Skip to main content
    Securitas Germany CEO Ralf Brümmer sitting in an armchair looking at the camera.

    A conversation about intelligence-led security

    Securitas Germany CEO Ralf Brümmer discusses evolving risks, resilience, and data-driven security.

    4 min read

    This is an English adaptation of an interview originally published by German business newspaper Tagesspiegel.

    Mr. Brümmer, suspected sabotage incidents, drone overflights, and attacks on critical infrastructure point to an increasingly complex security environment. Which organizations are most likely to be targeted today, and why?

    The range of potential targets has expanded significantly. In addition to critical infrastructure operators, defense companies, technology firms, logistics providers, research institutions, and specialized suppliers are increasingly in focus.

    From our perspective, organizations should spend less time asking, “Are we classified as critical infrastructure?” and instead ask, “What would happen if our operations were disrupted or if key information were lost?” The answer usually reveals a great deal about the organization’s actual risk profile.

    Many current activities remain below the threshold of open conflict, with both intent and attribution often unclear. What characterizes this “gray zone,” and why does it create new security challenges for organizations?

    A defining characteristic of the gray zone is that many activities are deliberately designed to remain below the threshold of open conflict. Increasingly, there is overlap among competitive activity, criminal behavior, activism, influence operations, cyberattacks, and sabotage. This creates uncertainty without allowing intent or attribution to be clearly established.

    As a result, organizations face a new challenge: they must evaluate not only individual incidents but also identify potential connections between them. An anomaly at one facility, an incident involving a supplier, or a digital disruption may seem manageable in isolation. Viewed collectively, however, they may indicate a broader risk.

    This is why maintaining an up-to-date operational picture is becoming increasingly important. The role of a security provider is not to determine attribution or carry out governmental responsibilities, but to help organizations identify, assess, and respond appropriately to relevant risks at an early stage. Data analysis plays a critical role in this process.

    The [January 2026] attack on Berlin’s power supply demonstrated that a single physical attack can affect both communities and businesses for days. How vulnerable are highly interconnected systems today, and where do organizations underestimate their dependencies?

    Interconnectivity delivers substantial efficiency gains, but it also increases vulnerability to cascading effects. Many organizations understand their direct risks very well. What is often underestimated, however, are indirect dependencies on energy providers, telecommunications networks, service providers, logistics partners, and digital platforms.

    That is why we increasingly view security through the lens of resilience and apply this perspective directly to our own business operations. The key question is not only whether an incident can occur, but also what consequences it would have and how quickly an organization can restore operational capability.

    Overhead view of a Securitas guard securing the outdoors of a facility with a Securitas car parked next to him.

    When people think about threats, cyberattacks often come to mind first, while physical security is treated separately. Can physical and digital protection still be planned independently in practice?

    In our view, increasingly less so. Many threats now span multiple domains simultaneously. A cyberattack may be preceded by physical surveillance, while physical sabotage can disrupt digital systems. Drones, access-control systems, sensors, and connected building infrastructure all operate at this intersection.

    That is why Securitas follows an integrated security approach. The goal is to create a common operating picture that combines physical events, digital indicators, and external risk factors. Only by connecting these sources of information can organizations gain the visibility they need to make fast and effective decisions. Today, data is a decisive differentiator.

    You often emphasize that security should be more preventive and information-driven. What exactly does the concept of “intelligence-led security” mean?

    Intelligence-led security means that security measures are not based primarily on historical experience or general assumptions, but on current and relevant information about risks and threats.

    To achieve this, multiple data sources, technological systems, and human analysis are combined to identify patterns, assess risks, and generate actionable recommendations. The objective is to identify risks before they evolve into actual incidents.

    We examine the entire risk context of an organization, from geopolitical developments and threats to employees to local events occurring around a specific site. The integration of open-source intelligence capabilities such as Liferaft into the global Securitas organization reinforces this commitment to advancing security through both technology and data-driven insights.

    Two Securitas analysists sitting in front of several screens.

    Technology and AI help identify patterns and anomalies. Do evaluation and decision-making still remain human responsibilities?

    I firmly believe they do. Technology and AI can analyze large data sets, identify anomalies, and make risks visible more quickly. This dramatically increases both speed and scale.

    However, understanding context, intent, potential consequences, and the most appropriate response remains a human responsibility. Security is always linked to accountability. That is why the experience and judgment of professionals remain essential, from security officers on the ground and control center personnel to specialists who evaluate and continuously improve security programs.

    Automation is particularly valuable when it accelerates routine tasks or prioritizes alerts. Complex security decisions, however, should not be made exclusively through automation. In my view, the most effective approach remains the combination of intelligent technology and human judgment.

    Organizations today face overlapping risks. How do you translate global risk intelligence into concrete protective measures at the local site level?

    The key step is translating global developments into local impacts. Geopolitical tensions, social unrest, and emerging threat patterns are initially abstract pieces of information. They become relevant only when their potential effects on a facility, supply chain, or business operation are evaluated.

    To accomplish this, data, technological analysis, and expert assessment are combined to identify the risks that are truly relevant to a particular client. This allows organizations to implement targeted measures such as adjusted access-control procedures, enhanced situational monitoring, emergency-response exercises, or additional protections for critical assets.

    Critical infrastructure is an obvious target. Increasingly, however, industrial companies, suppliers, and technology providers are also attracting attention. What characteristics make an organization security-relevant or particularly exposed today?

    An organization often becomes security-relevant when it is difficult to replace within a value chain or essential service ecosystem. This may be an energy facility, but it can also be a technology company, supplier, logistics provider, or manufacturer of specialized components.

    Organizations that possess critical know-how, sensitive data, or strategically important technologies may also be exposed. In the defense and dual-use sectors, we are seeing production capabilities, research activities, supply chains, and intellectual property become increasingly important as well.

    Importantly, an organization’s size is not necessarily the determining factor. Highly specialized companies are often particularly attractive targets because of their unique expertise or components.

    As an organization, you should ask yourself: What impact would it have on customers, supply chains, or other businesses if we were unable to operate or if critical information were lost?

    If threats are ambiguous and risks evolve rapidly, how can organizations recognize early signs that they may be becoming a target and make the right decisions in time?

    The first step is a realistic risk assessment. Organizations need to understand which risks are truly business-critical and where the greatest potential impacts lie. This requires a reliable operational picture that takes into account internal dependencies, critical processes, supply chains, and potential vulnerabilities.

    The second step is integrating different security disciplines. Physical security, cybersecurity, risk intelligence, and crisis management should not be viewed in isolation but as components of a unified security strategy. In hybrid risk environments, a shared operational picture that combines physical incidents, digital warning signals, and external developments is essential.

    The third step is the ability to identify relevant developments early. Organizations that merely react to incidents are always one step behind. Modern security is built on situational awareness, preparedness, and effective decision-making.

    The goal cannot be to prevent every incident. Rather, it must be to detect risks early, limit their impact, and remain operational even under difficult circumstances. The organizations that will succeed in the future are those with the clearest operational picture, well-defined decision pathways, and the ability to turn data and intelligence into proactive preparedness. That is what we mean by resilience today.

    • Frequently asked questions

    Sorry, www.securitas.com does not support Internet Explorer. To enjoy our website, try using a newer browser like Chrome, Safari, Firefox, or Edge.