IPB for Protective Intelligence: A Military Framework That Translates
Intelligence Preparation of the Battlefield, translated for protective work: four steps that show a small team where its intelligence picture has holes.
By Gavin Quinn
Intelligence Preparation of the Battlefield (IPB) is the military's systematic method for analyzing an operating environment before committing to a plan: terrain, conditions, threat, and how they interact. Stripped of its acronyms, it translates almost directly to protective work.
Why borrow a military framework
Cyber threat intelligence made this move a decade ago. The kill chain, the diamond model, structured analytic techniques: the digital side of security looked at military intelligence doctrine, took what worked, and built a professional discipline around it. The physical side never did the same translation at scale. Protective teams inherited craft through apprenticeship (ride along, watch the advance, learn by doing), which produces skilled practitioners and inconsistent process.
Most protective teams already run fragments of IPB by instinct. You drive the routes. You walk the venue. You check what's happening in town that weekend. That is IPB in plainclothes. What the framework adds is not new activity but two things the instinctive version lacks:
- A sequence. Environment before effects, effects before threat, threat before threat courses of action. Each step feeds the next, and skipping one degrades everything downstream.
- A completeness check. When you work the steps in order, the holes in your picture become visible. You know what you don't know, which is the difference between an assessment and a hunch.
One caveat before the steps: this is one way to run it. Military units adapt IPB to their echelon and mission. I watched SF teams run it differently than conventional units did, and both were right for their problem. Adapt it to yours.
Step one: define the operating environment
The military logic in one breath: bound the area of operations (the ground you will act on) and the area of interest (the wider space whose events can reach into it).
For a protective movement, the area of operations is concrete: the venue, the routes, the hotel, the districts the principal actually touches. The area of interest is the ring around it — the airport, the region, anything within an hour that could put people, traffic, or trouble into your space before you'd see it coming.
The discipline here is drawing the line consciously. Every team draws it somehow; most draw it by default, which usually means the line sits wherever attention ran out. Drawn deliberately, the line becomes a decision with consequences you can manage. What's inside the line gets analyzed — walked, driven, worked in detail. What's outside gets monitored, a lighter, ongoing activity with its own method, covered in monitoring a region before you travel.
A hole at this step looks like a protest forming two miles away that nobody owned, because it was outside everyone's mental map and inside nobody's monitoring.
Step two: describe the environment's effects
The military logic in one breath: analyze how terrain and weather shape what's possible for both sides — observation, cover, obstacles, avenues of approach.
"For both sides" is the part protective teams skip. The instinctive advance reads the ground once, from the detail's seat: where do we stage, where do we drop, where's the secondary egress. IPB demands a second read of the same ground from the other side.
Same terrain, read twice — once as the detail, once as the adversary.
Choke points are the clearest case. A one-lane garage entrance constrains your movement options; it also concentrates your predictability into a known place at a knowable time. That double reading is a discipline of its own (see choke point analysis). Sightlines you'd dismiss as irrelevant to your plan may be exactly what a surveillant needs: elevated positions with a view of the arrival point, loitering areas with a natural reason to exist, crowd flow that lets someone hold static without standing out.
Weather belongs here too, and not as small talk. Rain moves an arrival from curb to garage and changes the choreography. Heat changes how long a principal can be exposed on foot. Conditions stretch response and medical timelines: the drive time to the trauma center you planned in the sun is not the drive time in a storm.
Step three: evaluate the threat
The military logic in one breath: know the adversary — capabilities, patterns, and how they prefer to operate — before you guess what they'll do.
The protective translation is an honest threat picture for this principal, not a generic one. Three questions structure it:
- Who has shown interest? Correspondence, online fixation, prior approaches, grievances with a name attached. Known persons of interest are the concrete core of the picture.
- What is the baseline threat environment? Crime patterns where you're operating, local tensions, anything ambient that raises the floor regardless of who the principal is.
- What does capability realistically look like? A fixated individual on foot is a fundamentally different problem from organized crime with vehicles, funding, and patience. Assessing capability soberly, neither inflating it to justify posture nor deflating it to ease the client conversation, is where this step is won or lost.
Every input here comes from a source, and sources are not equal. A vetted police contact, a screenshot forwarded by the client's assistant, and an anonymous post deserve different weight. The method for assigning it is in how to rate an intelligence source.
Step four: determine threat courses of action
The military logic in one breath: project the threat's most likely course of action and its most dangerous one, so the plan is tested against both.
This is the step that separates analysis from scenery description, and it's the one small teams most often leave undone, because the first three steps feel like the work. They aren't. They're the inputs. Step four asks the question the whole framework exists to answer: given this environment, these effects, and this threat, where and how does interest become action against this specific movement?
The environment read only matters if someone asks what the threat does with it.
Work it as concrete propositions. The most likely course of action might be a fixated individual attempting approach at the public arrival, because that's the one moment location and timing are predictable. The most dangerous might exploit the choke point you flagged in step two. These aren't predictions — they're structured hypotheses, and their purpose is to be tested. They feed directly into the tabletop, where a red cell plays them against your plan and looks for the seams. That process is covered in wargaming an advance.
One boundary worth stating plainly: this is planning support. The team executing the mission plans its own mission and owns its own immediate-action decisions. Intelligence preparation sharpens the plan; it doesn't substitute for the team's judgment, in planning or on the ground.
The output is not a binder
Doctrine imagines IPB producing overlays and annexes. A small team's version is lighter and better for it: a marked-up map, a one-page environment read in the advance brief, and a sharper set of red-cell questions than you would have generated cold. If the output takes longer to produce than anyone will spend reading it, you've built the wrong output. The framework scales down cleanly because the value sits in the sequence, not the paperwork.
What IPB assumes that you don't have
Military IPB assumes an intelligence staff feeding it: collectors, analysts, databases, requests flowing up and answers flowing down. A protective team feeds it themselves, usually while also doing the advance, the logistics, and the client management. Two adjustments make it survivable:
- Time-box each step. Thirty focused minutes per step on a routine movement beats three unstructured hours of general worry. The sequence protects you even when the depth is thin.
- Let the gaps be explicit. When you can't answer a step's question, write the gap down instead of papering over it. A hole you've named is collection guidance: it tells you what to look for next, and it tells the detail what the picture doesn't cover. A hole you haven't named is just a surprise on layaway.
That last habit is the quiet payoff of the whole framework. The instinctive advance produces confidence; the structured one produces calibrated confidence — you know which parts of your picture are solid and which are guesswork. In this line of work, that distinction is worth more than any overlay.
