In capability development, the focus often falls on technology, equipment and visible solutions. Yet real capability is usually determined by the systems, people and structures that sit behind them.
Drawing on years of experience supporting governments and security institutions across the Middle East, Africa and beyond, Stuart McHutchon, Deputy Director for National Security and Resilience at TAG, advocates what he describes as the “Toyota Corolla approach” to capability building: prioritising practical, sustainable and maintainable solutions over impressive but ultimately unsustainable ones. In this article, he explores why enduring capability is built through the often unglamorous foundations that allow organisations to function long after the advisers, contractors and project funding have departed.
Why real capability is rarely the thing on the trade-stand banner — and why the unglamorous version is the only one that lasts
Counter-UAS is the latest in a long line of shiny defence capabilities to capture the attention of national security stakeholders around the world. The feeds are full of new systems, bristling with antennas and promise. Across government, attention is fixed firmly on the sector, and that is understandable. Drones have changed the threat picture: cheaply, rudely, and at scale.
The instinctive response is to reach for kit. If the other side has drones, then surely we need counter-drones. But in TAG’s experience there is far more to capability than what fits on a banner. A sensor might detect a drone. The hard question is what happens next. Who has the authority to act? Who owns the risk? Who pays for the debris? Who coordinates the response — and which of the nine ministries involved gets to say no?
None of that is a kit problem, and none of it can be bought from a catalogue.
The gadget reflex
This is not unique to counter-UAS. We have watched the same pattern repeat across years of capacity-building work, in sector after sector.
In cybersecurity, the natural response is licensed software, a better SOC, another dashboard — even while the server room is being used to keep the milk cool. In digital forensics, the request is for data-exploitation tools, even where there is no agreed legal framework to take a case to court. The device works perfectly. The capability still does not exist.
Call it the gadget reflex: the very human preference for solving a systemic problem with something that can be held in the hand or pointed to in a showroom. It is attractive precisely because it is concrete. A piece of equipment is visible, countable, and photogenic. A functioning chain of authority is none of those things.
TAG has consistently found the opposite to be true. The task is not to start with the gadget. It is to build the thing that makes the gadget useful.
The same mistake in two costumes
The development sector has largely learned the first half of this lesson. Gifting equipment has fallen out of fashion, and most opportunities are now rightly resistant to it — donors have seen too many warehouses of unused, unmaintained, unsustainable kit. But the reflex rarely disappears. It simply migrates. When you can no longer give equipment, the path of least resistance is to give training instead.
Training is different, and often better. But on its own it can be just as hollow, because it is the same mistake wearing different clothes. Both gifted kit and training-only programmes are single-line interventions: each invests in the one thing a donor can deliver unilaterally, then quietly assumes the rest of the system will assemble itself.
The UK Ministry of Defence codified the alternative years ago, in the Defence Lines of Development, TEPID OIL: Training, Equipment, Personnel, Information, Doctrine, Organisation, Infrastructure and Logistics, with Interoperability ocaisonally thrown in for good measure. It is the insistence that capability is a system of interdependent lines, and that equipment is only one of them. Real capability emerges when all of them are present and matched. Pull any single line out, no maintainers, no legal basis, no agreed owner, and the whole thing fails to start, or starts to fail, however good the kit or the training.
That is the lens through which TAG approaches a problem, and it resolves into two questions. One is structural: what is the minimum architecture that can actually do the job? The other is temporal: what will still be standing once the project, the supplier and the visit are gone? They sound like two ideas. They are really one principle, read along two different axes.
The structural axis: the Toyota Corolla
I sometimes call the structural answer the Toyota Corolla solution. Not the most glamorous answer, nor the most sophisticated, but the thing that actually works, can be maintained, and fits the road it has to drive on.
The metaphor does more than say “cheaper.” A Corolla works because its engine, gearbox and brakes are matched to one another, because there is a mechanic in town, and because it runs on a fuel you can actually buy. Capability behaves the same way. It is capped not by its strongest component but by its weakest line, the binding constraint. A SOC with no power and no analysts is not strong cyber capability with one weak spot; it is no capability, waiting for a weak spot to be fixed. Forensic tools with no prosecution framework do not produce convictions. Nine ministries with no agreed command arrangements do not produce a shot-down drone.
Which means a balanced minimum almost always beats an unbalanced maximum. A Ferrari on a dirt road, with no spare parts and no one trained to service it, is not more capability than a Corolla, it is less, because it stops the day the contractor flies home. The discipline is to find the line that is actually binding, which is rarely the one on the shopping list. When stakeholders in Iraq open early discussions on counter-UAS, the list arrives quickly enough. Radar here. RF detection there. Invoice attached. The harder and more valuable work is identifying the constraint the partner has not priced, and very often it is not made of metal.
There is a useful term for the ceiling here: absorptive capacity. An institution can metabolise capability only as fast as its structures allow. Push kit or courses past that rate and you are not building faster, you are generating waste with a ribbon on it. The Corolla is, by definition, the architecture matched to what the partner can absorb.
The temporal axis: institutionalisation
Now ask the same question across time, and you arrive at institutionalisation — the creation of genuine local ownership that endures beyond any single project, supplier or visit.
The honest test of institutionalisation is not a signed doctrine or a graduated cohort. It is a host-nation budget line. A capability the partner will not pay to keep running has not been institutionalised; it has merely been borrowed, and the lender will eventually want it back. Everything that matters follows from that test: doctrine written locally rather than translated; a train-the-trainer pipeline so the capability reproduces itself without outside help; maintenance the host can perform with parts it can source; an owner who survives the next reshuffle and the next change of supplier.
Notice where all of that lives. Not in Equipment, but in Organisation, Doctrine, Personnel, Infrastructure and Logistics — the unglamorous lines, the ones nobody puts on a banner. Endurance is built almost entirely from the parts of TEPID OIL that never make the brochure.
Why the two axes are really one
The bridge between them runs in a single direction: only the Corolla can be institutionalised. The Ferrari cannot be nationally owned, because the partner cannot afford it, cannot maintain it, and cannot doctrinally absorb it. So the minimum-coherent architecture is not just the thing that works today — it is the precondition for anything that works tomorrow. Choosing the Corolla is choosing institutionalisation in advance.
This is also where Interoperability earns its place as the binding line, because it cuts two ways. Interoperability internally — across those nine Iraqi ministries — is the actual prize. It is what turns a sensor feed into a decision, and a decision into an authorised act. Interoperability with coalition partners is the seductive version, and it is precisely how dependency creeps in. The risk is visible in Lebanon: a force can become so interoperable with Western systems and mentors that it can no longer operate without them. The sequencing matters. Build national interoperability first and coalition interoperability second. Reverse the order and you optimise for a capability that only works while the mentors are in the room.
The uncomfortable part
It would be comfortable to treat the gadget reflex as a partner-side failing. It is not. It is structural on the donor side too, and arguably worse there.
Kit and courses produce exactly what funding systems are built to reward: photogenic, countable, in-year outputs. Handover ceremonies. Graduation numbers. Spend delivered against budget before the financial year closes. Institutionalisation produces almost none of that. It is slow, it is largely invisible, it is led by someone other than the donor, and there is no ribbon to cut at the end. The Corolla approach is harder to fund for the very same reason it is more likely to endure.
Put plainly: the donor can give equipment, and the donor can give training, but only the partner can build a capability — and our incentives too often reward the giving over the building.
What we actually do
This is why TAG works the way it does. We start not with the catalogue but with the constraint: which line of development is actually binding, and what is the minimum coherent architecture that resolves it. Then we build the unglamorous foundations that hold a capability together — clear ownership, information-sharing that reaches the person with authority, a legal basis to act, command-and-control that holds under pressure, and a training pipeline that produces not just operators but maintainers and decision-makers.
None of that comes from a catalogue. It takes discussion, collaborative development, working groups, mentoring, compromise and time. We call it a whole-of-capability approach, and equipment is on the list — as one line among eight or more. Kit is usually the easiest part. That is exactly why everyone wants to start there, and exactly why we don’t.