Ask ten security professionals what "enough" security looks like for a given facility, and you'll likely get ten different answers — unless they're all working from the same Design Basis Threat.

The Design Basis Threat (DBT) is the formally defined set of adversary characteristics — numbers, capabilities, tactics, and intent — that a facility's physical protection system is designed and evaluated against. It's a concept used widely across nuclear security and critical infrastructure protection, and it originates from a simple, practical problem: you cannot design a protection system against "any possible threat," because that standard is both undefinable and unaffordable. You can, however, design one against a specific, agreed-upon threat.

Why a DBT Matters

Without a defined DBT, security discussions tend to drift into one of two unproductive directions. Either every proposed threat scenario, however implausible, becomes grounds for additional spending — or, just as commonly, ad hoc assumptions about "what's realistic" quietly shrink the threat until the program looks adequate on paper regardless of what it can actually withstand.

A properly developed DBT solves this by giving everyone — the facility operator, the regulator, and the security program designer — a common, defensible reference point. Protection system performance can then be measured objectively: does this system detect, delay, and enable a response against this specific threat, within acceptable timelines? That is a question that can actually be answered and tested.

What Goes Into a DBT

A credible DBT typically characterises an adversary across several dimensions, including:

National regulators — including, for nuclear facilities, guidance referenced in the IAEA Nuclear Security Series — typically require operators to develop and periodically review a DBT (or an equivalent representative threat statement) as part of a facility's licensing and security basis.

The Common Mistake

The most common failure GTS sees in practice is not an absent DBT — it's a stale one. A DBT developed five or ten years ago, never revisited as the surrounding threat environment, technology, or facility mission changed, gives operators false confidence. A protection system can pass every internal review and still be measured against a threat that no longer reflects reality.

Treating the DBT as a living document — reviewed on a defined cycle, and whenever the threat environment or facility mission changes materially — is what separates a security program that merely looks compliant from one that is actually defensible.

A protection system is only ever as good as the threat it was designed against. Get the DBT wrong, and everything built on top of it inherits that error.

GTS supports clients through every stage of DBT development and review — from first-time development for a new program, to periodic reassessment for an established facility preparing for a regulatory review or advisory mission.