Seeing the Threat, Understanding It Too Narrowly: What 9/11 Still Has to Teach NATO
Updated: Sep 12

Twenty-five years after the attacks of September 11, 2001, the temptation is to mark the anniversary by retelling the day itself, the burning towers, the grounded flights, the images that an entire generation absorbed before it fully understood what it was watching. That story has already been told many times over, in documentaries, congressional hearings, and the exhaustive record of the 9/11 Commission. The more useful anniversary exercise is harder: asking not what happened, but why the warnings that preceded it were not enough to prevent it, and whether the institutions built in its aftermath are making the same category of mistake today, only in a different domain.
The uncomfortable truth about September 11 is that it was not primarily a failure of information. Al-Qaeda was not an unknown organization to American intelligence agencies in the summer of 2001. There had already been an earlier bombing at the World Trade Center in 1993, attacks on the American embassies in Kenya and Tanzania in 1998, and the bombing of the USS Cole in 2000. The threats existed. What did not exist, in sufficient measure, was an institutional apparatus capable of weaving them into a coherent picture in time to act.
This is the argument at the center of Amy Zegart's landmark study of the intelligence failures that preceded the attacks. Zegart spent years examining more than three hundred intelligence reform recommendations issued in the decade before 9/11 and reconstructing, through declassified documents and dozens of interviews with senior officials, how the CIA and FBI actually functioned as organizations during that period. Her conclusion was not that individual analysts missed an obvious signal, but that longstanding organizational weaknesses left unaddressed through the 1990s kept the CIA and FBI from acting on numerous chances to disrupt the plot, a number she puts precisely at twenty-three missed opportunities. Political leaders, her research shows, were not oblivious to the danger. They understood that a serious terrorist threat was emerging and that intelligence reform was overdue. What blocked reform were the ordinary, durable obstacles that beset large bureaucracies everywhere: internal resistance within the agencies themselves, the career incentives of officials who had every rational reason to defend existing turf, and the fragmented structure of the American government itself, which distributes authority in ways that make coordinated adaptation difficult even when everyone agrees adaptation is needed.
That is a more disturbing finding than a simple story of incompetence, because it means the problem was structural rather than personal, and structural problems do not resolve themselves simply because a catastrophe demonstrates their cost. Intelligence, on this account, is not only the business of collecting facts. It is the harder business of interpretation: recognizing that a pattern of isolated incidents has become something categorically new, and overriding the institutional habits built for a previous era of threat.
The response that followed September 11 was, in its own terms, remarkable. Western governments made counterterrorism a central organizing priority almost overnight. Intelligence services expanded cooperation across borders. Governments poured resources into aviation security, border controls, financial monitoring, and dedicated counterterrorism capacity. NATO itself was transformed by the experience in a way that would have seemed almost unthinkable the week before the attacks. On September 12, 2001, the Alliance invoked Article 5 of the Washington Treaty for the first and only time in its history, extending its collective defense guarantee to cover an attack carried out not by a hostile state but by a non-state terrorist network. NATO subsequently built an entirely new set of institutional muscles around expeditionary deployment, counterinsurgency, and stabilization operations, most visibly through its long engagement in Afghanistan.
All of that adaptation was justified by the threat it addressed. But it illustrates a second lesson that deserves at least as much attention as the first, and one that is more directly relevant to the choices facing European security institutions today. Institutions do not merely respond to the threats they face. Over time they organize themselves around those threats, building doctrine, budgets, career paths, and expertise that all point toward the last confirmed danger, even as the world outside continues to change.
This is precisely the tension NATO confronts now. Russia's full-scale invasion of Ukraine has, for entirely sound reasons, pushed the Alliance back toward its founding logic of deterrence, territorial defense, and readiness for large-scale interstate war. That refocusing is necessary and overdue. But it is not the whole of the security environment NATO members actually inhabit. Alongside the return of conventional military danger, European states are contending with a steady stream of hybrid activity: cyber intrusions against critical infrastructure, sabotage of undersea cables and rail networks, covert foreign interference in domestic politics, coordinated disinformation campaigns, and forms of coercive pressure explicitly designed to stay below the threshold that would trigger a collective military response.
The parallel to 2001 is not that terrorism and hybrid threats are the same phenomenon, because they plainly are not, differing in actors, methods, and strategic aims. The parallel is institutional. In both cases, the central danger is not an absence of information. Individual hybrid incidents are usually detected. A cyberattack looks like a cyber incident, an act of sabotage looks like an isolated criminal act, interference in an election looks like a domestic political dispute, and a disinformation campaign looks like an unusually noisy news cycle. What is much harder for any bureaucracy to do, whether it was the CIA in 1999 or a European interior ministry today, is to recognize when a series of individually explicable incidents actually forms part of one deliberate strategic pattern.
That recognition problem is the real inheritance of September 11 for the present moment. The question worth asking on this anniversary is not whether NATO should prepare for major interstate war, since it plainly should and Ukraine has made that unmistakable. The question is whether an Alliance that becomes extremely good at preparing for that one contingency risks developing the same kind of institutional blind spot that left American intelligence agencies unable to see 2001 coming, this time toward the pressure that adversaries apply well before any war actually begins.
Twenty-five years ago, the failure was not that nobody saw the warning signs. It was that the warning signs were read through an understanding of threat that had already become outdated. The lesson worth carrying forward is not a lesson about terrorism specifically. It is a lesson about the limits of institutional imagination, and about how easily an organization can mistake vigilance in one domain for security in every domain that matters.
Photo: REUTERS/Stringer
____________________
By Megi Benia, Founder and Director of SSI

Comments