Data-Driven Decision Making in Defence: Opportunities and Challenges

Using data, including 'crowdsourced data' in defence
Organisations first need to identify and understand:
What insights is the business aiming to obtain? Including whether these insights are real-time or future-prediction driven.
The type(s) of data they need to collect, including whether to collect this data directly or via third parties.
The risks associated with using the data, including any privacy-risks or wider cybersecurity risks.
We are seeing an increase in 'crowdsourced data' being used in the defence sector. 'Crowdsourced data' is essentially a large data set that has been obtained from a number of different sources. This can include sources such as online questionnaires, live CCTV footage and other relevant information, such as current/future weather forecasts, which can be used together to generate insights.
If collected in a lawful manner, crowdsourced data can be very efficient in supporting defence strategic planning and operation execution. For example in situations such as navigation safety and mapping, crowdsourced data has played a pivotal role in providing real-time updates on geographical features, transportation routes, and potential hazards for decades. This continually updated information empowers both military and civilian users to make informed decisions, helping to ensure the success and safety of their endeavours.
However, it is vital that crowdsourced data is accurate and truly representative of the individuals involved. It can also be inherently sensitive, so comes with additional privacy/cyber compliance considerations and risks. For more information on some of the benefits and risks associated with using crowdsourced data, please see our article here .
How is technology being used to exploit data in the defence sector?
Technology is increasingly being used to maximise the benefits of data in defence. Examples include:
Storage management. Cloud computing (i.e. services provided over the internet as opposed to physical data storage facilities) enables organisations to collect and store large volumes of data.
Data collection and processing. Technology can be used to process data at rapid rates, across multiple machines while producing real-time immediate insights.
Data analytics. Automation, artificial intelligence and other forms of machine learnings has the ability to identify patterns, make predictions and provide recommended actions.
Practical guidance
Using technology in this way presents increased risks to organisations. These include regulatory risks, such as protecting individuals privacy rights and ensuring sensitive data is held securely and sufficiently protected against cyber-attacks. Key steps we recommend that organisations take now include:
Undertake data protection impact assessments where personal data is being used in a defence context. This will be key to ensuring a privacy by design approach is adopted from the outset and will help organisations to understand the types of personal data being used and balance the rights of individuals against organisations' aims.
Consider whether any improvements to cybersecurity can be made. For example, increased network segmentation and user logging enhanced encryption.
Identify what AI systems you are using and ensure you have an appropriate governance framework in place. This should be an ongoing exercise, as the AI systems (and way organisations use them) develop and advance. This should also consider what laws apply, for example, if the EU AI Act applies, is a 'conformity assessment' required? If so, this can potentially be undertaken alongside a data protection impact assessment to streamline the process.



