What Medicine, Law And Engineering Have Got Right and Why Security Was Left Behind

What Medicine, Law And Engineering Have Got Right and Why Security Was Left Behind

Certain professions in contemporary societies are placed under extraordinary trust. People consent to surgery without auditing the surgeon’s full training history. They rely on legal representation without reviewing every prior case. They inhabit buildings or board aircraft without questioning the competence of the engineers responsible for their design.

This trust is not naïve.

It is engineered.

Medicine, law and engineering did not achieve professional authority because they are morally superior or inherently more complex than other fields. They achieved it because they resolved a series of structural problems through deliberate professional design. Security, despite being central to public safety, economic sustainability and state functioning, was never afforded comparable structural evolution.

Understanding this divergence is essential if security is to move from being defined by activity to being defined by capability.

Professions Are Built Systems, Not Job Identities

A persistent misconception is that professions are simply collections of skilled individuals. Sociological research shows the opposite. Professions are institutional systems that regulate knowledge, authority, accountability and public trust (Abbott, 1988; Freidson, 2001).

Medicine and law did not professionalise because practitioners were trusted. Practitioners became trusted because systems were constructed to make practice governable. These systems determined who could enter, what knowledge was legitimate, how competence was assessed and how failure was managed.

Security evolved differently. It expanded rapidly in response to operational demand, commercial opportunity and state delegation, but without parallel development of professional architecture. Responsibility expanded faster than authority. Risk deepened without corresponding governance. Legitimacy remained fragile.

The Key Insight: Functional Separation

At the core of every mature profession lies an architectural principle: no single institution should control every professional function.

Professions deliberately separate:

education from employment, training from licensing, performance management from ethical discipline, commercial interest from public accountability.

In medicine, universities educate, professional bodies license, hospitals employ and regulators discipline. In law, bar associations operate independently of firms. In engineering, chartership is awarded by professional institutes rather than employers.

This separation is not bureaucratic excess. It stabilises trust.

Security systems have historically collapsed these functions into overlapping commercial arrangements or dispersed them among loosely coordinated bodies. Trainers certify, employers validate competence informally, regulators enforce minimum compliance and ethics often remain aspirational rather than enforceable (Gill, 2014).

This structural compression explains why security remains vulnerable despite decades of operational experience.

Knowledge Control and the Loss of Disciplinary Coherence

Medicine, law and engineering secured early control of their knowledge base. They defined legitimate knowledge, prescribed how it must be taught and determined who could certify mastery. This allowed expertise to become cumulative, transferable and governable.

Security did not follow that trajectory.

Security knowledge evolved through practice, apprenticeship and a fragmented training market. Experiential knowledge is valuable, but without codification and integration, a coherent disciplinary core struggled to emerge. This reinforced the misconception that security is primarily about vigilance or presence rather than applied risk science, behavioural analysis, intelligence integration and systems thinking.

As risk environments converged across physical, cyber, reputational and geopolitical domains, the absence of structured knowledge architecture became increasingly problematic (Loader and Walker, 2007).

Licensing Without Progress Is Regulatory Minimalism

Licensing mechanisms also diverge significantly.

In medicine and law, licensing is an entry threshold, not a career endpoint. It marks the beginning of structured progression.

Security licensing regimes were primarily designed to ensure legal conformity rather than to cultivate professional growth. They establish minimum standards but do not embed incremental development, differentiated authority or formal hierarchies.

Competence cannot mature without defined levels. Expertise cannot differentiate without sectoral structure. Convergence cannot stabilise without specialisation.

Recognised professions embed vertical progression into their architecture. Security has historically remained largely horizontal.

Ethics as Governance Infrastructure

Ethics represent another structural divergence. In medicine and law, ethics operate as enforceable governance mechanisms. Violations trigger investigation, due process and sanctions affecting licence and right to practise. Ethical failure is treated as systemic risk.

In security, ethical frameworks frequently remain aspirational, expressed in value statements rather than embedded in independent disciplinary systems. This reflects not a deficit of practitioner morality, but a deficit of institutional infrastructure.

Gill (2014) demonstrates that weak ethical enforcement can erode legitimacy more rapidly than operational failure. As authority expands, accountability must scale correspondingly. Without that alignment, legitimacy becomes unstable.

Engineering Legitimacy, Not Defending Practice

Medicine, law and engineering did not secure legitimacy through rhetoric. They engineered it. They accepted higher barriers to entry, external scrutiny, limitations on practice and constraints on employer discretion.

Security has often responded differently, highlighting individual excellence while leaving structural gaps unaddressed. That strategy cannot sustain long-term credibility.

In an era of security convergence, where failures cascade across physical, digital and human systems, the absence of professional architecture becomes a risk factor in itself.

At a Structural Crossroads

Security today exercises powers as complex and consequential as those of recognised professions. It manages surveillance, coercive authority, intelligence processes, crisis response and critical infrastructure protection. Its societal footprint is substantial.

What it lacks is engineered recognition.

Recognition cannot be demanded. It must be constructed.

Professionalisation is not imitation of other fields. It is the application of consistent structural logic: coherent knowledge domains, tiered development, sectoral pathways, enforceable ethics and aligned authority.

Closing Reflection

Medicine, law and engineering are trusted not because they are flawless, but because they built systems capable of managing imperfection.

Security now faces the same decision those professions once confronted: remain a market function defined by minimum standards, or undertake the structural redesign required for professional status.

The question is not whether security is important enough to professionalise.

It is whether it is prepared to accept the architecture that professionalisation requires.


References

Abbott, A. (1988). The System of Professions: An Essay on the Division of Expert Labor. Chicago: University of Chicago Press. Freidson, E. (2001). Professionalism: The Third Logic. Chicago: University of Chicago Press. Gill, M. (2014). The Handbook of Security. Basingstoke: Palgrave Macmillan. Loader, I. and Walker, N. (2007). Civilizing Security. Cambridge: Cambridge University Press.

Back to blog

Leave a comment