Louisiana
Louisiana Digital Forensics : LCG Discovery Experts
Address:
306 Morton St. Richmond, TX 77469Latest Blog in The eDiscovery Zone
Trust but Verify Part 6: Human Expertise Still Matters
The Trust but Verify series has examined what happens when digital forensic work becomes increasingly dependent on powerful commercial platforms. Earlier parts considered silent failures, concentration risk, validation, marketplace pressure, and the difficulty of explaining automated output when it becomes evidence. Each issue points to the same professional obligation: forensic software can extend an examiner’s reach, but it cannot assume responsibility for the conclusion.
Part 6 turns to the human side of that obligation. Modern platforms can acquire devices, recover records, normalize timestamps, identify application data, organize communications, correlate locations, and generate reports at a scale that would have been impossible only a few years ago. Those capabilities are valuable, but they do not eliminate the need for analytical judgment. They make that judgment more important because the volume, speed, and apparent completeness of the output can obscure the assumptions that produced it.
From Response to Prevention: Threat Assessments That Actually Matter – Part 5
Organizations frequently use the terms vulnerability assessment, threat assessment, risk assessment, and protective intelligence interchangeably. They are related, but they answer different questions, and confusing them can leave serious gaps in a security program.
A vulnerability assessment examines weaknesses that could be exploited. It considers physical security, technology, policies, staffing, training, communications, and operational practices. In simple terms, it asks: Where are we exposed?
A threat assessment evaluates a person, group, circumstance, or emerging behavior that could cause harm. It considers such factors as intent, capability, access, planning, grievances, escalation, and proximity to a potential target. It asks: Who or what may cause harm, and how likely is the concern to progress?
From Response to Prevention: Security Program to Intelligence Program – Part 4
Traditional security programs generally protect facilities, control access, safeguard assets, and respond when an incident occurs. A risk intelligence program has a broader mission: identify emerging concerns, evaluate information, support leadership decisions, and coordinate preventive action before threatening behavior escalates into violence or operational disruption.
During my public-sector service, I was part of a team that helped transform a statewide security operation from a largely reactive support function into a multidisciplinary risk-intelligence program.
Historically, security was commonly viewed as a building-support service. Its responsibilities included unlocking doors, managing visitors, conducting routine patrols, assisting employees, and responding to incidents. Although these functions were necessary, security was not consistently recognized as a professional investigative, intelligence, or risk-management capability.
That model also meant security was frequently brought into a situation too late. Employees reported concerns to supervisors, who elevated them through multiple levels of management. Individuals without investigative or behavioral-threat-assessment training were effectively deciding whether a concern warranted professional review. Serious warning behaviors could be minimized, while routine workplace conflicts might be escalated based on fear or perception rather than an objective risk assessment.
The transition to risk intelligence changed both the purpose of the security program and how information moved through the organization.




