Wednesday, February 07, 2007

CRS Report on Maritime Security

In January, the Congressional Research Service released a report on the threat of maritime terrorism.

While noting that "fewer than 1% of all global terrorist attacks since 1997 have involved maritime targets," the report discusses a few of the particular threats. It's an exercise in threat recognition.

The CRS notes that there are particular challenges to launching a maritime attack:

One U.S. naval analyst has identified a number of specific challenges for terrorists in the maritime environment:
  • Maritime targets are relatively more scarce than land targets;
  • Surveillance at sea offers less cover and concealment than surveillance on land;
  • Tides, currents, wind, sea state, visibility, and proximity to land must all be factored into a maritime terror operation;
  • Maritime terror operations may require skills that are not quickly or easily acquired such as special training in navigation, coastal piloting, and ship handling;
  • Testing weapons and practicing attack techniques, hallmarks of Al Qaeda’s typically meticulous preparation, are harder and more difficult to conceal at sea than on land;
  • The generally singular nature of maritime targets, the low probability of damage and casualties secondary to the intended target, and the problems associated with filming attacks at sea for terrorist publicity may also reduce the desirability of maritime targets.
Despite these difficulties, al Qaeda and other terrorists have chosen maritime targets in the past, including the USS Cole bombing in 2000, the attack on the French oil tanker Limburg in 2002, and the 2004 attack on the Philippine Superferry 14.

A maritime attack does not need to cause many human casualties to have an effect:
If economic loss is the primary objective, terrorists may seek to carry out different types of attacks, with potentially few human casualties but significant impacts to critical infrastructure or commerce. The Limburg bombing may have been an attack of this type, threatening to disrupt the global oil trade and causing considerable consternation among tanker operators. Although the bombing killed only one member of the Limburg’s crew, it caused insurance rates among Yemeni shippers to rise 300% and reduced Yemeni port shipping volumes by 50% in the month after the attack.
The report comments on the relative risks of different types of maritime attacks, starting with the nuclear "bomb in a box" (i.e., shipping container) scenario:
Expert estimates of the probability of terrorists obtaining a nuclear device have ranged from 50% to less than 1%. Among other challenges to obtaining such a device, experts believe it unlikely that countries with nuclear weapons or materials would knowingly supply them to a terrorist group. It also may be technically difficult to successfully detonate such a nuclear device. North Korea experienced technical failures in conducting its 2006 nuclear weapons test, and this test took place under highly controlled conditions. Attempting to detonate a nuclear device in a maritime terror attack could pose even greater operational challenges.
The risk of a "dirty bomb" attack may be higher, especially if the primary objective is economic damage, though there are skeptics:
Terrorist attacks on U.S. ports with radiological dispersion devices (“dirty” bombs) is also considered among the gravest maritime terrorism scenarios. A 2003 simulation of a series of such attacks concluded that they “could cripple global trade and have a devastating impact on the nation’s economy.” Many terrorism analysts view such a dirty bomb attack as relatively likely.

Scientists have long questioned whether terrorists could actually build a dirty bomb with catastrophic potential since handling the necessary radioactive materials could cause severe burns and would likely expose the builders to lethal doses of radiation. Building and transporting such a bomb safely and to avoid detection would likely require so much shielding that it would be “nearly impossible” to move. Weaker dirty bombs made from less radioactive (and more common) materials would be easier to build and deploy, but would have a much smaller physical impact and would likely cause few human casualties.
Attacking a tanker or port facility that handles liquified natural gas (LNG) could create a major explosion, though it's not easy:
To date, no LNG tanker or land-based LNG facility in the world has been attacked by terrorists. However, similar natural gas and oil assets have been favored terror targets internationally. The attack on the Limburg, although an oil tanker, is often cited as an indication of LNG tanker vulnerability.

Former Director of Central Intelligence, James Woolsey, has stated his belief that a terrorist attack on an LNG tanker in U.S. waters would be unlikely because its potential impacts would not be great enough compared to other potential targets. LNG terminal operators which have conducted proprietary assessments of potential terrorist attacks against LNG tankers, have expressed similar views.
If terrorists are looking for human casualties, a ferry is a possible target:
A RAND study in 2006 argued that attacks on passenger ferries in the United States might be highly attractive to terrorists because such attacks are easy to execute, may kill many people, would likely draw significant media attention and could demonstrate a terrorist group’s salience and vibrancy. One U.S. Coast Guard risk analyst reportedly has stated that “in terms of the probability of something happening, the likelihood of it succeeding and the consequences of it occurring, ferries come out at the very high end.” Such attacks have occurred overseas. As noted earlier in this report, terrorists linked to Al Qaeda attacked and sank the Philippine vessel Superferry 14 in 2004.
After examining the details, the report comes to this rather bland conclusion:
It appears, therefore, that while maritime terrorist attacks against the United States may be more difficult to execute and, consequently, less likely to occur than other types of attacks, they remain a significant possibility and warrant continued policy attention.

Friday, February 02, 2007

Boston's Aqua Teen Misadventure

Wednesday's news out of Boston, where the city came to a virtual standstill after city officials were notified of some suspicious objects - which later turned out to be "guerilla marketing" signs promoting a cartoon called Aqua Teen Hunger Force - is intriguing for a number of reasons.

First, a few basics of the case. Cartoon Network hired a marketing firm to come up with a "guerilla marketing" promotion for the trendy cartoon. The marketing firm created some light-up signs depicting characters from the cartoon (which looked a lot like Lite-Brite displays), then hired some people in various cities to plant them where they would be seen, such as "train stations, overpasses, 'hip and trendy areas, high traffic areas of high visibility'" (which only makes sense if you're trying to draw attention to your cartoon). The AP reported:

The first device was found at a subway and bus station underneath Interstate 93, forcing the shutdown of the station and the highway.

Later, police said four calls, all around 1 p.m., reported devices at the Boston University Bridge and the Longfellow Bridge, both of which span the Charles River, at a Boston street corner and at the Tufts-New England Medical Center.

The package near the Boston University bridge was found attached to a structure beneath the span, authorities said.

Subway service across the Longfellow Bridge between Boston and Cambridge was briefly suspended, and Storrow Drive was closed as well. A similar device was found Wednesday evening just north of Fenway Park, police spokesman Eddy Chrispin said.
So ... people notice the signs, think they look suspicious, call the police - and all hell breaks loose for the rest of the day.

Meanwhile, the marketing agency - in a truly dumb and irresponsible move - told its people in Boston to remain quiet, even as the city was locking down.
According to an e-mail one friend provided to the Globe, the executive at Interference Inc. told the artist, whom the agency had hired to install the small, battery-powered light screens in Boston, to remain silent, even as dozens of police officers collected the devices and shut down highways, subway lines, and part of the Charles River.

The executive asked Peter Berdovsky to "pretty please keep everything on the dl," slang for down low, or hush-hush, according to the message Berdovsky sent to his friends.
The city virtually shuts down, countless people are inconvenienced, the police and everyone else goes on high alert - and later in the day, the marketing company finally comes clean that it's just a promotion. There's no danger.

But, what's more, the company paid other people in other cities to plant the signs there. And in some cities, the signs had been there for 2-3 weeks - with not a single complaint. No one in New York reported any problems with the 41 signs there:
Not one New York City resident made a 911 emergency call in response to the promotion here Wednesday -- and, unlike Beantown, Manhattan has really been the target of terrorist attacks.
Portland responded "with a yawn," though maybe that had to do with the placement of the signs:
Portlanders have reported finding at least three of the devices that caused a minor panic in Boston, but reacted with a yawn, if that.

They were found in some of the trendier neighborhoods and were not near bridges or other infrastructure.
It's sensible that, if the people in Portland didn't place the signs near any key infrastructure elements, there would be less perception of a threat (unlike Boston). But ... if the placement of the signs were the determining factor, wouldn't you expect that Seattle would have had the same problem as Boston? At least one sign was posted on a bridge there:
Some of the same blinking electronic devices that threw a scare into the city of Boston today (Wednesday) have been found and removed from Seattle and several suburbs.

Police say the removal was low-key in Seattle.

One was found yesterday (Tuesday) by a Woodinville Public Works Department crew working on a rail trestle over State Highway 202.
Hmm ... and there was nothing to report in Atlanta:
Joe Cobb, Atlanta Police Department public information officer, said his department was unaware of the devices and had received no complaints.
In San Francisco it was also a non-event:
San Francisco police say 20 blinking signs advertising a cartoon show were scattered in various city neighborhoods without causing a stir.
Apparently no one had yet gotten around to placing any of the signs in Los Angeles:
None of the devices, which were planned to be placed around the Westside of Los Angeles, including Hollywood, West Hollywood and Santa Monica, had been reported found.
And although all of these cities seemed to shrug it off, the signs raised the ire of public officials in two cities: Philadelphia ...
When city officials learned little devices equipped with circuit boards and batteries were spread across Philadelphia, managing director Pedro Ramos and officials with the Mayor's office began combing the streets.

Ramos said the signs are illegal and those responsible will be punished.
... and Chicago:
They were recovered from elevated stations and storefronts…

And the city may seek monetary reimbursement from the marketing company responsible for planting them, said Supt. Philip Cline.
So ... the signs were considered a huge problem in Boston, a nuisance in Philadelphia and Chicago, and no big deal anywhere else. Philadelphia and Chicago want to be reimbursed for the trouble of finding and removing the signs.

And the prosecutor in Boston has prosecution on his mind - presumably, on charges of launching a full-blown terrorist hoax:
Assistant Attorney General John Grossman said bomb squad members who examined the lighted signs immediately detected three components that suggested the contraptions could be bombs. He said the black signs, about the size of a laptop computer, had what appeared to be a duct-tape wrapped package with a wire running into it and a power source, which would be needed to detonate a bomb.

"The devices looked like bombs" and had an "ominous nature," Grossman said.
While recognizing the fact that public authorities have to respond to any possible threat that's called in, a few questions come to mind:
  1. Even without hearing from the marketing company, why didn't officials in Boston more quickly recognize that these things weren't bombs? It took hours for bomb-squad experts to see these things for what they were? Yes, there were batteries and wires, but these devices really weren't planted like an IED typically would be. Generally speaking, when you're planting an IED, you want it to blend in with its surroundings. You hide it in a backpack, or in a garbage can, or under a pile of garbage. You don't put blinking lights on it and place it in plain sight.
  2. What effect will this have on "See Something, Say Something" efforts? Will people in Boston be as likely to report suspicious items if the result is a shutdown of the city, over something that turned out to be nothing at all?
  3. If the guys in Boston (and here I'm talking about the guys who placed the signs, not the marketing agency who directed them) committed a crime, then what about the people who were hired to plant the signs in other cities? Did they commit the same crime? Or is the crime determined primarily by the degree to which public officials react to it? Did the guys in Boston commit a really serious crime, the guys in Chicago and Philadelphia commit a less serious crime, and the guys in Portland, New York, San Francisco, Seattle, etc., no crime at all?
  4. Are we going to say that putting up signs like this is equivalent to, for instance, filling envelopes with white powder? Is it equivalent to calling in a bomb threat? Where do we draw the line?
  5. How do authorities maintain vigilance without giving the appearance of crying wolf, when something like this happens? Every time that something like this happens, and there turns out to be no threat, people are going to be less and less inclined to respond to future warnings. It really is the "cry wolf" syndrome.
It's an interesting case, and one that indicates that there's a lot of Homeland Insecurity out there.

National First Responder Appreciation Day

The First Response Coalition is sponsoring an effort to establish a National First Responder Apprecition Day. They point out that catfish and ice cream have national days of appreciation; but firefighters, police officers, and emergency medical personnel don't.

There's a video in support of the effort, as well as a petition that you can sign.



Tuesday, January 30, 2007

Review: "Discourse, Dissent, and Strategic Surprise"

The Institute for the Study of Diplomacy at Georgetown University recently published a report titled "Discourse, Dissent, and Strategic Surprise."

Although the authors' focus is the federal government - i.e., the communication difficulties experienced by diplomats (especially those overseas) and policymakers in Washington D.C., I thought the report had some relevant findings for homeland security professionals at all levels of government.

Generally, the report argues in favor of casting a wider net when seeking intelligence on a given threat - and it harshly condemns the practice of filtering all information through a pre-existing mindset.

We all are given to interpreting new information through the filter of our past experiences, but this report shows how prior failures of the U.S. government should serve as a lesson that the way to proceed is to keep an open mind, to listen, and to avoid pretending that we already know what the threat is.

The report focuses on a number of case studies which resulted in unpleasant surprises for the United States. Specifically, the failures to:

  1. Anticipate the 1979 revolution in Iran
  2. Recognize the threat against U.S. embassies prior to the 1998 embassy bombings
  3. Recognize the scale of the Soviet invasion of Afghanistan in 1979
  4. Understand the nature of the conflict in the U.S. - U.S.S.R. "proxy war" in Afghanistan from 1989-1992; specifically, the danger in arming and training the mujahedin
  5. Anticipate the Asian financial crisis of 1997-98
Here are a few highlights of the report, with comments:
Long-standing and systemic tensions in U.S. democracy exist between the need for open discourse and the requirements of a disciplined decision-making process, both of which are needed to govern effectively. Protection of the consensus, however, has the potential to hinder sound policy formulation when professionals are discouraged from presenting informed views simply because they challenge the status quo. When such information—and the people providing it—are excluded from policy discourse, the “marketplace of ideas” ceases to work as an essential corrective to mistaken or flawed assumptions.
Leaders must be especially sensitive to the danger of silencing those at lower levels. "Speaking truth to power" becomes extraordinarily difficult when your career is on the line. Leaders must be open to dissenting views:
It is inherently difficult for subordinates to challenge the prevailing views of their leaders at any time. This is particularly so when leaders are intent on pursuing a course of action, driven by firmly held assumptions about the nature and urgency of a threat.

But nonmonetary—or even monetary—incentives aimed at encouraging independent thought may not be enough to persuade individuals to express candid disagreements with the consensus if by doing so they also are bargaining with their professional survival. The interactions among senior and mid- to low-level professionals in both the intelligence and policy arenas are therefore central factors considered in our study, part of the analysis of how constraints on discourse can emerge and inhibit alternative interpretations of events, sometimes leading to a collective failure to anticipate or understand new threats.
The case of the Iranian revolution shows how the silencing effect can work:
Efforts by low- and mid-ranking analysts to discuss the regime’s failings were treated by most senior officials not just as irrelevant but suspect and soft headed. Just raising such issues could be incendiary, given that some officials believed that discussions of deteriorating conditions in Iran could add to the prospects that the shah would not survive. As such, reporting of bad news was actively discouraged, contrarian analysts found they were not being invited to meetings, and eventually the voices faded away.
In the case of the African embassy bombings, the problem was different. Information about the threat was available, but it was unwelcome:
Failure to heed—or to ask for—reports about conditions on the ground can lead to ignorance or misunderstanding of important political and economic trends that portend new security challenges.
Most ominously, the warning bell was repeatedly sounded by the U.S. ambassador to Kenya. But the warnings were received with hostility:
After it was disclosed that she had arranged to have her letter voicing security concerns hand-delivered to the secretary, [U.S. Ambassador to Kenya, Prudence] Bushnell, for the first time in her long and distinguished Foreign Service career, received a mediocre performance review. Just weeks before the bombings, Bushnell was chided for her excessive preoccupation with security and her “tendency to overload bureaucratic circuits.”
In the case of the 1989-92 "proxy war" in Afghanistan, which was almost entirely a covert operation, senior policymakers were actually the blindfolded ones. They kept on the current track because they did not have enough information to question whether it was the correct track:
This case provides a textbook example of how those who have access to information can become the drivers of policy, granting individuals authority that would normally exceed their jurisdiction or level of seniority. Without routine access to information, policymakers will always feel constrained from questioning the prevailing policy because, as one participant put it, “they feel they are missing the information needed to make judgment calls . . . and so they tend to back off.”
In short, the information sharing system virtually shut down:
Information about covert operations is always highly restricted, but in Afghanistan it extended only to a small number of individuals from Congress, the intelligence community, and a few executive branch officials. One former congressional aide whose senator was not included in the inner circle remembered how difficult it was for him to gain access to information about the situation in Afghanistan, notwithstanding the authority granted to the senator by virtue of his committee assignments. An intelligence official who was part of the operations agreed, adding the observation: “At any given time, in the peak of our involvement in Afghanistan, there were never a hundred Americans at work on the problem. . . . We [U.S. intelligence operatives] provided wide open door access [about events in Afghanistan], but to a very limited number of people. And they were very good about keeping it from everybody else.”
After examining all of the case studies, the report comes to some predictable conclusions:
The instances of surprise we examined in this study are not often the result of missing or faulty intelligence information; they are far more about the way information is interpreted, distributed, and prioritized by senior officials.

Policymakers dismissed warnings when the indicators failed to conform to common conceptions of what constitutes a genuine threat to U.S. “vital” interests.

When a healthy consensus evolves into a “mindset,” the assumptions and beliefs underlying that consensus can become impervious to new information, sometimes blinding leaders to the implications of global trends.
And ... in summary ... information sharing is absolutely vital to recognize threats:
When there is no routine discourse among top officials and professionals with detailed expertise, the ability even to consider realigning policies in response to breaking events, let alone to understand complex events, is virtually impossible. This factor is critical to understanding the phenomenon of surprise. Undue restrictions on the number and kind of individuals or agencies allowed to contribute to intelligence or policy debates by definition interfere with the government’s ability to assess events reliably.

Info Sharing and the Water Supply

A brief article in today's Tallahassee Democrat discusses an audit of that city's security plan for its water treatment systems. It's well known that water systems are potential targets for attack, for two reasons:

  1. Many of them use dangerous chemicals to purify water (i.e., chlorine and ammonia)
  2. The water system would be an excellent means of distributing poisons or other dangerous substances to an entire community.
City auditors found that Tallahassee's security plan was lacking in a few key areas:
Among its findings, the Jan. 9 audit noted that: some city employees weren't properly notified of what would be expected of them in an emergency; the locations of valves needed to isolate the water supply weren't identified in the emergency plan and access to a city wastewater plant was too lax.

The city has made good headway, the audit found, but the written plan needs to locate valves that isolate water supply to critical customers such as hospitals, nursing homes, day care centers and schools because "the ability of the Water Utility to quickly locate and shut off valves may be hindered without this information."

It also needs to be formally communicated to the staff who would potentially execute it, he said.

"The thought process was that the employees already knew what to do," said City Auditor Sam McCall. "But this actually spells out what you should be doing."
This is another demonstration that a good plan is next-to-useless unless you share information with others who need to know.

Monday, January 29, 2007

The County Interagency Safety Board

Hamilton County, Indiana - which includes northern suburbs of Indianapolis - recently approved its Interagency Public Safety Board, the Indianapolis Star reported.

The board has been meeting unofficially for about two years, but is just now getting formal recognition from county officials.

The board includes the sheriff, police and fire chiefs from Fishers, Noblesville and Carmel, the town of Westfield's administration director, two officials from the county emergency management office and one representative from the northern fire and police departments.

Originally created to help decide how to use a $4.8 million Homeland Security grant to update technology, [Sheriff Doug] Carter said the board will now delve into other issues.

"We want to have an open dialogue and meet and talk about things we can do, whether it's training initiatives, statutory updates or issues facing law enforcement around the county," he said. ... "We want to share resources and information."

"We have a lot of different issues before us today, and two of those major issues are communication and training," Noblesville Police Chief Dick Russell said.

He said public safety agencies today shouldn't try to function independently of each other. "It takes the public, it takes us communicating with other agencies. The better we can communicate, the better we will be able to do our jobs."
A few thoughts come to mind: First, this sounds like the kind of collaborative spirit that local authorities should have. Second, I wonder how many other communities have such a board - either official or unofficial? Third, I wonder why they waited 2 years before trying to get official recognition from county authorities?

Wednesday, January 24, 2007

The Risk Right Here

There was some interesting testimony at last week's hearing of the House Permanent Select Committee on Intelligence. Generally, there was a lot of old info, but some new info as well.

Director of National Intelligence John Negroponte discussed the likeliest threat:

Use of a conventional explosive continues to be the most probable al-Qa'ida attack scenario. … Nevertheless, we receive reports indicating that al-Qa'ida and other groups are attempting to acquire chemical, biological, radiological, and nuclear weapons or materials.
Lieutenant General Michael Maples, who's the Director of the Defense Intelligence Agency, provided more insight into probable WMD threats, as well as some of the more likely avenues of terrorist recruiting:
CBRN-related information is widely available, and if terrorists were to use unconventional materials in an attack, we believe they likely would use low-level biochemical agents such as ricin, botulinum toxin or toxic industrial chemicals such as cyanide. … We also judge that al Qaida and other terrorist groups have the capability and intent to develop and employ a radiological dispersal device.

Extremism throughout the West will continue to be spread primarily through radical clerics, the Internet, and in prisons.
Charlie Allen, the Chief Intelligence Officer at DHS, chimed in with some information on potential U.S. targets and additional info on terrorist recruiting:
We determine that transportation (particularly commercial aviation and mass transit) and commercial facilities remain the sectors most threatened by al-Qa'ida and its affiliates.

Our research indicates a variety of radicalizing influences, to include the role of charismatic extremist leaders, the spread of extremist propaganda through the Internet, the use of mass communication and multimedia, and more traditional person-to-person encounters, are among the key drivers that shape radicalization dynamics within the Homeland.
I thought the most interesting testimony was given by Phillip Mudd, who was appearing on behalf of Willie T. Hulon, the Executive Assistant Director of the FBI's National Security Branch (NSB). Mudd talked about the connections between terrorists and more ordinary criminal activities, the risk of homegrown terrorism, and the threat posed by Hezbollah:
Last year, we disrupted a homegrown Sunni Islamic extremist group in California known as the JIS, a.k.a. 'Assembly of Authentic Islam,' operating primarily in state prisons, without apparent connections or direction from outside the United States and no identifiable foreign nexus. Members of the JIS committed armed robberies in Los Angeles with the goal of financing terrorist attacks …

The radicalization of US Muslim converts is of particular concern. … converts appear to be more vulnerable and likely to be placed in situations that put them in a position to be influenced by Islamic extremists.

The Internet has facilitated the radicalization process, particularly in the United States, by providing access to a broad and constant stream of extremist Islamic propaganda, as well as experienced and possibly well connected operators via web forums and chat rooms.

US Hizballah associates and sympathizers primarily engage in a wide range of fundraising avenues in order to provide support to Hizballah to include criminal activities such as money laundering, credit card, immigration, food stamp, and bank fraud, as well as narcotics trafficking.
The UPI also reported on the hearing, adding some additional perspective from the participants on the use of the Internet to spread extremist ideologies. Mudd said:
The commonality we have (with Europe) is people who are using the Internet or talking among friends who are part of what I would characterize as a Pepsi jihad ... It's become popular among youth, and we have this phenomenon in the United States.

So that you have a kid in Georgia, a kid in California, a kid in Kansas, he may see the same images from Iraq, from Palestine, from Afghanistan, from Pakistan, that someone in Indonesia or Saudi Arabia sees, and he may be infected the same way with an ideology that says the use of violence against innocents is okay.
But, the UPI reported, others point out that there is a generally small risk of a group of young people becoming radicalized over the Internet and then launching a catastrophic attack, without any further connections or training:
"It's ridiculous to think that the U.S. or any other military would do its training over the Internet," said analyst and author Peter Bergen, arguing al-Qaida was just as professional in its approach. "Radicalization is one thing, having operational cells with the capacity to launch attacks is something else entirely.

"That basically means people who have been through one of the (terrorist training) camps."

Bergen said that the homegrown plots uncovered in the United States so far appeared to lack that thread back to al-Qaida central, which was one reason why he said they had been "pretty pathetic ... not much of a threat."

Monday, January 22, 2007

Calling Mall Security

The Department of Justice recently released the results of a study on mall security. The findings were not that surprising to me: Overall, state homeland security officials and mall security directors say yes, things are fine, they're prepared. But when you look closely at the actual preparations and training that's going on at malls, gaps emerge. And it's especially revealing to compare the security at American malls to the security at malls in Israel.

First, the good news:

In several cities, police and security firms have formed formal cooperative associations to meet and discuss topics such as bomb threats, executive protection, and burglary investigation.

Overall, [state homeland security directors] were fairly optimistic about the ability of large retail malls in their state to respond to terrorist attack. … Most respondents who reported a positive assessment (very good, good, or fair) believed either that malls cooperated well with local law enforcement or that they had developed emergency plans.

One state advisor noted:

We have three malls in the state that are currently participating in the DHS Buffer Zone Protection Plan initiative. By actually sitting down at the table and working with the other key stakeholders from the local law enforcement, fire, EMS, and EMA communities, these malls are much further down the road in identifying, understanding, and acquiring the physical security resources and training that better prepare them to interdict and/or respond to a terrorist event.

Fifteen, or slightly less than half, of the state homeland security advisors affirmed that they were aware of joint exercises between security staff in some malls and local police. Thirteen affirmed joint exercises with fire and/or EMT staff.

Cooperation with public officials proved to be an important stimulus for the development of emergency preparedness plans.

Three out of four (73%) [mall] security directors reported that they had developed written protocols for security staff to follow in the event of a disaster. The same proportion reported that these plans included coordination and communication with local law enforcement, fire, and medical first responders. A much smaller number (3 in 10) had held exercises to rehearse emergency protocols with first responders.

[T]wo in three mall security directors characterized their local police as being at least somewhat involved in their security planning. Nearly half (44%) of mall security directors stated that law enforcement officials regularly shared key intelligence with them, and another 34% said that information was sometimes shared.
But ... mall security directors would like even more help. And they need to do more:
By a large majority (63%), mall security officials would welcome greater involvement of their state DHS and law enforcement officials in security planning.

One of the most consistent and striking findings during the site visits was that malls we visited have not made any significant investment in increased security following 9/11.

We observed that, in sites that had received Buffer Zone Protection Program (BZPP) funds, local law enforcement, working with the state homeland security offices, took the initiative and contacted area malls to conduct a risk assessment. … Risk assessments, when conducted, have largely been driven by the BZPP application process. …Without undergoing some form of risk assessment process, it is difficult for mall managers to arrive at an understanding about what elements should be protected and which strategies should be employed for prevention of specific assets.

None of the malls we visited had developed ways to coordinate with first responders in the event of an emergency. The only means of communicating with first responders was by phone. The general plan in all cases was that, once first responders arrived on the scene, they would take charge and mall staff would follow any instructions they were issued by police or fire officials. In none of the malls we visited was it clear who would be responsible for briefing first responders or how mall security evacuation plans would be coordinated given law enforcement’s need to retain and interview eyewitnesses.

We found wide variation in how local law enforcement and regional terrorism task forces had been involved in mall security. We observed malls that had a close relationship with local law enforcement. … On the other hand, we also observed malls that had little relationship with local law enforcement. These malls were generally not privy to police intelligence data and did not participate in risk assessments or emergency plans.

We did not encounter any active programs to evaluate what guards derived from terrorism training, or if terrorism prevention and response was actually incorporated into daily work routines. … With no tabletop or live exercises and no clear standards for evaluation, it is impossible to say how well staff would respond in the event of a disaster.
And when compared to the security at malls in Israel, the security at American malls looks positively shoddy:
According to the [mall] security directors that we spoke with [in two Israeli malls], local law enforcement and emergency service representatives often conduct joint exercises with mall security. The exercises include comprehensive drills attended by the district fire brigade, ambulance system, and the entire police district. In addition, there is open intelligence sharing between mall security and local law enforcement. In one mall, police briefed the mall security chief weekly. In the other, the local police district held monthly meetings during which antiterrorism intelligence was shared and discussed with key individuals in the community, including mall security directors. One of the malls we visited provides the local police district with an onsite substation. This allows a subset of officers to become knowledgeable about mall operations and physical layout. It also allows these officers to get to know the mall’s security staff. Finally, mall security and local law enforcement share interoperable communication systems. In the event of an emergency, each unit could communicate with one another over a shared radiocommunications band.

According to the security officers we talked with, the malls [in Israel] usually conduct about 50 drills per month. These range from minor procedural drills to covert drills during which false bombs are planted and attempts are made to bring them into the mall. Major exercises are carried out in cooperation with the police, who evaluate the adequacy of the response by mall security. When security officers fail to detect planted threats, they are retrained. If they fail a second time, they are fired. In addition, a system of positive incentives is also utilized. If a security officer detects a problem during a drill and acts accordingly, that officer will receive a monetary bonus.
The study authors admit that it's unrealistic and unnecessary to try to protect American malls to the same degree that malls are protected in Israel. But they suggest a few reasonable steps "steps that are not expensive and would not alter the experience of consumers":
  1. Conduct formal risk assessments and take steps to mitigate known risks on a costbenefit basis
  2. Develop and rehearse detailed and coordinated emergency response plans and involve stakeholders
  3. Standardize antiterrorism training courses.
  4. Enhance partnerships with the public sector.
Once again, the emphasis is on developing relationships, collaborating, and sharing information. That's the foundation. Training and interventive measures can then build on this foundation.

Friday, January 19, 2007

Hurdle to Interoperable Comms: It's Not Money

Federal Computer Week ran a brief story on a market research report by Datamonitor, whose primary findings were that local communities plan to spend a lot of money on interoperable communications, but that there's still no guarantee of success:

State and local governments will boost their technology investment by 40 percent in the next five years as they struggle to overcome communications problems that stymie coordinated emergency response efforts ...

Technology spending will rise from $3.2 billion in 2006 to $4.4 billion in 2011 ...

But despite increased spending, those initiatives could run into a raft of problems ... Public safety agencies say funding is the major obstacle to improving interoperability, said Kate McCurdy, Datamonitor’s government technology analyst, “but we cannot overlook the fact that collaboration and collective decision-making is difficult in an environment where individual agencies or jurisdictions typically purchase equipment independently.”
These findings echo DHS' own recent findings, which indicated that "Governance" was the major factor for successful implementation of interoperable communications (original report: here; my blog entry: here).

You can't overestimate the importance of collaboration and information sharing. Throwing money at this problem will not solve it by itself.

Thursday, January 18, 2007

An al Qaeda Training Doctrine

Terrorism Monitor has an interesting article on the evolution al Qaeda's training doctrines. Focusing on one particularly influential jihadi strategist, Abu Mus'ab al-Suri, the report describes how his strategic thinking is affecting the shape of the al Qaeda organization today.

Anyone interested in homeland security should be aware of how terrorists are organizing their operations. In a nutshell, the article argues that al Qaeda is abandoning hierarchical organizational structures and is promoting the idea of small-cells-everywhere. The same concept has also been noted by others. Call this another data point that helps clarify the picture:

[T]he practice of "individual terrorism" is a core theme in al-Suri's most recent writings, and it is rooted in his most famous slogan: nizam, la tanzim (System, not Organization). In other words, there should be "an operative system" or template available anywhere for anybody wishing to participate in the global jihad either on one's own or with a small group of trusted associates, and there should not exist any "organization for operations." Hence, the global jihadi movement should discourage any direct organizational bonds between the leadership and the operative units.

The same goal of decentralization is applied in al-Suri's training doctrines; training should be moved to "every house, every quarter and every village of the Muslim countries." ... For al-Suri, the issue is not only that of decentralization, but also of transforming the jihadi cause into a mass phenomenon.
For local homeland security professionals, it is always worth noting that terrorists are most likely to manifest themselves in small groups or individuals.

One key question is whether the jihadist cause could or would ever be picked up by a critical mass of Muslims worldwide. Mass movements tend to peter out, often before they reach this critical mass, especially when an insistence is made that fighters should be true believers in the cause.

And that's just what Al-Suri insists upon. He argues that jihadist fighters should be fully ideologically motivated for the fight. He wants true believers:
The decisive factor for successful jihadi training is the moral motivation and the desire to fight, not knowledge in the use of arms, al-Suri asserts. If the ideological program is not fully digested and the mental preparation is absent, weapons training is of no use.

In an audiotaped interview in the late 1990s, al-Suri recalled how he had second doubts about the training that many Arab volunteers received in Peshawar and in Afghanistan, especially those hailing from the Gulf countries, since they more often than not failed to share his radical ideological platform:

"I am not prepared to train [people] in shooting practices because I think they will fire back at us justifying this by the fatwas of the Muslim Brothers and the Azhar clerics … People come to us with empty heads and leave us with empty heads ... They have done nothing for Islam. This is because they have not received any ideological or doctrinal training"
From the perspective of terrorist vulnerability, it is revealing that al-Suri questions the devotion of even many of those who went to Afghanistan. This tells me that, wherever there is a terrorist group, it's never a sure bet that all of them are going to be fully committed. This is a vulnerability for them.

Thursday, January 04, 2007

NYC's New Decontamination Central

According to an article in the New York Sun, NYC's Downtown Hospital just opened a large, advanced decontamination station, capable of treating 500-1000 patients per hour (compared to 20 patients per hour in the hospital's old decon unit):

Because water is the single greatest antidote to contamination, according to Dr. Najer, the hospital installed 25 high-power showerheads that jut down from the roof of the semi-outdoor enclosure.

The shower water is warmed by a 1,000-gallon tank that is separate from the hospital's water supply, ensuring a constant supply of heated water. Gas-powered heaters are scattered along the roof of the facility.

The unit also has several outlets that can pump "medical air" into the self-contained suits that physicians wear while treating contaminated patients.

"It's arguably the most technologically advanced decontamination unit in the world," Dr. Antonio Najer said.
This is good preparedness, at a relatively inexpensive cost of about $1 million. And it's not just NYC that could use one of these things. Any community that's near a chemical plant, a port, a nuclear power facility, etc., could benefit from a large decon station like this. In any major situation, you've got to get people cleaned up quickly. And, in a nod to hospital administrators, you can find other uses for it as well:
The unit has other functions as well, according to the hospital's assistant vice president of public affairs and marketing, Vanessa Warner. In the case of plane crash, it could be used to clean hazardous jet fuels off of victims, and it could double as a car wash for ambulances.

Wednesday, January 03, 2007

The Threat to the Energy Infrastructure

The National Governors Association recently released a report on the threat to the nation's energy infrastructure, both from natural and man-made threats. The report provides a number of recommendations that state-level executives can take to manage the risk. The suggestions were generally not surprising - work with other states, the energy industry, develop response and recovery plans, etc.

I thought some of the more interesting information in the report dealt with the threat itself:

The nation’s diffuse energy infrastructure—with many pipelines and transmission lines running through sparsely populated areas and electricity substations sited in remote areas—makes the industry susceptible to sabotage by international terrorists, loosely organized home-grown movements, lone-wolf extremists, and common thieves and vandals. Documents discovered in Afghanistan and elsewhere since the September 11, 2001 terrorist attacks indicate that al Qaeda has targeted energy infrastructure, particularly nuclear power plants and oil and gas infrastructure in the United States and Saudi Arabia, as part of a campaign to disrupt the U.S. economy and inflict mass casualties.

[E]xperts warn switching systems that control electrical substations could be vulnerable to sabotage and, if damaged, are expensive and difficult to replace. … Should a number of critical switching stations come off line, entire segments of the grid could be affected for weeks.

In fact, significant terrorist attacks against electrical systems are common in other parts of the world. In Colombia, for example, the electrical grid is a favorite target of the Revolutionary Armed Forces of Colombia (FARC). Shortly before the country’s May 2006 presidential elections, a FARC bombing of the electrical grid serving the port city of Buenaventura left the city in darkness for days.
The energy sector in general, and the electric grid in particular, are highly exposed. It's important for local first responders to know the vulnerable points in the network in their area.

Most Likely WMD Scenario?

The Canadian Security Intelligence Service (CSIS) recently issued a report indicating that the most likely WMD terrorist threat involves a radioactive dispersal device, or "dirty bomb," the Globe and Mail reported.

The CSIS even goes so far as to say that it's surprising that no one has yet used this mode of attack:

Canada's spy agency says it is “quite surprising” that terrorists have not detonated a crude radioactive bomb, given the availability of materials and ease with which they could be made into a weapon.

But the CSIS study cautions that “a determined and resourceful terrorist group” could execute more elaborate forms of nuclear or radiological attack.

“The technical capability required to construct and use a simple RDD is practically trivial, compared to that of a nuclear explosive device or even most chemical or biological weapons,” the CSIS study says.

A homemade radiological weapon could consist of a conventional explosive laced with radioactive material commonly found at universities, medical and research laboratories or industrial sites.

The intelligence service points to the notion terrorist thinking has shifted from the desire to inflict mass casualties to “one of inflicting severe economic damage.”
It's not news that an RDD is a more likely mode of attack than a nuclear weapon. It's important to note, though, that the CSIS is seeing terrorists as pursuing economic aims rather than bodycounts. This has long been a key element of al Qaeda's strategy, as Brian Michael Jenkins pointed out in his excellent book, Unconquerable Nation:
Lest anyone misunderstand the purpose of jihad and consider it a form of spiritual calisthenics, bin Laden is explicit: “It is a religious-economic war,” he says. ... He argues that the United States can be brought down by destroying its economy.
Al Qaeda, in its view, brought down the Soviet Union by draining its economy through the Afghan war. It seeks to do the same thing to the United States.

Seven, Not Three

Eric Holdeman, the director of the King County (WA) Office of Emergency Management (i.e., Seattle) published an opinion piece in the Seattle Post-Intelligencer that diverged from the DHS standard for personal preparedness.

Rather than be ready for 3 days without assistance, Holdeman writes, citizens should be ready for a week on their own:

If you are planning to be on your own for only three days, you are doing only the absolute "minimum" necessary to keep safe, warm and well fed after a disaster.

We should all plan for a minimum of seven days of preparedness. Seven days is how long it will take the federal government to mobilize resources and deploy them to a disaster area.

Does seven days sound like a lot? Consider a worst-case pandemic flu scenario, where a wave of infection can last 12 weeks; or a catastrophic earthquake ... Not only will we lose power, but also our bridge and overpass-dependent transportation system will be disrupted for months, hampering the movement of disaster supplies, food and goods.
Holdeman's advice is sensible. But the real question is how to encourage citizens to actually make their kits and plans. Being prepared for a disaster is one of those things that people never get around to.

Rail Security: Will the Information Be Shared?

GovExec has a short article today about pending rules from TSA regarding rail shipments of hazardous materials:

The Transportation Security Administration is set to propose a new rule that would require rail carriers to respond more quickly to government queries on the whereabouts of hazardous chemicals they transport through urban centers.

Under the proposed rule, slated for publication next week in the Federal Register, transporters of potentially explosive chemicals or those that could be lethal if inhaled would have as little as five minutes to tell federal investigators the precise location of rail shipments, in the highest risk situations. In less severe circumstances, the companies would be allowed up to half an hour to respond.

The regulation also would require industry officials to designate a rail security coordinator to work with federal officials and track and reduce "standstill" time for railroad cars carrying hazardous materials.
Here's my question: Who notifies local authorities, who will be the first on the scene in any hazardous materials incident? In a HAZMAT incident, every second counts. If lives are to be saved in this type of incident, they will be saved by local personnel. Will the information be shared promptly with local authorities?

Tuesday, December 19, 2006

The "Other" Terrorists

It can be tempting to think primarily of terrorists as al Qaeda types. But a recent terrorist case in Tennessee demonstrates that other threats are still out there. The AP reported:

A white supremacist was sentenced Nov. 28 to 30 years in prison for attempting to acquire Sarin nerve gas and C-4 explosives that he planned to use to destroy government buildings.

Demetrius Van Crocker, 40, a farmhand from the small town of McKenzie, Tenn., near Jackson, was arrested in 2004 after an FBI undercover agent posing as an employee at the Pine Bluff Arsenal in Arkansas, delivered a water-filled Sarin canister and a small quantity of explosives.

Crocker appeared to be obsessed with poisonous chemicals and showed an above-average knowledge of basic chemistry, which he said he acquired while working in an electroplating factory.

"I ain't gonna quit trying," he said of his desire to acquire a dirty bomb.

When he talked about casualties, Crocker said they "can't be helped." In a separate conversation with an informant, he said, "Let God sort 'em out."

The online magazine Salon also reported on the story, although in a more politicized way. Their article provided some of the backstory on how local authorities found out about Crocker:
According to court documents, the investigation of Demetrius Crocker began in early 2004, around the time he told a man named Lynn Adams that Timothy McVeigh "[did] things right." Adams, who had met the Mississippi-born farmhand through a mutual acquaintance, began to hear from Crocker about his plans for mass murder.

Adams was a former sheriff's deputy and a confidential informant for the Carroll County drug task force. At first, Adams didn't take Crocker seriously, but as their relationship progressed, Adams began believing Crocker was more than just talk.

At that point, the Carroll County Sheriff's Department passed the case on to the FBI. Steve Burroughs, an FBI agent, began working undercover.

But tapes of the conversations between Crocker and Burroughs reveal that Crocker knew what he was doing. He had made a version of Zyklon B, the gas used in the gas chambers in Nazi concentration camps, and he accurately described its manufacture. He had made nitroglycerin. He had the ingredients for a rudimentary bomb in his home ...

The Crocker case was brought in by old-fashioned police work. A confidential informant passed on a tip and a sting was conducted by an FBI agent careful to make sure the plan was real and not a creation of the government.
One of the truths of today's terrorism is that technology is making it easier for small groups and "lone wolf" terrorists to do much more damage than they could in the past. This is true for both Islamist terrorists like al Qaeda as well as others.

Friday, December 15, 2006

"Ready or Not?" Report on Preparedness for Biological Threats

The Trust for America's Health has issued its fourth annual "Ready or Not?" report on the state of preparedness in protecting the public from biological threats. The report's major findings are:

  1. Only 15 states and two cities are rated at the highest preparedness level required to provide emergency vaccines, antidotes, and medical supplies from the Strategic National Stockpile (SNS).
  2. Eleven states and D.C. lack sufficient capabilities to test for biological threats.
  3. Four states lack sufficient laboratory experts trained to test for a suspected outbreak of anthrax or the plague.
  4. Four states do not test for flu on a year-round basis, which is necessary to monitor for a pandemic flu outbreak.
  5. Half of states would run out of hospital beds within two weeks of a moderately severe pandemic flu outbreak.
  6. Flu vaccination rates for seniors decreased in 13 states.
  7. The national median for vaccinating seniors for pneumonia is 65.7 percent, the national goal is to vaccinate 90 percent by 2010.
  8. Twelve states and D.C. are not fully compatible with the Center for Disease Control and Prevention’s (CDC’s) National Electronic Disease Surveillance System (NEDSS) to track disease outbreak information.
  9. Forty states and D.C. have a shortage of registered nurses.
  10. Six states cut their public health budgets between FY 2004-05 and FY 2005-06. As of FY 2005-06, the median state funding for public health is only $31 per person per year.
The report emphasizes that collaboration is needed among public health professionals and other responders. It argues that an effective response will require, among other things:
  • Pre-planned, safety-first rapid emergency response capabilities and precautions:
  • Tested plans and safety precautions to mitigate potential harm to communities, public health professionals, and first responders.
  • Immediate, streamlined communications capabilities: Coordinated, integrated communications among all parts of the public health system, all frontline responders, and with the public. Must include back-up systems in the event of power loss or overloaded wireless channels.
But because the public health system is distributed across all levels of government, some problems with coordination arise. Specifically:
  • Lack of clear roles for the various state, local, and federal agencies.
  • Limited coordination among the levels of government, including determination of how federal assets would be deployed to states and localities, and across jurisdictions, such as sharing assets and resources among states.
  • No minimum standards, guidelines, or recommendations for capacity levels or services required of state and local health departments. This results in major differences in services and competencies across state and local agencies.
The bulk of the report provides scores on preparedness in for each state. It's worth looking up for your state. (Oklahoma scored the highest.) It also makes some recommendations, although these are mostly at the federal level.

Overall, the report provides more weight to the argument that better coordination between public health agencies – at all levels of government – and first responders is a must.

Wednesday, December 13, 2006

National Interoperability Baseline Survey

DHS recently released the results of a baseline survey on interoperability for first responders. They survyed "both fire response/emergency medical services (EMS) and law enforcement agencies in all 50 states and the District of Columbia," with 6,819 agencies responding. This means their findings are at the 99 percent confidence level.

The study assessed "the five critical elements—governance; policies, practices, and procedures; technology; training and exercises; and usage—that determine an organization’s capacity for interoperability." It took three levels of interoperability into account:

These levels include interoperability across disciplines (i.e., between law enforcement and fire response within the same jurisdiction), across jurisdictions (i.e., between agencies of the same discipline across local jurisdictions), and between agencies of the same discipline across state and local government.
Although the stated goal of the survey was to "create a national and statistically valid snapshot of the capacity for and use of interoperability," DHS was careful to point out that it's not possible to describe the nation's interoperability status with a simple, single national "score."
No one-dimensional scale can adequately define the current state of interoperability in the Nation, or the progress left to be made, because the capacity for interoperability is a complex issue that involves technological, political, operational, and human variables.
Here are a few key findings (though not all of them):
  • About two-thirds of agencies report using interoperability to some degree in their operations. According to our frequency of use and familiarity question, which addresses how often and in what situations interoperability are used, about one-third of agencies use interoperability primarily for out-of-the-ordinary events, and another third interoperate both for out-of-theordinary events and in their day-to-day operations.
  • The smallest agencies, as a group, tend to be at earlier stages of development than larger agencies.
  • Fire response/EMS and law enforcement agencies tend to show the same level of development in most areas of the Continuum.
  • Cross-discipline and cross-jurisdiction interoperability tends to be at a more advanced stage than state-local interoperability.
As of now, technological hurdles are not the main obstacle to interoperability:
Perhaps because technological issues have been placed at the forefront of interoperability problems, technology displays the highest level of development of any of the elements in the Continuum.
Of all the variables that determine interoperability, planning and governance is one of the most critical:
Interoperable communications cannot emerge on their own, nor can any single agency implement interoperability, without … collective leadership and support.

Moreover, the Government Accounting Office (GAO) has reported that, “The single greatest barrier to addressing the decades-old problems of interoperable communications has been the lack of effective, collaborative interdisciplinary and intergovernmental planning.”

Strategic plans for interoperability are the exception rather than the norm. Only 20 percent of agencies have strategic plans to ensure interoperability across disciplines, and 19 percent have plans to ensure interoperability across jurisdictions. For state-local interoperability, that proportion falls slightly, to 16 percent.
One of the interesting findings of the study is that, because of the nature of their work and the greater ability and need for cross-jurisdictional cooperation, fire and EMS agencies are more likely to have established decision-making groups and agreements with other agencies:
This question [of establishment of a public safety decision-making group] also showed the most dramatic instance of one discipline completely outdistancing the other in the advanced stage. SMEs reviewing these findings were not surprised to see fire response/EMS more likely to report in the advanced stage in this instance than law enforcement. One of the distinguishing characteristics of the advanced stage is reaching out to groups beyond traditional first responders, and it was agreed the fire response/EMS are often in contact with a wide variety of groups in their response efforts.

[Regarding cross-jurisdiction agreements] law enforcement is organized along political jurisdictions, and much of its operations across jurisdictional lines are codified in local law. Fire response/EMS agencies, on the other hand, are not organized according to political jurisdictions, and their cooperation is consequently not codified in law. They would thus have a greater need to establish agreements for working across political jurisdictions.
Another interesting finding is that collaboration breeds collaboration:
Several [agencies] expected improved interoperability would lead to faster response time—removing intermediary communications and ensuring that all responders could communicate to the incident commander. Various agencies also provided examples of interoperability improving response, from enhancing the safety of ambulance crews in high-crime areas to the prevention of secondary accidents at incidents. Others noted that reduced barriers to interoperability would lead to greater trust and improved working relationships between neighboring agencies—an interesting comment, given that an often-cited barrier to interoperability specifically is lack of working relations. These agencies are suggesting that simply working more regularly together could overcome barriers that tend to inhibit agencies from working together.
The thing that I take from this survey is that collaboration is an absolutely essential precondition to interoperability. And not only does collaboration aid in the development of interoperable systems, but it can also help in other ways, such as improved response time and greater unity of effort, even during the response to everyday incidents.

Note: As others have done before, this report also describes the problems that resulted from a lack of interoperability on 9/11 and in the aftermath of Hurricane Katrina:
[L]ack of interoperability [has] continued to result in the unnecessary loss of lives and property. As the 9/11 Commission Report stated, many of the first responders that responded to the attacks in New York City “lacked access to a [common] radio channel on which the Port Authority police evacuation order was given.” As the catastrophic events of September 11, 2001 showed the entire Nation, direct correlation exists between effective communications interoperability and first responders’ ability to save lives.

In August and September 2005, the ramifications of the lack of communications interoperability were once more brought to national attention in the aftermath of Hurricane Katrina. The massive damage to communications infrastructure alone wreaked havoc on the ability of any single agency to coordinate its own relief efforts in the Gulf Coast area. Establishing simple internal operability compounded problems with achieving interoperability with other agencies. The House of Representatives report on the response to Katrina noted, “There was no voice radio contact with surrounding parishes or state and Federal agencies. Lives were put at risk and it created a direct operational impact on their ability to maintain control of a rapidly deteriorating situation within the city, carry out rescue efforts and control the evacuation of those who had failed to heed the call for evacuation.”

Monday, December 11, 2006

Response Structure for Nuclear Incidents

Catching up a bit here. This one is a couple of months old. The American Nuclear Society published a brief article in September that described the response for a nuclear incident. Not surprisingly, the response would be a complicated process involving many agencies.

Nuclear weapon incidents or accidents will involve a joint Department of Energy (DOE) and Department of Defense (DoD) response. Local responders and state agencies, who always have the primary responsibility for the protection of the public, will also be involved.

If the emergency involves a nuclear weapon, either the DOE or the DoD is the lead agency (whichever organization had custody of the weapon at the time of the incident/accident). If an RDD is the issue, the FBI becomes the lead agency representing the Department of Justice. An accident at a nuclear power plant will put the Nuclear Regulatory Commission (NRC) in the lead role.
The military response, alone, involves a number of elements:
A military response will involve the DoD and may include the Defense Threat Reduction Agency (DTRA), which coordinates DoD responders to a nuclear/radiological incident.

The National Guard Civil Support Teams (CSTs) are available through the states to assess the seriousness of radiological accidents, to predict the consequences, and to assist the Incident Commander in the management of the consequences.

A global radiological/nuclear field response is provided by the Air Force Radiation Assessment Team (AFRAT). … Its mission is to deliver radiological risk assessment to assist in the recovery of the affected area.

Worldwide medical assistance is provided by the U.S. Army through its Radiological Advisory Medical Team (RAMT).

The Medical Radiobiology Advisory Team (MRAT) … provides radiological and medical expertise to military commanders and medical providers.
The federal civilian response is similarly complicated:
The primary civilian government agencies responding to radiological incidents include the National Nuclear Security Administration (NNSA), which is a semiautonomous agency within the DOE, the Environmental Protection Agency (EPA), the Nuclear Regulatory Commission, the Department of Health and Human Services, the Department of Agriculture, and others.

One of the best-known civilian response organizations is the Radiological Assistance Program (RAP), which is administered by the NNSA. … The main mission of RAP is to provide information or deployable assets (DOE measurement equipment and personnel) in order to assess and mitigate a radiological incident.

If radiological materials become airborne, two NNSA response assets can be brought into operation: the National Atmospheric Release Advisory Center (NARAC) … and the NNSA’s Aerial Measuring System (AMS).

Another NNSA radiological response asset is the Radiation Emergency Assistance Center/Training Site (REAC/TS), which provides medical information, medical personnel, and patient care in the event of a radiological accident.

Responses to incidents involving nuclear weapons under DoD or DOE custody can involve the DOE’s Accident Response Group (ARG), whose expertise includes weapons designers, radiation health professionals, and nuclear scientists, so that knowledge of all weapons in the U.S. stockpile is at hand.

The Nuclear Regulatory Commission will respond to terrorist and emergency incidents at the nuclear, industrial, and medical facilities it licenses.
Besides those involved in direct response, other agencies are involved in coordination:
Coordination among federal and state agencies during the emergency phase of a nuclear/radiological incident may be handled by the NNSA’s Consequence Management Planning Team. This is an advance component of the Federal Radiological Monitoring and Assessment Center (FRMAC), [whose mission] is to coordinate federal and state/local radiological monitoring and assessment activities.
The article suggests that state and local first responders can improve their response capacity by developing relationships with federal and state responding agencies, as California did with the FRMAC:
To at least improve the coordination of response between FRMAC and the states, including local governments, a close working relationship must be developed between the two entities. The state of California has been cited as a good model for developing this working relationship. Building this federal/state bridge initially involved federal/state coordination in nuclear power plant emergency response drills. This allowed the state to study FRMAC procedures, and FRMAC team members became informed about California’s response procedures. … Other states are attempting to achieve a similarly firm handshake with FRMAC. It must be noted, however, that the California/FRMAC relationship took years to develop.
Even though the likelihood of a nuclear or radiological disaster is relatively low, compared to other threats, its consequences could be extremely serious. Even in the event of a "dirty bomb" attack that killed or injured relatively few people, the panic caused by a radioactive release could significantly complicate the response. The right time to learn about the responding agencies and how the response might be organized is now, rather than after the fact.

Friday, December 08, 2006

Agroterrorism: Local Law Enforcement, You're in Charge

The Department of Justice (DOJ) just published a really interesting 4-page research brief on agroterrorism. According to the report, one aspect of our preparedness is falling far short:

Many believe that public health officials would lead the response to an agroterrorism attack, but this might not be the case. The laws of most States require that such an event be handled as a crime scene investigation, giving law enforcement primary responsibility. Ill-equipped to handle the magnitude of responsibilities that would follow an act of agroterrorism, local police departments would be pushed to the limit.
For example, how many law enforcement agencies - especially smaller agencies in rural areas - are ready to do this:
Research points to the first priority of local law enforcement after an agroterrorist attack: establishing and enforcing a 6-mile radius quarantine (113 square miles) around the point of origin to control the spread of the virus. The second priority would be to set up statewide roadblocks to enforce stop-movement orders. Such a tremendous effort— requiring that all vehicles coming into or going out of the impacted State be stopped and inspected— would require a coordinated response by local, State, and Federal officials.
In the brief, DOJ points out that, by the USDA's estimate, the economic cost to taxpayers of a major foot-and-mouth outbreak could be $60 billion (and a DHS official recently estimated the cost would be in the hundreds of billions). Given this, the DOJ calls for action:
Because terrorists rely on a lack of preparedness, law enforcement agencies should start now to develop a plan for preventing an agroterrorism attack—and the interruption of basic services, civil and emotional stress, and public health concerns that likely would follow.
DOJ also provides some specific steps local law enforcement can take:
On the local level, law enforcement agencies bear a responsibility for intelligence gathering … Local jurisdictions are also in the best position to conduct vulnerability studies of area farms and feedlots.
And perhaps most importantly at the beginning - DOJ suggests whom to collaborate with:
Partnerships—the best way to prevent an agroterrorism attack and the only way to contain one—must be created among local farmers, truckers, feedlot owners, and other critical members of the food-supply chain. A working relationship between criminal investigators and veterinarians and animal and plant health inspectors must be established.
The brief is sort of a good primer for preparedness: There is a threat. We are not fully ready or organized for it. Dealing with the threat could be a massive undertaking. So to get ready, we need to work together and plan now.

Survey on Emergency Management at the County Level

The National Association of Counties recently released the results of a survey on emergency management. The survey describes the organization and preparedness of county emergency management organizations nationwide. Here are some of the survey's findings:

How is emergency management organized and staffed?

[R]espondents to this survey suggest that emergency management is, for the most part, now a separate unit within a department of public safety (38 percent) or a stand-alone unit of the county government reporting directly to the chief executive or governing body (40 percent), meaning that 78 percent of counties nationally have established emergency management units separate from the police/sheriff and fire departments.

Most top managers have duties beyond coordinating the county’s emergency preparedness and response units … More than three-quarters (77 percent) of top managers report responsibilities beyond emergency management … This leaves only about one-quarter of top administrators who spend all of their time on emergency management and administration.
How prepared are counties?
While most respondents (70 percent or more) believe that the police/sheriff and fire departments are prepared to a great or very great extent, most believe that other organizations are less prepared. Respondents felt that only about 59 percent of health care organizations, 42 percent of other agencies, and 48 percent of schools were prepared to a great extent, and their assessment of the preparedness of other government agencies and of faith-based groups was even lower, at 42 and 14 percent, respectively. A strikingly low 13 percent of respondents believe that the general population is prepared to a great or very great extent.
The survey also asks what the county emergency management units are prepared for. While almost of them have plans in place, one area that gets relatively little attention is evacuation.
[Fewer than 60 percent of counties had evacuation plans.] In light of the complications in evacuating New Orleans residents prior to and after Hurricane Katrina in 2005, counties should begin to develop thorough evacuation plans, including routes, alternative routes and modes of transportation, and notification systems.
Also, counties are particularly unprepared regarding the response for those with special needs.
During hurricanes Katrina and Rita in 2005, one of the most glaring weaknesses was the inability to respond quickly to the needs of persons residing in the hospitals and nursing homes located throughout the region, indigent persons, and those without personal transportation. The data in [this survey] suggest that in a similar disaster, many areas would experience the same problems as those experienced along the Gulf Coast. Only 59 percent of the counties report that they have arrangements in place for sheltering those with special needs, and not even half include plans for managing prison populations and serving the non-English-speaking community. Less than one-quarter of counties nationwide have specific plans for meeting the needs of minorities, indigent persons, and the homeless. Plans for managing sex offenders are in place in only about 5 percent of counties.
The issue of people with special needs was strongly brought to the fore after Katrina, with some good news coverage. First responders may find helpful this set of tips for responding to those with disabilities, created by the Center for Development and Disability at the University of New Mexico.

FBI Arrests Mall-Bombing Suspect

Just a news byte:

An informant's tip led the FBI to arrest a suspect who allegedly intended to set off hand grenades in a Rockford, Illinois shopping mall.

The Chicago Sun-Times reported that he was a Muslim convert who had aspirations of being a jihadist. The informant was a friend who tipped off the FBI.

Update Dec. 11, 2006: As CBS reported, it's clear that they arrested this suspect, Derrick Shareef, well before he could do any serious damage. He was acting alone, with scarce finances. In short, he didn't yet have the means of carrying out an attack, though he apparently had the desire:

As depicted by [U.S. Attorney for Northern Illinois Patrick] Fitzgerald, Shareef was predisposed to violence but devoid of cash; a dangerous man who freely chatted about bombing a county courthouse, a city hall, a federal building, and then the mall.

"He did not have the money to buy the grenades. He was gonna hock and barter two stereo speakers to the undercover to buy the grenades," Fitzgerald said, proof Shareef was not directed or financed from overseas.

So Shareef fits a pattern of indicted "wanna be" terrorists with big ideas but no apparent means or backing from our real enemies.
The FBI has been paying special attention to those inspired by al-Qaeda, like the London subway bombers:
The FBI's Special Agent in Charge of its Chicago field office, Robert Grant, standing next to Fitzgerald on Friday, explained the nation's shift from investigating al-Qaeda to al Qaeda–inspired plotters.

"We've been focused for about two years on those types of domestic cells that could develop or individuals," Grant said.

Wednesday, December 06, 2006

Communication, Communication, Communication

Disaster communication is in the news.

The CDC has released an online guide for disaster communications in the early hours after a major incident involving biological or chemical agents, radiation, or suicide bombings:

The guide provides message templates for local leaders to communicate with the public:

The messages were written to be used by federal public health officials and to be adapted for the use of state and local public health officials during a terrorist attack or suspected attack. Use these messages as follows:

  • To communicate with the public during a terrorist attack or a suspected attack
  • To adapt for a specific event (These messages were written for fictitious situations, so assumptions were made about an event.)
  • To provide information during the first hours of an event
  • To save precious moments during the initial response time and to buy the time necessary for public health leaders to develop more specific messages

My only complaint about the guide is that it isn't organized in a very user-friendly fashion. You have to click around a bit to find what you're looking for.

In other news, Government Technology reported on Washington D.C. mayor Anthony Williams' efforts to increase subscriptions for the city's text-message alert system, which would send them information and updates in the event of an emergency. (San Francisco recently created a similar system.)
In order to make the process easier, individuals can now sign up by simply texting 32362 (D-C-E-M-A) from any cellular device.

"This new rapid enrollment feature means people who want to register for the system don't need access to the Internet or e-mail to sign up for alerts," said Williams. "Signing up for emergency alerts is as easy as using a cell phone -- and it can really pay off when there is any kind of emergency in your neighborhood."

DC Text Alert allows citizens to receive emergency messages about an event on any text-capable device -- cell phone, computer -mail, pagers, and PDAs. ... Currently, 23,000 individuals have registered for the system, which was inaugurated in June 2004.
On another subject, the National Emergency Management Agency (NEMA) released its biennial report (available for purchase only) . In a press release, NEMA summarized some of the survey's main findings:
Unfortunately, these growing [state] responsibilities that are mandated by the federal government are not supported by adequate funding.

There are positive findings as well. An overwhelming majority of states – 46 – are making use of established standards to assess capabilities and address shortfalls in their state emergency management programs. ... Standards would result in a more comprehensive emergency management program at the local level, which would mean greater capability when a disaster occurs.

The Biennial Report shows that the mutual aid system in the U.S. continues to strengthen. The Emergency Management Assistance Compact (EMAC), a national mutual aid agreement that allows support across state lines when a disaster occurs, played a key role in the Hurricanes Katrina and Rita response. By spring 2006, the compact had deployed nearly 66,000 people from 48 states, at a cost of more than $830 million.

Thirty-five states now have established similar structures within their own borders. These intrastate agreements allow jurisdictions to help one another while having provisions in place to address reimbursement, liability and workers compensation issues. Thirty-six states also have a regional mutual aid mechanism in place. This bodes well for faster, stronger and more efficient disaster response and recovery.
Government Computer News reported that the full NEMA survey estimated that the full cost of statewide systems for communication interoperability will be about $7 billion:

The National Governor's Association also tackled the issue of interoperability, in its recent issue brief: "Strategies for States to Achieve Public Safety Wireless Interoperability." The short report is worth reading, if only for the best practices that it found among the states for promoting interoperable communications (an example of the federal system at work). But generally, the NGA found that there is a lot of important work to do:
The lack of interoperable communications continues to be a serious, pressing public safety problem that severely undermines the ability of first responders to operate effectively during an mergency situation.

Five key issues underlie the current status of interoperability among public safety agencies in this country:
  • incompatible and aging communications equipment;
  • limited and fragmented funding;
  • limited and fragmented planning;
  • a lack of coordination and cooperation; and
  • inadequate and fragmented radio spectrum.
But here's one good thing: The NGA emphasizes that local agencies should be closely involved in any state effort to promote interoperability:
Providing local representation on the governance body and in interoperability planning is a critical. The state governance board that oversees the development of public safety wireless communications should include local public safety agency requirements for emergency communications. Local officials should be included in planning and decision making early.
Generally, anything that improves communication, either among first responders or between first responders and the public, can only be a good thing. Communication problems were significant in the aftermath of Katrina and 9/11. It's a problem that has lingered too long.