Professor Sele
Counterterrorism & Intelligence Lead | SafeHaven Strategies

"The threat you dismiss is the threat that finds you unprepared."

Module 4

CT Intelligence Collection and Analysis

Professor Sele: Intelligence is the primary weapon against terrorism — not force, not barriers, not luck. The best CT outcome is the attack that never happens because the threat was identified and disrupted in the planning phase. This module builds your CT intelligence capability.

Section 1 — CT Intelligence Priorities

In a private security CT context, intelligence priorities focus on: threat actor identification — who are the groups or individuals with intent to attack targets in the operating area? Pre-attack indicators — is there evidence of surveillance, planning, or preparation against a specific target? Insider threat — are there individuals within the organisation who may support or facilitate a terrorist act? Environmental threat picture — what is the current level and nature of terrorist activity in the operating area and region?

Section 2 — Intelligence Sources for CT

HUMINT: community contacts, informants, and observations from security personnel — the most immediately actionable source in Liberia. OSINT: news media, social media monitoring, government statements, international CT reporting. Technical: CCTV analysis, access control logs, communication pattern monitoring (within legal authority). Liaison: intelligence shared by LNP, NSA, and international partners through appropriate channels.

Section 3 — Analytical Techniques

Link analysis — mapping relationships between individuals, organisations, and events to identify networks. Pattern analysis — identifying recurring patterns in threat actor behaviour: surveillance routes, target selection criteria, attack timing. Timeline analysis — reconstructing the sequence of events before an attack or incident to identify missed indicators. Threat assessment — applying the CAP framework (Capability, Access, Probability) to specific threat actors.

Section 4 — Reporting CT Intelligence

CT intelligence must be reported through designated channels — not via standard incident reporting systems. Immediate credible threat: report directly to SafeHaven Operations Commander and the LNP National Security Branch simultaneously. Indicator or concern: report to SafeHaven Operations Commander for assessment and onward reporting decision. All CT intelligence reports must be classified at minimum SENSITIVE. Never share CT intelligence via unsecured channels or with unauthorised personnel.

Key Points
  • CT intelligence priorities: threat actors, pre-attack indicators, insider threat, area threat picture
  • Sources: HUMINT, OSINT, technical, liaison
  • Analytical techniques: link analysis, pattern analysis, timeline analysis, threat assessment
  • CT intelligence has dedicated reporting channels — not standard incident reports
  • All CT intelligence is classified SENSITIVE minimum — strict need-to-know
Field Note · Professor Sele

"Good CT intelligence is almost always built on small things. Not dramatic confessions or intercepted communications — those are rare. It is the guard who notices the same person photographing the building three times. The cleaning supervisor who notices a new cleaner asking unusual questions. The access control log that shows someone badging in and out of a sensitive area at 03:00. None of those is conclusive alone. Together, analysed as a pattern, they built a picture that led to a serious intervention. Collect everything. Record everything. Analyse the pattern."

Knowledge Check

What is "Hostile Reconnaissance" in a CT context?