Global
International security developments, NATO, and geopolitical threats.
Russian missile and drone barrage kills at least 12 in Kyiv, hits rail workers
A Russian drone and missile barrage struck Kyiv overnight, killing at least twelve people and directly hitting rail workers, marking a continued shift toward targeting transport and logistics infrastructure rather than purely military assets. For organisations with personnel, contractors, or supply chains touching Ukraine or its immediate neighbours, the strike underscores that rail corridors — increasingly relied upon as air travel and Black Sea shipping routes remain constrained — are now an explicit target set, with direct consequences for evacuation planning, freight continuity, and staff safety near stations and marshalling yards. The attack also reinforces the durability of the broader conflict as a driver of regional instability heading into autumn, with no sign of de-escalation. Firms operating in or transiting the region should reassess duty-of-care obligations for any personnel using Ukrainian rail links, maintain current threat intelligence on strike patterns near transport nodes, and build redundancy into any logistics routing that depends on a single corridor. Diplomatic and embassy-linked operations in the region should also review protective postures given the pattern of infrastructure targeting.
UK households face 'risk premium' on energy as US-Israel war on Iran intensifies
Reports indicate British consumers are now paying a 'risk premium' on energy supply as the US-Israel military campaign against Iran continues, with markets pricing in the possibility of disruption to Gulf oil and gas flows. Even absent a direct interdiction of shipping through the Strait of Hormuz, sustained conflict raises insurance and freight costs that filter through to end-user energy prices across Europe, not only the UK. For corporate security and risk functions, this is a reminder that Middle East escalation now has a measurable, ongoing balance-sheet impact well beyond the region itself, through energy procurement costs, freight insurance premiums, and second-order inflationary pressure on operations. Organisations with material energy exposure — manufacturing, logistics, hospitality, data centres — should stress-test budgets against continued or worsening premiums, review force-majeure and supply contracts for Gulf-linked energy inputs, and maintain intelligence coverage of shipping and chokepoint risk rather than treating the conflict as a distant geopolitical story. Executive travel and asset planning touching the wider Gulf region should also be reassessed in light of the sustained tension.
Infostealer campaigns target Anthropic users, hijacking active sessions
Security researchers report that infostealer malware campaigns are actively harvesting credentials and, more critically, hijacking active session tokens belonging to users of Anthropic's AI services. Session theft is particularly dangerous because it bypasses multi-factor authentication entirely — an attacker with a stolen session token inherits an already-authenticated session without needing a password or one-time code. As enterprises rapidly expand employee access to AI platforms for coding, research, and internal workflows, these accounts increasingly hold sensitive proprietary data, source code, and business context, making them a high-value target distinct from traditional email or SaaS credentials. This should be treated as a signal, not an isolated incident: any organisation issuing AI-tool access at scale needs endpoint hygiene, short session lifetimes with re-authentication for sensitive actions, and monitoring for anomalous session use from new devices or geographies. Security teams should also extend existing credential-theft playbooks to explicitly cover AI-platform sessions, which are often overlooked in identity governance reviews conducted before generative AI adoption accelerated.
European Union
EU security directives, Europol threat assessments, and policy developments.
Sabotage, hacking and drones: Europe searches for a response to the Russian threat
European governments are grappling with a rising tide of hybrid threats attributed to Russia — sabotage of critical infrastructure, cyberattacks on government and corporate networks, and unauthorised drone incursions over airports, military sites, and industrial facilities — with EU coordination on a unified response still lagging the pace of incidents. For organisations operating critical infrastructure, ports, energy assets, or facilities near military or government sites in Europe, this is no longer a background geopolitical risk but an operational one: physical perimeters, airspace above sites, and electronic communications are all now plausible attack surfaces simultaneously. The gap between the threat's evolution and coordinated state response means private-sector security postures cannot wait for EU-level solutions. Boards and security functions should commission current threat and vulnerability assessments covering physical perimeter security, counter-drone detection, and technical surveillance countermeasures for sensitive meetings and facilities, particularly for sites in the Baltics, Poland, and other frontline states, but also for Dutch and Western European sites tied to critical infrastructure or defence-adjacent supply chains.
Sweden's far right entrenches itself at Stockholm Central Station
Reporting from Stockholm describes how far-right groups have established a sustained, organised presence at Stockholm Central Station, one of Scandinavia's busiest transit hubs, targeting migrants and other vulnerable groups and effectively normalising intimidation in a high-footfall public space. The pattern is a useful case study for any organisation with staff, retail operations, or executive travel routed through major European transit hubs: organised extremist activity in transport nodes is not confined to isolated incidents but can become a durable feature of the environment, shifting the baseline risk for anyone transiting, working, or waiting there. Security and travel-risk functions should treat this as a prompt to update protective intelligence briefings for personnel and executives travelling through affected hubs, review situational-awareness training for staff based in or near stations with a documented pattern of organised activity, and ensure hospitality and retail operators in similar high-footfall environments have current threat assessments rather than relying on outdated baseline risk ratings for well-known transit locations.
The Netherlands
AIVD, NCTV, and domestic security developments relevant to Dutch operations.
One killed, two police officers injured in Gelderland shooting; multiple arrests
A shooting in Overasselt, a small village in Gelderland, left one person dead and two police officers injured, with police firing further shots hours later during the follow-up response and multiple arrests since made. Details remain limited, but the extended, multi-phase nature of the police response — an initial incident followed by further armed action hours afterwards — indicates authorities assessed continued risk to officers and the public in the area beyond the initial event. For manned guarding and static security teams operating in the wider region, incidents like this are a reminder to maintain live coordination channels with local police during any extended incident nearby, brief personnel on lockdown and shelter-in-place procedures, and avoid assumptions that an area is clear once initial reporting suggests the incident has ended. Corporate clients with facilities, events, or personnel in the vicinity of Nijmegen and surrounding Gelderland municipalities should request updated situational briefings as the investigation develops and confirm alarm and mobile-response protocols are current for the area.
Kickboxer Badr Hari, with long history of violence, arrested on suspicion of threats
Dutch kickboxer Badr Hari, who has a well-documented history of violent offences, has been arrested on suspicion of making threats, according to Dutch reporting. Details of the specific threat and target have not been disclosed, but the arrest of a high-profile individual with a prior violence record is directly relevant to any organisation, venue, or event that has engaged him commercially or may host him, as well as to anyone who may be a subject of the alleged threats. For hospitality venues, event organisers, and personal security teams, cases like this underline the importance of running current threat and background checks before booking or hosting high-profile individuals with contested public histories, rather than relying on past engagements as a proxy for current risk. Where an organisation or individual believes they may be connected to the matter, a formal threat assessment and, if warranted, protective measures should be arranged promptly. Venues with events involving controversial or high-risk figures should also review access control and incident-response readiness ahead of any related appearance.
Fireworks amnesty launches after ban takes effect, but public reluctant to hand devices in
A national amnesty scheme allowing people to hand in now-banned fireworks has launched in the Netherlands, but early reporting suggests public compliance is low, with most people reluctant to surrender stockpiles. Given the Netherlands' history of localised public-order disruption around New Year's Eve tied to fireworks, low voluntary compliance this early is a meaningful leading indicator for enforcement risk and potential unrest as the ban's effective date approaches at year end. For organisations responsible for public or semi-public venues, retail premises, or residential-adjacent sites, this is a signal to begin — rather than defer — planning for the traditional autumn-to-New Year risk period: reviewing static security and mobile response coverage for late December, assessing exposure to illegal fireworks storage or use near client premises, and factoring possible enforcement-related unrest into risk registers earlier than in past years. Compliance and security teams should also monitor enforcement statistics over the coming months as an indicator of how effectively the ban is landing, since low voluntary turn-in rates now suggest resourcing for December will need to be proportionately higher.
Compiled from credible pro-EU, pro-NATO news sources. Mission Support does not publish operational specifics or unverified claims.
Ready to speak with a specialist?
We respond within one business day. Initial conversations are confidential and without obligation.
Request a Consultation