The Discipline of Disclosure: Why Security Culture Has to Catch Up With the Sharing Generation
For much of my career as a security affairs writer, I worked around people whose instinct was not to talk.
In intelligence, counter-terrorism, specialist policing and the military, discretion was more than a rule imposed by an employer. It was part of the culture.
At one stage I held trusted-journalist status in certain areas of intelligence and policing. That sometimes meant being told things that were not intended for publication. I might need to know something to understand an operation, place an event in context, avoid drawing the wrong conclusion or simply know that there was more to a story than could safely be reported.
Access did not confer a right to publish.
Knowing was not the same as disclosing.
That arrangement depended upon judgement and trust on both sides. The officer had to judge what could be shared safely. The journalist had to understand the difference between information provided for publication, information provided for background and information provided simply to aid understanding.
It belonged to an information culture that is rapidly disappearing.
That presents security organisations with a problem considerably larger than social media policy.
The generation that kept quiet
The traditional security culture was built by generations for whom discretion came relatively naturally.
Many of the soldiers, intelligence officers and police officers I encountered over the years were what I think of as natural-born stoics. They did not expect every experience to have an audience. They did not routinely document their lives. Nor did they regard an interesting experience as something that acquired greater value by being shared with strangers.
The technology reinforced those habits.
Taking a photograph required a camera. Publishing one required considerably more effort. Reaching a large audience generally meant passing through a newspaper, publisher or broadcaster.
Disclosure therefore usually involved a deliberate act.
Even after leaving service, the prevailing convention in some organisations remained remarkably simple: we don't talk about what we did.
That culture had obvious shortcomings. It could sometimes be used to conceal institutional embarrassment as readily as legitimate secrets. But as a security mechanism it had one enormous advantage.
The individual arrived with many of the required social habits already installed.
That can no longer be assumed.
The sharing generation
Someone entering the military, policing or intelligence community today may have spent most of his or her life in an entirely different information culture.
Photographing experiences is normal. Sharing them is normal. Commenting publicly is normal. Maintaining an online identity is normal. Recording where you have been, what you have done and who you were with can happen almost without conscious thought.
The smartphone has collapsed distinctions that once mattered.
It is simultaneously a camera, audio recorder, video camera, notebook, communications system, archive, navigation device, location tracker and global publishing platform.
As a result, disclosure no longer necessarily requires a deliberate decision to disclose.
I have encountered cases where something as mundane as the metadata attached to a selfie has revealed the location of a sensitive military installation.
The person does not have to think: I am going to reveal sensitive information.
He takes a photograph.
The disclosure is a consequence.
That is a fundamentally different security problem.
Some years ago I worked on a project that involved two of the team taking a map to the Pentagon for a meeting with an admiral. When he saw the map, he asked if they knew what it was a map of. They said it was the journey of a US nuclear submarine around the world. The admiral, pointing out that failure to disclose could lead to arrest, demanded where the information had come from. It was publicly available information. They had developed a data-scraping method that allowed them to gather metadata from selfies sailors had been posting on social media each time the submarine surfaced. Other photos revealed weapons locations in Iraq, and one where a woman had posted a photo from work in a nuclear installation, which was used to trace where her children went to school. Anyone see a security problem there?
You cannot order culture backwards
The conventional institutional response is often to prohibit more things.
Issue another instruction. Add another paragraph to the security policy. Restrict social-media use. Remind people of their obligations.
Some of that is necessary.
But it does not address the underlying problem.
We cannot take a generation raised in a sharing culture and turn it into the generation that preceded it simply by telling people not to share.
Nor should the objective be to discard the older virtues. Discretion, restraint, loyalty, and an understanding that not everything one knows belongs to oneself remain essential to security work.
The challenge is to translate those virtues into a radically different information environment.
That requires moving from a culture of silence to a discipline of disclosure.
The difference is substantial.
A culture of silence depends heavily upon an internalised norm:
We don't talk about what we do.
A discipline of disclosure requires conscious professional judgement:
What do I know? Why do I know it? Who owns or controls it? What may I disclose? To whom? Through what channel? Under whose authority? And what are the consequences?
The second approach is more complicated.
It also better reflects the world we now inhabit.
An Australian intelligence chief provides an interesting example
This is what makes the current case of Mike Burgess, Director-General of the Australian Security Intelligence Organisation, worth examining.
Burgess has headed ASIO since 2019. His second term has included espionage and foreign-interference concerns, the December 2025 Bondi terrorist attack and the subsequent Royal Commission into Antisemitism and Social Cohesion.
Against that background, Burgess has spoken at length for Bondi Terror: The Tragedy, the Courage, the Aftermath, by Sharri Markson and Alex Ryvchin.
The distinction is important.
Burgess has not written a memoir. He has given an extensive on-the-record interview to other authors.
Public reporting around the book includes his account of ASIO's warnings about the deteriorating security environment, antisemitism and politically motivated violence, as well as threat assessments and ASIO's record of disrupting terrorist plots.
Yet Burgess talking does not mean ASIO has stopped keeping secrets.
That is precisely why the case is interesting.
Not secret or public, but layers of disclosure
The material surrounding the case reveals something more sophisticated than the familiar choice between SECRET and PUBLIC.
Some information is publicly available through interviews, statements, the book and open hearings.
More detailed intelligence and internal assessments can be examined within the Royal Commission process without necessarily being made immediately available to everyone.
And sources, methods, capabilities and sensitive operational material remain protected.
There are, in other words, layers of disclosure.
The process might be represented as: Privileged knowledge → institutional assessment → authorisation or declassification → controlled access → external intermediary → publication
But not everything travels along that chain.
Information can stop at any point.
That is the critical distinction between disclosure and disciplined disclosure.
The old trusted-journalist relationship worked on the same principle
Seen this way, the idea is nothing particularly revolutionary.
The trusted-journalist arrangements I encountered operated according to much the same principle, albeit less formally.
A journalist could possess information without being permitted, expected or sometimes even inclined to publish it.
That knowledge could nevertheless be useful.
It could stop a journalist from publishing something dangerously wrong. It could provide context. It could establish the significance of apparently unrelated events. And sometimes it could simply tell you that you did not yet know enough to write the story.
An important distinction exists between access to information and the right to exploit it.
That distinction becomes increasingly important when security intersects with publishing, television, film, podcasts and social media.
Access is not ownership.
Knowledge is not necessarily intellectual property.
Intellectual-property rights are not security clearances.
And possessing information does not necessarily confer the right to disclose it.
These distinctions are easily blurred when everyone carries a publishing house in his pocket.
Silence has risks too
Another reason is that simply trying to preserve the old culture of silence will not work.
Silence does not preserve an empty space.
Someone else fills it.
Journalists will write the stories. Academics will produce papers. Lawyers will construct arguments. Politicians will make claims. Documentary makers will make programmes. Dramatists will create characters.
Eventually historians will write the history.
If those possessing first-hand knowledge remain permanently silent, that does not prevent the story being told.
It cedes much of the story's authorship to other people.
For organisations involved in intelligence, policing and military operations, that can have profound consequences. Outsiders are necessarily working with incomplete information. Speculation hardens into accepted wisdom. Dramatisation becomes popular memory. Repeated claims become "facts" because nobody capable of correcting them has entered the conversation.
Operational secrecy and permanent historical silence are not the same thing.
A mature disclosure system needs to recognise the difference.
Controlled disclosure can preserve the record
The Burgess case illustrates this particularly well.
By speaking publicly, Burgess can put ASIO's position into the historical record. He can describe the warnings given, explain the wider threat environment, and point to attacks ASIO says it disrupted.
That account should not simply be accepted because it comes from the head of an intelligence service.
Accountability requires precisely the opposite.
The Royal Commission provides another layer in which evidence can be tested, including material that cannot necessarily be placed immediately into the public domain. Meanwhile, some information remains protected because disclosure would reveal capabilities, sources or sensitive operations.
The result is neither complete secrecy nor complete transparency.
It is a managed boundary between the two.
That strikes me as a much more useful model for the coming generation of security professionals.
The intellectual-property problem
There is also a commercial issue that deserves more attention.
Authentic security experience has value.
Publishers know it. Television producers know it. Streaming services know it. Journalists know it. Social-media platforms certainly know it.
First-hand testimony, archives, photographs, recordings, specialist knowledge and access can all contribute value to a commercial product.
But the person who possesses the experience does not necessarily possess unrestricted rights over everything associated with it.
Consider the different interests potentially involved in a single book or documentary.
The individual may possess memories and personal records. An institution may control documents or sensitive information. Other participants have privacy and legal interests. A journalist or author contributes research and narrative skill. A production company may finance development. A publisher or broadcaster supplies distribution. Copyright and contractual rights may arise in the resulting material.
Overlaying all of this may be secrecy legislation, employment obligations and national-security considerations.
Simply saying "it's my story" does not resolve those questions.
Neither does saying "you signed the Official Secrets Act".
A disciplined mechanism is needed between those two positions.
From prohibition to professional judgement
Security organisations need to reconsider what they are actually teaching people about disclosure.
"Don't post sensitive information online" is necessary advice.
It is nowhere near sufficient.
The next generation needs to understand information almost as a professional asset class. They need to recognise provenance, ownership, sensitivity, authority, access, attribution, intellectual property and downstream risk.
Most importantly, they need to understand that information can legitimately occupy different states.
Some information can be public.
Some can be shared with particular people for particular purposes.
Some can be released after review.
Some can be used without identifying its source.
Some can be preserved for later historical release.
And some must remain secret.
That requires judgement rather than obedience alone.
Preserve the virtue, change the mechanism
Whenever technology changes, there is a temptation to romanticise the world that preceded it.
I have considerable sympathy for the older culture of discretion. I spent enough of my career around it to understand its value.
But nostalgia is not a security policy.
At a meeting of senior police officers I moderated, during a break, a commander said: “You know the problem with these young blokes is that you can yell at them all f***ing day and they won’t move. Send them a text, and they spring into action.”
I replied, “Then stop yelling and send texts.”
When he looked nonplussed, I asked: “What do you want to do: change the way they communicate to your preferred style, or get them to do something?”
The young soldier carrying a smartphone is not going to become his grandfather because someone briefs him on communications.
The cultural environment has changed.
The task, then, is to preserve the virtue while changing the mechanism through which it is maintained.
The old system relied heavily upon a culture of discretion.
The new information environment requires a Discipline of Disclosure.
That does not mean encouraging people to talk.
Quite the opposite.
It means teaching them that disclosure is a professional act carrying legal, security, ethical, historical and sometimes commercial consequences.
It means replacing an unmanaged choice between silence and exposure with a system for deciding what may be disclosed, by whom, through which channel, under whose authority, with what protections and for whose benefit.
The natural-born stoics are disappearing.
The need for discretion is not.