On the night of September 19, 2014, a man named Omar Gonzalez climbed the fence at the White House, ran across the north lawn, and walked in through the unlocked front door of the most heavily guarded home in the world before anyone stopped him. What followed was one of the most thorough security reviews in modern memory. It named every failure and set out a long list of fixes. A decade later, several of those fixes had quietly come undone, and in July 2024 a gunman on a rooftop in Butler, Pennsylvania got a clear shot at a former president for reasons the 2014 review had already spelled out in black and white.
That is the uncomfortable pattern behind almost every high-profile breach. The report is thorough, the recommendations are sound, and then, slowly, the fix erodes, because it depended on people staying alert, funded, and coordinated long after the news trucks had left. Gonzalez is one of three breaches we are going to look at here, all from the last decade, each one taken apart more carefully than almost anything else in our field. In the second, an intruder reached a former Speaker's husband inside his own home while a security camera recorded the entire attack and nobody was watching the screen. In the third, a suicide bomber stood in a concert foyer for a full hour with a rucksack on his back while an uneasy 18-year-old steward wondered whether to say something, and, in the end, said nothing. Different countries, different threats, but each review came back to the same three failures: intelligence that existed and never reached the people on the ground, responsibility that fell between two organizations, and monitoring that was not actually watching anything.
In this article we walk through all three the way a review board would, and then we hand you the same method to run on your own program. It comes with a downloadable After-Action Review template: a simple, fillable structure you can pull out after any incident or near-miss, so that the next time something goes wrong on your watch, the lesson ends up in a corrective-action log with a name beside it and a date to check back, not in a memory that has faded by the next rotation. Get that habit right and you build the one thing all three of these programs were missing when it counted most: a memory that outlasts the people who made it.
Upgrade to Premium to keep reading.
Upgrade to Premium for the insight, tools, and briefings serious protection professionals use to stay sharper, better prepared, and always ready.
Go PremiumWith a Subscription:
- Read the full article now
- Unlock every Premium article and digital issue
- Access guides, templates, briefings, and downloads
- Turn industry incidents into usable lessons
- Keep your edge between assignments

