Texas Deploys Cognyte’s FalcoNet Mobile Cell‑Site Simulator, Raising Privacy and SOC 2 Concerns
What Happened – Cognyte, an Israeli‑origin surveillance firm, announced a contract with the State of Texas to supply “FalcoNet,” a mobile cell‑site simulator that can be mounted in a van, backpack, or helicopter. The device mimics a legitimate cellular tower, forcing any nearby phones to connect and allowing law‑enforcement to capture call‑metadata and location data from all devices in the vicinity, regardless of suspicion.
Why It Matters for Compliance & Audit Readiness
- The technology creates a de‑facto “mass‑collection” point, directly testing the effectiveness of privacy‑by‑design controls required by SOC 2 CC6 (Privacy) and GDPR/CCPA obligations.
- Continuous‑compliance programs must be able to demonstrate documented policies for lawful interception, data minimisation, and documented consent or legal basis for bulk data capture.
- Verisq’s CookiePLUS privacy capability can provide the audit‑ready evidence (consent logs, DSAR response workflows, data‑flow maps) needed to prove compliance when such surveillance tools are in use or being evaluated.
Who Is Affected – State and local law‑enforcement agencies, telecom providers, and any individual whose mobile device is within range of the FalcoNet unit (broadly the general public in Texas).
Recommended Actions
- Map the FalcoNet capability to SOC 2 CC6 privacy controls and document the legal basis for its use.
- Implement a data‑flow inventory that captures any intercepted metadata and establishes retention, minimisation, and deletion policies.
- Conduct a privacy impact assessment (PIA) and update DSAR procedures to handle bulk‑collection requests.
Source: Schneier on Security – Cognyte Sells a Mobile Cell Surveillance Van
Technical Notes – FalcoNet operates as an IMSI‑catcher (Stingray‑class) that forces phones to attach to its simulated base‑station, capturing IMSI, IMEI, signal strength, and potentially call‑metadata. No CVE or software vulnerability is disclosed; the risk stems from the technology’s inherent capability to intercept communications.