Multinational organizations operating in shared cybersecurity environments face a compounding intelligence challenge: the behavioral dynamics that determine human susceptibility to social engineering, insider threat development, and coordinated disinformation campaigns are not captured by conventional technical security monitoring, yet available evidence consistently positions them as the dominant attack surface in contemporary advanced persistent threat (APT) and hybrid cyber-influence operations, with Verizon’s 2024 Data Breach Investigations Report attributing 68% of breaches to a non-technical human element, and establishing social engineering as structurally prior to technical exploitation in APT attack chains. This article develops and applies the Behavioral Intelligence in the Cognitive Domain (BICD) framework to multinational cybersecurity contexts, reconceptualizing Social Media Intelligence (SOCMINT) as an epistemologically distinct discipline from Open-Source Intelligence (OSINT) grounded in behavioral rather than documentary epistemology, and arguing that this distinction has direct and underexplored consequences for multinational security operations centers (MSOCs), joint cyber defense coordination cells, and cross-border incident response teams. The BICD framework integrates five cyberpsychology mechanisms, online disinhibition, platform-conditioned identity performance, algorithmic belief environment formation, social proof manipulation, and digital cognitive bias amplification, into a structured analytical procedure for producing explanatory and predictive threat intelligence from human behavioral data in digital environments. The framework then specifies how BICD-derived intelligence products inform narrative-based countermeasure design, organizational resilience architecture, and cross-jurisdictional threat communication, creating a structured intelligence-to-defense pipeline applicable to the multinational cybersecurity operating environment. The article engages emerging scholarship in cognitive cybersecurity (2021-2025), AI-driven social engineering threats (2022-2025), and multinational cyber coordination frameworks to situate the BICD framework within current organizational and operational debates. Implications for multinational security governance, cross-border intelligence sharing, and practitioner training are addressed throughout.
Krombholz, K., Hobel, H., Huber, M. and Weippl, E. (2015) Advanced Social Engineering Attacks. Journal of Information Security and Applications , 22, 113-122. https://doi.org/10.1016/j.jisa.2014.09.005
Workman, M. (2008) Wisecrackers: A Theory-Grounded Investigation of Phishing and Pretext Social Engineering Threats to Information Security. Journal of the American Society for Information Science and Technology , 59, 662-674. https://doi.org/10.1002/asi.20779
La Polla, M.N. (2014) Social Media Analytics and Open Source Intelligence: The Role of Social Media in Intelligence Activities. https://tesidottorato.depositolegale.it/bitstream/20.500.14242/139718/1/LaPollaTesiDottorato.pdf
Dover, R. (2020) SOCMINT: A Shifting Balance of Opportunity. Intelligence and National Security , 35, 216-232. https://doi.org/10.1080/02684527.2019.1694132
Troublefield, T.C. (2025) Strategic Military Information Support Operations for Countering Digital Terrorist Threat Networks. Journal of Applied Security Research , 20, 586-602. https://doi.org/10.1080/19361610.2025.2498446
Torraco, R.J. (2005) Writing Integrative Literature Reviews: Guidelines and Examples. Human Resource Development Review , 4, 356-367. https://doi.org/10.1177/1534484305278283
Heartfield, R. and Loukas, G. (2015) A Taxonomy of Attacks and a Survey of Defence Mechanisms for Semantic Social Engineering Attacks. ACM Computing Surveys , 48, 1-39. https://doi.org/10.1145/2835375
Vishwanath, A., Herath, T., Chen, R., Wang, J. and Rao, H.R. (2011) Why Do People Get Phished? Testing Individual Differences in Phishing Vulnerability within an Integrated, Information Processing Model. Decision Support Systems , 51, 576-586. https://doi.org/10.1016/j.dss.2011.03.002
Verizon (2024) 2024 Data Breach Investigations Report. Verizon Business. https://www.verizon.com/business/resources/reports/dbir/
Deppe, C. and Schaal, G.S. (2024) Cognitive Warfare: A Conceptual Analysis of the NATO ACT Cognitive Warfare Exploratory Concept. Frontiers in Big Data , 7, Article 1452129. https://doi.org/10.3389/fdata.2024.1452129
Fenstermacher, L.H., Uzcha, D., Larson, K.G., Vitiello, C.A. and Shellman, S.M. (2023) New Perspectives on Cognitive Warfare. Signal Processing , Sensor / Informatio n Fusion , and Target Recognition XXXII . https://doi.org/10.1117/12.2666777
Loch, K.D., Carr, H.H. and Warkentin, M.E. (1992) Threats to Information Systems: Today’s Reality, Yesterday’s Understanding. MIS Quarterly , 16, 173-186. https://doi.org/10.2307/249574
Multinational Cybersecurity
Social Engineering
Insider Threat
Cognitive Domain
AI-Enhanced Influence
Cross-Border Cyber Defense
Akhgar, B., Bayerl, P.S. and Sampson, F. (2016) Open Source Intelligence Investigation: From Strategy to Implementation. Springer. https://doi.org/10.1007/978-3-319-47671-1
Goldstein, J.A., Sastry, G., Musser, M., DiResta, R., Gentzel, M. and Sedova, K. (2023) Generative Language Models and Automated Influence Operations: Emerging Threats and Potential Mitigations. arXiv: 2301.04246. https://arxiv.org/abs/2301.04246
Hazell, J. (2023) Spear Phishing with Large Language Models. arXiv: 2305.06972. https://arxiv.org/abs/2305.06972
Fredheim, R. and Pamment, J. (2025) Assessing the Risks and Opportunities Posed by AI-Enhanced Influence Operations on Social Media. Place Branding and Public Diplomacy , 21, 319-326. https://doi.org/10.1057/s41254-023-00322-5
Suler, J. (2004) The Online Disinhibition Effect. CyberPsychology & Behavior , 7, 321-326. https://doi.org/10.1089/1094931041291295
Ancis, J.R. (2025) The Cyberpsychology Influence on Modern Computing. Communications of the ACM , 68, 72-79. https://doi.org/10.1145/3720535
Markman, K.M. (2012) A Networked Self: Identity, Community and Culture on Social Network Sites. New Media & Society , 14, 1240-1242. https://doi.org/10.1177/1461444812453432
Chatzakou, D., Soler-Company, J., Tsikrika, T., Wanner, L., Vrochidis, S. and Kom-patsiaris, I. (2020) User Identity Linkage in Social Media Using Linguistic and Social Interaction Features. Proceedings of the 12 th ACM Conference on Web Science , Southampton, 6-10 July 2020, 295-304.
Friedl, P. (2025) The General Data Protection Regulation. In: Reasonable Expectations of Privacy : With Special Regard to European Privacy and Data Protection Law , Springer Nature Switzerland, 295-344. https://doi.org/10.1007/978-3-031-84881-0_11
Pariser, E. (2011) The Filter Bubble: What the Internet Is Hiding from You. Penguin Press.
Sunstein, C.R. (2017) #Republic: Divided Democracy in the Age of Social Media. Princeton University Press. https://doi.org/10.1515/9781400884711
Vosoughi, S., Roy, D. and Aral, S. (2018) The Spread of True and False News Online. Science , 359, 1146-1151. https://doi.org/10.1126/science.aap9559
O’Keefe, D.J. (2025) Persuasion. In: Hargie, O., Ed., The Handbook of Communication Skills , Routledge, 371-390. https://doi.org/10.4324/9781003367796
Muchnik, L., Aral, S. and Taylor, S.J. (2013) Social Influence Bias: A Randomized Experiment. Science , 341, 647-651. https://doi.org/10.1126/science.1240466
Biagio, M.S., Acquaviva, R., Mazzonello, V., La Mattina, E. and Morreale, V. (2021) A New SOCMINT Framework for Threat Intelligence Identification. 2021 Interna tional Conference on Computational Science and Computational Intelligence ( CSCI ), Las Vegas, 15-17 December 2021, 692-697. https://doi.org/10.1109/csci54926.2021.00180
Susarla, A., Oh, J. and Tan, Y. (2016) Influentials, Imitables, or Susceptibles? Virality and Word-of-Mouth Conversations in Online Social Networks. Journal of Management Information Systems , 33, 139-170. https://doi.org/10.1080/07421222.2016.1172454
Nickerson, R.S. (1998) Confirmation Bias: A Ubiquitous Phenomenon in Many Guises. Review of General Psychology , 2, 175-220. https://doi.org/10.1037/1089-2680.2.2.175
Kahneman, D. (2011) Thinking, Fast and Slow. Farrar, Straus and Giroux. https://grahamseibert.com/Reviews/Psychometric/thinking%20fast%20and%20slow.pdf
Heuer, R.J. (1999) Psychology of Intelligence Analysis. Center for the Study of Intelligence, Central Intelligence Agency.
Pote, M., Elmas, T., Flammini, A. and Menczer, F. (2025) Coordinated Reply Attacks in Influence Operations: Characterization and Detection. Proceedings of the International AAAI Conference on Web and Social Media , 19, 1586-1598. https://doi.org/10.1609/icwsm.v19i1.35889
Green, M.C. and Brock, T.C. (2000) The Role of Transportation in the Persuasiveness of Public Narratives. Journal of Personality and Social Psychology , 79, 701-721. https://doi.org/10.1037/0022-3514.79.5.701
McAdams, D.P. (2018) Narrative Identity: What Is It? What Does It Do? How Do You Measure It? Imagination , Cognition and Personality , 37, 359-372. https://doi.org/10.1177/0276236618756704
ENISA (2023) Blueprint for Coordinated Response to Large-Scale Cybersecurity Incidents and Crises in the EU. European Union Agency for Cybersecurity. https://www.enisa.europa.eu
Dash, S. and Mitra, T. (2024) Decoding the Playbook: Multi-Modal Characterization of Coordinated Influence Operations on Indian Social Media. ACM Journal on Computing and Sustainable Societies , 2, 1-19. https://doi.org/10.1145/3675760
Goldman, J. (2023) Influence Operations and the Role of Intelligence. In: Arcos, R., Chiru, I. and Ivan, C., Eds., Routledge Handbook of Disinformation and National Security , Routledge, 84-94. https://doi.org/10.4324/9781003190363
Chen, D., Yoon, H.J., Wan, Z., Alluru, N., Lee, S.W., He, R., Moore, T.J., et al . (2025) Advancing Human-Machine Teaming: Concepts, Challenges, and Applications. arXiv: 2503.16518. https://arxiv.org/abs/2503.16518
Floridi, L., Cowls, J., Beltrametti, M., Chatila, R., Chazerand, P., Dignum, V., et al . (2018) AI4People—An Ethical Framework for a Good AI Society: Opportunities, Risks, Principles, and Recommendations. Minds and Machines , 28, 689-707. https://doi.org/10.1007/s11023-018-9482-5
Ferrara, E. (2023) Social Bots, Deepfakes, and Disinformation in the Age of Large Language Models. arXiv: 2311.01790. https://arxiv.org/abs/2311.01790