When Small Talk Becomes a Security Risk

A friendly conversation at a conference. A new connection on LinkedIn. A coffee meeting with someone who seems unusually interested in your work.

Human intelligence (HUMINT) rarely begins with a secret meeting or stolen documents. More often, it starts with something far more ordinary: one person asking questions and another happily answering them.

In this episode of Spionpodden, Anders Spalding, Head of National Security (Protective Security) at HiQ and former intelligence officer at the Swedish Military Intelligence and Security Service (MUST), explores how HUMINT works in practice. He explains how people are mapped, how trust is established, and why even seemingly harmless information can become valuable when viewed as part of a bigger picture.

Modern espionage rarely looks like the movies

When we hear the word espionage, it’s easy to picture classified documents, encrypted messages and secret meetings in dark alleyways. Reality is usually far less dramatic.

Information is often gathered through ordinary conversations. At conferences, industry events, during business travel and across digital platforms, professionals from both the public and private sectors meet, exchange experiences and build relationships. We talk about our roles, projects, colleagues and challenges. It’s a natural part of networking and professional collaboration.

Most of these conversations are, of course, completely harmless. But the same openness can also be exploited by someone whose intentions are very different.

The objective isn’t always to uncover a single secret. Often, it’s the collection of small details that reveals how an organisation operates, who makes decisions, where challenges exist and where vulnerabilities may lie.

How ordinary questions can reveal more than you think

Elicitation is a technique used to obtain information without asking direct or obviously sensitive questions. The conversation feels natural and balanced, while one participant has a clear intelligence objective.

This might involve confirming something that appears to be common knowledge, deliberately making an incorrect statement or showing genuine interest in an area where the other person has specialist expertise. As humans, we’re naturally inclined to help, correct misunderstandings and demonstrate what we know.

As a result, a question doesn’t have to sound suspicious to produce a valuable answer.

The conversation might revolve around the systems an organisation uses, the progress of a project, why a delivery has been delayed or who is responsible for a particular decision. Each piece of information may seem insignificant on its own, but when combined with other data, it can provide a surprisingly detailed picture of an organisation.

Trust is built over time

Human intelligence gathering is rarely about a single conversation. Relationships are often developed gradually.

It may begin with a LinkedIn connection request or a brief conversation at a conference. More interactions follow, common interests emerge and the relationship starts to feel increasingly familiar and natural.

As trust grows, so does our willingness to share information. Questions become more specific over time, yet each individual step still feels entirely reasonable.

That’s precisely what makes this type of intelligence gathering so effective. We tend to evaluate each question individually, while the person collecting information is focused on the bigger picture.

“I don’t work with classified information”

It’s easy to assume that protective security only concerns people with access to classified information. In reality, people who never handle classified material may still possess information that is valuable to someone else.

Every organisation consists of people, technology, suppliers, processes and dependencies. Understanding how these elements fit together can reveal weaknesses and potential points of entry.

Information that may be valuable includes:

  • Individuals with key responsibilities or privileged access
  • Suppliers, systems and technical platforms
  • Internal challenges, delays or organisational changes
  • Upcoming projects, procurements and recruitment plans
  • How decisions are made and who influences them
  • Ways of working, travel patterns and operational routines

None of these details necessarily needs to be confidential. However, when combined, they can support intelligence gathering, social engineering or preparations for a cyber attack.

LinkedIn is also a map of your organisation

Digital platforms have made it easier than ever to map both organisations and the people who work within them.

On LinkedIn, we proudly share our roles, projects and career moves. Companies publish news about partnerships, technology investments, recruitment and business initiatives. This information serves an entirely legitimate purpose—but it can also be used to create highly credible approaches.

Someone who already knows your role, your colleagues and your organisation’s current priorities doesn’t have to start the conversation from scratch. They immediately appear informed, relevant and trustworthy.

The answer isn’t to stop using LinkedIn or avoid building new professional relationships. Instead, we need to recognise that the information we publish influences how easily others can build an accurate picture of us and our organisations.

Awareness without paranoia

Good security shouldn’t make people afraid to talk to one another. It should help them recognise when something feels unusual and know how to respond.

Employees don’t need to determine whether someone is attempting to recruit them or conduct intelligence gathering. They simply need to recognise when someone repeatedly shows an unusual interest in people, systems, projects or internal matters.

Questions worth asking include:

  • Why does this person need this information?
  • Are these questions reasonable given their role and the context?
  • Are they trying to get me to confirm or correct information?
  • Has the relationship gradually become more personal, or have the questions become increasingly detailed?
  • Do I know who to contact if something doesn’t feel right?

The goal isn’t suspicion. The goal is to create a culture where people naturally pause, reflect and report anything that feels out of the ordinary.

How organisations can strengthen their resilience

Technical controls are essential, but they don’t solve the entire problem. When people become the pathway to information, security must also focus on people.

Organisations can strengthen their resilience by:

Making training practical

General advice such as “be careful” is difficult to apply in real life. Use examples from conferences, recruitment processes, social media, customer meetings and other situations employees regularly encounter.

Explaining the value of small pieces of information

Employees need to understand that security risks aren’t limited to classified documents. Even seemingly harmless information can become sensitive when combined with other data.

Creating simple reporting channels

Employees should know exactly who to contact if something feels unusual. Reporting should be straightforward, and people shouldn’t feel they need to prove that a genuine threat exists before speaking up.

Involving the entire organisation

Security awareness shouldn’t stop with leadership or employees in security-cleared roles. Receptionists, HR professionals, procurement teams, communications, sales, IT and external consultants may all encounter people seeking information.

Treating awareness as an ongoing effort

A single annual training session is rarely enough. Security awareness needs to remain part of everyday work through continuous dialogue, practical exercises and well-established routines.

Security starts with understanding how threats emerge

Today’s organisations operate in a world where information is readily available and professional networks are larger than ever. That creates new opportunities for collaboration—but also for intelligence gathering.

Meeting regulatory requirements and implementing technical controls are important, but they are not enough. Organisations also need to understand how threats develop in practice and equip employees with the knowledge to recognise and respond when something feels wrong.

Espionage doesn’t always begin with a dramatic event.

Sometimes, it begins with an ordinary conversation.

And someone asking just a few of the right questions.

Listen to the podcast

In the Spionpodden episode When Small Talk Becomes Espionage – The Craft Behind HUMINT, Anders Spalding, Head of National Security (Protective Security) at HiQ, explores elicitation, recruitment and how everyday relationships can be used to gather intelligence.

Listen to the episode to gain deeper insight into the human side of intelligence gathering—and why awareness is one of the most important components of organisational resilience.

Get in touch to discuss how your organisation can strengthen its protective security.

Read more articles here