Evolving third dimension, UAS

Unmanned systems have pushed protective security into a third dimension. From private estates to airports, drones expose gaps in detection, response, attribution and procedure. The challenge is no longer the machine itself, but how access, ambiguity and cognitive effect reshape the protective model.

Evolving third dimension, UAS
Dimensions tell you where harm can arrive from, domains tell you which environment it moved through, and lanes tell you how it travelled and where it changed character on the way. The protective architecture looks complete until you add the vertical axis.

Unmanned Aircraft System and the protective operator

There is a lake in northern Italy where I spent several years of my working life. I knew the property the way you come to know a place you are responsible for: the gravel that announced a car before you saw it, the boats that came too close, the particular sound the gate made when it closed, the line of the trees where the light went at the end of the day. When you have walked the same park a few hundred times, you stop looking and start absorbing. It is a different sense entirely, and it is most of what the job actually is.

One afternoon in 2012, halfway through that walk, I heard a buzzing above me. My first reaction was not professional. For about a second I was completely certain it was a hornet, with whom I have never made peace. I would like to report that I stood my ground with quiet composure. I did not. Then the sound changed, or my ear did, and it stopped being an insect and started being a machine, and the other part of me took over.

I looked up and saw a drone. My first one.

What followed was two men inventing a procedure on the spot, because we did not have one. I filmed it and followed it on foot, keeping it in sight and working out where it had come from. My colleague took the Range Rover and went out through the lanes around the estate to find the pilot, which he did within a few minutes. A father and his son, just outside the property, standing over a new toy on an otherwise pleasant Sunday afternoon. We asked them to respect the family's privacy, and closed the matter there. They agreed, and we walked back.

What has stayed with me for fourteen years is not the drone, and not the father and son. It is that two competent people, on a well-run property, protecting a client we had worked for over years, had no framework at all for an object in the air above us. We had procedures for vehicles, for visitors, for deliveries, for the perimeter, for the approach roads, for household staff, and for incoming helicopters. We had nothing for drones. Our security field stopped at roughly the height of a person, and everything above that line belonged to somebody else. Or so we assumed.

Fourteen years later, the airspace above that line has become considerably more crowded.

Changing register

I was reminded of that afternoon recently in a conversation with a research group at a Dutch university working on the detection and identification of unmanned systems. Two people in the room: a researcher on the technical side and a business unit manager on the programme side. They had asked for practitioner input. It was a good conversation, and it did what these conversations do. It woke the analyst rather than the operator, and drew on both at once.

The object itself is not the revolutionary part. Accessibility, capability and the operating environment around it are. It is cheaper, quieter, faster, and it flies further, but the machine we chased around an Italian hillside in 2012 still belongs recognisably to the same category. What has changed more fundamentally is the landscape around it, and specifically the way the lanes within that landscape now blend into one another. Physical, digital, informational and cognitive risk no longer arrive separately and in sequence. They arrive together and they borrow from each other. For the average security specialist, that is not simply more to learn. It is a genuine problem of cognitive load, and it is part of why so much of our field still treats unmanned systems as a curiosity rather than as a structural change.

The structural change, stated plainly, is this. For the civil protective operator working in permissive environments, the physical security field has moved from two dimensions to three.

That claim needs one qualification, because the third dimension was never absent. Protective work has always understood elevation. The overlooking window, the rooftop, the high ground, the helicopter: all of these were read as threats long before anyone flew a quadcopter over an Italian lake. But they were read through the ground. A marksman reaches a roof by climbing to it. A camera reaches a window because someone carried it there. A helicopter needs an airframe, a pilot, fuel and a flight plan, and announces its arrival several kilometres out. Every one of those was gated by cost, by skill, by infrastructure or by visibility, and almost all of them were reachable through horizontal control. Secure the ground and the advance, and you largely secured the air by extension, because the air was entered from the ground.

For most civilian protective operations, the unmanned system is the first routinely accessible vertical threat that does not depend on the ground we control. It can be put up from a field two kilometres away by someone with no training, no organisation, and no intention of ever being near the site. That is what has actually changed. Not the existence of the third dimension, but the collapse of the barriers that kept it effectively closed, and with it the decoupling of the vertical axis from the horizontal one. An advance that reads a site horizontally no longer covers it by implication.

Side note: dimensions, domains, lanes

A word on vocabulary, because these three terms are used interchangeably in our field and the looseness causes real confusion. They describe different things, and the numbering that circulates informally, cyber as a fourth dimension and cognition as a fifth, mixes two systems that do not belong together.

Dimensions are geometric. They describe where in space something can be. Two is the horizontal plane. Three adds altitude. The fourth, strictly and properly, is time. That is not a rhetorical flourish. Time is already the most heavily worked variable in protective practice: departure timing, route variation, the length of a static exposure, the pattern of life an adversary is trying to establish, the thirty-second window discussed below. A discipline that already thinks carefully in two spatial dimensions plus time is being asked to add one more axis, not to learn a new philosophy. That is the encouraging part of this, and it is worth saying, because the alternative framing makes the problem sound larger than it is.

Domains are doctrinal. They describe operating environments rather than geometry, and they are a military inheritance rather than a physical fact. NATO formally recognises five: land, maritime, air, space and cyberspace, the last of these recognised at the Warsaw Summit in 2016 (NATO, 2016). A sixth candidate has been under discussion for some years, variously proposed as the cognitive, the human, the information or the electromagnetic domain. It remains debated rather than adopted, and several allies and partners already work with additional domains of their own (du Cluzel, 2020). Anyone citing a settled sixth domain is citing an argument, not a standard.

Lanes are mine, and they are practical. A lane is the route a given harm takes and the point at which it hands off to another environment. A digital lure that produces a physical meeting. A narrative campaign that produces a reputational consequence and then a legal one. A supplier compromise that becomes a residential exposure. Lanes are how a protective team should actually think, because a team does not defend a domain. It defends a person, and harm reaches that person by travelling.

Held together: dimensions tell you where harm can arrive from, domains tell you which environment it moved through, and lanes tell you how it travelled and where it changed character on the way.

The unmanned system matters precisely because it sits on the seam. It is a physical object operating in the air domain, now cheap enough that a private adversary can hold that domain for the price of a weekend. And its most common effect in our environment is not kinetic at all. It is informational and cognitive: disruption, intimidation, the demonstration that someone can reach you. The airport case later in this piece is the clean illustration. Nothing is struck, nobody is hurt, and the damage is real. The ambiguity about who was flying it is not a failure of reporting. It is part of the payload.

Friend or foe, tool or threat

A drone over a property, a venue or a route can be any of at least four things: a hobbyist, a commercial operator, a surveillance platform, or a delivery system for something unpleasant. In the environments where the principals I work with actually move, and those are the major cities of Europe, the Gulf, Asia and the Americas alike, the realistic ladder does not begin with a loitering munition over a quiet town. It begins with surveillance. Then intimidation, which is surveillance that wants to be seen. Then, at the far end, a small payload.

The operator on the ground cannot distinguish between those categories at the moment of contact. That is the entire practical problem. A camera and a payload look identical at two hundred metres. The response must therefore default to the least favourable plausible reading, which makes false alarms operationally expensive, and which means that identification, rather than detection alone, is what protective teams actually lack.

It is also why the drone is disruptive out of all proportion to its cost. It does not need to reach a person to do damage. Residences and event sites present a smaller version of the same asymmetry. A great deal of critical infrastructure carries its mechanical plant, cooling, ventilation and power, on the roof, where nobody expected it to be attacked, and a brief incursion into that airspace can force a shutdown that runs for hours. A short sighting near sensitive infrastructure can halt an entire operation, at a cost measured in the millions, without anything being struck and without anyone being hurt. That is the scale of the dimension we are discussing, and it is the same logic the airport case makes visible later in this piece.

The same object is also a tool, and it is worth remembering that. I have thought for years that I would like an overwatch capability of my own, an eagle eye above a moving motorcade, reading the route ahead and seeing what the follow car cannot. It is, after all, precisely the capability now used commercially to monitor vast sites such as offshore installations, pipelines and solar farms. The capability that would serve us is the capability being used against us, and both sides of that symmetry sit inside the same regulatory frame.

That frame is worth stating clearly, because it is regularly misunderstood in our sector. In the Netherlands, responsibility is formally divided: detecting drones over a site is the responsibility of the site owner, while tracking down the operator, seizing equipment and grounding a flight in progress sit with the Koninklijke Marechaussee at airports and military locations and with the police elsewhere (Koninklijke Marechaussee, 2025). Jamming is not available as a private option. The Dutch Telecommunications Act prohibits the deliberate disruption of radio communications (Telecommunicatiewet, 1998), and at European level the Radio Equipment Directive closes the same door on the equipment side (European Union, 2014). Interception of an aircraft in flight, which is what a drone legally is, is a state act.

For the private protective operator, the practical boundary is relatively clear. Detection may be available, subject to the technical and legal constraints of the jurisdiction concerned. Jamming, spoofing or physically intercepting an aircraft in flight generally is not. Those forms of mitigation remain a state responsibility. Any private-sector counter-drone concept that assumes otherwise risks being built around a capability the protective team cannot lawfully exercise.

It is worth noting that the European Commission's Action Plan on Drone and Counter-Drone Security, published in February 2026, is explicitly concerned with civilian internal security and raises the question of which parties may lawfully act against a threatening drone at all (European Commission, 2026). The regulatory picture is moving. It has not moved yet.

Time, not distance

During the conversation I was asked at what distance a drone becomes a concern. My answer was that in protective work we hardly measure in distance. We measure in time.

Take thirty seconds as a working figure: the window between the moment an airborne object is identified as a possible problem and the moment a decision has to have been taken and acted upon. In honesty it is often less. It is a practitioner's heuristic rather than a validated constant, and it moves with terrain, with the principal's position, and with how exposed the movement is. But it is the right unit of measurement, because it is the one that governs behaviour. Thirty seconds is enough to move a person through a doorway. It is not enough to convene anyone, consult anyone, or wait for a state response.

That distinction matters for anyone designing detection systems. A system that reports range and bearing has told a protective team something interesting. A system that reliably converts detection into usable warning time has told them something they can act on.

Who is looking up

Thirty seconds only exists if somebody was looking in the first place. Events are the hardest case for that. A residence can be surveyed once and understood for years. An event is a site you did not choose, occupied for a few days, with no fixed infrastructure, a hotel and an external venue and the movements between them, and a crowd that already consumes most of the team's attention. The airspace above it is uncontrolled in any practical sense. Whatever detection exists has to arrive with the advance team and work on the first morning, which rules out most of what is currently marketed as a solution.

The organisational question underneath it is more interesting than the technical one. Protective formations, in teams large enough to field them, have always worked by dividing arcs. Each agent holds a sector, and between them the sectors close. The change introduced by unmanned systems is not that a new task has appeared. It is that every existing sector now has a ceiling.

How that gets resolved depends almost entirely on team size. On a team large enough to carry it, one agent can be given vertical awareness as a primary responsibility, positioned with an unobstructed arc, elevated where the site allows, and ideally static rather than moving with the principal, because scanning the sky and walking are not compatible activities. That person is not a spotter in the military sense. They are the team member whose sector happens to be above everyone else's.

On a small team, and most private details are small, dedicating a person to the sky is not an option. Attention is finite, and the ground threat remains the more probable one. Every second spent looking up is a second not spent reading the approach, the crowd, or the vehicle that has stopped where it should not have. In that case the vertical component folds into each existing sector, and the question becomes a training question: how does an agent add altitude to their arc without losing the picture at eye level. There is a real cost to this, and it should be stated honestly rather than designed around.

Two practical observations that researchers rarely encounter. The first cue at low altitude is almost always acoustic rather than visual. You hear it before you see it, at least somewhere quiet. On a busy avenue in a major city, with traffic and construction, that acoustic advantage disappears entirely, which is itself worth knowing. The second is that the human layer only covers the low and slow case. It fails at altitude, at night, in urban clutter, and against small platforms, which is precisely the profile of anything flown by someone who does not want to be noticed. Technical detection is therefore not a replacement for the human arc. It is the extension of that arc beyond the point where the eye and the ear stop working.

The same logic runs backwards into advance work. A venue survey has traditionally read a site horizontally: approaches, entrances, sightlines, exits, choke points, the room you move to if something goes wrong. A survey that takes the third dimension seriously adds a vertical read. What overlooks this site. Where could a platform sit and hold position. Where are the natural launch points within a few hundred metres, and are any of them accessible without attracting attention. Where is the nearest overhead cover, and how long does it take to reach it from the positions the principal will actually occupy. None of that requires equipment. It requires the survey to look up, which most surveys still do not.

The vehicle problem

The clearest illustration of the shift sits in something many of our clients already own.

It is often said in our sector that armoured vehicles are simply unprotected from above. That is not accurate, and the accurate version is more useful. Full-vehicle certification under the European VPAM BRV 2009 standard tests the roof explicitly, including shots taken at any impact angle up to ninety degrees, fired from directly overhead (VPAM, 2009). The companion explosive standard includes the detonation of hand grenades on the vehicle roof as well as beneath it (VPAM, 2010). So the roof is tested. The question is what it was tested against.

Those protocols were written against plunging fire and a thrown or dropped grenade, which were the overhead threats that existed when the standards were drafted. They were not written against a munition delivered with precision, at an angle of the attacker's choosing, onto a selected point of a stationary vehicle, by an operator who can see what he is aiming at and can wait until the geometry is right. That is a different problem, and recent conflict has made it the defining one in the military domain, where top attack by cheap unmanned systems has become one of the central lessons of the last several years. The intensity does not transfer to the civil environment. The geometry does. If harm can arrive from above, relatively silent, largely undetected and cheap, a vehicle built against a horizontal threat model is protected in the wrong places.

Two practical consequences follow, and both are procurement questions rather than doctrine questions.

The first is that certification is not uniform. A vehicle certified as a complete vehicle under VPAM is a different proposition from one built to component-level material standards under CEN, where the materials are certified but the finished vehicle is not, and roof coverage becomes a design decision rather than a tested outcome (CEN, 1999). The right question to a supplier is therefore not what class the vehicle holds, but what the roof was tested against, and whether the vehicle was tested as a vehicle.

The second is that the consequences run past the armour specification into how the vehicle is used. Route logic changes, because a hovering platform can wait at a predictable choke point in a way a ground team cannot. Movement itself becomes more valuable, because a moving vehicle remains a difficult target for a cheap airframe. And the standing question in vehicle selection, which for two decades has been about protection level, acquires a second axis. The improvised answers from the battlefield do not transfer either. You can build a cage or a net over a military vehicle, as both sides have done in Ukraine, but that is no answer for an S-Class moving through central Paris. The civil requirement is protection that is invisible, and that constraint is exactly what makes the overhead problem hard.

The asymmetry problem

The most striking example from the conversation was not about protection at all. It was about airports. An individual with a hundred euro drone needs to fly it near or over airport property for a matter of seconds to be detected. At that point the operation is suspended. Aircraft hold, movements stop, and the cost accumulates across the airport, the airlines and the passengers.

The numbers are not speculative. The Gatwick closure over three days in December 2018 disrupted around a thousand flights and affected roughly 140,000 passengers. EasyJet alone reported a fifteen million pound cost. Nobody was hurt. No payload was involved. Two people were arrested and released without charge, and the investigation, which ran eighteen months across five police forces and cost around £790,000, closed without a prosecution (BBC News, 2019).

The pattern has since become routine rather than exceptional. Copenhagen closed for close to four hours in September 2025, with around fifty flights diverted and thousands of passengers stranded, and Oslo's airspace was closed the same evening (AeroTime, 2025). Munich suspended operations twice within twenty-four hours the following month, affecting roughly three thousand passengers on the first night and six and a half thousand on the second (CNN, 2025). The European Commission's own Action Plan cites the repeated trespass of Member States' airspace, the disruption of airport operations and near misses with civilian aircraft as part of the rationale for coordinated action at Union level (European Commission, 2026).

From the perspective of anyone wishing to cause harm without exposure, that is an extraordinary return. It requires no organisation, no funding, no expertise, and no willingness to hurt anyone directly. A bored teenager and a state-aligned actor have access to precisely the same capability, which is one of the defining characteristics of the hybrid environment: the tools have democratised faster than the frameworks meant to govern them. That is hybrid disruption at its cheapest, and it is also why attribution in these cases is so often unresolved, and why the ambiguity is itself part of the effect.

The airport case is the visible version, because the disruption is public and expensive. The same asymmetry applies more quietly to residences, to venues, to events, and to any environment where the appearance of an airborne object forces a protective team to assume the worst and act on it. The sighting may also be a feint, a diversion that pulls attention and people toward the sky while the real approach comes from somewhere else. Distraction is a use of the tool, not only an accident of it.

A more serious version of the same asymmetry appeared at Leipzig/Halle Airport a few days ago, August 2026, where German authorities recovered a drone carrying professional explosives and a detonator close to Ukrainian Antonov aircraft (Reuters, 2026). At the time of writing, attribution and precise intent remain under investigation, and it would be premature to describe the incident as either a failed attack or deliberate signalling. From the defender's perspective, however, the distinction does not remove the larger problem. The platform had reached a protected and strategically important environment carrying an explosive payload. Whether the device was intended to detonate or not, its presence demonstrated access.

That demonstration has consequences well beyond whatever damage the payload itself might have caused. It immediately generates the questions that consume protective organisations: how did it get there, what detected it and what did not, was this the first attempt, was the aircraft the intended target, what else is reachable, and what happens next time if the device functions as intended? An object that may have cost relatively little to deploy can therefore trigger investigation, intelligence collection, additional personnel, new detection capability, revised procedures and changes to the wider security architecture. The physical act lasts minutes. The cognitive and organisational effects can persist for months.

This is where the drone becomes more interesting than the machine itself. It can communicate capability without anyone claiming responsibility: we reached you; your existing architecture did not stop us; imagine what could have happened. Whether that message was actually intended in a particular incident is almost secondary to the protective consequence, because once the possibility has been demonstrated, the defender has to plan against it.

The drone, then, is not primarily interesting because it is a drone. It is interesting because it exposes a weakness in the protective model: an environment, a direction of approach and a set of consequences for which responsibility, capability and procedure have not yet caught up.

What follows

None of this argues for alarm. It argues for framework, and for awareness.

The practical questions in front of the private protective sector are not exotic. What are the standing procedures when an unmanned system is observed over a residence, a venue or a movement? Who in the team carries vertical awareness, and how is that reconciled with the fact that human observation fails at altitude, at night, and against small platforms? How is a repeat sighting escalated, given that a drone seen twice over the same address is not an incident but a pattern, and belongs in the protective intelligence picture rather than the incident log? What is legally available in the jurisdiction concerned, and what is not? And what is the honest answer when a client asks whether they can be protected from something arriving directly from above?

Most protective operations in Europe today cannot answer those questions in writing. That is not a criticism of the people doing the work. It is a description of a field whose reference frame was built for two dimensions and has not yet been formally extended into the third.

In 2012 I chased a drone around an Italian estate with a camera phone and a Range Rover, and found a father and son having a pleasant afternoon. The improvisation was forgivable then. Fourteen years later, the problem is no longer the novelty of the machine but the absence of a framework around it: who detects, who decides, who responds, how the sighting enters the intelligence picture, and how the protective architecture changes when access can come from above. The improvisation was forgivable then. It is less forgivable now.

References

AeroTime (2025) 'Copenhagen, Oslo airports reopen after drone sightings', AeroTime, 23 September. Available at: https://www.aerotime.aero/articles/copenhagen-oslo-airports-drone-sightings-closure.

BBC News (2019) 'Gatwick Airport drone attack: police have "no lines of inquiry"', BBC News, 26 September. Available at: https://www.bbc.co.uk/news/uk-england-sussex-49846450.

CNN (2025) 'Germany's Munich Airport closes twice in two days over "unconfirmed drone sightings"', CNN, 4 October. Available at: https://www.cnn.com/2025/10/04/europe/munich-airport-closed-drones-delays-intl-hnk.

du Cluzel, F. (2020) Cognitive Warfare. Norfolk, VA: NATO Allied Command Transformation, Innovation Hub.

European Committee for Standardization (1999) EN 1063: Glass in building. Security glazing. Testing and classification of resistance against bullet attack. Brussels: CEN.

European Commission (2026) Action Plan on Drone and Counter-Drone Security. COM(2026) 81 final. Brussels: European Commission.

European Union (2014) Directive 2014/53/EU on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment (Radio Equipment Directive). Brussels: Official Journal of the European Union.

Koninklijke Marechaussee (2025) Drones. Available at: https://english.marechaussee.nl/topics/d/drones.

North Atlantic Treaty Organization (2016) Warsaw Summit Communiqué. Brussels: NATO.

Reuters (2026) 'German prosecutor says airport drone was fitted with explosive device', Reuters, 6 August. Available at: https://www.reuters.com/business/aerospace-defense/german-prosecutor-says-airport-drone-was-fitted-with-explosive-device-2026-08-06/

Telecommunicatiewet (1998). The Hague: Government of the Netherlands.

VPAM (2009) BRV 2009: Bullet-Resistant Vehicles, test standard and certification guideline. Association of Test Laboratories for Attack-Resistant Materials and Constructions.

VPAM (2010) ERV 2010: Explosive-Resistant Vehicles, test standard. Association of Test Laboratories for Attack-Resistant Materials and Constructions.


Ombrex Consulting works at the intersection of physical protection, protective intelligence and hybrid risk. Analysis published here is intended as applied guidance for protective and corporate decision-making.