Unlikely, but Possible!

Terrorist attacks and active shooter events are among the most complex security challenges in our immediate environment. Many find comfort in old sayings like, “Oh, that won’t happen here,” or “What would anyone want here anyway?” Presumably, this was also the mindset of employees at a McDonald’s branch or a Saturn store in the northwest of Munich—until July 22, 2016. On that day, the gunman David S. killed nine people in Munich, with his first five victims at the aforementioned fast-food restaurant.

We often cling to a false sense of security through denial. The phrases mentioned above frequently resurface in these contexts. However, it’s critical to understand that neither terrorist attacks nor active shooter events are tied to targets that are “worthwhile” in a conventional sense. In a terrorist act, the goal is to spread fear and insecurity, while in an active shooter scenario, strong personal motives and emotions are often at play.

The Location Could Be Anywhere

As the motivations reveal, the crime scene can be entirely random. While active shooter events were once largely associated with the United States, recent trends suggest otherwise. This phenomenon has firmly established itself in Germany. Since 1999, 13 incidents have been classified as active shooter events by German security authorities, resulting in 62 fatalities. It’s neither unrealistic nor alarmist to acknowledge that such events could occur here as well.

Expand the Risk Portfolio

Most organizations are well-prepared for standard scenarios: fire, explosions, hazardous material spills, severe weather, or IT and personnel outages. Particularly in manufacturing industries, these scenarios are often anticipated and rehearsed. In other areas, bomb threats or suspicious objects/packages are also covered. However, active shooter and terrorist attack scenarios are rarely examined in depth within organizations.

Playing the Odds

Companies typically focus their risk assessments on production downtime or technical disruptions. This makes sense given the potential impact and likelihood. Within corporate security, there’s a guiding principle: not everything that is possible is probable. This logic, however, doesn’t justify completely ignoring the threat of active shooter and terrorist events. Often, risk evaluations conclude that these scenarios don’t require further consideration, which is a conscious decision during the risk assessment process.

While recent events have heightened awareness of these exceptional situations, some of the conclusions drawn are alarming for security consultants. A common response to an active shooter scenario is, “We’ll just trigger the evacuation alarm.” This response shows a lack of understanding regarding the motivation and psyche of the attacker, as well as the event itself. Encouraging people to flee directly into harm’s way could amplify the threat—this is clearly a flawed strategy.

Key Differentiator: Motivation

The motivation behind an attack is crucial. For emergency management in an organization, however, it makes no difference whether the attacker is driven by personal or political motives—aside from early detection as part of workplace threat management. Additionally, a blend of motivations has been observed in recent incidents: personal violence is often ideologically justified. Whether a single perpetrator randomly or purposefully threatens, injures, or kills people, or whether multiple perpetrators act together, the execution of such acts is often strikingly similar.

Rule 1: Stay Away from the Attacker!

An “active shooter event” differs significantly from other emergency scenarios, like evacuation during a fire alarm. As mentioned earlier, directing more people into the attacker’s range would be disastrous. The most critical principle is: stay away from the attacker—do not present additional targets!

In the United States, the “Run – Hide – Fight” strategy is used. Similar recommendations exist in Germany and other European countries, such as “Escape – Barricade – Defend.” The expert commission investigating the Winnenden school shooting (March 2009, 16 fatalities) concluded:

“In active shooter and other violent situations, it is crucial to provide early and clear information to promote optimal behavior among those at risk. Unlike other emergencies, such as fire, the recommendation for active shooter situations is: Lock yourself in and barricade. Escape is recommended only as a last resort.”
— Experts Commission on Active Shooters, Baden-Württemberg

Information is Key

These findings remain consistent with response strategies in other European countries. France, the UK, Switzerland—despite slight differences, the core principles remain the same. They emphasize one critical aspect of emergency management: early and clear communication to inform potentially endangered individuals. This requires not only technical alarm capabilities but also proper training for employees on how to respond.

Effective behavioral recommendations include:

  • Avoid direct confrontation unless absolutely necessary.
  • Focus on removing yourself from danger zones or barricading.
  • Understand that self-defense carries significant risks but may be necessary in dire situations.

While the concept of “defend” often stirs controversy—especially when excluded from corporate training citing “company culture”—recent incidents in Germany and France indirectly support the conclusions of the Winnenden commission:

“Attackers are driven by an absolute will to kill; they destroy until exhaustion, planned suicide, or police intervention. They rarely surrender voluntarily. Any delay gives the attacker more opportunity to kill.”
— Experts Commission on Active Shooters, Baden-Württemberg

This must not be sugarcoated: engaging with an armed and determined attacker without proper training is exceedingly risky. The reality of such encounters is starkly different from the heroics often portrayed in movies. However, when no other option remains, rejecting self-defense on ethical grounds in an unethical situation doesn’t make sense. As Major General Christian Trull of the German Armed Forces once said:

“We share the heavy knowledge that humanity and human dignity can be violated, and that preventing such violations may depend on force. Force for good, yes, but still force.”

Clemens Schindler

Security Consultant
Clemens Schindler is your contact person for everything to do with fire protection and security technologies and advises our customers online and on site.

Jetzt weiterlesen!

Cyber Security, Management Consulting, Security Consulting

Security 2025: The top trends that no company can ignore

The security landscape is changing rapidly. To stay protected in the future, companies must focus on trends like OSINT, robotics, and Zero Trust by 2025. This article outlines the five key developments that you can’t ignore and a groundbreaking technology that could transform security.

Uncategorized

Deepfakes: More Than Just a Digital Facelift – A Cybersecurity Threat

I recently came across an interesting article by BlackBerry titled "Deepfakes and Digital Deception." It painted a vivid picture of the rising threat of deepfakes in the cybersecurity landscape. While deepfakes can be entertaining, their potential for malicious use is what truly caught my attention. The article effectively highlights how deepfakes, fueled by advancements in generative AI, are becoming increasingly sophisticated and accessible. This ease of creation, coupled with the persuasive power of deepfakes, makes them a potent tool for cybercriminals.

Uncategorized

EU Cyber Resilience Act: Everything you need to know

The EU Cyber Resilience Act (CRA) is a pioneering step towards greater cyber security for digital products in the European Union. This regulation defines binding security standards and protects consumers and companies from increasing cyber threats. In this article, you will learn everything you need to know about the CRA, its scope of application, the requirements and how companies can prepare themselves.

Alternativ zum Formular können Sie uns auch eine E-Mail an info@concepture.de senden.

Instead of the form, you can also send us an email to info@concepture.de.