Rethinking security models

Rethinking security models

Why traditional security models are no longer fit for today’s threat landscape

By Mike Evans, Director of Securitas Risk Intelligence Centre

Over the course of my career in security, risk and intelligence, I’ve worked with organisations that were, by any reasonable definition, well protected. They had experienced teams, clear procedures, effective technology and governance structures that made sense.

Many had also responded successfully to serious incidents in the past. There was no lack of competence, and yet disruption is becoming harder to anticipate.

The reason is increasingly clear: most security models are still built around incidents – but today’s threats are driven by conditions.

That distinction now matters.

Security was designed for incidents

When I first started out in this industry, security was largely about incidents. Something happened – a crime, a protest, an intrusion, a safety incident, for example – and the organisation responded.

And if that response was fast, decisive and proportionate? Then the system was doing its job. And for a long time, this worked well. And in many contexts, it still does.

But the issue I’ve seen emerge over the past decade is that many of today’s threats begin to emerge, and last longer than the incidents themselves. Disruption is no longer defined by a single trigger. Rather, it develops gradually, often below formal thresholds, and across multiple domains at once – particularly where there is responsibility for critical infrastructure and large operational sites.

Threats no longer stay in silos

One of the most significant shifts in the current threat and risk landscape is convergence. Threats no longer develop in isolation; they evolve across digital, physical and information domains simultaneously. They move from online activity into real-world impact, from localised issues into coordinated, networked pressure and from lawful behaviour into disruptive action.

What begins as online mobilisation can evolve into open-source reconnaissance, third-party pressure or the targeting of individuals – before translating into physical disruption weeks or months later.

In isolation, each signal may appear manageable. Viewed collectively, they tell a different story.

These dynamics are particularly evident in the targeting of critical national infrastructure (CNI). Attacks on energy, water and communications systems– as well as data centres and major transport hubs – increased steadily throughout 2025 and continues to do so, driven by a combination of geopolitical tensions, grievance-based ideologies, the criticality of interconnected systems, and opportunistic actors.

What makes this especially challenging is not simply the volume of threat activity, but how it develops. Early-stage behaviours might include shifts in online narrative, the circulation of publicly available information about sites, or low-level reconnaissance activity. Only later does this translate into more visible disruption – whether through cyber-attacks, physical interference, or the growing use of commercially available drones against sensitive sites.

Each stage may sit below the threshold of a formal response. But collectively, they reflect a deteriorating set of conditions that significantly increases the likelihood of disruption.

At the same time, the range of actors involved is widening. Activist networks, criminal facilitators and proxy actors are increasingly operating across the same space, often making use of accessible technologies and, in some cases, unwitting participants. The result is that attribution becomes more complex, intent harder to interpret, and escalation easier to miss.

Where organisations remain siloed – with cyber, physical security, HR, legal and risk functions operating independently – these patterns can be difficult to detect in time.

From response to early recognition

In this environment, intelligence-led security is fast becoming a baseline requirement.

It shifts the central question from “How do we respond when an incident occurs?” to “How do we mitigate a threat before it comes a risk?”

That shift reframes:

  • how information is gathered
  • how weak signals are interpreted
  • how decisions are made under uncertainty

In many recent cases, indicators of disruption were visible well in advance – but only as fragmented activity across digital platforms, physical locations and human behaviour. Without the ability to connect those signals, organisations remain reactive.

An intelligence-led approach focuses on understanding how the wider environment is evolving, what that evolution means in context, and where pressure is likely to surface next. It does not replace response of course – but it reduces reliance on crisis and incident response by enabling earlier, effective intervention.

Recognition over visibility

In many cases, the indicators of disruption are not hidden – they are simply not interpreted in context. In CNI environments, for example, early warning signs can include increased drone activity near sensitive sites, changes in online sentiment linked to infrastructure projects, or the circulation of open-source material highlighting potential vulnerabilities.

None of these, in isolation, necessarily constitutes a security incident. But they are signals of environmental change. The challenge is that most security models are not designed to aggregate and interpret these signals over time. Instead, they rely on a clearly defined trigger to initiate action. And by the time that trigger appears, the disruption itself is often already the outcome of a longer process.

This is the difference between managing incidents and understanding conditions in practice – and it is where many organisations are now seeking to adapt.

What the current environment demands

As 2026 progresses, it is becoming clear that these dynamics are not temporary spikes. They reflect a broader and more persistent shift in how risk develops.

This has particular implications for organisations with exposure to critical infrastructure, whether directly or through supply chains. Threat actors are highly likely to continue targeting these environments using a mix of physical disruption, cyber activity, and hybrid threats including drone-enabled capabilities.

The consequences can be significant: operational outages, data exposure, increased regulatory and legal responsibility, and rising costs associated with securing both sites and personnel. Managing this risk is less about reacting to individual incidents, and more about understanding how exposure is evolving over time.

The organisations that are coping best tend to share three characteristics:

  1. Integration

Convergence is more than just combining physical and cyber security concerns. Digital activity, human behaviour, protest dynamics, insider exposure and physical targeting increasingly form one single risk picture.

  1. Intelligence-led as a capability and state of being

Point-in-time risk assessments are outdated. The threat landscape is dynamic, and effective management depends on ongoing monitoring that tracks how behaviours, sentiment and intent evolve in real time.

  1. Scenario-based thinking

Rather than asking, “Have we managed this risk?”, organisations are asking, “How might this develop and how should our response adapt at each stage?”

This approach helps build what many security professionals refer to as decision advantage: the ability to act earlier, more proportionately and with greater confidence, even in ambiguous situations.

People and technology remain essential

None of this diminishes the importance of frontline capability. Security officers, systems and infrastructure remain critical. But they cannot carry the burden of interpretation on their own.

Where organisations continue to struggle is not in the quality of their people or tools, but in how effectively information flows between them. Frontline teams are often required to make high-stakes decisions with limited context, while valuable intelligence sits elsewhere in the organisation.

Those organisations adapting most effectively are improving visibility, ensuring that early warning, context and insight reach those making decisions on the ground, in a timely and actionable way.

Rethinking what effective security looks like

The future of effective security will not be defined by faster responses, but by earlier recognition.

Organisations that continue to optimise purely for response risk finding themselves consistently behind the curve. The advantage no longer lies in reacting quickly – but in understanding early.