DroneDefender / A³O

UAV vulnerability assessment: what a facility audit actually covers

Leipzig/Halle had counter-drone protection. It never saw the drone that hit a parked An-124 — because that drone spoke over 5G, not radio. A vulnerability assessment exists to find gaps like that before an incident does. For critical entities in the EU, the deadline for doing so is already running.

insights/uav-vulnerability-assessment

Key takeaways

A vulnerability assessment in brief.

A UAV vulnerability assessment is not a product demonstration and not a list of equipment. It is a structured answer to one question: how would a drone actually reach the thing you care about, and what would happen next. The output is a costed, prioritised plan — which is also the specification you buy against.

✓ The assessment maps approach corridors, airspace, sensor blind spots, RF and GNSS exposure, and the assets worth protecting.
✓ It examines response as a legal and organisational problem, not only a technical one: who is allowed to act, and who decides.
✓ It measures time — from first detection to a person making a decision — because that number, not sensor range, determines the outcome.
✓ Owning a detector is not protection. Leipzig had counter-drone equipment; the attacking drone was controlled over a cellular link and did not look like a drone to it.
✓ A spatial digital twin turns coverage and blind zones from an estimate drawn on a satellite image into a calculated result.
✓ The threat class changes faster than procurement cycles, which is why an assessment is a baseline to revisit rather than a document to file.
✓ For entities identified under the EU Critical Entities Resilience Directive, a risk assessment covering hybrid threats is a legal obligation with a date attached.

A defended airport, an undetected drone

What actually happened at Leipzig/Halle.

On the evening of 4 August 2026, an FPV quadcopter roughly the size of a microwave oven flew over Leipzig/Halle Airport and struck the wing of a parked Antonov An-124, close to the fuel tank. It carried about 800 grams of high explosive. It failed to detonate, bounced off and landed on the apron, where an airport bus driver noticed it around four hours later. A second drone collided with a Boeing 757 at roughly 400 metres during a go-around; the crew declared a mayday and diverted to Hannover. A third drone, carrying 50 grams of RDX, was found in a field west of the airport ten days later. The detail that matters for anyone assessing their own site is not the explosive. It is the control link. The drone carried a 5G router and two SIM cards, had no navigation lights, and was flown over a cellular network — which meant that to a conventional counter-drone system listening for drone control protocols, it was indistinguishable from an ordinary mobile phone. Investigators later found an antenna in a nearby tree, apparently used as a relay. Leipzig was not an unprotected site. It had counter-drone equipment. That equipment was built around an assumption — that a hostile drone announces itself on known radio bands — and the attacker simply declined to meet it. German authorities called the incident a new level of danger and doubled the federal police counter-drone units in response. A vulnerability assessment is the process that is supposed to surface that assumption on paper, in advance, while it is still cheap to fix.

For critical entities, this is no longer optional

The CER Directive deadline is already running.

Directive (EU) 2022/2557 on the resilience of critical entities changed the status of this work. Member States were required to identify their critical entities by 17 July 2026. Once designated, an entity has nine months to carry out a risk assessment under Article 12 — which puts the outer limit at 17 April 2027, with full compliance obligations applying from 17 May 2027. That assessment must cover all relevant natural and man-made risks, explicitly including hybrid threats. After the past two years of European airspace incidents, drones are not a debatable inclusion. The European Commission's Action Plan on Drone and Counter Drone Security (COM(2026) 81 final, 11 February 2026) sharpens this further. It commits the Commission to issuing guidelines for critical entities under the CER Directive with specific advice on countering drone threats, to a voluntary stress-test plan letting Member States assess how their critical infrastructure holds up against drone intrusion, and to a certification scheme for counter-drone systems. It also encourages Member States to build the legal framework that would let civilian infrastructure operators take remedial action — including takedowns — which most of them currently cannot.

✓ 17 July 2026 — Member States identify critical entities
✓ Nine months — the entity's own risk assessment under Article 12
✓ 17 April 2027 — outer limit for that assessment
✓ 17 May 2027 — full compliance obligations apply
✓ The assessment must cover hybrid threats and is reviewed at least every four years
Directive (EU) 2022/2557 — the clock is already running From designation as a critical entity to a completed risk assessment: nine months about 7 months left 17.07.2026 Member States identify critical entities today 17.04.2027 outer limit for the risk assessment 17.05.2027 full compliance nine months
The deadline is not abstract: nine months from designation to a completed risk assessment.

Six things a real assessment looks at

Not a product list — a map of how you would be reached.

A vulnerability assessment inspects the site the way a hostile operator would plan against it, and it produces findings that survive contact with a procurement committee. Approach corridors and airspace. Where can an aircraft come from, at what altitude, using what terrain and what cover. A river valley, a treeline, a neighbouring industrial roof and a public road all change the answer. This is also where launch points get identified: an operator needs somewhere to stand, and on most sites there are only a handful of plausible ones. Assets and consequence. Not every part of a facility is equally worth protecting. The assessment ranks what an intrusion would actually cost — a production stoppage, a safety shutdown, surveillance of a process, physical damage to a single irreplaceable component — and works backwards from there. Protection effort follows consequence, not perimeter length. RF and GNSS environment. A measured survey, not an assumption. What the ambient spectrum looks like at the site, where the noise floor sits, what interference the facility generates itself, how exposed GNSS is to jamming or spoofing. This is also where the Leipzig question belongs: does the planned detection layer assume a conventional control link, and what happens if there isn't one. Existing sensors and the gaps between them. Most sites already have cameras, sometimes radar, often a perimeter system. The assessment establishes what they actually cover against a small, low, slow target — usually far less than the brochure range — and where the seams are. Coverage on paper and coverage in practice diverge most at low altitude and close in. Time, measured end to end. From first detection to a human being holding the information required to decide. This is the number most sites have never measured, and it is the one that decides outcomes. A four-kilometre detection range is worth nothing if the alert reaches a screen no one is watching, or reaches an operator who then needs eleven minutes to find someone with authority. Legal and organisational authority. What is permitted in this jurisdiction, at this site. Passive detection is broadly lawful across the EU. Jamming generally is not, and near an airport it is both unlawful and dangerous. Interception is almost always restricted to designated authorities. The assessment records who may act, who must be called, how quickly they arrive, and what the site is entitled to do in the meantime — which is often more than the security team assumes, and always less than a vendor implies.

From a map to an executable model

A digital twin turns assessment findings into something you can test.

The traditional output of a vulnerability assessment is a document. Documents describe blind spots. They do not let you fly through them. A spatial digital twin of the site changes what the assessment is able to prove. Built from open data or from centimetre-accurate photogrammetry, the twin carries the things that actually decide the answer: buildings and their heights, terrain, fence lines, vegetation, and the positions of existing cameras and sensors with their real coverage volumes. Coverage and blind zones stop being an estimate sketched over a satellite image and become a calculated result. You can see where a sensor's field of view ends, where two fields fail to overlap, and what a low approach along a treeline looks like from each camera already installed — before anyone has been asked to approve a purchase. On the analysis side, the platform already performs the work that makes a twin useful rather than decorative: it fuses sensor inputs into single tracks, scores risk with the reasoning attached, and projects a track forward so an operator sees where an object is going rather than where it has been. Attack simulation against the twin — flying scripted and adversarial approach profiles through the model to establish which sensors react, in what order, and how much time the operator is left with — and the operator training mode with an adversarial AI are available to pilot programme participants. Both run inside the A3O Mini Rapid environment on the A3O Mini appliance deployed at the site: they are part of the working platform rather than a separate service. That is why simulation comes with a pilot, not with a report.

A3O digital twin console: 3D model of the protected site, sensor coverage volumes, layer controls and a dedicated blind-zone view
The deliverable is not an opinion but a model: site layers, real sensor coverage volumes, and a dedicated view for blind zones.

The threat moves faster than the paperwork

Why an assessment is a baseline, not a certificate.

Most security disciplines allow an assessment to age gracefully. A fence is a fence; a lock does not acquire a new capability because someone published a paper. Drone threat does not behave that way. The relevant capabilities are assembled from consumer components, iterated in weeks, and distributed publicly — and each iteration can invalidate an assumption that a previous assessment treated as settled. The pattern is easy to trace. A site assessed in 2023 was asked, reasonably, which radio bands to monitor. By 2025 fiber-optic FPV drones — spooling ten to twenty kilometres of glass behind them, emitting nothing — had moved from curiosity to standard equipment, and the question of what to do when there is no signal at all became unavoidable. In August 2026 Leipzig added a second variant: control moved onto a public cellular network, making the aircraft look like a phone. Neither required new physics. Both required someone to notice that everyone was listening in the same place. The direction of travel is consistent: away from anything that announces itself. Onboard autonomy that needs no link during the approach, pre-programmed routes, swarmed and miniaturised airframes — the European Commission names multi-vector threats of exactly this kind in its Action Plan — and airframes whose radar cross-section is measured in hundredths of a square metre. Meanwhile the asymmetry stays brutal: a few hundred euros of hardware against an airport shutdown, and European incidents near critical infrastructure quadrupled between 2024 and 2025. The practical consequence is not despair. It is that an assessment should be written to be re-run. The CER Directive sets the regulatory floor at a review every four years; in this domain four years is a long time, and the review is worth doing whenever the threat picture shifts rather than when the calendar says so. This is also the strongest practical argument for building the site as a model rather than a document: re-testing a new approach profile against an existing twin is a short exercise, while re-surveying a site from scratch is a project.

✓ Fiber-optic control — no emission to detect, no link to jam. Two years from curiosity to commonplace.
✓ Cellular control — as at Leipzig: a 5G router and SIM cards make the aircraft indistinguishable from a phone to an RF layer.
✓ Autonomy on board — pre-programmed routes and terminal guidance that need no operator link at the moment it matters.
✓ Swarms and miniaturisation — named in the EU Action Plan as an emerging multi-vector threat.
✓ Cost asymmetry — hundreds of euros of airframe against a shutdown measured in millions.
Three steps in three years — each invalidated an assumption None of it required new physics. It required someone to notice that everyone was listening in the same place. 2023 Radio control RF layer: sees it A signal exists, so there is a bearing and a warning at 5–10 km. 2025 Fiber optic RF layer: silent No emission at all. Nothing to jam either. 2026 Cellular network RF layer: sees a phone Leipzig, August 2026: a 5G router and two SIM cards on board. Heading the same way: onboard autonomy · swarms and miniaturisation · radar cross-section in hundredths of a square metre
Each step invalidated an assumption the previous assessment had treated as settled.

Four ways an assessment becomes worthless

Most of these are cheap to avoid and expensive to discover later.

An assessment that produces a procurement list and no map has failed, whatever it cost. The recurring failures are consistent enough to name.

✓ It only tests the radio channel. The most convenient detection layer is also the first one a prepared adversary defeats — by flying a pre-programmed route, by using fiber, or as at Leipzig, by moving the control link onto a cellular network.
✓ It confuses equipment with capability. A detector with no one watching it, no procedure attached and no authority behind it is an expense, not a defence.
✓ It is written by the party selling the remedy. An assessment whose conclusions happen to match one vendor's catalogue should be read as a quotation, not a finding.
✓ It never measures elapsed time. Detection range is easy to specify and easy to sell. Time-to-decision is the number that determines whether the detection mattered.

What you should hold at the end

Decision-ready, not a sales deck.

A completed assessment should let a board approve or reject a budget without a further study. In practice that means five documents: a threat profile for this specific facility with the scenarios that are plausible against it and a risk rating; a coverage and blind-zone map showing what today's sensors truly see and where the seams lie; a recommended sensor layout with placement and justification, sized to the assets rather than the fence line; response and policy recommendations stating what is legally possible here and the authorisation and evidence workflow to execute it; and a phased deployment roadmap with indicative budget, so that the first phase is defensible on its own and the rest can wait for money. Where a digital twin was built, the coverage calculations and maps derived from it are part of that package. The twin itself is a working environment rather than a document: it executes in A3O Mini Rapid on the A3O Mini appliance, and stays on site for as long as that appliance does. Used properly, the assessment becomes the specification you buy against — and the document you hand to a regulator when asked how you reached your conclusions.

Frequently asked questions

What is a UAV vulnerability assessment?

An on-site evaluation of how exposed a facility is to drone threats. It maps approach corridors, airspace, sensor blind zones, RF and GNSS exposure, critical assets and the legal constraints on response, and ends with a prioritised, costed plan to close the gaps.

How is it different from a counter-drone system demo?

A demo shows what one product does in conditions the vendor selected. An assessment establishes what your site needs, independently of any product, and produces the specification a product then has to satisfy. Running them in that order is what stops you buying a sensor that cannot see the approach that actually matters.

Is this legally required?

If your organisation has been identified as a critical entity under Directive (EU) 2022/2557, a risk assessment covering hybrid threats is an obligation, due within nine months of designation. For everyone else it is not mandatory — but insurers, regulators and boards increasingly ask how the exposure was determined, and “we bought a detector” is not an answer.

How long does an assessment take?

Field work on a single site is usually one to three days depending on size and complexity, with the spectrum survey and the coverage modelling done alongside it. The reporting and the costed roadmap follow. Multi-site estates are normally assessed on a representative sample first, then extrapolated.

How often should an assessment be repeated?

The CER Directive requires a review at least every four years, which is the floor rather than the target. In practice the trigger should be a change in the threat picture or in the site: a new class of approach becomes common, a neighbouring building goes up, a process moves, a sensor is replaced. Where the site exists as a model, revisiting it is inexpensive — a new approach profile is tested against the existing twin rather than by re-surveying the ground.

What stays with us after the assessment — the twin, or only a report?

The report, the coverage and blind-zone map, the calculations and the roadmap stay with you in every case. They are standalone documents, and they are enough to evaluate vendor proposals against. The interactive twin is not a file but a working environment: it lives in A3O Mini Rapid and runs on the A3O Mini appliance deployed at the site. So the twin stays with you as long as that appliance does — through a pilot programme, or after deployment.

Do we have to buy anything afterwards?

No, and an assessment that assumes you will is the wrong assessment. A common and legitimate outcome is that existing cameras and procedures cover more than expected and the correct next step is a narrow one — a single sensor at one blind corner, or a change to who gets called at night.

Can an assessment tell us whether we may intercept a drone?

It can tell you what the law in your jurisdiction permits at your site, who holds the authority, and what you may do while waiting for them. It cannot grant permission. Passive detection is broadly lawful in the EU; jamming generally is not; interception is normally reserved to designated authorities. The Commission has encouraged Member States to widen what operators may do, but until national law changes, the constraint is real.

Find the gap before it is found for you

Start with an assessment, not a purchase order.

The most expensive way to discover a blind spot is during an incident. A facility vulnerability audit for UAVs maps your real exposure — approach corridors, sensor seams, RF and GNSS conditions, response authority — and turns “we need drone protection” into a plan with numbers attached. It is also the document that makes the rest of the work defensible. Request an assessment for your site below.

Ready to discuss your site?

Start with a short consultation, live demo or structured pilot program.