Physical hardware protects a facility. OPSEC protects the information, patterns, and routines an adversary uses to defeat it — schedules, vendor access, procurement details, and the small disclosures that add up to a plan.
OPSEC means thinking like the adversary gathering intelligence on you — a skill built through real threat-intelligence and investigative work, not a compliance checklist. Dr. Virga's background runs through federal threat-intelligence coordination and insider-risk investigations, not a generic security-audit template.
OPSEC isn't a policy binder — it's a repeatable process for finding what an adversary could actually use against you, and closing it before they do.
What, if learned by an adversary, would actually cause harm — schedules, access details, vendor relationships, capabilities.
Who is likely to seek that information, and how — informed by real threat intelligence, not a generic template.
Where critical information is actually exposed: public records, social media, vendor communications, routine movements.
Which vulnerabilities matter most, weighed against likelihood and consequence — so effort goes where it counts.
Practical changes to process and habit, not just policy on paper — the step where most programs stop short.
Monitoring, reporting structures, and training that catch integrity issues before they become incidents — see Personnel & Insider Risk.
An OPSEC assessment surfaces the exposures a document review never catches — and gives you countermeasures you can actually implement.