We Stole a Horse

We Stole a Horse

(With the owner’s permission)

 

At Sloane Risk Group, we have extensive experience in Protective Security Testing, also known as Physical Penetration Testing. Our work typically involves testing whether we can gain unauthorised access to a corporate building, reach a server room, identify or access critical assets, enter a private residence, or expose weaknesses in the procedures designed to prevent us from doing so.

Recently, however, a client gave us a rather different objective:

Steal a horse.

The exercise wasn’t about proving that we could steal a horse. It was about answering a much more important question:

Would the security measures in place actually detect, delay or prevent someone who genuinely intended to?

And, if they didn’t, what would happen next?

Starting with almost nothing

Our assessment began in much the same way as many of our corporate protective security tests: with very limited information.

In this case, all we were given was the horse’s show name.

From publicly available competition results, we were able to begin identifying connections between the horse, its rider, owner and grooms. Professional photographs from equestrian events provided further imagery and context.

From there, social media provided additional pieces of the puzzle. Individually, much of this information appeared fairly innocuous. Collectively, however, it allowed us to build a much clearer intelligence picture.

We were able to identify information relating to the rider’s equestrian activities, associates, routines, vehicles and other locations connected with their life, and crucially details of the yard where the horse was kept.

This is an important lesson in itself.

People rarely deliberately publish everything someone would need to target them. Instead, information is accumulated from multiple sources and pieced together.

A horse’s name. A competition result. A photograph. A tagged location. A vehicle. A familiar face.

Each fragment adds context.

From online research to physical reconnaissance

The first stage of our reconnaissance was conducted entirely online.

Once we had developed sufficient information, two members of our team were deployed to conduct physical reconnaissance of the yard.

The premises were in a rural location with a clearly defined perimeter. However, like many working equestrian environments, it was also a large and active site, with legitimate movement of people, horses, vehicles, staff, visitors and suppliers.

This presents an interesting security challenge.

A completely closed environment is relatively easy to control. A functioning equestrian yard is different. Vets, farriers, instructors, owners, riders, grooms, contractors, deliveries and visitors may all have legitimate reasons to be present.

The challenge therefore isn’t simply keeping people out.

It is recognising when someone shouldn’t be there.

Our reconnaissance suggested that unauthorised access might be achievable without immediately attracting attention.

We subsequently tested that assumption.

For obvious reasons, we won’t explain the method used to enter the yard or provide details that could assist someone attempting to replicate the exercise.

However, with the support of a suitably qualified and experienced member of our team, we were able to access the horse, safely load it into our horsebox and leave the premises.

The test didn’t end when the horse left

In many ways, this was the most important part of the exercise.

However, preventing an incident is only one element of security.

We also wanted to understand:

How quickly would someone realise something was wrong?

How long would it take to establish that the horse was actually missing?

Who would be informed first?

How quickly would the owner be contacted?

Who would take control of the incident?

Would CCTV or access information be reviewed?

What information would be available immediately?

Who would contact the police?

And, crucially, would people know what decisions to make during those first critical minutes?

These questions allowed us to assess not only the physical security of the yard, but its detection and response capability.

Because a security system that records an incident but doesn’t result in an effective response hasn’t necessarily prevented anything.

The vulnerabilities weren’t purely physical

One of the most useful findings from the exercise was that the route to the horse did not begin at the perimeter of the yard.

It began with information.

The assessment demonstrated how different areas of security can intersect:

Digital — publicly available information helped build the initial intelligence picture.

Physical — the yard itself presented opportunities that could be assessed and tested.

Personnel — a busy environment depends heavily on staff recognising unusual behaviour and being confident enough to challenge it.

Procedural — once an incident occurs, the speed and quality of the response can significantly influence the outcome.

This is why we approach equestrian security as more than locks, gates, alarms and CCTV.

A determined adversary looks for the easiest route to their objective. That route may be physical, digital or human, and frequently involves a combination of all three.

Turning the test into better security

The objective of protective security testing is never simply to demonstrate that something can be defeated.

The value comes from what happens afterwards.

Following the exercise, we worked with the yard to address the vulnerabilities identified.

This included providing security awareness training to staff, recommending proportionate improvements to security equipment and developing emergency response procedures covering a range of incidents that could realistically affect the yard.

Importantly, the answer wasn’t to turn a working equestrian environment into a fortress.

Good security should be proportionate to the threat, practical for the people who have to use it and appropriate for the environment it is protecting.

The aim was therefore to make the yard a harder target, improve the likelihood of suspicious activity being recognised and ensure that, if something did happen, everyone understood what to do next.

From assumed security to proven resilience

It is easy to look at gates, cameras, alarms and procedures and conclude that a property is secure.

But the presence of security measures tells us very little about whether they will actually work against someone deliberately trying to circumvent them.

That principle applies whether we are assessing a corporate headquarters, a private residence, a critical asset, or a valuable horse.

Sometimes the only way to understand the vulnerability is to look at the environment through the eyes of the person trying to exploit it.

And sometimes the only way to know whether your security works is to test it.

Security shouldn’t simply look effective. It should be tested.

You might also like to read

Public Profile, Public Exposure: Why Threat, Risk and Vulnerability Assessments Matter in Politics

Politicians and public figures face a threat landscape that has never been more complex – physical attacks, hostile surveillance, cyber intrusion, disinformation, and foreign influence activity are all part of the picture. Yet the most dangerous vulnerability is rarely a gap in technology. It is the assumption that “it won’t happen to me.” Here is what genuine protective security actually looks like – and why waiting for an incident to occur is always too late.

Interview with Hayley Elvins

Security Risk Management consultant and Non-Executive Director Hayley Elvins shares how she stays physically capable and mentally sharp under pressure. In this interview, she discusses running a counter-espionage consultancy, her training routine, and why STAIT has become part of her daily approach to health, recovery, and performance.

This website uses cookies. This data helps us provide the best experience for you, keeps your account secure, helps us provide social media features and allows us to personalise advert and service message content. Please select 'Accept all' to consent to us collecting your data in this way.

Shield