On August 31, at the Flight 93 memorial in Shanksville, the House Intelligence Committee released its bipartisan review of the 9/11 Commission recommendations, twenty-five years on. Two days later, on September 2, the same committee held a rare public hearing — “Persistent Competition and Legacy Architectures.” Read them together and they tell one story: the reforms that revolutionized counterterrorism after 2001 never reached counterintelligence, and the bill is coming due.
The review says it plainly. After 9/11 we broke the stovepipes for counterterrorism — stood up the National Counterterrorism Center, forced the interagency to share, and learned to connect the dots. But, in the committee’s own words, “the counterterrorism lessons learned have not translated to other intelligence areas, such as counterintelligence.” CI never got that treatment. A quarter century later, we are still running the mission the way we ran it before the towers fell.
At the September 2 hearing, Frank Cilluffo gave the sharpest framing of the problem I have heard: “Our adversaries … run campaigns. We open cases.” We are very good at investigating identifiable incidents — open a case, determine whether a law was broken, identify the actors, bring an enforcement action. Those capabilities matter. But “a strategic competitor is not measuring success one prosecution at a time.” They work across years, industries, and institutions, accept failure in any single effort, and simply move to the next researcher, the next vendor, the next investment vehicle.
The Investigation Silo Is the Connect-the-Dots Problem
I have run these programs, and here is the uncomfortable truth: our greatest strength — disciplined, rigorous investigations — is also where we get stuck. An investigation is bounded by design. It has a case file, a subject, a predicate. That is exactly what makes it defensible in court, and exactly what makes it blind to the campaign around it. “A series of seemingly disconnected events can take on a very different meaning when viewed together,” Cilluffo told the committee. Those events are usually already in our holdings. They are just sitting in different systems, under different owners, for perfectly legitimate reasons — and the adversary “does not organize its campaign around our organizational charts.”
Tip and Cue Between Collections and Investigations
This is where I want to get specific, because “connect the dots” has become a slogan that means nothing without the plumbing underneath it. The connective tissue we built into AxIS is cross-functional tip and cue — the ability for one part of the mission to automatically flag and hand off to another. Our collections module does not just log human-source reporting; it correlates across mission types — cyber, online-persona, social-media, and human-source operations — and links that reporting to the investigations, foreign contacts, and entity records already in the platform.
Walk it through concretely. A foreign intelligence service identifies, cultivates, and tasks a source. Somewhere along that arc the activity becomes observable — an anomalous contact, a pattern of approaches, a cyber indicator. In a siloed program those signals die in the inbox of whoever caught them. In AxIS, a collections indicator can cue an investigation, and an investigative finding can cue new collection. Collections and investigations become a feedback loop instead of a dead end, and cross-domain anomaly detection surfaces the pattern that no single analyst, looking at a single case, would ever see.
Getting Left of Boom
Everything above is in service of one thing: getting left of boom. Cilluffo again — this is “a warning problem as much as an enforcement problem,” and success “cannot simply mean that we investigated yesterday’s compromise. It should increasingly mean that we prevented tomorrow’s.” That is the whole game. When you aggregate and exploit collections and investigations together, you stop reconstructing what already happened and start recognizing what is happening — the indicators that drive an adversary’s next move, early enough to act on them. It is also the on-ramp to denial and deception: once you can see a foreign campaign forming, you can shape it, deny access, and impose cost, instead of documenting the loss after the fact.
I will be honest about the limits, because a vendor who promises certainty is selling you something. No platform makes counterintelligence foolproof. This is a reciprocal, adaptive contest — a cat-and-mouse cycle in which both sides collect, investigate, and learn. What AxIS changes is the odds: better visibility on both sides of boom, so you are proactive where you can be and faster where you cannot.
Measure the Mission, Not the Org Chart
The recommendation from the 9/11 review that belongs on every program manager’s wall is this: “Measure Success by Mission Outcomes, Not Agency Ownership.” Cilluffo’s version is the operational one — stop measuring the mission one prosecution at a time, and start asking whether you are reducing adversary access, raising their cost, and closing the same seams they keep exploiting. You cannot measure any of that on infrastructure that only tracks individual cases. It requires a single operational picture across cases, leads, assessments, and collections — what we call the Clear-Box model: a program that can see the state of its own mission at any moment, rather than reconstruct it after a damage assessment or a subpoena.
Twenty-five years ago, “failure of imagination” and “connect the dots” entered the language because the pieces existed and no one put them together. The committee’s warning this month is that the counterintelligence equivalent may be forming right now, in the gaps between our cases. The programs that answer it will not be the ones that investigate faster. They will be the ones that finally build the connective tissue to see the whole campaign — and get there before boom.
See this capability in action.
Book a briefing with the AxIS team.