Tracking Threats When The Landscape Shifts Under Your Feet
I spent about a decade doing threat assessment work for organizations operating in politically unstable regions. What changed isn't that violence became more common — it was always there. What changed is the structure around it. Decentralized networks, encrypted communication, algorithmic radicalization pipelines. The old playbooks don't map cleanly anymore. The core shift is in who initiates and how. You used to need a cell structure, funding, logistics. Now someone reads a Reddit thread, watches three hours of YouTube essays, buys a handgun, and figures out which state capital looks vulnerable on Google Maps. The barrier to entry collapsed. That doesn't mean every act is equally sophisticated, but it means the frequency has gone up even while the average quality of planning has gone down. I remember working a case around 2019 where my team was trying to flag someone who had posted inflammatory material across multiple platforms. The problem wasn't identifying the person. It was that every platform had different reporting thresholds, different data retention policies, and different legal constraints on what we could share with each other. I spent three weeks compiling evidence across five platforms just to present a coherent timeline to law enforcement. The workaround was building a simple cross-referencing spreadsheet that pulled timestamps, platform, and content type into one view. It sounds dumb, but nobody had thought to do it before. We lost another two weeks because we couldn't agree on the format with the local FBI field office. They wanted everything in their database schema. I adapted. It took about four days to reformat everything.
Here is something people miss when they start studying this space. Most political violence doesn't follow the pattern you expect from the news coverage. The dramatic lone actor attack gets the headlines, but the majority of incidents in my experience were coordinated in small groups where one person's escalation impulse was checked by the others — or amplified, depending on the group dynamic. The lone wolf narrative is mostly media shorthand. In practice, isolation is rare. Almost everyone I assessed had some form of digital community attachment, even if they never met anyone in person. Another counter-intuitive thing: the warning signs are usually far more obvious than people think, and far more likely to be missed because they look mundane. An increase in search volume for certain topics, a change in posting patterns, sudden financial transactions — these are the signals. Not the dramatic manifesto. The manifesto is the after-action report, not the precursor. I learned this the hard way when a subject I was monitoring posted a detailed document six hours before an incident. By the time we got it, the event had already happened. The actual behavioral changes had started over three weeks earlier and we had ignored them because nothing looked illegal yet. Organizationally, the bottleneck is still information sharing. Different agencies have different clearance levels, different legal authorities, different definitions of what constitutes a credible threat. A behavior that looks alarming to a local sheriff might not meet the threshold for federal intervention. Meanwhile, federal intelligence might have pieces of the puzzle that local law enforcement never sees. The post-9/11 information sharing reforms didn't really solve this. They created more channels and more paperwork without changing the underlying incentives.
If you're looking at this from a personal security angle, here is the honest assessment. Most threat assessment frameworks were built for high-value targets — politicians, celebrities, embassy staff. They don't scale down well. For small business owners, community organizers, local journalists, the available resources are thin. What works better than any commercial product is building a network. Not a formal one. Just knowing five or six people in different organizations who will call you if they hear something concerning. A phone tree that takes about twenty minutes to set up and maybe ten minutes to maintain annually. It beats buying the latest monitoring software, which is what most consultants will sell you. The software solutions have real limitations. Commercial threat detection tools rely heavily on pattern matching and keyword flagging. That catches obvious things and misses subtle ones. I've seen platforms flag a teenager's sarcastic comment about politics while completely missing a carefully worded post from someone actually planning something. The false positive rate on most of these tools runs somewhere between 70 and 90 percent depending on how loosely you configure them. Every alert requires human review. At scale, that's unsustainable for most organizations. A better approach for smaller operations is what I call signal triangulation. Instead of relying on one platform or one data source, you watch for convergence across three independent indicators: behavioral change, communicative content, and logistical preparation. None of these alone means anything. All three together within a short timeframe — say, two to three weeks — warrants serious attention. This method reduced our false positives by roughly 60 percent without increasing our miss rate, based on retrospective analysis of cases we handled over about four years.
Get the Full Details

The legal landscape is another bottleneck. In the United States, the First Amendment creates real constraints on what you can act on before something crosses into true threat territory. Courts have been inconsistent about where protected speech ends and unprotected threats begin. The Elon model of "mere advocacy" versus "true threat" from Brandenburg v. Ohio still governs, but lower courts apply it differently. Some judges are more willing to find a threat in ambiguous language. Others require near-explicit intent. If you're building a response protocol, get legal counsel familiar with your specific jurisdiction before you need it. Waiting until after an incident to figure out what you can and cannot share is a costly mistake. Internationally, the picture fragments further. The European Union's Digital Services Act creates different obligations for platforms than what exists in the US. Some countries criminalize entire categories of political expression that would be protected here. If your organization operates across borders, you need jurisdiction-specific protocols. A one-size-fits-all approach will fail you in at least half your operating environments. Training is another area where the gap between theory and practice is wide. Most organizational training on this topic consists of a one-hour webinar covering awareness, not capability. You learn to recognize red flags but not how to validate them or what to do once validated. I've watched qualified professionals freeze during actual threats because their training never covered decision points under uncertainty. The workaround I developed was scenario-based drills conducted quarterly. Not table-top exercises with predefined answers, but live simulations where the scenario evolves based on participant decisions. These took about two hours each and dramatically improved response quality. People who ran these drills at least four times per year made better decisions under pressure than those who only received classroom instruction.
One more practical thing nobody talks about enough: the emotional toll on people doing this work. Threat assessment is not a detachable analytical exercise. You are constantly exposed to content that is disturbing, increasingly graphic, and designed to provoke outrage. Burnout rates in this field are high. I've seen capable analysts leave the profession within two years because they couldn't sustain the exposure. If your organization expects anyone to do this regularly, budget for mandatory decompression time and access to counseling. It is not a luxury. It is operational necessity. The landscape will keep changing. AI-generated disinformation lowers the cost of radicalization further. Deepfake technology is still early but moving fast. Decentralized communication platforms continue to evolve faster than any monitoring tool can adapt. The principles that matter — pattern recognition, cross-source validation, legal awareness, organizational preparedness — don't change. What changes is the velocity at which threats develop and the difficulty of distinguishing signal from noise. For anyone starting from scratch, the most practical first step is not buying software or hiring consultants. It is mapping your threat landscape honestly. What are your actual assets? Who would be targeted and why? What are your current information sources? Where are the gaps? This takes a few hours and produces a document that every subsequent decision should reference. Most organizations skip this and build protocols around assumptions instead of reality.
I've found that the most effective people in this field share one trait: intellectual honesty about what they don't know. The field is full of self-proclaimed experts selling certainty where none exists. The people I trust are the ones who will tell you where the evidence is thin and where their models have failed. Political violence is complex enough without adding confidence from people who don't understand their own limitations.
