9/11 Attacks, 25 Years Later: Insights From the Council on Foreign Relations Symposium 

On Sept. 10, 2026, I had the honor of attending the Council on Foreign Relations (CFR) Symposium “9/11 Attacks: 25 Years Later.” 

The event had three sessions, including a conversation with former secretaries of homeland security, a discussion on the view from Washington and eyewitness history and a conversation on the current state of U.S. counterterrorism policy. I was in the room with many who were in government on Sept. 11, 2001, and many who helped build the U.S. Department of Homeland Security (DHS) and our security and counterterrorism posture thereafter. The discussion examined how the 9/11 attacks fundamentally changed the operations of government and our posture of security, reshaping policies, procedures and the broader homeland security mission. 

A key takeaway was that homeland security must evolve beyond the threat environment of 9/11. Threats are increasingly fragmented, decentralized, diversified, cyber-enabled and rapidly evolving. All secretaries who spoke at the event agreed that mass violence fueled by personal grievances, cyberattacks and threats from nation-state actors requires new approaches to prevention, preparedness and response. In new commentary, researchers from RAND stated that, “the strategy is deliberately layered, because different mitigations stop different threat actors… each layer is critical but only having one is insufficient.”  

I think this perfectly sums up how we must approach the environment we are in today. 

Former Secretary of Homeland Security Alejandro Mayorkas highlighted the changing relationship between homeland security and national security—and, I would add, the security industry. As these missions converge, so do the roles of government, technology providers and the public. Given today’s vast threat environment and threat actors, where anyone and anything can be a target and opportunity, the security industry has an important role to play. Government cannot address these threats alone—making security a shared responsibility across government, industry and in all sectors.  

This shared responsibility is particularly important as information sharing and communication remain critical challenges, even as communication technology has evolved significantly over the past 25 years. This is not because the technology does not exist, but rather because communication is fundamentally a people problem which we have worked to solve. Organizations and individuals do not always collaborate or ask one another for help, even when resources and expertise are available. A more connected security ecosystem will require people across sectors to recognize that everyone has a role in security, and that we all must work together and communicate effectively. In addition, a connected security ecosystem must require that employed technology is understood. People need to understand technology to effectively deploy, monitor, and update solutions. People need to know how to use technology, interpret it and work together with technology as a tool for it to be effective. 

The conversations briefly addressed the appropriate use of technology and the balance between security and privacy. The speakers emphasized that technology should be deployed responsibly and consistently with constitutional protections, aligning with SIA’s principles for the responsible and effective use of technology for purposes that are lawful, ethical and nondiscriminatory. While also pointing out that individuals’ privacy can be affected simply through everyday use of smartphones, the speakers noted that we have an existing legal and institutional architecture designed to establish guardrails and balance security requirements with privacy and civil liberties. We cannot forget the foundation that has already been built, as we address the future of security technology. In this conversation, artificial intelligence was identified as an area requiring particular attention. Three key needs were highlighted by former Secretary of Homeland Security Jeh Johnson: access to quality data for training, greater disclosure and transparency regarding the use of artificial intelligence (AI) and ensuring that consequential decisions retain a human in the loop. As AI becomes increasingly integrated into the security ecosystem, establishing responsible practices will be essential. 

Considering the future of DHS, the speakers argued that the department needs to be better aligned with the threats facing the country today and emphasized the importance of restoring credibility and public trust. Any meaningful change will take time and require rebuilding confidence in the mission of DHS. I mention this as a broader reflection of the security industry as a whole; while the Security Industry Association (SIA) is a very different organization, maintaining credibility and public trust in this industry is critically important and hard to gain back once lost. 

To me, it seems as if we are reaching a tipping point in homeland and national security. The next 25 years are likely to look very different from the period following 9/11, and we cannot assume that the security structures built in response to the threats of the past will adequately address the threats of the future. Bruce Hoffman, counterterrorism researcher and senior fellow for counterterrorism and homeland security at CFR, is coming out with his fourth iteration of his book in August 2027. First published in 1998, as Hoffman has released editions overtime to compensate for change in the field, we must as well. The discussion called for greater collaboration across government, industry and local communities, for more people to actively participate in the security ecosystem and for innovation and creativity as we look forward. 

The conversations at the CFR symposium underscored the importance of connecting government, industry and technology stakeholders to understand and address an increasingly complex threat environment that is not going to get easier. The insights shared reinforced SIA’s role in helping members navigate evolving government priorities, emerging threats and policy and regulatory developments, while ensuring policymakers understand both the capabilities and limitations of security technologies. The technology industry is at the forefront of change: principles of business require that the industry changes over time because they must create, innovate, and think forwardly to get business. SIA has the opportunity to serve as a bridge and help translate emerging security challenges into meaningful industry engagement and solutions. To our members and the SIA community: thank you for the work you do to enable our country to be safer and more secure.