The Post-9/11 Security System Faces a Threat It Wasn’t Built to Stop
The agencies built after 9/11 are confronting a threat landscape shaped by lone actors, cyber warfare, and global rivals.

WASHINGTON — The federal government’s counterterrorism architecture was built after the Sept. 11, 2001, terrorist attacks, which killed 2,977 people across New York, the Pentagon, and Shanksville, Pennsylvania. A quarter-century later, the security environment has shifted from centralized overseas terror cells executing multi-year plots to decentralized lone actors, digital radicalization, cyber operations, and nation-state rivalries.
On the morning of Sept. 11, 2001, Javed Ali was driving past the Pentagon on his way to work in Northern Virginia, roughly 30 minutes before American Airlines Flight 77 struck the building. From his office in Falls Church, he watched smoke rise from the structure.
A year later, Ali joined the Defense Intelligence Agency’s counterterrorism office and walked into the still-damaged Pentagon to begin his national security career. “It was a very eerie and odd and surreal moment in my career,” Ali said.

The statutory transformation began in November 2001, when Congress passed the Aviation and Transportation Security Act. The law created the Transportation Security Administration under the Department of Transportation before TSA was later transferred to the Department of Homeland Security. It shifted airport passenger and baggage screening from private contractors to federal employees and marked the largest civilian government undertaking in U.S. history up to that point.
Congress enacted the Homeland Security Act of 2002 the following year, consolidating 22 federal agencies and entities into DHS. Those entities included the U.S. Customs Service, the Coast Guard, the Secret Service, the Immigration and Naturalization Service, and the Federal Emergency Management Agency. DHS opened its doors in March 2003 and has since grown to employ more than 260,000 personnel, with duties spanning border management, infrastructure protection, cybersecurity, and emergency response.
Ali’s service later extended to DHS and the FBI, placing him inside the agencies created to monitor, track, and dismantle terrorist networks. During his tenure at DHS, intelligence and law enforcement agencies tracked international plots targeting aviation.
One of the most significant was a 2006 plot originating in the United Kingdom. Al-Qaeda-linked operatives planned to detonate liquid explosives disguised as soft drinks aboard multiple transatlantic flights bound for the United States and Canada. Disrupting the plot led to global security restrictions on liquids in carry-on baggage.

The financial cost of the new system was substantial. According to data from Brown University’s Costs of War project, the U.S. government has directed more than $1.1 trillion toward domestic homeland security efforts aimed at preventing and countering terrorism since the creation of DHS. Total expenditures on post-9/11 wars, regional counterterrorism operations, and related veteran care obligations have exceeded $8 trillion.
The intelligence framework also underwent a systemic overhaul after the National Commission on Terrorist Attacks Upon the United States, known as the 9/11 Commission, examined the attacks. The commission identified severe structural fractures before 9/11, including responsibilities scattered across agencies and minimal intelligence sharing between domestic law enforcement and foreign intelligence entities.
Congress responded with the Intelligence Reform and Terrorism Prevention Act of 2004. The law established the Office of the Director of National Intelligence to oversee the 18 agencies of the U.S. Intelligence Community and created the National Counterterrorism Center to integrate foreign and domestic intelligence.
The FBI concurrently expanded its network of Joint Terrorism Task Forces, pairing federal agents with state and local law enforcement officers across the country. The post-9/11 system, Ali said, eliminated the operational conditions that made the 2001 attacks possible, even as terrorism changed alongside the government’s defenses.
“So yes, we are safer from a certain type of threat,” said Ali, now an associate professor of practice at the University of Michigan’s Ford School of Public Policy. “But again, we are not immune from terrorism, and other types of threats are much more difficult to identify or stop.”

During the initial decade following 9/11, U.S. counterterrorism operations remained heavily focused on al-Qaeda and its global network. U.S. and coalition forces dismantled foreign training camps and targeted key leadership figures, but the network continued attempting transatlantic and domestic strikes.
Al-Qaeda founder Osama bin Laden was killed by U.S. special operations forces in Abbottabad, Pakistan, in May 2011. The threat landscape then fractured rather than dissolved. An operational vacuum in the Middle East enabled the rise of the Islamic State of Iraq and al-Sham, or ISIS, an al-Qaeda splinter group that expanded rapidly across Iraq and Syria in 2013 and 2014 before declaring a self-described caliphate in June 2014.

Unlike al-Qaeda’s traditional model of vetting and training dedicated operatives overseas, ISIS pioneered decentralized recruitment. Through digital propaganda, online forums, and encrypted communications, the group urged sympathizers in Western nations to conduct low-tech, independent attacks in their home countries.
For U.S. intelligence agencies, the center of gravity shifted toward detecting individuals undergoing online radicalization inside domestic borders rather than intercepting trained foreign cells.
“Mostly lone actors, lone offenders, not tied to groups overseas, not traveling overseas, and not being directed by people overseas,” Ali said.

The Office of the Director of National Intelligence noted in its 2026 Annual Threat Assessment that severe operational setbacks suffered by foreign Islamist groups have constrained their capacity to execute complex, multi-stage foreign operations. Foreign terror groups have increasingly turned toward propaganda campaigns aimed at inspiring self-directed violence within Western nations.
At least three Islamist terrorist attacks occurred within the United States in 2025, according to the intelligence assessment. During the same calendar year, federal law enforcement agencies disrupted at least 15 U.S.-based Islamist terrorism plotters. Intelligence figures show that approximately half of those disrupted individuals had maintained online contact with foreign radical networks or had been inspired by foreign terrorist propaganda.
The vulnerability of lone-actor attacks was highlighted on Jan. 1, 2025, when Shamsud-Din Jabbar, a U.S. citizen from Texas, drove a pickup truck into a crowded pedestrian area on Bourbon Street in New Orleans, killing 14 people. The FBI designated the incident an act of terrorism and said Jabbar had radicalized online in isolation before carrying out the attack.
After the New Orleans attack, the FBI reaffirmed that self-radicalized lone offenders and small cells represent the most difficult operational threat for law enforcement because they generate few observable pre-attack indicators and often operate without established intelligence signatures.
The 9/11 attack required 19 hijackers, international funding transfers, foreign coordination, domestic flight instruction, and long-term planning, generating multiple touchpoints across foreign and domestic intelligence databases. A single actor radicalizing in front of a computer screen can leave a minimal law enforcement trail before moving to action.

The evolution of the threat environment has drawn scrutiny from foreign policy analysts and former national security officials over the size, cost, and orientation of the U.S. homeland security state. Critics argue that bureaucratic structures established after 2001 remain focused on legacy vectors while newer, systemic vulnerabilities receive insufficient attention.
Morgan Murphy, who served as press secretary to the secretary of defense and later worked in the White House during the first Trump administration, argued that the post-9/11 expansion produced excessive administrative oversight at the expense of strategic preparation against nation-state adversaries.
“TSA agents still pat down grandma and gum up travel while Beijing wires our living rooms with cheap TVs and selfie sticks through the supply chain handed to them by Clinton, Bush, Obama, and Biden,” Murphy said. “We spent two decades frisking American passengers while our adversaries plugged themselves into our homes and businesses.”
Murphy added: “The genius of America after Pearl Harbor was that we built to fight. After 9/11, we built to process. Real security means sovereignty at home and lethality abroad — a sealed border, an untangled supply chain, and enemies who fear us.”
Theo Wold, who served as acting assistant attorney general in the Justice Department’s Office of Legal Policy and as deputy assistant to the president for domestic policy during the first Trump administration, said the structural legacy of the post-9/11 era relies too heavily on expansive federal bureaucracies and prolonged foreign engagements.
“George W. Bush and the DC governing elite responded to 9/11 the way their politics demanded: create large, unwieldy bureaucracy, push for special legal authorities with limited oversight, and activate ground wars in the Middle East,” Wold said. “Those wars didn’t make us safer, the legal authorities were wielded against Americans, and the bureaucracy is full of waste and has proven nearly unworkable.”
Wold maintained that future policy must prioritize agility: “Now we know better. Americans are safest when we are nimble and focus ruthlessly on targeting real enemies.”

National threat assessments also identify non-terrorist threats crossing physical and digital borders. The 2026 intelligence assessment highlights growing capabilities among China, Russia, Iran, and North Korea, as well as non-state ransomware cartels seeking entry into U.S. government infrastructure, electrical grids, and private-sector networks for espionage, economic disruption, or operational leverage.
The assessment noted that breakthroughs in artificial intelligence are accelerating the speed and sophistication of offensive cyber tools. Strategic rivals continue developing advanced missile and drone systems capable of striking domestic territory.
National security veterans have cautioned against discounting traditional counterterrorism vigilance. Ali emphasized that an enduring lesson of the pre-9/11 period was the danger of allowing extremist groups to operate unhindered overseas until they developed the space to plan long-range strikes.
“When these terrorist threats start to emerge, whether it’s overseas or here, you have to put pressure on them before they gather momentum to carry out operations,” Ali said. “Terrorism as a tactic is probably never going to be defeated.”











