25 Years After 9/11: Lessons for Securing the Homeland

The Tribute in Light rises above the New York skyline from the Brooklyn waterfront across the East River in New York, on September 9, 2025 Photo by Gordon Donovan/NurPhoto via Reuters

Friday marks 25 years since the September 11 terror attacks. Americans are spending the week remembering those who lost their lives and honoring the first responders and others who sprang into action to help. The attacks cast a long shadow, stretching beyond Ground Zero, the Pentagon, and Flight 93 to transform not just the United States but the world.

RAND experts are reflecting on one of the most enduring aspects of this transformation: what we’ve learned about homeland security in the quarter-century since the attacks. Below, RAND researchers answer questions about protecting soft targets, mitigating risks from emerging technologies, and more.

What has stayed with you most about September 11, 2001? How did that day shape the way you think about protecting the homeland?

Heather Williams My professional trajectory has been shaped by many events, but it was set in motion by September 11. The attacks led me to focus on the Middle East and to join the U.S. Intelligence Community. That day stays with me as a reminder that solidarity is interwoven into the American fabric. This is comforting as we grapple with the current national divisions.

My thoughts on September 11 as a policy expert are more nuanced. Policymaking is so difficult because bureaucracy is complex and people are naturally resistant to change. September 11 allowed leaders to overcome much of the resistance, and I lived the positive effects of the Intelligence Reform and Terrorism Prevention Act. At the same time, the reactionary nature of those changes created a patchwork of organizations working on homeland security, largely focused on terrorism as the threat.

That enterprise is now reorienting toward today’s multi-hazard environment but without the catalyst that September 11 provided. Like many others, I’m motivated to build the necessary protective institutions before another tragedy strikes.

Ryan Consaul I think back to the tremendous sense of patriotism and unity born from the great tragedy of 9/11. Sadly, that unity has given way to controversy and division. Congressional oversight remains diffuse, and past bipartisan efforts to enact meaningful legislation to protect the homeland have given way to more-partisan priorities. Given the multitude of threats we continue to face, we need to stand together to tackle ongoing and emergent homeland security challenges.

What have we learned in the years since 9/11 about how best to protect soft targets? What does the evidence say about safeguarding communities from mass attacks by nonstate actors and others?

Brian Jackson For protecting soft targets, we often think first about technology: cameras, weapon-detection systems, or other physical protection measures. But some of the most effective protection comes from the community working together to identify and respond to potential threats. This is called behavioral threat assessment and management, or BTAM, and it’s now one of the ways that the majority of K–12 schools, many workplaces, and some police departments or community safety efforts protect themselves. Teams respond when someone’s behavior suggests they may become violent. Much of what the teams using this approach do doesn’t look like security. For example, they might get the people referred to them into counseling or other programs to redirect them from whatever is moving them toward violence.

BTAM is effective, but it relies on everyone buying in. You can’t intervene with a kid who’s reading violent websites or making threats if their classmate doesn’t let the teacher know what’s happening or if the kid’s parent refuses to let the child work with a counselor. Building and maintaining trust is tough. We tried to use this approach in the years after 9/11; it was a central part of efforts to respond to radicalization to violent extremism. But because many of the other counterterrorism approaches undermined trust with key communities, the strategy was never able to strengthen homeland security as much as it could have.

John Hollywood The evidence supports starting with layered security strategies in which multiple measures work together to improve the chance that an attack will be stopped or at least mitigated.

These security layers start with prevention. Tips from the public to police or on-site security have often helped to foil plots. Look for warning signs that incorporate a strong motivation to attack with concrete actions to prepare. Things like creating attack plans; researching how to attack; seeking to learn from extremists (including traveling to receive paramilitary training); accumulating large quantities of weapons or materials used in the construction of improvised explosives; and probing or breaching potential attack sites. Be aware that most motivations for mass attacks have been personal rather than ideological or partisan.

For on-site security, focus on the basics. Cases where attackers had direct access to a large crowd have tended to have the highest lethality, so consider how to put distance, barriers, and crowd movement between would-be attackers and crowds. Access-control systems—notably exterior and interior door locks, secured windows, and securable entryways—have all been effective and efficient. However, all require training and maintenance.

Bystanders and security have stopped attacks. Groups of bystanders tackling shooters has been extremely effective. Again, training can make responses even more effective. That said, training needs to be low-stress and empowering without causing psychological injuries.

For communities, use interagency teams to support prevention, security training, and response planning. We need to establish and fund teams responsible for both educating the public about what to report and conducting diligent follow-up on reported cases. (Brian mentioned an approach for doing so, BTAM, above.) We then need to ensure advance planning and joint training with those agencies that will respond locally to a mass attack.

For many Americans, the creation of the Transportation Security Administration (TSA) and changes to airport screening remain among the most visible legacies of 9/11. What has research found about the TSA?

Kelly Klima Research over the past 25 years suggests that TSA has played a vital role in reducing the risk of terrorist attacks against U.S. aviation. Since 9/11, there has been no successful terrorist attack on a U.S. commercial flight that passed through TSA screening. This record reflects a layered defense-in-depth approach to screening passengers, baggage, and cargo, alongside intelligence, law-enforcement, and industry partners.

TSA has also balanced security with the need to move millions of travelers and large volumes of cargo efficiently and at reasonable cost. The passenger fee is less than $6 per flight, and the total TSA budget (which includes the development and procurement of screening technology) is about $8 billion in 2026.

That balance of security and reasonable cost continues to improve through better physical and chemical screening technologies, changes in checkpoint design and procedures, and risk-based approaches that focus attention where it’s needed most.

But the threat continues to evolve. Terrorists and insiders may seek to conceal firearms, explosives, or other weapons in new ways. Emerging cyber and other nontraditional threats require constant assessment. Continued investment in advanced detection technologies, process redesign, and responsibly developed AI can help TSA identify threats more accurately and quickly, strengthen aviation security, and improve the passenger experience.

Williams Americans associate TSA with the blue shirts they encounter at the security checkpoint, but the organization has a broader mandate than many realize. One of the other programs TSA manages is the Security Threat Assessment for multiple security credentials, including the Transportation Worker Identification Credential (TWIC) and Hazardous Materials Endorsement for commercial driver’s licenses. RAND research has found that TSA generally executes these programs effectively, at cost, and with timely resolution, in a way that reduces internal threats. For example, TWIC applicants who have no flags for possible disqualifying factors could find a physical card in their mailbox less than six days later.

Many anti-terrorism technologies and capabilities require collaborations between government and the private sector. What have we learned about how to effectively navigate those partnerships?

Thao Liz Nguyen One of the enduring lessons is that the development, maturation, and operational adoption of anti-terrorism technologies can proliferate in well-structured public-private collaboration. After 9/11, the Support Anti-terrorism by Fostering Effective Technologies Act of 2002, enacted as part of the Homeland Security Act of 2002, established the Office of SAFETY Act Implementation and created a statutory framework for evaluating and incentivizing anti-terrorism technologies. From a technology-evaluation perspective, the SAFETY Act not only encourages innovation in the abstract but applies a rigorous process to assessing technical performance, operational utility, and real-world deployment considerations of mature technologies to emerging capabilities.

Designation and Certification protections under the SAFETY Act have helped mature the market for proven security technologies and services by reducing liability uncertainty and signaling that a capability has undergone meaningful DHS review. At the same time, the Developmental Testing and Evaluation Designation protection has been especially important for emerging technologies, because it allows developers to generate operational evidence, refine concepts of use, and test performance in relevant environments before a capability is fully fielded.

What we’ve learned is that effective public-private partnership requires more than funding or policy encouragement; it requires credible evaluation pathways, clear incentives for participation, and mechanisms that help bridge the gap between innovation, validation, and scalable adoption for anti-terrorism technologies.

Of course, new technologies have also transformed the threat landscape. Let’s start with unmanned aerial systems, commonly known as drones. How have drones emerged as a potential threat to people and infrastructure, and what do we know about how to mitigate that threat?

Brendan Toland Drones have rapidly emerged as a threat because these systems have become more capable and more available. Parallel advances in a series of technologies (batteries, electric motors, precision manufacturing, optics) have shrunk the airframe for drones, increased their speed and endurance, and lowered their cost. Additionally, improvements in lightweight cameras, guidance via GPS waypoints, and wire-guided control have made it more difficult to detect and take over hostile drones. Finally, drones come in various forms. This lets bad actors select a drone that is optimal for the intended objective, whether that’s maintaining an eye in the sky or delivering compact items (contraband, bombs) virtually anywhere at speed.

As part of RAND’s work operating the Homeland Security Operational Analysis Center, we evaluated the capabilities of commercially available drones. We found that these systems continue to lower in cost while improving on operationally relevant metrics, such as speed, flight time, and payload capacity. We also developed several high-threat scenarios in which bad actors could use drones to threaten the homeland, including bombing a federal building or delivering a chemical agent outside a major sporting event. Looking across the market, we found more than 500 systems capable of conducting at least one of our high-threat scenarios. This number has only grown in the six years since our research was conducted.

The speed of drones and the ability to launch these systems from virtually anywhere constrains the response time for those working to defend the homeland. In our more recent simulation modeling, we found that defenders had only seconds to a few minutes to detect and defeat incoming drones, depending on the situation. If the adversary uses a drone to provide aerial surveillance, then in many cases the onboard camera enables a stand-off range that undermines detection. Any effective defense requires deploying layered mitigation capabilities in advance, putting these capabilities in the hands of trained personnel, sharing detection information across the homeland security enterprise, and empowering defenders on the ground to make quick decisions.

Christopher Scott Adams Advances in drone technology have made the threat more salient, but the homeland security enterprise has some tools to help mitigate that threat. The Preventing Emerging Threats Act and the SAFER SKIES Act have given key counter-drone authorities to federal and state/local/tribal/territorial law enforcement, respectively. These include permissions, under certain circumstances, to intercept communications between drones and their operators, track and monitor drone flights, and disable, down, or destroy potential threats.

These authorities have allowed DHS and its partners to invest in counter-drone technologies. At RAND, we’ve advised our DHS sponsors on the requirements for effective counter-drone capabilities and the right technology mix. This analysis has informed ongoing counter-drone investments at the border and in defense of major events, such as the World Cup and the Olympics.

Across these assessments, we’ve found a few consistent effective practices to mitigate, though not eliminate, the threat. First, defense-in-depth is key; having multiple types of sensors and effectors (kinetic and non-kinetic) in the same location gives the best chance of detecting and defeating a variety of drone threats. Second, defenders need to plan ahead. This includes resolving authorities issues, developing rules of engagement that are well understood by all operators, and creating information-sharing agreements across responsible agencies. Third, employing automation in defense can provide the speed to respond to a similarly automated threat.

What about artificial intelligence? For example, concerns are rising that AI could enable biological attacks. What do we know about this emerging risk and how best to mitigate it?

Steph Guerra Historically, biological attacks have been rare, unsuccessful, and difficult to execute. That’s because of the technical, operational, and motivational barriers that bad actors face. But AI is increasingly able to lower these barriers by democratizing biological expertise, driving laboratory workflows, raising the ceiling of biological novelty, and circumventing existing biosecurity controls like gene synthesis screening. At RAND, we seek to assess these capabilities to help inform policy action that reduces the risk of misuse while still enabling beneficial scientific innovation.

Our team recently published a biosecurity strategy for the AI era to prevent AI-enabled biological attacks. The strategy is deliberately layered, because different mitigations stop different threat actors. For example, access controls like gene synthesis screening may stop a lone terrorist, but they probably can’t stop a state bioweapons program. But a state program might be deterred from developing bioweapons by credible attribution and rapid response capabilities. Each layer is critical, but only having one is insufficient.

We know AI capabilities in biology are advancing fast, but thankfully the most hazardous thresholds haven’t yet been crossed. That gives us a narrow window to build protective infrastructure before misuse becomes demonstrably easy.

No Comments Yet

Leave a Reply

Your email address will not be published.

©2026. Homeland Security Review. Use Our Intel. All Rights Reserved. Washington, D.C.