Skip to content
Research & Analysis

Somalia Security Risk Assessment

In-depth review of the threat environment across Federal Somalia and Puntland, including clan dynamics, Al-Shabaab activity and coastal security.

Author
Mowlid Ali
Published
Q2 2026
Country / region
Somalia
Threat category
Armed conflict · Terrorism · Access risk
Reliability
Not separately rated
Confidence
See assessment limitations
Length
42 pages
Country RiskSomaliaPuntlandSomaliland
Listen · 3 minReady to play · about 3 min

Executive summary

Somalia remains a high-threat, access-constrained operating environment in which security risk is driven less by a single actor than by the interaction of insurgency, federal–state political friction and localised clan competition.

For organisations with staff on the ground, the dominant risk is not strategic defeat but operational disruption: movement restrictions, checkpoint exposure, contractor vetting failures and the compounding effect of short-notice programme suspension.

This assessment provides a practitioner's read of the environment in Mogadishu, Puntland and the federal member states, with mitigation measures written for security managers rather than analysts.

Sources · [12] INSO · [2] UCDP

Full report

Threat environment

The threat picture divides into three broadly distinct theatres. Mogadishu presents a mature urban insurgent threat characterised by VBIEDs, complex assaults on hardened targets, IEDs on approach routes and targeted killings of officials and perceived collaborators. Puntland presents a mixed picture of counter-ISIS operations, clan-based disputes over territory and revenue, and a maritime dimension along the Gulf of Aden coast. The federal member states of Jubaland, South West and Hirshabelle present rural insurgent control, contested supply corridors and highly localised access negotiation.

Across all three theatres, the practical determinant of safety is predictability. Routine, patterned movement is the vulnerability that hostile actors exploit most consistently.

Sources · [6] NASA FIRMS / Copernicus · [9] Mazin Intel analyst desk

Operational risk to international organisations

Duty of care exposure concentrates around four activities: airport transfers, inter-district movement, accommodation selection and field deployment outside secured perimeters. Each is manageable with rehearsed procedure and none is manageable with improvisation.

Programme continuity risk is dominated by access negotiation. Organisations that maintain relationships across federal, state and community levels retain access through political disruption; those that rely on a single channel lose access when that channel is contested.

Sources · [2] UCDP · [5] FEWS NET

Mitigation measures

Journey management with route variance, live tracking and a defined abort authority. Accommodation and office selection assessed against blast standoff, single-point-of-failure access and evacuation options. Local partner and contractor vetting conducted before contracting, not after an incident. Crisis management plans exercised at least twice annually with the actual on-call roster.

Sources · [5] FEWS NET · [8] Institute for Security Studies (ISS Africa)

Key findings

  • Al-Shabaab retains the intent and capability to conduct complex attacks against fortified compounds and hotels in Mogadishu, with VBIED and small-arms follow-on assault as the standing template.
  • Federal–member state disputes remain the single most reliable predictor of short-notice access loss, particularly around electoral milestones and revenue-sharing negotiations.
  • Puntland's counter-ISIS operations in the Cal Miskaad range have reduced the immediate threat to Bosaso but displaced risk onto coastal supply routes.
  • Contractor and landlord due diligence remains the most commonly skipped control among international organisations entering the market.
  • Coastal and maritime risk is rising again on the back of Red Sea instability, with a measurable increase in suspicious approaches off the northeastern seaboard.

Analyst assessment

We assess with high confidence that the operating environment through 2027 will remain viable for well-structured international operations, provided journey management, accommodation vetting and local partner due diligence are treated as controls rather than paperwork.

We assess with moderate confidence that Mogadishu attack tempo will remain broadly stable, with periodic surges tied to political milestones rather than a sustained escalation.

The most likely cause of a serious incident affecting an international organisation is not a targeted attack but proximity exposure, being adjacent to a target at the wrong moment, or moving without a rehearsed contingency.

Related reports

Footnotes & sources

  1. [1] ACLED: Armed Conflict Location & Event Data, Africa event recordsL1 Conflict · reliability A
  2. [2] UCDP: Uppsala Conflict Data Program, organised violence datasetL1 Conflict · reliability A
  3. [3] UN OCHA / ReliefWeb: Situation reports, access snapshots and humanitarian updatesL2 Early warning · reliability A
  4. [4] GDACS: Global Disaster Alert and Coordination System alertsL2 Early warning · reliability B
  5. [5] FEWS NET: Food security outlooks and alertsL2 Early warning · reliability A
  6. [6] NASA FIRMS / Copernicus: Active fire detections and open satellite imagery for corroborationL3 GEOINT · reliability B
  7. [7] GDELT Project: Global media event and tone monitoringL5 Strategic · reliability C
  8. [8] Institute for Security Studies (ISS Africa): Regional political and security analysisL5 Strategic · reliability B
  9. [9] Mazin Intel analyst desk: Practitioner interviews, field reporting and imagery verificationL6 Verification · reliability B
  10. [10] UKMTO: Maritime incident advisories, Gulf of Aden and Red Sea approachesL2 Early warning · reliability A
  11. [11] IOM DTM: Displacement Tracking Matrix, movement and displacement flowsL2 Early warning · reliability A
  12. [12] INSO: NGO safety incident reporting and access advisoriesL1 Conflict · reliability A
  13. [13] OpenSanctions: Sanctions, PEP and enforcement screening dataL5 Strategic · reliability A

Supporting capability statement

Horn of Africa security capability pack

Download the experience summary, applied risk frameworks and sample operational brief supporting this country threat assessment.

Independent research

Explore the research

Open-source analysis of security developments, operational risk and emerging threats across Africa, with a focus on Africa.

For shipowners, insurers and risk teams

Need a decision-ready briefing on this risk?

Country, port and voyage briefings with named sources, stated confidence and clear evidence limits.