Podcast Icon
Podcast

Most security teams know early warning signs of emerging threats can appear online. The challenge is finding credible intelligence amidst millions of posts spanning an increasingly fractured social media landscape.

AlertMedia recently expanded its Social Intelligence solution with new enhancements designed to improve visibility, streamline analysis, and help organizations identify risks before they escalate.

In this episode, AlertMedia’s Vice President of Risk Intelligence Neil Spencer explains what’s new in Social Intelligence, why these capabilities matter for modern security teams, and how organizations can turn online conversations into actionable intelligence.

Listen in to learn about the latest Social Intelligence enhancements:

  • Expanded Source Coverage: Monitor conversations across over 65 mainstream and fringe, social media platforms, forums and communities to identify emerging threats.
  • AI-Powered User Insights: Identify and link accounts of interest, evaluate intent with AI-enhanced risk assessment, and generate actionable next steps.
  • Integrated Threat Management: Investigate, triage, and escalate threats through a unified workflow that streamlines collaboration and response.
  • Security-Focused Intelligence: Reduce alert fatigue by prioritizing meaningful signals and providing context built specifically for corporate security teams.

Learn more about AlertMedia’s enhanced Social Intelligence capabilities.

Transcript

(Automatically transcribed)

Peter Steinfeld: Hello and welcome to The Employee Safety Podcast from AlertMedia, where you’ll hear advice from industry leaders on how to protect your people and business. I’m Peter Steinfeld.

In the wake of several high-profile incidents targeting executives, monitoring the digital landscape has become a key focus for many security teams. While it’s long been understood that early warning signals often emerge online before they surface in the physical world, cutting through the noise to identify credible threats has gotten harder as conversations happen across an ever-growing number of social platforms, fringe communities, and online forums. Last year, AlertMedia launched Social Intelligence to help security teams more easily identify, monitor, and act on these conversations.

So today I’ve asked Neil Spencer, AlertMedia’s Vice President of Risk Intelligence, to join the show to talk more about what’s new and why it matters. In this episode, Neil not only explains how the new Social Intelligence capabilities help organizations gain greater visibility into emerging risk signals, but also why a more proactive approach to monitoring digital channels should be a critical component of security operations moving forward. Let’s listen in.

Hey, Neil, thanks for being here.

Neil Spencer: Hey, Peter, thanks very much for having me.

Peter Steinfeld: All right, let’s start at a high level. What is social intelligence really?

Neil Spencer: In simple terms, social intelligence is the collection of data from the online domain. So the mainstream social media would be the likes of Instagram, Facebook, TikTok — those that have billions of users. Fringe social media are really much smaller, lesser-used platforms. And in these fringe groups, you start to see polarization of that content, polarization of conversations. And that’s why it’s incredibly important to be aware of where they are, what they’re doing, and the sorts of conversations that are taking place in those locations.

So as part of that emerging social media, deep and dark web — really the online space — enabling organizations to easily understand conversations that might impact their business operations and turn what is essentially data into intelligence. And that’s a really important part of what we’re doing with Social Intelligence. So it’s not just the aggregation of data, it’s that overlay of what that means to your business and business operations.

And importantly for AlertMedia, it also ties back into the overall risk intelligence portfolio. So understanding those conversations in the online space is really one pillar, if you will, of that risk intelligence portfolio — which is where we have a strong specialist team of global intelligence analysts that detect events across the world, be it as they emerge or be it proactively. And those are the bangs and booms, if you will, those kinetic events that might impact business continuity.

And the Social Intelligence element really rounds that out as being that proactive, forward-looking piece of risk — understanding those conversations around your brand, around your executives, around potential controversial topics that your organization may be caught up in. Misinformation, disinformation campaigns. Some of that future horizon scanning, the longer tail of threat intelligence, if you will, which really enables security organizations to be aware as soon as possible of potential threats that might be heading towards their organization. So the goal here is really to enable organizations to get an understanding of the online domain and do that easily and have that overlaid with the understanding of what that means.

Peter Steinfeld: Why is this important to an organization? What core problem is social intelligence designed to solve for?

Neil Spencer: There are over 6 billion social media users in the world, and really that traverses the breadth of content that we’ve just touched on — from mainstream through to fringe and so forth. That’s two out of three people in the world that have access and are using social media. So that’s a lot of intelligence, that’s a lot of information out there. And again, that content can consist of threat intelligence, direct threats made against the organization, misinformation, disinformation campaigns.

And if you imagine security teams trying to sift through all of that content — either you need something like Social Intelligence, a product like Social Intelligence, to do that in an automated fashion, or you need a small army of people, frankly, to go to all of those sites, all of those locations, those hundreds of sites that are out there, and start to sift through manually collecting that. So Social Intelligence from AlertMedia is really designed to take what is almost an unachievable task and make that incredibly achievable.

So when we speak to customers and when they look at their social intelligence capabilities and the programs that they’re using today, we often hear them talk about major concerns. Major concerns include alert overload and fatigue noise. There’s so much content out there — we’ve just touched on the billions of data points that are generated a day. And really getting the signal from the noise is incredibly important to organizations, especially those organizations that have limited resources.

And then limited source coverage — there are platforms out there that are just singular in their collection, singular source. And there are other platforms out there that are designed primarily for monitoring just mainstream. There are some platforms out there that are just designed for monitoring fringe social. And so how do you make sure that as an organization you are getting the best coverage that you can, having the greatest amount of contact with the threat landscape out there?

And that really comes with the benefit of automation, the benefit of automated collection across the breadth of data that is available in the AlertMedia platform — and then also cumbersome workflow. So we hear so often from organizations of the swivel chair effect. You are in a security environment, you are trying to do so many things at once, especially in the event of a crisis. And how do we make sure that users of Social Intelligence have a platform that streamlines their workflows? Time is critical when crises are emerging, or frankly in the day-to-day life of a security team. And therefore, how do we reduce cumbersome workflows? How do we reduce the swivel chair effect? How do we make sure that users of a tool like Social Intelligence can be within one platform and doing everything that they need to do from within one tool? So reducing those workflows, ensuring that they have the coverage that they need, and frankly increasing the signal-to-noise ratio.

Peter Steinfeld: AlertMedia introduced Social Intelligence last year as part of its risk intelligence suite. Since then you’ve continued investing in the solution. What’s changed with these latest upgrades?

Neil Spencer: Obviously nobody puts a product into the market and then stops, especially in the SaaS world and especially in the security world. The security world is forever changing, therefore so are the tools that the practitioners need to adapt to the changing world. And so we launched Social Intelligence last year and, as you say, this is not a new launch — this is an enhancement, this is an expansion of the capabilities. So really we’re rolling out expanded source coverage. We believe that we have some of the best sources in the market, the best coverage in the market — again for the reasons we spoke to earlier. Data collection, data aggregation, and source coverage is part of the DNA of the AlertMedia platform. We pride ourselves on the coverage that we have and what that means and what that enables our customers to access.

And so next up is our upgraded User Insights. The goal of this is really to enable practitioners to quickly and easily assess the authority of a threat that they might detect within the social sphere. And then we’ve also added our Social Intelligence capability to our threat management workflow. What that means is this reduces the swivel chair effect that we spoke to. So the AlertMedia platform enables users to triage content, task content, and really manage their threats as they come through and keep users in the platform to ensure that when time is of the essence, that work distribution is structured and those workflows enable users to go from point A to point B as quickly and easily as possible.

Peter Steinfeld: Those are all incredibly beneficial. So let’s break them down just a bit. What does expanded source coverage add to Social Intelligence?

Neil Spencer: As we’ve discussed, the social media domain is growing, fragmenting almost on a weekly basis. Those conversations are moving from fringe to mainstream, mainstream back to fringe, sometimes from fringe into the deep and dark web. And so what this means is that we are providing organizations with that broader visibility of early indicators and warnings, misinformation, cybercrime chatter, and really where any coordination might appear in that online domain. So detecting that as soon as possible, understanding that as soon as possible, understanding the business impact is critical to that data source expansion.

So really it’s around expanding the breadth of those sources, the depth of those sources, and making sure that we enable, as much as we can, our users to collect data in both an ethical and also a programmatic way that reduces the effort a user may take to collect those sources. Our social media collection now includes 65-plus singular sources across those mainstream, fringe, and dark web sources. And we’re analyzing about 15 million records a day. That is a huge volume of data that we are bringing in.

And really, again, the goal here is that whilst we are expanding the connectivity with the threat landscape, we want to make sure that that volume of data is both accessible but also digestible. So we are ensuring that our users reduce their blind spots within that intelligence framework, within the intelligence landscape, but at the same time making sure that that signal-to-noise ratio is high and also making sure that the data collection is targeted and meaningful to our users. And frankly, it is reducing the need that we’ve seen in the past of using separate tools or manual processes that mean hopping from one platform to another, from one browser to another web browser.

Peter Steinfeld: And why does such broad source coverage matter so much in this category?

Neil Spencer: The conversations that we see online are growing and fragmenting consistently into these fringe groups. And those conversations tend to move from fringe social networks into the mainstream domain. What that means is that understanding conversations when they take place in smaller forums, in ideologically driven forums, in echo chambers — having those early insights and detection in those spaces before they make the leap into mainstream is incredibly important for security practitioners.

And when we see some recent events across the world of executive targeting and the 300% increase in violent threats targeting executives, beyond some of the information narratives that we see around particular brands in the world — again, understanding why the conversations take place and where conversations take place, and what that means to the organization, to your executives, to the people you’re protecting, to your business continuity, is incredibly important. So having that breadth of coverage, having that depth of coverage across multiple sources — more than just mainstream social and into the fringe and into the emerging social media sites — means that you can get that detection early, understand the narrative, understand the potential impact of the threats being made or the conversation taking place before it reaches the mainstream, before it amplifies even further.

Peter Steinfeld: So broad is clearly critical, but so is deep. And another upgrade that you mentioned is User Insights, which I think addresses that. So what does that help customers do?

Neil Spencer: When you’re going through this threat detection process, one of the key things that you’re concerned about is: okay, is this threat real? Is it a bot? Is it something that I should be paying attention to? How do we escalate that? And the goal of User Insights is really to enable practitioners very quickly, very easily, to understand what this means to an organization. What does this threat mean to an organization? Is it credible? Is it a real-world individual, or is it just a bot?

What does the potential post history look like and what does that mean from a threat assessment? Is there ideation about the brand? Is there violent ideation? Are there other concerning elements within some post history that we should be flagging? Security practitioners can quickly help understand whether or not this particular threat is arguably viable or whether we should dismiss and move on because somebody is just having a bad day on a particular channel of choice. So the goal of User Insights is not to be a full-blown investigative platform. It’s for a SOC operator — somebody who’s doing that first initial triage — to assess, understand, and triage what a potential online threat might mean to the organization and what they should do next. So what we’re not doing is taking data elements like PII and ingesting that into the platform. But what we are doing is really making sure that we can look through some of the post history to look for relevant indicators and warnings and, as I mentioned, really assess intent, capability, and other actionable elements that we can use to inform our team and our stakeholders about where we go next with this. And part of that is to be able to create shareable artifacts that we can share internally with our stakeholders so that they can escalate from there.

Peter Steinfeld: Yeah, “what next” is really important, especially with the volume of stuff that’s coming in. So how does the integration with the AlertMedia threat management capability change the workflow?

Neil Spencer: Yeah, absolutely. So we spoke to that world of, okay, we’ve got a threat — now what? Once we’ve assessed, or even once we’ve had that initial threat detection phase, we want to start to loop other team members into this. We start to want to bring that potential threat into a workflow that makes sense. And so what that means is we are now moving it into a Kanban process. Okay, what are we investigating? What are we currently working through? What needs to be worked through? Who is working through that? Who is taking the next step? So assigning individuals, assigning priority, adding notes to a potential threat so that a team can very quickly collaborate.

When we’re looking at operations where time is of the essence, having the visibility across a team of a particular threat, understanding who is owning that threat, and understanding where they are in that threat triage process is incredibly important. So that simple Kanban goes from something that seems like such a simple workflow into an incredibly powerful deliverable that enables people to streamline their work. And it’s not just about our Social Intelligence deliverable either. It’s really combining our Social Intelligence with our threat intelligence. So now users have a single workflow that is easily repeatable, very familiar to users, and it means that users from one location can work through that detection through to potentially dissemination workflow if they need to — if they need to trigger an alert or trigger an incident from a single platform.

Peter Steinfeld: You’ve covered a lot. But stepping back just a little bit, how is social intelligence different from existing social listening or monitoring tools?

Neil Spencer: You know, a lot of people listening to this podcast will be familiar with social listening and many will have the lens of marketing tools. Many an organization has a very well-established social listening capability for brand management purposes versus brand protection purposes. And really those tools are designed far more for understanding sentiment around product launches, the reach that the product launch is having. And so the lens of a traditional social listening tool is very, very different to what we’re doing with AlertMedia.

Within AlertMedia, our Social Intelligence tool is really built for security practitioners, and that means a few different things. It is built for the purpose of detecting threats that are business continuity threats. We’ve spoken to why that is important within the fringe space and why coverage of locations like fringe media, dark web, but also the mainstream web — that holistic view — is incredibly important. And we’ve also spoken to some of the workflows that we’ve touched on. So having that single view of threat intelligence and risk intelligence overlaid into the workflows that enable a user to really take a threat from detection through to resolution — and that resolution and that action could be sending mass communications, it could be creating an incident within the AlertMedia platform. Having all of those workflows within one tool is incredibly important.

And then equally important is the ability to highlight those signals. Signals for a security team are very different to what a signal might mean for a brand protection team or a marketing team. So sentiment classifiers, some of the AI work that we’ve been doing around highlighting signals and noise, are very much around security-driven workflows and security-driven outcomes. And so that’s why AlertMedia’s Social Intelligence capability is a very different offering from something that might be used in a marketing team. The Social Intelligence capability within AlertMedia is there to help security teams detect, assess, escalate, and then respond within a single platform.

Peter Steinfeld: I’m glad you mentioned AI, because it’s really top of mind for just about everyone out there right now. So how is AlertMedia using AI specifically within Social Intelligence?

Neil Spencer: Yeah, it’s tough to escape it these days, right? And this isn’t something new to AlertMedia. AlertMedia has had AI in the tech stack for years at this stage, and really what we’re doing is harnessing AI in a slightly new way within the Social Intelligence world to help elevate content in the platform that otherwise would be manual.

We’ve heard from customers and users that other platforms they may have used involve scrolling through page after page of posts to try and find content that is concerning. And within AlertMedia, we’ve really been mindful about where we utilize AI, because you can’t just throw AI at anything and make it better. You have to be meaningful and purposeful as to how you’re using AI.

So one of the first challenges that we hear from our customers is: hey, it’s hard to build searches. It’s hard to build meaningful searches. And that’s why we’ve implemented AI into our search builder to help people who may not be building Boolean searches every day build a meaningful and purposeful search that collects good data and enables them to get contact with the threat landscape without overwhelming. And so that’s an important piece of the puzzle here. And likewise, once that data is in the platform, how do we summarize that? How do we take those summaries and enable users again to quickly understand — without reviewing every single post — what’s going on in that search, what sort of results have come back, what does that mean to our organization? And are there any particular posts in this search that I should be paying attention to over others? What potential critical content should I be paying attention to? And again, what does it mean to our business?

And likewise, when we look at the language used — language in the online domain is a very interesting facet of social intelligence. Highlighting and understanding negative sentiment around a particular topic is always a useful threat indicator for understanding if particular organizations might be concerned about what’s being said about them online. But also threatening content, violent content, content that contains hate speech. Surfacing those threat indicators to practitioners, to users of the platform, without them having to go and dig for it, is incredibly powerful. We hear from our users constantly that it saves them significant time — in some cases hours of their day, certainly minutes every time they log into the platform. And that starts to add up after a while.

Peter Steinfeld: Well, we’ve talked about what we do and why we do it, but let’s talk examples. Can you share a real-world scenario where social intelligence helped an organization better understand risk?

Neil Spencer: So when we tie together all these pieces of the threat landscape and the overlay of AI — be it to build the initial search or indeed to understand the outcomes — a particular example springs to mind. There is an automotive manufacturer whose name is commonly used in online discourse. For them, it was very hard to really start to understand where their brand name was being used within broader conversational online discussions, or whether or not there was a real threat attached to that name and that particular brand. What they found was that it was incredibly overwhelming to find the signal from the noise. They were just finding noise — constant, constant noise — when they were using generic keyword searches. That noise-to-signal ratio, the noise was far, far too high.

When this particular organization adopted Social Intelligence, they started to break out and bring in content that was meaningful to them. How did they do that? They started to refine their searches, started to use some of the AI support to help them build their searches, started to use those sentiment filters that I spoke about — surfacing meaningful content rather than content that was just using their name. So surfacing violent content, surfacing threatening content, surfacing hate speech. And again, using those AI summaries — because if there’s a little bit of noise in there, sometimes you can’t always avoid all of it, but those AI summaries really enable you to surface the content that is meaningful to you.

So there’s that threefold approach of the AI summaries, the sentiment filters, and the search-building approach that enabled an organization to take something that was almost impossible even with a technology platform. Once they made the switch to using AlertMedia’s Social Intelligence tool, they started to produce relevant insights and in this instance started to truly save them hours of work in reviewing content. So it’s not a lack of information that they sometimes see — before making the change, this particular organization had all the information in the world. But how do you really take that information? How do you take that data and turn it into meaningful insights rather than just too much information?

Peter Steinfeld: Well, looking ahead, how do you see social intelligence changing the way that security teams operate?

Neil Spencer: You know, if you go back 10 years ago, social intelligence and open-source intelligence really was the purview of government organizations. That’s really where this particular domain was most heavily adopted. If you go back five years ago, really this was the purview of very sophisticated security teams that maybe had a lot of resources and also had the threat landscape to have a meaningful social intelligence program.

I think as time moves on — and we’re starting to see this today — the efficiencies that we are building with our Social Intelligence tool means that smaller teams, more efficient teams, can really benefit from social intelligence and what that means to an organization. Getting better insight into what’s going on in the world and what’s going on in the digital space, and what that means to their organization — not only what that means for their organization, but what does that mean for their industry peers? All of those things were very, very hard for smaller teams to do in the past.

Social Intelligence really enables efficiencies to be created to — as I think I mentioned at the top of this conversation — make something that is incredibly powerful but in the past has been incredibly complex to achieve, or time and resource-intensive to access, now become incredibly achievable by teams that need it but historically haven’t been able to do it. So with Social Intelligence, we are really enabling those users — smaller teams and larger enterprise teams alike — to achieve powerful outcomes and time efficiencies that in the past they’ve not been able to.

So that’s near-term. In the future, how do we enable organizations to do more of the same? No organization out there, sadly, is necessarily throwing huge amounts of money at their security teams — we hear it constantly from our customer base. So how do we enable our security practitioners to have even more of an impact with the same resources? Touch more of the internet, understand more of the threat landscape with the same resources. How do we make sure that those workflows are incredibly efficient? How do we make sure that those insights can be gleaned even faster? And how do we make sure that we’re maintaining content connectivity with the threat landscape? So yeah — efficiency, connectivity to the landscape, and making sure that not just the most sophisticated teams have access to a tool like Social Intelligence.

Peter Steinfeld: Yeah, I guess you could say that we’re essentially democratizing this capability, and it’s something AlertMedia really is good at historically.

Neil Spencer: Absolutely. Yeah. It is not an exclusive capability. It is something that should be usable by anybody within a security organization, be it a Fortune 100 or be it a smaller SMB organization. Democratization is absolutely the goal of what we’re working on here.

Peter Steinfeld: Last question before we wrap up. How can listeners learn more about Social Intelligence?

Neil Spencer: You can find us at alertmedia.com, where you can request a demo. And we also just released a white paper that covers many of the topics we’ve discussed today, called the Definitive Guide to Misinformation and Disinformation, that can be found on the website. It’s a great read, and always reach out if you want to learn more.

Peter Steinfeld: Neil, thanks again for joining us and for walking through what these Social Intelligence upgrades mean for security teams.

Neil Spencer: Peter, thanks so much. Looking forward to doing it again sometime.

Peter Steinfeld: To learn more about AlertMedia’s enhanced Social Intelligence capabilities, click the links in the episode description. You can also watch the video highlights on AlertMedia’s YouTube channel. Don’t forget to subscribe, rate, and review the show wherever you get your podcasts. Stay safe out there.

Outro: Thank you for listening to The Employee Safety Podcast from AlertMedia, the world’s leading provider of risk intelligence and response solutions. To learn more about how to protect your people and business during critical incidents, visit alertmedia.com.

Episode Guest

Vice President of Risk Intelligence at AlertMedia

Neil Spencer, AlertMedia
Like What You're Listening to?
Subscribe to The Employee Safety Podcast and get automatically updated when we publish new content!

The Employee Safety Podcast is hosted by Peter Steinfeld, SVP of Safety Solutions at AlertMedia.

You can find this interview and many more by following The Employee Safety Podcast on Spotify or Apple Podcasts.

Peter Steinfeld
About the host

Peter Steinfeld

Peter Steinfeld, Senior Vice President of Safety Solutions at AlertMedia, is passionate about helping organizations protect their people and businesses through all phases of the incident lifecycle. Peter has more than 20 years of experience in emergency communication and employee safety, advising organizations on how to strengthen their approach to risk and resilience.
Discover Everything You Can Accomplish With AlertMedia
See exactly how AlertMedia is built to prepare your organization for the risks of tomorrow, today.

Cookies are required to play this video.

Click the blue shield icon on the bottom left of your screen to edit your cookie preferences.

Cookie Notice