Physical hardware protects a facility. OPSEC protects the information, patterns, and routines an adversary uses to defeat it: schedules, vendor access, procurement details, and the small disclosures that add up to a plan.
OPSEC means thinking like the adversary gathering intelligence on you, a skill built through real threat-intelligence and investigative work, not a compliance checklist. Dr. Virga's background runs through federal threat-intelligence coordination and insider-risk investigations, not a generic security-audit template.
OPSEC isn't a policy binder; it's a repeatable process for finding what an adversary could actually use against you, and closing it before they do.
What, if learned by an adversary, would actually cause harm: schedules, access details, vendor relationships, capabilities.
Who is likely to seek that information, and how, informed by real threat intelligence, not a generic template.
Where critical information is actually exposed: public records, social media, vendor communications, routine movements.
Which vulnerabilities matter most, weighed against likelihood and consequence, so effort goes where it counts.
Practical changes to process and habit, not just policy on paper, the step where most programs stop short.
Monitoring, reporting structures, and training that catch integrity issues before they become incidents, see Personnel & Insider Risk.
An OPSEC assessment surfaces the exposures a document review never catches, and gives you countermeasures you can actually implement.