Browse Definitions :
Definition

weaponized information

Weaponized information is a message or content piece that is designed to affect the recipient's perception about something or someone in a way that is not warranted. The term implies a target and the intention to cause harm.  

The goal of weaponized information is bringing about a change in beliefs and attitudes and, as a result, promote behavior that serves the attacker's purpose. Attacks involving weaponized information are sometimes referred to as cognitive hacking.  

Weaponized information often consists of intentional falsehoods, known as disinformation. It can also be true but taken out of context, like a comment carefully selected from a longer statement so that it does not reflect what the speaker said. It may be a mixture of truth and lies, so that the known facts lend credence to the untruths. In other cases, the information may be true but its significance overblown or the timing of release calculated to cause the most harm possible. 

Propaganda is an example of weaponized information: misleading or biased information of a political nature that is usually spread by governments. In contrast, weaponized information is also used in the marketplace to gain a competitive advantage. It might be used to tarnish a competitor's reputation, for example, or spread fear, uncertainty and doubt (FUD) about a product or technology. 

Weaponized information is one form of social engineering. The presentation of the information may be skillfully crafted to exploit common cognitive biases and errors. People can protect themselves from being affected by weaponized information by strengthening their capacity for critical thinking.  

In the enterprise, weaponized data may enter through automated channels and can impact security without being seen by a human. To protect organizations from malicious information, security experts are exploring the potential of cognitive security technologies to automatically detect and deal with weaponized information. 

This was last updated in August 2017

Continue Reading About weaponized information

SearchCompliance
  • OPSEC (operations security)

    OPSEC (operations security) is a security and risk management process and strategy that classifies information, then determines ...

  • smart contract

    A smart contract is a decentralized application that executes business logic in response to events.

  • compliance risk

    Compliance risk is an organization's potential exposure to legal penalties, financial forfeiture and material loss, resulting ...

SearchSecurity
  • COBIT

    COBIT is an IT governance framework for businesses wanting to implement, monitor and improve IT management best practices.

  • email spam

    Email spam, also known as junk email, refers to unsolicited email messages, usually sent in bulk to a large list of recipients.

  • security policy

    A security policy is a document that states in writing how a company plans to protect its physical and information technology (IT...

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • change control

    Change control is a systematic approach to managing all changes made to a product or system.

  • disaster recovery (DR)

    Disaster recovery (DR) is an organization's ability to respond to and recover from an event that affects business operations.

SearchStorage
  • JBOD (just a bunch of disks)

    JBOD, which stands for 'just a bunch of disks,' is a type of multilevel configuration for disks.

  • bare-metal restore

    A bare-metal restore (also referred to as bare-metal recovery or bare-metal backup) is a data recovery and restoration process ...

  • mSATA SSD (mSATA solid-state drive)

    An mSATA SSD is a solid-state drive (SSD) that conforms to the mSATA interface specification developed by the Serial ATA (SATA) ...

Close