Farage Terror Charge: Threat Case Continuity
One of the easiest ways for a protection program to miss a developing problem is not failing to collect information.
It is collecting the information and then losing the connection between events.
An unusual incident happens at a residence.
Nothing else immediately develops.
The report is closed.
Months later, somebody sends a concerning message.
A different employee receives it.
Another year passes.
A new protection company takes over.
The old incident remains in an archived folder nobody looks at.
Then something else happens.
Each event appears isolated because the protective program has forgotten its own history.
That is the issue I take from the October 2, 2026 terrorism charge involving Reform UK leader Nigel Farage.
The Crown Prosecution Service announced that Joshua Kerry, 28, of Rotherham, South Yorkshire, had been charged with one count of preparation of terrorist acts under Section 5 of the Terrorism Act 2006, including alleged activity against Farage.
Counter Terrorism Policing says the charged conduct is alleged to have taken place between May 31, 2024 and July 8, 2026.
That is more than two years.
Kerry is due to appear at Westminster Magistrates Court on October 7.
The charge is an allegation. No finding of guilt has been made, and the CPS has specifically reminded the public that the proceedings are active and that reporting should not prejudice the case.
That alone makes this different from a simple incident-response article.
But there is another fact that makes the case particularly useful from a protective-intelligence standpoint.
In August 2026, Counter Terrorism Policing announced that it had reopened an investigation into an attempted burglary reported at a Greater London property in April 2025.
The original investigation had been closed after no arrests were made.
After the matter was reopened, Counter Terrorism Policing London said it identified a line of inquiry that had not been identified and pursued during the original investigation and that might have been relevant. The organization made a mandatory conduct referral to the Independent Office for Police Conduct so that its support to the original investigation could be reviewed. News reporting identified the property as connected to Farage.
I am not going to speculate about whether that 2025 incident forms part of the terrorism prosecution, what prosecutors believe occurred there or what evidence investigators have developed.
The public charging statements do not establish that.
The protection lesson is narrower and, in my view, more useful:
An incident that looks closed today may become important when new information appears tomorrow.
That is why protective intelligence needs memory.

Key takeaways
- Closed does not mean irrelevant. An incident can be unresolved without appearing immediately significant and still become important when new information develops.
- Threat cases need continuity across years. The alleged conduct in the Farage terrorism charge spans more than two years, which illustrates why short incident-retention habits can create blind spots.
- Raw information should survive staff and vendor changes. The departure of an assistant, protector or security company should not erase the principal’s threat history.
- Timelines are more useful than piles of reports. Security should be able to reconstruct who did what, when, where and through which channel.
- Different locations need to feed the same protective picture. Residence, office, event, vehicle, travel and online contacts may be separate environments but should not become separate histories.
- Old events should be reviewable when a new identifier appears. A name, telephone number, email, vehicle, account, phrase, address or other identifier may make an older report relevant again.
- Do not force connections that are not supported. Good protective intelligence preserves possible relationships without turning coincidence into certainty.
- Threat files themselves are sensitive. They can contain home addresses, schedules, family information, police contacts and security procedures and therefore require access control.
- Public figures generate large volumes of noise. Good systems have to retain useful history without treating every abusive communication as the same level of threat.
- Reassessment should happen when context changes. A new arrest, charge, approach, surveillance concern or law-enforcement warning can justify reopening older internal reports.
What happened
On October 2, the Crown Prosecution Service authorized a charge against Joshua Kerry for engaging in conduct in preparation of terrorist acts, including alleged activity against Nigel Farage MP.
Kerry was charged under Section 5(1)(a) of the Terrorism Act 2006.
Counter Terrorism Policing says the alleged conduct occurred between May 31, 2024 and July 8, 2026 and described the investigation as intensive and complex, involving detectives, analysts and forensic specialists working across multiple lines of inquiry.
The CPS says Kerry has also previously been charged with murder in a separate criminal proceeding.
Those allegations should remain separate unless a court or investigators establish a relevant connection.
The terrorism charge is not itself proof that every concerning event involving Farage during the alleged period formed part of one plan.
What does a Section 5 terrorism charge mean?
Section 5 of the Terrorism Act 2006 makes it an offence for a person, with the required intent to commit acts of terrorism or assist another person in doing so, to engage in conduct preparing to give effect to that intention.
The statute also says the preparatory conduct does not have to relate to one specifically identified terrorist act.
That legal framework helps explain why the public charging announcement is broad.
It does not tell us every act prosecutors intend to rely upon.
It does not establish the exact alleged method against Farage.
It does not establish every alleged target.
And it does not establish which historical incidents, if any, investigators believe are connected.
Those are questions for the criminal proceedings.
For a protection program, however, the lengthy alleged time period raises a practical issue immediately.
Can your security system reconstruct two years of concerning activity?
The reopened 2025 incident is the real protective-intelligence lesson
On August 7, Counter Terrorism Policing issued an unusual public update.
As part of another ongoing investigation, officers had reopened an April 2025 attempted-burglary investigation at a Greater London property.
The Metropolitan Police had originally investigated the incident with support from Counter Terrorism Policing London.
No arrests were made.
The investigation was closed pending new lines of inquiry.
After reopening the matter, Counter Terrorism Policing London said it identified a potentially relevant line of inquiry that had not been identified and pursued initially.
That is a powerful reminder for private protection.
Not because a family office should try to second-guess police investigations.
Because context changes.
An event can be correctly assessed as unresolved and low-information at the time and still become important when another event supplies missing context.
A report can be closed operationally without being erased historically
This distinction is fundamental.
Suppose a vehicle appears outside the principal’s residence twice.
Nothing else happens.
No crime.
No approach.
No threatening communication.
Security documents it.
After appropriate review, the team determines that no additional protective action is justified.
Fine.
That does not mean the report should disappear.
Sixteen months later, the same registration appears near a corporate event.
Now the old report looks different.
Historical retention does not mean remaining in permanent alarm.
It means preserving context.
Incident closure and threat-case closure are not the same thing
An individual operational incident can end.
The unwanted caller stops.
The vehicle disappears.
The person leaves the event.
The package is examined.
The suspicious approach is resolved.
The police case is closed.
The household resumes normal operations.
But the principal’s historical record should still retain the event in a way that allows it to be found later.
That is threat-case continuity.
I want the principal’s security history to survive the people providing protection
This is one of the largest vulnerabilities in private protection.
People change.
The executive assistant leaves.
A security manager retires.
A residential officer resigns.
The principal changes protection companies.
The family office restructures.
A chief of staff moves on.
The new team starts with an almost blank slate.
The threat history remains scattered across:
old email accounts;
text messages;
paper reports;
shared drives;
personal notebooks;
police case numbers;
and the memories of people who no longer work there.
That is not acceptable for a sophisticated protection program.
A principal should own the threat history, not a security vendor
If a family replaces its security provider, the historical protective record should remain available to the family subject to appropriate legal, privacy and evidentiary requirements.
The departing company should not be the only organization capable of reconstructing what happened two years earlier.
This matters for:
stalking;
threats;
unwanted correspondence;
suspicious approaches;
vehicle sightings;
residential incidents;
event removals;
law-enforcement reports;
and other significant security concerns.
The database does not need to decide whether an incident was serious
That is another common mistake.
People hesitate to log an event because they do not want to overreact.
“It was probably nothing.”
That is fine.
Documenting something does not mean declaring it a threat.
A useful record can say:
status: resolved;
threat significance: undetermined;
action: none beyond documentation.
Then move on.
If new information appears later, the old event exists.
The chronology is more important than a stack of narratives
I like detailed incident reports when the situation justifies them.
But protective intelligence also needs structured chronology.
At minimum:
date;
time;
location;
reporting person;
person or identifier involved;
what actually occurred;
source of the information;
what was verified;
what remains unverified;
action taken;
law-enforcement involvement;
and related incident numbers.
That lets the team compare events without rereading hundreds of pages.
Keep raw evidence separate from the analyst summary
Original email.
Original voicemail.
Original screenshot.
Original surveillance video.
Original access log.
Original photograph.
Then the analyst can add a summary.
Do not replace the raw record with someone’s interpretation of it.
Three years later, the original wording may matter.
Do not paraphrase an important threat and then delete the original
“Subject made a threatening statement.”
That is less useful than preserving exactly what was communicated.
The wording may later allow comparison with another message.
Language.
Spelling.
Phrase choice.
Names.
Dates.
References to locations.
Those details can become identifiers.
A timeline should include negative findings too
This is important for avoiding confirmation bias.
Security reviews a car.
It turns out to belong to a neighbor’s contractor.
Record the resolution.
A strange email appears connected to a prior subject.
Further review shows it is not.
Record that.
Protective intelligence is stronger when the file records why connections were rejected, not only why they were suspected.
False linkage is a real risk
When teams begin looking for patterns, they can start seeing patterns everywhere.
Same first name.
Similar vehicle.
Same city.
Similar political language.
That is not enough.
I want identifiers that support the connection.
Telephone number.
Email address.
User account.
License plate.
Known alias.
Facial identification where lawfully and appropriately established.
Repeated distinctive language.
Confirmed address.
Law-enforcement information.
The stronger the identifier, the stronger the link.
Use unique case identifiers
Names are messy.
Two people can share the same name.
One person can use multiple names.
A social-media username can change.
Telephone numbers change.
I want a unique internal case or person-of-concern identifier so records can be linked without relying on one changing field.
That helps prevent both missed connections and accidental merging of unrelated people.
Aliases should remain searchable
Legal name.
Nickname.
Online account.
Email.
Old number.
New number.
If a relevant identifier was previously associated with the case, the system should allow an authorized security professional to find it later.
Locations should be searchable too
Residence.
Office.
School.
Event venue.
Hotel.
Airport.
Restaurant.
Second residence.
An individual who appears at three principal-related locations presents a very different context from someone observed once.
You cannot recognize that pattern if each location keeps its own isolated record.
The residence should not have one threat history and the EP team another
This is a common organizational problem.
Residential security keeps residential incidents.
Executive protection keeps movement incidents.
The family office keeps unusual correspondence.
Event security keeps ejections.
Corporate security keeps office contacts.
The same individual can move through several environments without anyone realizing it.
Someone needs visibility across the relevant categories.
That does not mean every employee needs access to everything
Centralization and broad access are different concepts.
A household officer may need to know that a named individual should not be admitted.
They do not necessarily need to read every letter the person has sent.
A driver may need a photograph and vehicle identifier.
They may not need the principal’s legal correspondence.
The security lead may need the complete file.
Use need-to-know access.
Threat records are themselves sensitive security information
A mature file may contain:
principal addresses;
family member names;
children’s information;
future travel;
law-enforcement contacts;
security procedures;
protective responses;
photographs of the estate;
vehicle data;
and personal information about other individuals.
That database requires strong access controls.
A poorly protected protective-intelligence system can create the exact exposure it was designed to reduce.
Access should be logged
Who viewed the case?
Who edited it?
Who exported it?
Who downloaded evidence?
If the information is sensitive enough to affect the principal’s security, the organization should know who accessed it.
Deletion authority should be limited
I do not want a frontline officer permanently deleting historical records because they believe the matter is irrelevant.
I also do not want a disgruntled administrator capable of wiping the principal’s threat history.
Retention, archive and deletion rules should be deliberate.
Security-provider transitions require data migration
This is one of the best opportunities to lose critical history.
The old company leaves Friday.
The new company starts Monday.
The handover covers:
keys;
radios;
posts;
vehicles;
and schedules.
What about threat cases?
Known unwanted contacts?
Old police reports?
Repeated vehicles?
Online accounts?
Restraining orders?
Event incidents?
Those belong in the transition process too.
The new team needs history without inheriting old conclusions blindly
This is another important balance.
An old security manager may have labeled someone:
“High risk.”
The new team should understand why.
What behavior supported that conclusion?
What information was confirmed?
What happened afterward?
Was law enforcement involved?
Did the concern resolve?
Historical judgments should be reviewable.
Long periods of silence should not erase the old timeline
A person may stop contacting the principal.
Good.
The case can move into an inactive state.
That is different from deleting it.
If the person reappears 18 months later, I want the new protector to know this is not the first interaction.
The significance of the new contact may depend heavily on the historical pattern.
Inactive should be an actual case status
Open.
Monitoring.
Inactive.
Resolved.
Reopened.
Referred to law enforcement.
Those categories help a team understand where something sits without throwing away the underlying record.
Reopening criteria should be clear
What should cause an archived case to come back onto the active list?
New contact from the same person.
A new identifier linked to them.
Appearance near a principal-related location.
Contact with a family member or staff.
Law-enforcement inquiry.
Arrest or criminal charge.
New court filing.
Threat information from another protection team.
A new report that matches distinctive historical behavior.
The exact threshold depends on the case.
But the concept should exist.
A criminal charge should trigger a historical review
If authorities tell me that somebody previously connected to the principal has been charged with serious preparatory conduct, I would not only focus on what happened yesterday.
I would look backward.
Prior correspondence.
Previous approaches.
Old visitor logs.
Event incidents.
Residential reports.
Vehicles.
Staff reports.
Anything already preserved that may now deserve another look.
The point is not to reinterpret every old event as sinister.
The point is to reassess it using new context.
Review the original report before reading the later conclusions
This helps reduce hindsight bias.
What did the officer actually see?
What did the email actually say?
What was known at that moment?
Then compare it with what is known now.
Otherwise the new information can distort the memory of the old event.
The public-figure environment creates a massive triage problem
This is where threat-case management becomes especially important.
British parliamentary research provides useful scale.
A Speaker’s Conference survey found that 96% of responding MPs had experienced at least one form of abuse, harassment or intimidation. A House of Commons research briefing reported that 37% had experienced threats of harm and 27% reported death threats.
That does not mean 27% of MPs face imminent assassination attempts.
It means a public-figure protection program can receive a very large volume of adverse information.
The problem is not simply collecting it.
The problem is finding the small number of events that deserve increasing attention.
Most reported security incidents may never become physical
Evidence submitted to the UK Speaker’s Conference by the Parliamentary Security Department said that, during October through December 2024, 83% of categorized MP security incidents occurred through virtual means such as email, social media, telephone or letters, while 12% involved face-to-face contact with MPs or staff.
That creates a difficult operating environment.
Thousands of communications.
A much smaller number of physical approaches.
An even smaller number representing severe violence risk.
A professional system has to retain history without treating everything equally.
Protective intelligence needs triage
Not every insult becomes a threat case.
Not every criticism becomes an incident.
Not every repeated email justifies executive protection.
I want enough structure to distinguish:
ordinary criticism;
abuse;
persistent unwanted contact;
information-seeking behavior;
physical approach;
repeated proximity;
boundary testing;
credible threats;
and behavior moving toward actual access.
The category can change over time.
The initial category should never become permanent by default
A report begins as:
“Unusual correspondence.”
Then the sender begins appearing at events.
Now it may become:
“Persistent unwanted contact.”
Later the person attempts to enter a restricted location.
The category changes again.
Good systems allow the assessment to evolve.
Security should track the change, not just the event count
Fifty emails are not automatically more serious than five.
Five communications that move from generic comments to private family information may represent a more significant change.
I care about direction.
Persistence.
Access.
Proximity.
Specific knowledge.
Boundary testing.
And actual behavior.
Volume can hide escalation
A public figure receives hundreds of abusive messages.
Staff become numb to them.
Then one sender moves from:
public comments;
to direct emails;
to contacting the office;
to asking about an event;
to appearing there.
If every communication is simply stored in a giant folder called threats, the behavioral change may disappear inside the volume.
Case ownership matters
Someone has to be responsible for significant cases.
Not necessarily investigating the subject.
Maintaining continuity.
Who reviews new information?
Who updates the timeline?
Who communicates with the protection lead?
Who records law-enforcement contacts?
Who decides when the case requires reassessment?
Without ownership, information tends to sit.
Shift logs are not enough for long-term threat cases
A residential shift log is designed to tell the next shift what happened.
It is not necessarily designed to preserve a two-year threat history.
The unusual vehicle may be documented correctly on Tuesday.
By next year, finding that entry among thousands of routine shift notes may be almost impossible.
Significant protective-intelligence events should be elevated from routine logs into a searchable case structure.
The same applies to email inboxes
An executive assistant’s mailbox is not a threat-management system.
If the assistant flags a concerning email, the relevant record should move into the established security process.
Otherwise the assistant leaves the company and the threat history leaves with the account.
Law-enforcement report numbers should live with the internal incident
If police were contacted, preserve:
agency;
date;
report number;
investigator or point of contact where appropriate;
and what information was provided.
That makes later coordination much easier.
The UK system itself shows the value of standardized incident reporting
Since late 2024, the UK Parliamentary Security Department and Metropolitan Police have used an Operation Bridger incident taxonomy designed to categorize both criminal and non-criminal security incidents involving MPs.
The published evidence says the system was created specifically so security professionals could quantify and categorize events that may not reach the criminal threshold but can still matter to the overall threat picture.
That is factual context from the UK public-figure environment.
For a private family, the system does not need to copy Operation Bridger.
But the underlying operational problem is the same:
If everybody describes incidents differently, correlation becomes harder.
Use consistent categories
For example:
unwanted communication;
threat;
information request;
physical approach;
access-control incident;
surveillance concern;
property incident;
event incident;
family contact;
law-enforcement notification.
The exact taxonomy should fit the organization.
Consistency matters more than the labels themselves.
Structured fields make searching possible
A narrative report might say:
“Gray SUV observed near the residence.”
Useful.
But also capture:
color: gray;
vehicle type: SUV;
license plate if lawfully observed;
date;
time;
location;
direction;
related incident.
Now the team can query the history later.
Do not make the system so complicated that nobody uses it
This is the other side of the problem.
If a protector has to complete 48 fields every time someone asks an unusual question at the gate, reporting will fail.
I want enough structure to make information searchable.
Not bureaucracy for its own sake.
Reports should be entered close to the event
Memory degrades.
Times become approximate.
Exact wording disappears.
Vehicle descriptions change.
When something is significant enough to preserve, record it promptly.
Corrections should not destroy the original history
Suppose an officer initially enters the wrong license plate digit.
Later video provides the correct plate.
Correct the field.
Maintain the audit history.
The ability to see what changed and why supports both integrity and accountability.
Protective intelligence should have version history
A mature threat assessment evolves.
Original assessment.
New information.
Reassessment.
Escalation.
Reduction.
Law-enforcement action.
A year later, the team should be able to understand why a decision was made at the time.
That protects the family and the security team
If somebody later asks:
“Why didn’t you add protection after this email?”
The file should show what information existed then.
Not what became known six months later.
Hindsight is easy.
Contemporaneous documentation is more useful.
Historical records should be revisited after major new intelligence
The reopened 2025 Greater London incident illustrates this concept in the public-law-enforcement environment.
Police had investigated the attempted burglary.
No arrests were made.
The matter was closed pending new lines of inquiry.
Later developments caused authorities to reopen it and identify a potentially relevant line of inquiry that had not been pursued initially.
Private protection should be capable of the same kind of historical reconsideration without pretending to perform a criminal investigation.
What should trigger a backward review?
A named individual becomes subject to a serious police investigation.
A known unwanted correspondent is arrested.
A previously unknown person is identified.
A vehicle is linked to another event.
An account is tied to an earlier alias.
A family member receives new contact.
Law enforcement asks about historical activity.
Another protected person reports the same individual.
That is when I would search older records.
Search across locations, not just dates
Residence.
Office.
Event.
Airport.
Hotel.
School.
Restaurant.
Public appearance.
One individual appearing in several principal-related environments deserves different attention from a person appearing once.
Search across people around the principal too
Principal.
Spouse.
Assistant.
Driver.
Family member.
Household employee.
Again, that does not mean every contact is threatening.
It means cross-contact can change context.
The family office should not become an amateur intelligence agency
This boundary matters.
The objective is not:
secret dossiers on critics;
political profiling;
diagnosing people;
or investigating lawful speech.
The objective is preserving security-relevant incidents and behavior around the principal.
There is a major difference.
Political disagreement is not a security indicator
This article involves a political figure.
That makes this worth saying explicitly.
Someone strongly opposing Nigel Farage politically is not, by itself, a protective-intelligence concern.
The same applies to any politician, CEO, celebrity or UHNW principal.
Protection should focus on conduct relevant to safety.
Not viewpoint.
Do not use ideology as a shortcut for threat assessment
I want to know:
What did the person do?
What contact occurred?
What access did they seek?
What locations did they appear at?
What information did they possess?
How did behavior change?
Labels do not answer those questions.
Lawful protest should remain separate from targeted security concerns
A public figure may attract:
demonstrators;
critics;
journalists;
activists;
and members of the public.
Those activities may be lawful.
Protective intelligence should distinguish legitimate public activity from behavior that actually affects principal safety.
Case continuity becomes even more important because most people never escalate
If every critic became violent, security would be easy.
They do not.
The challenge is identifying meaningful change among a very large amount of harmless or unpleasant activity.
History helps.
Old records should not automatically increase present threat level
A person sent angry messages four years ago.
Nothing happened afterward.
That history exists.
It does not automatically mean the person presents a current high threat.
The file should support current judgment, not replace it.
Recency is one factor, not the only factor
Recent contact often matters more.
But a serious historical incident may remain relevant longer than low-level recent noise.
Threat-case management has to consider both severity and time.
One serious physical approach can outweigh hundreds of messages
That is why raw event count can be misleading.
Security needs context.
Online commentary and a physical attempt to access the principal are not equivalent simply because both are entered as incidents.
Location movement is particularly important
Online only.
Then office contact.
Then event appearance.
Then residence proximity.
That is a meaningful change in behavior even if the communication volume decreases.
Security posture should respond to linkage
Suppose a person appears at a public event.
Ordinarily, that may be nothing.
Now the database shows that the same person previously attempted contact at the residence.
The event team has different context.
The protective response may change.
This is where executive protection benefits from historical intelligence
The protector standing next to the principal may have joined the detail yesterday.
The threat history may be five years old.
Good systems bridge that gap.
Before an important movement, the team can receive relevant case information without reading thousands of old reports.
Pre-event briefings should be selective
Known person expected?
Recent contact?
Specific vehicle?
Relevant photograph?
Recent law-enforcement update?
Give the team actionable information.
Do not overwhelm them with an encyclopedia of every unpleasant person the principal has ever encountered.
The threat file should support the mission, not become the mission
Protection can become consumed with intelligence collection.
The principal still needs to live.
Travel.
Work.
Attend events.
See family.
The purpose of the threat history is to make those activities safer.
Not to create permanent fear.
Current UK protective structures provide useful factual context
Operation Bridger is the UK policing framework supporting MP security away from the Parliamentary Estate.
In 2026, the Home Office said MPs should reference Operation Bridger when reporting both emergency and non-emergency security incidents so the appropriate coordinators can follow up. The government has also said that Parliamentary Security, police and the Home Office keep security measures for MPs under review while withholding detailed individual arrangements for obvious security reasons.
Private UHNW clients obviously do not operate inside that government framework.
But it shows something important:
Even national public-figure protection depends on incidents being reported in a way that allows the right people to retrieve and act on them.
The private-sector equivalent needs clear law-enforcement handoff
If conduct becomes criminal or potentially criminal, the private protection team should know how to transition information to authorities.
Preserve the original evidence.
Provide factual timelines.
Maintain case numbers.
Do not embellish.
Do not perform amateur surveillance operations that interfere with law enforcement.
Police may later ask for information the private team did not think was significant
That is one reason records matter.
“Did this individual ever appear at the residence?”
“Did this telephone number ever call?”
“Did this vehicle appear near an event?”
If the team documented correctly, it can answer.
If everything relied on memory, maybe not.
Protecting the integrity of the historical record matters
If law enforcement later becomes involved, the team should be able to distinguish:
original evidence;
contemporaneous notes;
later analysis;
and subsequent additions.
Mixing those together reduces clarity.
What families and protection teams can do now
Find every place threat information currently lives
Email.
Shift logs.
Security software.
Assistant notes.
Police reports.
Phones.
Shared drives.
Paper files.
Create one authoritative case index
You do not necessarily need every piece of evidence stored in one technical platform.
You do need one place that tells authorized personnel what cases exist and where the source material is preserved.
Create unique case numbers
Do not rely only on names.
Preserve original communications
Keep the raw evidence when legally appropriate.
Use consistent categories
Make historical searches easier.
Record exact locations
Residence.
Office.
Event.
Hotel.
Travel.
Record identifiers
Telephone numbers.
Email addresses.
Accounts.
Vehicle information.
Known aliases.
Record what disproved a suspected link
Negative findings prevent the same false connection from returning repeatedly.
Link police report numbers
Make later coordination easier.
Create inactive and reopened case statuses
Do not make deletion the only alternative to active monitoring.
Define reopening triggers
New contact.
Physical approach.
Arrest.
New identifier.
Law-enforcement inquiry.
Review provider handover procedures
Make threat history part of the security transition.
Control who can view the database
Threat information is sensitive principal information.
Log administrative changes
Know who edited or exported critical records.
Test retrieval
Ask the system:
“Show me every security incident involving this telephone number during the past three years.”
Can it?
Test cross-location retrieval
“Show me every appearance of this vehicle at any principal-related property or event.”
Can it?
Test personnel continuity
If the current security director leaves tomorrow, can the next person understand the history?
How MSB Protection approaches threat-case continuity
At MSB Protection, I do not want protective intelligence living in individual people’s memories.
I want a system.
Not because every strange interaction is dangerous.
Because we cannot know today which piece of information may become useful later.
My approach is simple:
report facts;
preserve significant source material;
organize it;
link what can be linked;
leave uncertain things uncertain;
retain history;
and reassess when new context appears.
That supports executive protection.
It supports residential security.
It supports travel.
Events.
Family-office decision making.
And law-enforcement coordination when necessary.
I do not want AI or software deciding who is dangerous
Technology can help find matching identifiers.
Dates.
Locations.
Repeated phrases.
Vehicle records.
Case relationships.
That is useful.
The final protective judgment still requires human context.
A computer can tell me the same name appears in two reports.
It cannot automatically tell me whether those two reports involve the same person or whether the behavior is dangerous.
Software should help analysts remember
That is where I see the strongest value.
The machine does not replace the protector.
It helps the protector find something a human being might otherwise forget.
“This number appeared 19 months ago.”
“This vehicle was previously logged at another residence.”
“This email account is associated with an inactive case.”
That is useful operational support.
Case history should inform protective posture without controlling it
The existence of an old case does not automatically mean more guards.
A new match means:
look again.
Assess current behavior.
Consider the old information.
Decide what changes, if anything.
Frequently asked questions
What was Joshua Kerry charged with?
The Crown Prosecution Service charged Joshua Kerry with one count of preparation of terrorist acts under Section 5(1)(a) of the Terrorism Act 2006, including alleged activity against Nigel Farage MP. The charge remains an allegation and Kerry has not been convicted.
What period does the terrorism charge cover?
Counter Terrorism Policing says the alleged activity occurred between May 31, 2024 and July 8, 2026.
When is Kerry due in court?
The CPS says he is due to appear at Westminster Magistrates Court on October 7, 2026.
Has the CPS described the exact alleged plot against Farage?
No. The public charging announcement says the alleged preparatory conduct included activity against Farage but does not publish the complete alleged method, individual acts or evidentiary case.
What does Section 5 of the Terrorism Act 2006 cover?
Section 5 concerns conduct undertaken in preparation for committing or assisting acts of terrorism with the required intent. The statute does not require the preparations to relate to one specifically identified terrorist act.
Was there an earlier incident involving a property reportedly connected with Farage?
Counter Terrorism Policing said it reopened an April 2025 attempted-burglary investigation at a Greater London property after later developments. The official statement did not publicly name Farage, while subsequent national news reporting identified the property as linked to him.
Why was the earlier investigation reopened?
Counter Terrorism Policing said that after reopening the case, a potentially relevant line of inquiry was identified that had not been identified and pursued during the original investigation. It made a mandatory referral to the Independent Office for Police Conduct regarding its earlier support to the investigation.
Does that prove the attempted burglary was part of the terror case?
No. The public statements reviewed for this article do not establish that conclusion, and it would be inappropriate to present it as fact while proceedings remain active.
What is threat-case continuity?
Threat-case continuity is the ability to preserve, retrieve and reassess historical security information over time so new events can be compared with older incidents even after personnel, providers, locations or circumstances change.
Why is threat-case continuity different from general protective intelligence?
Protective intelligence is broader. Threat-case continuity focuses specifically on memory across time: retaining incidents, linking identifiers, reopening old cases and preventing information from disappearing when the operational environment changes.
Should every unusual contact become a threat case?
No. Minor observations can be documented without labeling the person dangerous. The system should allow information to exist with an undetermined or low-significance assessment.
Why retain an incident that was determined to be harmless?
A resolved report can prevent future confusion and demonstrate that an apparent match was previously explained. Historical records should include resolutions, not just concerns.
How long should protective-intelligence records be retained?
There is no universal period appropriate for every organization. Retention should reflect legal requirements, privacy obligations, threat profile, principal exposure and the type of incident. High-significance cases may justify much longer preservation than routine low-value observations.
Should inactive threat cases be deleted?
Not automatically. An inactive status allows the team to stop active attention while retaining history that may become relevant if the individual or behavior reappears.
What information should an incident record contain?
Date, time, location, source, exact behavior, relevant identifiers, what was verified, what remained unverified, actions taken, related case numbers and any later resolution.
Why preserve the original email or voicemail?
Because later analysis may depend on exact wording, dates, account identifiers or other details that can disappear when someone merely summarizes the communication.
Should threat reports include conclusions?
They can include professional analysis, but factual observation and analytical conclusion should be clearly distinguishable from one another.
What is the problem with putting everything in shift logs?
Shift logs are excellent for immediate continuity but can become difficult to search across years. Significant protective-intelligence incidents should be elevated into a structured system that allows later retrieval and correlation.
Why should vehicle information be structured?
A searchable plate, description or other identifier can help the team recognize that the same vehicle was documented at another relevant location months earlier.
Should security store every license plate seen near a residence?
No. Collection should be purposeful, lawful and proportionate to the security requirement. The objective is not indiscriminate surveillance of the neighborhood.
What if two people have the same name?
Do not merge them automatically. Use stronger identifiers and maintain uncertainty until the connection is supported.
Why use unique case numbers?
Because names, phone numbers and online handles can change or overlap. A stable internal identifier allows the organization to maintain one coherent record.
Should old aliases remain in the system?
When legitimately relevant to a protective case, yes. A later contact may use an old account, telephone number or name that helps reconnect it to the historical record.
Can a protection company own the clients threat database?
Contractual and legal arrangements vary, but from an operational standpoint the family should not become incapable of reconstructing its own security history merely because a vendor relationship ends.
What should happen when a family changes security companies?
The transition should include significant protective-intelligence history, known persons of concern, unresolved incidents, relevant police contacts and active security concerns in addition to normal post and access-control handover.
Should the new company accept every old threat assessment as correct?
No. It should preserve the history while reviewing the underlying facts and current context independently.
Why are negative findings important?
They show why a suspected connection was rejected and help prevent future analysts from repeatedly reaching the same unsupported conclusion.
Can software automatically identify threat actors?
Software can help surface matching information, but human review is needed to determine whether records actually involve the same person and what the behavior means.
Should AI decide threat levels?
I would not delegate final protective judgments to AI. It can assist with retrieval, organization and correlation, but threat assessment requires context, uncertainty management and professional accountability.
How should law-enforcement reports be stored?
Keep the agency, report number, date, relevant point of contact where appropriate and what information was provided. Preserve legal and privacy requirements around those records.
Should every employee have access to threat files?
No. Threat cases often contain sensitive information about the principal, family and security program. Access should be limited to people with an operational need.
Why log who views a threat file?
Because the information itself can create security exposure. Audit logging provides accountability for access, editing and export.
What should reopen an inactive case?
Examples include new contact, physical appearance, a matched identifier, family contact, a law-enforcement inquiry, arrest, criminal charge or new information that materially changes the earlier assessment.
Should a new arrest cause security to review older incidents?
Yes when the arrested person or related identifiers have a prior connection to the principal. The purpose is to reassess old information in light of the new context, not automatically reinterpret every historical incident as hostile.
Does a long period with no contact mean a case no longer matters?
It may reduce current concern, but history can remain relevant if the person or behavior returns.
Why is this especially important for public figures?
Public figures can receive very high volumes of abuse and unwanted communication. UK parliamentary research found that 96% of responding MPs had experienced abuse, intimidation or harassment, with substantial numbers reporting threats of harm or death threats. High volume makes organized triage and historical continuity particularly important.
Are most security incidents involving MPs physical?
No. Parliamentary Security Department evidence covering October through December 2024 said 83% of categorized incidents occurred through virtual means and only 12% involved face-to-face contact with MPs or staff.
Does that mean online messages are more dangerous than physical approaches?
No. Those statistics describe volume, not severity. Physical behavior can carry very different operational significance even when it occurs less frequently.
What is Operation Bridger?
Operation Bridger is the UK policing framework supporting security for MPs away from the Parliamentary Estate. MPs are advised to reference it when reporting relevant incidents so the appropriate police coordinators can be notified.
Does Operation Bridger apply to private UHNW families?
No. It is a UK public-official framework. Private clients require their own reporting and law-enforcement liaison structures.
Should political beliefs be stored as threat indicators?
Political disagreement alone is not a protective threat indicator. Security should focus on conduct relevant to safety rather than ideology or lawful criticism.
Should lawful protesters be entered into threat databases?
Not simply for protesting. A record should be tied to legitimate security-relevant behavior and handled in accordance with applicable law and privacy requirements.
How does threat-case continuity support executive protection?
It gives the mobile protection team relevant historical context before movements, events and travel so new activity can be evaluated against what is already known.
How does it support residential security?
It allows the residential team to understand whether a visitor, vehicle or unusual contact has appeared elsewhere in the principal’s protective environment.
How does it support a security assessment?
A professional security assessment should not look only at hardware and physical vulnerabilities. Historical incidents can reveal where the principal has actually experienced unwanted attention and where the protective system has lost continuity.
What is the biggest threat-case management mistake?
Allowing important information to remain trapped in one person’s memory, inbox or notebook until that person leaves.
Final thoughts: protective intelligence needs institutional memory
The October terrorism charge involving Nigel Farage is an active criminal matter.
Joshua Kerry has been charged.
He has not been convicted.
The public does not know the complete alleged plan.
We do not know every act prosecutors intend to rely upon.
We should not invent any of that.
The useful protection lesson comes from the timeline.
The alleged conduct covers more than two years.
Separately, an older attempted-burglary investigation was reopened after later developments caused investigators to look again at an incident that had previously been closed pending new information.
That is exactly why a professional protective-intelligence program cannot function like a daily newspaper.
Today’s incident does not disappear when tomorrow arrives.
It becomes part of history.
Most of that history may never matter again.
Some of it will.
The challenge is making sure the team can find the relevant piece when the context changes.
Document the event.
Preserve the original evidence.
Record what was confirmed.
Record what was not.
Use searchable identifiers.
Keep locations connected.
Preserve negative findings.
Maintain law-enforcement references.
Carry the history through personnel changes.
Carry it through vendor changes.
Allow cases to become inactive without erasing them.
Reopen them when new facts justify another look.
And do not force a connection simply because two events look similar.
That is what threat-case continuity means to me.
The visible protector beside the principal may change.
The residential officer may change.
The assistant may change.
The security company may change.
The principal’s security history should not disappear every time the people around them do.
A serious protection program needs memory.
Because sometimes the event everyone dismissed eighteen months ago becomes important only after the next piece arrives.
Sources
About Michael Braun
Michael Braun is a former Special Unit Operator, former Manager at Gavin de Becker & Associates, and Founder & CEO of MSB Protection, an executive protection and residential security firm serving high-net-worth and ultra-high-net-worth clients.
Braun has built his career at the intersection of specialized protective operations, executive protection, residential security, protective intelligence, and security risk management. His experience spans special-unit operations, leadership within Gavin de Becker & Associates, and the development and oversight of private protection programs within demanding UHNW environments.
He has been recognized by The Top 100 Magazine as a leading CEO in the private security field and is the subject of an upcoming Marquis Who’s Who feature highlighting his leadership and contributions to the profession.
Today, Braun is recognized for his work in executive protection, UHNW estate security, residential protection, protective intelligence, adversarial security assessments, and security auditing throughout Beverly Hills and Southern California.
His work focuses on moving private security beyond simply “providing a body” and toward intelligence-led, risk-based protection programs designed to identify vulnerabilities before an adversary can exploit them.
Looking for Executive Protection or Residential Security Services?
If you are a high-net-worth or ultra-high-net-worth individual, family office, estate manager, chief of staff, or executive in Beverly Hills, Los Angeles, Malibu or Southern California, MSB Protection provides executive protection, residential security, 24/7 protection, protective intelligence, medical-readiness planning, and security risk management.
We evaluate the complete security environment, from threat exposure and residential vulnerabilities to personnel, technology, procedures, protective intelligence, and emergency response, and build a program around the risks that actually exist.
Contact us for a confidential consultation or message us at +1 (805) 285-2807.