Attack Cycle Basics for Protective Intelligence Teams

Intelligence Analysis

Attack Cycle: Predicting Threats Isn't Rocket Science

Anyone who runs or supports a small or mid-sized business, a nonprofit, a humanitarian or faith-based organization knows that funds are limited and that practical decisions are necessary. Even if the budgets are tight, there remains a need for Protective Intelligence and well-disciplined Travel Risk Management.

Having served for two decades as an intelligence officer in the U.S. Army and later working as a security consultant to large companies, I now assist organizations that want professional-level protection without having to bear the costs associated with the Fortune 100 companies. In this article, I look again at a key idea in the field of Protective Intelligence and Travel Risk Management: the Attack Cycle. It is easy to understand the concept, but what smaller organizations achieve by applying it is to disrupt threats before they become fully developed.

The Attack Cycle Is Predictable

The Attack Cycle is a logical sequence followed by people planning deliberate attacks, whether those individuals are members of terrorist groups, violent extremists, or criminal organizations aiming at soft targets. It usually involves:

Attack Cycle
  • Target selection - identifying a vulnerable person, location, or event that offers high impact relative to the attacker’s resources.

  • Intelligence collection and analysis - surveillance, open-source research, pattern-of-life observation, and assessing security posture.

  • Planning and asset deployment - assembling people, weapons, timing, and logistics.

  • Execution - carrying out the attack.

  • Exploitation and escape - maximizing propaganda, recruitment, or operational advantage, then resetting the cycle.

Even though it is predictable, many organizations have difficulty putting this knowledge into practice. Operational leaders at times see intelligence input as something that slows down the pace of operations, or they use previous intelligence failures as an excuse to ignore warnings. The truth is more complex. Analysts are not always correct, but neither are they always incorrect. If any one stage is interrupted, the adversary will be forced to restart, delay, or give up the operation. While measuring that disruption is imperfect, the effect is real.

A Classic Illustration: Kabul, August 2021

The situation regarding the evacuation of at-risk personnel in Afghanistan is a clear example to study. It is very likely that intelligence experts had identified the vulnerability of having large groups of people gathered at Hamid Karzai International Airport. Public reports indicated that the Taliban had themselves warned of possible attacks. The two bombings on 26 August 2021 resulted in the deaths of thirteen U.S. service members and over 140 civilians. The Islamic State – Khorasan Province took credit for the attacks, but the general circumstances… thousands of identifiable opponents of the new regime attempting to leave, a limited number of entry and exit points, and a high-visibility target… fit exactly with the logic of the Attack Cycle.

From the enemy’s point of view, the calculation was simple: choose a target that will result in a large number of casualties, generate extensive media attention, have a strong terror effect, and be valuable for recruitment, all while keeping the risk to their own forces as low as possible. Crowded areas provide an opportunity. Mobility and unpredictability reduce that opportunity. The idea that "movement is life" is not just something from a film; it is in fact part of operational doctrine in humanitarian crises and in situations involving a high level of threat. Changing the points of entry and exit, spreading out assemblies, and preventing fixed patterns can break the cycle before it is carried out.

The same reasoning is still applicable today: soft targets, such as airports, hotels, places of worship, public events, aid distribution centers, and staff movements in high-risk areas, remain appealing because they allow a strong effect to be achieved with relatively easy access for determined attackers.

Thinking Like the Adversary

To be able to predict the next stage of an Attack Cycle, it is necessary to make a deliberate attempt at seeing things from the adversary's point of view. What is a high-value, low-cost target in their eyes?

Small and medium-sized organizations don't need classified sources or a full-time team of analysts. All they need is careful monitoring of open source information, a truthful evaluation of their own level of visibility, and the readiness to alter their routines when signs appear. The aim is not perfect prediction; it is to raise the adversary's costs and uncertainty so much that they abandon their efforts… or until you are able to detect their activities early enough to protect your personnel.

Practical Application for Organizations with Limited Resources

You can apply the Attack Cycle framework by developing a simple habit of asking a few key questions before travel, events, or high-visibility activity:

  • Why might anyone consider our people or our locations to be a useful target?

  • What current patterns of movement, meeting, or communication can be predicted?

  • Which of the open-source indicators (for example, local reporting, social media, incident trends, official warnings) are relevant to our locations and profiles?

  • What simple changes (such as varying the route, altering the timing, decreasing concentration, and improving local awareness) would cause an adversary to have to restart their planning?

  • Do our staff know how to raise concerns and when to do so without being regarded as being too cautious?

These practices involve only a small amount of expense and provide the practical basis for Protective Intelligence and for credible Travel Risk Management among nonprofit field teams, mid-sized companies that send staff overseas, and faith-based organizations that support partners in complex environments.

Attack Cycle Disruption

Disruption Is the Goal

The idea of understanding the attack cycle isn't one of attaining perfect foresight. Since most deliberate attacks proceed in a logical sequence, there are opportunities at each stage for detection or disruption. If early indicators are taken seriously, they can cause the adversary to go back to the start of the cycle or look elsewhere.

In a situation where threats keep on developing, ranging from ideologically driven violence to opportunistic attacks on soft targets and aid workers, this framework is still one of the most effective tools that organizations with limited resources can use. It is not complicated; rather, it involves disciplined attention applied consistently.

Need Practical Support?

We assist organizations that need professional-quality Protective Intelligence and Travel Risk Management without having to bear the costs associated with a large corporate program. If you are getting your teams ready for higher-risk travel, if you wish to develop simple protocols based on indicators and attack cycles, or if you just want a clear and straightforward evaluation of your present position, we do so within realistic budgets.

If the ideas set out in this article match the problems you're experiencing, get in touch; usually a brief talk will be sufficient to spot the most effective improvements you can make with the resources you currently have.

Previous
Previous

Overcoming Bias: Lessons from Ukraine

Next
Next

Protection Agents: Avoidance Over Armed Confrontation