On the morning of September 11, 2001, I was the head of the Criminal Division at the Department of Justice. There was no Department of Homeland Security then. If there was a terrorist attack on American soil, it was the Justice Department’s problem. I was in the car on the way to work, on the phone with my deputy, when he told me a plane had hit the World Trade Center. Like most people, I assumed a small aircraft and a confused pilot. Then he told me a second plane had hit, and it was clear we were under attack.
I walked over to the FBI building, to the Strategic Information and Operations Center, where Bob Mueller already was. The Pentagon was struck while I was on my way. We followed the fourth aircraft, and I heard the order relayed to shoot it down if it reached Washington. It was a day or two before I learned that no fighter had brought it down. The passengers had.
What I remember most sharply is not the attacks themselves. It is the days that followed. A transponder signal from a fifth aircraft suggested another hijacking; it was an error. There was a report of taxis carrying bombs in their trunks. During a video conference with the State Department an alarm sounded and I braced for another bombing. That too was false.
We now describe September 11 as one day of attacks followed by a period in which further attacks were prevented. That was neither obvious nor inevitable at the time. Everyone making decisions that week was doing so without the benefit of hindsight, inside an event whose shape and end were unknown. What did we learn from September 11 that bears relevance today?
Preparedness planning
At DHS after the 9/11 attacks, we framed preparedness planning around a core set of operational planning scenarios, and British banking regulators now require similar planning and testing around “severe but plausible” scenarios. Ukraine’s pre-invasion migration of workloads to the cloud was critical to its ability to weather a torrent of Russian cyber attacks. The current geopolitical climate underscores the importance of reframing resiliency planning around how to keep an organization afloat if its core systems are compromised. Have we maintained offline back-ups and tested recovery? Can we reconstitute a way to communicate with essential employees? Do we know how to ensure that certain important but low-risk payments can continue?
A crisis can strike any time. The morning of September 11, Bob Mueller had been on the job as FBI Director for a week. One of the first things I did after being confirmed DHS Secretary was to visit the Department’s Operations Center. Executives need to familiarize themselves with crisis management protocols quickly after taking on new roles, and exercises are also a great way to build muscle memory.
Emergency action protocols
On the morning of September 11, commercial airplanes were turned into weapons. At 9:42, in an improvised command, the FAA Command Center’s national operations manager ordered all FAA facilities to instruct all aircraft to land at the nearest airport, and about 4,500 commercial and general aviation aircraft soon landed without incident. Over time, protocols were developed to coordinate short-notice civilian and military response to aircraft takeovers. The FAA’s Domestic Events Network (DEN) now facilitates sharing of operational information in real time between Departments and Agencies across the Federal Government, and airlines, to ensure shared situational awareness and support coordinated action. New technologies such as Artificial Intelligence (AI) frontier models offer tremendous potential for good, but we also know they can be weaponized, either on purpose or by accident. We need to consider how emergency action concepts can be applied in novel situations.
Minimum viable organization
While United #93 was never able to reach the White House or the U.S. Capitol thanks to the heroic efforts of passengers on that plane, continuity of government contingency plans were activated that morning. Agencies are now required to define “primary mission essential functions,” which are those functions that need to be continuous or resumed within 12 hours after an event and maintained for up to 30 days or until normal operations can be resumed. The President’s Council of Advisors on Science and Technology recommended in 2024 that critical infrastructure organizations define minimum viable delivery objectives for critical functions or services that could operate even in the face of adversity. While business impact analysis is a standard feature across larger organizations, far fewer organizations have actually engaged in resiliency planning for sustaining minimal viable operations notwithstanding a compromise.
Can we resort to manual operations? We can learn from what happened to Maersk in the 2017 notPetya incident, where the company came within a hair’s breadth of permanently losing its IT system to destructive malware later attributed to Russia.
Delegation of authority
Crisis planning sometimes implicitly assumes that relevant leadership will be immediately available. On the morning of September 11, the President was delivering education remarks in Florida, and the Attorney General was en route to Minnesota to deliver a speech. Organizations need to ensure that executives are deputized and trained to make key decisions if principals are unavailable.
Resilient communications
Crisis management protocols sometimes also implicitly assume a continued ability to use regular communications channels. When 7 World Trade Center (WTC) collapsed, the collapse destroyed a Consolidated Edison electrical substation and breached the Verizon central office building, causing damage to equipment and the flooding of basement power systems. While most of the nation’s telecommunications proved resilient in the face of these attacks, the collapse (plus related fires and flooding) took out most telecommunications service in Lower Manhattan. New York City’s Office of Emergency Management (EOM) headquarters was also located at 7 WTC. In today’s world of cyber threats, we know that primary communications systems frequently become untrusted. We also know that Chinese state actors have sought to pre-position on U.S. networks for disruptive cyberattacks in the event of a conflict with the United States. Crisis management protocols thus need to contemplate out-of-band or redundant communications.
Identity
The 9/11 Commission spent a good deal of its time in the review of the events leading to 9/11 addressing the question of vulnerability and weakness in our identity security systems, the ease with which people could fabricate identities and use it as a way to live amongst us without being detected by the authorities or use it as a way to get on airplanes without being intercepted as somebody on a watch list. But identity is also at the heart of a number of other very significant elements of our social fabric.
At DHS, we worked to introduce choice into the identity ecosystem – facilitation benefits for citizens who voluntarily shared additional background information eventually became programs like Global Entry and TSA Precheck. The entirety of our economic livelihood in the 21st Century is going to turn in large measure upon our ability to verify identity for those who want to transact business online. Leading frontier AI labs are preconditioning access to their most advanced models on identity assurance – for example OpenAI’s Trusted Access program and Anthropic’s Cyber Verification Program. We need to ensure these systems remain resilient to deepfakes, fraud and AI-enabled cyber threats.
Information Sharing
Active relationships with law enforcement and security agencies can help make timely decisions possible in a crisis, and they cannot be created during one. Know your local field office and your sector information sharing organization now. Because crises are increasingly hybrid, carrying physical and cyber elements at once, those relationships need to span both.
It is expected that commercial entities hold proprietary information closely for competitive reasons, but security information often benefits everyone in the community with a need to know. Industry associations, the Information Sharing and Analysis Centers (ISACs), and other industry led groups are critical to developing joint approaches to emerging security threats. These groups exist for almost every sector of the economy.
Unity of Effort
In the days after 9/11, Bob Mueller and I would brief the House and Senate on investigative developments, and they were as one. There was no difference between Republicans and Democrats. For a generation of people in our country born after 9/11, these events are a history lesson not a living memory. It’s critical to understand that when you are living in the event, there is no certainty that it’s going to come out okay. This country has weathered some very big crises but there is no predetermined outcome. It’s what we make it, and we’ve all got to be willing to step up and play a role, cooperatively, to protect ourselves and our loved ones.
Michael Chertoff is co-founder and executive chairman of The Chertoff Group. He served as the second U.S. Secretary of Homeland Security from 2005-2009.




