You secured the doors, gates and fence, but who is watching the sky? Liam Hutcheson, UK Director, MyDefence explains why organisations face a security challenge above their sites and facilities.
The next security breach may not come through the front door. It may not climb the fence or force a gate. It may already be above the site, unseen, unchallenged and recording.
With the 2026 World Cup recently putting airspace security in the spotlight, attention has naturally focused on stadiums, restricted zones and major public gatherings.
That is understandable, but it risks missing the more important point: drones are not only an event security problem, but they are also becoming an everyday corporate security problem.
Changing the conversation
For decades, organisations have built security around the visible perimeter. They have invested in gates, barriers, guards, CCTV, access control and fence line detection.
Those measures remain essential, but drones expose what that model does not protect: the airspace above the site.
A drone does not need to enter a building to create risk. It does not need to land on a roof, carry a payload or cross a fence line. It may only need to observe, record or appear at the wrong moment.
For a logistics operator, a drone overhead may represent reconnaissance of routes, yards, delivery schedules or loading operations.
For a corporate headquarters, it may introduce espionage, privacy and information security concerns. For venues and public spaces, it raises questions about crowd safety, disruption and duty of care.
The technology may be the same, but the risk profile changes depending on what sits beneath it.
That’s why the conversation needs to move beyond the drone itself. A drone above a site is a test of the organisation below. Can it see it? Can it understand what it is doing?
Moreover, can it tell the difference between careless, compliant and hostile activity? Can it preserve evidence? Can it escalate quickly? Can it explain its decisions afterwards? For many organisations, the answer is still no.
This is not conceptual. UK prisons have spent years dealing with drone-enabled smuggling. Phones, drugs and other contraband flown over walls that were built to stop people, vehicles and objects moving at ground level.
Gatwick Airport showed in 2018 how reported drone activity could disrupt more than 1,000 flights and affect around 140,000 passengers, because uncertainty in the airspace can paralyse decision-making when detection, attribution and response are not mature.
The same lesson now applies to corporate environments.
We are seeing large organisations suffer reputational damage caused by drone operators filming operations. A facility can be filmed from the air, the footage edited without context and the story published before the organisation even knows it has been targeted.
That is a new kind of exposure. It is not intrusion in the traditional sense. It is observation, interpretation and amplification.
Regulation is improving, but not fast enough. From 1 January 2026, any new drone model placed on the UK market must have a UK class mark, while Remote ID requirements are being phased in depending on the class of drone and the category of operation.
Remote ID is intended to help police and enforcement bodies assess whether a drone is being used legally, and it transmits information such as the aircraft’s position, height and route course.
That is progress, but regulation should not be confused with protection. Rules help when operators comply. They help when the drone is broadcasting correctly. They help when someone can detect, interpret and act on the information in time. They do not, by themselves, stop malicious or careless activity.
There is also the question of smaller drones. Sub-250g systems remain particularly difficult for security teams because they are accessible, portable and increasingly capable.
The assumption that small means low-risk is outdated. A small drone can film sensitive activity, support reconnaissance, create disruption or contribute to a coordinated operation. The more difficult issue is response.
Under current UK law, in most cases it is illegal to use equipment that deliberately interferes with wireless communications. That means most civilian organisations cannot lawfully jam a drone, even if they have detected it, tracked it and assessed the activity as hostile.
That position is becoming too prohibitive for high-risk environments. It leaves defenders in a structural imbalance: the drone operator can act immediately, while the organisation below may be limited to calling the police and waiting. In some scenarios, that may be too slow.
This is not an argument for uncontrolled civilian jamming. Interference with communications must be tightly governed, especially in dense urban environments. But other jurisdictions have recognised that a blanket prohibition is increasingly difficult to defend.
The UK needs a more mature conversation about authorised, auditable counter-drone capabilities for specific high-risk sites and defined circumstances.
That conversation can only happen responsibly if organisations can first prove they understand the airspace.
If you can detect, classify and evidence activity in the spectrum, it becomes easier to discuss regulation in practical terms, including when and how more active measures, such as jamming, might be authorised.
If you cannot show what you saw, what you assessed and why you escalated, the argument for additional powers will fail.
Rethinking the perimeter
This is where spectrum awareness becomes central. Most drones rely on radio frequency communications for command, telemetry and video transmission.
Those signals can appear before the drone is visible, before it reaches the fence line and before its purpose is clear.
RF-based detection, such as the systems MyDefence develops and deploys, gives security teams an earlier and richer view of drone activity than visual observation alone.
It can help identify whether a drone is a recreational operator drifting off course, a delivery platform operating outside an expected route, repeated surveillance or activity that requires immediate escalation.
That distinction matters. It allows proportionate response. It creates evidence. It supports engagement with police and regulators. It also gives organisations the foundation they will need if the UK moves towards a more graduated authorisation model for counter-drone measures.
This is why drone detection should not sit at the edge of the security conversation as a specialist technical topic. It belongs in board-level discussions about duty of care, resilience, information security, business continuity and reputation.
The organisations that treat 2026 as a one-off event security exercise will miss the larger lesson.
The organisations that use it to rethink the perimeter will be better prepared for the world that is already here. The fence line was never the whole perimeter. It was only the part we could see most easily.
About the Author
Liam is UK Director at MyDefence, a provider of RF-based drone detection and counter-UAS solutions working with government agencies, critical infrastructure operators and corporate security teams across the world.

