Security Intelligence

Case Study: Building a Defensible Security Decision System in the Horn of Africa

How an international NGO replaced inconsistent movement decisions with shared risk criteria, journey thresholds and accountable escalation, an anonymised practitioner case study.

By Mowlid Ali 13 Sep 2026 8 min Security Intelligence
Source

Originally reported by INGO ADVISORY. INGO ADVISORY analysis is attributable to our intelligence desk; the underlying reporting remains the property of the publisher.

Read the original publication View all 5 citations
Author
Mowlid Ali
Source
INGO ADVISORY
Publication date
13 Sep 2026
Location
Client locations withheld
Country
Horn of Africa
Category
Security Intelligence
Threat level
SUBSTANTIAL — An attack is likely.
Analytic confidence
High
Verification status
Verified
Listen · 2 minReady to play · about 2 min

This anonymised practitioner case study draws on Horn of Africa security-management work. The organisation, country sequence and identifying operational details are withheld to protect the client and its personnel. No invented performance figure has been added.

Client profile

An international non-governmental organisation operating through national and international staff across a volatile Horn of Africa environment. Its work depended on regular road movement, partner access and continuity through periods of political and security deterioration.

Risk scenario

The organisation faced a compound operating problem rather than a single incident: changing armed-actor activity, short-notice route disruption, uneven field reporting and pressure to continue programme delivery. Country-level ratings were too broad for daily movement decisions, while teams were applying different thresholds to similar journeys.

The management problem was not a shortage of alerts. It was the absence of one defensible method for deciding when to move, pause, reroute or escalate.

Actions taken

  • Reframed the risk assessment around staff activities, locations and route segments rather than a single national score.
  • Separated confirmed facts, reported information and analytical judgement in each briefing.
  • Built a 5x5 risk register linking threats, vulnerabilities, controls, residual risk, owners and review triggers.
  • Introduced journey authorisation, check-in windows, no-move conditions and written abort criteria.
  • Defined incident thresholds and decision rights so field, country and leadership teams knew when escalation was required.
  • Converted recurring indicators into a concise briefing rhythm for management review.

Outcome

The organisation gained a common decision framework for security, programme and leadership teams. Journey decisions became easier to explain and audit; escalation was tied to agreed thresholds; and contextual reporting was translated into named actions and ownership. Confidentiality prevents publication of internal metrics, locations and personnel details.

Why the approach worked

The work did not promise to remove risk. It reduced ambiguity. A shared vocabulary, visible assumptions and pre-agreed triggers allowed managers to act before pressure or incomplete information forced an improvised decision.

Transferable lessons for NGOs

  • Assess exposure by activity and route, not only by country.
  • Make the distinction between fact and judgement visible.
  • Write thresholds before the incident, not during it.
  • Give every control an owner and review date.
  • Treat access, programme continuity and staff security as one decision system.
Africa Risk Brief

Get the weekly Africa Risk Brief

Analysis like this — on security intelligence and Africa's highest-risk operating environments — delivered every Monday. Free.

No spam. Unsubscribe anytime. We never share your email.