WHAT IF WE ARE PREPARING FOR THE PREVIOUS TERRORIST ATTACK?

I recently commented on a post asking what makes a book important.
My answer was simple - Boldness.
For me, it is the boldness of the argument that matters most. We often see books published in the aftermath of major disasters; financial crises, terrorist attacks and corporate failures; each explaining why they happened, how they were allowed to happen and the systemic gaps that enabled them.
What strikes me is that the real test of boldness may be whether those same questions are asked “before the disaster occurs.”
It is considerably easier to explain a failure once the evidence is visible. The more valuable contribution, in my view, is the work that challenges accepted thinking whilst there is still time to act.
Could this be the distinction between explaining history and genuinely anticipating it?
There is another reason I have been thinking about this. I have always found it interesting how many experts become particularly articulate after an event. Once something has happened, the warning signs suddenly become obvious.
The vulnerabilities can be mapped. The missed opportunities can be identified.
The intelligence can be reconstructed. The decisions can be criticised. The lessons can be written down. And, eventually, another book can be published explaining what went wrong.
But what about before?
What about when the evidence is incomplete, the outcome is uncertain and there is no convenient hindsight to tell us which questions were the right ones to ask?
That is where bold risk analysis becomes much more difficult.
I have asked this question before…
In October 2014, I wrote an article for The Korea Times entitled “Take away the terrorists' M&Ms.”
At the time, the Islamic State was expanding across Iraq and Syria and the international community was once again confronting a rapidly changing terrorist threat.
My argument centred on three things:
Media. Manpower. Money.
The media provided publicity. Publicity helped recruitment and radicalisation.
Manpower created operational capability.
And money sustained the organisation.
The argument was relatively simple; if we wanted to weaken a terrorist organisation, we should not look only at the individual terrorist. We should examine the ecosystem that allowed terrorism to function.
I wrote that article twelve years ago. The interesting question now is not whether that analysis was correct then. It is whether we have learned to anticipate what comes next. Because the threat environment has changed considerably since 2014.
What happens when the objective changes?
Iran is now facing significant military and economic pressure. I am not suggesting that we know what the Iranian leadership will do next. Nor am I suggesting that a terrorist attack in Britain is imminent. But there is a broader question worth asking.
What happens when a state or organisation concludes that it cannot achieve its objectives through conventional means?
Does the objective change?
Perhaps it becomes less about winning and more about demonstrating the cost of your victory.
That distinction matters. Because terrorism does not necessarily require conventional military capability. Nor does it necessarily require a target with obvious strategic value.
We are very good at preparing for what we already know
Counter-terrorism learns from experience.
After an attack, vulnerabilities are identified.
Security is strengthened.
Procedures change.
Intelligence priorities evolve.
Police and security agencies adapt.
This is necessary. But there is an uncomfortable problem. The adversary is watching too.
If we become exceptionally good at protecting the locations, methods and behaviours associated with previous attacks, an intelligent adversary has an incentive to look somewhere else.
The danger is that we become increasingly prepared for yesterday. And tomorrow does not necessarily look like yesterday.
Terrorism is not only about casualties.
We tend to measure terrorist attacks in familiar terms.
Deaths.
Injuries.
Physical destruction.
Economic damage.
But terrorism has another weapon – “FEAR.”
A sophisticated terrorist campaign does not necessarily need to maximise casualties. It may seek to create an event that people believe could happen in their own community. That could be considerably more powerful.
Imagine an attack somewhere that does not immediately fit the public's mental picture of terrorism.
Not London.
Not a government building.
Not an international airport.
Not a major financial centre.
Instead, somewhere ordinary.
A beautiful English tourist destination.
A busy Sunday.
Families walking through the streets.
Restaurants full.
Children with their parents.
People taking photographs.
A place that people associate with relaxation, leisure and safety.
The physical consequences would be concentrated in one location. The psychological consequences might not be.
Suddenly, people throughout Britain could begin looking at their own communities differently.
The village they visit at weekends.
The local Christmas market.
The summer festival.
The railway station.
The shopping centre.
The sporting event.
The tourist attraction.
The place where they take their children.
And two questions would become unavoidable:
Could it happen to me?
Can the police protect me?
The target may be the assumption.
This is the part of terrorism that I think deserves more attention. A sophisticated adversary does not necessarily need to identify the most strategically important location. It may identify the location where the greatest psychological assumption of safety exists.
If you attack a heavily protected government building, people may conclude that the government was targeted. If you attack an airport, people may conclude that airports are vulnerable.
But if you attack somewhere people regard as completely ordinary and safe, something else happens. People begin to generalise.
The question then moves from:
“Why did they attack there?”
to:
“Where else could they attack?”
That is potentially a much larger form of disruption. The target is no longer simply the physical location.
The target becomes confidence.
If terrorism becomes part of city life, what happens outside the city?
There is another comment that has stayed with me. In 2016, following the bombing in New York, the Mayor of London, Sadiq Khan, said that being prepared for terrorist attacks was “part and parcel of living in a great global city.”
His wider point was about preparedness and vigilance. He said that people had to be prepared, remain vigilant and support the police and security services. He was not arguing that terrorism itself should simply be accepted as part of everyday life.
But there is an interesting risk-management question within that observation. If we accept that being prepared for terrorism is part of living in a major global city, we also create a mental map of where terrorism belongs.
London.
New York.
Paris.
Brussels.
Major transport hubs.
Government buildings.
Financial centres.
Large public events.
Places that already exist within our mental model of terrorism.
But what happens if an adversary deliberately chooses somewhere that does not fit that model? What happens if the attack occurs in a small English town?
A popular tourist destination?
A village where people have gone for a Sunday afternoon?
A place with no obvious political or strategic significance?
Suddenly, the assumption changes. People are no longer thinking:
“That is what happens in London.”
They are thinking:
“That could happen here.”
And that is a very different psychological problem. The significance of such an attack would not necessarily be measured only by the number of people killed or injured. It could be measured by the number of people who subsequently changed their behaviour.
The number of people who questioned whether they should attend a local event.
The number of parents who became more conscious of where their children were.
The number of communities that began looking differently at their local police presence.
The number of people who started asking whether their own town was adequately protected.
That is why I think we should be careful about becoming too comfortable with the idea that terrorism is primarily an urban problem. Perhaps the real opportunity for an adversary lies in demonstrating that it is not.
And if that happens, the question may no longer be whether people are prepared to live with terrorism in a major city.
It may become: Are we prepared for people to believe that terrorism can happen anywhere?
And then there is the question of who we know.
This brings me to another uncomfortable part of the British security environment. Since 2018, more than 200,000 people have arrived in the UK by small (and not so small) boat. The number is significant.
But the number itself is not the argument. Nor would it be responsible to suggest that people arriving by small boat are, collectively, a terrorist threat. There is no evidence to support such a blanket label.
The risk-management question is different. It concerns identity, information and uncertainty. How confident are we that we know who has entered the country? How much do we know about an individual's previous activities? How effectively can identity and background information be established? Where are the information gaps? And, could a hostile actor ever seek to exploit weaknesses within a system handling large numbers of people whose backgrounds may be difficult to verify?
That is not an accusation against migrants. It is a question about the resilience of a system. Because unknown is itself a risk category.
The numbers should make us uncomfortable, but not for the reason some might suggest.
Recent evidence submitted to the UK Parliament by the Henry Jackson Society cites approximately 43,000 individuals on the MI5 terror watchlist, of whom approximately 39,000 are identified as Islamist extremists.
These are not figures published by MI5 itself; they are figures cited in third-party evidence submitted to Parliament. That distinction matters. But if the underlying figures are broadly accurate, the scale is significant.
The Parliamentary evidence also points to a discrepancy between the proportion of individuals on the watchlist associated with Islamist extremism and the proportion of Prevent referrals and Channel cases attributed to Islamist extremism.
Again, that does not tell us what the next attack will look like. But it does provide another reason to examine whether the way we measure, categorise and respond to threats accurately reflects the environment we are actually facing.
Because risk management depends upon understanding the threat environment accurately.
And that means being willing to challenge the numbers, the assumptions and the models we use to describe it.
Iran makes the question even more complicated.
There is another reason I am reluctant to look at this purely through the traditional lens of Islamist terrorism.
Iran represents a different kind of problem.
It is a state actor.
It has intelligence capabilities.
It has relationships with proxy organisations.
It has demonstrated an ability to operate outside Iran.
And MI5 has already identified Iran-backed activity presenting potentially lethal threats in Britain.
In October 2024, MI5's Director General stated that since January 2022, MI5 and police partners had responded to 20 Iran-backed plots presenting potentially lethal threats to British citizens and UK residents. He also warned of the risk of an increase or broadening of Iranian state aggression in the UK.
That is not speculation. It is an assessment from Britain's domestic security service.
At the same time, Iranian nationals have represented a significant proportion of boat arrivals. This does not establish a causal relationship. It does not mean Iranian migrants are Iranian state operatives. It does not mean asylum seekers are terrorists. It does not mean the small-boat route is being used by Iran to insert terrorists into Britain. There is no basis for making that leap.
But it does raise a legitimate security question:
How resilient is any system when a hostile state is actively seeking opportunities to operate within the country while, simultaneously, the country is processing very large numbers of people whose identities and backgrounds may not always be immediately clear?
That is a security question. And it should be possible to ask it without turning an entire population into a threat.
Are we looking in the wrong places?
This brings me back to the question with which I started. What if we are preparing for the last terrorist attack? We know what previous attacks looked like. We know where terrorists have attacked. We know which locations have historically attracted attention. We know the security measures that have been introduced. And we know the indicators that have previously been useful.
But an intelligent adversary understands this too.
So perhaps the next attack will deliberately avoid the profile we have spent years preparing for.
Perhaps it will not seek maximum casualties.
Perhaps it will seek maximum psychological reach.
Perhaps the target will be selected because it is ordinary.
Because it is familiar.
Because people feel safe there.
Because nobody expects terrorism to happen there.
And perhaps the objective will be to make millions of people ask the same question:
Could it happen here?
This is where risk management differs from prediction.
I cannot predict whether such an attack will occur. Neither can anyone else. Anyone claiming to know exactly what a terrorist organisation, proxy group or hostile state will do next is offering something closer to certainty theatre than risk analysis.
Risk management is not about predicting exactly what will happen.
It is about being willing to question our assumptions and prepare for undesirable events that may never happen, at some unknown point in the future.
That requires something which is often uncomfortable. Boldness. The word I began this piece with.
The boldness to challenge the accepted threat picture.
The boldness to examine environments that appear safe.
The boldness to recognise uncertainty as a risk category.
The boldness to challenge uncomfortable statistics rather than simply accepting comfortable ones.
And the boldness to ask what happens when an adversary decides that the most valuable target is not the building, the institution or the infrastructure;
but the public's confidence that they are safe.
Because once the attack happens, the questions become much easier.
The warning signs will be visible.
The vulnerabilities will be identified.
The intelligence will be reconstructed.
The failures will be explained.
The reports will be written.
The lessons will be learned.
But by then, it is history.
The real test of risk management is whether we are bold enough to challenge our assumptions while there is still time to act.
Anthony Hegarty MSc (Criminal Psychology & Criminology)
DSRM RISK




Comments