Organization Security: Protecting Your Org from Spies, Scams, and Sabotage
Protect your Star Citizen organization from spies, scams, and internal sabotage. Learn operational security, vetting procedures, and counterintelligence…
As Star Citizen's gameplay deepens, so do the threats to your organization. Rival orgs send spies, scammers target your members, and disgruntled players can sabotage operations from within. Operational security isn't paranoia — it's preparation. Here's how to protect your org.
The Threat Landscape
Understand what you're defending against:
Espionage:
- Rival orgs planting members to gather intel
- Monitoring your operations and fleet composition
- Stealing tactical plans and schedules
- Mapping your alliance network
- Identifying your key members and weaknesses
Scams and Social Engineering:
- Fake alliance proposals to gather information
- Phishing for Discord/RSI credentials
- "Too good to be true" trading deals
- Impersonation of leadership
- Manipulation of new or naive members
Internal Sabotage:
- Disgruntled members leaking information
- Intentional disruption of operations
- Theft of org resources or credits
- Spreading discord and drama
- Recruiting members away to rival orgs
External Attacks:
- Coordinated griefing campaigns
- Reputation attacks on social media
- DDoS or technical harassment
- Mass reporting abuse
- Alliance manipulation
Operational Security (OPSEC) Basics
Protect your information:
Information Classification:
- Public: Org name, general focus, recruitment info
- Internal: Member roster, event schedules, general plans
- Confidential: Tactical plans, alliance details, financial data
- Restricted: Leadership discussions, security matters, intelligence
Need-to-Know Principle:
- Share information only with those who need it
- Don't over-share in general channels
- Keep tactical plans in officer channels
- Restrict financial data to leadership
- Compartmentalize sensitive operations
Communication Security:
- Use private channels for sensitive discussions
- Don't discuss plans in public Discord servers
- Be careful what you post on social media
- Assume public channels are monitored
- Use SCORG's role-based permissions to control access
Vetting New Members
Your first line of defense:
Application Review:
- Check RSI profile history and age
- Look for multiple org memberships
- Research their reputation in the community
- Check for connections to rival organizations
- Verify claims about experience and ships
Interview Process:
- Voice interview required (confirms they're real)
- Ask about previous organizations
- Discuss their goals and expectations
- Gauge cultural fit and attitude
- Trust your instincts about red flags
Probationary Period:
- 2-4 weeks minimum before full access
- Limited channel access during probation
- No access to confidential information
- Monitored participation and behavior
- Gradual trust building
Red Flags:
- Excessive interest in your operations or plans
- Asking detailed questions about fleet composition
- Reluctance to voice chat or share RSI profile
- Previous membership in rival organizations
- Too eager to access restricted information
- Vague or inconsistent backstory
Access Control
Limit damage from compromised accounts:
Discord Permissions:
- Role-based channel access
- New members get minimal permissions
- Gradually increase access with trust
- Separate channels for different security levels
- Regular permission audits
SCORG Permissions:
- Use custom roles to control page access
- Restrict sensitive features to trusted members
- Audit who has access to what
- Remove access immediately when members leave
- Don't give admin access unnecessarily
Information Compartmentalization:
- Operation plans shared only with participants
- Financial data limited to leadership
- Alliance details restricted to diplomats
- Intelligence shared on need-to-know basis
- No single person has access to everything
Counterintelligence
Detect and neutralize threats:
Monitoring:
- Watch for unusual behavior patterns
- Note members who ask too many questions
- Track information that appears in rival orgs
- Monitor for unauthorized screenshots or recordings
- Pay attention to members who are suddenly less active
Investigation:
- Don't accuse without evidence
- Gather information quietly
- Consult with trusted leadership
- Document suspicious behavior
- Act decisively when evidence is clear
Response:
- Remove compromised members immediately
- Change any compromised information
- Notify affected members and allies
- Review and strengthen security procedures
- Learn from the incident
Protecting Against Scams
Educate your members:
Common Scams:
- "I'll double your credits" schemes
- Fake ship sales or trades
- Phishing links disguised as RSI/Discord
- Impersonation of CIG staff or streamers
- "Investment opportunities" in fake ventures
Prevention:
- Educate members about common scams
- Establish org policies for trades and transactions
- Use trusted intermediaries for large deals
- Verify identities before sharing sensitive info
- Report scams to leadership immediately
If Scammed:
- Document everything
- Report to CIG if applicable
- Warn org members
- Update security procedures
- Support affected members
Leadership Security
Protect your command structure:
Account Security:
- Strong, unique passwords for all accounts
- Two-factor authentication everywhere
- Don't share account credentials
- Regular password updates
- Secure recovery options
Succession Planning:
- Multiple people with admin access
- Documented procedures for leadership transition
- Backup communication channels
- Emergency contact information
- Clear chain of command
Decision Security:
- Major decisions discussed in secure channels
- Verify identity before acting on unusual requests
- Don't rush decisions based on pressure
- Consult with multiple officers
- Document decisions and rationale
Building a Security Culture
Make security everyone's responsibility:
Education:
- Regular security briefings
- Share examples of threats (anonymized)
- Teach basic OPSEC to all members
- Update training as threats evolve
- Make security part of onboarding
Reporting:
- Easy, anonymous reporting mechanism
- No punishment for false alarms
- Quick response to reports
- Follow-up on all concerns
- Recognize good security behavior
Balance:
- Don't create a paranoid atmosphere
- Security should enable, not restrict
- Trust is still essential for community
- Proportional response to threats
- Fun and security can coexist
Incident Response Plan
When something goes wrong:
Immediate Actions:
- Assess the scope of the breach
- Contain the damage (remove access, change info)
- Notify affected leadership
- Preserve evidence
- Begin investigation
Short-Term Response:
- Communicate with org (appropriate level of detail)
- Implement temporary security measures
- Support affected members
- Coordinate with allies if needed
- Continue investigation
Long-Term Recovery:
- Complete investigation and document findings
- Implement permanent security improvements
- Update policies and procedures
- Train members on new measures
- Monitor for recurring threats
Conclusion
Organization security is an ongoing process, not a one-time setup. By implementing strong vetting, access controls, monitoring, and education, you create an environment where your members can focus on enjoying the game while knowing their community is protected.
The best security is invisible — your members feel safe and trusted while threats are quietly identified and neutralized before they cause harm.
Stay vigilant, citizens. The verse is full of opportunities — and opportunists.