Skip to content
    All briefs
    Daily Brief

    Published · 9 items · 3 Global · 3 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    Geopolitics
    Reuters

    Israeli ground operation extends into southern Lebanon; diplomatic security posture across Middle East reviewed by EU missions

    Israeli ground forces made limited incursions into three border villages in southern Lebanon on 9 July, after a Hezbollah drone strike on settlements in northern Israel caused seven civilian casualties. The Israeli Defence Ministry called the operation 'targeted counterterrorism action'. The EU External Action Service then raised the security level for EU diplomatic missions and civilian personnel in Lebanon from Level 2 (Heightened Awareness) to Level 3 (Enhanced Security Measures). All non-essential diplomatic staff must now shelter in place or withdraw to Beirut, depending on where they are. The EU has about 340 civilian staff in Lebanon across EUBAM, UNIFIL civilian components and bilateral missions. If you have staff in Lebanon or plan work in the region, you need real-time travel security monitoring, pre-arranged evacuation routes and a clear answer to who decides on withdrawal. HEAT training remains a practical requirement for anyone deployed near the conflict.

    For staff deployed near conflicts like the one in Lebanon, we provide HEAT training and travel security assessments.

    LockBit affiliate deploys novel firmware-level ransomware targeting building management systems in corporate campuses

    On 9 July CrowdStrike published technical analysis of a new ransomware variant, BrickLocker. A LockBit affiliate used it against building management systems (BMS) at five corporate campuses in the United States and Western Europe over the previous six weeks. BrickLocker targets BMS controllers that run HVAC, access control, fire suppression and physical security. It encrypts firmware configuration rather than data files, so systems can stay out of action even after decryption. In one incident, electronic access control failed across an entire campus for 72 hours and every door had to be overridden manually. This is where cyber and physical risk meet. A successful attack can disable an organisation's perimeter security, open the way for physical intrusion and create life-safety risks through the HVAC and fire systems. Audit BMS network segmentation, make sure BMS controllers cannot be reached from the corporate IT network, and keep offline backup configurations for every building control system.

    Our cyber security team assesses BMS security and the links between your IT network and your building systems.

    Intelligence
    Reuters

    Global K&R premiums rise 18% in H1 2026 as kidnapping activity surges in Haiti, Ecuador, and West Africa

    Lloyd's specialist insurer Markel published its mid-year Kidnap & Ransom market update on 9 July. It reports an 18% average premium increase across K&R products in the first half of 2026. One driver is a sustained surge in kidnapping in Haiti, where gang-controlled territory now covers about 90% of Port-au-Prince. The other is a sharp rise in abductions of executives in Ecuador and across the Sahel and the Gulf of Guinea in West Africa. The report says K&R increasingly hits senior corporate professionals and is no longer confined to aid workers and journalists. Ransom demands have grown in size and complexity, with criminal groups researching a target's finances before an abduction to match the demand to what can be paid. For risk managers, K&R risk assessment belongs in the standard approval process for executive travel to these regions, as part of duty of care. Also check that your K&R cover matches the specific countries and activities involved.

    Before executives travel to these regions, we assess the K&R risk and can provide close protection on the ground.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    Compliance
    EURACTIV

    European Commission proposes mandatory security clearance framework for private contractors accessing EU critical infrastructure

    On 9 July the European Commission published a legislative proposal for a Directive on Security Clearance Requirements for Private Contractors (DPSC). It would require security screening and background vetting for private contractors with access to EU critical infrastructure, classified information environments or systems processing sensitive personal data at EU institutional level. If adopted, it would be the first harmonised EU-wide framework for contractor vetting, which member states now handle inconsistently. Contracting organisations would need certified vetting from accredited national authorities before deploying staff in scope. Major EU security providers welcome the level playing field, while smaller operators worry about compliance costs. For private security in the Netherlands and the wider EU, the proposal speeds up a move toward formal personnel security requirements that run alongside Wpbr licensing. Organisations that build solid vetting processes now will be better placed for the rules expected by 2028.

    For embassies and diplomatic sites, we deploy vetted security officers, which is where EU contractor-vetting rules are heading.

    EU Agency for Law Enforcement Cooperation warns of increased use of encrypted IMSI catchers by criminal networks in border regions

    Europol's European Cybercrime Centre issued a technical advisory on 9 July to national law enforcement and private-sector security professionals. It warns that organised crime networks in EU cross-border regions are using a new generation of encrypted IMSI catchers that are much harder to find with conventional counter-surveillance techniques. The devices are believed to come from grey-market suppliers in South-East Asia and the Middle East. They use frequency-hopping spread-spectrum transmission and frequency bands outside the range covered by most commercial TSCM equipment, which is calibrated for older cellular standards. The advisory links them to high-value cargo theft, drug trafficking and targeted robberies in border corridors, including the Netherlands-Germany-Belgium triangle. For TSCM practitioners, equipment calibrated only for 2G/3G IMSI catcher signatures may no longer be enough. Sweeps in sensitive environments need to cover the full spectrum, including 4G/5G and non-standard transmission bands.

    Our TSCM team uses full-spectrum equipment, so a sweep does not stop at older 2G/3G signatures.

    Geopolitics
    EURACTIV

    Frontex and EUBAM Moldova complete joint border security assessment ahead of Moldova's EU accession preparations

    Frontex and the EU Border Assistance Mission to Moldova and Ukraine (EUBAM) completed a joint assessment of border security capacity on 8 July. It covered Moldova's entire border, including the contested Transnistrian segment, as part of Moldova's accelerated preparation for EU accession. It is the most thorough assessment since Moldova became an EU candidate. It found significant gaps in surveillance technology, border crossing infrastructure and staff training, especially on the Transnistrian segments, which run under a separate informal security arrangement. The findings will feed a €340 million EU-funded border security programme, expected to be approved by the European Parliament before the end of 2026. Security companies with border management, surveillance integration or training capability should watch for procurement in the region. Organisations already working in Moldova, or planning to enter, now have a timeline for aligning with EU security standards.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    Intelligence
    NCTV

    NCTV publishes updated Terrorist Threat Assessment Netherlands: jihadist online radicalisation flagged as growing concern

    On 9 July the National Coordinator for Security and Counterterrorism (NCTV) published the second Dreigingsbeeld Terrorisme Nederland (DTN) update of 2026. The national threat level stays at Level 4 (Substantial), and the update adds new assessments of how online radicalisation develops. It flags faster jihadist radicalisation through encrypted messaging platforms as a growing concern, especially among young men aged 16–24 in cities. In recent cases, the operational planning cycle from the onset of radicalisation to a possible attack has become shorter. The update also records more activity by far-right networks with international links, particularly online communities that tie into foreign conflict narratives. For corporate and event security teams, the practical points are solid counter-terrorism procedures and hostile vehicle mitigation at public-facing venues. Staff should also be trained to recognise behaviour that may signal pre-operational surveillance or attack preparation.

    Our advisory team can turn the DTN update into a threat assessment and awareness training for your staff.

    Physical Security
    ANP

    Gemeente Den Haag completes security upgrade of Malieveld perimeter ahead of summer diplomatic season

    The Municipality of Den Haag confirmed on 9 July that it has completed a security upgrade at and around the Malieveld. This is the large open space next to the Binnenhof government quarter that often hosts big public events and protests. The work includes retractable hostile vehicle mitigation bollards, better CCTV coverage and an improved communications network linking venue security to the Den Haag police central control room. It is part of a wider €12 million programme for public space security in the city. It was finished ahead of the summer diplomatic season, when state visits, ministerial meetings and international events in Den Haag peak. For teams running protective details or event security in the diplomatic quarter, the new infrastructure eases the perimeter burden at Malieveld. It does not remove the need for close protection when individuals and delegations move through the area.

    Our close protection and diplomatic security teams accompany principals and delegations as they move around The Hague.

    Intelligence
    ANP

    Dutch Security Industry Association (NVB) publishes annual sector report: 12% growth in managed security services, TSCM demand up 34%

    The Dutch Security Industry Association (NVB) published its 2025 Annual Sector Report on 9 July, showing continued strong demand growth in the Dutch private security market. Sector revenue reached €2.4 billion in 2025, up 9.3% on 2024. Growth came mainly from managed security services (up 12%), technology-integrated security (up 18%) and specialist services. Within the specialist segment, TSCM-related services grew fastest, at 34% year on year. The report attributes this to greater corporate awareness of state-sponsored industrial espionage after a series of high-profile incidents and AIVD advisories. Executive protection grew 21%, helped by higher awareness of K&R risk and more use by mid-sized companies that used to rely only on standard travel insurance. The report notes continuing consolidation among Wpbr-licensed providers, as smaller operators struggle to meet client demand for combined physical and digital security. The 2026 outlook is 'strongly positive', with NIS2 compliance expected to bring significant additional advisory and assessment work.

    Our TSCM team, available 24/7, sweeps offices and boardrooms in the Netherlands and abroad for the kind of espionage driving this demand.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation