On August 14, 2026, Luigi Mangione stood in a federal courtroom in Manhattan and described, in his own words, exactly how he planned and carried out the killing of UnitedHealthcare CEO Brian Thompson. He talked about building part of the weapon on a 3D printer. He talked about posing as an investor managing more than $50 billion in assets to obtain details about the investor conference Thompson was scheduled to attend. He talked about traveling to New York with the singular intent to shoot him.
He pleaded without a plea agreement. What he gave the court was a sworn, on-the-record narration of a complete targeting cycle, from initial intent through reconnaissance to execution. That is a rare document in this profession. We almost never get to read an attacker's own account of his planning, under oath, in his own words.
Read it closely and one fact stands out more than any other: Mangione had no prior contact with UnitedHealthcare. No correspondence with Thompson. No history with the company, no grievance filed against it, nothing that tied him specifically to the man he killed. He was not a known quantity to anyone until the moment he acted.
That fact should unsettle the corporate security industry more than it has.
The model we've built is designed to catch known unknowns
Protective intelligence, as most organizations practice it, runs on a specific premise: threats announce themselves before they arrive. Somebody sends a hostile email. Somebody shows up at a facility uninvited. Somebody posts something alarming that a monitoring service flags. The program's job is to catch that signal early, assess it, and act before it escalates.
That model works. It has stopped real attacks. But it works against a specific kind of actor: one who generates behavioral indicators before the event. A known unknown. Someone who is, in some sense, already on the board, even if nobody has connected the dots yet.
Mangione was not that. He was a zero-history, single-event actor who built his own weapon, approached through a legitimate business channel, and gave the organization no data points to assess until the day he executed his plan. Run his profile against any protective intelligence program built on prior contact, escalation patterns, or correspondence history, and it returns nothing. Not because the program failed. Because the program was never built to catch this category of actor in the first place.
Say that plainly and it sounds like you're arguing yourself out of a sale. You're not. It's more accurate to say the product solves one problem well and a different problem not at all.
Protective intelligence and threat assessment are essential, they catch real threats other controls miss, and no serious program should run without them. What's worth pushing back on is a specific claim that shows up constantly in this industry's self-promotion, which is the people watching for signals are the sophisticated ones, and the guys in suits standing next to the principal are theater.
Sometimes the signals get missed. Sometimes, like here, there are no signals to catch. Either way, someone still has to be standing there. The honest position isn't PI instead of physical protection. It's both, because each one covers what the other misses.
If you can't predict him, deny him the pattern
Here's the part that matters more than the diagnosis. This isn't an argument that protection is futile against an unknown actor. It's an argument that the control shifts from prediction to denial.
You cannot put a zero-history actor on a watchlist before he acts. What you can do is deny him the thing every targeted attack of this kind actually depends on, which is a predictable pattern to exploit.
But this case demands an honest distinction, because it's one the industry routinely blurs.
Thompson's conference was publicly announced. The email posing as an investor didn't discover the event, it confirmed and refined the details around it, and that points to something a lot of protection advice gets wrong. For a principal whose calendar is public by necessity, you cannot hide the appearance. A CEO hosting an investor day is going to be at a known building on a known morning, and no amount of schedule discipline changes that.
What remains controllable is everything around the fixed point. Thompson was killed walking alone on a public sidewalk, approaching the venue, hours before he was scheduled to speak. The event was fixed. The movement to it was not, and that movement is where the entire exposure lived.
In practice, that looks like:
- Predictability reduction where it's still available. When the destination and time are public, the route, the approach, the vehicle, the drop point, and the entry used are the variables you still own. The fixed point on the calendar doesn't mean the path to it has to be guessable.
- Coverage during transitions, not just at the destination. Most targeted violence against a principal happens in the movement, getting out of a car, crossing a sidewalk, walking into a building, not inside a secured space. A publicized event is precisely the moment that transition should be covered, because the attacker already knows where to be.
- Discipline around what gets confirmed externally. Investor relations, scheduling assistants, and front-of-house staff can all be used to gather intelligence if they'll fill in operational detail for an unverified inquiry. A public event announcement is not the same as a public itinerary, and the gap between the two is a policy and training problem, not a hardware problem.
None of that requires knowing an attacker exists. All of it reduces what any attacker, known or unknown, has to work with.
The harder sell, and the truer one
"We catch bad guys before they act" is the easier pitch. It's also not fully true, and Mangione's own allocution is now public proof of exactly the kind of actor it doesn't catch.
The truer pitch is less dramatic: a protective program's value isn't that it sees every threat coming. It's that it denies the attacker, seen or unseen, the exploitable pattern he needs, and that it puts trained coverage on the principal at the moments when the pattern can't be denied at all.
That's a harder sell than "we see it coming before it happens." It's also the one that survives contact with a case where nothing was there to see.