The Art & Science of Using Surveillance Detection to Predict & Disrupt Planned, Targeted Attacks
A conversation with Justin M. Bishop, CPP, PSP — Subject Matter Expert in Surveillance Detection, Threat Prediction, and Protective Services.
The following is a conversation between Sky Fort Systems and a subject matter expert in surveillance detection and threat prediction. They discuss the current state of executive and dignitary protection, why the conventional security approach leaves at-risk individuals and organizations dangerously exposed, and what a new generation of AI-enabled technology is about to change.
— Question 1 —
Sky Fort Systems:
We’ve been looking forward to this one. Before we get into the substance give us a bit of your background. How does someone end up becoming a specialist in surveillance and threat detection? It’s not exactly what most people picture when they think of “security.”
Justin:
You’re right, it’s not the most glamorous part of the business. Nobody’s making movies about the guy sitting in a café at a street corner watching people walk by. But that’s actually where I fell in love with this work.
After joining the U.S. Army in 1988 and serving several years in post-war Bosnia as a military intelligence officer, I left the military in 1999 to join a Department of Defense counterterrorism unit. The unit’s mission was to deter, detect and disrupt planned, targeted attacks against U.S. military installations and personnel overseas. That experience of conducting surveillance operations to detect and disrupt terrorist attack plans, particularly after 9/11, fundamentally shaped how I think about security.
Since then, I’ve applied that knowledge and experience to supporting private sector multinational corporations operating in austere, high-risk environments across Eastern Europe, North Africa, and the Middle East, as well as counterterrorism and counterintelligence activities. Somewhere along the way I picked up my CPP and PSP certifications, and about 35 years in, I’m still finding that the most interesting question in security is the one most programs aren’t asking: not how do we respond to a threat, but how do we find the threat before it finds us.
— Question 2 —
Sky Fort Systems:
That’s a fascinating trajectory — and that distinction between finding a threat and responding to one is a great way to frame what we want to dig into today. How would you characterize the general state of the executive and dignitary protection industry right now? Are programs getting this right?
Justin:
Not enough of them, no. And I say that with genuine respect for the professionals in this space. There are talented, dedicated people doing important work. But many corporate EP programs – and even some government programs – are built on a foundational assumption that is both understandable and dangerous: they assume local law enforcement or security services will identify and flag credible threats early enough to implement threat-specific protective measures.
Unfortunately, if you’re waiting for a confirmed threat to surface through open-source monitoring or law enforcement or intelligence service reporting, you may be too late. The adversary may already be in the final stages of attack planning or worse, preparing to execute their attack. You’re behind the curve. And in this business, being behind the curve is a very bad place to be.
The other issue is that most programs – particularly in the private sector – lack access to the kind of persistent, actionable intelligence needed to predict when and where an adversary will attack. So they operate in a kind of comfortable fog, assuming that if something serious develops, they’ll hear about it. That assumption is misplaced, and I think it’s worth unpacking why.
— Question 3 —
Sky Fort Systems:
Yes, let’s. There seems to be a widespread assumption – and we see it in the European market as well – that if a serious threat is emerging against a principal, a corporation or an organization, local law enforcement or national intelligence services will provide a heads-up. Is that reasonable?
Justin:
It isn’t, but I understand why people believe it. It’s comforting and easier to place the burden knowing when or where a threat may manifest itself on others, specifically law enforcement and security services. But there’s a critical distinction that consistently gets lost: duty to warn is not the same thing as ability to warn. Most police and intelligence agencies are indeed obliged to share threat information when they get it. But these organizations are chronically under-resourced, over-tasked, and have other priorities that rarely, if ever, include you or your principal. And even if these organizations do acquire credible threat information, the process of vetting, analyzing, and disseminating that information takes time – time that may not exist.
Then there’s the OSINT question. A lot of EP programs invest in open-source monitoring – social media, dark web feeds, threat intelligence platforms – and rely on it for early warning. I understand the appeal. But this reflects a fundamental misunderstanding of what open-source information is and what it isn’t. Despite the “INT” in its name, OSINT is not intelligence. Open-source information only becomes intelligence when it is analyzed, corroborated, and placed in context.
More critically: sophisticated adversaries, those likely to pose the greatest threat to a principal, often have rigorous counterintelligence and communications discipline. They are unlikely to have an easily discoverable open-source footprint. They are unlikely to use or communicate over social media. With little or no information to collect and no communications to intercept there’s nothing to analyze. The more sophisticated the threat, the less reliable traditional intelligence and OSINT collection are — which is exactly backwards from what most security managers assume.
— Question 4 —
Sky Fort Systems:
So if external warning isn’t reliable, and OSINT has real limits against capable adversaries – where does that leave a security program? What’s the alternative?
Justin:
It leaves you with surveillance detection (SD), which is good news, because SD exploits something adversaries cannot eliminate, no matter how disciplined they are. Planned, targeted attacks require physical surveillance. Full stop. Before an adversary can act, they must look. They must conduct surveillance to understand their target’s pattern of life, to know where they are time and place predictable and vulnerable to attack. They must look before they strike. That is every adversary’s Achilles heel — their need to conduct physical surveillance, which is exactly when they are most vulnerable to detection.
The operational foundation of SD is built on this insight: attack sites are always located at the confluence of the principal’s time and place predictability, vulnerability and adversary capabilities. Once you’ve identified potential attack sites through the vulnerability assessment process, you can work backwards to identify locations conducive to conducting discreet, covert or clandestine pre-attack surveillance. Those hostile surveillance locations become the focus of your SD efforts. Your SD team occupies their surveillance detection locations before the adversary occupies their hostile surveillance locations. And the adversary, believing they are invisible, walks right into your coverage.
— Question 5 —
Sky Fort Systems:
I love that framing – the adversary’s Achilles heel. It genuinely flips the logic of the problem. Walk us through how a properly structured SD program exploits that vulnerability in practice.
Justin:
SD delivers deterrence, detection and disruption.
Deterrence is the first benefit, and it’s often underappreciated. The adversary who suspects they may have been detected and therefore could be under countersurveillance faces a critical decision: pause and assess the situation to know if it’s safe to proceed with the attack plan, modify the plan, or abort? In either case, the principal lives to see another day. Deterrence deepens when you introduce unpredictability in the principal’s pattern of life — varying routes, timings, modes of transport, and visible security profile. Each of these changes forces the adversary to conduct additional surveillance – to confirm previous planning assumptions – and that translates into more time on the street and greater risk of comprise.
Detection is the operational core. SD teams occupy surveillance detection locations identified during the vulnerability assessment to look for behavioral and pre-incident indicators associated with hostile surveillance. The vulnerability assessment also identifies areas of concern, which are almost always associated with hostile surveillance locations and attack sites. SD teams look for people whose presence and demeanor in these locations correlate with the principal’s movements or activities. For example, individuals displaying no apparent reason for being in an area of concern, or whose dress and demeanor are inconsistent with the normal environment, or repeated appearances by the same person or persons, vehicles or objects in areas of concern.
But detection does more than identify potential threats – it tells you something about an adversary’s intent. The locations an adversary surveils narrows down possible attack methods. Different attack sites require different reconnaissance, different cover for action, different pre-attack rehearsals and attack team deployment. Where an adversary is looking reveals a lot about when and how they may strike.
And then there’s disruption. When SD assets identify suspected or confirmed hostile surveillance, they can initiate a range of responses or interventions. These include altering the principal’s route of travel, departure or arrival times, security escort profile, as well as notifying law enforcement or simply increasing the scope and scale of SD. These actions increase the principal’s unpredictability and the adversary’s uncertainty to the point where the adversary cannot confidently move beyond the planning phase of the attack cycle. They’ll need to conduct additional surveillance – increasing their exposure – to confirm operational planning assumptions.
The adversary must decide if it’s worth the risk to continue, or should they shift to a different target, or abort their plan altogether? Each change or disruption extends the adversary’s planning timeline, introduces more doubt, and increases the probability they’ll make a fatal mistake. The cumulative effect of sustained SD operations is that is raises the adversary’s risk and cost of attacking their target to the point where they will redirect their efforts elsewhere.
— Question 6 —
Sky Fort Systems:
Here’s the challenge we consistently hear from clients: this sounds resource intensive. Not every executive has a full protection detail, let alone a dedicated SD capability. How do you make this work for individuals or organizations with limited budgets?
Justin:
It’s a fair challenge. The honest answer is that SD doesn’t have to be a full-time, around-the-clock operation to deliver value. It can be deployed episodically – selectively targeting periods and locations of high vulnerability. But the groundwork must be laid in advance.
Here’s the scenario I use to make this concrete. The Chief Security Officer for a large U.S. defense contractor gets a call from a law enforcement contact: credible intelligence indicates a transnational terrorist group plans to kidnap or assassinate senior executives working for U.S. defense contractors. No specific names, no locations, no timing. Because this particular CSO has proactively conducted detailed vulnerability assessments before this credible threat emerged, he already knows where his senior executives are most vulnerable to attack while in transit. This CSO can deploy SD coverage within hours. Now, the CSO who hasn’t done that work is starting from zero – at the worst possible moment. This is not the time to figure out where your principal is vulnerable to attack while traveling from his home to the office or the airport or his daughter’s school. That time has passed.
So the resource argument gets flipped: doing the foundational work is not a luxury. The vulnerability assessment, the route mapping, the identification of attack sites and hostile surveillance locations – this is not expensive. But it does require time, expertise and discipline to do it before you need it. Because when you need it, it’s too late to build it.
— Question 7 —
Sky Fort Systems:
That’s a compelling argument – and a great segue. We know you’ve been working on some technology that addresses exactly this. There’s been some buzz about an AI system in development. Can you give us a preview without giving too much away?
Justin:
I’d love to. Everything we’ve discussed today – the importance of vulnerability assessments, periodically employing SD to identify pre-incident indicators – that methodology is sound and it works. The limitation has always been scaling and persistence. Trained human SD teams are extraordinarily capable, but they can’t be everywhere and can’t observe everything all the time. Then there’s a practical ceiling on how much coverage any organization can sustain, financially. What we’re building is a system designed to extend and augment the scope, scale and reach of human SD – not replace it.
It’s a multi-agent AI system – currently going through the patent process – built specifically for correlation-based surveillance detection, pre-incident threat identification, and longitudinal behavioral analysis. The core idea is actually quite elegant: the system correlates observed behavior from a sensor array against the location and movement of a principal and associated areas of concern – those attack sites and hostile surveillance locations we’ve been discussing. It doesn’t just flag anomalous behavior in isolation. It determines whether this behavior, at this location, at this time, is consistent with what an adversary would need to while conducting pre-attack surveillance. Correlation is the primary detection test.
The architecture has three layers. A sensor array and edge compute layer tracks entities in real time. Domain-specialized AI subagents – separate agents for human behavior, vehicle behavior, aerial threats, social media and digital signals, and pattern-of-life analysis – produce structured intelligence records that feed into a central fusion agent we call Fuser. Fuser maintains a longitudinal behavioral database and performs probabilistic identity resolution across encounters. That’s where the real power lives.
What makes this genuinely different is something we call the dormant-record mechanism. The system preserves entity histories across long, quiet periods so it recognizes when a previously observed individual or vehicle reappears after a gap in time consistent with initial target surveillance, final target surveillance, and pre-attack deployment. That is a capability that has simply not existed before in a deployable system. And it operates in two modes on identical hardware: a mobile mode mounted within a principal’s vehicle for in-transit threat detection, and a fixed-site mode for residences, offices, schools and universities, places of worship, or critical infrastructure. The system builds a picture that no single observer, human or automated, could construct alone.
Field trials will begin before year-end, and the first units will be ready for delivery by Q2-Q3 2027. I’m genuinely excited about what this does for the kind of episodic, resource-conscious SD programs we’ve been discussing. This system will dramatically lower the barrier to building a persistent, intelligence-grade surveillance detection capability for private individuals and organizations currently lacking dedicated protection, or struggle financially to sustain it.
— Question 8 —
Sky Fort Systems:
That’s a really interesting point. You mentioned individuals and organizations that currently lack dedicated protection. Let’s dig into that for a moment, because I think it’s worth making explicit. There’s a large segment of people out there – high net-worth individuals, C-suite executives at mid-sized firms, senior officials at NGOs, families of at-risk persons – who may genuinely be at risk but do not use or cannot afford professional close protection or SD services. Some can’t justify the cost. Some simply don’t believe they need it. Is the AI system you’re developing relevant to that population?
Justin:
Absolutely – and honestly, that might be where I’m most excited about what we’re building. Let’s be direct about the reality: the vast majority of individuals who could genuinely benefit from proactive threat awareness – executives, high net-worth individuals, controversial public figures – have zero dedicated protection coverage. The challenge is both financial and psychological. Financially, it comes down to the fact that specialized security and executive protection is expensive. Psychologically, many people believe that because a particular incident has never happened, it never will happen. At the end of the day, they cannot rationalize spending a lot of money on personal security to prevent what they view as a low probability, albeit high consequence event. So they go without, which presents a gap. And that gap is where attacks happen.
Our AI system changes that calculus entirely. It doesn’t require a full protective detail to operate. It runs autonomously – in a vehicle, at a home, at a facility – correlating behavioral data from a plurality of sensors arrayed against knowable areas of concern and the user’s location in real-time. It surfaces the same threat indicators trained human SD operators would surface, but over a greater area and longer period. For someone who currently has zero security coverage, that is a genuinely transformative capability. For the first time, they now have access to a persistent, intelligent layer of awareness that’s working even when no one is watching. 24 hours a day. 7 days a week. 365 days a year.
But here’s where it gets particularly compelling. When the system detects and reports anomalous or suspicious behavior – patterns consistent with pre-attack surveillance – that report becomes an intelligent, documented trigger for the next decision. It answers the question the at-risk individual wasn’t sure they needed to ask: Am I being targeted? If the answer is yes, or just maybe, they now have an informed basis for at least considering employing additional resources. That’s a very different conversation than “I probably should think about getting some security.” It’s “here’s what the system has detected, here’s where it happened, it’s time to get a security professional in the loop.”
So what we’ve really built is a spectrum solution. At one end: individuals and organizations with no current EP or SD coverage now benefiting from 24/7, 360-degree protective awareness for the first time. At the other end: organizations with well-resourced, professional EP programs, where our AI product amplifies and extends the capability of those human operators – sustaining coverage between deployments, building longitudinal behavioral histories that no human can maintain on their own, and providing a level of analytical depth that simply wasn’t available before. Same platform, same technology, serving both ends of that spectrum and everything in between. Whether you’re just starting to think about your security posture or already managing a sophisticated protective services program, this system adds value.
— Question 9 —
Sky Fort Systems:
That genuinely sounds like a step-change for the field – and we’ll absolutely want to revisit this as it moves toward deployment. Last question, and it’s the big one: if you had one message for the security director or EP program manager reading this, what would it be?
Justin:
Do the work now. That’s it.
The absence of a specific, known threat isn’t evidence that the threat doesn’t exist – it’s evidence that it hasn’t been detected. Surveillance detection is the best mechanism to know if an adversary is considering or already planning to target your principal – but only if it’s in place before the adversary takes the field.
Security professionals who get this right are the ones who invest in vulnerability assessments. Those assessments, when done correctly, reveal where their principals are exposed and vulnerable to hostile surveillance and attack. Armed with that knowledge they can train or employ professional SD assets before specific, credible threats emerge. Because when threats emerge, the time for doing the upfront work has passed. The only question then will be whether the work was done or not. And the answer to that question has consequences that extend far beyond a budget line item.
Be the professional who already did the work.
About Sky Fort Systems
Sky Fort Systems is a Croatian-based physical security and risk management firm specializing in executive protection, security consulting, and risk advisory services across European and international markets.
About the Interviewee
Justin M. Bishop has 35 years of experience providing security, intelligence, and executive protection services throughout Eastern Europe, the Balkans, North Africa, and the Middle East. He is a former U.S. Army intelligence officer and Mission Coordinator for the U.S. Department of Defense Counterintelligence Field Activity. He has supported public and private sector clients operating in austere, high-risk environments, as well as counterterrorism, force protection, and counterintelligence activities. Justin earned a Baccalaureate in Russian and Post-Soviet Studies from Auburn University and is accredited by ASIS International as both a Certified Protection Professional (CPP) and Physical Security Professional (PSP).
Justin M. Bishop, CPP, PSP
D3 Secure LLC
501 Union Street, Suite 545
Nashville, Tennessee USA
+1-509-999-0841
+385-91-444-1492 (Croatia)
Email: [email protected]