
Identifying a Genuine Threat During a Healthcare Firm's Customer Backlash Crisis: Protective Intelligence Case Study
See how Insite identified and escalated a credible threat within one day of launching a protective intelligence program for a healthcare organization facing violent customer backlash.
Protective Intelligence Identifies a Credible Threat Within One Day
Industry:
Healthcare
Primary Service:
Protective Intelligence
A healthcare organization contacted Insite after an influx of violent sentiment was received following a policy change. One day into the program, our team discovered a legitimate threat near their headquarters location.
The Challenge
A healthcare organization began receiving hostile calls and emails from customers angry about a corporate policy change. The rhetoric escalated from general frustration to direct threats aimed at staff, many of which warned of violent action.
Leadership contacted Insite to establish a protective intelligence program around key executives, evaluate any imminent threats, and analyze brand sentiment to better understand the organization’s risk profile.
The program needed to address:
The ability to parse the actionable, legitimate threats amongst the hundreds of angry calls
Clear risk profiles for executives, including exposure of personal information that could be leveraged by bad actors
Employee anxiety around how to handle hostile calls
Insite's Protective Intelligence team launched a focused 30-day threat monitoring engagement to identify and assess Persons of Interest (POIs) from the client's inbound call data, in addition to general online chatter. After a single day into the program, Insite identified an individual who had posted online threatening to “Luigi Mangione” a key executive should he not receive coverage.
Monitoring
Reviewed client call data to identify Persons of Interest warranting closer examination
Tracked each POI's online activity for posts referencing the client or its executives
Maintained real-time alert protocols for any POI requiring immediate escalation
Delivered a comprehensive report with contextual analysis of each POI's broader online behavior
Escalation
Flagged one individual for consistently hostile or violent sentiment directed toward a specific executive
Confirmed the individual's residence was within driving distance of the client's headquarters
Extended monitoring another 30 days and added physical surveillance through Insite's investigations and protection team
Discovered several key executives had exposed personal identifiable information (PII) including home addresses, emails, and phone numbers
Response
Immediate escalation to stakeholders of urgent POIs/ threats
Trained frontline staff on de-escalating calls and provided specific guidance on how to manage/escalate calls from identified POIs
Advised the client's communications team on responding to public hostility on social media platforms
Maintained ongoing monthly reports that defined risk levels and remediation guidance around relevant threats appearing on the surface, deep, and dark web
Insite’s Personal Information Removal (PIR) team managed the end-to-end process of taking down each executive’s leaked personal information
The Insite Approach
The Results
The organization was able to proactively manage a credible threat before an incident could occur
Leadership received monthly detailed analysis of the firm’s risk exposure, including threats directed towards covered executives
Insite’s intelligence team provided constant monitoring of exposed personal information and instances of fraudulent profiles impersonating the organization’s staff
Frontline staff felt safer and better prepared handling hostile calls
An ounce of prevention is worth a pound of cure. By engaging Insite's team to create a bespoke program that included Protective Intelligence and Investigations, the healthcare organization was able to identify legitimate threats before they turned into physical incidents.
More importantly than saving the firm the costs of responding to the incident, it also strengthened the protection of their employees and leadership teams who may have been targeted. Without a proactive approach to security, organizations are only able to react to an incident once it occurs.
