Defending Truth, Trust, and Decision Space
Integrate incident response, verification, audience analysis, leadership, legal review, and communication.
In this lesson, you will learn to:
- Build an influence-incident playbook with evidence, audience, communication, and operational decision tracks.
Defending Truth, Trust, and Decision Space
This lesson focuses on preserving the organization’s ability to make and communicate trusted decisions during a cyber-enabled influence incident.
Defend the decision, not only the document
Defending against cyber-enabled influence requires trusted channels, decision records, spokespersons, verification contacts, document provenance, and cross-functional incident command before a leak. When material appears, preserve it safely, establish what was accessed, determine authenticity item by item, identify alterations and omissions, and analyze distribution. Do not let the adversary’s release order set the investigative priority.
Segment audiences and harms. Staff may face exposure; partners may doubt confidentiality; citizens may need service facts; journalists need verifiable context; leadership needs uncertainty and options. Communicate known facts, actions, limitations, and next update time. Avoid repeating sensational claims more than necessary.
Technical takedown alone may amplify censorship narratives. Public rebuttal alone may expose sensitive truth. Compare containment, pre-bunking, direct partner notification, platform coordination, legal action, selective disclosure, and silence against the desired audience behavior.
Measure trust and learn without overclaiming
Track awareness, reach, referral paths, verification demand, partner behavior, staff harm, service use, belief where credible research permits, and concrete actions. Platform impressions are not strategic effect. Establish a baseline of public trust and communication reach before crisis.
Afterward, compare response timing, accuracy, correction rate, partner coordination, audience movement, and operational disclosure. Identify whether the adversary changed topic, channel, persona, or target. Feed indicators into intelligence and exercises. The aim is not perfect narrative control; it is resilient decision space in which authentic institutions can continue to act and correct errors.
Resources
- Information Operations Surrounding the Invasion of Ukraine — Mandiant analysis of hack-and-leak, fabricated material, narrative laundering, established assets, and geopolitical aims.