Cole Tomas Allen had been a guest at the Washington Hilton for several days before he tried to kill the President of the United States. On the night of April 27, Allen opened fire inside the hotel hosting the White House Correspondents’ Association dinner. He has since been charged with the attempted assassination of Donald Trump. Guests inside the ballroom heard the shots, and the proximity of the alleged assassin to a secured venue raises fundamental questions about the integrity of the protection architecture in place that night.
This is the third time in under two years that the protective architecture around an American president has been tested and found short. Butler, Pennsylvania, July 2024: a bullet grazes Trump’s ear at a campaign rally. Sixty-four days later, a second would-be assassin is intercepted at his Florida golf course. Now a man who had checked into the venue hotel for days moved largely unimpeded before he was stopped, not at the entrance, but deep inside the building.
Three near misses and one worrying gap emerges: the outer layer did not hold.
A Recurring Vulnerability
The post-incident picture is instructive. Magnetometers were positioned at the ballroom entrance, not at the hotel perimeter, while entry to the building required only a ticket. Allen, having checked in days earlier, had ample time to assess the layout, identify the gaps, and move through the building before the event reached full security footing. According to his own writings, he had expected to encounter heavy surveillance. He found, in his own words, “nothing.”
Former Secret Service personnel quoted in the aftermath drew the same conclusion they drew after Butler: the protective perimeter needs to extend further out, even at the cost of public inconvenience. That tension sits at the heart of every protection failure in this sequence. In the professional security literature, it is described as the security-convenience continuum. Large, publicly announced, ticketed events, fixed in time and location and open to credentialled access at scale, sit at the exposed end of that continuum almost by definition.
The coordination picture presents a further area of concern. Multiple agencies held concurrent responsibility for protecting multiple principals within the same venue on the same night. The staggered and haphazard extraction of cabinet members points to an absence of unified command, with many individual protection teams defaulting to protecting their own principal rather than the collective security environment.
Large hotels compound all of this. Multiple entrances, public lobbies, extended guest lists, service access, and days of prior occupancy by unvetted guests. They are, in the professional risk assessment literature, classified as soft targets precisely because they cannot be fully controlled. The choice to hold a high-profile event in one is always a concession on the security-convenience continuum.
The failures at the Hilton are structural rather than incidental. Across all three incidents involving Trump since 2024, a consistent pattern is identifiable: insufficient outer ring integrity, incomplete advance work, and coordination deficits between agencies operating with overlapping mandates in complex, high-profile environments. These are not isolated operational shortfalls. They represent a recurring vulnerability in the protection architecture around the American president that has yet to be demonstrably resolved.
What changes in 47 days is the scale of the test. The 2026 FIFA World Cup opens across sixteen venues in the United States, Canada and Mexico, with an estimated 6.5 million attendees over 39 days. The protection architecture that has been stress-tested three times against a single principal will be required to perform across multiple simultaneous venues, hundreds of agencies across three sovereign jurisdictions, and the largest concentration of international visitors, including numerous heads of state and VVIPs, ever hosted on North American soil.
The structural weaknesses are unlikely to be ironed out by the time the largest sporting event in the world begins. Ahead of King Charles’s visit to the United States to meet President Trump, it was reported that elements within the UK’s security services had reservations about the protection environment they would be operating in, and that there were considerations to pull the plug on the visit.
The World Cup Security Challenge
FIFA President Gianni Infantino has described the 2026 tournament as the equivalent of hosting 80 major sporting events simultaneously. Forty-eight teams, sixteen stadiums across the United States, Canada and Mexico, fan festivals in each host city, and unofficial public gatherings extending the security perimeter well beyond any venue boundary. An estimated 6.5 million fans travelling between cities over 39 consecutive days. Stadiums ranging in capacity from 45,000 to just under 94,000. The security complexity is without direct precedent in international sport.
And the precedent is not encouraging. In June 2024, the United States hosted the Copa America final in Miami: a single match, in a single city, at a fraction of the World Cup’s scale. Thousands of ticketless fans breached the perimeter at Hard Rock Stadium, delaying the match by over an hour. Available intelligence flagged the developing situation more than an hour before it reached mainstream news coverage. The response, when it came, was reactive. For an event of the Copa America’s relative manageability, that represents a significant operational shortfall.
Where the Threat Picture Becomes Structural
The security weaknesses identified at the Washington Hilton are not specific to that venue or that event.
Coordination across jurisdictions. The FBI, FEMA, the Secret Service, and their Canadian and Mexican counterparts are required to function as an integrated system across three sovereign nations, hundreds of local and federal agencies, and sixteen venues operating in parallel. The financial commitment is substantial: FEMA has allocated over a billion dollars in federal funding, and Canada has committed more than $100 million to Toronto alone. Resource availability, however, is a necessary but not sufficient condition for effective coordination. The first high-level trilateral security meeting between the three governments took place in August 2025. For an operation of this complexity, that timeline represents limited lead time for genuine systems integration.
The drone threat. The primary agenda item at that trilateral meeting was counter-unmanned aircraft system capability. The focus is well-placed. Unmanned systems are low-cost, increasingly available, and capable of operating above and beyond conventional physical access controls. An open-air stadium at capacity presents a significant exposure to aerial threats that perimeter fencing and credential checks do not address.
Cyber vulnerabilities. The 2024 Paris Olympics recorded more than 140 cyberattacks over the course of the Games. The World Cup’s operational infrastructure, encompassing mobile ticketing, credential verification, stadium communications and transport coordination, runs on interconnected digital systems across three countries. A coordinated attack targeting entry management systems could generate crowd control failures at multiple venues without requiring any physical presence. This is a threat vector that sits largely outside the perimeter-focused security model and demands a parallel, dedicated response architecture.
The surrounding environment. Allen accessed the Washington Hilton as a registered guest several days before the event. The same dynamic applies at scale across World Cup host cities, where hundreds of thousands of fans will occupy hotels, public spaces and transit corridors immediately adjacent to match venues throughout the tournament. Security doctrine recognises large hotels and high-density public environments as inherently difficult to control. Hardening a stadium perimeter does not compensate for permeability in the surrounding environment.
The Gap Between Doctrine and Operational Reality
Executive protection doctrine establishes a clear framework: concentric rings of security hardened from the outside in, comprehensive advance work for every location a principal will occupy, and unified command ensuring that decision-making authority is concentrated rather than fragmented when an incident develops.
The pattern visible across the three incidents involving Trump since 2024 reflects a consistent departure from that framework. In each case, the emphasis was placed on the inner security ring: the immediate access point, the final checkpoint. In each case, the outer ring proved insufficient to prevent a threat from reaching proximity to the principal. The Hilton, Butler, and the Florida golf course share that structural characteristic.
At the scale of the World Cup, with sixteen venues, three jurisdictions, and tens of thousands of access points operating simultaneously, an operational model that prioritises inner ring hardening over outer ring integrity carries proportionally greater risk.
Executive Protection: What Good Looks Like
The failures visible across the three incidents involving Trump since 2024 are not difficult to diagnose. They become more instructive when measured against the standards that underpin professional executive protection good practice. What follows in the paid subscriber section is an operational baseline against which any protection program should be assessed…

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.