SGShelby Glaskin All articles

Decision making

Nobody buys detection until after the first incident

September 2026 · 7 min read

Counter-drone investment repeatedly follows the incident that justified it. The pattern says less about competence than it does about how organisations allocate money against unfamiliar risks.

While assembling the evidence for a white paper on Australia's exposure to small drones, I put together a table of recent counter-drone investment. It was meant to be a reference table. It turned out to be the most interesting thing in the document, though not for the reason I built it.

Gatwick installed a £5 million detection network. It did so after the December 2018 closure that cost it and its airlines around £50 million. Victoria funded $420,000 of corrections detection equipment. It did so after prison drone incidents rose 246 per cent in eight months. Belgium approved a €50 million counter-drone package on 8 November 2025, four days into the intensified phase of the incursions over its airports and military bases.

Three jurisdictions, three sectors, three sensible decisions. Every one of them made after the event that justified it.

This is not a story about incompetence. Each of those decisions was defensible at the time it was taken, and the officials who took them were not being negligent beforehand. It is a story about how organisations allocate capital against a particular shape of risk, and the shape matters more than the subject. Low probability, high consequence, physical, and unfamiliar. Drones happen to be the current example. The pattern is older than they are.

Consider what the business case for pre-incident detection actually looks like. You are asking for money against a threat that has not occurred at your site, cannot be quantified in the usual frequency-times-consequence way because the frequency is unknown, has no regulatory deadline attached, and competes against risks that already have incident histories and owners. If nothing happens, nobody notices the spend was unnecessary. If something happens and nothing was bought, the failure is legible and attributable. Rational actors respond to those incentives by waiting, and the waiting is not usually a decision anybody makes. It is a decision nobody makes, repeatedly, which is harder to correct.

There is also a salience problem. Cyber risk reached standing board attention in Australia partly through *ASIC v RI Advice*, which established that cyber controls had become too foreseeable to leave to the IT function, and partly because almost every director knows someone whose organisation has been hit. Physical risk of this kind has neither. The evidence base is real, but it lives in other people's countries and other people's sectors, which is not how organisational attention works. Both risks are foreseeable, both are documented, both engage director duties, and only one gets standing attention. The asymmetry is not about the quality of the evidence.

One Australian data point cuts against the pattern, and it is instructive. Defence committed up to $7 billion to counter-drone capability over a decade, announced in April 2026, before the confirmed incursions over RAAF Base Williamtown in July. That is genuinely anticipatory spending. It is also the exception that demonstrates the rule, because Defence is the one Australian organisation with a threat assessment function whose entire job is to be persuaded by evidence from other people's countries. Almost no commercial operator has that, and almost none will build it for this.

So the practical question is not how to become Defence. It is what a private operator can reasonably do before the incident that makes the decision easier when it arrives.

Three things, none of which requires capital.

Start a pattern-of-activity register. Log every sighting, with time, location, direction and duration, in a form somebody reviews monthly. It costs nothing, and it converts "we think there have been a few" into evidence. It is also the only way you will ever know whether something is a pattern rather than an anomaly, which is the distinction that changes what a response is worth.

Build the escalation matrix on behaviour rather than on identity. Almost every peacetime incursion on record closed without a publicly identified operator, from Gatwick to the 2025 European wave, and Australia's own defence and corrections cases follow the same pattern. A decision threshold that waits on knowing who is flying will not trigger. One built on observed behaviour will.

Exercise the decision, not the equipment. The Gatwick closure ran across three days in significant part because nobody could confirm when it was safe to reopen. That is a decision problem. It can be rehearsed around a table, this quarter, with the people who would actually be in the room, for the cost of an afternoon.

None of that is a substitute for detection. It is the thing that makes the detection case when the time comes, and it means the first incident produces a considered response rather than an expensive one.

The organisations in that table all bought sensible equipment. They simply paid for the evidence first.

This argument draws on the consequence and governance analysis at sections 9 and 14 of the white paper Distance Is Not a Defence: Australia's Vulnerability to Small Drones, available on this site.

Read Version 8 of the research paper