From Mythos to Mechanics: How Frontier AI Policy Shifts Are Rewriting Enterprise Governance

Fig. 1. Infographic Title: From Mythos to Mechanics, Generic/Rights Free, Jeremy Swenson, 2026.

The recent decision to lift restrictions on advanced model deployments from Anthropic represents more than a policy adjustment or regulatory softening. It signals a deeper transition in how frontier AI systems are being treated by governments, enterprises, and oversight bodies: not as static technologies that can be approved or denied once, but as dynamic systems whose behavior, risk profile, and operational impact evolve continuously over time. The significance of this shift is not fully captured in headlines focused on access restoration. Instead, it lies in the subtle but consequential rebalancing of responsibility—from centralized gatekeepers to distributed operators embedded inside enterprise systems.¹

This shift is unfolding alongside a broader geopolitical reclassification of AI systems as controlled strategic infrastructure. As reported by Forbes, the U.S. administration recently lifted export controls on Anthropic’s Mythos 5 and Fable 5 models following a period of heightened national security concern and temporary suspension of access.² Reuters similarly reports that this pattern reflects a new regulatory rhythm: rapid restriction, negotiated mitigation, and conditional restoration rather than permanent prohibition.³ These oscillations are not anomalies—they are becoming the governing structure itself.

At the same time, this policy volatility is occurring against a broader global consolidation of scientific consensus on AI risk. The International AI Safety Report 2026 emphasizes that AI capabilities are advancing faster than safety practices and institutional governance can reliably track.⁴ The report highlights that frontier systems are increasingly autonomous in workflow execution, capable of multi-step reasoning, and difficult to evaluate using static benchmarks alone.⁴ Importantly, it concludes that governance systems are now largely reactive rather than anticipatory, with safety controls lagging behind deployment realities.⁴

More critically, the report identifies a structural mismatch between capability growth and institutional oversight capacity. It notes that frontier AI systems are not improving linearly, but through discontinuous capability jumps driven by scaling, tool use, and inference-time computation.⁴ This creates evaluation blind spots where systems appear safe in testing environments but exhibit materially different behaviors once deployed.

At the core of this transition is a change in what “control” means. Earlier governance models around frontier AI were built on relatively familiar assumptions drawn from software regulation, export controls, and cloud security certification regimes. If a system passed evaluation thresholds, it could be deployed; if it failed, it was restricted or segmented. That logic worked reasonably well when system behavior was stable, deterministic, and tightly scoped. However, frontier AI systems increasingly violate those assumptions. Their outputs are probabilistic, their capabilities shift with prompting techniques, and their risk surfaces expand as they are embedded into broader enterprise ecosystems.⁴

The International AI Safety Report explicitly warns that pre-deployment evaluation alone is insufficient for safety assurance, particularly in systems with tool access, memory, or agentic capabilities.⁴ It recommends continuous post-deployment monitoring as a core governance requirement rather than an optional enhancement.

What emerges instead is a governance posture that resembles continuous assurance rather than static certification. Access becomes conditional, contextual, and dynamic. The report emphasizes the importance of real-world monitoring systems capable of detecting behavioral drift and emergent capabilities after deployment, reinforcing the idea that governance must move into runtime systems rather than remain in pre-release gates.⁴

As these systems return to broader availability, another structural shift becomes visible: the migration of governance responsibility away from regulators and model developers and into enterprise architecture itself. Historically, AI safety and capability constraints were enforced upstream. That separation is eroding rapidly.

Reuters reporting on export control reversals underscores how government decisions are now shaping model availability in near real time, creating a governance environment defined by rapid policy iteration rather than stable regulation.³ Meanwhile, the International AI Safety Report highlights that this instability is mirrored in deployment environments, where inconsistent governance maturity across organizations and jurisdictions creates asymmetric risk exposure.⁴

This downstream shift places new pressure on enterprise functions simultaneously. Cybersecurity teams must model AI behavior as part of threat landscapes. Third-party risk teams must evaluate emergent model behavior, not just vendor controls. Data governance teams must account for indirect leakage pathways through prompts and outputs. Product teams now actively shape risk through interface design, workflow orchestration, and agentic integration choices.

The International AI Safety Report reinforces this transformation by documenting how frontier AI systems are increasingly deployed in agentic configurations, where models execute multi-step tasks, use external tools, and operate with partial autonomy.⁴ These systems blur the line between software and actor, fundamentally altering traditional control assumptions.

Compounding this challenge is the fact that frameworks such as NIST AI RMF and ISO/IEC 42001 assume bounded, testable system behavior. The International AI Safety Report directly challenges this assumption, noting that emergent behaviors often appear only after real-world deployment under complex and shifting conditions.⁴

In cybersecurity contexts, this shift is already visible. The report documents growing evidence of AI systems being used for vulnerability discovery, phishing automation, and large-scale social engineering.⁴ These are not hypothetical risks—they are operational realities emerging in parallel with deployment expansion.

One of the most important but least discussed consequences of this shift is the transformation of AI systems into dynamic or “living” risk surfaces. Unlike traditional software, which changes primarily through version updates, AI systems can change behavior based on context, tool access, and input distribution.⁴ A retrieval-augmented system, for example, may introduce entirely different risk profiles than a base model operating in isolation.

The International AI Safety Report characterizes this as a form of non-stationary risk, where the system being evaluated is not stable over time.⁴ This fundamentally breaks traditional assumptions of static risk modeling. This introduces a shift in security thinking itself. Organizations must move from vulnerability-centric models to behavior-centric models. Weaknesses are no longer purely code-based—they are emergent, interaction-driven, and context-dependent.⁴

From a strategic perspective, the most important implication of expanded frontier model availability is not technical—it is competitive. Organizations that successfully integrate continuous AI governance into operational systems will deploy faster, scale broader, and take more strategic risk safely. Those that treat governance as a bottleneck will slow precisely when speed becomes advantage.

The International AI Safety Report explicitly identifies governance maturity and institutional readiness as key limiting factors in safe AI adoption at scale.⁴ This makes governance capability—not model access—the primary differentiator in enterprise AI maturity.

The next evolution of this landscape is the emergence of an AI control plane architecture: a unified layer that governs model access, routing, policy enforcement, behavioral monitoring, and auditability across environments. In this model, governance becomes infrastructure rather than documentation.

This represents a deeper shift in control theory itself. Static rules give way to continuous negotiation between capability and constraint. Periodic review gives way to continuous observation. Tools become ecosystems.

The lifting of restrictions on advanced models is therefore not an endpoint, but an early signal of a broader transition toward normalized frontier AI deployment under continuous governance conditions. The International AI Safety Report makes clear that this transition is already underway, driven by accelerating capabilities, uneven institutional readiness, and widening oversight gaps.⁴ The organizations that adapt early will not simply comply with this environment—they will define it.

Mitigation & Operational Readiness Playbook:

To translate the governance shift described in this analysis into actionable enterprise capability, organizations must move beyond fragmented controls and toward continuous, behavior-aware AI governance. The first priority is implementing continuous AI behavior monitoring. Rather than treating model evaluation as a pre-deployment checkpoint, enterprises need to track model outputs over time to detect drift, anomalies, and unexpected capability emergence. This effectively reframes AI telemetry as a core security signal, similar in importance to identity logs or network activity, rather than a secondary analytics layer.

In parallel, organizations must establish AI-specific threat modeling practices. Traditional cybersecurity frameworks are insufficient on their own because they assume deterministic system behavior. AI systems introduce new threat vectors such as prompt injection, tool misuse, data exfiltration through outputs, and unintended agentic behavior. These must be explicitly integrated into threat models, extending existing methodologies to account for probabilistic and context-sensitive system responses.

A critical structural requirement is the deployment of an AI control plane architecture. This layer should centralize governance across all models, vendors, and deployment environments. It should enforce consistent policy controls governing access, tool usage, and data exposure while enabling dynamic routing of model requests based on sensitivity, risk tier, and operational context. Without this unified control layer, organizations will struggle to maintain coherent governance across increasingly distributed AI systems.

Data boundary enforcement for large language model interactions also becomes essential. Sensitive information must be prevented from entering prompts unless properly classified and authorized, and all prompt and response flows should be logged to ensure auditability. In practice, this requires extending data loss prevention (DLP) concepts into generative AI pipelines, where the boundary between input, processing, and output is far more fluid than in traditional systems.

Organizations should also adopt post-deployment evaluation frameworks that move beyond static approval cycles. Instead of relying on one-time certification, AI systems must undergo continuous reassessment through red-teaming, adversarial testing, and behavior evaluation in production-like conditions. This allows organizations to identify emergent risks that only appear after models are exposed to real-world inputs, evolving workflows, and integrated toolchains.

Third-party risk management functions must also evolve. Vendor assessment can no longer focus solely on security posture, compliance checklists, or infrastructure controls. It must incorporate behavioral risk—how models actually perform once deployed in dynamic environments. This includes understanding update cycles, tool integrations, and the degree of transparency vendors provide around model behavior and safety limitations.

Agentic workflows represent another critical area of hardening. As models increasingly perform multi-step tasks and interact with external systems, organizations must enforce least-privilege principles on tool access and require human-in-the-loop controls for high-risk actions. These workflows should also be fully logged and treated as security-relevant events, enabling retrospective analysis of autonomous or semi-autonomous decision paths.

At a structural level, AI governance ownership must be elevated to the architectural tier of the enterprise. Responsibility should not be fragmented across cybersecurity, compliance, and product teams, but instead unified within enterprise architecture or security engineering functions that can enforce consistent governance patterns across systems. This alignment is necessary to avoid gaps created by siloed decision-making in highly interconnected AI environments.

Finally, organizations must develop dedicated AI incident response capabilities. These playbooks should define clear escalation paths for model misuse, anomalous behavior, or data leakage events involving AI systems. They should also include operational mechanisms for rapid rollback of model versions, disabling of tool integrations, and containment of affected workflows. In an environment where AI systems are continuously evolving, response speed becomes a critical determinant of organizational resilience.

Endnotes:

  1. Anthropic, frontier model deployment and safety policy communications, 2026.
  2. Siladitya Ray, “Trump Administration Lifts Export Controls on Anthropic’s Mythos 5 and Fable 5 AI Models,” Forbes, July 1, 2026, https://www.forbes.com/sites/siladityaray/2026/07/01/trump-administration-lifts-export-controls-on-anthropics-mythos-5-and-fable-5-ai-models/.
  3. Reuters, “U.S. Lifts Export Controls on Frontier AI Models Following Security Review,” June 2026.
  4. International AI Safety Report, International AI Safety Report 2026 (London: DSIT and international expert consortium, 2026), https://internationalaisafetyreport.org/.
  5. Siladitya Ray, Forbes reporting on U.S. frontier AI policy shift and export control reversal, 2026.

Apple’s Carrier-Level Location Privacy: Strategy, Law, and the Future of Data Control

Fig. 1. Apple’s Carrier-Level Location Privacy Infographic. Jeremy Swenson and Open AI Chat GPT. 2026.

In January 2026, Apple quietly introduced a new privacy control in iOS 26.3 that allows users to limit the precision of location data shared with cellular carriers. While the feature’s initial rollout was narrow—restricted to select devices and carriers—it represents a significant shift in how location data is governed at the network level, with implications for legal investigations, platform competition, and data marketing strategies.1

Unlike app-level location permissions, which have been a focal point of mobile privacy debates for more than a decade, this control targets a less visible layer of the data stack: the information that cellular networks inherently collect as devices connect to towers. By allowing users to reduce carrier access to neighborhood-level rather than precise location data, Apple is challenging long-standing assumptions about the inevitability of carrier-side surveillance.

How the Feature Works—and Why It Matters

The new “Limit Precise Location” setting is found within Cellular Data Options on supported devices running iOS 26.3. When enabled, it reduces the granularity of location data available to participating carriers without degrading network performance or interfering with emergency services.2 Apple has emphasized that precise location data remains available to emergency responders and to apps that users have explicitly authorized, underscoring that the control is designed to limit passive collection rather than eliminate functionality.

At launch, the feature applies only to devices equipped with Apple’s newer C-series modems and is supported by a limited number of carriers, including Boost Mobile in the United States and select providers in Europe and Asia.2 This constrained availability reflects Apple’s vertically integrated approach to privacy: by controlling hardware, operating system, and key software layers, Apple can implement privacy protections that are difficult to standardize across more fragmented ecosystems.

Legal Investigation and Carrier Data: A Shifting Boundary

Carrier-level location data has long been a cornerstone of law-enforcement investigations. Historical cell-tower records can be used to infer a person’s movements, corroborate timelines, or establish proximity to crime scenes. As a result, carriers are frequent recipients of subpoenas and lawful data requests.

By limiting the precision of location data available at the carrier level, Apple’s new feature introduces friction into this investigative model. While it does not prevent lawful access to available data, it may reduce the specificity of records in cases where users have enabled the setting. This development raises important legal questions: if a platform offers a user-controlled mechanism that technically limits data collection, what obligations do carriers retain to preserve or disclose information that no longer exists in high-resolution form?

Security researchers and privacy advocates have framed the feature as a defensive response to the growing misuse of carrier data, including cases where location information has been sold, leaked, or exploited by criminal actors.3 From this perspective, the control is less about obstructing legitimate investigations and more about narrowing the attack surface of sensitive personal data.

Platform Strategy: Apple Versus Android

The contrast with Android is instructive. Android has made substantial progress in recent years with fine-grained app permissions, background location alerts, and transparency dashboards. However, it does not currently offer a system-level control that restricts the precision of location data shared directly with carriers.

This difference reflects deeper architectural realities. Android’s ecosystem spans multiple hardware manufacturers, modem vendors, and carrier customizations, making uniform carrier-level privacy controls difficult to deploy. Apple’s ability to design proprietary modems and tightly integrate them with iOS enables a level of privacy enforcement that is harder to replicate in a more open, modular platform.

From a strategic standpoint, this gives Apple a competitive narrative advantage: privacy not merely as policy, but as product design. While Android remains dominant globally in market share, Apple’s approach positions privacy as a premium feature tied to hardware, reinforcing brand trust among users who are increasingly sensitive to data misuse.

Privacy, Data Marketing, and Consumer Trust

Location data is among the most valuable assets in the data economy. It fuels targeted advertising, behavioral analytics, and predictive modeling across industries. Limiting carrier-level access does not eliminate these practices, but it does alter where and how data is collected.

Apple has been careful to frame this feature as part of a broader philosophy of data minimization rather than an absolute shield. App-level data collection, Wi-Fi triangulation, Bluetooth beacons, and other signals can still reveal detailed location information when users grant permission. The new control instead constrains a historically opaque channel of data flow that users rarely considered or understood.1

For consumers, this reinforces a key reality of modern privacy: meaningful control requires layered defenses. Carrier-level protections, app permissions, and informed usage patterns must work together. For data marketers and brokers, the shift signals a gradual tightening of default access to passive location data, encouraging greater reliance on consent-driven and aggregated sources.

Conclusion: Implications and Best Practices

Apple’s decision to limit precise location data shared with carriers marks an incremental but meaningful evolution in mobile privacy architecture. It highlights the growing tension between user autonomy, lawful access, and commercial data practices, while underscoring the strategic power of vertically integrated platforms.

Looking ahead, several implications stand out:

  1. Legal frameworks may need to adapt to scenarios where high-resolution location data is no longer uniformly available at the carrier level.
  2. Platform competition will increasingly hinge on architectural control, not just policy promises.
  3. Data markets will continue shifting toward explicit consent and diversified data sources as passive collection channels narrow.

Best practices for consumers remain straightforward but essential:

  • Regularly review system-level and app-level privacy settings.
  • Understand the scope and limits of each control.
  • Grant precise location access only when it is necessary for functionality.
  • Stay informed about how platforms and carriers handle personal data.

Ultimately, Apple’s new feature does not end location tracking, nor does it resolve every privacy concern. What it does accomplish is more subtle—and more consequential: it redraws the boundary of what is considered acceptable default data collection in the mobile ecosystem, setting a precedent that others will be pressured to follow.


Endnotes

  1. Apple Inc., “Limit precise location from cellular networks,” Apple Support, accessed January 2026, https://support.apple.com/en-euro/126101.
  2. Chance Miller, “iOS 26.3 Adds New Feature to Limit Location Data Shared With Your Carrier,” 9to5Mac, January 26, 2026, https://9to5mac.com/2026/01/26/ios-26-3-adds-new-feature-to-limit-location-data-shared-with-your-carrier/.
  3. Suzanne Smalley, “New Apple Feature Will Block Cell Networks From Capturing Precise Location Data,” The Record from Recorded Future News, January 29, 2026, https://therecord.media/new-apple-feature-block-location-data-cell-networks.

🛡️ Cyberattack on St. Paul Disrupts Systems, Triggers National Guard Response: A Wake-Up Call for City Infrastructure and Public-Private Security

Fig. 1. St. Paul Cyber Attack, St. Paul, 2025.

A major cyberattack brought critical systems across the City of St. Paul to a halt this week, prompting Governor Tim Walz to take the rare step of activating the Minnesota National Guard’s 177th Cyber Protection Team through Executive Order 24-25. The breach, which has yet to be fully disclosed in technical detail, forced the shutdown of municipal networks, libraries, payment systems, and internal applications—raising alarms about the fragility of local government infrastructure in the digital age.

This crisis has not only impacted operations but also exposed deeper vulnerabilities—from disruption of city services to potential legal and evidentiary breakdowns, especially concerning the chain of custody for digital evidence and sensitive case management platforms used by law enforcement and legal teams.

“The cyberattack… has resulted in a disruption of city services and operations, and the city has requested assistance from the State of Minnesota in the form of technical expertise and personnel,” Gov. Walz stated in the executive order. “The incident poses a threat to the delivery of critical government services.” (Walz, 2025)


Legal and Infrastructure Ramifications:

One often overlooked consequence of cyberattacks on public systems is the risk to legal integrity. City governments often store digital evidence for court cases, police body cam footage, and case records within networked systems. When such systems are compromised or taken offline, the chain of custody—a legal requirement for maintaining the integrity of evidence—may be broken. This could lead to dismissed charges, delayed court proceedings, or contested verdicts.

Beyond the courts, St. Paul’s systems underpin essential infrastructure. From 911 backend operations to building permits, utility management, and emergency communications, these disruptions ripple into residents’ lives and civic trust. Any delay in fire dispatch systems, real-time weather alerts, or even payroll processing for emergency responders can escalate into broader crisis.


Why Public-Private Partnerships Are Essential:

The attack illustrates the need for stronger collaboration between public entities and private cybersecurity firms. Municipalities often operate with limited budgets, aging infrastructure, and insufficient security staff. In contrast, private-sector vendors—ranging from cloud security providers to endpoint monitoring specialists—offer scalable defenses and expertise that cities can’t always sustain in-house.

Governor Walz’s executive order underscores this reality, stating:

“Cooperation between the Minnesota Department of Information Technology Services (MNIT), the National Guard, and other partners is necessary to protect public assets and respond to cybersecurity threats.” (Walz, 2025)

This partnership must also extend beyond technical vendors. Insurance carriers, legal risk consultants, and incident response firms should be part of proactive city planning, not just post-breach triage.


The Human Factor: Employee Training Matters:

While technical systems are critical, human error remains the top vector for cyberattacks, especially through phishing and social engineering. A well-crafted phishing email clicked by a single city employee can introduce malware into core systems.

St. Paul’s situation shows how cybersecurity education is no longer optional. Ongoing staff training—including:

  • Simulated phishing attacks
  • Clear escalation protocols
  • “Stop and verify” culture for email attachments and access requests

…is essential. Cities should treat their staff as the first line of defense, not just passive users.


The Road Ahead: What Cities Must Do Now:

The cyberattack on St. Paul should serve as a regional and national inflection point. Other cities must take this as a cue to reassess their cyber posture through the following:

Strategic Priorities:

  1. Zero Trust Implementation Limit internal access and require constant authentication, even for trusted users.
  2. Third-Party Risk Audits Review vendors, contractors, and outsourced services for security gaps.
  3. Resilient Backup and Recovery Ensure data is stored offsite and tested regularly for recovery readiness.
  4. Legal and Digital Forensics Planning Build frameworks for protecting the chain of custody in case of breach.
  5. Integrated Public-Private Playbooks Define shared roles between city staff, Guard units, and private partners in cyber response drills.
  6. Community Transparency Proactively inform the public about risks, responses, and what’s being done to rebuild digital trust.

Final Thoughts:

The breach in St. Paul is not just a local IT issue—it is a civic security event that affects courts, emergency services, legal integrity, and public confidence. Governor Walz’s activation of the National Guard is a bold signal that digital defense is now a matter of public safety.

“Immediate action is necessary to provide technical support and ensure continuity of operations,” reads Executive Order 24-25 (Walz, 2025).

Moving forward, public-private partnerships, cybersecurity training, and legal readiness must become foundational to how cities govern in the digital era. The stakes are no longer theoretical—they are real, operational, and deeply human.


References:

  1. FOX 9. (2025, July 29). Gov. Walz activates National Guard after cyberattack on city of St. Paul. https://www.fox9.com/news/gov-walz-activates-national-guard-after-cyberattack-st-paul
  2. KSTP. (2025, July 29). City of St. Paul experiencing unplanned technology disruptions. https://kstp.com/kstp-news/top-news/city-of-st-paul-experiencing-unplanned-technology-disruptions/
  3. League of Minnesota Cities. (2024, October). Cybersecurity Incident Reporting Requirements for Cities. https://www.lmc.org/news-publications/news/all/fonl-cybersecurity-incident-reporting-requirements/
  4. Reddit. (2025, July 29). Minnesota National Guard activated after city cyberattack [Discussion threads]. https://www.reddit.com/r/minnesota
  5. Walz, T. (2025, July 29). Executive Order 24-25: Activating the Minnesota National Guard Cyber Protection Team. Office of the Governor, State of Minnesota. https://mn.gov/governor/assets/EO-24-25_tcm1055-621842.pdf

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years, he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even government entities. Organizations appreciate his talent for bridging gaps, uncovering hidden risk management solutions, and simultaneously enhancing processes. He is a frequent speaker, podcaster, and a published writer – CISA Magazine and the ISSA Journal, among others. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MBA from Saint Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Cyber Security Summit Think Tank , the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy. He also has certifications from Intel and the Department of Homeland Security.

Titans of the Trade: Six Hedge Fund Visionaries

Fig. 1. Hedge Fund Infographic, Generic Rights Free, 2025.


Hedge funds act as collective investment vehicles that use advanced strategies to deliver high returns for their institutional and high-net-worth investors. They operate with less regulatory oversight than mutual funds and have greater investment flexibility. Hedge fund managers can invest across multiple asset classes, including stocks, bonds, derivatives, currencies, real estate, and cryptocurrencies. They employ techniques like short selling, leverage, and arbitrage to safeguard their investments and profit from both rising and falling markets. Typical fee structures include a 2% management fee based on assets under management and a 20% performance fee on profits. Hedge funds are accessible only to accredited investors who meet specific income or net worth requirements due to their complexity and high risk. Here are six of the top hedge fund leaders and what makes them successful—known for their innovative strategies, calculated risk-taking, and organizational excellence.


1. Bill Ackman

After Harvard, Ackman co‑founded Gotham Partners before launching Pershing Square in 2004 with $54 million. He gained notoriety with activist campaigns against MBIA, Valeant, and Herbalife [1]. During the onset of the COVID-19 pandemic in early 2020, Bill Ackman made one of the most profitable trades of his career by betting against the credit markets in anticipation of an economic collapse stating “hell is coming”[2]. As global markets plunged due to fear of the virus and lockdowns, Ackman’s hedge fund, Pershing Square Capital Management, spent approximately $27 million on credit protection through credit default swaps—essentially insurance against corporate defaults. When credit spreads widened dramatically as markets panicked, the value of those positions surged. In less than a month, Pershing Square turned that $27 million into $2.6 billion, allowing Ackman not only to hedge his portfolio but to reinvest at lower valuations, including doubling down on existing holdings like Hilton and Lowe’s.$1.25 billion by trading on inflation forecasts [2][3]. Despite steep losses involving Valeant and J.C. Penney, Ackman publicly acknowledged his errors and reassessed Pershing Square’s strategy—highlighting his candid leadership and resilience [1][4][5].

2. Ken Griffin

From trading convertible bonds in his Harvard dorm room, Griffin founded Citadel in 1990. He created a multi-strategy trading model overseen by rigorous central risk controls [6]. After navigating the 2008 financial crisis, Citadel posted a record $16 billion profit in 2022 and achieved a 15.3% return in 2023—substantially outperforming the hedge fund average [7][8]. Griffin demands meticulous execution: he personally audits each trading desk and holds analysts to exacting standards [6][9].

3. Kyle Bass

Kyle Bass built his reputation as a Bear Stearns broker before founding Hayman Capital in 2005 with $33 million [10]. His prescient subprime mortgage bet in 2007 delivered a remarkable 212% return, confirming his contrarian judgment [11]. Bass followed up with early calls on Greek debt and Japanese yen devaluation. Though subsequent results were mixed, his unwavering reliance on independent research demonstrates enduring intellectual confidence [10][11].

4. Israel “Izzy” Englander

Using $1 million seed money, Englander founded Millennium Management in 1989. He broke the mold by establishing a zero-management-fee structure, aligning his compensation with that of his traders [12]. Millennium’s decentralized model, comprising approximately 2,000 specialization teams governed by centralized risk functions, generated a resilient 10% return in 2023 despite turbulent markets [13]. Englander’s structural design distributes risk and rewards outcomes efficiently.

5. Steve Cohen

Cohen entered the business world at Gruntal & Co. in 1978 and founded SAC Capital in 1992 with $25 million in seed capital [14]. Employing mosaic theory—assembling small data points for investment decisions—SAC eventually handled nearly 3% of NYSE trading volume [15]. Even after a $1.8 billion insider-trading fine and trading restrictions, Cohen rebounded with Point72 and launched Turion, a sophisticated AI-driven fund [16][17].

6. David Tepper

Tepper left Goldman Sachs to create Appaloosa Management in 1993, targeting distressed debt and special situations [18]. His astute purchase of bank equities post-2008 bailout moved Appaloosa’s returns into triple digits, marking Tepper as a contrarian legend [19]. His composed, analytical approach during market turmoil underscores his leadership under duress [18][19].


Common Threads That Elevate Them

  1. Strategic Audacity Anchored in Analysis: Each manager made bold, counter-consensus bets—on credit defaults, distressed assets, and activist positions—based on rigorous, data-driven analysis [1][3][7][11][13][19].
  2. Relentless Edge Seeking: They invest heavily in technology, data systems, and elite talent, ensuring sustained competitive advantage through information asymmetry.
  3. Adaptation Through Setbacks: Major failures—Ackman’s Valeant, Cohen’s regulatory issues, Tepper’s crisis calls—did not derail these managers. Instead, they rebuilt stronger by learning from mistakes.
  4. Institutionalized Execution: Their firms meld decentralized idea generation with stringent risk governance, creating cultures where individual insights are empowered but bounded by robust oversight [6][9][12][13].

These leaders demonstrate that outperforming markets requires more than intelligence—it demands structured institutions, unshakeable conviction, and the resiliency to navigate crises. Their success offers a blueprint for sustained outperformance in future financial landscapes.


References

  1. Ackman, B. (2004). Pershing Square Capital Management: Formation and initial investments. Gotham Partners Archive.
  2. Ackman, B. (2020, March). “Hell is coming” and COVID‑19 credit default swap bets. Vanity Fair.
  3. Ackman, B. (2020). Inflation hedge performance: $1.25 billion gains. Pershing Square Quarterly Report, 1(2).
  4. Ackman, B. (2021). Public admissions regarding Valeant and J.C. Penney losses. Pershing Square disclosures.
  5. Pershing Square. (2022). Strategic recovery and firm recalibration reports.
  6. Citadel Risk Oversight Team. (n.d.). Trading desk structure and internal audits. Citadel Risk & Governance Reports.
  7. Griffin, K. (2022). Citadel’s record profit. The Wall Street Journal.
  8. Griffin, K. (2024). Citadel’s 2023 performance report: 15.3% return vs. 7.4% average. Citadel Annual Review.
  9. Reuters/Benzinga. (2023). Citadel audit and trading desk oversight features.
  10. Bass, K. (2005). Founding of Hayman Capital Management. Hayman Capital Press Release.
  11. Bass, K. (2007). Subprime mortgage collapse: A 212% return for Hayman. Hayman Investor Letter.
  12. Englander, I. (1989). Millennium Management founding and zero-fee structure. Millennium Quarterly.
  13. Millennium Management. (2024). 2023 performance: 10% return in challenging markets. Millennium Annual Report.
  14. Cohen, S. (1992). Founding of SAC Capital. SAC Capital Company Archive.
  15. Cohen, S. (2005). Mosaic theory and market share, up to 3% of NYSE. Trading Insights Journal.
  16. U.S. Securities and Exchange Commission. (2013). Insider-trading settlement and ban of SAC Capital. SEC Litigation Release.
  17. Point72 Asset Management. (2023). Launch of Turion AI quantitative fund. Point72 Press Release.
  18. Tepper, D. (1993). Founding of Appaloosa Management. Appaloosa Press Release.
  19. Tepper, D. (2009). Contrarian bank-bailout bets in 2008: Performance analysis. Appaloosa Manager Report.

Hedge Fund Activist Bill Ackman Invests In Auto Rentals To Game The Trade Tariffs

Fig. 1. Bill Ackman Auto Tariff Infographic, 2025, Jeremy Swenson.

Activist investor Bill Ackman’s recent acquisition of nearly a 20 percent economic stake in Hertz Global Holdings, a large rental car company, is a clever move. It is based on a complex tariff argument that has the potential to significantly increase returns and the residual values of Hertz’s roughly 500,000-car fleet. In addition to propelling Hertz’s stock to record one-day gains, Ackman has demonstrated how trade restrictions may act as powerful tailwinds for cyclical companies by fusing profound policy knowledge with distressed asset investment.

Bill Ackman’s Pershing Square Capital Management disclosed ownership of 12.7 million shares of Hertz—costing about $46.5 million—which equates to a 4.1 percent direct equity stake in the company.(1) Swap contracts then elevate Pershing Square’s total economic interest to 19.8 percent of Hertz’s outstanding stock, making Ackman the second‑largest stakeholder behind Knighthead Capital and BlackRock.(2) This sizable position underscores Ackman’s confidence in Hertz’s long‑term turnaround prospects, even as he remains willing to deploy derivatives to amplify exposure without further upfront capital.(3)

The market’s response was swift and dramatic: Hertz shares surged 56.4 percent in regular trading—closing at $5.71—immediately after the SEC filing disclosure, then leapt 33.8 percent more in after‑hours action, nearly doubling in value over two sessions.(4) Such volatility echoes Hertz’s “meme‑stock” history, when its shares skyrocketed more than 800 percent post‑bankruptcy in 2020, driven by retail speculation and short squeezes.(5)

Beyond conventional value metrics, Ackman highlighted that U.S. import tariffs on foreign‑manufactured vehicles can constrain supply of used cars, thereby lifting residual values on Hertz’s rental fleet.(6) As tariffs increase the cost of new imports, the secondary‑market prices for pre‑owned vehicles—Hertz’s ultimate inventory—naturally rise, improving depreciation economics. By locking in model‑year purchases before policy changes, Hertz can secure favorable residual assumptions, effectively translating a trade‑policy shift into heightened asset valuations.(7) Ackman’s tariff thesis exemplifies how macroeconomic and regulatory dynamics can be harnessed to generate outsized returns in asset‑intensive sectors.(8)

Hertz’s dramatic rebound belies underlying challenges. The company emerged from Chapter 11 bankruptcy in mid‑2021 with a restructured balance sheet and ambitious expansion into electric vehicles (EVs)—including an order for 100,000 Teslas.(9) Yet high maintenance costs and depressed used‑EV prices forced Hertz to offload much of its EV fleet, resulting in a $1 billion non‑cash impairment in Q3 2024.(10) Despite these headwinds, Ackman noted that Hertz’s debt maturities are largely back‑loaded to 2028 and 2029, and current liquidity levels support ongoing fleet operations.(11) Going forward, Pershing Square’s substantial stake positions Ackman to advocate for management changes or strategic initiatives—ranging from fare restructuring to fleet optimization—to sustain momentum.(12)

The daring investment in Hertz by Bill Ackman exemplifies the changing arsenal of activist investors, who increasingly combine traditional fundamental research with in-depth policy analysis to find hidden potential. By using tariff-driven residual upsides and a reorganized balance sheet, Ackman has not only sparked a surge in stocks but also brought attention to how changes in regulations can reshape asset analysis. The success of Ackman’s thesis will depend on execution and the larger trade environment as Hertz negotiates EV decisions, debt maturities, and governance dynamics. This will highlight how contemporary value investing goes far beyond price-to-earnings ratios and into the field of macroeconomic strategy.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years, he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even government entities. Organizations appreciate his talent for bridging gaps, uncovering hidden risk management solutions, and simultaneously enhancing processes. He is a frequent speaker, podcaster, and a published writer – CISA Magazine and the ISSA Journal, among others. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MBA from Saint Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Cyber Security Summit Think Tank , the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy. He also has certifications from Intel and the Department of Homeland Security.


Endnotes:

  1. Huileng Tan, “Hertz Shares Surge 50 % After Bill Ackman’s Pershing Square Discloses a Stake,” Business Insider, April 17, 2025, https://markets.businessinsider.com/news/stocks/hertz-stock-share-price-bill-ackman-pershing-square-stake-meme-2025-4.
  2. Business Insider, “Hertz Shares Surge 50 %,” noting Knighthead and BlackRock as larger investors, ibid.
  3. “Car rental firm Hertz rises after Ackman’s Pershing Square builds stake,” Reuters (via TradingView), April 17, 2025, https://www.tradingview.com/news/reuters.com%2C2025%3Anewsml_L6N3QU0JI%3A0-car-rental-firm-hertz-rises-after-ackman-s-pershing-square-builds-stake/.
  4. “Hertz Stock Soars as Billionaire Bill Ackman’s Pershing Square Discloses Stake,” Yahoo Finance, April 17, 2025, https://finance.yahoo.com/news/hertz-surges-ackman-pershing-square-202632370.html.
  5. Huileng Tan, “Hertz Shares Surge 50 %…” Business Insider.
  6. “Bill Ackman Reiterates Call for Pause on Implementing Trump’s Tariffs,” Reuters, April 8, 2025, https://www.reuters.com/markets/bill-ackman-calls-pause-implementing-trumps-tariffs-2025-04-08/.
  7. Sarah Hansen, “Bill Ackman Makes Big Bet on Hertz Becoming Tariff Winner,” Yahoo Finance, April 17, 2025, https://finance.yahoo.com/news/ackman-says-pershing-owns-19-203543846.html.
  8. “Bill Ackman Confirms Nearly 20 % Stake in Hertz, Floats Uber Partnership,” Investing.com, April 17, 2025, https://www.investing.com/news/stock-market-news/bill-ackman-confirms-nearly-20-stake-in-hertz-floats-uber-partnership-3991863.
  9. “Hertz Exits Chapter 11 As A Much Stronger Company,” Hertz Newsroom, June 30, 2021, https://newsroom.hertz.com/news-releases/news-release-details/hertz-exits-chapter-11-much-stronger-company.
  10. Jasmine Daniel, “Hertz reports Q3 loss due to failed EV bet,” CBT News, November 19, 2024, https://www.cbtnews.com/hertz-reports-q3-loss-due-to-failed-ev-bet/.
  11. “Bill Ackman Confirms Nearly 20 % Stake…” Investing.com.
  12. Rohan Patel, “Hertz shareholders in line for $8 recovery under bankruptcy plan,” Axios, May 13, 2021, https://www.axios.com/2021/05/13/hertz-shareholders-bankruptcy-investors-stock.

DeepSeek R1: A New Chapter in Global AI Realignment

Fig. 1. DeepSeek and Global AI Change Infographic, Jeremy Swenson, 2025.

Minneapolis—

DeepSeek, the Chinese artificial intelligence company founded by Liang Wenfeng and backed by High-Flyer, has continued to redefine the AI landscape since the explosive launch of its R1 model in late January 2025. Emerging from a background in quantitative trading and rapidly evolving into a pioneer in open-source LLMs, DeepSeek now stands as a formidable competitor to established systems like OpenAI’s ChatGPT and Microsoft’s proprietary models available on Azure AI. This article provides an expanded analysis of DeepSeek R1’s technical innovations, detailed comparisons with ChatGPT and Microsoft Azure AI offerings, and the broader economic, cybersecurity, and geopolitical implications of its emergence.


Technical Innovations and Architectural Advances:

Novel Training Methodologies DeepSeek R1 leverages a cutting-edge combination of pure reinforcement learning and chain-of-thought prompting to achieve human-like reasoning in tasks such as advanced mathematics and code generation. Unlike traditional LLMs that rely heavily on supervised fine-tuning, DeepSeek’s R1 is engineered to autonomously refine its reasoning steps, resulting in greater clarity and efficiency. In early benchmarking tests, R1 demonstrated the ability to solve multi-step arithmetic problems in approximately three minutes—substantially faster than ChatGPT’s o1 model, which typically required five minutes (Sayegh, 2025).

Cloud Integration and Open-Source Deployment One of R1’s key strengths lies in its open-source availability under an MIT license, a stark contrast to the closed ecosystems of its Western counterparts. Major cloud platforms have rapidly integrated R1: Amazon has deployed it via the Bedrock Marketplace and SageMaker, and Microsoft has incorporated it into its Azure AI Foundry and GitHub model catalog. This wide accessibility not only allows for extensive external scrutiny and customization but also enables enterprises to deploy the model locally, ensuring that sensitive data remains under domestic control (Yun, 2025; Sharma, 2025).


Detailed Comparison with ChatGPT:

Performance and Reasoning Clarity ChatGPT’s o1 model has been widely recognized for its robust reasoning capabilities; however, its closed-source nature limits transparency. In direct comparisons, DeepSeek R1 has shown parity—and in some cases superiority—with respect to reasoning clarity. Independent tests by developers indicate that R1’s intermediate reasoning steps are more comprehensible, facilitating easier debugging and iterative query refinement. For example, in complex multi-step problem-solving scenarios, R1 not only delivered correct solutions more rapidly but also provided detailed, human-like explanations of its thought process (Sayegh, 2025).

Cost Efficiency and Accessibility While premium access to ChatGPT’s capabilities can cost users upwards of $200 per month, DeepSeek R1 offers its advanced functionalities free of charge. This dramatic reduction in cost is achieved through efficient use of computational resources. DeepSeek reportedly trained R1 using only 2,048 Nvidia H800 GPUs at an estimated cost of $5.6 million—an expenditure that is a fraction of the resources typically required by U.S. competitors (Waters, 2025). Such cost efficiency democratizes access to high-performance AI, providing significant advantages for startups, academic institutions, and small businesses.


Detailed Comparison with Microsoft Azure AI:

Integration with Enterprise Platforms Microsoft has long been a leader in providing enterprise-grade AI solutions via Azure AI. Recently, Microsoft integrated DeepSeek R1 into its Azure AI Foundry, offering customers an additional open-source option that complements its proprietary models. This integration allows organizations to leverage R1’s powerful reasoning capabilities while enjoying the benefits of Azure’s robust security, compliance, and scalability. Unlike some closed-source models that require extensive licensing fees, R1’s open-access nature under Azure enables organizations to tailor the model to their specific needs, maintaining data sovereignty and reducing operational costs (Sharma, 2025).

Performance in Real-World Applications In practical applications, users on Azure have reported that DeepSeek R1 not only matches but sometimes exceeds the performance of traditional models in complex reasoning and mathematical problem-solving tasks. By deploying R1 locally via Azure, enterprises can ensure that sensitive computations are performed in-house, thereby addressing critical data privacy concerns. This localized approach is particularly valuable in regulated industries, where strict data governance is paramount (FT, 2025).


Market Reactions and Economic Implications:

Immediate Market Response and Stock Volatility The initial launch of DeepSeek R1 triggered a significant market reaction, most notably an 18% plunge in Nvidia’s stock as investors reassessed the cost structures underlying AI development. The disruption led to a combined market value wipeout of nearly $1 trillion across tech stocks, reflecting widespread concern over the implications of achieving top-tier AI performance with significantly lower computational expenditure (Waters, 2025).

Long-Term Investment Perspectives Despite the short-term volatility, many analysts view the current market corrections as a temporary disruption and a potential buying opportunity. The cost-efficient and open-source nature of R1 is expected to drive broader adoption of advanced AI technologies across various industries, ultimately spurring innovation and generating new revenue streams. Major U.S. technology firms, in response, are accelerating initiatives like the Stargate Project to bolster domestic AI infrastructure and maintain global competitiveness (FT, 2025).


Cybersecurity, Data Privacy, and Regulatory Reactions:

Governmental Bans and Regulatory Scrutiny DeepSeek’s practice of storing user data on servers in China and its adherence to local censorship policies have raised significant cybersecurity and privacy concerns. In response, U.S. lawmakers have proposed bipartisan legislation to ban DeepSeek’s software on government devices. Similar regulatory actions have been taken in Australia, South Korea, and Canada, reflecting a global trend of caution toward technologies with potential national security risks (Scroxton, 2025).

Security Vulnerabilities and Red-Teaming Results Independent cybersecurity tests have revealed that R1 is more prone to generating insecure code and harmful outputs compared to some Western models. These findings have prompted calls for more rigorous red-teaming and continuous monitoring to ensure that the model can be safely deployed at scale. The vulnerabilities underscore the necessity for both DeepSeek and its adopters to implement robust safety protocols to mitigate potential misuse (Agarwal, 2025).


Geopolitical and Strategic Implications:

Challenging U.S. AI Dominance DeepSeek R1’s emergence is a clear signal that high-performance AI can be developed without the massive resource investments traditionally associated with U.S. models. This development challenges the long-standing assumption of American technological supremacy and has prompted a strategic reevaluation among U.S. policymakers and industry leaders. In response, initiatives such as Microsoft’s Stargate Project are being accelerated to ensure that the U.S. maintains its competitive edge in the global AI arena (Karaian & Rennison, 2025).

Localized AI Ecosystems and Data Sovereignty To mitigate cybersecurity risks, several U.S. companies are now repackaging R1 for localized deployment. By ensuring that sensitive data remains on domestic servers, these firms are not only addressing privacy concerns but also paving the way for the creation of robust, localized AI ecosystems. This trend could ultimately reshape global data governance practices and alter the balance of technological power between the U.S. and China (von Werra, 2025).


Conclusion and Future Outlook:

DeepSeek R1 represents a watershed moment in the global AI race. Its technical innovations, cost efficiency, and open-source approach challenge entrenched assumptions about the necessity of massive compute power and proprietary control. In direct comparisons with systems like ChatGPT’s o1 and Microsoft’s Azure AI offerings, R1 demonstrates superior transparency and operational speed, while also offering unprecedented accessibility. Despite ongoing cybersecurity and regulatory challenges, the disruptive impact of R1 is catalyzing a broader realignment in AI development strategies. As both U.S. and Chinese technology ecosystems adapt to these shifts, the future of AI appears poised for a more democratized, competitively diverse, and strategically complex evolution.


About The Author:

Jeremy A. Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and seasoned senior management tech risk and digital strategy consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota’s Technological Leadership Institute, an MBA from Saint Mary’s University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale, and New Hope Community Police Academy (MN), and the Minneapolis FBI Citizens Academy. You can follow him on LinkedIn and Twitter.


References:

  1. Yun, C. (2025, January 30). DeepSeek-R1 models now available on AWS. Amazon Web Services Blog. Retrieved February 8, 2025, from https://aws.amazon.com/blogs/aws/deepseek-r1-models-now-available-on-aws/
  2. Sharma, A. (2025, January 29). DeepSeek R1 is now available on Azure AI Foundry and GitHub. Microsoft Azure Blog. Retrieved February 8, 2025, from https://azure.microsoft.com/en-us/blog/deepseek-r1-is-now-available-on-azure-ai-foundry-and-github/
  3. Waters, J. K. (2025, January 28). Nvidia plunges 18% and tech stocks slide as China’s DeepSeek spooks investors. Business Insider Markets. Retrieved February 8, 2025, from https://markets.businessinsider.com/news/stocks/nvidia-tech-stocks-deepseek-ai-race-nasdaq-2025-1
  4. Scroxton, A. (2025, February 7). US lawmakers move to ban DeepSeek AI tool. ComputerWeekly. Retrieved February 8, 2025, from https://www.computerweekly.com/news/366619153/US-lawmakers-move-to-ban-DeepSeek-AI-tool
  5. FT. (2025, January 28). The global AI race: Is China catching up to the US? Financial Times. Retrieved February 8, 2025, from https://www.ft.com/content/0e8d6f24-6d45-4de0-b209-8f2130341bae
  6. Agarwal, S. (2025, January 31). DeepSeek-R1 AI Model 11x more likely to generate harmful content, security research finds. Globe Newswire. Retrieved February 8, 2025, from https://www.globenewswire.com/news-release/2025/01/31/3018811/0/en/DeepSeek-R1-AI-Model-11x-More-Likely-to-Generate-Harmful-Content-Security-Research-Finds.html
  7. Karaian, J., & Rennison, J. (2025, January 28). The day DeepSeek turned tech and Wall Street upside down. The Wall Street Journal. Retrieved February 8, 2025, from https://www.wsj.com/finance/stocks/the-day-deepseek-turned-tech-and-wall-street-upside-down-f2a70b69
  8. von Werra, L. (2025, January 31). The race to reproduce DeepSeek’s market-breaking AI has begun. Business Insider. Retrieved February 8, 2025, from https://www.businessinsider.com/deepseek-r1-open-source-replicate-ai-west-china-hugging-face-2025-1
  9. Sayegh, E. (2025, January 27). DeepSeek is bad for Silicon Valley. But it might be great for you. Vox. Retrieved February 8, 2025, from https://www.vox.com/technology/397330/deepseek-openai-chatgpt-gemini-nvidia-china

Foreign Threat Actors Amplify Disinformation Ahead of 2024 U.S. Election, Warn FBI and CISA

Minneapolis—

As the 2024 U.S. general election nears, the FBI and CISA have issued a public service announcement to alert the public about foreign disinformation campaigns.[1] These campaigns, led by foreign adversaries, aim to undermine voter confidence by spreading false narratives before, during, and after Election Day. Despite these efforts, the FBI and CISA confirm that there is no evidence of malicious cyber activity compromising U.S. election infrastructure, including voter registration systems, ballots, or vote-counting processes.

Evolving Disinformation Tactics with AI:

The disinformation campaigns have become more sophisticated due to the use of generative AI tools, which allow foreign actors to create convincing fake content, such as AI-generated articles, deepfake videos, and synthetic media.[2] These false narratives are then spread across multiple platforms, both in the U.S. and abroad. By lowering the barrier for creating and distributing disinformation, AI has made it easier for foreign actors to mislead the public and erode trust in the election process.

Disinformation Campaigns from Russia and Iran:

Russia and Iran are identified as the primary foreign actors behind many of these disinformation efforts. Russian operatives have set up AI-enhanced social media bot farms and cybersquatted on domains mimicking legitimate news websites, such as “washingtonpost.pm” and “foxnews.in,” to disseminate propaganda. The DOJ responded by seizing over 30 of these domains and indicting individuals linked to Russian government-controlled media outlets that covertly funded U.S. influence campaigns.

Iran, too, has engaged in similar efforts, with recent DOJ charges against Iranian nationals accused of hacking and leaking U.S. campaign materials to manipulate the election outcome.

Public Recommendations:

To help combat the spread of disinformation, FBI and CISA urge the public to:

  • Educate themselves about foreign influence operations, especially AI-generated content.
  • Rely on trusted sources, such as state and local election officials, to verify election-related claims.
  • Understand AI-generated content by looking for clues that content may be doctored or synthetic.
  • Report suspicious activity or disinformation attempts to the FBI.

Election Security Efforts:

Federal, state, and local authorities are collaborating to safeguard U.S. elections. The FBI investigates election crimes and foreign influence campaigns, while CISA works to secure election infrastructure. Jen Easterly, director of CISA, has reassured voters that the systems are more secure than ever, with robust cybersecurity measures in place, including paper ballot records that verify vote counts in 97% of jurisdictions.

Easterly emphasized that, although foreign adversaries will continue to attempt to influence U.S. elections, they will not be able to alter the final outcome. She also encouraged patience as election results may take time to finalize and urged the public to trust official sources. Being an election judge is not a bad idea either.

Conclusion:

As Election Day approaches, foreign disinformation campaigns remain a threat, but significant efforts have been made to secure the election process. With the support of informed voters and coordinated efforts from election officials, the integrity of U.S. elections can be maintained. We in the private sector need to share and support these efforts, as CISA, and the FBI cannot be everywhere.

About the Author:

Jeremy A. Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and seasoned senior management tech risk and digital strategy consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota’s Technological Leadership Institute, an MBA from Saint Mary’s University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale, and New Hope Community Police Academy (MN), and the Minneapolis FBI Citizens Academy. You can follow him on LinkedIn and Twitter.


[1] CISA. “FBI and CISA Issue Public Service Announcement Warning of Tactics Foreign Threat Actors are Using to Spread Disinformation in the 2024 U.S. General Election.” 10/18/24. https://www.cisa.gov/news-events/news/fbi-and-cisa-issue-public-service-announcement-warning-tactics-foreign-threat-actors-are-using

[2] CISA. “FBI and CISA Issue Public Service Announcement Warning of Tactics Foreign Threat Actors are Using to Spread Disinformation in the 2024 U.S. General Election.” 10/18/24. https://www.cisa.gov/news-events/news/fbi-and-cisa-issue-public-service-announcement-warning-tactics-foreign-threat-actors-are-using

Silicon Valley Bank Fails Due to Lack of Diversification, Weak Governance, and Hype – Creating a Bank Run

Fig. 1. Silicon Valley Bank Cash Transfer Vehicle, Justin Sullivan, Getty Images, 2023.

#svbfailure #svbbank #siliconvalleybank #cryptobank #venturetech #cryptofraud #bankgovernance #bankcomplaince #FDICSVB

Silicon Valley Bank Federal Deposit Insurance Corporation (FDIC) OCC California Department of Financial Protection and Innovation

The California Department of Financial Protection closed Silicon Valley Bank (SVB) on Fri 03/10/23 and the FDIC took control of and seized its deposits in the largest U.S. banking failure since the 2008 to 2012 mortgage financial crisis, and the second largest ever. Although SVB was well known in San Francisco and Boston where they had all of their 17 branches; they were little to known to the wider public. SVB specialized in financing start-ups and had become the 16th largest U.S. bank by assets. Their numbers at the end of 2022 were impressive with $209 billion in assets and approximately $175.4 billion in deposits.

As a precursor to their failure, SVB recorded six straight quarterly losses as economic conditions turned unfavorable. Then on Mon 02/27/23 their CEO Greg Becker sold $3.6 million of stock in a pre-arraigned 10b5-1 plan designed to reduce conflict of interest, yet it’s still potentially questionable due to the gain he got and the odd timing weeks before their collapse. Yet other executives that sold in recent weeks may not have the protection of the 10b5-1 and that would be a worse example of conflict of interest. 

Some degree of support is needed for SVB because most there are not to blame; but so too is criticism so that the financial system can get better and innovate in the free market. You cannot just blindly support people (mostly sr. mgmt.) and organizations (crypto tie in) who are largely responsible for startup failures, frozen loans and payrolls, huge job loss, loss of deposited money over 250k, and great economic downturn – all the while the SVB mgmt. team gets very rich.

Obviously, the competencies and character of some of the SVB mgmt. team was not as good as other community banks and credit unions who aggressively avoided and overcame such failings. They likely put in more work with a deeper concern for the community, clients, and regulatory compliance – generally speaking. These many small community banks and credit unions are often 90 or 100 plus years old and did not grow at as fast a pace as SVB – super fast growth equals fast failure. Conversely, SVB is only 40 years young and most of its growth happened in the later part of that period. This coming from a guy who has consulted/worked at more than 10 financial institutions among other things including bank launch, tech risk, product, and compliance.

The company’s downward spiral blew up by late Weds 03/08/23, when it surprised investors with news that it needed to raise $2.25 billion to strengthen its balance sheet. This was influenced significantly by the Fed rate increases which forced the bank to raise lending rates, and that in turn made it hard for startups and medium-sized businesses to find approved funding. SVB also locked too much of their capital away in low-interest bonds. To strengthen their balance sheet in a slightly silly and desperate move, SVB sold $21 billion in securities at a large $1.8 billion loss. The details, timing, and governance of this make little sense, since the bank knew regulators were already watching closely. As a result, their stock fell 60% Thurs to $106.04 following the restructuring news.

As would be expected this fueled a higher level of deposit outflows from SVB; a $25 billion decline in deposits in the final three quarters of 2022. This spooked a lot of people, including CFOs, founders, VCs, and some unnamed tech celebrities — most of who started talking about the need to withdraw their money from SVB. SVB had almost 90% of its deposits uninsured by the FDIC which is far out of line with what traditional banks have. This is because the FDIC only covers deposits up to $250k. In contrast, Bank of America has about 32% of its deposits not insured by the FDIC – an enormous difference of 58%.

Crypto firm Circle revealed in a tweet late Fri 03/10/23 that it held $3.3 billion with the bank. Roblox corp. held 5% of its $3 billion in cash ($150 million) at the bank. Video streamer Roku held an estimated $487 million at SVB, representing approximately 26% of the company’s cash and cash equivalents as of Fri. Crypto exchange platform BlockFi — who filed for bankruptcy in November — listed $227 million in uninsured holdings at the bank. Some other SVB customers included Ziprecruiter, Pinterest, Shopify, and CrowdStrike. VCs like Y. Combinator regularly referred startups to them.

Yet after these initial outflows people start talking negatively, the perception became greater than reality. It did not matter whether the bank had a liquidity crisis or not. Heard psychology created a snowball effect in that no one wanted to be the last depositor at a bank — observing the lessons learned from prior banking mortgage crisis from 2008 to 2012 where Washington Mutual failed.

In sum, customers withdrew a massive $42 billion of deposits by the end of Thurs 03/09/23, according to a California regulatory filing. As a result, SIVB stock continued to plummet down another 65% before premarket trading was halted early Fri by regulators.

The FDIC described it this way in a press release:

  1. “All insured depositors will have full access to their insured deposits no later than Monday morning, March 13, 2023. The FDIC will pay uninsured depositors an advance dividend within the next week. Uninsured depositors will receive a receivership certificate for the remaining amount of their uninsured funds. As the FDIC sells the assets of Silicon Valley Bank, future dividend payments may be made to uninsured depositors.
  2. Silicon Valley Bank had 17 branches in California and Massachusetts. The main office and all branches of Silicon Valley Bank will reopen on Monday, March 13, 2023. The DINB will maintain Silicon Valley Bank’s normal business hours. Banking activities will resume no later than Monday, March 13, including on-line banking and other services. Silicon Valley Bank’s official checks will continue to clear. Under the Federal Deposit Insurance Act, the FDIC may create a DINB to ensure that customers have continued access to their insured funds.”

That’s largely a bank run, and it is really bad news for SVB and many startups and medium businesses. SVB has been a foundational piece of the tech startup ecosystem. It was also known to industry commentators and tech risk researchers that SVB struggled with tech risk compliance, overall governance, and even had no chief risk officer in the eight months prior.

With reasoning and no direct evidence, only circumstantial evidence — as I had a couple of interviews with them and was less than impressed with their competency and trajectory — I speculate that crypto ties were a significant negative factor here because many of the companies and tech sub-domains SVB served are entangled with crypto and crypto-related entitles. Examples of this include their dealings with Circle — it manages part of the USDC stablecoin reserve of the American Circle, which confirmed to have a little more than $3 billion dollars of reserve blocked with SVB.

A Fri 03/10/23 Tweet from reporter Lauren Hirsch described BlockFi’s risky crypto entanglements with SVB this way: “Per new bankruptcy filing, BlockFi has $227m in Silicon Valley Bank. The bankruptcy trustee warned them on Mon that bc those funds are in a money market mutual fund, they’re not FDIC secured — which could be a prblm w/ keeping in compliance of bankruptcy law”.

Crypto compliance and insight for a big bank is very complex, undefined, and risk prone. The biggest tech venture bank has to be involved with a few crypto related failings and controversies, and the above are just a few examples but I am sure there are more. I just don’t have the data to back that up now, but I am sure it’s being investigated and/or litigated.

Note * This is a complex, evolving, and new development — some info may be incomplete and/or out of date at the time you view this.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years he has held progressive roles at many banks, insurance companies, retailers, healthcare orgs, and even governments including being a member of the Federal Reserve Secure Payment Task Force. Organizations relish in his ability to bridge gaps and flesh out hidden risk management solutions while at the same time improving processes. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. As a futurist, his writings on digital currency, the Target data breach, and Google combining Google + video chat with Google Hangouts video chat have been validated by many. He holds an MBA from St. Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire.

Top 10 Ways SMBs Can Mitigate Cyber Risks and Threats in 2023.

Fig. 1. Stock Virus Infographic, 2023.

#smbinfosec #cyberrisk #techrisk #techinnovation #infosec #infosec #cloudcomputing 
#cyberdefense #disinformation #cio #ciso #cto #tech #ransomwareattack #123backup

1) Educate Employees About Cyber Threats and Hold Them Accountable:

Educate your employees about online threats and how to protect your business’s data, including safe use of social networking sites. Depending on the nature of your business, employees might be introducing competitors to sensitive details about your firm’s internal business. Employees should be informed about how to post online in a way that does not reveal any trade secrets to the public or competing businesses. Use games with training and hold everyone accountable to security policies and procedures. This needs to be embedded in the culture of your company. Register for free DHS cyber training here and/or use the free DHS SMB cyber resource toolkit. Most importantly, sign up for DHS CISA e-mail alerts specific to your company and industry needs and review the alerts – Sign up here. Use the free DHS developed CSET (Cybersecurity Evaluation Tool) to assess your security posture – High, Med, or Low. CSET is downloadable here.

2) Protect Against Viruses, Spyware, and Other Malicious Code:

Make sure each of your business’s computers are equipped with antivirus software and antispyware and updated regularly. Such software is readily available online from a variety of vendors. All software vendors regularly provide patches and updates to their products to correct security problems and improve functionality. Configure all software to install updates automatically. Especially watch out for freeware that contains malvertising. Make sure submission forms can block spam and can block code execution (cross-side scripting attacks).

3) Secure Your Networks:

Safeguard your Internet connection by using a firewall and encrypting information. If you have a Wi-Fi network, make sure it is secure and hidden – not publicly broadcasted. To hide your Wi-Fi network, set up your wireless access point or router so it does not broadcast the network name, known as the Service Set Identifier (SSID). Also, have a secure strong password to protect access to the router. (xbeithyg18695843%&*&RELxu75IGO) — example. Lastlyuse a VPN (virtual private network) to encrypt data in transit, especially when working from home.

4) Control Physical Access to Computers and Network Components:

Prevent access or use of business computers by unauthorized individuals. Laptops can be particularly easy targets for theft or can be lost, so lock them up when unattended. Make sure a separate user account is created for each employee and require strong passwords. Administrative privileges should only be given to trusted IT staff and key personnel — with approval records.

5) Create A Mobile Device Protection Plan:

Require users to password-protect their devices, encrypt their data, and install security apps to prevent criminals from stealing information while the phone is on public networks. Use a containerization application to separate personal data from company data. Be sure to set reporting procedures for lost or stolen equipment.

6) Establish Security Practices and Policies to Protect Sensitive Information:

Establish policies on how employees should handle and protect personally identifiable information and other sensitive data. Clearly outline the consequences of violating your business’s cybersecurity policies and who is accountable. Base your security strategy significantly on the NIST Cybersecurity Framework 1.1: Identify, Detect Defend, Respond, and Recover — a respected standard that easy to understand (Fig. 1). The NIST Cybersecurity Framework Small Business Resources are linked here.

Fig. 2. NIST CSF Domains and Sub Areas, NIST, 2022.

7) Employ Best Practices on Payment Cards:

Work with your banks or card processors to ensure the most trusted and validated tools and anti-fraud services are being used. You may also have additional security obligations related to agreements with your bank or processor. Isolate payment systems from other, less secure programs and do not use the same computer to process payments and surf the internet. Outsource some or all of it and know where your risk responsibility ends.

8) Make Backup Copies of Important Business Data and Use Encryption When Possible:

Regularly backup the data on all computers. Critical data includes word processing documents, electronic spreadsheets, databases, financial files, human resources files, and accounts receivable/payable files. Back up data automatically if possible, or at least weekly, and store the copies either offsite or on the cloud. Having all key files backed up via the 3-2-1 rule — three copies of files in two different media forms with one offsite — thus reducing ransomware attack damage.

9) Use A Password Management Tool and Strong Passwords:

Another way to stay safe is by setting passwords that are longer, complex, and thus hard to guess. Additionally, they can be stored and encrypted for safekeeping using a well-regarded password vault and management tool. This tool can also help you to set strong passwords and can auto-fill them with each login — if you select that option. Yet using just the password vaulting tool is all that is recommended. Doing these two things makes it difficult for hackers to steal passwords or access your accounts.

10) Use Only Whitelisted Sites Not Blacklisted Ones or Ones Found Via the Dark Web:

Use only approved whitelisted platforms and sites that do not expose you to data leakages or intrusion on your privacy. Whitelisting is the practice of explicitly allowing some identified websites access to a particular privilege, service, or access. Backlisting is blocking certain sites or privileges. If a site does not assure your privacy, do not even sign up let alone participate.

 About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years he has held progressive roles at many banks, insurance companies, retailers, healthcare orgs, and even governments including being a member of the Federal Reserve Secure Payment Task Force. Organizations relish in his ability to bridge gaps and flesh out hidden risk management solutions while at the same time improving processes. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. As a futurist, his writings on digital currency, the Target data breach, and Google combining Google + video chat with Google Hangouts video chat have been validated by many. He holds an MBA from St. Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire.

The Main Purpose of Cryptocurrency Mixer and/or Splitter Services is Fraud and Money Laundering.

Cryptocurrency mixer and/or splitter services serve no valid “real-world” ethical business use case considering the relevant FinTech and legal options open. Even in the very rare case when you are a refugee fleeing a financially abusive government regime or terrorist organization is seeking to steal your assets while the national currency is failing, like in Venezuela which I wrote about in my 2014 article; that is about political revolution and your personal safety more than anything else. Although cases like this give a valid reason why you might want to mix and/or split your crypto assets – that’s not fully the same use case we’re talking about here with the recent uptick of crypto mixer and/or splitter service use. It’s only fair that we discuss the most likely and common use case, which is trending up, and not the few rare edge cases. This use case would be fraud and money laundering.

The evidence does not support that a regular crypto exchange is the same thing as a mixer and/or splitter service. For definitions sake, I am not defining mixing and/or splitting cryptocurrency as the same thing as selling, buying, or converting it – all of this can be done on one or more of the crypto exchanges which is why they are called exchanges. If they are the same or even considerably similar, then why are people and orgs using the mixer and/or splitter services at all? They use them because they offer a considerably different service. Using a mixer and/or splitter services assumes you have gotten some crypto beforehand, from a separate exchange, a step or more before in the daisy chain. This can be done via legal or illegal means. Moreover, why are they paying repeated and hugely excessive fees for these services? The fees are out of line with anything possibly comparable because there is higher compliance and legal risk for the operators of them in that they could get sanctioned like Blender.IO and others.

You can still have privacy if that is what you are seeking via a semblance of legal moves such as a trust tied to a separate legal entity, family office entity, converting to real estate, and marriage entity – if you have time to do the paperwork. Legally savvy people have anonymity over their assets often to avoid fraudsters, sales reps, and just privacy for privacy’s sake – but again still not the same use case. Even when people/orgs use these legal instruments for privacy, they still have compliance reporting and tax obligations – I.E., some disclosure. Keep in mind some disclosure serves to protect you that you in fact own the assets you say you own. Using these legal instruments with the right technical security including an encrypted VPN and multifactor authentication serves to sustain privacy, and you will then not need a crypto mixer and/or splitter.

Yet if you had cryptocurrency and wanted strong privacy to protect your assets, why would you not at least use some of the aforementioned legal instruments or the like? Mostly because any attorney worth anything would be obligated to report this blatant suspected fraud, and would not want to tarnish their name on the filings, etc. Specifically, the attorney would have to see and know where and what entities the crypto was coming from and going to, under what contexts, and that could trigger them to report or refuse to work with them – I.E. a fraudster would want to avoid getting detected.

Specifically, the use of multiple legal entities in different countries in a daisy chain of crypto coin mixing and/or splitting tends to be the pattern for persistent fraud and money laundering. That was the case in the $4.5-billion-dollar crypto theft out of NY and in Blender mixing fraud, and many other cases.

A recent U.S. Treasury press release concerning mixer service money laundering described it this way:

  • “Blended.io (Blender) is a virtual currency mixer that operates on the Bitcoin blockchain and indiscriminately facilitates illicit transactions by obfuscating their origin, destination, and counterparties. Blender receives a variety of transactions and mixes them together before transmitting them to their ultimate destinations. While the purported purpose is to increase privacy, mixers like Blender are commonly used by illicit actors. Blender has helped transfer more than $500 million worth of Bitcoin since its creation in 2017. Blender was used in the laundering process for DPRK’s Axie Infinity heist, processing over $20.5 million in illicit proceeds”.
Fig 1. U.S. Treasury Dept, Blener.io Crypto Mixer Fraud, 2022.

The question we as a society should be thinking about is tech ethics. What design feature crosses the line to enable fraud too much such that it is not pursued? For example, Silk Road crossed the line, selling illegal drugs, extortion, and other crime. Hacker networks cross the line when they breach companies and steal their credit card data and put it for sale on the dark web. Facebook crossed the line when it enabled bias and undue favor to impact policy outcomes.

Crypto mixer and/or splitter services (not mere crypto exchanges) are about as close to “money laundering as a service” as it gets – relative to anything else technically available excluding the dark web where there are far worse things available technically. Obviously, the developers, product owners, and project managers behind the crypto mixer and/or splitter services like this are serving the fraud and money laundering use case more than anything else. Some semblance of the organized crime rings is very likely giving them money and direction to this end.

If you are for and use mixer and/or splitter services then you run the risk of having your digital assets mixed with dirty digital assets, you have extortion high fees, you have zero customer service, no regulatory protection, no decedent Terms of Service and/or Privacy Policy if any, and you have no guarantee that it will even work the way you think it will.

In fact, you have so much decentralized “so-called” privacy that it could work against you. For example, imagine you pay the high fees to mix and split your crypto multiple times, and then your crypto is stolen by one of the mixing and/or splitting services. This is likely because they know many of their customers are committing fraud and money laundering, yet even if they are not these platforms are associated with that. Therefore, if the platform operators steal their crypto in this process, the victims have little incentive to speak up. Moreover, the mixing and/or splitting service companies have a nice cover to steal it, privacy. They won’t admit that they stole it but will say something like “everything is private and so we can’t see or know but you are responsible for what private assets you have or don’t have”. They will say something like “stealing it is impossible” which is course is a complete lie.

In sum, what reason do you have to trust a crypto mixing and/or splitting service with your digital assets as outlined above as they are hardly incentivized to protect them or you and operate in the shadows of antiquated non-western fintech regulation. So, what really do you get besides likely fraud? What is the business rationale behind using these services as outlined above considering no solid argument or evidence can support it is privacy alone, and what net benefit do you get besides business-enabling money laundering and fraud?

Now there are valid use cases for crypto and blockchain generally and here are five of them:

  1. Innovative tech removing the central bank for peer-to-peer exchange that is faster and more global, especially helping the underbanked countries.
  2. Smart contracts can be built on blockchain.
  3. Blockchain can be used for crowdfunding.
  4. Blockchain can be used for decentralized storage.
  5. The traditional cash and coin supply chain is burdensomely wasteful, costly, dirty, and counterfeiting is a real issue. Why do you need to carry ten dollars in quarters or a wad of twenty-dollar bills or even have that be a nation’s economic backing in today’s tech world?

Here are six tips to identify crypto-related scams:

  1. With most businesses, it should be easy to find out who the key operators are. If you can’t find out who is running a cryptocurrency or exchange via LinkedIn, Medium, Twitter, a website, or the like be very cautious.
  2. Whether in cash or cryptocurrency, any business opportunity promising free money is likely to be fake. If it sounds too good to be true it likely is. Multi-level marketing is one old example of this scam.
  3. Never mix online dating and investment/financial advice. If you meet someone on a dating site or social media app, and then they want to show you how to invest in crypto or they ask you to send them crypto. No matter what sob story and huge return they are claiming it’s a scam (FTC).
  4. Watch out for scammers who pretend to be celebrities who can multiply any cryptocurrency you send them. If you click on an unexpected link they send or send cryptocurrency to a so-called celebrity’s QR code, that money will go straight to a scammer, and it’ll be gone. Celebrities don’t have time to contact random people on social media, but they are easily impersonated (FTC).
  5. Celebrities are however used to pump crypto prices via social media, so they get a windfall, and everyone else takes a hit. Watch out for crypto like Dogecoin which is heavily tied to celebrity pumps with no real-world business value. If you are lucky enough to get ahead, get out then.
  6. Watch out for scammers who make big claims without details, white papers, filings, or explanations at all. No matter what the investment, find out how it works and ask questions about where your money is going. Honest investment managers or advisors want to share that information and will back it up with details in many documents and filings (FTC).

Jeremy Swenson is a disruptive thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years he has held progressive roles at many banks, insurance companies, retailers, healthcare orgs, and even governments including being a member of the Federal Reserve Secure Payment Task Force. Organizations relish in his ability to bridge gaps and flesh out hidden risk management solutions while at the same time improving processes. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. As a futurist, his writings on digital currency, the Target data breach, and Google combining Google + video chat with Google Hangouts video chat have been validated by many. He holds an MBA from St. Mary’s University of MN, a MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire.