In our day to day physical routine, there are certain precautions that we can take to protect ourselves. We are aware of our surroundings, we look for changes in the baseline behavior of the persons in the community, we watch for surveillance being conducted on us, etc. But what about in our digital lives? It is here that most of us fail to recognize the vulnerabilities that we create for ourselves. I’ve seen a lot of extremes when it comes to OPSEC with police officers. They either hide everything or they hide nothing. It’s always been this way. However, what we have to realize (and accept) is that we cannot keep our entire lives a secret and expect to live our lives – there has to be a balance. Deleting your entire digital footprint is not realistic or even desirable. But minimizing what is out there for an adversary to use against you is. In this case, an adversary could be the thief that knows cops keep weapons and equipment in their homes or vehicles, or it could be the bad guy that wants to kidnap, harm, or kill you (or your family).
What you have to protect isn’t just people and stuff – you have to protect or at least control what are called indicators. An indicator is something that gives up valuable information about your identity and your vulnerabilities. Realistically, you cannot protect 100% of your indicators. In the physical world every time you put on a uniform, respond to a call, or otherwise identify yourself as a police officer – you reveal an indicator and thus expose yourself to becoming a potential target. In the digital world however, most times you can control these indicators and only reveal what you choose to.
A good balance to reducing your online indicators is to not openly share information about who you are or what you do with people until you feel that you not only trust them, but that they need to know the information. In this respect, you should have a very tight circle of friends that know everything and a wider circle that does not know everything but knows some, and the rest who don’t know anything. By controlling your indicators, you can maintain a proper balance with your OPSEC and still be able to continue with your life – both personal and professional. Consider your social media accounts – Facebook, LinkedIn, Twitter, etc – how many ‘friends’ do you have that you actually know? What about their friends? Do you identify yourself as a police officer? Do you post photos of yourself in uniform? Do you only post articles that support or endorse the law enforcement profession? I’m not saying that any of these things are bad, but every one of them is an indicator of what you do and who you are. Combine these with clues from your comments, (such as, “I’m on the midnight shift – Merry Christmas to me!”) and with the pictures of your family in the backyard; and someone could find out where you live, who else lives there, and even when you’ll be gone. The posting of photos and videos provide deeper insights into you, your family and friends, your house, what you drive, your favorite hobbies, and your interests. All of these are useful for a bad guy to build a target profile of you.
While law enforcement is an honorable profession, it is one where we need to exercise good judgment and appropriate OPSEC. As such I would recommend that law enforcement officers remove or limit their online presence – especially those profiles that identify them as a representative of the law enforcement profession. This means photos, videos, or posts that directly or indirectly associates them with law enforcement. In fact, you should take steps to remove your personal information from internet databases as well. At a minimum, personally identifiable information should be altered to include names, dates of birth, addresses, email addresses, and phone numbers (as a side, but very important note – information about your children should always be kept confidential – where they go to school, their friends, etc). In some cases, keeping your online identity confidential may not always be possible, especially if your agency lists you as a representative for the agency, but you should control the indicators that you can – such as those on your social media accounts.
The key thing to remember is that any information that reveals something about you should be protected. Go through your social media profiles and start scrubbing that information. Then make sure that from now on, you only put information out to those that really need it.