Why Security Lacks a Codified Knowledge Core

Why Security Lacks a Codified Knowledge Core

“Security continues to expand in scope, but its intellectual foundations remain fragmented.”

Security knowledge is not absent. It is everywhere. It exists in training programmes, operational manuals, regulatory frameworks, and, most significantly, in lived experience. Across sectors and regions, professionals are constantly making decisions under uncertainty, interpreting risk, and responding to evolving threats.

But when you step back and look at it properly, something becomes clear.

That knowledge is not organised.

It is dispersed across industries, jurisdictions, and specialisms. It is taught differently in different countries. It is applied differently across sectors. And only a small proportion of it is structured into anything resembling a coherent disciplinary framework.

That raises a more serious question.

If security is to be recognised as a profession, where is its knowledge system?

Professions Are Built on Structured Knowledge

Established professions did not gain their status through experience alone.

Medicine is underpinned by medical science. Engineering is grounded in centuries of formalised principles. Law is supported by structured jurisprudence and doctrine.

In each case, knowledge was not just accumulated. It was organised, codified, and institutionalised.

That is what gave these professions authority.

Not time served. Not operational exposure. Structured knowledge.

Security, by contrast, operates in a different position.

Professionals carry out complex analytical work every day. They assess risk, interpret behaviour, analyse intelligence, and make decisions with real-world consequences.

But much of the knowledge behind those decisions is informal.

It is learned on the job. Passed through organisations. Shaped by culture rather than codified frameworks.

So you end up with a contradiction.

High-level practice, without a fully developed intellectual base.

How Fragmentation Became the Norm

The modern security sector expanded rapidly from the late twentieth century onwards. Demand increased across government, corporate, and private domains.

In response, the industry built what it needed.

Training programmes. Licensing systems. Operational standards.

These developments were necessary. They established baseline competence and improved consistency in delivery.

But they did not create a unified body of knowledge.

Instead, security knowledge evolved in parallel streams.

Operational training focused on procedures and incident response. Technology providers specialised in surveillance and access control. Intelligence practitioners refined threat assessment methods. Academia contributed through criminology, policing studies, and governance research.

Each of these areas developed depth.

But not integration.

What emerged was not a discipline, but a collection of adjacent domains.

Article content


The structure outlined above is conceptualised as the Mardner Security Knowledge Structure Model (MSKSM), which frames security knowledge across three interconnected levels: operational (doing), analytical (understanding), and strategic (deciding). The model highlights the current fragmentation between these layers and emphasises the need for integration as a prerequisite for professionalisation.

“This fragmentation can be understood more clearly when security knowledge is viewed across three distinct but disconnected layers:”

In most sectors, these layers develop independently. Operational training rarely connects to analytical reasoning, and both remain weakly linked to strategic frameworks. A codified discipline would require integration across all three.

The Consequence: Experience Without Integration

This fragmentation has real implications.

In the absence of a codified knowledge core, practice becomes heavily dependent on context. Professionals develop through exposure rather than through structured frameworks. Knowledge remains embedded within organisations rather than shared across the field.

The result is an industry rich in experience, but weak in conceptual cohesion. This condition can be understood as Operational Knowledge Fragmentation, a state in which critical knowledge exists across practice, technology, and research, but remains unstructured, non-transferable, and inconsistently applied across the profession. In such environments, capability depends heavily on context rather than on shared disciplinary understanding.

Sociologist Andrew Abbott described professions as systems of organised knowledge linked to specific jurisdictions. Where knowledge is fragmented, professional authority becomes unstable.

Security sits precisely in that space.

It performs increasingly complex functions, yet its intellectual foundations remain dispersed.


Towards a Security Science Framework

Security Science can be defined as an interdisciplinary field concerned with the systematic analysis of threats, risks, vulnerabilities, and protective measures across physical, human, and digital domains. It integrates principles from risk management, intelligence studies, behavioural science, criminology, and organisational governance into a unified framework that enables consistent decision-making, measurable competence, and transferable professional knowledge.

Not as a rebrand. Not as a slogan.

But as a structural response.

Security Science offers a way to bring together the multiple knowledge streams that already exist. Risk management, intelligence analysis, behavioural science, criminology, cybersecurity, and governance do not need to remain isolated.

They can be integrated into a coherent disciplinary framework.

One that defines how security problems are analysed. How decisions are made. How competence is measured.

In that model, knowledge becomes transferable. Methods become standardised. Practice becomes explainable, not just experiential. This does not replace experience. It gives experience structure.

Professionals begin to understand not only what they are doing, but why. They can situate their decisions within a broader system of knowledge rather than relying solely on precedent or intuition.


A Sector Already Operating Beyond Its Framework

For example, a security officer working within a critical infrastructure environment may be required to identify behavioural indicators of hostile intent, assess risk in real time, and coordinate response protocols across multiple stakeholders. While these actions appear procedural on the surface, they rely on layered judgement drawn from behavioural analysis, intelligence awareness, and risk evaluation, none of which are consistently taught within a unified framework.

Across the UK, Canada, Africa, and the Caribbean, the scope of security work is expanding.

Critical infrastructure protection. Behavioural threat analysis. Integrated risk management. Intelligence-led operations.

These are not routine tasks in the traditional sense. They require judgement, synthesis, and structured reasoning.

Procedures alone are not enough.

They require a knowledge base that supports them.

From Occupation to Profession

The question is no longer whether security has knowledge.

It clearly does.

The real question is whether that knowledge can be organised into a coherent discipline capable of supporting professional status.

Experience builds expertise.

But professions are sustained through structured knowledge.

Security has reached the point where accumulation is no longer the issue.

Organisation is the defining challenge that will determine whether security evolves into a true profession.

References

Abbott, A. (1988). The System of Professions. University of Chicago Press.

Freidson, E. (2001). Professionalism: The Third Logic. University of Chicago Press.

Loader, I. & Walker, N. (2007). Civilizing Security. Cambridge University Press.

Button, M. (2007). Security Officers and Policing. Ashgate.

Mardner, O. (2026). Mardner Security Knowledge Structure Model (MSKSM).

Back to blog

Leave a comment