Why Security Reform Repeats the Same Mistakes
The Illusion of Progress
Figure 1: The Security Reform Cycle
Across multiple jurisdictions, the private security sector has undergone repeated cycles of reform. Governments introduce new regulatory frameworks, licensing regimes are revised, training requirements are expanded, and industry standards are updated. Each cycle is presented as progress, an effort to modernise the sector, enhance public trust, and elevate professional standards.
In many respects, these reforms are necessary and, in the short term, effective.
Minimum standards are raised.
Training becomes more structured.
Accountability mechanisms are strengthened.
On the surface, the sector appears to advance.
Yet, over time, a familiar pattern re-emerges.
Concerns about inconsistent training resurface. Practitioners question whether licensing frameworks reflect operational realities. Policymakers debate whether regulatory structures are keeping pace with increasingly complex threat environments.
The conversation returns to reform.
Not as progression, but as repetition.
This raises a more fundamental question:
Why does security reform consistently fail to achieve lasting transformation?
Regulation Improves Practice, But It Does Not Create a Profession
At the centre of this issue lies a critical imbalance.
Most reform initiatives focus on regulation rather than knowledge.
Regulation is essential. It defines who may operate within the sector, establishes minimum competence thresholds, and provides mechanisms for accountability. Given the responsibilities entrusted to security professionals, regulation is not optional, it is a necessity.
This distinction can be understood more clearly when viewed as two foundational components of professional formation:
Figure 2: Regulation vs Knowledge in Professional Formation
However, regulation alone does not create a profession.
Professions are not sustained by rules. They are sustained by structured bodies of knowledge.
It is these knowledge systems that determine how individuals are educated, how competence develops over time, and how complex decisions are made under conditions of uncertainty.
Licensing frameworks can enforce minimum standards. They can control entry into the sector. But they do not, in isolation, provide the intellectual foundation required for professional stability, authority, and long-term development.
This distinction is where most reform efforts fall short.
Procedural Change Without Structural Transformation
In the absence of a coherent knowledge base, reform becomes procedural rather than structural.
Training hours are increased.
Certification requirements are adjusted.
Operational guidelines are expanded.
These measures can deliver short-term improvements. They may reduce immediate vulnerabilities and create the appearance of progress.
But they do not address the underlying issue:
The absence of a unified disciplinary framework for security knowledge.
As a result, reform becomes reactive rather than cumulative.
Each cycle attempts to resolve the problems that have become visible, but fails to address the structural conditions that produce those problems in the first place. Consequently, the same issues re-emerge, not because reform efforts are ineffective, but because they are incomplete.
They improve practice.
But they do not build a profession.
Knowledge as the Foundation of Professional Authority
This distinction has long been recognised within the sociology of professions.
Andrew Abbott’s work on professional systems highlights that professions derive legitimacy from their control over organised bodies of knowledge. These systems define the boundaries of expertise, establish norms of practice, and provide the intellectual basis for professional autonomy.
Where knowledge systems are fragmented or undefined, professional authority becomes unstable.
This is the position in which much of the security sector currently operates.
Reform efforts often attempt to secure professional legitimacy through regulatory mechanisms, without simultaneously developing and consolidating the knowledge structures required to sustain that legitimacy.
The result is a persistent gap between operational capability and intellectual foundation.
Fragmentation Across Sectors and Contexts
The challenge is further compounded by the diversity of environments in which security operates.
Private security functions span multiple domains, including critical infrastructure protection, corporate risk management, event security, aviation, maritime operations, and public space monitoring. Each of these domains presents distinct risks, regulatory pressures, and operational requirements.
As a result, reform efforts are often sector-specific.
Training is tailored to particular contexts.
Policy frameworks are designed for specific environments.
Competence is defined differently across domains.
While this specialisation is necessary, it also produces fragmentation.
What emerges is not a coherent profession, but a collection of parallel practices, each governed by its own standards, assumptions, and knowledge structures.
This fragmentation limits the ability of reform to achieve system-wide impact.
Beyond Regulation: The Case for Structured Security Knowledge
If security is to transition from occupation to profession, reform must move beyond regulation alone.
Regulatory frameworks remain essential. They ensure accountability, protect public interest, and establish baseline competence.
But they must be complemented by structured knowledge frameworks.
Such frameworks do not replace regulation. They underpin it.
They provide the intellectual architecture through which training, certification, and professional development can be aligned and sustained over time. They enable different sectors to operate within a shared conceptual system, even where operational contexts differ.
In doing so, they transform reform from a series of isolated interventions into a coordinated process of professional development.
Organising What Already Exists
It is important to recognise that security does not lack knowledge.
Relevant knowledge already exists across multiple domains:
The difference between fragmentation and professional integration can be visualised as follows:
Figure 3: Fragmented vs Integrated Security Knowledge
Risk management methodologies.
Intelligence analysis frameworks.
Behavioural threat assessment models.
Criminology, cybersecurity, and organisational governance.
The issue is not absence.
It is organisation.
When knowledge remains dispersed across disciplines and sectors, it cannot function as the foundation of a profession. It remains difficult to standardise, difficult to teach coherently, and difficult to apply consistently.
When that same knowledge is structured, integrated into a coherent and recognised body, it becomes the basis for professional stability.
From Repetition to Cumulative Progress
The difference between cyclical reform and lasting transformation lies in structure.
When knowledge is unstructured, reform is repetitive.
When knowledge is organised, reform becomes cumulative.
Instead of restarting the conversation every decade, each phase of reform builds upon a stable intellectual foundation.
This does not eliminate the need for reform. Security will always evolve in response to changing threats, technologies, and societal expectations.
But it changes the nature of reform itself.
From reactive adjustment to strategic progression.
Conclusion: Reforming the Right Problem
The question facing the security sector is no longer whether reform is required.
It is whether reform is addressing the right problem.
As long as reform remains focused primarily on regulation, it will continue to deliver incremental improvements without achieving structural transformation.
To move beyond this cycle, the sector must shift its focus.
From rules to knowledge.
From procedures to structure.
From repetition to progression.
Because the issue is not reform itself.
It is the absence of a system capable of sustaining it.