In one of the most infamous scandals in international banking, Deutsche Bank helped move an estimated $10 billion out of Russia without anyone inside the institution raising a flag. Between 2011 and 2015, the bank’s Moscow desk executed what came to be called “mirror trades”: Russian clients, including some tied to politically exposed and sanctioned networks, bought securities in Moscow while related counterparties sold the identical securities through the bank’s London office. Each individual trade looked routine. But the aggregate was a covert pipeline that moved billions in funds out of Russia through London and into offshore accounts, exposing the bank to regulatory penalties on three continents.
This case underscores a reality the financial industry is now grappling with. Banks, fintechs, digital asset platforms, and investment firms face risks today that have outgrown the tools built to detect them. The gap between what traditional compliance can protect against, and the evolving tactics and techniques of adversarial nations, is where strategic intelligence becomes essential.
A Growing Target
Governments in Western countries (including the United States, Canada, United Kingdom, Japan, Australia, and throughout Europe) have designated the financial services and banking sectors as critical infrastructure. When a sector is classified as critical infrastructure, it signifies that its assets, systems, and networks are essential to national security, the economy, or public health. Failure or compromise of that sector would cause debilitating effects for society.
Because financial institutions sit at the center of global capital flows, regulatory scrutiny, and geopolitical competition, their systems, people, and partnerships are persistent targets for state-sponsored actors. The PRC’s systemic emphasis on data as a driver of national power ensures that banks and financial services companies will remain high-priority intelligence targets, valued less for their role as financial intermediaries than for their visibility into the broader ecosystems of strategic industries and capital flows. Banks serve clients in defense, energy, advanced technology, and critical infrastructure. They sit at the center of cross-border trade and investment. And they play a pivotal role in enabling corporate strategy, allocating capital, and shaping risk assessments, giving adversaries a window into the decision-making processes of global firms and governments—and the people who lead them.
State-sponsored actors seeking to infiltrate hiring pipelines, exploit third-party relationships, and influence deals are targeting enterprise banks whose innovation units are building AI, quantum, and cybersecurity capabilities. In the fintech and digital asset space, payment platforms, digital wallets, and crypto-processing environments hold high-value data and assets that adversarial governments are actively pursuing for leverage. And investment firms face growing enforcement from regulatory agencies, where even indirect exposure to sanctioned entities can trigger scrutiny and jeopardize funding.
The pressure is showing up across the sector. North Korean operatives have used fabricated identities to secure remote IT roles inside U.S. financial firms, funneling salaries back to the regime while gaining access to sensitive systems. Those schemes have helped the DPRK steal more than $6 billion in cryptocurrency. At Coinbase, overseas support contractorswere bribed by cybercriminals to exfiltrate customer data from inside the company. The result was a $20 million ransom attempt that affected tens of thousands of users. Cases like the Bitzlato CEO arrest and the JPEX exchange scandal tell a different but related story: undisclosed foreign control and executive-level misconduct at crypto platforms can trigger sanctions exposure, money laundering investigations, and lasting reputational damage.
Where the Financial Sector is Most Exposed
Understanding where adversaries are finding their way into organizations starts with understanding how exposure accumulates. It comes through hiring decisions made without full visibility, deal counterparties whose ownership structures aren’t fully traceable, and supply chain dependencies that no one has examined closely enough. For organizations across financial services, markets, and banking, the risk concentrates in three places.
The first is people. Financial institutions need to screen applicants, employees, vendors, and contractors for risky affiliations and falsified resumes, especially in high-trust roles across cybersecurity, fraud, money-movement operations, AI, quantitative research, and cyber R&D. These are the positions state-sponsored actors are working hardest to access, and they are doing so through falsified credentials, hidden affiliations, and ties to foreign programs that conventional background checks were not designed to detect. Rapid hiring cycles and remote-first work have expanded the surface area, making continuous vetting of both candidates and existing personnel essential.
The second is deals and partnerships. Every M&A transaction, IPO, fund onboarding, investment deal, and joint venture pulls new entities into a financial institution’s orbit, and each one can carry hidden ties, foreign control, or sanctions exposure that is rarely visible from the outside. Financial institutions need to be able to identify these risks across counterparties, customers, investors, LPs, board members, and global partners before a deal closes or a relationship deepens. Even indirect exposure, like adversarial capital or a sanctioned co-investor on a cap table, can trigger regulatory reviews and jeopardize investments. The Deutsche Bank mirror trading scandal is a case in point: the clients and counterparties behind the scheme were closely related entities with common owners, but the bank’s KYC (Know Your Customer) processes failed to surface those connections until billions of dollars had already moved.
The third is open source software and supply chain dependencies. Financial institutions increasingly rely on open source tooling in internal platforms and quantitative systems, as well as third-party crypto-processing centers, liquidity partners, and external infrastructure providers. Contributors to these tools and organizational dependencies can carry hidden nation-state ties, and without visibility into who is contributing to the code and infrastructure these institutions depend on, the risk compounds silently.
Case Study: Tracing an IRGC-Linked Network into European Real Estate
In 2025, reporting by Bloomberg and the Financial Times identified more than 400 million euros worth of European properties linked to Ali Ansari, an Iranian national sanctioned by the UK that year for providing economic resources to the Islamic Revolutionary Guard Corps (IRGC). Despite the designation, his holdings, which include London properties, hotels in Germany, and a resort in Spain, largely remain intact. They are held through a web of offshore companies and proxy individuals spread across at least eight jurisdictions. Any financial institution that encountered this network through a deal, a counterparty, or a vendor relationship would have had no way of knowing what sat behind it using standard screening tools.
Strider traced the network from beginning to end. Inside Iran, Ansari built a sprawling empire under the Tat Group name, with holdings in banking, finance, and construction. Tracing Tat Bank’s ownership through Iran’s corporate registry leads through his core construction entity, through multiple U.S.-sanctioned holding companies, and finally to Bonyad Taavon Sepah, the IRGC Cooperative Foundation. From there, the money moved west along a deliberately layered route. Iranian oil revenues, sold to China through sanctioned crude channels, passed through UAE intermediaries, into offshore holding companies in Saint Kitts and Nevis and the Isle of Man, then into Luxembourg and Dutch corporate vehicles, and finally into European real estate. By the time the capital arrived, it looked like legitimate Western investment on paper.
The network also depended on trusted individuals who could operate without drawing attention. Iman Rahimi Aloughareh held senior roles across Ansari’s Iranian businesses while simultaneously serving as founding managing director of the Luxembourg entities and the German operating company that anchored the European structure. Despite sitting at the center of a network with direct ties to the IRGC, Aloughareh has never been sanctioned. His name would not appear in any due diligence screen. This is exactly the kind of hidden ownership, foreign control, and sanctions exposure that financial institutions need visibility into, and exactly the kind that regulators, once they uncover it, treat as the institution’s responsibility.
How Strider Helps Financial Institutions
Strider is the leading provider of strategic intelligence for identifying and mitigating nation-state risk. The platform equips CISOs, insider threat teams, fraud and FinCrime leaders, compliance organizations, and investment teams with visibility into workforce risk, third-party exposure, and malicious communications.
For personnel risk, People Search and Falsified Resume Screening verify identities and surface risky affiliations before and after hire. Insights surfaces targeted technologies and associated employees most at risk from state-sponsored actors and provides tailored briefings to reduce recruitment risk across AI, quantum, and cyber R&D programs.
For deals, partnerships, and supply chain risk, Organizations Search maps multi-tier ownership and personnel ties for deal counterparties, investors, LPs, board members, joint-venture partners, and crypto-processing vendors. It supports M&A, investment banking, and strategic transactions by identifying foreign ownership, sanctions exposure, and hidden affiliations, and helps organizations better align with compliance requirements.
For open source software risk, OSS Search detects state-linked contributors across open source repos and assesses contributors and dependencies in tooling used in internal platforms or quantitative systems, helping prevent supply chain compromise. Shield feeds curated selectors into SIEM and DLP tools to identify, flag, and monitor geopolitical threats, including malicious emails, domains, and multilingual terms tied to state-sponsored cyber or recruitment activity targeting employees. Strider also provides expert analysis within its Intelligence Center on threats facing the financial sector—offering additional context on state-sponsored recruitment initiatives and efforts to identify and exploit vulnerabilities.
Looking Ahead
The financial services sector is operating in a rapidly changing risk environment—where the threats are geopolitical, the exposure is structural, and the cost of finding out too late keeps rising. Strider gives financial institutions the strategic intelligence to see what’s coming and act before it arrives.
How Amended Rules Increase Risk for Foreign Companies and Their Employees Operating in Hong Kong
On March 23, 2026, the Hong Kong government, under pressure from the Chinese Communist Party (CCP), changed the implementing rules of its National Security Law in ways that should put every company that does business in, or transits through, Hong Kong on alert. Refusing to hand over passwords or provide decryption assistance to Hong Kong police is now a criminal offense—and that applies to everyone: residents, visitors, and anyone transiting Hong Kong International Airport, including U.S. citizens. Hong Kong authorities also gained expanded powers to seize and retain personal devices as evidence in national security cases.
The rule change is the latest development in a trend Strider analysts have been tracking since Hong Kong’s Article 23 passed in 2024—a steady, deliberate convergence of Hong Kong’s legal and intelligence environment with that of the People’s Republic of China (PRC). For foreign companies that have continued operating in the city without adjusting their posture, the risk is no longer theoretical.
A Law with Broad Reach
In June 2020, the PRC National People’s Congress Standing Committee (NPCSC) unanimously passed the “Law of the People’s Republic of China on Safeguarding National Security in the Hong Kong Special Administrative Region,” bypassing Hong Kong’s own legislature entirely to impose a national security law directly on the city, criminalizing secession, subversion, terrorism, and collusion with foreign forces.
Hong Kong’s Legislative Council passed Article 23 in March 2024, also known as the “Safeguarding National Security Bill,” to quell “political crimes,” including theft of state secrets and espionage. Article 23 defines “state secrets” to include any information related to a “major policy decision” or to economic, social, technological, or scientific developments—even if that information has never been officially classified. Acts of “espionage” under the law include providing “useful” information to an “external force” or colluding with such a force to publish false or misleading statements.
Like their counterparts in Mainland China, Hong Kong residents are now legally compelled to inform authorities when they suspect someone of committing an infraction. The two laws now operate in tandem, giving the PRC a comprehensive legal architecture to govern national security in Hong Kong on its own terms.
In 2024, the PRC revised its Law on Guarding State Secrets to prevent the leaking of information that could harm the CCP or benefit foreign countries or businesses. In 2023, Beijing amended its counter-espionage law to characterize information collection related to national security or national interests as an act of espionage.
The U.S. State Department expressed “deep concern” over Article 23, noting that it carries “broad implications” for Hong Kong residents as well as U.S. citizens and companies. Officials also warned that Hong Kong authorities could seek to apply the law extraterritorially.
Industries Most at Risk
Companies engaged in due diligence, business intelligence, or economic and market research face the greatest exposure. Hong Kong authorities could characterize these activities as “intelligence work” targeting “state secrets.” The PRC has already used its national security framework, the same framework that shaped Article 23, to clamp down on foreign consulting and due diligence businesses conducting investment screening, forensic accounting, or background checks.
The risks also extend to personnel. PRC intelligence services (PRCIS), including the Ministry of State Security (MSS) and Ministry of Public Security (MPS), have long operated in Hong Kong to monitor the local population and target foreign nationals. The PRCIS employs a wide range of collection methods: front organizations operating under commercial or academic cover, advanced technical surveillance, co-opted locals across service industries, targeted online outreach via professional networking platforms, and offers of paid travel or financial remuneration. Employees traveling to Hong Kong should assume that all electronic devices and communications are subject to monitoring.
The intelligence apparatus in Hong Kong also prioritizes access over ethnicity. While the PRCIS can leverage familial or cultural ties to the PRC, its primary objective is identifying any individual willing to provide information of value—regardless of background. Anyone with access to sensitive data, advanced research, or government-connected networks is a potential target.
Historical cases illustrate the point: In 2022, a former U.S. Army pilot and cleared U.S. defense contractor was sentenced to prison. Over two years, he traveled multiple times to Hong Kong to meet with PRCIS handlers, passing sensitive aviation-related material in exchange for payment. In a separate 2024 incident, a U.S. Army sergeant was charged with leaking classified information on advanced weapons systems to a foreign national claiming to live in Hong Kong, receiving a series of payments that increased as the sensitivity of the material grew.
What Companies Should Do
As Beijing tightens its control over Hong Kong, these risks will only deepen. Following Article 23’s passage, Hong Kong Chief Executive John Lee announced that the city would “actively integrate” into the PRC’s “overall development” and “strengthen the flow of people, logistics, capital, and information.” The head of the German Chamber of Commerce in Hong Kong acknowledged that company executives would find it increasingly difficult to distinguish the city from the rest of the PRC.
Foreign companies operating in Hong Kong can take concrete steps to manage their exposure.
Update Policies and Procedures. The law’s deliberately vague language gives authorities wide latitude to target groups and individuals perceived as a threat to stability—whether they are doing business in or transiting through Hong Kong. Organizations should review Hong Kong-based operations and reevaluate activities that could be conflated with criminal conduct under the new framework.
Educate and Empower Personnel. Briefing leadership and staff on the risks associated with information gathering and sharing in Hong Kong can drive more cautious behavior. Engaging with groups or individuals critical of Beijing or the Hong Kong government—even casually—could raise an organization’s profile and invite scrutiny by security agencies.
Conduct Thorough Due Diligence. Vetting Hong Kong-based organizations and individuals, with particular attention to their ties to Beijing, is essential. Monitoring Western sanctions lists is a baseline requirement for remaining compliant and avoiding relationships that expose technology, talent, and supply chains to unnecessary risk.
The Intelligence Dimension
Strider helps organizations understand and manage state-sponsored risks in environments like Hong Kong, where the line between commercial activity and legal liability has become dangerously thin. Tools like People Search and Insights help identify individuals’ ties to state-sponsored programs or entities, while Organizations Search enables organizations to assess third-party partners for connections to state-directed actors. Shield helps protect intellectual property by identifying higher-risk indicators associated with state-linked recruitment and technology transfer activity. Within its Intelligence Center, Strider analysts provide ongoing coverage of legislative, institutional, and operational developments that affect how organizations must think about their exposure in complex geopolitical environments.
Hong Kong’s newly amended rules of its National Security Law represent a meaningful shift in the risk calculus for foreign companies. The legal exposure, the intelligence threat, and the erosion of institutional independence demand immediate attention from any organization operating in or connected to Hong Kong.
The companies best positioned to navigate this environment will be those that treat it with the seriousness it demands—understanding the law, preparing their people, and building the intelligence capabilities needed to stay ahead.
From the systems that power electrical grids to the communications networks that connect the world, critical infrastructure is the foundation of economic growth and resiliency, national security, public safety, and life as we know it. It is a sprawling web of interdependent systems operating at extraordinary scale—divided by sector, but united by shared technologies, intertwined supply chains, and, increasingly, collective vulnerabilities.
While governments around the world maintain their own definitions of “critical infrastructure,” they largely converge around the same core systems that underpin modern society. Terminology may differ, but critical infrastructure sectors broadly include communications, information technology, and digital infrastructure systems; major energy sources (including electricity, renewables, oil, and gas); financial services and banking; government services and facilities; transportation systems (including air, rail, and maritime); water and wastewater; and defense. These are the sectors that societies rely on—making them uniquely attractive targets.
Adversarial nation-states like the People’s Republic of China (PRC), Russia, and Iran have spent the past decade mapping vulnerabilities in critical infrastructure—learning about them, figuring out how best to exploit them, and infiltrating them. The threat these countries now pose is more coordinated, more persistent, and more strategically targeted than at any prior point in history.
Critical infrastructure systems have become the new terrain through which power is projected and pressure is applied.
The Threat Landscape Has Changed
For organizations in critical infrastructure sectors, reliability has always been a top priority: keeping the power flowing, networks connected, goods moving, and daily life running. That hasn’t changed. But the threat landscape these organizations are operating in has. Today, resilience against adversarial nation-states has become as important as the reliability these systems have always prioritized.
That resilience is already being tested worldwide. Foreign-manufactured components with opaque capabilities have been discovered in Western power grids. Major telecommunications carriers have identified state-linked actors operating within their core networks. Energy and industrial companies in North America and Europe have taken systems offline following attacks that moved through third-party partners and global supply chains. The methods of intrusion are varied, but the scale and coordination point to something more deliberate than opportunistic attacks.
What distinguishes this new landscape is the strategy behind it. Intelligence and law enforcement agencies have assessed with high confidence that recent activity by groups like Volt Typhoon, a PRC state-sponsored hacking group known to target critical infrastructure, is inconsistent with traditional cyber espionage. Meanwhile, Russian-backed groups have targeted power grids, government networks, and financial institutions in Europe, aiming to destabilize and erode public trust. And Iran has gone after critical sectors in both the U.S. and Europe—including healthcare, transportation, and oil and gas—to test vulnerabilities.
These actors are not just trying to steal data. They are pre-positioning themselves deep inside critical systems with the goal of being able to cause disruption on demand. The objective is leverage, and critical infrastructure is how they intend to get it.
Policymakers have taken notice and are taking action. Japan’s Economic Security Promotion Act, enacted in 2022, designated approximately 200 entities across 15 sectors as critical infrastructure operators. The government is enabled to vet equipment suppliers or maintainers to ensure that vulnerabilities aren’t introduced related to foreign entities of concern.
In the United States, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) confirmed that PRC state-sponsored actors had compromised networks across communications, energy, transportation, and water system sectors. Previously, the U.S. banned PRC technology provider Huawei from its 5G and telecommunications networks due to espionage risks.
In its National Security Strategy 2025, the UK government stated that “Hostile activity on British soil from countries like Russia and Iran is increasing, threatening our people, critical national infrastructure and prosperity.” The UK government also pledged to “roll out a series of new measures to…enhance the resilience of our critical national infrastructure.
The European Union, meanwhile, recently moved to restrict PRC suppliers from critical infrastructure, such as telecommunication networks, across member states entirely.
These actions make clear that critical infrastructure is a prime target for adversaries. For those responsible for keeping these systems safe and secure, understanding where and how deeply they have already been reached—and the strategies being employed by adversarial nation-states—has become essential for safeguarding economies and societies.
Where Critical Infrastructure Is Most Exposed
Understanding where adversaries are finding their way in starts with understanding how exposure accumulates—and it rarely happens the way most organizations expect. It comes through procurement decisions made without full visibility, hires that passed every background check, and partnerships that looked clean on paper. For organizations across critical infrastructure sectors, the risk concentrates in three places.
The first is the supply chain. The global supply chain for critical infrastructure components is vast, layered, and can often be difficult to trace. While that complexity is a byproduct of operating at global scale and within intertwined economies, it is also one of the most consequential vulnerabilities that organizations face. Adversaries have spent years learning to exploit it. The result has been solar inverters with undisclosed communication capabilities; telecommunications hardware sourced from entities with government ties; and transformers, fiber optic cables, and industrial control components whose origins cannot be verified.
Strider’s “In Broad Daylight” report captured exactly what that exploitation looks like in practice. In November 2024, PRC-linked company Deye remotely disabled inverters across the United States, United Kingdom, and Puerto Rico following a commercial dispute. The capability had been embedded in the hardware before it ever reached the grid. The leverage was already in place. The dispute simply revealed it. Strider research also shed light on the sustained PRC effort to identify vulnerabilities and develop methods to disrupt Western power grids—uncovering 2,723 publications on the subject authored by researchers affiliated with PRC defense institutions, including the People’s Liberation Army and national defense universities.
The second is the workforce. Privileged access to critical infrastructure systems is among the most valuable things an adversary can acquire—and state-sponsored actors are pursuing it methodically through recruitment, cultivation, and talent pipelines that look entirely legitimate from the outside. In 2023, that reality came into sharp focus when a telecom contractor in Florida was charged with acting as an agent of China’s Ministry of State Security while maintaining active system access at a major U.S. carrier. For every case like this that surfaces, the harder question is how many have not. Any organization that relies solely on conventional vetting methods is likely carrying risk that has not yet been illuminated.
The third is the extended partner ecosystem. Every joint venture, contractor relationship, and operational partnership is a potential entry point for adversaries to exploit. Partners bring their own supply chains, personnel, and geopolitical entanglements into shared operational environments, and there is rarely visibility into the full ecosystem. In the oil and gas sectors, where global operations and joint ventures are common, adversaries actively seek out partnerships as digital access points to disrupt operations and gain strategic advantage. Intellectual property from exploration breakthroughs, refining processes, and material-science research are frequent targets—compromised through the same trusted partnerships that companies depend on to operate. When any part of that ecosystem is compromised, the entire organization is compromised with it.
A Strider Use Case: A Major Energy Provider Prevented Exposure
A prominent U.S. power and energy company servicing some of the largest metropolitan areas in the country wanted to ensure its critical systems were safeguarded from nation-state threats. Company leaders wanted full visibility into the entities within its ecosystem as third-party partners or technology providers.
The company used Strider’s strategic intelligence platform to identify all entities with technology embedded in its infrastructure, then screened every third-party partner involved in day-to-day operations for connections to foreign entities of concern. What they found was alarming. A substantial portion of their critical infrastructure was being managed by a third-party company with direct connections to the PRC government, military, and defense organizations. The relationship posed a serious risk: this energy company could potentially lose operational control of their critical systems to a PRC government entity or actors working on its behalf. Company leaders severed ties with the management company.
For organizations involved in critical infrastructure sectors, this case illustrates something important: the exposure existed before anyone went looking for it. It only became visible when they had the right tools to see it.
How Strider Helps Critical Infrastructure Organizations
The organizations that manage risk posed by adversarial nation-states best are the ones that can see it clearly across their supply chains, their workforce, and their extended partner ecosystem. Most organizations have invested heavily in tools designed to detect threats after they’ve entered their critical systems. Strider’s strategic intelligence enables organizations to get ahead of these threats.
For supply chain and partner risk, Organizations Search maps the full ownership and affiliation picture behind every vendor, supplier, component, joint venture partner, and major contractor embedded in an operational environment—uncovering multi-tier relationships, hidden parent companies, and state-linked intermediaries.
For workforce risk, People Search screens employees, contractors, and candidates for nation-state ties, falsified credentials, and risky affiliations—revealing hidden connections that conventional background checks were never built to detect.
Across all three, Insights tracks the specific technologies and subject-matter experts most likely to be targeted by state actors and generates reporting for leadership on emerging geopolitical and partner risks.
And Shield flags and blocks malicious domains, emails, and communications tied to known adversary campaigns—feeding high-risk indicators into existing security systems to monitor risky inbound and outbound activity before it reaches operational environments.
Strider also provides expert analysis within its Intelligence Center on critical infrastructure security—offering additional context on state-sponsored recruitment initiatives and efforts to identify and exploit vulnerabilities.
The systems that make up critical infrastructure are only as resilient as the technologies, supply chains, and people that support them. Strider gives organizations the visibility to understand that full picture and to act on it before someone else does.
Conclusion
Critical infrastructure is the foundation that modern society cannot function without. And precisely because of that, it has become a primary target for those seeking leverage in this new geopolitical era. Keeping it secure, reliable, and free from foreign interference requires a level of vigilance that many organizations have not yet applied—but must.
Those who act now will find the exposure. Those who wait will feel it.
For more than a decade, the Thousand Talents Program (TTP) was one of the People’s Republic of China’s (PRC) largest and most successful mechanisms for attracting overseas scientific and technical expertise. It targeted the world’s top researchers, scientists, and experts, incentivizing them to work in the PRC through competitive compensation, funding, and institutional support. Public reporting estimates that more than 7,000 individuals participated in the program from 2008 to 2018, providing a significant boost to Beijing’s science and technology sectors.
Then, after years of prominence, the program appeared to vanish.

As major Western news outlets began to highlight the risks of intellectual property theft linked to talent recruitment by the PRC, references to the TTP disappeared from official PRC government websites and public-facing recruitment materials. PRC officials told foreign governments and institutions that the program had been discontinued. Even the words “Thousand Talents Program” were discouraged from being used in written correspondence by the PRC. To outsiders—and competing nations—it looked as though the program had run its course.
As references to the TTP declined, Strider analysts observed a corresponding increase in the activity of other talent programs operating under different names. In many cases, the eligibility requirements and incentives for these programs were similar to those offered under the TTP. They targeted the same types of researchers, scientists, and experts from abroad and continued to channel that talent into the PRC’s scientific and technological pipelines.
Eventually, the evidence pointed to a different conclusion: the Thousand Talents Program—perhaps the PRC’s most effective state-sponsored talent recruitment program to date—was never eliminated. It was rebranded, reorganized, and better positioned to influence the next phase of the PRC’s global talent strategy.
The Rise and Fall of the Thousand Talents Program
The Thousand Talents Program (also known as the Thousand Talents Plan) was one of hundreds of talent plans designed to systematically draw advanced scientific and technical expertise to the PRC at scale. It operated as a centralized framework through which universities, research organizations, state laboratories, and companies could recruit foreign talent and align it with PRC priorities.
From its inception, the program was embedded within the Chinese Communist Party’s (CCP) broader political and organizational architecture. According to the plan’s now-defunct website, the United Front Work Department (UFWD) was one of the authorities responsible for implementing the TTP. The UFWD is a decades-old agency responsible for managing the CCP’s influence operations and advancing its interests inside and outside the PRC. President Xi Jinping has described it as “an important magic weapon for the party to defeat the enemy.”
The United States government has framed the program in similarly strategic terms. In 2020, the U.S. Department of Justice described the TTP as “one of the most prominent Chinese talent recruitment plans that [is] designed to attract, recruit, and cultivate high-level scientific talent in furtherance of China’s scientific development, economic prosperity, and national security.”
Over time, the program expanded into a set of distinct branches designed to target different career stages and use cases. These included long-term tracks for researchers, short-term arrangements that allowed overseas experts to retain foreign affiliations, entrepreneurial tracks linked to commercialization, and the Young Thousand Talents Program, which focused on early- and mid-career researchers trained abroad.
That scale and visibility, however, created exposure.

As international scrutiny intensified and U.S. enforcement actions increasingly cited the Thousand Talents Program by name, the branding that had once amplified the program’s reach became a liability. Some individuals affiliated with the TTP became targets of FBI investigations aimed at curbing the transfer of sensitive technology and intellectual property to the PRC. As a result, the program became closely associated with enforcement and counterintelligence concerns in the United States and across the West.
A Strategic Rebrand and Reorganization
By the early 2020s, the PRC’s national talent recruitment architecture began to shift in visible ways.
Chinese-language recruitment forums and open-source reporting indicate that in 2021, the Thousand Talents Program was rebranded under a new name: the Qiming Program. Overseen by the PRC’s Ministry of Industry and Information Technology, Qiming seeks technological experts in industries of strategic importance, such as semiconductors.
The timing and structure of the change are notable.
The rise of Qiming closely tracked the decline of Thousand Talents references on the open web. Eligibility requirements for participation in Qiming closely mirrored those previously associated with the Thousand Talents Program, indicating continuity in how candidates were targeted and selected. Qiming’s financial incentives—which include lucrative one-time awards from central and local governments—are identical to provisions in the original TTP. The end goal also remained consistent: recruiting overseas talent to advance the PRC’s strategic scientific and technological dominance. Taken together, these signals suggest that Qiming functions as an alias for, if not the direct replacement of, the TTP.
Qiming and other national-level talent introduction programs are only part of the PRC’s sustained, whole-of-nation approach to recruiting foreign talent. Even as individual programs change names or structures, talent recruitment activity remains a top priority for the PRC—and an essential consideration for organizations seeking to safeguard their people, technology, and innovation from economic statecraft.
From Indicators to Actionable Intelligence
Strider helps organizations address this challenge by enabling a more comprehensive view of the PRC’s talent recruitment ecosystem.
Tools like Shield help organizations protect intellectual property by identifying higher-risk indicators—such as specific email addresses, affiliated domains, and keywords in multiple languages—commonly associated with state-linked recruitment and technology transfer activity. Other tools, such as People Search and Insights, help illuminate individuals’ involvement in state-sponsored talent programs. Meanwhile, Organizations Search can uncover organizations involved in state-directed recruitment efforts. Alongside this data-driven approach, Strider provides ongoing analysis within its Intelligence Center of recruitment trends, institutional linkages, and talent movement—offering additional context on how state-sponsored efforts are evolving in real time.
Conclusion
The evolution of the Thousand Talents Program demonstrates how the PRC rebrands and reorganizes major initiatives to sustain talent recruitment under external pressure. Looking ahead, the most consequential developments are unlikely to announce themselves. Instead, they will emerge through updated programs, new structures, and familiar patterns in unfamiliar places. As a result, the advantage will belong to organizations that can leverage cutting-edge intelligence to identify, assess, and act on threats faster.
Insider threats remain one of the most complex and consequential risks organizations face today. Unlike external cyberattacks or obvious physical intrusions, insider threats often arise from trusted individuals—employees, contractors, or research partners—who exploit their access to sensitive data, intellectual property, or systems. While not every insider threat is malicious, the potential damage is significant: intellectual property theft, reputational harm, regulatory violations, and compromised national security.
At Strider, we recognize that the insider threat challenge is no longer limited to disgruntled employees or lone actors. Increasingly, these risks are linked to state-sponsored efforts that target organizations through talent recruitment, supply chain infiltration, and research partnerships. Our products are designed to give organizations the visibility and intelligence they need to identify these risks early, mitigate vulnerabilities, and protect what matters most.
In this blog post, we’ll explore how Strider’s suite of products empowers organizations to protect against insider threats by uncovering hidden affiliations, mapping risky connections, and delivering actionable intelligence.
Understanding the Modern Insider Threat
Traditional security models focused on access control and monitoring system anomalies. While these remain important, they fall short when insiders are recruited or influenced by foreign adversaries. For example, researchers may be courted by state-backed talent recruitment programs that encourage them to transfer cutting-edge innovations abroad. Or an employee may conceal ties to a foreign military entity during the hiring process.
These risks are especially acute in sectors like defense, high tech, energy, and academia—where sensitive intellectual property is both highly valuable and highly targeted. The challenge is that many of these threats do not leave digital fingerprints in the early stages.
Instead, they are rooted in affiliations, backgrounds, and institutional relationships that require deep analysis of open-source intelligence and proprietary data.
This is where Strider’s products deliver unmatched value.
People Search: Uncovering Hidden Affiliations
When hiring, vetting researchers, or evaluating collaborators, organizations often rely on self-disclosed resumes and standard background checks. Unfortunately, these methods are often insufficient when individuals deliberately conceal foreign ties.
Strider’s People Search addresses this gap by aggregating and analyzing open-source intelligence to uncover connections to high-risk entities, such as foreign intelligence services, governments, and militaries. With this capability, organizations can:
- Detect undisclosed affiliations: Identify if an applicant or employee is linked to state-sponsored talent programs or research institutions affiliated with adversarial nations.
- Verify credentials: Through Falsified Resume Screening, ensure that the applicant is who they are purporting to be and haven’t applied with a fraudulent persona. This is especially relevant for organizations concerned about unwittingly hiring remote workers from the DPRK.
- Ensure transparency: Build confidence that no hidden affiliations threaten sensitive projects.
By enabling proactive screening, People Search helps organizations ensure trust in their workforce and avoid inadvertently granting access to individuals who may pose an insider threat.
Organizations Search: Securing the Supply Chain and Partnerships
Insider threats don’t always come from direct employees. Contractors, research partners, and suppliers can serve as entry points for state-sponsored influence. Often, affiliations are hidden in complex ownership structures or through partnerships with universities and institutes that serve as fronts for foreign militaries.
Strider’s Organizations Search empowers leaders to understand these hidden relationships within their organizations. Specifically, the Organizations Search tool reveals:
- Risk profiles of organizations.
- Ownership and subsidiary structures that link vendors or partners to adversarial governments, shown in a network view.
- Board memberships and leadership ties to sanctioned or restricted entities.
- Connections to banned talent programs or institutes like Confucius Institutes.
For example, before entering into an academic collaboration, a university can use Organizations Search to determine whether a foreign partner has ties to a hostile nation. By making these risks visible, Organizations Search prevents insider threats from entering through seemingly trusted third parties.
Open Source Software Search: Protecting the Software Supply Chain
Insider risks also extend to the software ecosystem. With open source software now serving as the foundation of many mission-critical systems, organizations face growing exposure if contributors to their code base have risky affiliations.
Strider’s Open Source Software Search (OSS Search) screens contributors across an organization’s software supply chain. By analyzing repositories and contributor backgrounds, OSS Search uncovers:
- Hidden links between open-source contributors and adversarial nation-state entities.
- Dependency risks that could create vulnerabilities in critical systems.
- Potential insertion of malicious code or data exfiltration mechanisms.
In an era where a single compromised software library can ripple across industries, OSS Search adds a critical layer of defense against insider threats buried in code.
Insights: Strategic Intelligence for At-Risk Teams
While detection and screening are essential, insider threat mitigation also requires a proactive approach to awareness and resilience. That’s where Strider’s Insights—our advanced intelligence—comes in.
Insights provides organizations with tailored strategic intelligence about which research areas, technologies, or people are most likely to be targeted by foreign adversaries. This intelligence enables organizations to:
- Protect researchers and innovators: Identify which faculty or employees may be under surveillance or recruitment efforts.
- Deliver targeted training: Equip at-risk staff with knowledge of espionage tactics and best practices to safeguard data.
- Enhance travel security: Brief personnel before international travel on surveillance risks and protective measures.
By shifting the conversation from reactive to proactive, Insights ensures organizations can anticipate and blunt insider threat recruitment before it succeeds.
Shield: Real-Time Detection in Digital Systems
Insider threats often communicate with foreign sponsors through digital channels, blending into the noise of everyday email and network traffic. To help organizations spot these signals, Strider developed Shield.
Shield delivers a curated, expert-verified dataset of high-risk email addresses, domains, and multilingual keywords associated with state-sponsored actors. Integrated via API into an organization’s SIEM or DLP system, Shield enables:
- Real-time detection: Existing systems, layered with Strider’s dataset, can spot and block suspicious communications and activities linked to known adversaries.
- Reduced false positives: Data is curated to minimize noise so analysts can focus on what matters.
- Continuous updates: Monthly refreshes ensure organizations stay ahead of evolving threats.
By integrating Shield into existing systems, organizations gain a powerful capability to detect when insiders are engaging with adversarial entities.
Building a Comprehensive Insider Threat Defense
The insider threat problem is multi-faceted: it spans people, partnerships, software, and communications. Strider’s holistic approach ensures that organizations can address these risks from every angle:
- People Search builds trust in the workforce.
- Organizations Search secures partnerships and supply chains.
- OSS Search protects the software ecosystem.
- Insights equips people and institutions with proactive defenses.
- Shield enables real-time detection in digital systems.
Together, these tools give organizations the visibility and intelligence to detect risks early, respond decisively, and stay compliant with regulations. More importantly, they empower leaders to safeguard their people, technology, and intellectual property from insider threats driven by state-sponsored actors.
Spark, Strider’s proprietary AI engine, is layered onto each existing product. With Spark, organizations have the ability to security integrate internal DLP data with Strider’s AI risk intelligence for deeper, data-driven risk insights. It also features an intuitive chat interface with real-time analysis and query, suggested searches, multilingual data input, and sourcing for original intelligence sources.
Insider threats will never be fully eliminated—but they can be managed. The key is understanding that these risks are not random but often deliberate, coordinated efforts by nation-state actors. By shining light on hidden affiliations, risky partnerships, and subtle recruitment efforts, Strider helps organizations take back control.
With Strider’s products, insider threat protection becomes less about suspicion and more about clarity. Organizations gain the confidence to collaborate, innovate, and grow—knowing they are protected by intelligence built for the modern era of geopolitical competition.
This is the second post of four in our Research Security blog series. To read the first post, click here.
Introduction
In the realm of international research, collaboration is often seen as a pathway to innovation and progress. However, not all collaborations are benign. The People’s Republic of China (PRC) and Russia have strategic motivations for encouraging open-source research collaborations that go beyond academic advancement. Understanding these motivations is crucial for safeguarding intellectual property, maintaining research integrity, and ensuring compliance with funding regulations.
The PRC’s Strategy
China’s ruling party takes direct control of the country’s universities, with presidents’ offices being merged with embedded party committees to form a ‘unified’ leadership for higher education. This centralized control is part of a broader strategy to advance national objectives through scientific and technological development.
Xi Jinping, General Secretary of the Communist Party of China, has explicitly called for the PRC to achieve “high-level science and technology (S&T) self-reliance.” This directive is reflected in the party’s emphasis on “indigenous innovation,” which aims to reduce dependence on foreign technology and bolster China’s global competitiveness.
Tactics Employed
The PRC employs several tactics to exploit international collaborations:
- Talent Recruitment Programs: China identifies and recruits top international researchers to work in China, often through well-funded talent programs. These initiatives are designed to transfer valuable knowledge and skills to Chinese institutions.
- Research Partnerships: Collaborative research projects with international universities serve as a conduit for transferring advanced technologies and intellectual property to China.
- Reverse Engineering Efforts: Chinese institutions often engage in reverse engineering Western technologies to replicate and enhance them for domestic use.
Case Study: University Involvement
An example of this strategy is seen in China’s emphasis on brain research through the China Brain Project, which involves substantial government funding aimed at attracting global talent and expertise. International collaborations in such projects are closely monitored and leveraged to advance China’s strategic goals.
Russia’s Approach
Since 2022, the Russian government has poured significant resources, at least USD 110 million, into initiatives aimed at reverse engineering Western goods, particularly to copy Western weapon systems. Universities are integral to these efforts, offering training and conducting projects designed to replicate and improve upon Western technologies. At least two of the universities leading these projects have been involved in economic espionage activities, demonstrating the extent to which academic institutions are leveraged for state objectives (DNI.gov) (ProPublica).
Implications for Global Research
The strategic motivations behind the PRC and Russia’s calls for open-source research collaboration pose significant risks to international research institutes. These include:
- Intellectual Property Theft: Valuable research and innovations can be appropriated without proper credit or compensation.
- National Security Risks: Advanced technologies developed through international collaborations can be used to enhance military capabilities in these countries.
- Talent Drain: Highly skilled researchers may be recruited away from their home institutions, leading to a loss of expertise and innovation potential.
Ensuring Compliance and Protecting Funding
For many academic institutions, the primary concern is compliance with regulations from bodies such as the Department of Defense (DOD), Department of Energy (DOE), and National Science Foundation (NSF) to secure and maintain funding. This involves:
- Due Diligence in Vetting Collaborations: Institutions must thoroughly vet research partners and donors to ensure compliance with funding regulations and avoid affiliations with high-risk entities.
- Maintaining Transparency: Ensuring that all research activities and partnerships are transparent to comply with regulatory requirements and avoid penalties.
- Protecting Research Integrity: Safeguarding intellectual property and maintaining the integrity of research without making researchers feel like they are under surveillance.
Mitigating Risks Through Advanced Intelligence
Understanding and mitigating these risks is essential for protecting intellectual property and maintaining the integrity of research collaborations. Leveraging advanced data processing and risk analysis capabilities, institutions can identify high-risk collaborations and implement measures to safeguard their research and personnel. This approach helps secure funding while ensuring compliance with necessary regulations.
The recent memorandum from the Office of Science and Technology Policy (OSTP) further underscores the importance of robust research security programs. It provides guidelines for federal research agencies to implement certification requirements for research security programs at covered institutions, aligning with National Security Presidential Memorandum-33 (NSPM-33) and the CHIPS and Science Act. These guidelines emphasize the need for cybersecurity, foreign travel security, research security training, and export control training.
Specific Tools for Risk Mitigation
Strider provides unique intelligence and tools necessary to identify and mitigate these risks. By leveraging our advanced data processing and risk analysis capabilities, research institutions can protect their intellectual property and maintain the integrity of their collaborations. Specifically:
- Shield: Strider’s Shield tool can help university cybersecurity teams proactively identify recruitment efforts being made by foreign institutions aimed at their talent.
- People Search: This tool helps institutions validate the information provided by self-disclosures, providing quick access to a list of publications, patents, funding records, and relationships to malign talent programs.
Conclusion
While international collaboration is essential for scientific progress, it is crucial to remain vigilant about the hidden motivations of certain state actors. Understanding and addressing these risks ensure that research efforts contribute positively to global innovation and security. By staying informed and proactive, research institutions can continue to collaborate safely and advance their mission of expanding knowledge and creating a better world without compromising compliance or funding.
This is the second post of four in our Research Security blog series. To read the next post, click here.
In academia and innovation, the integrity and security of research not only propel the boundaries of knowledge but also safeguard the interests of national security. Strider, through its meticulous gathering of open-source data and strategic intelligence, stands at the forefront of ensuring that research institutes thrive in a complex landscape with security at the core of their efforts.
Research Security as National Security
The interconnectedness of global research initiatives has undeniably spurred innovation at an unprecedented scale. However, this openness has also introduced vulnerabilities that foreign entities, governments, or individuals exploit, casting a shadow over the integrity of research endeavors. The U.S. government’s growing apprehension towards such influences underscores a crucial equilibrium—one where research security and international collaboration must coexist without compromising the other.
Instances of these concerns range widely, from the inadvertent sharing of proprietary information and intellectual property to the non-disclosure of substantial foreign support. These are not mere administrative oversights but potential breaches of national security. Thus, ensuring research integrity is more critical now than ever, demanding a vigilant and proactive stance against such influences.
Many Faces of Research Security Breaches
The National Science Foundation (NSF) regularly provides examples of the various types of research security breaches to highlight the myriad ways they occur and bolster efforts to identify and mitigate these threats. Below are two case studies NSF recently shared:
Case Study 1
A striking example involves an NSF-funded principal investigator who, unbeknownst to their U.S. organization, participated in a foreign talent program while holding a faculty position abroad. This case escalated when the investigator failed to disclose foreign affiliations and funding, a requirement by NSF’s standards. The repercussions were severe—suspension of awards, resignation, and eventual government-wide debarment. This case underscores the critical need for transparency and adherence to funding guidelines.
Case Study 2
Another case saw a professor exploiting federal grants for research already conducted overseas. The breach involved not just the misallocation of funds but also an active effort to obstruct investigations by submitting falsified documentation. The subsequent criminal conviction of the professor highlights the rigorous measures taken to uphold research integrity and security.
Using Data to Protect Data
At Strider, our approach to safeguarding research and fostering secure international collaborations is rooted in strategic intelligence. This intelligence is sourced from a comprehensive collection of critical open-source data, which is then augmented by proprietary data processing methodologies. Our suite of products and services is tailored to preemptively identify and mitigate risks, ensuring the integrity of your research endeavors.
Insights stands as our flagship offering, empowering organizations to discern and protect against pursuits by foreign governments. It identifies which of your technologies and research topics are at risk of being targeted by foreign governments. It also illuminates any connections to sanctioned, restricted, or state-owned entities your employees—including researchers—may have. With Insights, you can ensure individuals working on specific research have disclosed appropriate information and connections beforehand.
People Search facilitates instantaneous due diligence, screening for potential state-sponsored risks among researchers and visitors. Its sophisticated identification process illuminates connections that might pose security risks in areas including restricted government and military entities, as well as industry and education associations.
Organizations Search enables third-party due diligence for security risks before collaboration and partnership. It reveals connections that third-party partners may have with restricted or high-risk entities, including foreign government, defense, research, or military institutions.
Shield is an email security tool that offers protection against covert attempts by state-sponsored actors to solicit your researchers and employees. By providing an ever-growing list of verified email addresses, domain names, and key words directly linked to such actors, you can be alerted when anyone in your organization is approached.
Conclusion
In an era when the geopolitics of research security are continually evolving, Strider helps research institutes be better equipped to safely navigate state-sponsored risk with critical strategic intelligence. Reach out to a Strider representative today to see how you can better enhance security in your organization.
Geopolitics Are Growing in Complexity
With numerous sanctions from Western countries against Russia, banking and other financial institutions are operating in an extremely complex geopolitical landscape. Working safely with Russia-related third-party partners and end-users while remaining compliant with ever-changing regulations is the new reality that many organizations face today.
Security teams in the banking industry are already inundated with a host of risks due to the sensitive nature of the information they handle, managing increased geopolitical complexity can easily become overwhelming.
Conducting Safer Business
Strider offers a suite of products designed to assist banks and other financial institutions in navigating the challenges of the dynamic geopolitical landscape. Our offerings encompass ensuring regulatory compliance and identifying state-sponsored risks within your organization.
Organizations Search is a third-party due diligence tool that provides visibility into security, compliance, and reputational risks. Organizations Search identifies organizational relationships including ownership, parent-subsidiary connections, and supplier-and-client relationships. It also provides insights into third-party partners and end users with connections to restricted or high-risk entities, foreign government, defense, research, or military organizations.
Our premiere email security product, Shield is a growing set of data that includes verified email addresses, domain names, and terms that are directly linked to state-sponsored actors. It allows you to effectively defend against state-sponsored solicitation directed at your organization.
People Search is a due diligence tool that allows you to more safely meet your talent needs. Search and immediately identify potential connections that individuals may have with state-sponsored risk. Using Strider’s robust data collection and AI processing tools, People Search identifies up to 13 potential connections, including government ties, military ties, and funding history.
Client Success with Organizations Search
As one of the largest and most reputable financial institutions
in the United States, our client regularly engages in merger & acquisition (M&A) activities. To ensure the safety of the organization and its clients, they prioritize thorough due diligence on potential M&A partners.
One of the most challenging aspects of their due diligence process has consistently been determining the state-sponsored risks associated with potential partners. It involved laborious processes, including gathering complex data, cross-referencing international sources, and conducting in-depth investigations. Due to the lengthy nature of this investigation, incidents occurred where an M&A had to be stopped entirely at the last minute after discovering state-sponsored associations with the organization, wasting valuable time and resources.
Realizing the need to streamline the due diligence process, our client sought out a solution and discovered Strider’s Organizations Search. Organizations Search enables our client to instantly verify whether potential M&A partners have possible ties to restricted or high-risk organizations, including sanctioned entities and subsidiaries, military suppliers, end-users, and other state-owned enterprises. Organizations Search also includes a dynamic network graph view that can be used to easily and visibly show high-risk organizational relationships that potential M&A partners have.
Taking advantage of the speed to insight, our client now utilizes Organizations Search as an initial screening tool before entering the entire due diligence process for potential partners. This new process has led to both time and cost savings, along with improved decision-making capabilities.
See Strider Products in Action
Our suite of products can help you proactively manage the risks that come with talent recruitment, compliance, and third-party and end-user due diligence. Get never-before-seen intelligence for faster, more confident decision-making.
Request a demo today to see how Strider can safeguard your organization.

Rising Risk in the Biotech Industry
As the biotech industry continues to experience significant growth, high-caliber talent recruitment is critical for organizations. For that reason, many Fortune 500 biotech companies employ researchers from around the world. Yet in recent years, this recruitment structure has become increasingly risky due to the rising amount of state-sponsored IP and talent theft attempts.
For example, in 2021 husband-and-wife scientists, Yu Zhou and Li Chen, were sentenced to prison for over two years for conspiring to steal trade secrets from Nationwide Children’s Hospital’s Research Institute, where they were employed for ten years. The couple intended to use these trade secrets to benefit the company they started in China with the assistance of the PRC government.
This incident serves as one of many examples of how the PRC government is actively targeting individuals working overseas to extract trade secrets to achieve their national objectives.
In this rising risk climate, many biotech research organizations are looking for solutions to help safeguard their IP, technology, and talent.
Conducting Safer Recruitment
Strider offers products that can protect biotech organizations to help ensure safer recruitment, better protection of research, and more confident end-user due diligence.
A new product from Strider, People Search empowers organizations to safely meet their talent needs by illuminating an individual’s potential connections to state-sponsored risk, including talent, partners, and collaborators. People Search identifies potential connections in areas including restricted, government, and military entities, as well as industry and education associations.
With Insights, you can visualize the overlap between foreign-government interests and your organization’s research and technologies. Broken down into detailed subcategories, you can gain a comprehensive view of where to focus your security response. Learn more about Insights here.
Shield is our premiere email security product. It enables biotech security teams to block, monitor, and investigate inbound emails originating from sanctioned, restricted, or state-owned entities. This growing list of proprietary data helps proactively stop the seeds of state-sponsored risk in organizations and helps protect the innovation and reputation of both the company and the employee.
Organizations Search enables our biotech clients to thoroughly screen potential third-party partners for any connections to sanctioned or restricted entities and subsidiaries, including state-owned organizations. Users can also ensure proper end-user due diligence and disambiguate specific ownership of various supply chain relationships in mergers and acquisitions.
See Strider Products in Action
With the use of Strider products, our clients can proactively manage the risks that come with talent recruitment, collaborations, and mergers & acquisitions. Get never-before-seen intelligence for faster, more confident decision-making.
Request a demo today to see how Strider can safeguard your organization.
Since its founding in 2019, Strider has taken a unique approach to managing state-sponsored risk. Traditionally, companies and governments have used a manual, case-by-case response. But as foreign governments increasingly exploit organizations’ intellectual property and talent to further their national objectives, a faster, more automated security response is needed. The first of its kind for state-sponsored risk, Strider takes a big-data approach. We leverage open-source intelligence to provide organizations with actionable data that allows them to visualize, manage, and respond to state-sponsored risk and supply chain vulnerabilities.
Industry in the Crosshairs
Foreign governments have always used tactics to obtain information that could help expand their technological and military prowess—the difference today is how they’re going about it. Historically, state-sponsored actors focused on collecting classified information at a government-to-government level. Today, we also know they focus on growing their strategic advantages through the global economy. That means collecting valuable information across a wide range of industries, like artificial intelligence, quantum computing, electric vehicles, and even agriculture equipment. As we have entered this new era of geopolitical competition, many companies are at a heightened risk of state-sponsored intellectual property theft.
Strider was founded on a clear purpose, “protecting the ideals and innovations of the free world.” We achieve that purpose by providing our clients strategic intelligence and subject-matter expertise.
Strategic intelligence at your fingertips
Now that private organizations are more in the crosshairs of foreign governments than ever before, the most effective way to combat this risk is with visibility. What technologies are foreign governments targeting? What tactics, techniques, and procedures (TTPs) are they leveraging? How do they find, contact, and recruit key employees? How does an organization know which of their suppliers have ties to government and military organizations? These questions are critical in securing your IP, talent, and supply chains.
Strider collects open-source data globally from over 31,000 primary sources in multiple languages. With over 7 billion documents in our system and 12 million more added every day, Strider delivers actionable insights without our clients providing any internal data. This dynamic data reaches across borders with source documents gathered from countries including the People’s Republic of China (PRC), Russia, and Iran. The data is then processed and merged with global patents, research publications, government websites, career profiles, and other publicly available sources.
But having all that raw data is meaningless unless you can turn it into contextualized, actionable intelligence. That’s where our proprietary methodology comes in. Strider leverages multiple different AI and machine learning (ML) technologies, including natural language processing (NLP), automated machine translation, hierarchical clustering, transformers, and other AI/ML technologies. These tools allow us to quickly organize, analyze, and pull the most relevant insights for our clients in the timeliest manner possible.
Our intelligence is currently channeled into three products:
- Identify and respond to state-sponsored risk in your organization at industry and individual levels. See which of your talent and technology is at the highest risk of being targeted, so you can get a more proactive view of where to focus your time, attention, and resources.
- Defend against state-sponsored communication attempts directed at your organization. Shield can be integrated directly into your existing security capabilities and flag any risky emails or other communication attempts.
- Organizations Search is third-party due diligence tool that provides visibility into state-sponsored security, compliance, and reputational risk. Strider’s automated screening process provides actionable and contextualized data that allows clients to adapt more quickly to changing business and compliance needs.
Subject-matter experts at the ready
State-sponsored risk is complex, continually developing, and can feel overwhelming at times. Even with heightened visibility, you might be left wondering about the best course of action. For that reason, we also make available a team of leading experts on protection, big data, tradecraft, finance, and analytics. The Strider Global Intelligence Team comes from top government agencies and companies from around the world.
Our team answers questions, provides insight, conducts Requests for Information (RFIs), and offers additional context when needed. This deeper, supplemental intelligence has proven invaluable for our clients time and time again.
See our offerings in action
Our unique data combined with our subject-matter experts offer an unparalleled level of intelligence on state-sponsored risk and supply chain vulnerabilities. Experience it in action with a live demo. Because we only use open-source intelligence, our demos aren’t hypothetical. We’ll show you real data and real insights in real time. Reach out today to get connected to a Strider representative to strategize how our intelligence and products can best serve your organization.