Playbook

The 90-Day Disinformation Preparedness Plan

You do not have to do everything at once

The scale of the disinformation problem can be paralysing, which is its own kind of risk. Gartner’s Dave Aron, co-author of World Without Truth, is pragmatic about it: leaders “can’t do everything now,” and “probably haven’t got the money and time to do everything now with so many other priorities.” The goal for the first quarter is not coverage. It is momentum. Here are his four moves.

Step 1: Stand up a trust council

Aron’s first step is governance, not tooling: “standing up a trust council.” Make one cross-functional body accountable for disinformation, spanning security, communications, brand, risk, legal and regulatory. It can be “part of an existing committee like an operating committee or a strategy committee,” or a separate one. The point is that someone owns this before an attack forces the question. (We go deeper in who should own disinformation.)

Step 2: Ground your critical content

Next, protect what you publish. Aron suggests you “identify some important, critical content items and start trying some of these grounding techniques like C2PA,” with quarterly or annual reports as the “classic example.” C2PA, the Coalition for Content Provenance and Authenticity, attaches a secure, verifiable label to content showing who created it, much like a nutrition label on food. Grounding your own highest-stakes content is the half of TrustOps you control directly.

Step 3: Put eyes on the market

You also need to see what is being said about you. Aron recommends, “if you have budget,” tasking “one or two people researching and experimenting with all these new tools and techniques,” and trying “some of the monitoring services” that “monitor all the narratives in the market and inform you if there are any that look dangerous.” He notes the scale of investment already flowing in: a Gartner survey found “three-quarters of a billion dollars being spent by venture capitalists on 75 startups and scaleups in this space.” This is the debunking half of TrustOps: knowing when a narrative is turning against you, early enough to respond.

Step 4: Educate and pre-bunk

Finally, prepare your people. Aron points to “education”, training staff on “how disinformation attacks could happen”, which he calls pre-bunking: “get them ready for disinformation attacks before they happen.” Like a phishing drill for narratives, pre-bunking builds the reflex to question a too-perfect video, a sudden coordinated push, or a story that arrives pre-loaded with outrage.

If you only do one thing

Start with the council. Every other step needs an owner to fund it, prioritise it and act on it. Without that body, monitoring produces alerts no one is accountable for, and grounding and education stall. Governance first, then eyes on the market, then the muscle memory.

Where AI Uniti fits

Step 3 is where narrative threat intelligence earns its place. Signal is the monitoring layer Aron describes: it watches narratives across platforms, scores the coordination behind them, and raises explainable alerts 6 to 12 hours before content-led monitoring sees a spike, the window in which a trust council can still change the outcome. PulseCheck identifies the inauthentic accounts driving a campaign. The method is behavioural, reading coordination rather than content, which is what gives a council a verdict it can defend. The council decides; Signal gives it something to decide on in time.

Step 3 is the one you do not have to build from scratch. See how Signal gives your trust council eyes on coordinated narrative attacks 6 to 12 hours early, or book a 15-minute demo.

Frequently Asked Questions

What should we do about disinformation in the next 90 days?

Per Gartner's Dave Aron, four things: stand up a cross-functional trust council, ground your critical content with provenance standards like C2PA, task one or two people with evaluating monitoring tools, and run pre-bunking education so staff recognise attacks early.

What is pre-bunking?

Pre-bunking is educating people about how disinformation attacks work before they happen, so they recognise and resist them, the narrative equivalent of a phishing drill.

What is C2PA?

C2PA (Coalition for Content Provenance and Authenticity) is a standard for attaching a secure, verifiable label to digital content showing its provenance and authenticity, like a nutrition label. Grounding critical content such as annual reports is an early, practical step.

What is the first step?

The trust council. Every other step needs an accountable owner to fund and act on it. Governance first.

See how AI Uniti detects coordinated narratives 6 to 12 hours before traditional monitoring.