"The threat you dismiss is the threat that finds you unprepared."
Counter-Surveillance in High-Threat Environments
Professor Sele: In high-threat CT environments, the surveillance detection skills from Course 4 become life-critical. This module applies and extends those skills specifically to the counter-terrorism context — where the surveillance you miss may be the planning phase of a mass casualty attack.
Section 1 — CT Surveillance vs. Criminal Surveillance
Terrorist surveillance differs from criminal surveillance in several important ways: timescale — terrorist pre-attack reconnaissance may be conducted over weeks or months (patient, methodical, well-resourced); professionalism — state-linked or well-funded terrorist groups conduct surveillance with significant tradecraft; multiple actors — reconnaissance may involve several individuals operating in relay across different time periods; objective specificity — terrorist surveillance is focused on specific vulnerabilities (guard positions, response times, VIP movement patterns, access control weaknesses).
Section 2 — High-Threat SD Posture
In elevated CT threat environments, the SD posture is enhanced: increased observation frequency — surveillance detection runs conducted more frequently and at irregular intervals; extended observation zones — coverage extended beyond the immediate perimeter to capture relay surveillance; technical augmentation — CCTV and access logs actively monitored for pattern indicators; communication protocols — all potential contacts reported immediately, no waiting to apply the 3× Rule when the potential threat is a CT actor.
Section 3 — Target Hardening as CT Counter-Surveillance
Making a target difficult to surveil is itself a protective measure: vary principal movement routes and timings systematically — denying the attacker the pattern-of-life data they need; limit public information about site layouts, security measures, and operational routines; maintain operational security around VIP visits — no advance public notification; use counter-surveillance posture changes (additional SD coverage, route variation) when a CT threat elevation is declared.
Section 4 — Reporting CT Surveillance Contacts
In a CT context, the reporting threshold is lower than in standard operations. Standard SD: 3× Rule before confirming surveillance. CT-elevated environment: two sightings of a potential surveillance indicator triggers a report to the TL and an immediate enhanced observation posture. Any single sighting that involves photography of security measures, guard positions, or access points triggers an immediate report — this is specific hostile reconnaissance, not general suspicious behaviour.
- •Terrorist surveillance is patient, methodical, multi-actor, and focused on specific vulnerabilities
- •Enhanced CT SD posture: increased frequency, extended zones, technical augmentation, lower reporting threshold
- •Denying pattern-of-life data through route and timing variation is a core target hardening measure
- •CT reporting threshold: two sightings triggers a report — not three
- •Any photography of security measures triggers an immediate report regardless of confirmation level
"In a high-threat CT environment I deployed a CS team in an overt-covert posture — some operators visible, some covert. The visible operators were not just deterrent. They were bait. A surveillance actor watching us will be observed by our covert operators watching them. The visible presence pushes the surveillance further out. The covert presence observes them at range. It is a layered counter-surveillance architecture. In a standard operation, overt and covert are separate. In a CT environment, they work together."
Which of the following is a PRIMARY indicator of pre-attack surveillance by a potential terrorist threat actor?