Two problems in one domain. Securing the drones you operate, and dealing lawfully with the ones you did not invite over your site.

What we track

Counter-UAS powers

EU, UK and US. Which organisations may detect, track or intervene, and where those powers have been extended, including to energy terminals.

Operating rules

EU and US. EASA and FAA requirements for operators, including beyond visual line of sight.

Remote identification

EU and US. What a drone must broadcast, and what you may lawfully do with that data once you receive it.

Critical infrastructure protection

All jurisdictions. Site protection duties where incursions have become routine rather than exceptional.

Supply chain restrictions

US and EU. Restrictions on drone components and manufacturers on national security grounds.

Incursion reporting

All jurisdictions. Who must be told when an unidentified aircraft appears over a regulated site.

Who is in scope

Operators, on one side, through aviation regulation. Registration, competency, operational categories and flight authorisations all attach to whoever flies, including a facilities team using a drone for roof inspection.

Site owners, on the other, through critical infrastructure duties and through the practical question of what to do about an incursion. Energy terminals, airports, ports, prisons, defence sites and increasingly data centres and chemical plants are where this has become an operational problem.

Where the deadlines fall

Operator obligations arrive with authorisations and renewals, so the dates are yours. Counter-UAS powers change by legislative amendment, and each extension names the categories of site and organisation it applies to, which is the detail to check first.

Where organisations get caught

Detection is usually legal and intervention usually is not. Jamming, spoofing and interception are restricted to specified authorities in most jurisdictions, so a site that buys a counter-drone system frequently cannot lawfully use half of it. The workable answer is detection, evidence, and a rehearsed call to the authority with the legal power to intervene.

Three teams, no procedure. Drone incursions cross physical security, aviation regulation and cyber, and organisations usually have three functions with no shared playbook and no agreed threshold for escalation.

Your own drones are aircraft. Teams that adopt a drone for inspection or survey work often treat it as equipment, and discover the registration, competency and insurance obligations only after an incident.

Questions worth asking now

  • Do we operate drones anywhere in the group, and is anyone tracking the authorisations?
  • Which of our sites have had an incursion in the last year, and was it recorded anywhere?
  • What are we legally permitted to do about a drone over our perimeter, in each country we operate in?
  • Who do we call, and have we ever called them?
  • If we bought detection equipment, would the data it produces be lawful for us to hold?
  • Does any regulator expect us to report an incursion, and within what window?

Related domains

Cyber-kinetic and OT security covers the sites most affected. Space systems security covers the positioning signals drones depend on. Export controls covers component restrictions.

All sixteen domains and how the Radar works.