On 30 and 31 July, around 70,000 people attempted to enter the Spanish enclave of Ceuta from Morocco, in one of the largest episodes of mass border crossings in Spain in recent years. The mobilisation had been preceded for several weeks by calls to cross the border and exchanges on social media and messaging platforms. A question quickly emerged: had these signals been detected in time by Spain’s intelligence services and, more importantly, had they been translated into a decision?

Ceuta raises a question that reaches far beyond the Spanish exclave: What turns an observable threat into a decision?

Spain is debating whether its intelligence services warned the government before tens of thousands of people entered the Spanish exclave of Ceuta on 30 July.

The government acknowledges that it had information about an emerging seasonal increase in arrivals. It says that no intelligence report anticipated an event of the scale that followed. Interior Minister Fernando Grande-Marlaska has stated that no information service warned of “a circumstance of that nature” (RTVE).

Sources attributed to Spain’s intelligence community tell a different story. According to these accounts, the National Intelligence Centre sent several warnings to the Interior Ministry. Other reports claim that the principal chat encouraging the crossing had been identified eight days before the event (Cadena SER, La Razón).

Those accounts rely on anonymous sources. Spain’s National Court has now asked the Guardia Civil to establish whether any of its units in Ceuta received information that could have provided prior warning (Demócrata).

The investigation will have to establish what was known, when it was known and where the information went. For the wider security community, Ceuta already exposes a deeper problem.

Security organisations have become very good at collecting signals.
They remain far less consistent at deciding what those signals require them to do.

Localisation of Ceuta

What was visible before Ceuta

The digital activity preceding 30 July developed in public over several weeks.

Rumours about a Spanish Supreme Court decision circulated across Facebook, Instagram, TikTok, WhatsApp and Telegram. The decision was reframed as an opening of the border. Accounts shared successful crossings, routes and practical instructions.

An online campaign related to Ceuta generated an estimated 11 million views from early July onward (AFP). One Instagram video showing a route from Fnideq to Ceuta reached 1.4 million views in the days before the crossing. Other accounts directed followers into WhatsApp groups where journeys were discussed and coordinated (CBC).

Public data also showed growing physical pressure. By 15 July, Spain’s Interior Ministry had recorded 2,826 irregular entries into Ceuta during 2026, an increase of 146 percent over the previous year (Antena 3).

Together, these observations created an intelligence question well before the scale and timing of the event could be established.

Were the signals fragments of a familiar seasonal pattern?
Or were they becoming something qualitatively different?

This is the point at which collection ends and judgment begins.

From detection to judgment

Security discussions often treat warning as a binary condition.

An organisation was warned.
Or it was surprised.

Real intelligence work sits between those two positions.

The first signal is usually ambiguous. Its source may be unknown. Its reach may be measurable while its effect remains uncertain. Large audiences do not always mobilise, while small groups can create serious disruption.

Intelligence has to answer several different questions:

  • Is the information credible?
  • Does the observed activity indicate capability, intent or both?
  • Which people, locations or operations could be affected?
  • How quickly could the situation develop?
  • What level of confidence is available?
  • Which precautionary measures would be proportionate?

An alert that says “something may happen” transfers uncertainty to the recipient. An intelligence judgment structures that uncertainty by describing the observable change, plausible consequences, confidence level and time remaining for action.

This distinction matters in every security domain. A SOC may see anomalous activity before the nature of an intrusion is clear. A government may identify mobilisation without knowing how many people will respond.

Waiting for certainty resolves the analytical problem by allowing the event to resolve it for us.

Ceuta, carrefour maritime et numérique

The last mile

An intelligence assessment has to reach someone who understands the consequence, has the authority to act and can mobilise the required resources in time.

This is the last mile of intelligence: where collection, analysis and management meet.

In government, that path may pass through intelligence services, police commands, border authorities, ministries, regional administrations and political leadership. In a critical infrastructure company, it may pass through the SOC, Corporate Security, site management, business continuity, communications and the executive team.

Each participant sees the issue through a different mandate. The SOC asks whether systems are affected. Corporate Security asks whether people and locations are exposed. Operations considers continuity, Communications follows the narrative, and management decides whether intervention is justified.

The threat keeps moving while the organisation translates between those perspectives.

Ceuta illustrates the resulting governance challenge. Signals existed, the increase in arrivals was measurable, and intelligence warnings may have circulated. Their content and recipients remain disputed, while the eventual scale exceeded the assessment acknowledged by the government.

The decisive questions are therefore organisational:

Who owned the combined picture?
Who could change the readiness level?
Which threshold would have justified reinforcement?
How much uncertainty was the decision-maker expected to accept?

These questions belong in an incident review alongside the quality of collection and analysis.

Decisions without certainty

Security leaders rarely receive a complete warning. Attribution may be unresolved, timing imprecise and projected scale expressed as a range. The decision still has to be made.

A practical response can be based on four considerations:

Probability. How credible is the development, and which observable indicators support the assessment?

Impact. What could happen to people, essential services, sites, supply routes or public order?

Lead time. How long would a meaningful preparation take?

Reversibility. What would it cost to activate a measure and later stand it down?

A highly disruptive and irreversible intervention requires a strong evidential basis. Increasing staffing, briefing local management or placing response teams on standby costs less and can be reversed quickly. Such measures can be justified earlier where the potential consequences are severe.

The objective is disciplined preparation under uncertainty.

Cybersecurity teams already work this way. Incident response plans define escalation levels while the nature of an intrusion remains uncertain. Threat hunting starts with hypotheses and tests them against emerging evidence. The same logic can guide decisions about digitally observable threats to the physical world.

What changed on 15 August

A second mobilisation around Ceuta created a useful comparison.

Posts promoted 15 August as another opportunity to cross into the Spanish exclave. This time, the Guardia Civil produced a six-page assessment based on publicly available information. It described an active digital call with mobilisation potential and stated clearly that its execution, size and authorship remained unconfirmed (Spain in English).

The assessment preserved the uncertainty and gave decision-makers a structured basis for preparation.

Spanish and Moroccan authorities reinforced their presence. Thousands of police were deployed on both sides of the border. Hundreds of people arrived, and Moroccan authorities reportedly detained nearly 300 (CBC).

Many variables may explain the different outcome. The operational sequence is still instructive:

Signal.
Assessment.
Decision.
Preparation.

This is the last mile working as intended.

A shared intelligence picture

Ceuta also shows why the boundary between cybersecurity and Corporate Security is becoming less useful as a boundary for intelligence.

Digital signals produced consequences for people, public services, transport and physical infrastructure.

Cybersecurity teams have developed capabilities that are valuable across this entire path: continuous collection, behavioural analysis, anomaly detection, threat hunting, correlation and structured escalation.

Corporate Security contributes the context required to translate those signals into physical consequence: exposed locations, employee presence, critical routes, local actors, operating dependencies and available protective measures.

These functions can retain distinct responsibilities while contributing to a shared intelligence picture.

For operators of critical infrastructure, the requirement is especially clear. Energy sites, ports, transport hubs, telecommunications facilities, hospitals and data centres depend on more than the integrity of their technical systems. They also depend on physical access, personnel, logistics and a functioning operating environment.

A digitally organised campaign can affect all four.

The National Court may establish whether warnings were received by units in Ceuta and how they were handled. The lasting lesson already reaches beyond that dispute.

Multilingual and cross-platform collection belongs in that shared picture, together with the ability to correlate external developments with an organisation’s own people, locations, suppliers and routes. Automated and agentic AI systems can assist with this correlation at scale; responsibility for interpretation and consequential decisions remains human.

The management question

Security performance cannot be measured only by whether a signal was collected or an alert was issued. It also depends on whether uncertainty was structured, ownership was clear and proportionate action remained possible.

Cybersecurity has spent years improving the speed of detection.

The next challenge is reducing the distance between detection and decision.

That distance is where emerging threats gain time.
It is also where security leadership proves its value.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.