Who Owns Disinformation? Build a Trust Council
Disinformation falls between the cracks
Ask who in your organisation owns disinformation, and you usually get a pause. Security assumes it is a communications problem. Communications assumes it is a security problem. Brand watches sentiment, legal watches liability, and the coordinated campaign moving against your share price or your reputation belongs to no one until it is already at scale.
That gap is the point. As Gartner’s Dave Aron, co-author of World Without Truth, puts it, disinformation “kind of falls between the cracks at the moment in the organisation.” Cyber security has an owner. Physical security has an owner. The integrity of the information your business consumes and publishes, the thing every other decision depends on, usually does not.
The first step is a trust council, not a new tool
Aron’s recommendation is deliberately unglamorous. Before you buy anything, you “need one governance body that takes responsibility for everything to do with disinformation.” He calls standing one up the first step in building TrustOps, the discipline Gartner defines for grounding the information you rely on and debunking the false narratives spread against you.
The council does not have to be a new committee. Aron notes it “could be a new body, or it could be a new line item on an existing body like an operating committee” or a strategy committee. The form matters less than the accountability: somewhere, someone owns this.
Who sits on it
A trust council only works if it is genuinely cross-functional, because coordinated disinformation crosses every internal boundary. Aron’s composition is broad on purpose: the CIO and CISO, but also marketing and branding for brand-reputation protection, risk management, regulatory, and PR and communications. Each sees a different face of the same threat, and none can counter it alone.
That breadth is also why the council is the natural home for the buying decision. The tools that detect coordinated narrative attacks serve security, comms and risk at once, so the body that funds and oversees them has to speak for all three.
You probably do not need a Chief Trust Officer
When a risk gets serious, the reflex is to appoint a new executive for it. Aron pushes back. Asked whether organisations need a Chief Trust Officer, his answer is that Gartner’s belief is “you don’t necessarily need that.” Adding another C-level officer, he says, “always seems to be a knee-jerk reaction.”
What you do need, in his words, is a trust council, “the one throat to choke around this topic.” The accountability has to be singular and clear. The title does not.
What the council owns: decide, communicate, educate
Singular accountability does not mean the council does everything itself. Aron is precise here: it is “responsible for everything to do with” disinformation, but “not necessarily doing everything.” Execution can be decentralised across the functions already in the room. What the council holds is the deciding, communicating and educating: setting policy, choosing and funding tools, defining metrics, and making sure the whole organisation understands the threat.
That last part matters more than it sounds. Much of the defence is preparation. Aron describes educating people on how disinformation attacks happen before they happen, a practice he calls pre-bunking, and the 90-day preparedness plan is one way to operationalise it. A council that only meets after an attack has already missed its job.
From council to capability
A trust council is the governance. The capability it funds is where narrative threat intelligence comes in. Grounding and debunking, the two halves of TrustOps, both need a way to see coordinated manipulation early and explain it credibly to the board, the regulator and the market.
This is the layer AI Uniti builds. Signal monitors narratives across platforms and raises explainable alerts on coordinated activity, typically 6 to 12 hours before content-led monitoring registers a spike, the window in which a council can still act. PulseCheck identifies the bots and inauthentic accounts behind a campaign on a bot-to-human spectrum. Unite combines those signals with AI agents to investigate and respond. The method underneath all three is behavioural: we read the coordination, not just the content, which is what makes a verdict hold up when a trust council has to defend a decision to the board.
A council without that capability can only react to what it reads in the press. A council with it can see the attack forming and answer for the response.
Standing up a trust council is the first step. Giving it eyes on coordinated attacks is the next. See how Signal surfaces coordinated narrative attacks 6 to 12 hours early, or book a 15-minute demo.
Frequently Asked Questions
What is a trust council?
A trust council is a cross-functional governance body accountable for an organisation's defence against disinformation. Gartner's Dave Aron describes it as the first step in building TrustOps, drawing in security, communications, brand, risk, legal and regulatory so that coordinated narrative threats have a single owner.
Do we need a Chief Trust Officer?
Not necessarily. Gartner's view, per Aron, is that appointing a new C-level officer is often a knee-jerk reaction. What an organisation needs is clear, singular accountability, the trust council as the one throat to choke, rather than a new title.
Does the trust council do all the work itself?
No. It is responsible for everything to do with disinformation, but not for doing everything. It owns the deciding, communicating and educating, setting policy, funding tools and defining metrics, while execution can be decentralised across existing functions.
How does a trust council relate to TrustOps?
TrustOps is the discipline of grounding the information you rely on and debunking false narratives against you. The trust council is the governance body that owns TrustOps: it sets the policy, funds the tooling and holds the metrics.