# Foreign-Amplified Domestic Legitimacy Fracture

## Executive assessment

**Scope.** This is a strategic-warning and continuity model for the U.S. defense industrial base, not an assessment that the United States is presently experiencing the scenario described. It assumes a **genuine domestic constitutional shock**—for example, disputed succession, conflicting claims of executive authority, federal-state confrontation, or mass mobilization—already exists. Foreign actors exploit that uncertainty; they do not create the underlying constitutional dispute.

**Bottom line.** The most dangerous foreign contribution is unlikely to be a single persuasive deepfake or one decisive cyberattack. It is a **recursive legitimacy-fracture cycle** in which real domestic ambiguity and authentic institutional disagreement make forged evidence more believable; foreign amplification makes official clarification slower and more contested; cyber disruption reduces access to authoritative information; domestic actors unknowingly or deliberately repeat foreign-originated claims; and subsequent attribution itself becomes partisan evidence. Russia has the clearest publicly documented record and strategic motive for exploiting such a fracture. Iran has demonstrated an ability to combine cyber collection, hack-and-leak activity, personas, and influence operations. The PRC has formidable cyber and influence capabilities but has generally been assessed as more cautious than Russia or Iran about high-risk political influence; recent U.S. intelligence nevertheless reports increased PRC covert influence and AI-enabled disinformation activity. citeturn23view0turn16search0turn13view0turn13view1

The core pathway is:

**real constitutional event → genuine uncertainty → foreign narrative selection and fabrication → domestic repetition → contradictory official communications → verification bottlenecks or outages → mutual allegations that authentic evidence is fabricated → foreign re-amplification of U.S. voices as “independent confirmation” → increasingly partisan attribution → prolonged uncertainty.**

That pathway is consistent with already observed pieces of the problem. The U.S. Intelligence Community assessed in 2024 that Russian influence actors fabricated videos purporting to show illegal voting and bribery, and assessed that Moscow sought to undermine confidence and divide Americans. ODNI separately assessed that Russian influence actors were adapting to better conceal their role and could exploit generative AI. DOJ charged Iranian IRGC-linked actors in a hack-and-leak operation intended to influence the 2024 presidential election, while Treasury subsequently sanctioned Iranian and Russian entities it said sought to stoke U.S. sociopolitical tensions. citeturn14view3turn23view0turn16search0turn16search1

**The principal strategic danger is therefore epistemic rather than purely persuasive.** A foreign campaign need not make most Americans believe a particular claimant. It can succeed tactically if it makes a sufficiently large population unsure which communications, videos, court orders, agency websites, emergency alerts, financial notices, or cyber-attribution statements are authentic. In a severe crisis, “nothing can be trusted” can be more destabilizing than “believe our preferred story.” This is an analytic judgment based on the documented emphasis of foreign actors on division, concealment, fabricated media, and institutional distrust. citeturn23view0turn14view3turn16search2

For the DIB, however, **political uncertainty does not automatically imply operational-authority uncertainty**. Federal acquisition rules provide an important institutional firewall: contracting officers possess authority to enter into, administer, or terminate federal contracts within their authority, and only authorized contracting officers may execute contract modifications on the government's behalf. A dramatic speech, social-media post, televised claim, program-office rumor, or purported political instruction therefore is not by itself a valid contract modification. citeturn17search0turn18search2

The same institutional inertia is stronger still at high-consequence facilities. Current NRC material-control-and-accounting rules require covered licensees to maintain records of receipts, inventory—including location and identity—transfers and disposition of special nuclear material; covered licensees must maintain written MC&A procedures, and §74.31 requires capabilities including physical inventories and current knowledge of items. Current Federal Select Agent Program regulations require written security and incident-response plans, inventory and access records, information-security controls, and contingency measures for failures and emergencies. A purported political order does not erase those standing obligations. citeturn8view4turn8view5turn8view1turn8view2turn8view3

**Key confidence judgments**

| Judgment | Confidence | Basis |
|---|---|---|
| Major foreign adversaries would attempt to exploit a genuine, severe U.S. legitimacy crisis. | **High** | Russia's documented goal of sowing discord and hiding sponsorship, documented Iranian election influence activity, increased PRC covert influence capability, and growing adversarial cooperation all support the judgment. citeturn23view0turn16search0turn13view1turn13view3 |
| Russia would probably be the most aggressive major-state information exploiter. | **High** | ODNI calls Russia a serious foreign-influence threat and specifically identifies division of Western alliances and U.S. domestic discord as objectives. citeturn23view0 |
| Iran could integrate cyber collection or leakage with influence activity during such a crisis. | **High** | DOJ's 2024 hack-and-leak case and ODNI's assessment of Iran's growing willingness to conduct aggressive cyber operations provide direct precedent for the capability combination. citeturn16search0turn13view2 |
| The PRC would possess substantial capability but might employ it more selectively than Russia. | **Moderate-high** | ODNI characterizes China as highly capable but comparatively cautious while also reporting increased covert influence and AI-enabled disinformation activity. citeturn13view0turn13view1 |
| Temporary communications or authentication failures could create more DIB risk than the propaganda itself. | **High** | Federal cybersecurity guidance explicitly treats alternate communications as a continuity requirement; facility regulations depend on persistent authorization, accountability, records, and incident response. citeturn21search1turn8view4turn8view2 |
| Foreign diplomatic “recognition” of a U.S. claimant could intensify narratives but would not itself determine U.S. constitutional succession. | **High** on legal irrelevance; **moderate** on political effect | Presidential succession is governed domestically by the Constitution and statute, including the Twenty-Fifth Amendment and 3 U.S.C. §19. The political effect of foreign recognition would be contextual. citeturn17search2turn18search6 |
| Exposure of foreign sponsorship can undermine an influence narrative, but will not reliably eliminate it. | **Moderate** | Russian influence actors' efforts to conceal sponsorship and U.S. enforcement actions against covert intermediaries imply sponsorship can be reputationally damaging, while domestically adopted claims can persist independently of their original source. citeturn23view0turn16search1 |
| Robustly exercised authorization, communications, accounting, and safe-state procedures can substantially contain facility consequences even while national political uncertainty remains unresolved. | **High** | The regulatory and acquisition regimes deliberately bind operations to persistent procedures, accountable officials, records, access controls, and incident-response mechanisms rather than media narratives. citeturn17search0turn8view4turn8view1turn8view2 |

## Foreign actors, objectives, and domestic amplification pathways

### Foreign actor/objective matrix

| Foreign actor or ecosystem | Likely objective in a U.S. legitimacy fracture | Plausible exploitation instruments | Likely approach to escalation | DIB significance | Assessment |
|---|---|---|---|---|---|
| **Russia** | Extend uncertainty; make constitutional institutions appear arbitrary or fraudulent; intensify antagonism among U.S. factions; weaken allied confidence and U.S. international standing. | Overt state media; fabricated video/audio; AI-generated personas; covert financing or content placement; proxy and cutout accounts; selective dissemination of stolen information; diplomatic rhetoric affirming whichever interpretation maximizes conflict. | Aggressive and opportunistic, with emphasis on hiding Russian authorship while making messages appear domestic. ODNI says Russian influence actors have adapted to conceal their hand and assessed Moscow's influence efforts aim at domestic discord and alliance division. citeturn23view0 | **Very high:** DIB workforces and communities can become targets for rumors about lawful authority, contract status, mobilization, sanctions, payroll, or facility operations. | **High confidence** Russia would exploit the crisis; **moderate confidence** regarding the exact mix of instruments. |
| **Iran** | Retaliate against or constrain U.S. policy; intensify political antagonism; discredit specific officials or institutions; obtain intelligence on crisis decision-making. | Hack-and-leak activity; targeted cyber collection; personas and covert content; manipulated documents; narratives around violence, retaliation, foreign policy, or government illegitimacy; opportunistic disruptive cyber activity. DOJ charged three IRGC-linked actors in a 2024 hack-and-leak effort, and Treasury later sanctioned an Iranian entity over election-interference activity. citeturn16search0turn16search1 | More selective than Russia but potentially willing to couple influence with cyber activity where Tehran perceives strategic or retaliatory benefit. ODNI has assessed growing Iranian cyber expertise and willingness to conduct aggressive operations. citeturn13view2 | **High** where contractors support operations involving Iran or where senior personnel, communications, suppliers, or identity systems are intelligence targets. | **High confidence** in capability; **moderate-high** that a major crisis would trigger exploitation. |
| **People's Republic of China** | Shape long-term perceptions of U.S. governance failure; weaken alliance confidence; protect PRC interests; collect intelligence on decision processes and critical infrastructure; selectively exacerbate issues favorable to Beijing. | State and proxy narratives; covert influence; AI-generated personas/media; cyber espionage and access; diplomatic messaging contrasting U.S. instability with PRC governance. ODNI reported increased PRC covert influence and examples involving AI-generated news anchors and fake accounts discussing divisive U.S. social issues. citeturn13view1 | Likely more controlled and risk-sensitive than Russia; direct intervention in a succession contest would carry reputational and counterintelligence costs. ODNI characterizes Beijing as highly capable but comparatively cautious. citeturn13view0 | **Very high for intelligence collection and infrastructure risk; moderate-high for overt political manipulation.** | **Moderate-high confidence** in exploitation; **moderate** on willingness to openly back a claimant. |
| **DPRK and other opportunistic state actors** | Harvest intelligence, obtain economic benefit, create distraction, or attach their narratives to a wider anti-U.S. information environment. | Cyber espionage, criminal activity, fabricated claims, impersonation, opportunistic amplification. | More opportunistic than strategically decisive in shaping a broad U.S. legitimacy narrative. | **Moderate**, especially where distraction reduces vigilance against ordinary espionage or fraud. | **Low-moderate confidence** on political influence significance; higher confidence that opportunistic intelligence collection would continue during distraction. |
| **State-directed cutouts, nominally independent media, front organizations and unwitting domestic relays** | Obscure state sponsorship and convert foreign claims into apparently indigenous discourse. | Financial support, content placement, laundering through domestic personalities, cloned outlets, fake experts, selectively leaked material, coordinated account networks. DOJ's 2024 RT-related case and Treasury's enforcement actions illustrate the value foreign states place on concealed intermediaries. citeturn16search1turn23view0 | Designed for plausible deniability: the most valuable content is content Americans subsequently repeat without reference to the foreign origin. | **High**, because employees and suppliers may encounter the narrative through trusted domestic relationships rather than obvious foreign channels. | **High confidence** this would be a major mechanism. |

ODNI also judges that cooperation among China, Russia, Iran and North Korea has grown, although it remains uneven and largely bilateral and is motivated in part by a shared interest in challenging U.S. power. That matters because a legitimacy crisis could produce **parallel, mutually reinforcing campaigns without requiring a centrally coordinated anti-U.S. operation**. One actor might emphasize fabricated political media, another cyber espionage, another diplomatic messaging, and another criminal or financial exploitation. citeturn13view3

### The recursive domestic-amplification mechanism

The highest-impact pathway is **foreign-to-domestic-to-foreign recirculation**, not direct foreign persuasion:

> **Authentic event** → real ambiguity creates demand for immediate explanation → **foreign actor seeds an interpretation or counterfeit artifact** → domestic activists, influencers, commentators or officials repeat it → mainstream reporting covers the domestic controversy → the foreign source cites the American coverage as evidence → a second wave of domestic accounts cites the foreign reporting or the enlarged controversy → official correction arrives → one faction treats the correction as authentic and another treats it as evidence of institutional capture.

Documented covert Russian activity demonstrates why the domestic relay is valuable: concealment separates the message from a distrusted foreign sponsor. Likewise, the 2024 fabricated-video episode shows how false audiovisual evidence can attach itself to a genuine political process and force authentic authorities to respond. citeturn23view0turn14view3

Several pathways deserve distinct warning treatment.

**Fabricated or manipulated authority media.** A plausible video, audio clip, scanned memorandum, courtroom document, regulator notice, or agency screenshot appears to show an official issuing a consequential order. The content is most dangerous when it contains mostly authentic details—correct logos, real names, a genuine event, previously public terminology—with one false instruction. The 2024 IC attribution of manufactured Russian videos establishes a precedent for fabricated audiovisual political content, although the regulator/order variants here are scenario extrapolations rather than claims that those exact techniques have already been used. citeturn14view3

**Covert amplification.** Instead of originating a sensational claim from an obvious foreign account, the adversary quietly places, funds, boosts or supplies content to domestic channels. The political value rises as the provenance disappears. U.S. enforcement actions against Russian and Iranian influence entities show that hidden sponsorship and apparently independent intermediaries are established concerns. citeturn16search1turn23view0

**Hack-and-leak recursion.** Genuine stolen documents are mixed with selective framing, omitted context, or potentially fabricated additions. Even authentic documents then become contestable: supporters say “the leak proves it,” opponents say “the files were manipulated,” and a cyber incident affecting the victim's systems makes independent validation slower. DOJ's Iranian case demonstrates the hack-and-leak component of this model. citeturn16search0

**Financial disinformation.** During a constitutional crisis, false claims about frozen federal payments, invalid appropriations, contractor-payment suspensions, sanctions, bank closures, payroll interruptions, Treasury orders, or procurement termination could induce precautionary behavior even without compromising a financial system. This is a scenario judgment rather than a claim of a specific observed state operation. Its principal DIB effect would be supplier caution, liquidity hoarding, delayed deliveries, or employees believing that continued work is unauthorized.

**False emergency communications.** A screenshot or imitation of a Wireless Emergency Alert, Emergency Alert System message, state emergency notice, or FEMA communication could be circulated as proof that a particular government has ordered evacuations, curfews, closures or other action. FEMA's IPAWS architecture uses authorized Alerting Authorities and governance requirements for alerting organizations; consequently, an alert-like social-media image should not be treated as a substitute for a facility's authenticated operational communications. citeturn19search11turn19search35

**Impersonation of authorities.** Crisis-themed messages may purport to originate with a contracting officer, regulator, emergency manager, inspector, military customer, law-enforcement official, or corporate executive. Their objective need not be sophisticated cyber compromise; inducing an employee to bypass the normal authority-validation chain may be sufficient. Federal acquisition rules make the distinction particularly important because authority to modify contracts is constrained to duly authorized contracting officers. citeturn17search0turn18search2

**Foreign diplomatic signaling.** An adversary could publicly treat one disputed claimant as the “real” government, alter embassy interactions, invite one claimant's representatives, or use state media to announce supposed international recognition. Such actions could create powerful visual propaganda and diplomatic inconvenience, but they do not themselves settle domestic U.S. succession, which remains governed by constitutional and statutory rules. citeturn17search2turn18search6

## Scenario tree, warning indicators, and attribution confidence

### Scenario tree from crisis onset through six months

The scenario below deliberately separates **political outcomes** from **DIB safety outcomes**. A contractor's success criterion is not which claimant prevails; it is whether the organization preserves lawful authorization, safety, security, accountability, cyber integrity, records and continuity while domestic institutions resolve the political question.

| Horizon | Central pathway | Escalatory branch | Stabilizing branch | DIB consequence |
|---|---|---|---|---|
| **First seventy-two hours** | A genuine succession or authority dispute produces inconsistent statements from political principals, agencies, states and media. Foreign operators rapidly amplify the sharpest interpretations and introduce counterfeit audiovisual or documentary “evidence.” | A regional communications outage or unrelated cyber incident coincides with fake orders. Each camp concludes the other's authentic communications infrastructure has been compromised. Foreign media cite domestic accusations as corroboration. Viral claims say contracts, emergency powers, security authorities or regulator instructions have changed. | Courts, Congress, states, agency general counsels and established officials communicate through recognizable processes; falsified artifacts are quickly identified; contractors default to standing authority matrices and do not operationalize social-media claims. | **Highest acute risk:** authentication latency, workforce rumor, unauthorized changes, fraudulent payment instructions and pressure to take irreversible action before authority is verified. Documented foreign fabrication and influence tactics make this phase particularly susceptible to information shocks. citeturn14view3turn23view0 |
| **Through thirty days** | The initial crisis becomes institutionalized in litigation, state-federal disputes, investigations and competing narratives. Foreign actors shift from “breaking news” fabrication to reinforcement of every domestic contradiction. | Multiple cyber incidents—some foreign, some criminal, some accidental—are narratively fused into one conspiracy. Leaked data are selectively released. Adversaries experiment with diplomatic recognition-like gestures. Employees and suppliers begin making business decisions based on factional information ecosystems. | Judicial decisions, statutory procedures, state action and bureaucratic continuity progressively narrow the space of plausible authority. Public attribution identifies foreign campaigns. Independent cybersecurity and media investigations produce corroborating evidence. | Acute safety risk falls if facilities preserve procedure, but **counterintelligence and business-continuity risk rises**: phishing, recruitment approaches, supplier stress, leaked contact directories, insider rumor and politically motivated workforce conflict. Federal election processes themselves involve canvass, audit and certification stages rather than a single media declaration, illustrating how distributed procedural nodes can outlast a disinformation burst. citeturn14view6 |
| **Through one hundred eighty days** | The conflict either converges institutionally or hardens into a durable legitimacy cleavage. Foreign operators try to convert crisis narratives into permanent distrust. | Foreign-origin stories become domesticated: people no longer know or care where they originated. Sporadic protests, litigation and cyber incidents are interpreted through the old fracture. Intelligence services exploit the prolonged distraction to collect on DIB personnel, crisis procedures and government decision chains. | Domestic institutions establish sufficiently consistent legal authority; foreign sponsorship is documented; contradictory claims lose novelty; contractors incorporate lessons into exercises and authentication procedures. | Long-term issue shifts from immediate contradictory orders to **persistent CI, insider-risk, workforce cohesion, supplier resilience and trust in digital evidence**. Regulatory requirements and contractual authority continue to constrain facility action. citeturn17search0turn8view4turn8view2 |

The highest-impact branch is not necessarily constitutional collapse. A more plausible severe outcome is **partial institutional convergence combined with persistent informational non-convergence**: courts and agencies settle enough questions for government to function while millions of people continue to regard official evidence as forged or compromised. Foreign influence then has enduring strategic value even after it fails to determine formal authority.

### Attribution-confidence framework

Attribution during a legitimacy crisis should never collapse six separate questions into the statement “foreign disinformation.” The analytic cell should score them separately:

| Attribution question | What must be established | Confidence treatment |
|---|---|---|
| **Artifact authenticity** | Is the document, video, audio, site, message or account genuine, altered, synthetic, or unresolved? | Often answerable faster than state attribution. An artifact can be demonstrably fake while its creator remains unknown. |
| **Immediate origin** | Which account, infrastructure, organization or individual first produced or disseminated it? | Requires provenance, platform, cyber, financial or human-source evidence; political alignment alone is inadequate. |
| **Network coordination** | Was dissemination organic, coordinated, automated, paid or centrally directed? | Repeated timing/content patterns strengthen but do not by themselves prove state control. |
| **State linkage** | Is the originating actor employed, funded, tasked, supplied or knowingly facilitated by a foreign government? | Highest-confidence judgments should combine independent evidence streams. DOJ and Treasury cases illustrate the relevance of financial and organizational linkages in addition to content. citeturn16search1 |
| **Operational intent** | Was the objective influence, espionage, monetization, disruption, retaliation or opportunistic trolling? | Keep intent separate from identity; the same infrastructure can support multiple purposes. |
| **Actual effect** | Did the operation materially alter decisions, merely generate attention, or have negligible effect? | Never infer effect from reach or virality alone. |

Use **High confidence** when multiple independent streams converge and important alternatives have been tested; **Moderate confidence** when credible evidence points in one direction but significant proxy, provenance or intent gaps remain; and **Low confidence** where the conclusion depends largely on circumstantial similarities, a single uncorroborated source, or the fact that content happens to benefit a foreign state. Those are analytic definitions for this framework rather than probabilistic percentages.

A special rule is essential in a polarized crisis: **content truth, provenance and sponsorship are separate variables.** A true document can be stolen by a foreign service. A false document can be created by a domestic actor and amplified by a foreign service. A foreign-origin claim can later be repeated innocently by Americans. Conversely, accusing a domestic claim of being “foreign” without evidence can itself become part of the legitimacy struggle. The Iran hack-and-leak case and Russia's documented efforts to hide its sponsorship demonstrate why those distinctions matter. citeturn16search0turn23view0

### Twenty strategic warning indicators

No single indicator establishes foreign intervention. Escalation confidence rises when indicators occur **across different domains at the same time**.

|  | Warning indicator | Significance |
|---|---|---|
| **1** | Foreign state media abruptly shifts from commentary about U.S. political conflict to categorical assertions that one U.S. authority is illegitimate. | Suggests movement from exploitation of controversy toward active legitimacy framing. |
| **2** | Multiple apparently domestic accounts release the same novel constitutional claim, terminology, image or “leaked” document before credible U.S. sources do. | Potential coordinated seeding or narrative laundering. |
| **3** | High-quality audio/video purporting to show an official issuing an extraordinary order appears without an independently verifiable original. | Fabricated political audiovisual material has documented precedent. citeturn14view3 |
| **4** | Previously unrelated influencer ecosystems begin repeating identical claims while concealing or misrepresenting funding or sourcing. | Hidden sponsorship is a known influence concern. citeturn23view0turn16search1 |
| **5** | Foreign media cite U.S. social-media posts, which then cite foreign media as “confirmation.” | Circular validation can make a weak claim appear independently corroborated. |
| **6** | A foreign government adopts unusually specific language about which American individual or institution it regards as entitled to act for the United States. | Potential diplomatic amplification of a domestic dispute. |
| **7** | Foreign diplomatic or state-media channels issue purported practical guidance—visa, embassy, military, trade or financial—premised on a disputed U.S. authority claim. | Turns symbolic recognition into an operational-looking narrative. |
| **8** | Viral claims allege federal payments, contractor invoices, bank access, appropriations or payroll have been frozen, with no confirmation from established financial or contracting channels. | Financial disinformation can create real precautionary disruption without changing any ledger. |
| **9** | Screenshots purporting to be emergency alerts circulate significantly faster than corresponding notices on established government channels. | Warning of alert impersonation; FEMA's IPAWS system is based on authorized alerting entities. citeturn19search11turn19search35 |
| **10** | Contradictory purported orders use valid names, titles or terminology but arrive through new addresses, numbers, accounts or channels. | Possible authority impersonation or compromised contact information. |
| **11** | Cyber outages affecting authoritative government or media sources coincide closely with spikes in claims that “the real order is being suppressed.” | Creates a verification vacuum even when causation between outage and influence campaign is unproven. |
| **12** | Crisis-themed credential theft, impersonation or social engineering disproportionately targets contracting, legal, executive, regulatory or emergency-management personnel. | Indicates interest in the people who can authenticate authority rather than only broad public opinion. |
| **13** | Leaked genuine documents are accompanied by unverifiable documents that cannot be traced to the same corpus. | Possible hack-and-leak contamination. DOJ's Iranian case demonstrates the underlying collection-and-leak threat. citeturn16search0 |
| **14** | Public claims of foreign attribution appear before responsible agencies or private investigators have supplied corroborating evidence. | Risk that attribution itself is being weaponized domestically. |
| **15** | Foreign cyber and influence narratives begin referencing nonpublic details of contractor organizational structures or internal contacts. | Raises the possibility of concurrent espionage or prior compromise. |
| **16** | Employees receive purported contract modifications or stop-work directions outside established contracting channels. | Federal contract modification authority is restricted to authorized contracting officers. citeturn18search2 |
| **17** | Purported regulatory orders call for bypassing standing accountability, access-control, recordkeeping or incident-response requirements. | Strong anomaly: NRC and FSAP requirements continue to bind covered facilities absent lawful change. citeturn8view4turn8view1turn8view2 |
| **18** | Staff press to add or remove personnel from sensitive access lists solely because of factional claims rather than the approved authorization process. | Political legitimacy disputes are crossing into facility-control mechanisms. FSAP rules require controlled access and current access records. citeturn8view1turn8view3 |
| **19** | Rumors recur across physically or organizationally separated shifts/sites with nearly identical wording before corporate crisis communications address them. | Potential coordinated amplification or rapid internal rumor propagation; either requires response even without foreign attribution. |
| **20** | Inventory, accountability or security anomalies emerge during communications disruption and are immediately explained politically before reconciliation occurs. | Dangerous fusion of an operational discrepancy with a legitimacy narrative; accounting procedures should resolve the discrepancy first. NRC and FSAP regimes require continuing inventory/accountability records. citeturn8view4turn8view5turn8view3 |

## Why foreign political exploitation is likely to fail

“Fail” should be defined carefully. A foreign campaign can inflict serious harm—delay, distrust, financial cost, intelligence loss, episodic violence or workforce disruption—while still **failing to determine who legitimately exercises U.S. constitutional authority or to redirect a well-controlled DIB facility**.

**The first barrier is institutional multiplicity.** Presidential succession is not created by social consensus, a media call, a foreign government's recognition, or a viral video. Constitutional and statutory mechanisms—including the Twenty-Fifth Amendment and 3 U.S.C. §19 for relevant contingencies—create legally significant decision points independent of information-space popularity. citeturn17search2turn18search6

**States and local institutions create additional independent sources of record.** In the election context, for example, the EAC explains that official results emerge through canvass, reconciliation, auditing where required, and certification by election officials; election-night projections are not official certification. More generally, federalism means a nationwide legitimacy narrative has to contend with many separate state governments, courts, officials and records rather than one information node. citeturn14view6

**Courts introduce procedures that are difficult for a foreign actor to simulate at scale.** A forged image of a supposed court order can circulate quickly, but an actual judgment produces a docket, counsel, parties, subsequent proceedings and implementation actions across multiple institutions. The adversary may confuse audiences temporarily; sustaining a counterfeit legal reality becomes progressively harder as independent records accumulate. This is an analytic inference from the distributed institutional structure rather than a claim that courts are immune to disinformation.

**The federal acquisition system compartmentalizes operational authority.** A defense contractor does not need to resolve every constitutional argument before determining whether a purported programmatic instruction is contractually binding. FAR 1.602-1 defines contracting-officer authority, and FAR 43.102 restricts execution of contract modifications to contracting officers operating within their authority. That creates a narrower, auditable question: *did an authenticated official possessing the relevant delegated authority issue a valid direction through the applicable contractual mechanism?* citeturn17search0turn18search2

**Regulatory continuity is similarly “sticky.”** Current NRC MC&A provisions require continuing records and controls, while FSAP regulations require written security and incident-response plans, controlled access, inventory records and responses to system failures and emergencies. A political actor cannot make those obligations disappear merely by announcing that authority has changed. citeturn8view4turn8view5turn8view1turn8view2

**Law-enforcement and intelligence attribution creates an adversary dilemma.** Hiding sponsorship increases operational freedom but makes direct command of a narrative harder. Exercising more overt control produces more financial, technical and organizational evidence for attribution. The U.S. has publicly combined intelligence assessments, criminal charges and sanctions in response to foreign influence efforts, as illustrated by the joint ODNI/FBI/CISA attribution of fabricated Russian media, DOJ's Iranian hack-and-leak charges, and Treasury sanctions. citeturn14view3turn16search0turn16search1

The institutional base for this work is distributed as well. ODNI's Foreign Malign Influence Center has an interagency role focused on foreign actors seeking to influence U.S. public opinion and behavior, while the NCSC and other national mission centers integrate counterintelligence and threat information. citeturn12view0

**Allied intelligence relationships complicate foreign deception further.** A forged American narrative may have to survive comparison against collection, cyber telemetry, diplomatic reporting and intelligence held by multiple friendly governments. This does not guarantee rapid public attribution, but it reduces an adversary's ability to control the full evidentiary environment. Likewise, international security partnerships create channels independent of the contested U.S. public narrative; the broader pattern of allied security cooperation is evident across longstanding multilateral mechanisms and U.S. intelligence relationships. citeturn13view3

**Private cybersecurity and distributed media are double-edged but ultimately obstruct monopoly control.** Fragmentation gives adversaries more channels to seed claims, yet it also means no state has exclusive control over forensic investigation, archival copies, independent reporting, network telemetry or platform data. CISA's guidance for foreign malign influence defense explicitly treats preparation, transparency and response to influence operations as resilience problems rather than assuming the information environment can be centrally controlled. citeturn16search2

**Ideological diversity is another constraint.** An influence theme that maximally energizes one constituency may repel another. An adversary attempting to intensify both sides must operate through different personas and intermediaries, increasing operational complexity and the chance of exposure. The documented use of different covert and AI-enabled personas by foreign actors is consistent with this need for segmentation. citeturn13view1turn23view0

Finally, **foreign sponsorship can become a liability.** Russia's effort to conceal its hand is itself evidence that overt Russian provenance can reduce the utility of a message for at least some American audiences. Exposure will not erase a narrative—especially after domestic actors have incorporated it into their own worldview—but it can fracture the coalition repeating it, force prominent relays to distance themselves, and shift attention from the original claim to manipulation by a foreign government. citeturn23view0turn16search1

The important warning is that these barriers are strongest against **decisive political manipulation**, not against damage. A failed foreign attempt can still degrade trust, increase protective costs, distract counterintelligence resources, prolong litigation narratives, create workforce conflict and provide cover for espionage.

## Contractor communications resilience and the facility-control problem

The DIB should treat a severe legitimacy fracture as two related but distinct problems:

**Political question:** Who lawfully exercises a disputed constitutional office?

**Operational question:** Is this particular instruction authentic, issued by an official with authority over this particular facility/contract/license, consistent with continuing law and regulation, and safe to execute?

Contractors generally should not improvise an answer to the first question in order to answer the second. Their continuity architecture should narrow the problem to verifiable authority.

### Resilient authority-validation model

| Control layer | Crisis behavior | Why it matters |
|---|---|---|
| **Pre-established authority register** | Maintain an offline-capable record of the offices—not merely personalities—authorized to issue defined categories of contractual, regulatory, emergency and corporate direction, together with approved escalation/succession paths. | A crisis can change officeholders faster than it changes legal delegations. FAR authority is role- and delegation-based. citeturn17search0 |
| **Authenticated primary channel** | Treat established agency/regulator systems and known official channels as primary. An extraordinary instruction received solely via press conference, social media, forwarded email, personal device or screenshot is information to verify, not operational authority. | Reduces susceptibility to impersonation and manipulated media. FEMA's alerting model likewise distinguishes authorized alert originators from generic public content. citeturn19search11turn19search35 |
| **Independent second confirmation** | For extraordinary, irreversible or high-consequence directions, confirm through a second pre-established organizational path wherever time and emergency procedures permit. | Prevents compromise of one account or channel from becoming compromise of the decision. NIST contingency controls explicitly contemplate alternate communications for continuity. citeturn21search1 |
| **Legal and contractual verification** | Ask whether the sender possesses the required contracting or regulatory authority and whether the proposed action requires a formal modification, order, waiver or other instrument. | Only authorized contracting officers may execute federal contract modifications. citeturn18search2 |
| **Alternate communications** | Pre-plan nonidentical communications paths for critical coordination rather than assuming internet, cellular, enterprise identity and cloud collaboration will fail or recover together. Eligible national-security/emergency users may also use CISA priority telecommunications services such as GETS/WPS where appropriate to their role. citeturn19search2 | A regional outage should degrade speed, not eliminate the ability to authenticate all authority. |
| **Decision logging** | Record message provenance, time, claimed authority, authentication checks, persons consulted, legal basis, decision and later corrections. | A contemporaneous record supports accountability, incident reconstruction and resistance to retrospective narrative manipulation. NRC and FSAP regimes already make accurate records central to material control. citeturn8view4turn8view3 |
| **Workforce single-source-of-truth process** | Provide frequent internal updates that distinguish known facts, unresolved claims, unchanged procedures and the next update time. Do not repeat sensational falsehoods unnecessarily. | Reduces the vacuum in which workforce rumor substitutes for operational direction. |
| **Cyber-degraded operations** | When compromise is suspected, shift authority validation to predetermined unaffected paths and follow incident-response/recovery procedures; do not permit a business-IT incident to automatically redefine facility authority. | NIST contingency guidance calls for alternative communications, while CISA's cyber-resilience guidance treats incident response and recovery as planned functions. citeturn21search1turn21search2 |
| **Conservative reversible posture** | While authority is unresolved, preserve the facility-specific safe, secure, contained and accounted-for condition and defer unnecessary irreversible transitions, unless an established emergency/safety procedure requires immediate action. | Prevents information uncertainty from becoming a physical-control failure. This is a continuity principle, not a universal instruction to shut down. |
| **Recovery validation** | Restoration of communications does not by itself prove the restored system is trustworthy; reconcile messages, logs and outstanding orders before resuming deferred high-consequence changes. | Avoids executing queued malicious or contradictory instructions merely because connectivity returns. |

NIST SP 800-53 expressly includes a contingency control for **alternate communications protocols** in support of continuity. CISA's GETS service is designed to improve completion of priority calls during network congestion and can be used with Wireless Priority Service for eligible users. These mechanisms support a general resilience principle: critical authority verification should not depend on one commercial channel. citeturn21search1turn19search2

### Simultaneous contradictory purported orders

Consider a contractor that receives, nearly simultaneously:

* one message purporting to come from an executive authority directing an immediate operational change;
* another purported federal direction telling the facility to disregard the first;
* a regulator-themed message claiming emergency suspension or a changed security requirement;
* news reports showing contradictory political claims;
* a regional network outage preventing normal confirmation.

The correct analytical framing is **not “which political faction should the facility obey?”** It is:

**What is the last verified lawful operational baseline, what standing safety/security obligations remain in force, which claimed order can be independently authenticated, and which official possesses authority to alter the relevant contract/license/activity?**

During the verification interval, the facility should remain within its approved emergency and continuity procedures. It should not invent a new political chain of command. For contractual matters, the FAR's allocation of authority remains a powerful filter. For regulated nuclear or biological matters, standing accountability, security, access-control, incident-response and recordkeeping duties continue while political questions are resolved elsewhere. citeturn17search0turn18search2turn8view4turn8view1turn8view2

A useful **decision gate** for any extraordinary instruction is:

**Authentic message? → authorized office? → authorized for this specific action? → independently confirmed where practicable? → legally/regulatorily consistent? → safety/security implications reviewed? → logged?**

Failure at an early gate should generally trigger verification and use of the approved degraded-mode procedure, not improvisation.

This is especially important because communications may be authentic while authority is not. An actual government employee can send an instruction outside that person's delegated power. Conversely, a lawful instruction may arrive while public narratives falsely claim the sender no longer holds authority. Authentication and legal authority therefore must be tested independently. FAR 43.102's restriction on contract modifications illustrates this distinction. citeturn18search2

## Nuclear and high-containment biological continuity annex

The annex is intentionally high level. It does not prescribe facility-specific physical security configurations, cyber architecture, containment parameters, or material handling procedures. Those belong in approved site plans and regulatory programs.

### Nuclear special-material continuity

The applicable regulatory regime depends on the facility. The NRC provisions discussed here apply to covered NRC licensees; Department of Energy and NNSA government-owned/contractor-operated facilities can be governed by different departmental orders, contractual requirements and site-specific authorization bases. A continuity plan therefore should begin by mapping **which authority governs which material and activity**, rather than assuming NRC rules cover all DIB nuclear operations.

For NRC-regulated special nuclear material, current 10 CFR Part 74 requires records showing receipt, inventory—including location and unique identity—acquisition, transfer and disposal of special nuclear material. Covered licensees must maintain written MC&A procedures, and §74.31 includes management responsibility, inventories, measurements and the capability to maintain current knowledge of items. Electronic records must remain accurate and complete, with safeguards against tampering or loss. citeturn8view4turn8view5

That yields six continuity priorities during a legitimacy fracture:

**Preserve material accountability.** Political uncertainty is not a reason to suspend inventories, records, reconciliation or established discrepancy-resolution processes. An apparent discrepancy should be investigated as an accountability event first, not immediately interpreted through the political narrative. citeturn8view4turn8view5

**Preserve existing personnel/access authorization.** A purported change of political leadership should not, by itself, cause ad hoc changes in sensitive access. Any change follows the applicable site authorization regime and authenticated authority.

**Reject unverified extraordinary movement or configuration changes.** A purported instruction to move, transfer, release, reclassify or otherwise alter control of special material should be subjected to the facility's established authorization and independent-verification requirements. When authority cannot be established, preserve the approved safe and secure baseline unless a genuine safety emergency requires action.

**Maintain incident logging.** Keep contemporaneous records of contradictory orders, authentication attempts, communications failures, access decisions, anomalies and corrective actions. NRC rules emphasize continuing material records and require reporting for specified loss, theft or attempted diversion events. citeturn6view0turn8view4

**Separate political-information uncertainty from cyber integrity.** An enterprise network outage may make confirmation harder, but it should not be treated as evidence that every safety, security or accounting system is compromised. Conversely, restoration of a website or email server should not automatically establish authenticity. Use approved incident response, alternate communications and known-good recovery processes. NIST explicitly calls for alternate communications capability as part of continuity planning. citeturn21search1

**Use a facility-defined safe-state default.** Here, “safe state” means the preplanned condition that maintains safety, physical security, material control/accountability and regulatory compliance while unnecessary high-consequence transitions wait for verified authority. It does **not** mean a universal reactor shutdown, universal movement prohibition, or a particular physical configuration; those decisions are facility- and authorization-specific.

### Select-agent/high-containment biological continuity

Current 42 CFR Part 73 provides unusually direct support for the same model. The regulations require a written, site-specific security plan sufficient to safeguard select agents and toxins against unauthorized access, theft, loss or release. Required measures address physical security, inventory control, information systems and access. The information-security provisions require control or isolation of external connections, authorized/authenticated users and backup security measures when access controls, surveillance or record systems fail. citeturn8view1

The incident-response rule requires a written, site-specific plan covering theft, loss or release; inventory discrepancies; physical or information-system security breaches; severe weather; workplace violence; fire; power outages; and other natural or man-made emergencies. It also calls for lines of authority and communication and coordination with outside responders, and requires periodic exercises with corrective-action documentation. citeturn8view2

Records must support current inventories, movement/storage/use histories, access lists, security and incident documentation, and explanations of inventory discrepancies; the regulations also require that records be accurate, access-controlled and capable of authenticity verification. citeturn8view3turn7view5

Accordingly, a high-containment biological contractor facing contradictory purported orders should preserve four things above all:

**containment and security; inventory/accountability; existing authorized-access controls; and the approved incident-response chain.**

A false “regulator message” should therefore be evaluated as both an information-security incident and an authority-validation problem. It is not a valid basis for bypassing the written security plan merely because it invokes a national political emergency. citeturn8view1turn8view2

### Cross-domain facility rule

For both nuclear and biological operations, the safest institutional principle is:

> **No contested political narrative should be allowed to directly actuate a high-consequence facility decision. Political claims must cross an authentication, legal-authority, regulatory, safety/security and logging boundary before they can become operational instructions.**

The principle works even when the national constitutional dispute remains unresolved because it asks the facility to preserve the last authenticated lawful baseline rather than to independently adjudicate national legitimacy.

## Tabletop exercise, intelligence gaps, and final confidence judgments

### Inject-based tabletop

The exercise should be run as a **nonpartisan continuity exercise**. Teams are scored on preservation of lawful authority, information integrity, material accountability, personnel control and facility safety—not on whether their actions help one political claimant.

The scenario begins with a genuine constitutional event creating competing claims. Exercise control should deliberately avoid revealing which claim is ultimately validated until late in play.

| Time | Inject | Expected decision problem | What good performance looks like |
|---|---|---|---|
| **T+0** | National media report a genuine event creating uncertainty over executive authority. Different officials make apparently inconsistent statements. | Does the site prematurely choose a political interpretation? | Crisis structure activates; standing operational authority and unchanged requirements are identified; extraordinary changes require validation. |
| **T+1 h** | A highly realistic video circulates in which a purported senior official orders all facilities supporting a named mission to take an immediate extraordinary action. | Manipulated media versus time pressure. | Team does not operationalize video alone; seeks authenticated official instruction and independent confirmation. The inject reflects documented foreign use of fabricated political video. citeturn14view3 |
| **T+2 h** | Primary agency website and several regional communications services become intermittently unavailable. No attribution is available. | Loss of authoritative information. | Alternate communications procedures activate; outage is not automatically attributed to a foreign state or political faction. NIST continuity guidance supports alternate communications. citeturn21search1 |
| **T+3 h** | An official-looking email purporting to come from a regulator orders an immediate change inconsistent with part of the standing facility plan. | False-regulator message. | Sender, channel and legal authority are independently validated; standing regulatory requirements remain in force while the message is unresolved. citeturn8view4turn8view1 |
| **T+4 h** | Two callers, each using correct names and internal terminology, claim to represent different government authorities and give contradictory directions. | Identity versus authority. | Personnel distinguish knowing internal details from possessing delegated authority; calls are documented and escalated through known contacts. |
| **T+6 h** | Internal chat fills with claims that employees working under “the wrong government” could face criminal liability. A screenshot purports to show an emergency alert reinforcing the rumor. | Workforce fear and false emergency messaging. | Corporate/legal communication states what is known, what is unchanged and where official instructions originate; screenshot alone is not treated as operational authority. FEMA's public warning architecture depends on authorized alerting authorities. citeturn19search11turn19search35 |
| **T+8 h** | Viral posts claim Treasury has frozen federal contractor payments and a major supplier says it may stop shipments unless paid immediately. | Financial disinformation becomes supply disruption. | Finance/contracting teams verify through established financial and contracting paths; supply-continuity options are assessed without repeating the rumor as fact. |
| **T+12 h** | A genuine agency statement contradicts the earlier false message, but a major domestic faction claims the agency account or website has been hacked. | Authentic correction fails to end controversy. | Team relies on multiple authentication paths and records the evidentiary basis rather than arguing about political credibility. |
| **T+18 h** | A program official verbally says, “assume your contract is suspended,” while the contracting officer is unreachable. | Contracting-authority ambiguity. | Team distinguishes program preference from binding contractual modification and escalates under the contract's existing procedures. FAR restricts modifications to authorized contracting officers. citeturn18search2 |
| **T+24 h** | An overseas partner asks which competing U.S. authority the contractor recognizes and requests a written answer before sharing data. | Diplomatic/partner pressure to take a political position. | Contractor answers within approved government/contractual channels and avoids independently determining national recognition policy. |
| **T+36 h** | Corporate IT discovers evidence of compromise in a business network used for email and collaboration; there is no confirmed compromise of facility safety/security systems. | Avoiding both complacency and overreaction. | Cyber incident is scoped under approved response procedures; alternate communication is used; unsupported claims of wider compromise are rejected. citeturn21search1turn21search2 |
| **T+44 h** | Rumor spreads across two shifts that a named employee is an “agent of the illegitimate side,” generating pressure to revoke access immediately. | Political rumor versus personnel authorization. | Existing access/security processes—not factional allegiance—govern access decisions; specific security concerns are separately investigated. |
| **T+52 h** | A court or other competent domestic institution issues a genuine consequential ruling, but public reporting is inconsistent about its scope. | Translating legal development into facility authority. | Counsel obtains and validates the actual instrument, determines applicability, and identifies what operationally changes and what does not. |
| **T+60 h** | During the distraction, personnel identify an inventory/accounting discrepancy. Social media immediately claims it proves sabotage. | Material accountability under narrative pressure. | Facility follows the established discrepancy and reporting process without prematurely assigning motive. NRC and FSAP rules emphasize continuing inventory/accountability and discrepancy records. citeturn8view5turn8view3 |
| **T+72 h** | Connectivity stabilizes. Multiple queued instructions arrive, including authentic, obsolete and fraudulent messages. | Unsafe “catch-up” behavior. | Team reconciles timestamps, authority, supersession and system integrity before acting; no blind execution of accumulated messages. |

### Exercise scoring

A five-level scale can be applied to each decision. The score should reward **process integrity under ambiguity**, not political prescience.

| Dimension | Strong performance | Serious failure |
|---|---|---|
| **Decision quality** | Decisions are reversible when uncertainty is high; assumptions are recorded; immediate safety requirements are separated from deferrable actions. | Irreversible action is taken primarily because of media pressure, rumor or factional affiliation. |
| **Legal/authority verification** | Sender identity, office, delegated authority and required contractual/regulatory instrument are separately tested. | “Senior government official” is treated as synonymous with “authorized to direct this action.” |
| **Material accountability** | Inventory and custody records remain current; discrepancies follow established reconciliation/reporting channels. | Political assumptions replace accounting; records lapse; unverified directions alter custody/control. |
| **Facility safety/security** | Approved emergency procedures and safe-state assumptions remain controlling while external legitimacy questions are unresolved. | Staff invent novel facility procedures to accommodate a political claimant. |
| **Communications resilience** | Primary and alternate channels are used; workforce receives regular authoritative updates; failed channels do not end validation. | One failed identity provider, website or telecom service produces an authority vacuum. |
| **Cyber discipline** | Compromise is scoped from evidence; affected systems are handled through approved incident response and recovery. | Every outage is attributed politically, or restoration is equated with trustworthiness. |
| **Incident logging** | Contradictory instructions, authentication attempts, decisions and corrections remain reconstructable. | Oral improvisation and fragmented chat become the only record. |
| **Rumor control** | Communications identify verified facts, unresolved issues, unchanged procedures and next-update timing. | Leadership either goes silent or repeats sensational claims while attempting to debunk them. |

A mature organization should also test whether its authentication architecture itself creates a common-mode failure. For example, phone, email and messaging that all depend on the same identity, network or cloud dependency are not truly independent alternatives. NIST's contingency-control framework specifically emphasizes alternate communications in support of continuity. citeturn21search1

### Priority intelligence gaps

The most important gaps are not “which political faction would win.” They concern foreign preparation and DIB vulnerability:

| Intelligence gap | Why it matters | Priority |
|---|---|---|
| **Prepositioned foreign influence assets aimed specifically at DIB workforces and defense communities** | Generic political networks may not reveal accounts intended for contractor employees, military communities or local facility populations. | **Critical** |
| **Foreign possession of contractor contact directories, delegation charts and crisis-call trees** | Such data materially improves authority impersonation without requiring compromise of operational technology. | **Critical** |
| **Knowledge of common-mode communications dependencies** | Determines whether a regional outage could simultaneously remove primary and supposed “backup” verification paths. | **Critical** |
| **Adversary intent to transition from influence/espionage to disruptive cyber activity during a domestic legitimacy crisis** | Capability alone does not establish willingness to risk escalation. Russia, Iran and China have different risk tolerances. citeturn23view0turn13view0turn13view2 | **Critical** |
| **Foreign understanding of U.S. contracting-authority distinctions** | An adversary that understands contracting-officer delegations can craft more credible false instructions. | **High** |
| **Compromised or cultivated domestic influencer accounts held in reserve** | Dormant trusted personas may be much more effective in a crisis than newly created foreign accounts. | **High** |
| **Capacity to clone regulator, emergency-management and contracting communications convincingly** | Determines whether impersonation remains nuisance-level or creates meaningful operational hesitation. | **High** |
| **Foreign access to authentic but nonpublic documents suitable for insertion into fabricated packages** | Real material can greatly improve the credibility of false additions in a hack-and-leak campaign. The Iranian hack-and-leak precedent makes this especially relevant. citeturn16search0 | **High** |
| **Supplier and financial fragility under false-payment narratives** | Disinformation can create physical production delays through precautionary supplier behavior even without a cyber breach. | **High** |
| **Baseline workforce trust and rumor-propagation patterns** | Sites cannot measure anomalous influence without knowing normal communication behavior. | **High** |
| **Latency in government-to-contractor authoritative crisis communications** | Long silence creates the space in which counterfeit orders acquire operational relevance. | **High** |
| **Cross-facility consistency of safe-state and authority-validation doctrine** | Inconsistent responses by similar facilities can themselves become “evidence” in competing political narratives. | **High** |
| **Ability of allies and private-sector investigators to independently corroborate attribution** | Independent evidence reduces reliance on a single contested U.S. institution. | **Medium-high** |
| **Degree to which foreign-seeded narratives have become self-sustaining domestically** | Once source provenance no longer matters, removing foreign infrastructure may have little immediate effect. | **Medium-high** |

### Final warning judgment

The **most plausible foreign success** is not installation of a preferred American authority. It is creation of a temporary environment in which *every* piece of evidence becomes faction-contingent: genuine communications are denounced as deepfakes, deepfakes are defended as censored truth, cyber outages are treated as proof of political sabotage, authentic leaks make fabricated additions more credible, and attribution findings are evaluated primarily according to whether they help or hurt a domestic side. Russia's documented division-oriented influence strategy, Iranian hack-and-leak activity and increased PRC covert influence capability establish credible components of that threat model. citeturn23view0turn16search0turn13view1

The **most important DIB defense is procedural legitimacy rather than political persuasion**: pre-established authority, authenticated and redundant communications, independent confirmation, written delegation boundaries, continuing legal and regulatory requirements, material accountability, controlled personnel access, contemporaneous logs, rehearsed cyber-degraded modes and facility-specific safe-state defaults. FAR rules, NRC material-accounting requirements, FSAP security/incident-response regulations and NIST continuity guidance all create mechanisms by which operations can remain bounded even while the public information environment is severely contested. citeturn17search0turn18search2turn8view4turn8view5turn8view1turn8view2turn21search1

**Overall confidence: high** that a genuine severe U.S. constitutional legitimacy crisis would attract coordinated and uncoordinated exploitation by foreign intelligence and influence actors; **high** that communications disruption and fabricated authority messages would materially increase uncertainty; **moderate** that foreign diplomatic recognition maneuvers would substantially deepen the political crisis; **low** that foreign influence alone could settle the U.S. legitimacy contest; and **high** that facilities which have genuinely exercised authority verification, alternate communications, legal escalation, accountability and degraded-mode safety procedures would be substantially more resistant to foreign amplification than facilities relying on informal relationships or ordinary enterprise communications. citeturn23view0turn14view3turn13view1turn16search0turn17search0turn21search1