
The next materially distinct documentary angle is Shell’s own security-control failure. This is separate from the insider-collusion story already covered: the issue here is a 2011 internal review that reportedly judged SPDC’s security operations “seriously flawed”, citing deficient incident response, intelligence, security-force relationships, procurement due diligence and questions over payments. The contrast with Shell’s contemporaneous public commitments on security and human rights is particularly important.
THE SHELL NIGERIA FILES
Shell’s “Seriously Flawed” Security System: Intelligence Failures, Weak Due Diligence and Questions Over Payments
Shell has long said organised criminals overwhelmed its Niger Delta pipelines. A newly public internal review raises another question: how competent was Shell’s own security operation when the theft crisis was escalating?
Shell’s central explanation for much of the pollution in the Niger Delta is familiar.
Organised criminal gangs attacked pipelines.
They installed illegal taps.
They stole crude.
They supplied illegal refineries.
And Shell argues that this criminal activity caused the majority of the pollution now at issue in the Bille and Ogale litigation. (Shell)
The theft was real.
The sabotage was real.
The violence surrounding the trade was real.
But the newly disclosed documentary record introduces another part of the story that cannot be answered simply by pointing at the thieves.
According to Nigeria: Lifting the Lid, an internal 2011 review of SPDC’s security operations reached an extraordinarily severe conclusion.
It judged those operations to be:
“seriously flawed.”
The problems identified went well beyond an inability to stop determined criminals.
The review reportedly found poor responses to security incidents, ineffective management of relations with government security forces, inadequate development of staff skills and capability, weaknesses in intelligence gathering and assessment, deficient due diligence in security contracting and procurement, and “serious questions about inappropriate payments and effective cost control.”
That is not the description of an otherwise robust security organisation being defeated solely by an external criminal enemy.
It is evidence that Shell’s own security machinery was itself considered deficient.
And when a company relies so heavily on third-party criminality to explain environmental damage, the effectiveness of the systems it maintained to deter, detect and respond to that criminality becomes part of the accountability question.
The evidence comes from the court record
This point requires precise sourcing.
Unlike some of the numbered Shell documents directly downloadable from HEDA’s archive, the 2011 security-review findings are cited in Nigeria: Lifting the Lid through the Claimants’ Supplemental Skeleton for the Case Management Conference of 18 May 2026, paragraph 17.1.
The report records the findings in section 4.3, headed “‘Seriously Flawed’ Security Operations.”
HEDA states that the broader cache consists of internal Shell emails, audits, presentations and other records released from the English proceedings after campaigning organisations sought their publication in the public interest. (HEDA Resource Centre)
That distinction matters.
The quoted security findings are presented in the claimants’ court material and reproduced in the coalition report.
They have not been established as findings of fact by the trial judge.
Nor does the phrase “inappropriate payments” establish bribery.
It records that the review itself reportedly raised serious questions about payments and cost control.
Those questions require investigation and explanation.
They should not be converted into a criminal conclusion that the available evidence does not establish.
This was not merely a failure to catch thieves
Look carefully at the range of weaknesses identified.
A criminal gang defeating a patrol is one problem.
A security organisation that responds poorly to incidents is another.
A thief possessing good local intelligence is one problem.
A company having an unsatisfactory system for gathering and assessing its own intelligence is another.
Government security forces failing to stop theft is one problem.
A company ineffectively managing its relationship with those forces is another.
And dishonest contractors are one problem.
A procurement system that has not applied adequate due diligence when selecting and controlling contractors is another.
The 2011 review, as described in the court material, appears to have identified deficiencies across the security-management chain rather than one isolated operational weakness.
That matters because Shell knew it was operating in an exceptionally difficult security environment.
The harder the environment, the more rigorous the security architecture needed to be.
Shell was publicly saying something much more reassuring
The timing makes the internal review particularly significant.
In its 2011 Sustainability Report, Royal Dutch Shell said it supported the Voluntary Principles on Security and Human Rights, which govern how companies manage relationships with public and private security while respecting human rights.
Shell said that during 2011 it was continuing work to incorporate those principles into all its security contracts. (Shell)
The following year, Shell’s 2012 Sustainability Report went further.
It said the company had requirements designed to keep employees, contractors and facilities safe while respecting the rights and security of local communities; that security staff and contractors were trained in the Voluntary Principles; and that those principles were incorporated into security contracts. (Shell)
Those were broad Shell Group statements, not Nigeria-specific certifications that every SPDC contract and process was flawless.
That qualification is important.
But they create an obvious documentary tension with a contemporaneous Nigerian security review reportedly finding no proper due diligence in the contracting and procurement process.
The fair question is not whether Shell had security policies.
Clearly it did.
The question is whether those policies were being effectively implemented where the risks were greatest.
A policy in London or The Hague is not the same as a control in the Niger Delta
Major corporations frequently possess excellent written standards.
What matters operationally is implementation.
A security contract may contain human-rights clauses.
That tells us what the company expects.
It does not establish that the contractor was adequately vetted.
A procurement system may require due diligence.
That does not establish that due diligence occurred.
A corporate code may prohibit improper payments.
That does not explain why an internal review reportedly raised serious questions concerning payments and cost control.
The difference between policy and practice is precisely what internal audits and reviews are supposed to expose.
If the 2011 review accurately described SPDC’s position, the issue was not that Shell lacked sophisticated corporate standards.
It was that the system on the ground was failing important tests of those standards.
Shell depended heavily on Nigerian security forces
The finding concerning management of government security-force relationships is especially important because Shell itself repeatedly emphasised how dependent its operations were upon those forces.
At Royal Dutch Shell’s 2012 AGM, management described how severe crude theft had become and said SPDC had shut in production during part of 2011 because safety could not be assured.
Production resumed, Shell said, only after government security forces increased their presence and dismantled infrastructure installed by oil thieves. (Shell)
Shell’s 2012 Sustainability Report similarly said preventing theft depended on prompt action by government security agencies. It called for better security, evidence gathering and law enforcement, and for additional Nigerian government and security-force resources. (Shell)
That public account demonstrates just how critical Shell regarded the relationship.
Now put it beside the internal assessment.
The 2011 security review reportedly found ineffective management of relationships with security forces.
Those two facts belong together.
If government forces were indispensable to protecting Shell’s infrastructure, Shell’s ability to manage that relationship was not a peripheral administrative issue.
It sat at the heart of its anti-theft strategy.
Intelligence was another weak point
Oil theft on the scale Shell described was not casual opportunism.
Shell itself portrayed it as organised criminal enterprise.
Crude had to be stolen, transported, stored, refined or exported.
Illegal taps had to be installed.
Operations had to avoid or overcome surveillance.
Large networks required information.
An effective corporate security response therefore depended heavily upon intelligence.
Yet the 2011 review reportedly criticised SPDC’s approach to intelligence gathering and assessment.
That finding becomes still more significant in light of later internal documents.
By March 2013, Shell executives were warning internally that bunkerers appeared to have good access to SPDC planning data, while senior managers discussed allegations that staff and contractors might be involved in crude theft.
Those later insider concerns have been examined separately in this series.
The important point for the present article is chronological.
Before those 2013 fears emerged in the documents, Shell had already been warned that its security intelligence operation was inadequate.
That suggests a control problem existed before management confronted the possibility that sensitive information itself was leaking.
The procurement finding may be the most uncomfortable of all
Security in the Niger Delta involved contractors as well as Shell personnel and government agencies.
That makes the reported finding that proper due diligence was not being applied to contracting and procurement particularly serious.
Due diligence is how a company asks basic questions before giving an outside organisation access, money or authority.
Who owns the contractor?
Who controls it?
What conflicts exist?
What is its record?
Who are its employees?
Does it have connections to the activities it is being hired to prevent?
What are the payment arrangements?
Can expenditure be audited?
Those questions become exceptionally important where contractors may have access to sensitive facilities and operational information.
This article does not allege that Shell deliberately hired oil thieves.
The evidence does not establish that.
But if Shell’s own review concluded that proper due diligence was absent from the contracting and procurement process, it raises an obvious question about how Shell could confidently know whom it was entrusting with security-sensitive work.
Then there are the payments
The wording concerning payments must be handled carefully.
The 2011 review reportedly raised “serious questions about inappropriate payments and effective cost control.”
That is serious.
It is not synonymous with a finding of bribery.
“Inappropriate” could encompass a range of issues: insufficient authorisation, poor documentation, excessive expenditure, incorrect recipients, deficient controls or something more serious.
The public material presently available does not allow a responsible writer to select among those possibilities.
But neither should the phrase simply be ignored.
If an internal security review raises questions about payments in a high-risk contracting environment, a company committed to transparency should be able to explain what was meant and what happened next.
Were the payments investigated?
To whom had payments been made?
Were they legitimate?
Were control weaknesses corrected?
Were disciplinary measures taken?
Were external authorities informed?
Was a follow-up audit completed?
Those are factual questions.
Shell’s public response placed responsibility outside the company
Shell’s contemporaneous public communications understandably concentrated on the external threat.
Its 2012 Sustainability Report said crude theft had escalated dramatically, forcing production below capacity. It said there had been 137 spills attributed to sabotage and theft near SPDC facilities that year and described extensive environmental damage from illegal refining. (Shell)
In the same report, Shell stressed that preventing theft required greater action by Nigerian government security forces and international cooperation. (Shell)
Again, none of that was necessarily wrong.
What the newly public internal material changes is the completeness of the picture.
The company was not simply confronting inadequate state security and sophisticated criminals.
Its own review reportedly concluded that its security operation had serious internal deficiencies as well.
That is a fact shareholders and affected communities were entitled to understand.
The criminal environment does not absolve the control environment
There is a crucial distinction here.
A company cannot guarantee that criminals will never attack its assets.
It can, however, be expected to maintain competent systems appropriate to a known threat.
If theft is occasional and unpredictable, one level of security may be proportionate.
If theft is systematic, violent, organised and capable of causing catastrophic environmental harm, the required control environment is necessarily much more demanding.
Shell’s own public statements demonstrate that it understood the scale of the threat.
By 2012 it was describing the trade as international in dimension and calling for greater intelligence, evidence gathering and enforcement. (Shell)
Against that backdrop, an internal finding of weak intelligence, inadequate incident response and poor contracting due diligence becomes more significant, not less.
Shell says the report is misleading
Shell has rejected the overall portrayal advanced by the publishers of Nigeria: Lifting the Lid.
In its formal response dated 15 July 2026, reproduced in the report, Shell said the organisations had selectively quoted from documents in a way that created a misleading impression.
It stressed the difficult operating environment, including large-scale oil theft, sabotage and illegal refining by organised criminal gangs, and said its former Nigerian subsidiary worked with Nigerian authorities, its government-owned partner and communities in responding to the crisis. Shell also said the Bille and Ogale proceedings involve complex and contested issues that will be tested through the English court process.
Shell’s current case page likewise says SPDC invested heavily in surveillance, monitoring, repairs, shut-ins, spill response and engagement with government security forces as criminal interference increased. Shell says it will vigorously defend the claims at the factual trial in 2027. (Shell)
Those are substantive answers.
But they do not specifically explain the 2011 security review.
Investment is not the same as effectiveness
This distinction recurs throughout the Shell Nigeria documents.
A company may spend substantial sums and still operate ineffective systems.
Security spending does not prove security competence.
A surveillance contract does not prove the contractor was properly vetted.
An intelligence department does not prove intelligence was being assessed effectively.
A relationship with state security forces does not prove the relationship was managed competently.
And money spent does not answer concerns about inappropriate payments or cost control.
The internal review appears to have been examining outcomes and controls rather than the mere existence of expenditure.
That is precisely why Shell should disclose the review in full.
What changed after 2011?
Shell’s later reporting provides evidence that measures were expanded.
Its 2013 Sustainability Report described increased pipeline surveillance, additional repair teams and greater community collaboration as part of its response to crude theft. (Shell)
By 2015 Shell said SPDC had removed more than 850 illegal theft points since 2012, while continuing surveillance and deploying anti-theft protection on important equipment. (Shell)
More recently, Shell’s 2024 Annual Report described surveillance flights, drones, CCTV, strengthened anti-theft equipment and continuing work with government security agencies. (Shell)
That later history is relevant.
It suggests that security arrangements developed materially after the period covered by the 2011 review.
What it does not tell us is whether those changes were a response to the deficiencies identified internally, how quickly they occurred, or whether the specific problems over intelligence, contracting and payments were remedied.
That missing chronology matters.
Publish the 2011 review
Shell says documentary extracts require context.
There could hardly be a better case for supplying it.
Publish the full 2011 security review, subject only to genuinely necessary redactions protecting individuals and operational security.
State who commissioned it.
State who received it.
Identify its recommendations.
Explain what “inappropriate payments” referred to.
Publish the remediation plan.
Publish the follow-up audit.
Explain what changes were made to contractor due diligence.
Explain what changes were made to intelligence collection and assessment.
Explain how management of government security-force relationships was improved.
And establish when Shell considered the security operation no longer “seriously flawed.”
If the company corrected the problems rapidly and comprehensively, the records should demonstrate that.
If it did not, the public interest in disclosure becomes even stronger.
Security was part of environmental protection
It is tempting to put security management in a different compartment from environmental performance.
The Niger Delta makes that impossible.
If thieves breached a pipeline, pollution could follow.
If intelligence failed to identify a theft network, more breaches could follow.
If incident response was poor, damage could continue longer.
If inappropriate contractors gained sensitive information, prevention could be undermined.
If relations with government security forces were ineffective, illegal taps might remain in place.
In this operating environment, security controls were environmental controls.
A breakdown in one could become contamination in the other.
Shell cannot have the sabotage argument only one way
This is ultimately why the 2011 review matters.
Shell says third-party criminality is central to understanding pollution in Nigeria.
Fair enough.
Then the systems Shell maintained to deal with foreseeable third-party criminality are also central to understanding what happened.
A company cannot make sabotage the centrepiece of its defence while treating the competence of its anti-sabotage operation as peripheral.
If criminals caused the risk, security was one of Shell’s principal means of controlling that risk.
And according to the newly public court material, Shell’s own review found that system “seriously flawed.”
That does not transfer responsibility for criminal acts from thieves to Shell.
It raises a different question.
Did Shell manage a known and foreseeable criminal threat with the competence required of the operator of hazardous infrastructure?
The documents do not yet provide a complete answer.
They provide enough to make the question unavoidable.
And the references to deficient intelligence, absent contracting due diligence and questionable payments make this much more than another story about thieves with drills.
It is a story about the institution that was supposed to stop them.
Documentary record
The principal evidence for this instalment appears in section 4.3 of Nigeria: Lifting the Lid — Internal Documents Expose Shell’s Negligent Oil Operations. The report attributes the 2011 security-review findings to the Claimants’ Supplemental Skeleton for the Case Management Conference of 18 May 2026, paragraph 17.1. It records that SPDC’s security operations were considered “seriously flawed” and identifies weaknesses involving incident response, security-force relationships, capability, intelligence, contracting and procurement, payments and cost control.
HEDA Resource Centre hosts the public catalogue of Shell documents released through the English proceedings and explains that the material was made available following public-interest applications by campaigning organisations. (HEDA Resource Centre)
HEDA Resource Centre — Shell Documents Released in UK Legal Proceedings
Shell’s 2011 Sustainability Report said the company supported the Voluntary Principles on Security and Human Rights and was working to incorporate them into all security contracts. Its 2012 report said security staff and contractors were trained in those principles and described Shell’s dependence on government security agencies in tackling Nigerian oil theft. (Shell)
Shell’s present position is that organised theft, sabotage and illegal refining caused the majority of pollution relevant to the Bille and Ogale proceedings; that its former subsidiary invested extensively in surveillance, infrastructure protection, spill response and cooperation with Nigerian authorities; and that the allegations remain contested ahead of trial in 2027. (Shell)
Shell’s current account of the Bille and Ogale litigation
Editorial note
The phrase “seriously flawed” and the associated findings are reported from the claimants’ May 2026 court filing as reproduced in the coalition report. They have not yet been adjudicated as factual findings at the substantive trial.
The reference to “inappropriate payments” does not, on the material presently available, establish bribery, corruption or criminal conduct by any identified individual. It establishes that an internal review reportedly raised serious questions requiring explanation.
Shell disputes the publishers’ broader interpretation of the disclosed material and says the documents have been selectively quoted without sufficient regard to the exceptional level of organised crime and insecurity in the Niger Delta.
The factual and liability issues in the Bille and Ogale proceedings remain contested.
Site wide disclaimer also applies.
*This website and sisters royaldutchshellgroup.com, shellnazihistory.com, royaldutchshell.website, johndonovan.website, shellnews.net, and shellwikipedia.com, are owned by John Donovan - more information here. There is also a Wikipedia segment, the Shell DPA Files, "Shell and the Spies", the Shell Leaks files, as well as books written and published by John Donovan - Kindle eBooks. Timeline of the Donovan Shell Feud. Toxic History of Royal Dutch Shell Group. Shell and the Donovans: The Full Media Record — 550+ Articles, 110 Books, 40 Years. *All created and supported by internet wizz, Nick Gill.























