Skip to content
    All briefs
    Daily Brief

    Published · 8 items · 3 Global · 2 European Union · 3 The Netherlands

    Global

    International security developments, NATO, and geopolitical threats.

    Geopolitics
    Reuters

    Gulf maritime tension escalates as Iran-linked vessels shadow US carrier group near Strait of Hormuz

    US Fifth Fleet confirmed on 13 July that three vessels shadowed the USS Abraham Lincoln carrier strike group in the lower Arabian Gulf for about eighteen hours before withdrawing. Naval intelligence assesses the vessels as operated by or for Iranian Revolutionary Guard Corps Naval (IRGCN) units. It is the longest direct IRGCN contact with a US carrier group since April 2024. It also fits a pattern of step-by-step escalation that analysts at the International Institute for Strategic Studies (IISS) describe as deliberate pressure testing ahead of nuclear negotiation milestones. Lloyd's of London Joint War Risk Committee has kept higher war risk premium bands on the Strait of Hormuz corridor since March. Brokers report clients asking for updated risk assessments for staff and vessel movements across the Gulf. If you have operations, staff or supply chain exposure in the Arabian Gulf, UAE, Oman, Bahrain or Qatar, the risk has gone up in concrete terms. Review emergency evacuation plans, duty-of-care procedures and travel advisory status now. The threat is assessed as most acute in the 48 to 72 hours after any declared breakdown in negotiations.

    For staff in the Gulf, we provide travel security advice and close protection while tensions stay high.

    AI-enhanced audio surveillance devices discovered at EU trade negotiation venue in Geneva; TSCM sweep triggered 48 hours after delegation arrival

    Swiss federal security services confirmed on 13 July that a Technical Surveillance Countermeasures sweep at a Geneva conference facility found four concealed audio capture devices. The sweep took place two days into a closed-door EU–Asia Pacific trade negotiation. Two of the devices contained edge-processing AI modules that could filter conversations and selectively transmit content in near real time. Investigators describe them as a significant generational step up from standard room microphones. They were recovered from the conference table, a diplomatic communications terminal cabinet and a ventilation access panel. The source of the implants has not been publicly attributed. The sweep was triggered by a routine alert about an anomalous RF emission, not by a precautionary pre-event protocol, which exposes a serious gap in standard procedure. Sweep before delegations arrive and repeat at intervals during multi-day events. Delegations negotiating in third-country venues should never assume a room is secure without independent verification before the event.

    We carry out TSCM sweeps before delegations arrive and repeat them during multi-day negotiations at third-party venues.

    Physical Security
    Africa Intelligence

    Security driver killed in Kinshasa executive convoy ambush; vehicle hardening and route protocol failures identified

    A security driver working for a multinational mining company was killed on 12 July when a two-vehicle executive convoy was ambushed in Kinshasa, Democratic Republic of Congo. The convoy was travelling from N'djili International Airport to a company site in the Ngaliema district. The principal, a senior executive from a European extractives firm, survived with minor injuries. The company's duty-of-care insurer found three contributing factors. The convoy used a predictable airport route with too little variation. The lead vehicle was a standard commercial SUV without ballistic door protection or run-flat tyres. And no advance reconnaissance of route chokepoints had been done in the 24 hours before the move. It is one of several high-profile convoy security failures in the DRC in 2026. It reflects a wider deterioration in security for foreign corporate staff in Kinshasa and on routes to the mining regions. If you move people in the DRC, review route variation, vehicle specification and pre-movement reconnaissance now.

    Our trained security drivers vary their routes and can provide armoured vehicle escort for executives moving through high-risk areas.

    European Union

    EU security directives, Europol threat assessments, and policy developments.

    Compliance
    EURACTIV

    EU Hybrid Threats Regulation enters implementation phase — member states begin national transposition planning

    After the EU Council formally adopted the Hybrid Threats Regulation on 11 July, the European Commission published its first implementation guidance on 14 July. It covers the definition of a 'hybrid incident', the minimum content of a compliant notification and how national competent authorities will be designated. The guidance clears up several ambiguities in the Regulation. Incidents that combine digital and physical elements need one unified notification, not parallel reports under NIS2 and the Regulation. And the 24-hour clock starts when an incident is 'reasonably suspected', not when it is confirmed. Legal and compliance teams at organisations running critical infrastructure in several member states should check their incident response and notification procedures against the guidance now. The 18-month transposition period runs alongside a live threat. If you have significant exposure in the Netherlands, note that the NCTV has signalled it intends to transpose ahead of the standard window.

    Our advisory team helps you classify hybrid incidents and file one compliant notification within the 24-hour window.

    Intelligence
    Frontex

    Frontex expands EUROSUR integration to include non-state threat actor tracking in the Mediterranean corridor

    Frontex announced on 13 July that it is widening the operational mandate of the European Border Surveillance System (EUROSUR). It will now track, in real time, vessel movements linked to non-state threat actors across the Central and Eastern Mediterranean, including human trafficking networks, smuggling operations and possible hostile reconnaissance. The expansion combines patrol data from member state coast guards, commercial AIS feeds and Copernicus satellite imagery into a single operational picture. That has practical value for security professionals with maritime or coastal assets in the Mediterranean, and for organisations responsible for staff travelling through the region. In effect it adds an early-warning layer on threat actor movements that can inform route planning, vessel escort needs and shore-side security. Mediterranean member states have been invited to appoint liaison officers at Frontex's Situation Centre for real-time data exchange.

    We provide close protection and escorts for staff working in or travelling through the Mediterranean region.

    The Netherlands

    AIVD, NCTV, and domestic security developments relevant to Dutch operations.

    Intelligence
    MIVD

    MIVD annual report: foreign military intelligence operations against Dutch defence industrial base at record level

    The Military Intelligence and Security Service (MIVD) published its annual threat assessment on 14 July. It names the targeting of the Dutch defence industrial base by foreign military intelligence services as the most significant espionage trend of the past year. Detected collection attempts rose about 40% year on year. Activity is concentrated around firms in drone component supply chains, naval vessel systems integration and optronics manufacturing, which reflects the priorities of states involved in, or preparing for, large-scale conventional conflict. The MIVD explicitly describes a combined digital and physical approach. Cyber intrusion is used to identify key staff and meeting schedules, followed by physical surveillance and attempts to plant technical collection devices in offices and meeting rooms. Dutch defence suppliers include tier-two and tier-three firms that may underestimate how attractive they are as soft targets. For all of them, the assessment effectively requires a review of both cyber and physical security, including TSCM for sensitive project discussions.

    For defence suppliers at every tier, we sweep meeting rooms before sensitive project discussions and advise on physical security.

    Physical Security
    Port of Rotterdam

    Rotterdam port authority upgrades vessel access security following MIVD alert on sabotage risk to critical maritime infrastructure

    On 13 July the Port of Rotterdam Authority announced it is fast-tracking stricter vessel access screening at three critical terminal groups. They are the deepwater LNG terminal, the chemical storage complex in the Botlek district and the container terminal at Maasvlakte 2. The move follows an MIVD intelligence advisory that assesses a higher risk of maritime infrastructure sabotage by state-sponsored actors over the next six months. The new measures include mandatory advance notification windows for arriving vessels and more underwater hull inspections at the LNG terminal. At the chemical terminal, the Koninklijke Marechaussee will take part in perimeter access control. Together, the advisory and the port's response show physical security for critical infrastructure being recalibrated across the Netherlands. The MIVD's assessment of sabotage risk from actors linked to Russia's naval intelligence (GRU Main Directorate) has sped that up.

    We provide manned guarding and physical security assessments for port and critical infrastructure sites in the Netherlands.

    Geopolitics
    Rijksoverheid

    Dutch government issues executive travel security advisory for Gulf Cooperation Council states amid regional tensions

    On 14 July the Dutch Ministry of Foreign Affairs raised its travel advice for Bahrain, Kuwait and the wider Arabian Gulf from level 1 (basic safety) to level 2 (be extra cautious). It cites the heightened regional security situation after the sustained IRGCN naval pressure campaign against US assets in the Strait of Hormuz. The advice names risks to business travellers and corporate delegations, and recommends sharper situational awareness, security briefings before travel and clear emergency contact arrangements with the home organisation. Dutch companies with operations, supply chain exposure or staff movements in the Gulf Cooperation Council states, especially in energy, logistics and finance, now face a clear duty-of-care expectation. Security advice and emergency response arrangements should be in place and tested before anyone travels.

    For Dutch executives travelling to the Gulf, we arrange close protection on the ground, backed by a pre-travel briefing and an extraction plan.

    Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.

    Ready to speak with a specialist?

    We respond within one business day. Initial conversations are confidential and without obligation.

    Request a Consultation