I feel as bad and outraged about the shooting at Marjory Stoneman Douglas school in Parkland, Florida as anyone – I truly do. And I understand the frustration of the students and parents and staff at this school and others across the country who want something – anything – done to prevent such incidents in the future. I have listened to and read the heated comments about this incident, the calls for banning guns and more “gun control” (whatever that means). But I am outraged as much about what I haven’t heard or read.
Because of what I do for a living, I have dissected and analyzed this incident (and most of the others like it) both frontwards and backwards. And what I rarely see (the shooting from Mandalay Bay Resort in Las Vegas being a notable exception) is any outrage directed toward the place where the shooting occurred…in other words, the lack of security which allowed such an event to happen.
Consider just these few issues related to Stoneman Douglas school:
· There was nothing or no one to identify, prevent, restrict or impede the armed shooter from being on the school grounds – no outdoor access control.
· There was nothing or no one to monitor, identify, screen, prevent, restrict or impede the armed shooter from getting into the school – no perimeter access control.
· There was nothing or no one to monitor, screen, prevent, restrict, impede or limit the armed shooter from roaming through the school once he got in – no interior access control or response plan.
· There was the questionable response from the school resource officer who failed to immediately enter the school to engage the shooter.
But of course the measures needed to remedy these shortcomings – which are unfortunately common at most schools across the country – require more resources, and nobody wants their taxes raised or additional fees imposed.
The point I am trying to make is that there is no single or simple fix to prevent these types of incidents. We need to expend resources to reasonably harden our schools and other “soft targets.” We need to assure that we have adequate plans in place to respond to these kinds of incidents because there is no such thing as perfect or absolute security and such situations will surely be attempted in the future. And perhaps most importantly we need to expend resources to identify and deal with the kinds of aberrant people and behaviors which commit these heinous acts.
What we don’t have to do is focus all the blame and attention on banning guns and creating more gun laws, because to do so ignores the real roots of the problem.
Monday, April 09, 2018
Wednesday, November 22, 2017
Security In Today’s World
We claim to be winning the war on terrorism; and we base
this claim on the fact that there have been relatively few significant
terrorist acts in the recent past.
(This does of course make a distinction between extremist/radical
terrorism and homegrown domestic violence/terrorism – although the lines are
becoming more and more blurred.)
But our sense of accomplishment and almost-victory is belied
by reality. The bad guys – whatever
their ilk – are in fact winning. To
make my point, consider the following:
·
Heavily armed law enforcement officials patrol downtown
areas and sporting venues and public buildings and transportation hubs and
election sites. The Super Bowl is
classified as a National Security Event.
·
The airplane experience has no resemblance to what it
used to be: removing shoes, physical
body searches, extensive baggage screening, waiting lines to enter plane areas
and board are now the norm.
·
The places we went to feel safe and to “get away from
it all” – the movie theatres and restaurants and resorts and public parks and
shopping malls are now the scenes of cruel and deadly attacks and murders. We now go armed to those places.
·
The places we went for comfort and solace and healing
and education – schools, churches, hospitals, day care centers, rehab
facilities – are now places where the bad guys know they can prey upon the
defenseless.
So with all these changes to the way we feel and the way we
must now live, can we really say that we are “winning” the war on terrorism?
I think there is some comfort and consolation in knowing
that bad events are still relatively infrequent. But I also think that we must never let our sense of comfort
overshadow our sense of realization that we still live in an unpredictable and
not-so-safe world.
Tuesday, January 03, 2017
Being An “Expert”
In the security profession
– or in any discipline really – being an “expert” or “expert witness” is
usually not a position to which one aspires at an early age. It often comes first as an ancillary
endeavor, then perhaps as a full-time profession. It usually comes mid-career, and often endures past career prime
and even past normal retirement time.
So how does one “become” an expert?
Is there a course or test that must be taken to “become” an expert? Here’s the reality:
One does not necessarily seek
recognition as an “expert;” and “expert” is not a connotation or designation
bestowed on oneself – it is status or standing in one’s profession as attested
to and recognized and conferred by others.
Therefore, there is – and really can be – no course of study or training
program or test that culminates with the title of “expert” since a true
“expert” does not become so until the expertise is recognized by others.
An “expert” is generally recognized for a composite of
professional education, training, experience, expertise, analytical skills,
writing skills, presentation skills, involvement in professional organizations,
involvement in professional activities as a volunteer, professional and
personal integrity, professional and personal credibility – and having a good
track record in all the aforementioned.
And in addition to these attributes, “experts” usually have some other
traits that are acknowledged by others:
He is the “go-to” guy within his organization; he is a “go-to” guy within one’s industry and/or among one’s
professional peers; he is actively
sought to help with resolving problems or improving operations or developing
strategies or developing policies and procedures – being sought to do for
others what they should/could be doing for themselves. He is regarded as the person who will almost
undoubtedly do the right thing or have the right answer at the right time.
So being the smartest man in the world by self-appointment –
even if true – does not make one an “expert” as the term is being used
here. Rather, it is the acknowledgement
by others that one is the right person to do a particular job that
distinguishes one as an “expert.”
Wednesday, June 29, 2016
Words To Live – Or Stay Living – By
In the world of security, as in many facets of life, an old adage is absolutely true: It is better to have it and not need it than to need it and not have it.
Thursday, January 28, 2016
The Concept Of “Reasonable Security”
Every organization has a legal obligation to provide a safe environment, based on the concept of “reasonable security.” The owner/landlord does not have to guarantee absolute security. However, reasonableness and adequacy of security must be affirmatively demonstrated. This basic concept is founded in most states’ case law (and, in some states, in statutory law). In today’s world, there is virtually no place that can claim that no security is adequate.
The implementation or existence of a
security program in and of itself does not guarantee that the program is
adequate and sufficient, since the standard by which a security program will be
judged is reasonableness with regard to foreseeable threats and risks at a specific
place.
“Reasonable security” has been consistently defined by
premises security case law to mean that appropriate security measures must be
implemented commensurate with risks which are reasonably foreseeable at a
specific place. And a reasonable consideration
of foreseeability has been determined to include the nature of the premises;
the history of incidents at the premises; the history of incidents in
geographic surroundings; and any
relevant industry standards.
Adequacy of security is legally
defensible only when vulnerabilities
and risks are assessed via some conscious or formalized process to determine
foreseeability, and commensurate security measures then implemented to reasonably address those
identified foreseeable risks (this is the usual standard by which adequacy and
sufficiency of security is determined by courts).
A good process for developing a sound security strategy has dual benefits: The program will be designed to protect the organization’s assets; and the program will be legally defensible should it be challenged in court.
Friday, June 12, 2015
SOMETIMES...
SOMETIMES...
good security means doing things that are not politically correct – you can’t always have it both ways;
doing the right thing is more important than following the rules or being politically correct;
the perception of good security is as good as or better than the reality;
there isn’t a good choice – sometimes you must choose between the best of the bad choices;
the end does justify the means;
it’s better to be judged by 12 than carried by 6;
popularity of an issue does not equate to fairness or justice;
a verdict has nothing to do with a good or bad prosecution strategy or a good or bad defense strategy –sometimes a verdict is based simply on facts and evidence;
“justice” fueled by public opinion and media and political pressure is not really justice;
“justice” is not what someone wants it to be – sometimes justice is simply what is;
the cutest puppy has the meanest growl and the sharpest teeth;
you get what you want, but sometimes you get what you deserve.
there is virtually nothing that is purely or simply black or
white.
Labels:
reasonable security,
security,
security expert
Wednesday, February 11, 2015
Value In “Dummy” Surveillance Cameras?
As both a former Director of Security and now an independent
security consultant, I have rarely been a proponent of using “dummy” cameras as
part of a security strategy.
Real cameras are used for several general purposes: To monitor areas/events in real time to
(hopefully) initiate appropriate response as needed; and/or to record
areas/events for investigative/documentation purposes; and/or to provide a
visible deterrent to inappropriate activities;
and/or to provide a heightened sense of security to the area’s
legitimate users.
With that being the case for real cameras, here are the
operational downsides of using “dummy” cameras: Obviously, there is no real-time monitoring of areas/events
possible, so appropriate response to problems is not possible (and it would be
cost-prohibitive – and economically foolish – to try to replace cameras with
personnel); and obviously, there is no recording of events for
investigative/documentation purposes (the chances of personnel being able to
provide comparable information are slim).
On the plus side, there might be a comparable visible deterrent to
inappropriate activity, especially if the cost savings of “dummy” cameras vs.
real cameras is used to provide additional “dummies.” But even that deterrent value might be negated if poor-quality
“dummy” cameras (an oxymoron?) are used which are easily identified as
“dummies” because of no lights or wiring connections. (NOTE: the only time I
have ever used “dummy” cameras was to add the impression of even more cameras
to an application of real cameras which already covered everything I wanted
covered.
But to me, the primary problem with the use of “dummy”
cameras is an unnecessary and thus unacceptable increase in liability.
The heightened sense of security for legitimate area users is totally
negated when it is learned that there is no real protection being afforded.
Legitimate users will feel betrayed and tricked when the truth is learned (and
it will be – someone will find out somehow). And the worse-case scenario will
be when an incident occurs and a victim questions and learns why there was no
ready response or at least visual documentation of the event. I have been involved in such cases as an
expert witness (this would most probably evolve as a premises security
liability lawsuit based on inadequate security) and have been able to opine
that the “dummy” cameras created a false sense of security that did not truly
exist, and this is actually worse than having no cameras of any kind: at least if there are no cameras present,
legitimate users will not have any expectations as to the level of security and
may thus be more aware of their own responsibility for personal security; where
on the contrary a legitimate user may be less aware of personal security issues
since he believes that he is being “helped” by real cameras.
Bottom line for me:
“Dummy” cameras have the potential to cause more problems than they
solve.
Thursday, November 13, 2014
“Predicting” Violent Behavior
We currently live in a society that is “an environment conducive to criminality:” virtually all aspects of the most popular forms of entertainment involve violence and anti-social behavior (movies, television, video games, etc.); the news media thrives on violence and anti-social behavior (count the number of such stories versus “good” or “nice” news); society by and large has come to accept violence and anti-social behavior (we abide such behaviors in our neighborhoods and schools, our criminal justice system is virtually an ineffective revolving door, etc.); and we expend resources to protect ourselves usually only after a tragic event has occurred. In other words, we may not like it, but we actually do – or can do – little about it.
We try to find reasons for violent behavior, and try to find
ways to “predict” it in hopes of preventing it. But is such a lofty goal even possible? Or does the concept of preventing problems exist only in theory,
not reality or practicality? Consider:
“Behavior modification” is a great term and concept –
provided that we have some idea as to whose behavior we are attempting to
modify. When the threat is external to
an organization, how can we begin to know which of the next 732 persons to
enter a facility is the one whose behavior needs modifying? How can we begin to know if the “behavior
modification” techniques that might work on 731 of those persons will work on
the 1 who will actually be the next shooter?
If none of those 732 go on a shooting rampage today, does that mean that
our “behavior modification” techniques were successful – or that none of them
simply chose today as the day to shoot?
Etc. etc. etc.
We see examples of our efforts to find a new way to predict
the next shooter every time another incident occurs (and by the way, nothing
PREDICTS behavior – certain behaviors may be indicated, but none can be
PREDICTED). But the reality is that
there is virtually nothing we can do because, even when some people see the
signs, nothing is done because “if you see something, say something” is not
socially acceptable, or is contrary to HIPAA (when the see-er is a mental or
medical health professional), or is something that “…I was going to do later…”
or whatever. Families, bosses,
co-workers, fellow classmates, etc. see things every day that are indicators of
potential violent behavior, but do nothing because it is simply not politically
correct or they’re busy or they did not realize what they were seeing or a
million other excuses.
After every new incident comes another discussion of the
same things, and the results are always the same – nothing gets changed,
because nothing can really be changed.
Because even when problems are indicated before they occur, we still
almost never do anything about them until after they have occurred.
Security professionals do not control organizational purse
strings or the magic key to the CEO’s psyche, so we cannot implement the things
which we know will pretty much stop the bad guys from doing most bad things
most of the time. And all of the
studies and nice terminology and fancy graphs will never change that fact. (And while agencies such as the U.S. Secret
Service do a great job of behavioral analysis, remember that they have an
entire division of professionals who do nothing but behavioral analysis and
have the resources to investigate and check out their findings and leads and
have to “only” protect a handful of key assets.)
So in the end, all
we as security professionals can really DO (as opposed to discussing theory and
hypothesis) is do the best we can with resources our bosses choose to expend –
that is, protect to the best of our abilities, with whatever resources we have
been allotted, whatever our bosses have decided are our key assets. Period.
Friday, October 03, 2014
Academic vs. Practical Security Knowledge
Regardless of the extent of knowledge acquired via formal education or academic pursuit, it is almost always most beneficial to retain a security consultant or expert witness who has practical, hands-on experience in the subject matter at hand.
When a particular situation or case needs someone to interpret or present information that is based solely on scientific or theoretical fact, an expert with only an educational or academic background might be most suitable. But in circumstances requiring expert OPINION – knowledge of specialized information and its application to a specific scenario – an expert with practical experience is most valuable. In such cases, an expert who has been personally involved in the application of the relevant subject matter to a variety of diverse situations will be best able to provide the comprehensive insight that is needed to best assist the organization or attorney because he has had to not only know the subject matter, but has had to apply that knowledge to the situational nuances of the real world (a skill not generally found in experts who only possess academic or theoretical knowledge).
The primary value that a security consultant or expert witness brings to an organizational situation or legal case is his ability to apply general security principles to a specific situation because he has been there and done that.
Monday, May 12, 2014
Business Size And The Need For Security
Regardless of the size and sophistication of a business –
from the sole proprietor of the neighborhood bar to the international
conglomerate – the concept of providing a reasonably safe premises remains the
same: namely, a business must provide
reasonable security commensurate with reasonably foreseeable threats and risks;
and reasonable foreseeability is generally determined by a conscious analysis
of the inherent nature of the business and the history of general criminal acts
at and around the business.
While large organizations may meet their obligation to
provide a safe environment via sophisticated security programs with designated
personnel and formalized policies and procedures, even small businesses must do
something proactively to meet their obligation – they must still take into
account the kinds of problems that they will likely encounter given their
particular situation (i.e., location, nature of business, clientele, prior
problems, etc.).
Many small businesses erroneously presume that their small
size will somehow either preclude problems or somehow absolve them of their
legal obligation to provide a safe environment. But statistics continue to show that small businesses – bars,
apartment buildings, retail stores, etc. – are the venues where criminal
activities are most likely to occur and consequently the kinds of places most
likely to be sued for inadequate security.
And the settlements and awards stemming from these lawsuits should give
business owners and operators cause for concern.
This information is important for 2
reasons: First, it is prudent for businesses to understand that proactive attention to security matters is
better and ultimately less expensive than after-the-fact litigation; and
businesses that may find themselves involved in premises security liability cases need to remember that the criteria by which security is
assessed will be the same regardless of the size of the business at which an
incident has occurred.
Sunday, March 09, 2014
The Paradox of “Soft Targets”
There is both an irony and conundrum related to active
shooter scenarios at soft targets: These types of places – and by the way,
“soft targets” refers not only to places that customarily have minimal or at
least non-aggressive security programs but also to places where the site’s
users customarily have some sense of it being a safe place (so even personal
security awareness is low) – almost “create” their desirability as targets
because they consciously choose (or, “make business decisions”) to maintain a
low security posture. And while these “reasons” are sometimes economic, that is
not always the full story: there still seems to be some prevalent thought among
proprietors of soft targets that the appearance of aggressive security somehow
conveys an impression of impending danger. And isn’t that ironic – some people
actually believe that more security equates to or implies greater danger. (I
may be wrong, but I never thought that banks were inherently dangerous because
they have armed guards!?!
No one deserves to
be a target for violence. But I tend to feel a bit less sorry for places at
which violence occurs when it is learned that those place consciously chose to
do little if anything to minimize or mitigate their vulnerability.
Tuesday, January 14, 2014
Can Security Programs Really Do More With Less
Can we almost always find ways to do a little more with a
little less? Certainly, as we have all experienced. But here’s the downside: The reality is that we really don’t do a
“little more” – we may do a “little more” in quantity, but actually do a
“little less” in quality. And every “little less” that we do results in
decreased service and increased liability (the old and true “you can pay me now
or pay me later” adage).
When we talk about “working smarter” or better utilizing
technology, we usually mean the replacement of people with machines and
systems. Automation is not a
significant part of this problem (smaller budgets for security), contrary to
what many “new school” practitioners and security product vendors would have
you believe. Surely automation can make security somewhat easier, but it
doesn’t necessarily make it better, because people will always be part of the
equation and people will always be a significant and costly and on-going budget
line item. Virtually all of the types
of services routinely provided by security personnel – preventive patrol,
evicting trespassers, opening doors, providing escorts, conducting
investigations, problem intervention, etc. – could not be accomplished without
people. Can technology help? Sure. But successful conclusions to security
incidents and problems rarely can occur without security personnel.
Other business operations don’t have the same problems as
Security: When sales are down, marketing and advertising costs go up; when
customer service complaints rise, personnel hiring costs go up; when floors get
too dirty and equipment breaks down, housekeeping and maintenance costs rise.
But even when security is at stake and problems and/or liability increase, the
budget for security gets cut.
The panacea is not all the latest technologies and bells and
whistles or even more operational security personnel. What we need is better
security executives who can credibly sell security service based on accurate
data collection and analysis, and who have the fortitude to strongly support
and defend their positions even when such may not be politically- or
career-correct (or wise).
Thursday, November 14, 2013
The Re-Branding of Security
There has been an effort over the past several years to
change the titles of persons who perform security functions within an
organization: I have seen such persons in various industries called “asset
protection specialists,” “loss prevention associates,” “protection officers,” “doormen,” “ushers,”
even “ambassadors.” But
regardless of a company’s job title nomenclature, these persons all perform, to
some degree, the function of
security: namely, protecting the assets
of that company. And the function is
more important than the title.
Perhaps companies believe that the word “security” has
somehow taken on a negative connotation, that the presence of “security”
somehow implies an admission that problems exist (the PR department’s
nightmare). But in reality – especially
in our post-9-11 world – the very concept of “security” should be embraced as a
comfort. So maybe the root problem is
that there is a misperception and misunderstanding of what “security” really
is.
I think that most people’s primary exposure to and
perception of what “security” is comes from the uniformed guards that they see
wherever they go (it’s getting to be the Holiday Season, so perhaps the armed
guards at the front door of Toys-R-Us will be back!). And because the guards in uniform look like police officers in
uniform – whose primary job (people think) is patrolling and responding to problems
– they equate the two types of personnel to that similar job function. But just as there is so much more to law
enforcement work than the visible patrol officer, so too is there much more to
“security” than observe and respond (which is amazingly ironic, since a good
percentage of security personnel are only supposed to observe-and-report as
opposed to observe-and-respond). And to
compound the confusion, since police officers are usually seen in the aftermath
of a crime that has already been committed, that ascription of similar function
makes people believe that “security = problems.” But those in our profession know that the opposite is really the
truth – that the foundation and raison d’etre of security is finding ways to
identify and prevent (or at least mitigate) problems before they occur. The underlying principle of security should
be to create a safe, inviting environment for all the persons who visit a
company and have dealings with it.
So for those companies that have tried to be politically
correct by re-branding the persons who try to keep them safe and to try to
convey the impression that problems do not exist, that is certainly your
choice. But I for one am comforted
whenever I visit a place that proudly announces that it has good and strong
“security.”
Wednesday, August 28, 2013
The Building Blocks Of Security
From the first tower of a toddler to the most sophisticated
building in the world, no structure can be put together properly without a firm
foundation of building blocks. And if
we equate the infrastructure of a business to a building and presume that part
of that infrastructure is a sound security program to make sure that the
business doesn’t collapse, the same holds true – we need a firm foundation of
building blocks.
Here are the building blocks that will result in a sound
security program:
·
If I need to protect my business and my stuff and my
liability, I need to know exactly what my business and my stuff and my
liability are.
·
If I need to protect my business and my stuff and my
liability, I need to know all of the potential problems and threats I might
encounter that might put them at risk.
·
If I’ve identified all my potential problems and
threats, I need to know how likely it is that each of those problems and
threats might occur so that I can prioritize them.
·
If I’ve determined the likelihood of occurrence of each
of my potential problems and threats, I need to know what the impact would be
to my business, stuff and liability if any of those potential problems or
threats occurred so that I can prioritize them.
·
If I’ve gathered all the information about my business
and stuff and liability and prioritized them,
and prioritized all the problems and threats that may occur, I need to
determine if a security plan is needed.
·
If I already have a plan to protect my business and
stuff and liability, I need to know if any safeguards I currently have in place
are adequate and sufficient.
·
If I don’t already have plan to protect my business and
stuff and liability, I need to develop one based on the information I’ve
gathered, and I need to implement the appropriate safeguards.
·
If I have a plan and safeguards to protect my business
and stuff and liability, I have to assess and adjust them regularly to assure
that they remain adequate and sufficient in relation to changing circumstances.
A firm foundation usually assures that what is on top of and
around it is strong.
Tuesday, July 16, 2013
What Is “Profiling” – And Is It Inherently Bad
From the never-ending hunt for terrorists to the George
Zimmerman/Trayvon Martin criminal case, the term “profiling” is much in
everyday news and media. But do we
fully understand the concept?
If memory serves me correctly, “profiling” was initially
intended to connote an unwarranted singling out of a particular group for
excessive or intense scrutiny. The term
was primarily focused on law enforcement practices, and was usually translated to mean the surveillance of persons of
color by white police officers for no particular or specific reason other than
the color of their skin. The term was
then expanded: “surveillance” was
expanded to include practices such as stopping, questioning, detaining, and
harassing; and “color of their skin” was expanded to include certain names,
ethnic groups, religious affiliations and neighborhoods. Used in that narrow and straightforward
context, “profiling” is not a good concept or effective law enforcement strategy.
HOWEVER: With the
advent of sophisticated data collection practices and tools,
information-gathering has become the norm rather than the exception, so the
“simple” concept of profiling is no longer so simple and straightforward. Now there are empirical ways to gather and
analyze data to single out and categorize specific groups for specific reasons
– the perpetrators of every type of crime or terrorist act can be specifically
identified and correlated to specific kinds of incidents. This categorization of individuals who are
undeniably linked to particular kinds of crimes and incidents creates groups
who need to be more intensely scrutinized than groups who have little if any
relationship to those crimes.
Hypothetical case in point:
I am the Security Manager for a store with a significant theft
problem. I have competently performed
my due diligence and gathered and analyzed information from 5 years worth of
theft statistics including surveillance video and apprehensions and
investigations and interviews, and the resulting empirical data shows that 95%
of my theft problems have been caused by well-dressed white women over the age
of 50. Is it not then good practice to
pay special surveillance attention to well-dressed white women over the age of
50 who come into my store? And if so,
then watching for those women is NOT “profiling” in the bad sense, it is good,
reasonable and appropriate security practice which I would be remiss to ignore. But have I singled out (“profiled”) a
particular group for enhanced observation?
Certainly.
Profiling is not inherently a bad practice. It is bad only when used in a haphazard,
uneducated, unsubstantiated manner. So
the intensified scrutiny of young Middle Eastern men by those concerned with
terrorism detection and prevention, or the focused scrutiny of an unrecognized
young black man by a neighborhood watch volunteer are not intrinsically bad
things.
Friday, June 28, 2013
Righting 4 Profeshunals
You can probably read and understand the title of this post,
but that doesn’t make it right…
I currently belong to a number of online professional forum
groups; and I’m active in the groups, so I see many posts from persons with lots
of letters after their names including those denoting professional
certifications and Masters Degrees and Doctorates. Yet I continue to be amazed at the quality of communication from
many persons who share their thoughts in these posts because, with all due respect, the quality of the
written words frequently is not commensurate with what I expect from
professionals. Spelling errors (which
can largely be avoided with Spell Check), grammatical usage errors, use of
incorrect words and terms (“then” for “than,” “there” for “their” or “they’re,”
etc.), poor (if any) punctuation, etc. etc. seem to be the norm rather than the
exception.
So why is this important, you ask? This is only going to be seen by others on the forum, you
say? Maybe!! But I have a hard time believing that the same people who cannot
write a coherent sentence to fellow practitioners and professionals take the
time and make the effort to do any better when they’re writing “official”
documents, reports and memos. And how
do we know that the very people who we should be trying to impress – like
bosses, clients, professional adversaries, etc. – aren’t also reading what we
write?
Habits are difficult to break, especially when it comes to
speaking and writing. If someone is
used to using colorful, vulgar language in everyday speech, sooner or later one
of those colorful terms is going to slip out at exactly the wrong moment – like
when having a conversation with a corporate executive or a client. If someone is used to writing careless and
sloppy postings on a forum (like texting “shorthand”), sooner or later that
same level and quality of writing is going to be used in a document being read
by a company president or local District Attorney or Judge. Based on some of the posts on these forums,
it’s sometimes difficult to get to and appreciate the content of a post because
of all the distractions from poor format.
And yes, I realize that many professionals have someone else to do their
formal writing. But professionals do – or should – proofread any work done on
their behalf, which is hard to do if the professional himself is lax in writing
skills (it’s hard to find errors when reading if you can’t write any better
yourself). And even those professionals
with assistants to do most of their writing occasionally write for themselves
(like in these forums) and the deficiencies become glaring.
And one other reason why this is important: Professionals are frequently judged on first
impressions, and first impressions are frequently made based on what we say or
on something we’ve written. If we
communicate well, our actions may not be scrutinized as closely because we will
be perceived as intelligent, knowledgeable people. But if we communicate
poorly, our actions – even the good ones – can be diminished because of what we
have said or written. The quality of
communication – either verbal or written – is just as important as the
content. And with the proliferation of
online forums where everything everyone writes is preserved for posterity, it
becomes a simple matter for anyone – like an opposing attorney – to dig up a
file full of posted faux pas in an attempt
to disparage professionalism and credibility (an avoidable problem, thus
inexcusable).
One of the best compliments I have ever received during my
tenure as a Director of Security was being told by a District Attorney that
the reports written by my security personnel were far superior to those written
by the local police. I have seen cases
lost because of poor communication (documentation). But in 30+ years, neither I nor my staff have ever lost a case
for that reason.
Meant as constructive criticism, and to generate thought…
Tuesday, April 23, 2013
Conducting Emergency Preparedness Drills
There is increasing awareness and understanding of the need
for adequate and proper planning for emergencies. Preparedness for any type of emergency (natural or man-made,
accidental or deliberate, criminal or terrorist) really requires not only the
development of an appropriate strategy and plan with commensurate policies and
procedures, but 2 additional, separate but equally important activities: a desktop exercise, and a live/physical
drill.
The desktop exercise will be of significantly longer
duration than the live drill (because activities will be discussed
consecutively rather than occurring concurrently) and should include all
stakeholders, all of whom should participate in all aspects of the
exercise. The agenda should include
verbalization and visualization (maps, charts, etc.) of all steps that would be
taken during each phase of an actual emergency. Key decision-makers and responders for each phase should take the
lead in the discussions, but the discussions should also include immediate
analysis, feedback and critique from all participants to assure that as many
nuances and potential problems as possible are brought to light (the different
perspectives from persons usually not directly involved in a particular aspect
can be very helpful and insightful).
To be effective and a true learning and preparedness
experience, a live/physical drill must include everyone that would normally be
involved at the time of a live incident (and that includes random types of
non-employees who would normally be present at the scheduled time of the drill)
and should be conducted in real time – some organizations erroneously believe that
only certain employees need to participate in an emergency drill and those only
need to slowly act out or verbalize their motions during the drill. But such is not productive, since it is
important to learn/know what the scope of chaos and extent of time will be
during an actual event, both of which are critical for successful mitigation of
a real emergency.
As in any facet of real life, theoretical knowledge is
important; but actual hands-on participation is a key component of assuring
that emergency plans are truly workable.
Wednesday, March 20, 2013
What Is “Success” In Security?
There is one unequivocal certainty in the world of security: There is no such thing as absolute security (defined as some strategy or system that will fully protect everything against everything all the time) – given sufficient resources, motivation and opportunity, any/every security strategy and system can eventually be breached.
So…since we know that even the best security may be
breached, how do we measure success?
For purposes of this commentary, we have to re-define some
terms that are usually pretty straightforward – “success” and “failure.”
Let’s begin with “failure.”
In the world of security, we can have occasional “failures”
(independent, isolated incidents in which the security plan was not fully
effective), without having “FAILURE” (a complete and continuing collapse of
protection due to an ineffective security strategy).
The same holds true for “success.” We can have recurring “successes” (times during which protection
efforts are adequate and sufficient to meet extant security needs), even while
realizing that we can never achieve “SUCCESS” (the continuous state of
everything being adequately and sufficiently protected against everything).
When trying to assess whether security has been a “success”
or a “failure” based on these definitions, we must also add another component
to the mix: "legal defensibility" (a security strategy that includes the elements
that a reasonable person would utilize to provide reasonable security at a
particular place and time under a given set of circumstances). The addition of this concept raises another
interesting conundrum: Even when
security efforts are occasionally “successful,” they may not be "legally
defensible" (because the security strategy may not withstand legal scrutiny when
an incident occurs).
So back to the original question: What is success in
security? The answer is really not
that difficult: Success in security is
the existence of a strategy which protects most things most of the time; and
which will endure legal/forensic analysis during challenges which result from
short-lived “failures.”
As always we should hope for the best, but we must plan for the worst.
Monday, February 18, 2013
Challenges To Effective Security
Here are some facts that I have found to be unequivocally
true during my 30+ years of providing security service and counsel to a wide
variety of organizations:
We ARE a reactive culture.
For a variety of reasons, primarily economic, we do not do the things
proactively that would make us less attractive targets; and we naively believe
that “it can’t happen to me.”
There ARE bad people in this world, bad for a variety of
reasons, who do bad things; and many of those bad people are not recognized
preemptively because we again naively believe in the inherent goodness of all
people and tend to and want to overlook anything that deviates from that rosy
perspective.
There is NO SUCH THING as absolute security – nothing can be
done to assure that nothing bad ever happens.
The best that can be achieved is security that protects from most bad
things most of the time – and even that level requires continuous attention.
People intent on doing bad things WILL find a way to achieve
their objective – they WILL find the resources and opportunity to perpetrate
bad things, regardless of what stumbling blocks – i.e., good security – are
imposed.
Those are the downsides; here are the upsides:
Even being reactive is BETTER than ignoring security
problems completely and continuously.
IF we stop always trying to be politically correct and IF we
make informed, judicious, prudent use of tools like “profiling” we WILL be more
able to proactively identify more bad people.
And after my lengthy experience in this business, I totally despise the currently-in-vogue
concept of “profiling” – if empirical data suggests that 95% of my problems
are caused by xxx people, then watching for xxx people is NOT profiling, it is
good, reasonable security practice which I would be remiss to ignore.
IF we harden targets appropriately, having adequate and
sufficient security will not stop all bad things from happening, but it WILL
stop most of the worst things most of the time.
Even bad persons usually hope to achieve 2 things: accomplishment of their bad deeds, and concluding the accomplishment of their bad deeds in the way they desire (usually either anonymous escape, or suicide). Good security WILL reduce the“environment conducive to criminality” at a given place so that the bad person might choose to do his bad things elsewhere.
A whole other facet of this issue may divert into a
discussion of who is best able to provide security guidance and assistance to
the places that most need it. Once
again – as usually is the case – economics dictates to many organizations that
security planning assistance comes from a little- or no-cost resource, which is
frequently the local law enforcement agency.
But with all due respect to my law enforcement colleagues who provide
heroic and loyal service on a daily basis,
they are usually not the best source of advice on security matters, if
for no other reason than that is not their primary job focus.
Better security can be achieved anywhere…but it comes at a
cost and requires a commitment.
Thursday, January 10, 2013
Sandy Hook Tragedy - Response, Part II
The tragedy at Sandy Hook Elementary School seems to have
offended our sensibilities more than other such tragedies because of the ages
of the victims. But in reality, this
tragedy was not significantly different or worse than other such events –
innocent lives should never be lost at the hands of a crazed or deranged
person. The term “gun violence” is
always a prominent part of stories about these events, and the anti-gunners
capitalize on that fact to put their emphasis on the wrong word: the crux of the problem is violence, not
guns.
While not the warm and fuzzy, politically correct
philosophical ideal, it is nonetheless an absolute fact that it is simply and
literally impossible to identify all the people who will do bad things and/or
to accurately predict what bad things they will do and/or when and where they
will do them. Period.
Since bad things will undoubtedly happen regardless of our
wishes, intentions and preventive efforts (because there is no such thing as
absolute security, meaning some system/strategy that will protect against any
conceivable or possible threat at all times), it behooves us to have the best
mitigation, response and recovery strategies in place to protect everything
important (meaning people, physical things and information).
Security must be considered at least as important and
necessary as our attitudes and endeavors related to fire, which we have
embraced and incorporated wholeheartedly:
While it is nice to idealize that people and things won’t burn and hope
that “…it can’t happen here,” yet we
still design and implement (and pay for) reasonable and sometimes mandated fire
protection precautions into our buildings; and install fire control systems and
have fire response equipment in our buildings; and have regular fire system
inspections; and have extensive fire plans that are reviewed and updated
regularly; and have regular fire drills; and have internal personnel properly
trained to deal with fires; and have Fire Departments to come and put out fires
when they occur; and have plans to maintain and/or resume operations after a
fire event. Why is the same not so for security?
Why are places with adequate and sufficient fire control
systems and procedures not considered “fire traps,” but places with adequate
security systems and procedures are considered “armed fortresses?” When I walk
into a building and see sprinklers on the ceiling and fire extinguishers at key
places and evacuation route maps and “No Smoking” signs on the walls and a fire
truck parked outside, I get a feeling of comfort – the thought never crosses my
mind that this building must pose some grave fire danger. Why do we not put commensurate emphasis on
security? Why do we not see alarm
systems and CCTV cameras and monitors and uniformed – perhaps armed – security
personnel as an indication of concern for our safety and security?
Logic and consistency do not seem to be traits held in
esteem by anti-gun proponents, because in virtually no other situation do they
condemn the tool used in a bad consequence as the cause or culprit: When a porch pulls away and falls from a
house killing/injuring partygoers, the hammer is not blamed. When a pedestrian is killed by a drunk
driver, the car is not blamed. When an
editorial or cartoon is written that enflames and angers the masses, the
typewriter/computer is not blamed Only
when it comes to guns is the tool rather than the actor condemned.
We learned (or should have learned) from Benghazi that
diplomatic and bureaucratic and philosophic options are meaningless at the time
of an attack, because without proper response capability good people die. When my family is being threatened with
grave harm and I am not present to intervene, I do not want a philosopher or
psychologist or social worker or a book of social ills analysis there – I want
“…rough men (who) stand ready in the night to visit violence on those who would
do us harm.”
Subscribe to:
Posts (Atom)
