates that obtaining a viable source of information is a lengthy process that requires many steps. The source must be chosen correctly to avoid the process being pointless. The target must be known so that it is not misleading, unwilling to cooperate, or without access to relevant information. The target may be a counterintelligence agent looking for personal informants. The target may be completely unwilling to compromise and accept the offer. Then, the long process will be futile. 2.1.3 What are the covers for clandestine and covert HUMINT? Next, I will explain the topic of cover in clandestine and covert HUMINT. Clandestine HUMINT is done in secrecy. HUMINT is covered and kept unknown for outsiders during covert operations. The cover is used to hide the activity of the HUMINT operation. Lowenthal (2017) presents a formal and informal cover. In the former, a cover is an official position for the presence of an intelligence operative in the target country. A cover can be an official function in a foreign mission with diplomatic status. In this case, the disclosure of the intelligence operation leads the person to be a persona non grata, whereby the operative has a limited period to leave the country. Informal cover as a non-official one does not have the protection of diplomatic status. Exposure leads to immediate imprisonment (Lowenthal, 2017, pp. 139-140). Johnson (2010) involves diversified cover officers (DCO) in addition to official and non-official. DCO could be an intelligence officer with ethnic origins from the target country. Johnson holds that ”closed societies” with ”effective counterintelligence” demand high-quality covers. That is why non-official covers and DCOs are highly important for human intelligence (Johnson, 2010). A diplomatic cover has diplomatic consequences, while non-official cover and DCO 19 have more possibilities for cover than official cover. According to Lowenthal (2017), the duration of the cover varies. Either the mission is activated immediately upon entry into the country, or the recruiter remains as a sleeper. Sleepers are activated into the intelligence role after a certain period, making the mission long-standing and requiring assimilation into the target country (Lowenthal, 2017, pp. 139-140). Stefano Musco (2017) analyses non-official covers (NOC) used throughout history. The intelligence operative has an incalculable number of cover options to choose from, and so demands good imagination. The essence is to understand the socio-cultural context of the target country to have a great non-official cover. A particular NOC should also fit the characteristics of the person gathering intelligence. The cover should also have features that let the spy carry certain objects (such as approval to carry a weapon) and travel to succeed in the task without having local officials alarmed by inconsistent behavior. The target sets the purpose for cover. Moreover, a cover without access to the targeted people is not convenient for the operation. Musco asserts that their NOC could be almost anything, which is why he notes there could be ethical problems when using NOC. One example is having “clergymen” and “patriarchs” as NOCs. The operative must make the cover believable and the NOC solid. That demands high acumen to keep the cover story intact and capable of spontaneously fabricating a story when needed. It is essential not to get caught (Musco, 2017). There are fewer options for cover based on regarding the country of operations and the zeitgeist. For example, in the case of economic change, covers that worked well in the 19th century in the Arabian Peninsula would require upgrades in the 21st century. An energy trader would have been a lousy cover for a 19th-century intelligence operative working in the Arabian Peninsula but a great one in the 20th and 21st centuries. Musco (2017) notes that “humanitarian” networks and other non-gov- ernment organizations (NGOs) are the type of contemporary cover organizations that give access and cover for intelligence operations (Musco, 2017). Next, I conclude on the topic of cover. There are two kinds of covers: informal and formal. The latter is a diplomatic position, therefore the person has diplomatic immunity. The immunity of a diplomat is held until becoming a persona no grata after the cover is exposed. Even then, there is time to escape the country. The former is not a governmental position and is without diplomatic security. There are unlimited options for the informal cover, namely non-official covers (NOC). Furthermore, a NOC must be personally and situationally consistent, and it does not abide by ethics. It needs to be a fit for the person, the purpose, and the current social and cultural milieu. The cover could be anything. 2.1.4 What are the costs and the benefits of HUMINT? Next, I will explain the costs and benefits of clandestine and covert HUMINT. These consist of technical demands, human skills and knowledge, and time and money. Conventionally, HUMINT is less machine-technical and naturally 20 psychological and cultural in its human-centricity. The goal is to gain critical inside knowledge from adversaries and not get caught. HUMINT is, at minimum, a low-tech and low-cost collection discipline (Lowenthal & Clark, 2016, p. 46). Human intelligence activities have high risks. According to Lowenthal (2017), the weakness of human intelligence has traditionally been the need for immediate proximity to the target. Therefore, getting caught in an act of espionage is a major threat (Lowenthal 2017, p. 143). The risks of human intelligence operations must be weighed against their benefits. Lowenthal (2017) suggests that human intelligence does not acquire information in the sense of high quantity but in high quality. Therefore, human intelligence targets high-level insiders with “access” to the information sought (Lowenthal 2017, p. 143). Johnson (2010) and Steele agree (2010) to target strategically relevant sources that are not within the reach of other collection methods and disciplines (Johnson, 2010; Steele, 2010). Magee (2010) holds that when information needs are met, the lower-tier target suits the purpose, but acquiring it will be a riskier, quicker, and more coercive process (Magee, 2010). HUMINT demands to be more on the field compared to other collection disciplines. Human intelligence operations take a significant risk that threatens both the recruiter and the recruitable. Disclosures threaten to end an operation on which a great deal of time and resources have been spent. Johnson (2010) describes the necessity of patience in the following: For an operations officer to succeed as an ace recruiter, he or she would ideally know the language, history, politics, and customs of the assigned nation; after all, winning the confidence of a local government official depends upon establishing rapport, in part, and it is easier to relate to foreigners when one displays a certain comfort level in the norms of their society. Some experts believe that it takes about seven years to reach this level of familiarity. (Johnson, 2010) Next, I elaborate on the costs and benefits of clandestine and covert HUMINT in conclusion. Time is what makes HUMINT expensive, but it also pays off in the end when operatives are accustomed to the local environment of operations. Clandestine and covert human intelligence is a risky intelligence activity that demands patience, durable effort, deniability, and deception through either informal or formal covers. HUMINT acquires key information that is beyond the reach of other collection disciplines from relevant persons in target organizations or states about the goals, plans, and intentions that meet the given RFI (request for information). Human intelligence is either acquired by humans or from humans, or both. 2.2 What is meant by cyber-prefix in the context of cyber HUMINT? Next, I will explain the cyber-prefix in cyber HUMINT references. The cyber-pre- fix in cyber HUMINT has different variations. They all encompass HUMINT 21 activity with the added use of information technological innovations. The main concept is cyberspace, which references the digital milieu in which cyber HUMINT is conducted. Cyberspace is, by definition, an interconnected totality of information networks. The interconnectivity creates a coherent and complex space of interactivity. It acts as a medium for the exchange of information between digitally connected systems and ”devices” (Lehto & Neittaanmaki, 2015, p. v). Cyberspace does not include humans in a conceptual sense, but it works as a medium for humans to interact with each other for all kinds of purposes. Devanny and others (2021) state that there is still too little research on cyber HUMINT (Devanny et al., 2021). The reviewed literature provides a framework for further research. 2.2.1 What is Cyber-HUMINT? Amit Steinhart (2014) and Paola Giannetakis, Lucia Iannilli, and Federica Caravelli (2020) consider cyberspace as a concept where cyber HUMINT is operated (Giannetakis et al., 2020; Steinhart, 2014). Steinhart (2014) mentions the cyberworld without defining it further (Steinhart, 2014). Cyberworld as a framework includes humans as users, while cyberspace does not. Steinhart (2014) sees social engineering—a cyberespionage technique—as an activity that resembles human intelligence collection. Social engineering is used to overcome technical obstacles by exploiting human nature based on "social conformity." Cyberespionage is often technically oriented, but the human side of cyberespionage is to target human users and manipulate them to achieve different kinds of purposes. Social engineering has strong similarities with HUMINT but has lacked methodological prowess. Social engineering has benefits in the knowledge of operating in cyberspace (Steinhart, 2014). The intelligence process can be accelerated in theory by targeting, assessing, and handling in a cyber environment. This lowers the risk and the time used to recruit people. Steinhart (2014) comes to the following conclusion in The future is behind us? The human factor in cyber intelligence: Correlations between Cyber- HUMINT and Hackers’ Social Engineering: In recent years, we have been able to observe professional cooperation between experienced HUMINT professionals and cyberwarriors skilled in defense technologies and social engineering. The innovation proposed here is the development of a new direction, which I refer to as: “Cyber HUMINT,” the system in which human-factor mainstays like false identity creation, recruiting, human sources, and complex information manipulation are exploited by cybersecurity and HUMINT experts together. The expected outcome, when given the necessary time and resources, is the creation of a human intelligence structure in the cyberworld (Steinhart, 2014). Steinhart’s conclusion reveals a future convergence of cyberespionage and HUMINT. The technological prowess of cyberespionage meets the methodological prowess of HUMINT. Understanding human behavior is combined with technical expertise to reach targets and sources without entering the target 22 country. Social engineering is human-oriented cyber espionage, which describes a HUMINT-like process. HUMINT and social engineering have different conceptual frameworks. Both still pursue their goals by using people to give required access or information. Giannetakis, Iannelli, and Caravelli (2020) hold cyber HUMINT as HUMINT in cyberspace. According to them, the whole agent-acquisition cycle can be operated by cyber means. Recruited targets are virtual agents. Operatives build a rapport with targets in cyberspace. For that, operatives require digital covers (Giannetakis et al., 2020). The same principles that have been essential in traditional HUMINT are being adapted to cyberspace. Giannetakis and others (2020) describe a part of the process of agent acquisition as follows: Within the intelligence cycle, once the target has been determined, the team takes care of the entire preparatory phase of the operation (technical preparation, creation of profiles, etc.) and subsequent exploitation through real active participation that involves recruitment of sources and/or approach to the target, all rigorously online. For this reason, the team created ad hoc prepares an operation like the way in which a traditional HUMINT activity is set up (Giannetakis et al., 2020). Cyber HUMINT is analogical to HUMINT. Differences are found in the technical conducting of operations. Giannetakis and others (2020) make the notion of covert operations having two central points: cover and access. A hub is formed for sets of covers (created fronts, backstories, and identities) to gain web traffic and to gain information on visitors. Access to cyber groups begins with building rapport on forums and social platforms with users. Building rapport with targets and maintaining relationships with sources requires persistence (Giannetakis et al., 2020). Cyber HUMINT is HUMINT in cyberspace, and it requires specialization in the milieu of activity. Therefore, at the base, there is the creation of a profile, which can be assimilated into the equivalent creation of a cover story. This story must be consistent, as must all the traces that must necessarily be released on the web to support it. CYB HUMINT is, therefore, a full-time activity that, on average, requires several months before it can be implemented via an active profile on the net without creating suspicion, months during which the social profiles must be fed with all the material necessary to outline exactly the characteristics of the "virtual agent" (Giannetakis et al., 2020). As mentioned earlier, Giannetakis and others (2020) assert that cyber HUMINT can be operated in cyberspace. “Delocalization and dematerialization” make cyber HUMINT a fully comprehensive whole. Cyberspace makes it possible to approach people digitally who would be difficult to meet physically (Giannetakis et al., 2020). Cyber HUMINT would be a subspecies of HUMINT. It requires specialized operatives to function in cyberspace. 23 2.2.2 What is Cybernetic HUMINT? Tal and Siman-Tov (2015) coined the term cybernetic HUMINT to name a “new subprofession” under HUMINT (Tal & Siman-Tov, 2015). What is cybernetic in cybernetic HUMINT? Siman-Tov and Tal do not explicate what is meant by cybernetic in their article. Based on their description of cybernetic HUMINT and HUMINT in the cybernetic age, cybernetic HUMINT is identical to cyber- HUMINT as Giannetakis and Steinhart have described it. Tal and Siman-Tov (2015) refer to “cybernetic tools,” which give rise to cybernetic HUMINT. Those are “internet” and “online forums” (Tal & Siman-Tov, 2015). In the cybernetic HUMINT, the agent-acquisition cycle is operated in cyberspace. Tal and Siman- Tov (2015) see the possibilities of cybernetic HUMINT as follows: In the cybernetic HUMINT era, the candidates for recruitment are diverse and almost unlimited. The intelligence required to locate them can be obtained quickly, the selection is broad, and access is easy. Furthermore, cyberspace makes it possible to conduct the recruitment and handling stages with relatively little risk, at almost no cost, and with almost no effort, with the help of impersonation or anonymity, including multimedia meetings. Connecting with individuals and groups can be done easily, without any physical danger. Cybernetic HUMINT is groundbreaking and significantly improves the ability of HUMINT personnel to reach remote target audiences that are difficult to recruit (Tal & Siman-Tov, 2015). Tal and Siman-Tov’s definition of cybernetic HUMINT is similar to that of the concept of cyber-HUMINT (Chapter 2.2.1). They see it as a subcategory of HUMINT operated in cyberspace. What was done in traditional HUMINT is doable in cybernetic HUMINT when it is fitted to cyberspace. The development of cybersecurity makes it more difficult for operatives to conduct operations in cyberspace. Tal and Siman-Tov (2015) indicate that digital footprints are more noticeable when digital surveillance develops (Tal & Siman- Tov, 2015). This is why having a good cover for covert operations in cyberspace is important. As discussed in Chapter 2.1.3, Stefano Musco (2017) noted that covers must be situationally fit. As in the physical milieu, the digital cover should fit a particular forum or social media group. Siman-Tov and Tal (2015) name cover in cyberspace as avatar. Those are fake “identities,” which are represented by digital features such as “icons” and “images.” Avatars are formed to meet situational criteria and are used for varying purposes. The range of covers as avatars is as vast as imagination allows. Those are created to operate on different kinds of social media platforms (private and public) and are used to do various tasks such as checking users' identities (there are technical applications to support this kind of activity). When developing digital relationships with humans, it is preferable to have “social sensitivity.” This, combined with emotional intelligence, makes good cybernetic HUMINT operatives (Tal & Siman-Tov, 2015). 24 2.2.3 What is Cyber-enabled HUMINT? Gioe et al. (2020) show that technology-enabled HUMINT has gained new collection disciplines or new technical means to operate with. Gioe brings forth two major benefits of cyber-enabling: “distance” between operative and source and “plausible deniability if caught” (Gioe et al., 2020). New possibilities with the reduction of risks are made possible by technological innovation and the adoption of those innovations, which are relevant in enabling HUMINT with new methods and techniques. Gioe and others (2020) give the following notion of technologies leading to conceptual developments when new technical means are adopted to support intelligence tradecrafts: […] converging specialisms might be seen as the forebears of technological development enabling other collection methods that have evolved in contemporary terms such as “cyber‐enabled HUMINT” or the converse, “HUMINT‐enabled cyber operations,” such as the Stuxnet attack on Iran’s nuclear program (Gioe et al., 2020). Technology, which allowed new collection disciplines to emerge, is the main driver of intelligence collection. The results of human intelligence collection depend on technological adoptions. Cyber-enabled HUMINT allows HUMINT to operate in cyberspace without mutating into a wholly another new collection discipline. Cyber-enabling lowers risks and grows the reach of operations. 2.2.4 What is HUMINT in the Cyber Age and Hybrid Intelligence? David Gioe (2017) holds that human intelligence collection stays ”traditional” but concludes that cyberspace makes operating human intelligence more vulnerable. He thinks that other collection disciplines will commend human intelligence more via cyberspace. HUMINT as the core activity is supported and, in turn, hinged by cybersecurity, cyber espionage methods, social media intelligence (SOCMINT), disseminating secret information on the internet, and open-source intelligence (OSINT). These require HUMINT to adapt to the new demands of the evolving operational environment. HUMINT also gains a “force multiplier” in cyber when digital data is reached from a distance. Social media allows seeking information on potential targets and foreign operatives but requires more from covers and fake profiles because of a” digital footprint.” Hacked private digital records potentially reveal operatives' or targets' vulnerabilities. Gioe holds that digital meetings leave more possibilities for deception than physical meetings between an operative and a recruitable target or a handled source (Gioe, 2017). Gioe (2018) asserts in another article that a combination of traditional human intelligence and cyber methods is conducted by state actors to expose damaging information. This is called hybrid intelligence. It means combining human and cyber espionage with information operations (Gioe, 2018). Hybrid intelligence is not just intelligence. It is a combination of intelligence to produce leaks, 25 which cause damage to a hacked person’s or organization’s reputation, or to let guarded secrets be publicized on the internet. According to Gioe (2017), the effect of cyberspace on HUMINT remains to be unanswered. Gioe assures that at least the intelligence cycle has been accelerated by cyber (Gioe, 2017). 2.2.5 What is the human domain in cyberespionage? Human-targeting cyberespionage and HUMINT share similarities. Both use humans as sources of information and/or get access to an information source. Brian Mitchell (2020) divides cyberespionage threats among human resources between outsiders and insiders and between external actors and internal actors. In case of an outside attack, insiders are manipulated and exploited. On the contrary, in case of an inside attack, insiders as internal actors pursue gains or satisfaction in their self-interests. Outsiders, as external actors, use either technical means or insiders from the target organization to get access to the required information. A method of using human resources in cyberespionage is called “social engineering” (Mitchell, 2020). External actors using insiders resemble traditional human intelligence. Mitchell’s (2020) following description of an external actor using insiders for cyberespionage has close similarities with the agent-acquisition cycle: If the external actor recruits a person within the organization, then this adds a human dimension because the internal participant is normally acting on the instructions of the external actor that continues to control the attack vector. This human dimension requires planned means of communication and transfer of information (physical or virtual contact) […] (Mitchell, 2020). Mitchell (2020) explains that malintent outsider “recruits” insiders and exploit them to conduct cyberespionage (Mitchell, 2020). Mitchell’s article shows that methods from human intelligence tradecraft are found in other frameworks and contexts. Concepts of cyberespionage are different from concepts of HUMINT but share similarities in the definition. 2.3 How do traditional and cyber HUMINT differ from each other? The literature review on human intelligence (HUMINT) highlights that intelligence can be gathered directly by operatives from sources or indirectly through agents. It also covers the methods used to acquire and maintain operational cover, as well as the need to balance risks and rewards when conducting operations. The recruitment process involves identifying potential sources, evaluating their potentiality, converting them into a source, extracting information from them, and ending the source status if necessary. Obtaining a reliable source is a lengthy process that involves choosing the right source and knowing the target 32 2. Using sentence -- ("cyberhumint" or "cyber-humint" or "cyber humint") -- 10 sources were chosen from 15700 results. 3. Using sentence -- ("cyberhumint" or "cyber-humint" or "cyber humint" OR "Cyber Human Intelligence") – 0 sources were chosen from 675 results. 4. Using sentence -- ("cyberhumint" or "cyber-humint" or "cyber humint" OR "Cyber Human Intelligence") AND "cyber security" -- 0 sources were chosen from 189 results. 5. Using sentence -- ("cyberhumint" or "cyber-humint" or "cyber humint" OR "Cyber Human Intelligence") AND (cybersecurity OR "cyber security") – 4 sources chosen from 264 results. 6. Using sentence -- ("cyberhumint" or "cyber-humint" or "cyber humint" OR "Cyber Human Intelligence") AND (cybersecurity OR "cyber security") AND Blog - 0 sources were chosen from ninety-one results. 7. Using sentence -- ("cyberhumint" or "cyber-humint" or "cyber humint" OR "Cyber Human Intelligence") AND "cyber security" - 0 sources were chosen with one hundred results. 8. "digital humint" AND blog - 5 sources were chosen from 13900 results. Search results often showed repetitive results. Different search sentences were used and modified to limit and vary search results. The chosen sources included web pages consisting of content cyber HUMINT and HUMINT in cybersecurity, which were gathered for content analysis. Twenty-three sources were imported to Mendeley Library. Fourteen documents were included in the research data after nine were excluded. Reasons for exclusions were the following: Only HUMINT without cyber; not a private security or cybersecurity organization; the concept was Virtual HUMINT. Next, the websites and web publications of private security and cybersecurity companies will be reviewed. First, there will be a short introduction to the company or organization, followed by a summary of their text about HUMINT in cybersecurity and/or cyber HUMINT. SOS Intelligence is a company that offers threat intelligence services. Its focus is on surveilling data leaks and alerting those affected. On its website, it informs us that it monitors, for example, the dark web to alert people about leaks and risk monitoring. It also provides threat-hunting services. The company collects data using automation. (SOS Intelligence, no date) Amir Hadzipasic discusses Cyber HUMINT and automation on the company's website, focusing on efficient data collection techniques. (Hadzipasic, 2021) Cyber Cupula is a cybersecurity company that works together with clients and law enforcement to identify and counter cyber threats. On their website, they state that the company specializes in using human intelligence in cybersecurity to attribute threat actors and provides effective tools for protection. Their target audience is companies in the financial sector. Through their Cyber HUMINT services, Cyber Cupula combines human intelligence with web and open-source intelligence to guard against cyber threats (Cyber Cupula, no date). 33 The International Anti-Crime Academy offers specialized training courses in digital investigation and combating cybercrime. On their website, they state that the courses are instructed by experienced professionals. Courses concentrate on practical and applicable skills on topics such as Cyber HUMINT, digital analysis, and personal information protection. The training can be beneficial for individuals who are interested in acquiring advanced investigative techniques. Furthermore, law enforcement agencies in the United States have utilized this training to combat financial crimes. (International Anti-Crime Academy, no date) Cyber Risk GmbH in Switzerland provides professional training and consultancy services on cybersecurity topics like cyber espionage, cyber HUMINT, and cyber threats' impact on businesses. George Lekatis founded the company, which specializes in compliance and risk management. (Cyber Risk Gmbh, no date) The company writes on cyber espionage and warfare, with a brief touch on cyber HUMINT. Cyber espionage is hard to detect, making cybersecurity training and awareness crucial. (Cyber Risk GmbH, no date) Intel 471 provides Cyber Threat Intelligence services to businesses to improve their cyber defenses against potential financial loss, data leaks, damage to public image, or intellectual property theft. They use human analysis and data collection to identify cyber threats (Intel471, no date). In their blog, Michael DeBolt informs about Cyber HUMINT, which involves using human collectors to gather intelligence from digital sources, providing insights into adversaries' motives and tactics that automated methods may overlook. Combining automation and cyber HUMINT is a powerful approach for enterprise security, offering critical details for effective risk mitigation and staying ahead of evolving threats. (DeBolt, 2023) CQR is a cybersecurity outsourcing company based in Eastern Europe that provides IT security services. They offer various solutions, including red teaming and penetration testing, to enhance their clients' security measures. (CQR Company, no date.) CQR highlights the importance of HUMINT in cybersecurity, detailing its types, methods, benefits, limitations, tools used, and ethical considerations on its website. HUMINT plays a critical role in threat intelligence, incident response, vulnerability assessment, and gathering contextual information. (CQR Company, 2023) Grey Dynamics is a London-based intelligence firm that prioritizes timely, accurate, and actionable intelligence services. They offer a range of services, including articles on intelligence, intelligence reports, research, and investigations (Grey Dynamics, no date). A blog by Rachele Momi informs about HUMINT and touches briefly on the topic of cyber HUMINT. (Momi, 2021) Rapid7 simplifies cybersecurity challenges through a comprehensive security platform and services. Their Insight Platform automates operations and enables teams to focus on priorities (Rapid7, no date). Intelligence tools, including HUMINT, are crucial for effective cybersecurity strategies that recognize adversary motivations, according to Nathan Teplow's blog (Teplow, 2018). CyberProof offers cybersecurity assistance for businesses transitioning to digital cloud environments utilizing virtual and human analysts along with 34 automation. The company is multi-certified and emphasizes the importance of adapting to the opportunities and threats presented by the cloud era (CyberProof, no date). Eva Prokofiev, a Senior Intelligence Analyst at Cyber- Proof, explains cyber HUMINT - a combination of traditional espionage techniques with cyber capabilities to proactively prevent cyber threats. By integrating classic HUMINT strategies with cyber methods, cyber HUMINT enhances cybersecurity measures by gathering critical information, engaging with threat actors, and preventing attacks before they occur. (Prokofiev, 2019) ADEO Cyber Security provides cybersecurity services to corporate customers in Türkiye and the MEA region, with expertise in offensive and defensive cyber offense, cyber resilience, and technology procurement. Their team is committed to continuously improving their customers' cybersecurity defenses (ADEO, no date). Effective cybersecurity defense requires understanding the human element of cyber threats through HUMINT and developing strategies accordingly. (Adeo, 2023) Treadstone 71 provides cyber intelligence services. The founder has expertise in linguistics and cybersecurity. They offer courses on cyber intelligence and provide threat assessments, planning, and research services (Treadstone 71, no date). Treadstone 71 writes on cyber HUMINT and its automation that automation leads to effective intelligence gathering on adversarial activities in cyber environment. (Treadstone 71, 2023) Hacktoria, a Helsinki-based company, provides story-driven Capture The Flag (CTF) challenges that use gamification to teach various cybersecurity and digital investigation skills (Hacktoria, no date). The company provides information on social engineering and cyber HUMINT techniques for CTF challenges (Hacktoria, no date). CrowdStrike is a cybersecurity company that provides AI-powered cybersecurity platforms, threat intelligence, and threat-hunting solutions (CrowdStrike, no date). HUMINT is crucial in cyber security to understand adversaries and enhance protection, according to Bart Lenaerts-Bergmans, a Senior Product Marketing Manager with over 20 years of experience at CrowdStrike (Lenaerts-Bergmans, 2023). Cyberarch is a cybersecurity consulting firm that provides tailored services globally, with a focus on Information Security and Computer Forensics. The company has expertise in risk management consulting and provides services to manage the challenges of Information Technology (Cyberarch, no date). Their published content emphasizes the use of HUMINT in cybersecurity to counter cyber threats effectively. They leverage strategies such as social engineering and engagement with hacker communities to enhance cybersecurity defenses. (Cyberarch Admin, 2021). The content was encoded, and citations were brought in as sentences for the content analysis. The chosen content as citations was reduced to simpler forms (Table 2). The content was encoded and analyzed by using data analysis software called “Atlas.ti.” Content was encoded based on research questions and data. I used Atlas.ti to perform reduction and the first two rounds of categorization. 35 Codes, citations, reduced content, and lower and upper classes were then exported to Microsoft Excel. Citations were excluded if they did not answer the research question. TABLE 2 Examples of content analysis, from Citations to Reductions Citations Reduction “Cyber-HUMINT is frequently understood to mean social engineering activities – which, in the context of security, means the psychological manipulation of people into divulging confidential information, or performing actions they do not want to do.” (Prokofiev, 2019) Cyber-HUMINT psychological manipulation social engineering activities to divulge confidential information to perform unwanted actions “Cyber-HUMINT has two aspects to it: on the one hand, there are espionage methodologies such as agent recruitment and information gathering through deception; and on the other hand, there is Cyber-HUMINT – the deception methodologies that are commonly referred to as social engineering. “ (Prokofiev, 2019) agent recruitment Cyber-HUMINT deception methodologies espionage methodologies information gathering social engineering through deception “Cyber-HUMINT means putting into action the information passively gathered by intelligence analysts and operatives.” (Prokofiev, 2019) Cyber-HUMINT gathered by intelligence analysts and operatives information put into action Table 2. The examples above show the process of reduction. The final phase of the content analysis was categorization and abstraction. Words and phrases after the reduction were grouped together based on their similarity. Classes were named based on the denominating factor. These lower classes were connected to the upper classes (Table 3). TABLE 3 Examples of grouping of Lower classes Reduction Lower Class interplay between cyber HUMINT, hackers, and social engineering phishing attacks psychological manipulation social engineering social engineering activities social engineering strategies and practices Social engineering deception deception methodologies online deception through deception Deception agent recruitment recruitment Recruiting an ethical dimension in cybersecurity Ethical consideration 36 combination of automated collection and cyber HUMINT-derived insights combine the collected data with other sources of intelligence not a standalone solution Combination Table 3. The examples above show the reduction grouping. Upper classes were named based on the consistence of the class. This was done again to form two main classes and eventually one combined class. Categorization was conducted inductively from data. The categorization is shown in chapter 4 (Table 4). 37 4 Proactive Cyber Human Threat Intelligence I will now present the findings of a data-driven qualitative content analysis. The report will include categories (TABLE 4) and descriptive quotes from the research data. Two main categories were formed from lower-level classes. The first category is "Covert Human Threat Intelligence Professionality," while the second is "Proactive, Compliant, and Scalable Cyber Intelligence Tool." These categories are combined into "Proactive Cyber Human Threat Intelligence.” The research question was: What is cyber HUMINT in cybersecurity? TABLE 4 Categorization of Classes towards Main Combined Class Lower Class Upper Class Main Class Combined class Social engineering Exploiting human attack vector Covert human threat intelligence professionality Proactive cyber human threat intelli- gence Recruiting Targeting Relationship building Infiltration Humans as an attack vector Deception Denial and deception Digital cover Threats Threat intelligence process Collection Analysis Insights Decision support Expert knowledge Professionals Operators Training Intelligence methodologies Proactive intelligence methodology Proactive, compliant, and scalable cyber intelligence tool Proactive Benefits Benefits, potentiality, and challenges Technological development Ethical consideration Tool Cyber intelligence tool Cybersecurity Cyber intelligence Digital forensics/investigations Counterintelligence Combination Operating digital environment 38 Table 4 Categorization process of the content analysis is presented above. 4.1 Covert Human Threat Intelligence Professionality This main class includes the following upper classes: Exploiting the human attack vector, Denial and deception, Threat intelligence process, and Professionals. 4.1.1 Exploiting the Human Attack Vector The first upper class was named Exploiting the human attack vector, which included the following lower classes: Social engineering, Targeting, Recruiting, Relationship building, Infiltration, and Human attack vector. Social engineering is a core method in cyber HUMINT. The following citation from the data states: “Cyber-HUMINT starts with traditional human intelligence processes (recruitment, training, intelligence gathering, deception, etc.), combined with social engineering strategies and practices.” (Cyber Risk GmbH, no date). The concept overlaps with social engineering in terms of using humans to obtain information. The data cites the following: “Cyber-HUMINT is frequently understood to mean social engineering activities—which, in the context of security, means the psychological manipulation of people into divulging confidential information or performing actions they do not want to do.” (Prokofiev, 2019). Recruiting is part of Cyber HUMINT as the following citation states: “Recruiting Human Agents: Cyber Humint involves recruiting human agents strategically to gain insights into potential threats and hostile actors.” (Hacktoria, no date-b). Targeting is identifying potential sources to recruit. Relationship building is necessary to create trust between operative and the target. Relationship building is done online, and it is fast-paced, which the following quote from the data reflects: “On the other hand, Cyber-HUMINT is based on a short-term and virtual relationship.” (Momi, 2021). Infiltration is the main operation to get access to relevant digital communities to reach recruitable sources. A quote from the data mirrors this as follows: “Cyber HUMINT operators were able to infiltrate online spaces where the group was active.” (Adeo, 2023). Humans are attack vectors in cyber HUMINT. They are manipulated and exploited for attaining required information. A following quote from the data reflects this thought: “Cyber-HUMINT refers to the strategies and practices used in cyberspace, in order to collect intelligence while attacking the human factor.” (Cyber Risk GmbH, no date) 39 4.1.2 Denial and Deception The next class in the hierarchy is known as Denial and Deception, which is further divided into two lower classes named Deception and Digital Cover. The lower class, named Deception, is conducted to conceal the true purpose of a particular operation, referred to as a part of cyber HUMINT in an earlier quote, while Digital Cover is employed to hide the identity of the operative as well as their organization. According to a quote from the data, "However, cyber HUMINT typically involves a single human collector who operates under a digital identity - commonly referred to as a persona, sock puppet, handle, or moniker - that is carefully crafted with believable backstories and motivations, also known as legends (similar to traditional HUMINT)." (DeBolt, 2023). 4.1.3 Threat Intelligence Process The following text describes the Threat intelligence process, which is composed of five lower classes: Threats, Collection, Analysis, Insights, and Decision Support. Threats are the biggest challenge in cybersecurity. To tackle this issue, Collection is the most important operation in cyber HUMINT. It involves gathering information about threats to cybersecurity. As the data states, "Our Cyber-HUMINT handlers, together with talented analysts, are operating Digital Avatars interacting with and collecting data from the threat actors in the Cyber vicinity." (Cyber Cupula, no date). Another essential part of cyber HUMINT is analysis, where gathered information about threats, threat actors, and the overall threat landscape are assessed. It helps to string together the collected information. Insights are critical information received from threat actors. They provide a better understanding of the intentions of the threat actors. As mentioned in the data, "In other words, cyber HUMINT has the advantage over other types of cyber intelligence collection methods because it reaches below the surface to reveal critical insights necessary to solve security and risk use cases that would be otherwise missed using other collection methods." (DeBolt, 2023). Decision Support is the final step in the Threat intelligence process. It helps cyber HUMINT operatives and cybersecurity professionals to use gained intelligence effectively. Decision Support identifies critical threat actors and provides guidance on how to defend against threats. As stated in the data, "Cyber- HUMINT means putting into action the information passively gathered by intelligence analysts and operatives." (Prokofiev, 2019). 4.1.4 Professionals The following text explores the cyber security profession and its essential parts further. The profession comprises professionals with expert knowledge of the operational environment, methods, tactics, and procedures. They need to know 40 where they operate and how to gather critical information about the threat landscape and actors, which the following quote reflects: “When it comes to the concept of Cyber Humint, the role of cyber experts and human intelligence specialists is crucial.” (Hacktoria, no date,b) Operators are the professionals who know how to operate cyber HUMINT. This requires not only cyber security expertise but also the ability to handle humans in a cyber environment. Here is a quote from CyberProof, for example: “Our cyber threat intelligence professionals use Cyber-HUMINT to identify individuals or groups that are secretly trading sensitive information belonging to […] customers, as well as those who are conducting other forms of malicious activity.” (Prokofiev, 2019) As quoted earlier, training is a relevant aspect of this profession. Professionals must possess human skills and the ability to operate in the digital environment and, for that reason, use a fitting set of techniques and procedures in cyber HUMINT. 4.1.5 Conclusion This set of classes consists of four upper classes that focus on different aspects of human intelligence and threat intelligence. The first upper class, "Exploiting human attack vector," deals with the techniques and strategies used to exploit human weaknesses and gain access to threat actor’s information. The second upper class, "Denial and deception," aims to prevent exposure of the operation and the identity of an operative. The third upper class, the "Threat intelligence process," is focused on collecting, analyzing, and disseminating information about potential cyber threats to enhance protection measures. Finally, the fourth upper class, "Professionals," is dedicated to educating and training cybersecurity professionals, improving their skills and knowledge to keep up with the evolving threat landscape. In cyber HUMINT, social engineering plays a pivotal role in information collection. This approach uses human intelligence processes and social engineering tactics to manipulate individuals to obtain intelligence. The process includes the steps of recruitment, targeting, building relationships, infiltration, and analysis; it often involves deception and digital cover to operate under false identities. Cyber HUMINT professionals use digital avatars to interact with threat actors and gain critical insights that aid in decision-making for cybersecurity defense. Adequate training is essential for these professionals to perform effectively in the cyber HUMINT field. 4.2 Proactive, Compliant, and Scalable Cyber Intelligence Tool This main class includes the following upper classes: Proactive intelligence methodology, Benefits, potentiality and challenges, and Cyber intelligence tool. 41 4.2.1 Proactive Intelligence Methodology The following text explains the Proactive Intelligence Methodology, which has two lower classes called Intelligence Methodologies and Proactive. Intelligence Methodologies are techniques used in intelligence collection outside the domain of Cyber HUMINT. Cyber HUMINT is the collection of intelligence by human means, which is the foundation of Cyber HUMINT. The quote is an excerpt from the data: “Cyber HUMINT, or the application of traditional human intelligence techniques in the digital realm, provides a unique and proactive perspective on the intentions, tactics, and plans of adversaries.” (Adeo, 2023) Proactive refers to offensive cybersecurity, which is different from technical and defensive cybersecurity systems that passively gather information from web traffic to identify and detect malicious attacks. Proactive cybersecurity tools actively find human sources to uncover threats. Proactive cybersecurity does not wait for the first indications of a malicious attack. The quote exemplifies, "Cyber HUMINT is an important component to this proactive intelligence gathering approach, providing “eyes and ears” visibility into pre-attack signals that would otherwise go undetected.” (DeBolt, 2023). 4.2.2 Benefits, Potentiality, and Challenges The next upper class was Benefits, potentiality, and challenges. The next level in cyber intelligence is Benefits, Potentiality, and Challenges, which consists of three sub-levels: Benefits, Technological Development, and Ethical Considerations. Cyber HUMINT, a method of collecting intelligence from human sources, has many benefits in providing insights about the intentions of threat actors that would otherwise be unknown using other cyber intelligence tools. The following quote from the data suggests the benefits, "Cyber HUMINT has the advantage over other types of cyber intelligence collection methods because it reaches below the surface to reveal critical insights necessary to solve security and risk use cases that would be otherwise missed using other collection methods." (DeBolt, 2023) Technological development is an integral part of cybersecurity, and it plays a significant role in optimizing the operational cycle of cyber HUMINT in the digital environment. The technical environment in which cyber HUMINT operates generates a lot of data, and therefore, technical expertise is required to automate multiple processes and utilize big data. As the following quote from the data suggests, "The general approach is to identify relevant sources of targeted cyber HUMINT, develop automated mechanisms to collect information from identified sources, apply text mining and natural language processing (NLP) to automatically process and analyze the collected data, combine the collected data with other sources of intelligence, contextual analysis, cross-reference and verification, threat actor profiling, visualization and reporting, and continuous monitoring and update." (Treadstone 71, 2023) 48 ethics, and theoretical framework on the topic of cyber HUMINT would enhance our understanding of its place in Finnish cybersecurity. 49 6 CONCLUSION This study explored how human intelligence collection functions in the digital age, particularly in the context of cybersecurity. It investigated the concept of cyber HUMINT in cybersecurity. By analyzing web content from cybersecurity organizations, the research aimed to understand how technology impacts human activity in ensuring security. The study utilized content analysis as the research method and drew on various academic sources on intelligence, HUMINT, cyber HUMINT, and cyber espionage. The goal was to show how human intelligence adapts and operates in a digitalized world, providing insights for enhancing organizational security measures. This research explored the adaptation of traditional human intelligence collection to the digital environment in cybersecurity. The chosen research method was content analysis on cyber HUMINT, using data from published web content. The process involved limiting, reviewing, excluding, combining, encoding, and reporting the analyzed content. Data was collected from private security and cybersecurity organizations' websites to define cyber HUMINT in cybersecurity. The analysis followed American tradition, involving reduction, categorization, and abstraction to answer the research question. The synthesis of web content was presented in tables to identify similarities and differences in cyber HUMINT content. The saturation principle was used to determine data relevance. The research question was appropriately addressed through content analysis. Cyber HUMINT is a form of proactive cyber human threat intelligence that concentrates on gathering information about threat actors and the threat landscape from humans in a digital environment. In the cyber domain, human threat intelligence assists organizations in staying ahead of potential cyber threats by providing valuable intelligence to support the development of effective strategies to prevent cyber-attacks. This research focused on the importance of human intelligence in cybersecurity, specifically exploring the concept of "cyber HUMINT". The study analyzed how human intelligence is integrated with digital technologies to combat cyber threats. The findings highlighted the proactive nature of cyber HUMINT, combining covert intelligence techniques with scalable cyber tools to gather information on threat actors in the digital landscape. The research emphasized the significance of proactive intelligence gathering to identify and prevent cyber threats before they occur. It also addressed the ethical and legal considerations of cyber HUMINT. The study concluded that cyber HUMINT plays a crucial role in cybersecurity by gathering threat intelligence from human sources to enhance organizational security measures. 50 REFERENCES Adeo. (2023). The Vital Role of Human Intelligence (HUMINT) in Cybersecurity. Adeo. https://adeo.com.tr/en/the-vital-role-of-human-intelligence- humint-in-cybersecurity ADEO. (no date). ADEO. Retrieved 13.4.2024, from website https://adeo.com.tr/en CQR. (no date). CQR. Retrieved 13.4.2024, from website https://cqr.company/ CQR Company. (2023). HUMINT. CQR. https://cqr.company/pentestingprocess/humint/ CrowdStrike. (no date). CrowdStrike. Retrieved 13.4.2024, from website https://www.crowdstrike.com/en-us/ Cunliffe, K. S. (2021). Hard target espionage in the information era: new challenges for the second oldest profession. Intelligence and National Security, 36(7), 1018–1034. https://doi.org/10.1080/02684527.2021.1947555 Cyber Cupula. (no date). The Art Of Active Cyber Humint. Cyber Cupula. Retrieved 5.4.2024, from website https://cybercupula.com/ Cyber Risk Gmbh. (no date). Cyber Risk GmbH. 13.4.2024, from website https://www.cyber-risk-gmbh.com/ Cyber Risk GmbH. (no date). From Espionage to Cyber Espionage. Cyber Espionage. Retrieved 7.4.2024, from website https://www.cyber-espionage.ch/ Cyberarch. (no date). Cyberarch. Retrieved 13.4.2024, from website https://cyberarch.eu/ Cyberarch Admin. (2021). What is the importance of human intelligence HUMINT? - CYBERARCH. Cyberarch. https://cyberarch.eu/our-blog/what-is-the- importance-of-human-intelligence-humint/ CyberProof. (no date). CyberProof. Retrieved 13.4.2024, from website https://www.cyberproof.com/ Dando, C. J., & Ormerod, T. C. (2020). Noncoercive human intelligence gathering. Journal of Experimental Psychology: General, 149(8), 1435–1448. https://doi.org/10.1037/xge0000724 DeBolt, M. (2023). Gaining the Intelligence Advantage with Cyber HUMINT - Part One. Intel471. https://intel471.com/blog/gaining-the-intelligence- advantage-with-cyber-humint-part-one 51 Devanny, J., Martin, C., & Stevens, T. (2021). On the strategic consequences of digital espionage. Undefined, 1–22. https://doi.org/10.1080/23738871.2021.2000628 Merriam-Webster. (no date). Digitalization Definition & Meaning. https://www.merriamwebster.com/dictionary/digitalization#medicalDictionary Merriam-Webster. (no date). Enable Definition & Meaning. https://www.merriam-webster.com/dictionary/enable Giannetakis, P., Iannilli, L., & Caravelli, F. (2020). Cyber Humint. A Behavioral Analysis Perspective. American Journal of Multidisciplinary Research & Development (AJMRD, 2(11), 27–33. www.ajmrd.com Gioe, D. V. (2017). ‘The More Things Change’: HUMINT in the Cyber Age. Undefined, 213–227. https://doi.org/10.1057/978-1-137-53675-4_12 Gioe, D. V. (2018). Cyber operations and useful fools: the approach of Russian hybrid intelligence. Intelligence & National Security, 33(7), 954–973. https://doi.org/http://dx.doi.org/10.1080/02684527.2018.1479345 Gioe, D. V., Goodman, M. S., & Stevens, T. (2020). Intelligence in the Cyber Era: Evolution or Revolution? Political Science Quarterly, 135(2), 191–224. https://doi.org/10.1002/POLQ.13031 Grey Dynamics. (no date). Grey Dynamics. Retrieved 13.4.2024, from website https://greydynamics.com/ Hacktoria. (no date -a). Hacktoria. Retrieved 13.4.2024, from website https://hacktoria.com/ Hacktoria. (no date -b). Utilizing Social Engineering Techniques in HUMINT. Hacktoria. Retrieved 5.3.2024, from website https://hacktoria.com/socialengineering-humint/ Hadzipasic, A. (2021). Automating Cyber HUMINT Collection. SOS Intelligence. https://sosintel.co.uk/automating-cyber-humint-collection/ Hirsjärvi, S., Remes, P., Sajavaara, P., & Sinivuori, E. (2009). Tutki ja kirjoita (15. uud. p.). Tammi. Intel471. (no date). Intel471. Retrieved 13.4.2024, from website https://intel471.com/ Johnson, L. (2010). Evaluating ”humint”: The role of foreign agents in U.S. security. Comparative Strategy, 29(4), 308–332. https://doi.org/10.1080/01495933.2010.509635 52 Lehto, M., & Neittaanmaki, P. (2015). Cyber security : analytics, technology and automation. Springer International Publishing. Lenaerts-Bergmans, B. (2023). What is Human Intelligence (HUMINT) in Cybersecurity? Crowdstrike. https://www.crowdstrike.com/cybersecurity- 101/threat-intelligence/human-intelligence-humint/ Lowenthal, M. M. (2017). Intelligence : from secrets to policy (Seventh ed). CQ Press. Lowenthal, M. M. (2020). Intelligence : from secrets to policy. SAGE/CQ Press. Lowenthal, M. M., & Clark, R. M. (2016). The five disciplines of intelligence collection. CQ Press. Magee, A. C. (2010). Countering nontraditional HUMINT collection threats. International Journal of Intelligence and CounterIntelligence, 23(3), 509–520. https://doi.org/10.1080/08850601003798807 Mitchell, B. (2020). CORPORATE CYBERESPIONAGE: IDENTIFICATION AND PREVENTION PART 2. https://doiorg.ezproxy.jyu.fi/10.1080/07366981.2020.1798595, 62(6), 1–14. https://doi.org/10.1080/07366981.2020.1798595 Momi, R. (2021). HUMINT: The Human Intelligence Discipline. Grey Dynamics. https://greydynamics.com/humint-the-human-intelligence-discipline/ Musco, S. (2017). The art of meddling: a theoretical, strategic and historical analysis of non-official covers for clandestine Humint. https://doiorg.ezproxy.jyu.fi/10.1080/14751798.2017.1377367, 33(4), 380–394. https://doi.org/10.1080/14751798.2017.1377367 Prokofiev, E. (2019). Leveraging Traditional Humint Methodologies in Cyberspace. CyberProof. https://blog.cyberproof.com/blog/leveraging-traditional- humint-methodologies-in-cyberspace Rapid7. (no date). Rapid7 . Retrieved 13.4.2024, from website https://www.rapid7.com/ SOS Intelligence. (no date). SOS Intelligence. Retrieved 13.4.2024, from website https://sosintel.co.uk/ Steele, R. D. (2010). Human Intelligence: All Humans, All Minds, All the Time. http://www.strategicstudiesinstitute.army.mil/ Steinhart, A. (2014). The future is behind us? The human factor in cyber intelligence: Interplay between Cyber-HUMINT, Hackers and Social Engineering. Списание Дипломация. https://web.archive.org/web/20140903143855/http://diplomacy.bg/arch 53 ives/1190%0Ahttps://www.academia.edu/7432960/Cyber_Humint_articl e_end Stottlemyre, S. A. (2015). HUMINT, OSINT, or Something New? Defining Crowdsourced Intelligence. http://dx.doi.org.ezproxy.jyu.fi/10.1080/08850607.2015.992760, 28(3), 578–589. https://doi.org/10.1080/08850607.2015.992760 Tal, A., & Siman-Tov, D. (2015). HUMINT in the Cybernetic Era: Gaming in Two Worlds. 7(3). Teplow, N. (2018). HUMINT: The Riskiest (and Most Valuable) Form of Cyber Intelligence. Rapid7. https://www.rapid7.com/blog/post/2018/09/12/humint-the-riskiest- and-most-valuable-form-of-intelligence-gathering/ Treadstone 71. (no date). Treadstone 71. Retrieved 13.4.2024, from website https://treadstone71.com/ Treadstone 71. (2023). Analyzing Targeted Cyber-HUMINT. Treadstone 71. https://treadstone71.com/intelligence-briefs/analyzing-targeted-cyber- humint Tuomi, J., & Sarajärvi, A. (2009). Laadullinen tutkimus ja sisällönanalyysi (6. uud. laitos). Tammi. Tuomi, J., & Sarajärvi, A. (2018). Laadullinen tutkimus ja sisällönanalyysi (Uudistettu). Kustannusosakeyhtiö Tammi.