European aviation consulting, SORA, risk, audits and compliance

How to build a counter-UAS threat evaluation framework

A practical C-UAS risk assessment starts with site-specific threat scenarios, evidence-led sensor choices and response steps that stay within lawful authority.

By Anke Weber·October 3, 2026·4 min read
What matters here
  1. A useful counter-UAS assessment ranks specific intrusion scenarios, not drones as a single generic threat.
  2. Choose sensors against site needs, coverage gaps and evidence requirements—not a technology checklist.
  3. Detection does not grant authority to interfere with a drone; response permissions must be established in advance.

For an airport or critical infrastructure operator, counter-UAS planning is not a shopping exercise. The first task is to decide what a drone intrusion could do at this particular site, how the operator would recognize it, and who is allowed to act. A C-UAS risk assessment should connect those decisions before the organization chooses sensors or writes response procedures.

1. Define the site and the decision

Start with a map of the operating environment. Mark runways, approach and departure paths, fuel or energy facilities, communications sites, public areas, access points and neighboring land uses. Note normal aircraft and drone activity, controlled or restricted airspace, operating hours, weather conditions and any terrain that limits visibility.

Then name the decisions the system is expected to support. For example: alert air traffic control, verify a report, protect a defined area, pause an activity or notify emergency services. Each decision needs an owner. If the team cannot say who receives an alert and what they may do next, adding detection equipment will not solve the core problem.

2. Write threat scenarios before assigning scores

Build a short list of plausible scenarios rather than treating every drone as equally dangerous. Consider where an aircraft could approach from, whether the activity appears deliberate or accidental, what asset or operation could be affected, and how long the site would have to respond. Include false reports and benign drone activity: these can consume staff attention and disrupt operations if procedures are vague.

For each scenario, record likelihood, consequence, warning time and uncertainty. Keep the reasoning visible. A low-confidence report near a sensitive area may need a different verification step from a confirmed track near an active runway. Avoid scores that create false precision; the purpose is to compare priorities and expose assumptions.

Assign a risk owner and identify what evidence would change the rating. That could include repeated incursions, a new operating pattern, a change to site activity or a sensor blind spot. Set a review trigger as well as a calendar review, so the assessment is revisited when conditions change.

3. Match sensors to the problem

Only after the scenarios are clear should the site assess sensor options. Compare technologies by the information they can provide at the location: detection range under local conditions, coverage of likely approach routes, performance in clutter or poor weather, ability to distinguish a drone from other objects, and the quality of records available for later review.

Map coverage gaps against the site plan. Check where buildings, terrain, reflective surfaces, nearby activity or restricted access could affect performance. Decide what the organization needs to know: presence, location, direction of travel, identification confidence or a record suitable for investigation. A sensor that detects an object but cannot provide useful context may not support the intended decision.

Evaluate the operating burden, too. Who monitors alerts? How are reports verified? How will teams handle outages and conflicting sensor reports? Test the proposed arrangement against realistic scenarios, including false alarms and loss of coverage. Sensor fusion may help in some deployments, but it needs a clear case, defined limits and an operating authority; the case for sensor fusion in Nordic civil airspace is a useful companion to that decision.

4. Set a lawful response ladder

Separate observation, verification, operational mitigation and any action intended to interfere with a drone. Detection alone does not confer authority to take action against an aircraft or its control link. Do not assume a facility’s security role, a sensor capability or an emergency makes a response lawful.

For each step, document who may act, who must be notified, what information is required and what conditions trigger escalation. Confirm permissions and responsibilities with the relevant aviation and public authorities, and obtain appropriate legal advice for the jurisdiction and site. This is especially important where civil aviation, military interests, law enforcement or critical infrastructure responsibilities overlap.

Write procedures for an uncertain track as well as a confirmed intrusion. Include notification channels, decision time limits, the person authorized to pause or alter site operations, and how the event will be logged. Keep the response proportionate to the evidence and avoid procedures that encourage staff to improvise technical countermeasures.

5. Exercise, record and revise

Run tabletop exercises before relying on the framework. Use scenarios such as a report from a member of the public, an alert near an operational area, conflicting sensor indications and a detection-system outage. Check whether staff can reach the right decision-maker, distinguish confirmed facts from assumptions and follow the notification chain without disrupting unrelated operations.

After an exercise or real event, record response times, missed handoffs, false alarms, evidence gaps and operational impacts. Assign corrective actions to named roles and track completion. Reassess the threat when the site changes, regulations or responsibilities shift, or incident evidence alters the original assumptions.

A counter-UAS framework is useful when it makes decisions clearer, not when it merely lists equipment. North Sky Aviation Consultancy offers drone operations, counter-UAS, air traffic control and risk management consulting, alongside advice on EASA regulations and Norwegian aviation law. For organizations in Norway, Sweden and Denmark, specialist drone consultancy can help test whether threat assumptions, operational needs and compliance responsibilities fit together. Contact North Sky at [email protected] or +47 971 74448 to discuss a site-specific assessment.

More from North Sky Aviation Consultancy News