The Apex Threat Event Framework (Soft Targets and Crowded Places)
- Montane PS Staff

- 3 hours ago
- 4 min read

Safeguarding Today's Priorities. Preparing for Tomorrow's Challenges.
Security incidents involving terrorism, violent extremism and serious criminal violence rarely occur spontaneously.
Most attacks evolve through a series of identifiable stages involving planning, preparation, reconnaissance, target selection and execution. While the specific motivations, tactics and methods may vary, many attacks follow similar behavioural patterns and progression pathways.
Understanding these pathways provides organisations with a significant opportunity.
Rather than focusing exclusively on responding to an attack once it occurs, organisations can identify opportunities to detect, deter, disrupt and respond before an attacker achieves their objectives.
To support this approach - based on current law enforcement guidelines and realworld experience - Montane developed the Apex Threat Event Framework, a practical model designed to understand and disrupt the progression of terrorism, violent extremism and serious violent criminal attacks against soft targets and crowded places.
The framework identifies key phases of an attack and the protective security opportunities that exist throughout the threat event lifecycle.
Why Understanding Attack Progression Matters
Traditional security planning often focuses heavily on the moment an incident occurs.
However, every attack is preceded by a series of activities that create opportunities for intervention.
These opportunities may include:
Identifying suspicious behaviour
Detecting hostile reconnaissance
Recognising attack preparation
Implementing protective security barriers
Enhancing response capability
Reducing attack effectiveness
Supporting recovery and resilience
By understanding how attacks typically evolve, organisations can shift from a purely reactive security posture towards a proactive and threat-informed approach.
The Apex Threat Event Framework
The Apex Threat Event Framework divides an attack into three key phases:
Pre-Attack Phase
Attack Phase
Attack Extension Phase
Each stage creates opportunities for protective security interventions and response actions.

Phase 1: Pre-Attack
Understanding the Threat Before the Attack Occurs
Before carrying out an attack, offenders typically undertake a period of preparation.
This may include:
Developing motivation
Planning activities
Obtaining materials
Conducting reconnaissance
Identifying logistics and movement pathways
The duration of this phase can vary significantly depending on the offender, target and intended attack methodology.
The key characteristic of this phase is that opportunities often exist to detect suspicious activity before harm occurs.
Examples may include:
Hostile reconnaissance
Suspicious enquiries
Unusual photography
Attempts to gain information
Procurement of attack materials
Online indicators of mobilisation
This phase represents one of the most valuable opportunities for security intervention because the attacker has not yet initiated the attack.
Phase 2: Attack
The Attack Begins
Once an attacker commits to action, the focus shifts from prevention towards protection, disruption and rapid response.
Within the framework, this phase can involve:
Infiltrating the Perimeter
Attempting to gain proximity to a target.
Infiltrating the Entrance
Bypassing or exploiting access controls.
Infiltrating the Interior
Moving within a location to maximise access to potential victims.
Attacking Occupants
Initiating violence against people within the target environment.
The framework highlights that soft targets and crowded places are often attractive because they provide:
Large numbers of potential victims
Open access arrangements
Limited security controls
High visibility
Significant psychological impact
Protective security measures implemented during this phase aim to increase attacker difficulty, delay progression and improve response effectiveness.
Phase 3: Attack Extension
Limiting Consequences and Saving Lives
Once an attack has commenced, preventing all harm may no longer be possible.
The focus becomes:
Protecting life
Reducing casualties
Supporting emergency response
Limiting attack duration
Enabling recovery
Attackers may attempt to:
Extend the duration of the incident
Increase the number of casualties
Continue movement through a location
Escape the attack scene
The framework recognises that response capability can significantly influence outcomes.
Every minute gained through effective protective security measures, emergency response and incident management may reduce harm and improve survivability.
Protective Security Layers
One of the most important aspects of the framework is that security measures should not be concentrated at a single point.
Instead, organisations should apply layered protective security controls throughout the threat event lifecycle.
The framework identifies six key functions:
Deter
Discourage an attack through visible security measures, policies and environmental design.
Detect
Identify suspicious behaviour, hostile reconnaissance and emerging threats.
Disrupt
Interrupt attack planning, preparation or execution.
Delay
Increase the time and effort required for an attacker to progress.
Respond
Enable rapid and coordinated incident management.
Recover
Restore operations and support organisational resilience following disruption.
Together these layers create multiple opportunities to intervene before, during and after an attack.
From Protection to Resilience
The Apex Threat Event Framework is not solely about preventing attacks.
It is about improving organisational resilience.
No security measure can eliminate every threat.
However, organisations that understand attack progression are better positioned to:
Identify vulnerabilities
Prioritise investment
Improve preparedness
Strengthen response capability
Support recovery activities
Reduce overall consequences
This approach shifts the conversation from security compliance towards genuine organisational resilience.
Supporting the Montane Methodology
The Apex Threat Event Framework aligns directly with Montane's threat-informed protective security methodology.
UNDERSTAND THE THREAT.
Recognise how threat actors plan, prepare and execute attacks.
MANAGE THE RISK.
Implement layered protective security controls that reduce exposure and vulnerability.
BUILD RESILIENCE.
Prepare organisations to respond, recover and adapt when incidents occur.
Final Thoughts
Effective security requires more than reacting to incidents after they occur.
It requires understanding how attacks develop, where opportunities for intervention exist and how layered protective security controls can influence outcomes.
The Apex Threat Event Framework provides a practical way of understanding the progression of terrorism, violent extremism and serious violent criminal attacks while identifying opportunities to deter, detect, disrupt, delay, respond and recover.
Because understanding the threat is the first step towards reducing risk and building resilience
Ready to take the next step?
Montane Protective Security
UNDERSTAND THE THREAT.
MANAGE THE RISK.
BUILD RESILIENCE.
Safeguarding Today's Priorities.
Preparing for Tomorrow's Challenges.
Threat-informed protective security, risk management and resilience solutions.




Comments