It has been 25 years since the devastating attacks of September 11 2001. Amid the reflection that followed emerged the most comprehensive examination of any terrorist attack in history, the 9/11 Commission Report. Several statements in this forensic diagnosis continue to shape our understanding of those events. These range from the intelligence systems that were “blinking red” in the months preceding the attacks to various institutional “failures of imagination” that left the threat unrecognised. Yet the commission’s investigation into the circumstances of the 9/11 terrorist attacks was also, fundamentally, a report on how to reimagine and improve security. The commission’s recommendations foreshadowed and legitimised a new model of security that emerged from the ashes of the twin towers, one centred on protecting critical infrastructure using and integrated security architecture.The 9/11 commission’s blueprint involved integrating agencies, systems and technologies. This principle took many forms. The integration of intelligence reporting is illustrated by UK’s Joint Terrorism Analysis Centre (JTAC). Technology became weaved into security activities. Important spaces were fortified using a “layered security” approach. Symbolic buildings, financial districts, city centres, stadiums, high-end shopping malls, and especially airports were the first to be upgraded. Passenger preclearance, biometric documents, full-body scanners, armed police patrols and the canopy of surveillance cameras became the building blocks of these contemporary fortresses. With each attack following 9/11, this template is reasserted. Whatever the threat, the answer is always more integration, more technology, more layers, more of the same.But after 25 years of building these new architectures of security and a vast expenditure of blood and treasure to fight the global war on terror, are we any safer? Academics and security experts are asking this question. The conclusion is generally that that a similar attack is improbable – though obviously nobody can say for sure. But we offer a very different analysis based on many years spent examining security systems up close.Our new book, The Empty Watchtower: Counterterrorism After 9/11 draws on two decades of empirical fieldwork. We experienced these developments and their legacies first hand. Across five distinct case studies, we saw expensive, poorly integrated and porous security systems that look the part but are prone to catastrophic failure.This journey led us into surveillance control rooms and secure sites to study the rollout of biometric security systems in airports, cities and major sporting events. We participated in counterterrorism training programmes in multiple countries and, more recently, conducted ethnographic research while embedded with specialist surveillance units in several European countries.Advanced surveillance?The immediate aftermath of 9/11 stimulated a clamour to do something, to bring certainty against uncertain and terrifying possibilities. International airports became another kind of frontier, a key testing ground for new surveillance systems. Technologists recommended fabulous new solutions for identifying hostile actors, all while keeping the flow of law-abiding passengers moving. But across all five of our recent case studies, we found security staff who did not understand the technical systems they operated, surveillance cameras pointed in the wrong direction – and declining morale. In one location, the crisis management control room – the centre of the fortress – was used for storage.Over the past decades, the security sector has placed huge emphasis on training staff to conduct behavioural detection – spotting signs of imminent threat through observation of body movement or facial expressions. We spent months in several European capital cities with covert surveillance teams observing the practice. In several jurisdictions, these teams carried out their missions to a high standard. But what was the standard? Thankfully, terrorism is rare (though less so in countries destabilised by the war on terror). This means that standards are hard to verify in terms of proving a negative; an absence of rare attacks.It also means that, in many countries, most indicators of a potential threat are rarely more than signs of stress, fatigue, or other maladies that often affect people in crowds. And so, advanced behavioural and technological systems focused on ordinary people as if they had something to hide. Worse, because of the discretion accorded to counterterrorism policing, and lack of oversight, the full power of the state was sometimes trained on vulnerable people who had broken no law. Worse still, many of these new post-9/11 policing techniques were improperly integrated with technology-based systems. At times, this convergence targeted entire communities, evident in the abandoned Project Champion in 2011, which involved hundreds of cameras being installed in mainly Muslim areas of Birmingham.Hidden vulnerabilities?Several countries where we studied counterterror policing, such as the UK and France, struggle with the number and diversity of individuals on their counterterrorism watchlists. Therefore, we cannot afford to rely on the intelligence services to unmask every terrorist network or foil every attack. Instead, we have become dangerously reliant on the security fortresses, composed of layers of technology and policing techniques. In our book we review several major attacks during the recent past, such as the Brussels airport attack in 2016. We show that successful terrorist attacks disrupt the points at which technology and human systems integrate – separating the layers of security and potentially leading to destabilisation and collapse.The intersection of these two domains – technology and organisational systems – has been crucial to both the success and failure of security practice. Yet shortcomings exist in each of these components. As our other work has shown, security technology is routinely overhyped, with benefits assumed and failures routinely overlooked. Abandoned experiments with facial recognition technology, unstaffed control rooms, and AI hallucinated “intelligence” all constitute real world examples that speak to an uncritical faith in technology. The most successful environments we encountered arose from the initiative, competence and motivation of specific individuals. Following another pattern set out in the 9/11 commission report, responses to terrorist attacks routinely call for more technology and better integration. Systemic failure and absent technology is easily diagnosed. But correcting them is harder, particularly when solutions call for embellishments of the same systems that were the problem in the first place.This article features references to books that have been included for editorial reasons, and may contain links to bookshop.org. If you click on one of the links and go on to buy something from bookshop.org The Conversation UK may earn a commission.The authors do not work for, consult, own shares in or receive funding from any company or organisation that would benefit from this article, and have disclosed no relevant affiliations beyond their academic appointment.