GoFirm
Back to Blog
Threat Landscape·2 min read

The Intelligence Is There. The Authority Confirmation Isn’t.

By GoFirm

Securitas published a briefing this month on hybrid threats in aerospace and defence. Its core argument is sharp: physical incidents, cyber intrusions, information manipulation, and economic pressure are routinely treated as isolated events. By the time the pattern is recognised as coordinated, response options are limited and costs have escalated.

Their answer is intelligence-led security - analysing patterns rather than isolated incidents to reach what they call “clearer decision points” and “the confidence to act.”¹

That framing is exactly right. And it stops one step short.

Intelligence gets you to the decision point. It tells you what is happening, how the incidents connect, and what response is warranted. What it does not do is confirm that a named authority has reviewed that picture and sanctioned the action. In aerospace and defence organisations - environments where the consequences of acting without authority are as serious as failing to act at all - that confirmation is not a formality. It is the control.

The problem is that no infrastructure exists to provide it reliably. Authorisation in most organisations still travels through email, messaging platforms, or verbal instruction. In a hybrid threat scenario - where communications may be compromised, where spoofing and impersonation are active tools, and where the pressure to act fast is highest - those channels are exactly the ones adversaries target.

GoFirm operates at this boundary. When a decision point is reached and a consequential action needs to execute, GoFirm routes a confirmation request to the named authority on their registered personal device, through a channel entirely separate from the operational environment. The authority reviews the exact action parameters and confirms with their biometric. A spoofed communication cannot produce that confirmation. A compromised inbox cannot produce it. The action proceeds only when the right person has confirmed it, on record.

Every confirmation is signed, timestamped, and written to an append-only audit trail. In defence contracting environments, where accountability for decisions carries legal and regulatory weight, that record is as important as the decision itself. It proves the action was authorised, by whom, and when - before the question is ever asked.

Securitas is right that confident action requires a clear decision picture. It also requires confirmed authority at the moment of execution. One without the other is incomplete.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. Securitas, Navigating the New Cross Domain Risk Landscape: Hybrid Threats in Aerospace & Defence, May 2026

Share this article