Clandestine cell system


A clandestine cell system is a method for organizing a group of people such as resistance fighters, sleeper agents, or terrorists so that such people can more effectively resist penetration by an opposing organization.
In a cell structure, each of the small group of people in the cell only know the identities of the people in their cell. Thus, a cell member who is apprehended and interrogated will not likely know the identities of the higher-ranking individuals in the organization.
The structure of a clandestine cell system can range from a strict hierarchy to an extremely distributed organization, depending on the group's ideology, its operational area, the communications technologies available, and the nature of the mission.
This sort of organizational structure is also used by criminal organizations, undercover operations, and unconventional warfare units led by special forces.

Covert operations vs. clandestine operations

and clandestine operations are not the same when it comes to tradecraft. The modern NATO definition of a covert operation says the identity of the sponsor is concealed, but in a clandestine operation the operation itself is concealed from the participants. Put differently, clandestine means "hidden", and covert means "deniable"—that is to say that the sponsor of a covert action is sufficiently removed from it that the sponsor can claim ignorance in the event the plot is discovered.
A sleeper cell refers to a cell, or isolated grouping of sleeper agents, that lies dormant until it receives orders or decides to act.

History

World War II French Resistance

In World War II, Operation Jedburgh teams parachuted into occupied France to lead unconventional warfare units. They were composed of two officers – one American or British, and the other French, the latter preferably from the area into which they landed – and a third member who was a radio operator.
Especially through the French member, they would contact trusted individuals in the area of operation, and ask them to recruit a team of trusted subordinates. If the mission was sabotage, reconnaissance, or espionage, there was no need to meet in large units. If the team was to carry out direct action it would be necessary to assemble into larger units for combat. Even then, the hideouts of the leadership were known only to subcell leaders. The of the Jedburgh team came from its known affiliation with Allied powers, and it was a structure more for unconventional warfare than for truly clandestine operations.

National Front for the Liberation of South Vietnam

Also known as the Viet Cong, this organization grew from earlier anticolonial groups fighting the French and from anti-Japanese guerrillas during World War II.
Its command, control, and communication techniques derived from the experiences of these earlier insurgent groups. The group had extensive support from North Vietnam, and, indirectly, from the Soviet Union. It had parallel political and military structures, often overlapping. See Viet Cong and PAVN strategy and tactics.
The level consisted of three-person cells who operated, and engaged in the sort of self-criticism common, as a bonding method, to Communist organizations.

Provisional Irish Republican Army

The modern Provisional Irish Republican Army has a history going back to Irish revolutionary forces in the early 20th century. It has little control. Its doctrine and organization have changed over time, as political, technological, and cultural situations have changed in Ireland.
Officially, the PIRA was hierarchical, but as British security forces became more effective it changed to a semiautonomous model for its operational and for certain of its support cells. Its leadership saw itself as guiding and as building consensus. The lowest-level cells, typically of 2–5 people, tended to be built from people with existing personal relationships. British counterinsurgents could understand the command structure, but not the workings of the operational cells.
The had an extensive network of inactive or sleeper cells, so it could summon new ad hoc organizations for any specific operation.

Parallel organizations

The NLF and PIRA, as well as other movements, have chosen to have political and military organizations. In the case of the NLF, except for some individuals with sanctuary in North Vietnam, people in the political organization could not be overt during the Vietnam War. After the war ended, surviving NLF officials held high office.
In the case of the PIRA, its political wing, Sinn Féin, became increasingly overt, and then a full participant in politics. Hamas and Hezbollah also have variants of overt political/social service and covert military wings.
Once an active insurgency began, the secrecy freedom of action, distort information about goals and ideals, and restrict communication within the insurgency. In such a split organization, public issues can be addressed overtly while military actions are kept covert and intelligence functions stay clandestine.

External support

Many cell systems receive support from outside the cell. This can include leaders, trainers, and supplies, or a safe haven for overt activities.
External support need not be overt. Certain Shi'a groups in Iraq, for example, receive assistance from Iran, but this is not a public position of the government of Iran, and may even be limited to factions of that government. Early U.S. support to the Afghan Northern Alliance against the Taliban used clandestine operators from the CIA and United States Army Special Forces. As the latter conflict escalated, U.S. participation became overt.
Note that both unconventional warfare and foreign internal defense may be covert and use cellular organization.
In a covert counterinsurgency mission, only selected host nation leaders are aware of the foreign support organization. Under Operation White Star, for example, U.S. personnel gave covert counterinsurgency assistance to the Royal Lao Army starting in 1959, this became overt in 1961, and finally ceased operations in 1962.

Models of insurgency and associated cell characteristics

Different kinds of insurgency differ in where they place clandestine or covert cells. Also, when certain types of insurgency grow in power, they deemphasize the cell system. They may still use cells for leadership security, but if overt violence by organized units becomes significant, cells become less important. In Mao's three-stage doctrine, cells are still useful in Phase II to give cover to part-time guerillas, but as the insurgency creates full-time military units in Phase III, the main units become the focus, not the cells.
Different varieties of insurgency place their cells differently with respect to the existing government. The U.S. Army Field Manual FM3-07 distinguishes between varieties of insurgencies. Drawing on this work, Nyberg describes four types of cell system :
  1. Traditional: The slowest to form, these are typically indigenous insurgencies that begin with limited goals. These are more secure than others, as they tend to form from people with preexisting social, cultural, or family ties. The insurgents resent a government that has failed to recognize tribal, racial, religious, or linguistic groups. They "perceive that the government has denied their rights and interests and work to establish or restore them. They seldom seek to overthrow the government or control the whole society; however, they frequently attempt to withdraw from government control through autonomy or semiautonomy." The Mujahideen in Afghanistan and the Kurdish revolt in Iraq are examples of this traditional pattern of insurgency. al-Qaeda generally operates in this mode, but if they become strong enough in a given area, they may change to the mass-oriented form.
  2. Subversive: These are usually driven by an organization that contains at least some of the governing elite, some being sympathizers already in government, and others who penetrate the government. When they use violence, it has a specific purpose, such as coercing voters, intimidating officials, and disrupting and discrediting the government. Typically, there is a political arm that directs the military in planning carefully coordinated violence. "Employment of violence is designed to show the system to be incompetent and to provoke the government to an excessively violent response which further undermines its legitimacy." The Nazi rise to power, in the 1930s, is another example of subversion. Nazi members of parliament and street fighters were hardly clandestine, but the overall plan of the Nazi leadership to gain control of the nation was hidden. A subversive insurgency is suited to a more permissive political environment which allows the insurgents to use both legal and illegal methods to accomplish their goals. Effective government resistance may convert this to a critical-cell model.
  3. Critical-cell: These come into play when the political climate becomes less permissive than one that allowed. While other cell systems try to form intelligence cells within the government, this type sets up "shadow government" cells that can seize power once the status quo is overthrown. This model includes the classic coup d'etat, and often tries to minimize violence. Examples include the Sandinista takeover of an existing government weakened by external popular revolution. "Insurgents also seek to infiltrate the government's institutions, but their object is to destroy the system from within." Clandestine cells form inside the government. "The use of violence remains covert until the government is so weakened that the insurgency's superior organization seizes power, supported by the armed force. One variation of this pattern is when the insurgent leadership permits the popular revolution to destroy the existing government, then emerges to direct the formation of a new government. Another variation is seen in the Cuban revolution and is referred to as the foco insurgency. This model involves a single, armed cell which emerges in the midst of degenerating government legitimacy and becomes the nucleus around which mass popular support rallies. The insurgents use this support to establish control and erect new institutions."
  4. Mass-oriented: While the subversive and -cell systems work from within the government, the mass-oriented system builds a government completely outside the existing one, with the intention of replacing it. Such "insurgents patiently construct a base of passive and active political supporters, while simultaneously building a large armed element of guerrilla and regular forces. They plan a protracted campaign of increasing violence to destroy the government and its institutions from the outside. They have a well-developed ideology and carefully determine their objectives. They are highly organized and effectively use propaganda and guerrilla action to mobilize forces for a direct political and military challenge to the government." The revolution that produced the People's Republic of China, the American Revolution, and the Shining Path insurgency in Peru are examples of the mass-oriented model. Once established, this type of insurgency is extremely difficult to defeat because of its great depth of organization.

    Classic models for cell system operations

The examples here will use CIA cryptonyms as a naming convention used to identify members of the cell system. Cryptonyms begin with a two-letter country or subject name, followed by more letters so as to form an arbitrary word, such as "BERRY", "BEN", and "BEATLE" in the example below.

Operations under official cover

Station BERRY operates, on behalf of country B, in target country BE. The station has three case officers and several support officers. Case officer BETTY supervises the local agents BEN and BEATLE. Case officer BESSIE supervises BENSON and BEAGLE.
Some recruits, due to the sensitivity of their position or their personalities not being appropriate for cell leadership, might not enter cells but be run as singletons, perhaps by other than the recruiting case officer. In this example, asset BARD is singleton, who is a joint asset of the country B, and the country identified by prefix AR. ARNOLD is a case officer from the country AR embassy, who knows only the case officer BERTRAM and the security officer BEST. ARNOLD does not know the station chief of BERRY or any of its other personnel. Other than BELL and BEST, the Station personnel only know BERTRAM as someone authorized to be in the Station, and who is known for his piano playing at embassy parties. He is as Cultural Attache, in a country that has very few pianos. Only the personnel involved with BARD know that ARNOLD is other than another diplomat.
In contrast, BESSIE and BETTY know one another, and procedures exist for their taking over each other's assets in the event one of the two is disabled.
Some recruits, however, would be qualified to recruit their own subcell, as BEATLE has done. BETTY knows the identity of BEATLE-1 and BEATLE-2, since he or she had them checked by headquarters counterintelligence before they were recruited.

Clandestine presence

The diagram in this section shows that two teams, ALAN and ALICE, have successfully entered an area of operation, the country coded AL, but are only aware of a pool of potential recruits, and have not yet actually recruited anyone. They communicate with one another only through headquarters, so compromise of one team will not affect the other.
Assume that in team ALAN, ALASTAIR is one of the officers with local contacts, and might recruit two cell leaders: ALPINE and ALTITUDE. The other local officer in the team, ALBERT, recruits ALLOVER. When ALPINE recruited two subcell members, they would be referred to as ALPINE-1 and ALPINE-2.
ALPINE and ALTITUDE only know how to reach ALASTAIR, but they are aware of at least some of other team members' identities should ALASTAIR be unavailable, and they would accept a message from ALBERT. Most often, the identity of the radio operator may not be shared. ALPINE and ALTITUDE, however, do not know one another. They do not know any of the members of team ALICE.
The of the subcell structure came from the recruitment process, originally by the case officer and then by the cell leaders. The cell leader might propose subcell member names to the case officer, so the case officer could have headquarters run a background check on the potential recruit before bringing them into the subcell. In principle, however, the subcell members would know ALPINE, and sometimes the other members of the ALPINE cell if they needed to work together; if ALPINE-1 and ALPINE-2 had independent assignments, they might not know each other. ALPINE-1 and ALPINE-2 certainly would not know ALASTAIR or anyone in the ALTITUDE or ALLOVER cells.
As the networks grow, a subcell leader might create her or his own cell, so ALPINE-2 might become the leader of the ALIMONY cell.

Fault-tolerant cellular structures

Modern communications theory has introduced methods to increase fault tolerance in cell organizations. Game theory and graph theory have been applied to the study of optimal covert network design.
In the past, if cell members only knew the cell leader, and the leader was neutralized, the cell was cut off from the rest of the organization. But if a traditional cell had independent communications with the foreign support organization, headquarters might be able to arrange its reconnection. Another method is to have impersonal communications as "side links" between cells, such as a pair of dead drops, one for Team ALAN to leave "lost contact" messages to be retrieved by Team ALICE, and another dead drop for Team ALICE to leave messages for Team ALAN.
These links, to be used only on, do not guarantee a contact. When a team finds a message in its emergency drop, it might do no more than send an alert message to headquarters. Headquarters might determine, through SIGINT or other sources, that the enemy had captured the leadership and the entire team, and order the other team not to attempt contact. If headquarters can have reasonable confidence that there is a communications failure or partial compromise, it might send a new contact to the survivors.
When has electronic communications, such as the Internet, it has a much better chance of eluding surveillance and getting emergency instructions than by using a dead drop that can be under physical surveillance.

Non-traditional models, exemplified by al-Qaeda

If the al-Qaeda Training Manual is authentic, it demonstrates that Eastern cell structures may differ from the Western mode. Al-Qaeda's minimal core leadership group can be viewed as a ring or chain network, with each leader/node heading their own particular hierarchy.
Such networks function by having their sub-networks provide information and other forms of support, while the core group supplies 'truth' and decisions/directions. Trust and personal relationships are an essential part of the Al-Qaida network. Cell members are trained as 'replaceable' units and 'vetting' of members occurs during the training period under the observation of the core group.
Cells of this structure are an internal leadership core. Superficially, this might be likened to a Western cell structure that emanates from a headquarters, but the Western centrality is bureaucratic, while structures in other non-Western cultures build on close personal relationships, often built over years, perhaps involving family or other in-group linkages. Such in-groups are thus extremely hard to infiltrate. Still, it may be possible for an in-group to be compromised through COMINT or, in rare cases, by compromising a member.
The core group is a ring, superimposed on an. Each member of the core forms another hub and spoke system, the spokes leading to [|infrastructure cells] under the supervision of the core group member, and possibly to operational groups that the headquarters supports. In an organization like this, there is a point at which the operational cell becomes autonomous of the core.
Osama bin Laden, in this model, had the responsibility of commanding the organization and being the spokesman on propaganda messages distributed by the propaganda cell. The other members of the core each command one or more infrastructure cells.
While enhances security, it can limit flexibility and the ability to scale the organization. The in-group values that tie the cell together initially, shared cultural and ideological values, are not sufficient to create additional loyalty to a bureaucratic process.
"Members of the core group are under what could be termed 'positive control'—long relationships and similar mindsets make 'control' not so much of an issue, but there are distinct roles, and position determines authority, thus making the core group a hierarchy topologically."
In the illustration of the core shown here, each member knows how to reach two other members, and also knows the member he or she considers her or his ideological superior. Solid lines show basic communication, dotted red arrows show, and dotted blue arrows show a second level of ideological respect.
If Osama, the most respected, died, the core would reconstitute itself. While different members each have an individual ideological guide, and these are not the same for all members, the core would reconstitute itself with Richard as most respected.
Assume there are no losses, and Osama can be reached directly only by members of the core group. Members of outer cells and support systems might know him only as "the Commander", or, as in the actual case of al-Qaeda, Osama bin Laden's face is recognizable worldwide, but only a few people knew where he was or even how to contact him.

Infrastructure cells

Any clandestine or covert service, especially a non-national one, needs a variety of technical and administrative functions, such as:
  1. Forged documents and counterfeit currency
  2. Apartments and hiding places
  3. Communication means
  4. Transportation means
  5. Information
  6. Arms and ammunition
  7. Transport
  8. Psychological operations
  9. Training
  10. Finance
A national intelligence service
has a support organization to deal with services like finance, logistics, facilities, information technology, communications, training, weapons and explosives, medical services, etc. Transportation alone is a huge function, including the need to buy tickets without drawing suspicion, and, where appropriate, using private vehicles. Finance includes the need to transfer money without coming to the attention of financial security organizations.
Some of these functions, such as finance, are far harder to operate in remote areas than in cities with large numbers of official and unofficial financial institutions and the communications to support them. If the financial office is distant from the remote headquarters, there is a need for couriers, who must be trusted to some extent, but who may not know the contents of their messages or the actual identity of the sender and/or receiver. The couriers, depending on the balance among type and size of message, security, and technology available, may memorize messages, carry audio or video recordings, or hand-carry computer media.
These cells are socially embedded, structurally embedded, functionally embedded, and knowledge base-specific. Such cells are probably subjected to a mixture of both positive and negative control.
MemberInfrastructure commanded
RichardFinance
AntonMilitary training/operations 1
HassanMilitary training/operations 2
DavidTransportation
KimCommunications and propaganda

The leader of a military cell is responsible for training its members, and, when an operation is scheduled, selecting the operational commander, giving her or him the basic objective and arranging whatever support is needed, and then releasing her or him from tight control to execute the. Military leaders might have direct, possibly one-way, communications with their cells, or they might have to give Kim the messages to be transmitted, by means that Anton and Hassan have no need to know.
The security structure also means that Hassan does not know the members of Anton's cells, and Kim may know only ways to communicate with them but not their identity.
Kim operates two systems of cells, one for secure communications and one for propaganda. To send out a propaganda message, Osama must pass it to Kim. If Kim were compromised, the core group might have significant problems with any sort of outside communications.
Terrorist networks do not to other cell systems that regularly report to a headquarters. The apparent al-Qaeda methodology, of letting operational cells decide on their final dates and means of attack, exhibits that could easily be used for an indications checklist appropriate for a warning center. Such lists depend on seeing a pattern to give a specific warning.
Note that Hassan has two subordinates that have not yet established operational cells. These subordinates can be considered sleepers, but not necessarily with a sleeper cell.

Operational cells

For each mission, one or more operational cells. If al-Qaeda uses its typical modus operandi of multiple concurrent attacks, there may be an operational cell for each target location. Some operations may need support cells in the operational area. For example, it may be more secure to have a local cell build bombs, which will be delivered by cells coming from outside the area.
U.S. special operations forces sometimes wait for presidential authorization to make an attack, or even to move to staging areas. A country would have to face the consequences of an inappropriate attack, so it may tend to be overcautious, whereas a terror network might merely shrug at the world being upset. Assuming that the al-Qaeda operational technique is not to use, their operations may be more also more unpredictable for counterterror forces. If their cells need constant control, there are communications links that might be detected by SIGINT, and if their command can be disrupted, the field units could not function. Since there is fairly little downside for terrorists to attack out of synchronization with other activities, the lack of positive control becomes a strength of their approach to cell organization.
Operational cells need to have continuous internal communication; there is a commander, who may be in touch with infrastructure cells or, less likely from a security standpoint, with the core group.
Al-Qaeda's approach differs from that of earlier terrorist organizations:
In the above graphic, note the indirect support network controlled by Richard's subcell.
"While Al-Qaida has elements of the organization designed to support the structure, but such elements are insufficient in meeting the needs of such an organization, and for security reasons there would be redundant and secondary-/tertiary-networks that are unaware of their connection to Al-Qaida. These networks, primarily related to fundraising and financial activities, as well as technology providers, are in a 'use' relationship with Al-Qaida—managed through cut-outs or individuals that do not inform them of the nature of activities, and that may have a cover pretext sufficient to deflect questions or inquiry."

A possible countermeasure

In 2002, U.S. News & World Report said that American intelligence was beginning to acquire intelligence on al-Qaida indicating that "nce thought nearly impossible to penetrate, al-Qaeda is proving no tougher a target than the KGB or the Mafia—closed societies that took the U.S. government years to get inside. 'We're getting names, the different camps they trained at, the hierarchy, the infighting,' says an intelligence official. 'It's very promising.'" The report also said that the collected data has allowed the recruiting of informants.
Writing in the U.S. Army journal Military Review, David W. Pendall suggested that a "catch-and-release program for suspected operatives might create reluctance or distrust in such suspects and prevent them from further acts or, perhaps more important, create distrust in the cell leaders of these individuals in the future." The author noted the press release describing Ramzi bin al-Shibh's cooperation with the United States is "sure to prevent reentry into a terrorist cell as a trusted member and most likely limits the further trust and assignments of close cell associates still at large. The captor would determine when to name names and when to remain silent." Indeed, once intelligence learns the name and characteristics of an at-large adversary, as well as some sensitive information that would plausibly be known to him, a news release could be issued to talk about his cooperation. Such a method could not be used too often, but, used carefully, could disturb the critical trust networks. The greatest uncertainty might be associated with throwing doubt onto a key member of an operational cell that has gone autonomous.