Counter-UAV Planning: Why Training Is the Capability Gap That Procurement Cannot Close
Drones are no longer a military-only threat. Critical infrastructure operators face a growing C-UAS challenge — and the gap that matters most is not in hardware budgets, it is in trained planners.
The Drone Threat Is No Longer a Military-Only Problem
Unmanned aerial systems have moved from the battlefield to the threat landscape of every critical infrastructure operator. Airports, energy substations, water treatment facilities, stadiums, ports, and government buildings now face a threat vector that most security plans were never designed to address: low-cost, commercially available drones that can carry payloads, conduct surveillance, or disrupt operations — and that are difficult to detect, identify, and neutralise under existing legal and technical frameworks.
The numbers make the challenge clear. An attack drone can cost as little as a few hundred euros. A kinetic interceptor costs orders of magnitude more. A defence built exclusively on expensive countermeasures loses the economic contest even when it wins every individual engagement. The answer is not simply to procure more hardware — it is to train the people who plan the response.
Why Planning Comes Before Procurement
The most common mistake organisations make when addressing the drone threat is to start with the technology. They evaluate jamming systems, detection radars, and directed-energy solutions before they have answered the foundational questions: What is the specific threat to this facility? What are the airspace characteristics? Where does the vulnerability begin — and how far *left of launch* can the defence reach?
Without trained planners who can answer those questions, even well-funded counter-UAS programmes produce systems that are deployed in the wrong locations, configured for the wrong threat profiles, and unable to integrate with the legal and command-and-control frameworks that govern their use.
Hardware is necessary. But it is not sufficient. The capability gap that most organisations face today is not in their equipment budget — it is in their planning capacity.
Structured C-UAS Training for Critical Infrastructure
Tools of Tech works with [APSI (Institute for American Policy and Standards Innovation)](https://apsi.org), a US-based policy and standards institute that has trained more than 430 professionals from over 100 organisations in counter-UAS planning for critical infrastructure.
APSI's C-UAS Critical Infrastructure Planners Workshop is a five-day, on-site programme built around applied practice rather than classroom theory. Participants work through guided discussion, tabletop exercises, airspace mapping, and a facility-specific capstone assessment — producing work products their organisation can use immediately upon return.
The programme is structured as a two-certificate sequence:
- —Certificate 1 — Security and UAS Ecosystem and Law: A two-day course covering the legal, regulatory, and operational ecosystem for counter-UAS. Designed for security professionals who need to understand the framework before they can plan within it.
- —Certificate 2 — Counter-UAS Assessment and Mitigation Planning: A three-day course focused on assessment methodology and hands-on planning exercises, including left-of-launch planning. Certificate 1 is a prerequisite.
Graduates leave with a facility and airspace assessment, a written report, a risk-mitigation plan with sequenced and layered controls, and a structured framework for ongoing planning — all vendor-neutral and immediately applicable to their specific environment.
The workshop is delivered on-site, anywhere in the world, including fully mobile delivery. It is designed for planners and officers across government, military, and private sectors: federal and national planners, military planning officers, emergency response leadership, infrastructure operators, and corporate security teams.
The Regulatory Dimension
For organisations operating under the EU's CER Directive (Critical Entities Resilience), the drone threat is not optional to address. The Directive's all-hazards risk assessment requirement explicitly covers physical threats to critical infrastructure — and regulators are increasingly expecting to see drone threat vectors included in those assessments.
NIS2 adds a parallel obligation for network and information system resilience. Organisations subject to both frameworks cannot credibly separate their physical and cyber security postures: a drone that disrupts a control system is both a physical and a cyber incident.
Neither Directive provides by itself the legal authorisation to jam or intercept a drone — that requires explicit national law. But the planning obligation is already there, and the organisations that have trained their planners will be better positioned when regulators ask for evidence.
What to Do Next
Counter-UAS capability starts with trained planners who understand the threat, the airspace, the legal framework, and the layered controls available to them. That foundation cannot be purchased — it has to be built.
