Surveillance, Hostile Behavior, and Attack Recognition
Terrorist Attack Cycle
Definition
A planning model describing stages such as target selection, surveillance, preparation, execution, and escape.
The attack cycle matters because it shows that many attacks are not spontaneous. They develop through observable stages. If the protection team recognizes early-stage behaviors, it may disrupt the process before execution.
For security driving, the cycle is relevant to routes, routines, surveillance, reconnaissance, predictable stops, and attack-site selection. The driver's daily observations may reveal repeated interest, dry runs, or probing behavior.
This page should connect Volume I's attacker mindset chapter with Volume III's protective intelligence and attack recognition framework.
Common misconceptions to correct
- Attackers are not always impulsive.
- Surveillance may be a stage, not a coincidence.
- Rehearsal and dry runs may look like ordinary incidents.
- The cycle can apply beyond terrorism to organized hostile planning.
Where this concept is treated in the books
- Security Driving - Volume I: The Foundations of Security Driving - establishes the definition, professional identity, misconceptions, attacker mindset, European context, risk, liability, and legal framework.
- Security Driving - Volume III: Advanced Security Driving - applies the discipline through tactical driving, motorcade operations, protective intelligence, route analysis, surveillance detection, attack recognition, and immediate action drills.
- The Complete Handbook of Security Driving - brings the full trilogy together as a complete professional reference for long-term study, training preparation, research, and website cross-linking.
- Book pages: Volume I | Volume II | Volume III | Complete Handbook