Tuesday, January 14, 2014

Can Security Programs Really Do More With Less


Can we almost always find ways to do a little more with a little less? Certainly, as we have all experienced.  But here’s the downside: The reality is that we really don’t do a “little more” – we may do a “little more” in quantity, but actually do a “little less” in quality. And every “little less” that we do results in decreased service and increased liability (the old and true “you can pay me now or pay me later” adage).
 
When we talk about “working smarter” or better utilizing technology, we usually mean the replacement of people with machines and systems.  Automation is not a significant part of this problem (smaller budgets for security), contrary to what many “new school” practitioners and security product vendors would have you believe. Surely automation can make security somewhat easier, but it doesn’t necessarily make it better, because people will always be part of the equation and people will always be a significant and costly and on-going budget line item.  Virtually all of the types of services routinely provided by security personnel – preventive patrol, evicting trespassers, opening doors, providing escorts, conducting investigations, problem intervention, etc. – could not be accomplished without people. Can technology help? Sure. But successful conclusions to security incidents and problems rarely can occur without security personnel.
 
Other business operations don’t have the same problems as Security: When sales are down, marketing and advertising costs go up; when customer service complaints rise, personnel hiring costs go up; when floors get too dirty and equipment breaks down, housekeeping and maintenance costs rise. But even when security is at stake and problems and/or liability increase, the budget for security gets cut.
 
The panacea is not all the latest technologies and bells and whistles or even more operational security personnel. What we need is better security executives who can credibly sell security service based on accurate data collection and analysis, and who have the fortitude to strongly support and defend their positions even when such may not be politically- or career-correct (or wise).

Thursday, November 14, 2013

The Re-Branding of Security


There has been an effort over the past several years to change the titles of persons who perform security functions within an organization: I have seen such persons in various industries called “asset protection specialists,” “loss prevention associates,”  “protection officers,” “doormen,”  “ushers,”  even “ambassadors.”  But regardless of a company’s job title nomenclature, these persons all perform, to some degree,  the function of security:  namely, protecting the assets of that company.  And the function is more important than the title.
 
Perhaps companies believe that the word “security” has somehow taken on a negative connotation, that the presence of “security” somehow implies an admission that problems exist (the PR department’s nightmare).  But in reality – especially in our post-9-11 world – the very concept of “security” should be embraced as a comfort.  So maybe the root problem is that there is a misperception and misunderstanding of what “security” really is.
 
 
I think that most people’s primary exposure to and perception of what “security” is comes from the uniformed guards that they see wherever they go (it’s getting to be the Holiday Season, so perhaps the armed guards at the front door of Toys-R-Us will be back!).  And because the guards in uniform look like police officers in uniform – whose primary job (people think) is patrolling and responding to problems – they equate the two types of personnel to that similar job function.  But just as there is so much more to law enforcement work than the visible patrol officer, so too is there much more to “security” than observe and respond (which is amazingly ironic, since a good percentage of security personnel are only supposed to observe-and-report as opposed to observe-and-respond).  And to compound the confusion, since police officers are usually seen in the aftermath of a crime that has already been committed, that ascription of similar function makes people believe that “security = problems.”  But those in our profession know that the opposite is really the truth – that the foundation and raison d’etre of security is finding ways to identify and prevent (or at least mitigate) problems before they occur.  The underlying principle of security should be to create a safe, inviting environment for all the persons who visit a company and have dealings with it.
 
So for those companies that have tried to be politically correct by re-branding the persons who try to keep them safe and to try to convey the impression that problems do not exist, that is certainly your choice.  But I for one am comforted whenever I visit a place that proudly announces that it has good and strong “security.”
 
 

Wednesday, August 28, 2013

The Building Blocks Of Security


From the first tower of a toddler to the most sophisticated building in the world, no structure can be put together properly without a firm foundation of building blocks.  And if we equate the infrastructure of a business to a building and presume that part of that infrastructure is a sound security program to make sure that the business doesn’t collapse, the same holds true – we need a firm foundation of building blocks.
 
Here are the building blocks that will result in a sound security program:

·         If I need to protect my business and my stuff and my liability, I need to know exactly what my business and my stuff and my liability are.

·         If I need to protect my business and my stuff and my liability, I need to know all of the potential problems and threats I might encounter that might put them at risk.

·         If I’ve identified all my potential problems and threats, I need to know how likely it is that each of those problems and threats might occur so that I can prioritize them.
·         If I’ve determined the likelihood of occurrence of each of my potential problems and threats, I need to know what the impact would be to my business, stuff and liability if any of those potential problems or threats occurred so that I can prioritize them.

·         If I’ve gathered all the information about my business and stuff and liability and prioritized them,  and prioritized all the problems and threats that may occur, I need to determine if a security plan is needed. 

·         If I already have a plan to protect my business and stuff and liability, I need to know if any safeguards I currently have in place are adequate and sufficient.

·         If I don’t already have plan to protect my business and stuff and liability, I need to develop one based on the information I’ve gathered, and I need to implement the appropriate safeguards.

·         If I have a plan and safeguards to protect my business and stuff and liability, I have to assess and adjust them regularly to assure that they remain adequate and sufficient in relation to changing circumstances.

A firm foundation usually assures that what is on top of and around it is strong.

Tuesday, July 16, 2013

What Is “Profiling” – And Is It Inherently Bad


From the never-ending hunt for terrorists to the George Zimmerman/Trayvon Martin criminal case, the term “profiling” is much in everyday news and media.  But do we fully understand the concept?
 
If memory serves me correctly, “profiling” was initially intended to connote an unwarranted singling out of a particular group for excessive or intense scrutiny.  The term was primarily focused on law enforcement practices,  and was usually translated to mean the surveillance of persons of color by white police officers for no particular or specific reason other than the color of their skin.  The term was then expanded:  “surveillance” was expanded to include practices such as stopping, questioning, detaining, and harassing; and “color of their skin” was expanded to include certain names, ethnic groups, religious affiliations and neighborhoods.  Used in that narrow and straightforward context, “profiling” is not a good concept or effective law enforcement strategy. 
 
HOWEVER:  With the advent of sophisticated data collection practices and tools, information-gathering has become the norm rather than the exception, so the “simple” concept of profiling is no longer so simple and straightforward.  Now there are empirical ways to gather and analyze data to single out and categorize specific groups for specific reasons – the perpetrators of every type of crime or terrorist act can be specifically identified and correlated to specific kinds of incidents.  This categorization of individuals who are undeniably linked to particular kinds of crimes and incidents creates groups who need to be more intensely scrutinized than groups who have little if any relationship to those crimes. 
 
Hypothetical case in point:  I am the Security Manager for a store with a significant theft problem.  I have competently performed my due diligence and gathered and analyzed information from 5 years worth of theft statistics including surveillance video and apprehensions and investigations and interviews, and the resulting empirical data shows that 95% of my theft problems have been caused by well-dressed white women over the age of 50.  Is it not then good practice to pay special surveillance attention to well-dressed white women over the age of 50 who come into my store?  And if so, then watching for those women is NOT “profiling” in the bad sense, it is good, reasonable and appropriate security practice which I would be remiss to ignore.  But have I singled out (“profiled”) a particular group for enhanced observation?  Certainly. 
 
Profiling is not inherently a bad practice.  It is bad only when used in a haphazard, uneducated, unsubstantiated manner.  So the intensified scrutiny of young Middle Eastern men by those concerned with terrorism detection and prevention, or the focused scrutiny of an unrecognized young black man by a neighborhood watch volunteer are not intrinsically bad things.

Friday, June 28, 2013

Righting 4 Profeshunals


You can probably read and understand the title of this post, but that doesn’t make it right…
 
I currently belong to a number of online professional forum groups; and I’m active in the groups, so I see many posts from persons with lots of letters after their names including those denoting professional certifications and Masters Degrees and Doctorates.  Yet I continue to be amazed at the quality of communication from many persons who share their thoughts in these posts because,  with all due respect, the quality of the written words frequently is not commensurate with what I expect from professionals.  Spelling errors (which can largely be avoided with Spell Check), grammatical usage errors, use of incorrect words and terms (“then” for “than,” “there” for “their” or “they’re,” etc.), poor (if any) punctuation, etc. etc. seem to be the norm rather than the exception.
 
So why is this important, you ask?  This is only going to be seen by others on the forum, you say?  Maybe!!   But I have a hard time believing that the same people who cannot write a coherent sentence to fellow practitioners and professionals take the time and make the effort to do any better when they’re writing “official” documents, reports and memos.  And how do we know that the very people who we should be trying to impress – like bosses, clients, professional adversaries, etc. – aren’t also reading what we write?
 
Habits are difficult to break, especially when it comes to speaking and writing.  If someone is used to using colorful, vulgar language in everyday speech, sooner or later one of those colorful terms is going to slip out at exactly the wrong moment – like when having a conversation with a corporate executive or a client.  If someone is used to writing careless and sloppy postings on a forum (like texting “shorthand”), sooner or later that same level and quality of writing is going to be used in a document being read by a company president or local District Attorney or Judge.  Based on some of the posts on these forums, it’s sometimes difficult to get to and appreciate the content of a post because of all the distractions from poor format.  And yes, I realize that many professionals have someone else to do their formal writing. But professionals do – or should – proofread any work done on their behalf, which is hard to do if the professional himself is lax in writing skills (it’s hard to find errors when reading if you can’t write any better yourself).  And even those professionals with assistants to do most of their writing occasionally write for themselves (like in these forums) and the deficiencies become glaring.
 
And one other reason why this is important:  Professionals are frequently judged on first impressions, and first impressions are frequently made based on what we say or on something we’ve written.   If we communicate well, our actions may not be scrutinized as closely because we will be perceived as intelligent, knowledgeable people. But if we communicate poorly, our actions – even the good ones – can be diminished because of what we have said or written.  The quality of communication – either verbal or written – is just as important as the content.  And with the proliferation of online forums where everything everyone writes is preserved for posterity, it becomes a simple matter for anyone – like an opposing attorney – to dig up a file full of posted faux pas in an attempt  to disparage professionalism and credibility (an avoidable problem, thus inexcusable).
 
One of the best compliments I have ever received during my tenure as a Director of Security was being told by a District Attorney that the reports written by my security personnel were far superior to those written by the local police.  I have seen cases lost because of poor communication (documentation).  But in 30+ years, neither I nor my staff have ever lost a case for that reason.
 
Meant as constructive criticism, and to generate thought…

Tuesday, April 23, 2013

Conducting Emergency Preparedness Drills


There is increasing awareness and understanding of the need for adequate and proper planning for emergencies.  Preparedness for any type of emergency (natural or man-made, accidental or deliberate, criminal or terrorist) really requires not only the development of an appropriate strategy and plan with commensurate policies and procedures, but 2 additional, separate but equally important activities:  a desktop exercise, and a live/physical drill.
 
The desktop exercise will be of significantly longer duration than the live drill (because activities will be discussed consecutively rather than occurring concurrently) and should include all stakeholders, all of whom should participate in all aspects of the exercise.  The agenda should include verbalization and visualization (maps, charts, etc.) of all steps that would be taken during each phase of an actual emergency.  Key decision-makers and responders for each phase should take the lead in the discussions, but the discussions should also include immediate analysis, feedback and critique from all participants to assure that as many nuances and potential problems as possible are brought to light (the different perspectives from persons usually not directly involved in a particular aspect can be very helpful and insightful).
 
To be effective and a true learning and preparedness experience, a live/physical drill must include everyone that would normally be involved at the time of a live incident (and that includes random types of non-employees who would normally be present at the scheduled time of the drill) and should be conducted in real time – some organizations erroneously believe that only certain employees need to participate in an emergency drill and those only need to slowly act out or verbalize their motions during the drill.  But such is not productive, since it is important to learn/know what the scope of chaos and extent of time will be during an actual event, both of which are critical for successful mitigation of a real emergency.
 
As in any facet of real life, theoretical knowledge is important; but actual hands-on participation is a key component of assuring that emergency plans are truly workable.

Wednesday, March 20, 2013

What Is “Success” In Security?


There is one unequivocal certainty in the world of security:  There is no such thing as absolute security (defined as some strategy or system that will fully protect everything against everything all the time) – given sufficient resources, motivation and opportunity, any/every security strategy and system can eventually be breached.
 
So…since we know that even the best security may be breached, how do we measure success?
 
For purposes of this commentary, we have to re-define some terms that are usually pretty straightforward – “success” and “failure.”
 
Let’s begin with “failure.”  In the world of security, we can have occasional “failures” (independent, isolated incidents in which the security plan was not fully effective), without having “FAILURE” (a complete and continuing collapse of protection due to an ineffective security strategy). 
 
The same holds true for “success.”  We can have recurring “successes” (times during which protection efforts are adequate and sufficient to meet extant security needs), even while realizing that we can never achieve “SUCCESS” (the continuous state of everything being adequately and sufficiently protected against everything).
 
When trying to assess whether security has been a “success” or a “failure” based on these definitions, we must also add another component to the mix: "legal defensibility" (a security strategy that includes the elements that a reasonable person would utilize to provide reasonable security at a particular place and time under a given set of circumstances).  The addition of this concept raises another interesting conundrum:  Even when security efforts are occasionally “successful,” they may not be "legally defensible" (because the security strategy may not withstand legal scrutiny when an incident occurs).  
 
So back to the original question: What is success in security?   The answer is really not that difficult:  Success in security is the existence of a strategy which protects most things most of the time; and which will endure legal/forensic analysis during challenges which result from short-lived “failures.”
 
As always we should hope for the best, but we must plan for the worst.

Monday, February 18, 2013

Challenges To Effective Security


Here are some facts that I have found to be unequivocally true during my 30+ years of providing security service and counsel to a wide variety of organizations:
 
We ARE a reactive culture.  For a variety of reasons, primarily economic, we do not do the things proactively that would make us less attractive targets; and we naively believe that “it can’t happen to me.”
 
There ARE bad people in this world, bad for a variety of reasons, who do bad things; and many of those bad people are not recognized preemptively because we again naively believe in the inherent goodness of all people and tend to and want to overlook anything that deviates from that rosy perspective.
 
There is NO SUCH THING as absolute security – nothing can be done to assure that nothing bad ever happens.  The best that can be achieved is security that protects from most bad things most of the time – and even that level requires continuous attention.
 
People intent on doing bad things WILL find a way to achieve their objective – they WILL find the resources and opportunity to perpetrate bad things, regardless of what stumbling blocks – i.e., good security – are imposed.
 
Those are the downsides; here are the upsides:
 
Even being reactive is BETTER than ignoring security problems completely and continuously.
 
IF we stop always trying to be politically correct and IF we make informed, judicious, prudent use of tools like “profiling” we WILL be more able to proactively identify more bad people.  And after my lengthy experience in this business,  I totally despise the currently-in-vogue concept of “profiling” – if empirical data suggests that 95% of my problems are caused by xxx people, then watching for xxx people is NOT profiling, it is good, reasonable security practice which I would be remiss to ignore.
 
IF we harden targets appropriately, having adequate and sufficient security will not stop all bad things from happening, but it WILL stop most of the worst things most of the time.
 
Even bad persons usually hope to achieve 2 things: accomplishment of their bad deeds, and concluding the accomplishment of their bad deeds in the way they desire (usually either anonymous escape, or suicide). Good security WILL reduce the“environment conducive to criminality” at a given place so that the bad person might choose to do his bad things elsewhere.
 
A whole other facet of this issue may divert into a discussion of who is best able to provide security guidance and assistance to the places that most need it.  Once again – as usually is the case – economics dictates to many organizations that security planning assistance comes from a little- or no-cost resource, which is frequently the local law enforcement agency.  But with all due respect to my law enforcement colleagues who provide heroic and loyal service on a daily basis,   they are usually not the best source of advice on security matters, if for no other reason than that is not their primary job focus.
 
Better security can be achieved anywhere…but it comes at a cost and requires a commitment.

Thursday, January 10, 2013

Sandy Hook Tragedy - Response, Part II


The tragedy at Sandy Hook Elementary School seems to have offended our sensibilities more than other such tragedies because of the ages of the victims.  But in reality, this tragedy was not significantly different or worse than other such events – innocent lives should never be lost at the hands of a crazed or deranged person.  The term “gun violence” is always a prominent part of stories about these events, and the anti-gunners capitalize on that fact to put their emphasis on the wrong word:  the crux of the problem is violence, not guns.
 
While not the warm and fuzzy, politically correct philosophical ideal, it is nonetheless an absolute fact that it is simply and literally impossible to identify all the people who will do bad things and/or to accurately predict what bad things they will do and/or when and where they will do them.  Period.
 
Since bad things will undoubtedly happen regardless of our wishes, intentions and preventive efforts (because there is no such thing as absolute security, meaning some system/strategy that will protect against any conceivable or possible threat at all times), it behooves us to have the best mitigation, response and recovery strategies in place to protect everything important (meaning people, physical things and information).
 
Security must be considered at least as important and necessary as our attitudes and endeavors related to fire, which we have embraced and incorporated wholeheartedly:  While it is nice to idealize that people and things won’t burn and hope that “…it can’t happen here,”  yet we still design and implement (and pay for) reasonable and sometimes mandated fire protection precautions into our buildings; and install fire control systems and have fire response equipment in our buildings; and have regular fire system inspections; and have extensive fire plans that are reviewed and updated regularly; and have regular fire drills; and have internal personnel properly trained to deal with fires; and have Fire Departments to come and put out fires when they occur; and have plans to maintain and/or resume operations after a fire event. Why is the same not so for security?
 
Why are places with adequate and sufficient fire control systems and procedures not considered “fire traps,” but places with adequate security systems and procedures are considered “armed fortresses?” When I walk into a building and see sprinklers on the ceiling and fire extinguishers at key places and evacuation route maps and “No Smoking” signs on the walls and a fire truck parked outside, I get a feeling of comfort – the thought never crosses my mind that this building must pose some grave fire danger.  Why do we not put commensurate emphasis on security?   Why do we not see alarm systems and CCTV cameras and monitors and uniformed – perhaps armed – security personnel as an indication of concern for our safety and security?
 
Logic and consistency do not seem to be traits held in esteem by anti-gun proponents, because in virtually no other situation do they condemn the tool used in a bad consequence as the cause or culprit:  When a porch pulls away and falls from a house killing/injuring partygoers, the hammer is not blamed.  When a pedestrian is killed by a drunk driver, the car is not blamed.  When an editorial or cartoon is written that enflames and angers the masses, the typewriter/computer is not blamed Only when it comes to guns is the tool rather than the actor condemned.
 
We learned (or should have learned) from Benghazi that diplomatic and bureaucratic and philosophic options are meaningless at the time of an attack, because without proper response capability good people die.  When my family is being threatened with grave harm and I am not present to intervene, I do not want a philosopher or psychologist or social worker or a book of social ills analysis there – I want “…rough men (who) stand ready in the night to visit violence on those who would do us harm.”

 

Thursday, December 27, 2012

Sandy Hook Tragedy - Response, Part I


Once again a tragedy involving a firearm has struck the U.S. (Sandy Hook Elementary School in Connecticut); and the aftermath brings the usual spate of comments and solutions to avert such tragedies in the future, most of which deal with additional regulation of guns.  But let’s not forget that most of the rhetoric related to guns and gun laws is spouted by both individuals and media who have little if any true knowledge or experience with either.  Cases in point:
 
Many/most of the current diatribes make frequent use of the terms “assault rifle” and “semi-automatic” and paint them with the same negative brush. In reality, an “assault rifle” (as available to civilians) is nothing more than a cosmetically-different rifle (configured to resemble a military weapon), most of which are “semi-automatic” which simply means that 1 bullet is fired with each pull of the trigger and the next bullet is fed into the firing chamber without manual manipulation (strictly speaking, even a revolver operates in a “semi-automatic” manner!).
 
There are literally tens of thousands of gun-related laws in the U.S., ranging from Federal law to local/municipal law. Virtually every facet of owning, carrying, transporting and using a gun is either directly regulated in some way or is covered under the umbrella of some related law (e.g., a general law relating to disorderly conduct would encompass the act of unnecessarily brandishing a gun).
 
Deliberate gun violence (crime) and inadvertent gun harm (accidents) are not the “epidemic” that might be expected due to the civilian ownership of approx. 300 million guns in the U.S. – approx. 8% of all violent crimes are committed by a person known to have a gun, and approx. .5% (1/2 of 1 percent) of all fatal accidents involve guns.
 
Guns are used approx. twice as often for self-defense as they are to commit crimes; and crime and murder rates are generally lower in states with established concealed-carry laws.
 
Two of the cities with the strictest regulation of gun ownership and possession in the U.S., Washington, D.C. and Chicago, IL, have crime and murder rates involving handguns significantly higher than the national average for the same offenses; and both cities had significant increases in their crime and murder rates after the more stringent gun laws went into effect.
 
There is no way to predict anti-social or psychopathic behavior (the root causes of the vast majority of gun misuse); and there is no way to assure that a person unfit to own, possess or use a gun will never do so.
 
So…guns are not inherently evil, they are simply tools for a variety of purposes; there are sufficient gun laws on the books if they would be administered/enforced strictly and consistently (the vast majority of gun-related crimes are diminished or pled down during criminal proceedings); the vast and overwhelming majority of guns in the U.S. are owned and used lawfully and responsibly.
 
Here is a rhetorical question for the anti-gunners: If guns are so inherently bad, why do you immediately want a gun on scene (in the hands of a trained professional) to respond to and mitigate some evil action?   It would seem that that in itself is a tacit admission that it is not the gun itself that is inherently bad…

Tuesday, November 13, 2012

The "Environment Conducive to Criminality"


In most states in the U.S., landlords/proprietors have some basic obligation to provide a reasonably safe and secure environment for tenants, patrons and other invitees.  This obligation may arise from specific laws/statutes, or from general laws/statutes relating to negligence, or from case law. 
 
In any event, the obligation to provide a safe environment virtually always uses the concept of reasonable security based on foreseeability as the test for adequacy and sufficiency of security when some incident occurs.  In simple terms, this means that a landlord/proprietor must take the precautions that a reasonable person would take under the same/similar conditions and circumstances after giving due consideration to factors affecting the premises (namely:  the inherent nature of the premises; the history of problems at the premises; the history of problems in the area immediately surrounding the premises; and any industry standards that may exist relating to the premises).  This definition thus presupposes that some “one-size-fits-all” approach to security will usually not be adequate or sufficient since circumstances are different at every premises.  But the single factor which exists in the majority of times when some security incident occurs at some specific place is what I refer to as the “environment conducive to criminality.”
 
Let me here make a disclaimer:  There is no such thing as absolute security (meaning continuous, constant, total, complete and unqualified protection and safety of a given asset) – any security system or strategy can be compromised given sufficient motivation, opportunity and resources.  So, since security breaches can occur even when adequate and sufficient security exists, then the primary purpose of any security strategy is to control as many variables as possible to limit the opportunity for criminal acts to the extent reasonably possible, i.e., make it as difficult as possible for crime to occur successfully. 
 
Except for crimes of passion (which generally occur spontaneously), criminals usually seek 2 conditions when deciding how/when/where to commit a crime:  environment/circumstances which allow greatest probability of the criminal act succeeding; and environment/circumstances which allow greatest probability of committing the criminal act without being stopped, caught or identified.  This means that criminals generally choose the circumstances and places which provide the greatest opportunity for successful accomplishment of the crime – they choose a place which has an “environment conducive to criminality.”

As noted above, every place is different and has different conditions to consider when determining security needs.  But regardless of place or conditions, an “environment conducive to criminality” usually has some common traits:
  • no formal or careful consideration has been given to security needs (nothing has been done to assure that appropriate security measures have been implemented commensurate with foreseeable threats)
  • no formalized security plan exists (security measures, if any even exist, have been chosen and applied haphazardly with no formal strategy or objective)
  • area has easy access (a place which has a perimeter which cannot readily be secured or which has access controls which can be easily defeated)
  • area is unkempt (making it difficult to determine if something is missing or providing places to hide or move furtively)
  • area is dark (a place where crime can occur undetected and persons cannot be readily seen or identified)
  • area is not routinely surveilled either by technological means (such as cameras) or persons (a place where crime can occur undetected and persons cannot be readily seen or identified)
  • area has no regulatory or warning signage prominently displayed (information is not provided to advise patrons of proper or prohibited behaviors, to publicize security measures as a deterrent to inappropriate/criminal activity, and/or to warn of the penalties for engaging in inappropriate/criminal activity)
  • there is no ready security response when problems occur (no plan is in place or competent personnel available to deal with inappropriate persons or activities)
  • employees, even those ostensibly having security responsibilities, are not selected or trained properly (personnel are not competent to identify suspicious persons or respond to inappropriate/criminal activity)
  • records/documentation related to security are not maintained (history of security issues is not kept or reviewed to ascertain that security measures are adequate and sufficient)
  • security is not given adequate management attention (nothing is routinely done to assure that security measures are adequate and sufficient for current or changing security needs)
In summary and conclusion:  When a place fails to identify its security needs and fails to take reasonable steps to provide reasonable security, the result is usually a place where persons go to engage in inappropriate and criminal activities with little concern for being stopped, identified or caught  – a place with an “environment conducive to criminality”.

Thursday, October 11, 2012

The Lesson from Benghazi


The tragic – and apparently avoidable – death of an Ambassador and 3 other officials is another grim reminder of both an endemic and systemic problem:  the United States is a reactive country.  And this is a significant problem for both national security strategy and business security.  Loss of life is certainly far more important than the loss of physical or intellectual assets, but the underlying principle is basically the same:  we fail to provide adequate security.
 
As a nation and in the business sector, we tend to be more reactionary than proactive – we have a long history of “not closing the barn door until after the horse has run off.”  We believe that bad things can happen, but only somewhere else or to somebody else;  and even when we recognize that something bad may happen, we rarely expect the worst-case scenario to occur.  We tend to look only at the immediate past for the information with which we make our decisions regarding the immediate future.    So when there are few actual, everyday problems or incidents, security becomes an afterthought and again becomes relegated to the status of “necessary evil.”
 
We fail to recognize that the law of averages and the intent of our enemies will ultimately affect everybody. We rely on our God or Lady Luck or whatever to keep us safe from “the big one.” The security assessors and planners are always viewed as the naysayers,  the ones who bring negativism to the table because, while everybody else is talking about peace and détente and political correctness, the person charged with looking for the bad things will raise his hand and ask “...But what if...?”  And all the shaking heads will turn in that person's direction and his views will be looked on as the ramblings of someone who isn't really with the team or on the bandwagon because "...those things just won't happen to us." But they can...and they will...and they usually do happen.
 
The major cause for having inadequate security is readily apparent:  the people who do the security assessments and create the security plans (in other words, the people who are the most likely to know what to expect) are never the ones in complete control of security. Responsible and accountable and scapegoat-able, yes. In control, no. Why? Because someone else always controls the decision to implement the plans and policies, the money and the resources. Some bureaucrat or executive always has to look at what the security readiness plan will entail and cost and determine – usually in a completely uninformed way – if the imposition of inconvenience and expenditure is really worthwhile, and if the funds and other resources are really most wisely spent on something that may never happen.  So with this fiscal attitude, bolstered by our naïve and erroneous belief that it can't happen to us, the will and the money and the resources we need for truly adequate security are never in place when we need them most – preferably before, but at least at the beginning of some disaster.  And we suffer again.  Needlessly.
 
Both our nation and the business world need to recognize the importance and value of security.  Our post-9/11 world,  coupled with the realities of today’s economy, makes the practice and implementation of adequate security a virtual necessity.  No longer can the protection of our people and our assets be relegated to good fortune and happenchance.  Rather, a systematic approach to assure that everything reasonable is being done to guarantee our nation’s and our business organizations’ safety and financial well-being is of vital and strategic importance.  And the marketing and selling of the concept of adequate protective efforts is a job that must be continually and relentlessly pursued by security professionals, since bureaucrats and executives are most often concerned only with the things that undermine the ability to provide good security.

Wednesday, September 05, 2012

A Lesson from the Past


I think the adage “If no order, chaos” is truly applicable in the security world – not necessarily to the security function per se, but to the overall concept of security, loss prevention and asset protection within business organizations.

I am old enough to remember the days when order and discipline was the rule of thumb in the business world:  Executives set goals and broad strategies; management made policies and rules to support and implement the strategies; and employees were expected – nay, REQUIRED – to follow and implement the rules and procedures and policies.  Each of those three tiers had its inherent authority, responsibility and accountability.  If a particular person in a particular tier did not properly exercise his role, he would be disciplined – formal discipline on his record, or demotion, or termination.  Everybody clearly understood his particular defined role in the organization, its concomitant responsibilities, and the penalties for failure.  Supervisors and managers were responsible for assuring compliance – they actually supervised and managed.  This was the very concept and essence of ORDER.

In those days, there was far less opportunity for internal security problems within a business organization because there was a defined system of checks and balances, and there were people in place to assure that the system functioned properly and successfully.  The thought and belief was “Even if Big Brother (i.e., Security) was not watching, my boss was.”  I had to perform and behave, or I’d be gone.

Today, that scenario does not exist.  Everybody does everything, so nothing really gets done thoroughly or correctly (another true adage:  “When everyone is responsible, no one is responsible”).  Executives don’t have time to formulate sound goals and strategies because they’re too busy and worried about what is now the end-all and be-all of business: next week’s profits.  So management muddles along, trying to support the executives’ “goal” of next week’s profits.  And the employees do whatever their job-of-the-day happens to be.  EVERYONE gets frustrated.  There is NO sound management or supervision.  So there is lots of time and opportunity to devise devious schemes for “getting my fair share” and doing things in the easiest, simplest way possible, which results in errors and mistakes and an I-don’t-care attitude.   This is the very concept and essence of CHAOS.

Some organizations still focus primarily on “old” security ideas like preventing, mitigating and managing external problems.  But that is because there was a time when focusing on external problems (like theft, trespassing, vandalism, bad checks and credit cards, etc.) was pretty much the sole extent and focus of the security function because there just weren’t that many other issues for Security to be concerned about, because when there was ORDER the internal systems worked and resulted in efficiency, correctness…and low levels of loss.

But now in the land of CHAOS there are many more things to be concerned about in terms of protecting an organization, many (most?) of which are internal, because Security has been charged with cleaning up the mess created by the broken systems that were broken by someone else.  And in order to fix this pervasive problem, we have to first repair the broken windows before we can make sure that they don’t get broken again.

Oh for the simple life of the past……

Friday, July 13, 2012

Value of a Diverse Background

When selecting an organizational security executive, an independent security consultant or a security expert witness, the nature and diversity of the individual’s background should be given thoughtful and careful consideration.

In general, security professionals should have practical rather than (or at least in addition to) theoretical experience. While a knowledge of security concepts and theories is helpful and necessary, it is generally more valuable for a person who will manage or review security operations to have “…been there, done that.” In other words, a professional who has actually worked with the principles he is expected to administer or review (a practitioner) generally brings a more comprehensive perspective than someone who has only studied the principles in theory (a researcher or academician).

In addition, many organizations feel that a person with public law enforcement experience will necessarily make a good security executive, but then do not take into account the nature of the law enforcement experience. With the inherent difference between law enforcement and security – a reactive mindset vs. a proactive mindset – it is important to assure that the law enforcement candidate being considered has some practical experience with the kinds of activities most likely to be encountered in the business setting. This concept holds true in the selection of an independent consultant or expert witness.

As an example, my professional background is unique because it brings a practical knowledge of my field from 3 distinct perspectives: I have served as a Director of Security for 3 organizations, assessing security needs from a subjective standpoint, developing, implementing and managing security programs; I have served as an independent Security Consultant to a wide variety of private and public sector organizations assessing security needs from an objective standpoint, recommending strategies for risk mitigation; and I regularly serve as a court-recognized Security Expert, evaluating adequacy and sufficiency of security programs and operations from a forensic standpoint.

Diverse experience guarantees both broad knowledge and analytical insight.

Friday, June 15, 2012

Process for Conducting Security Assessments

I don’t believe in using anyone else’s form or template for conducting security assessments – each consultant or manager who conducts such assessments has a unique style coupled with his own knowledge and experience; so, as with many things related to security, a “one-size-fits-all” approach usually doesn’t work. But other groups (such as ASIS International and the Federal protective Service) do have some great ideas, so I have incorporated some of those ideas into the forms and procedures that I personally developed for my own use.

In general, I use several background/ “inventory” forms to generate basic information about the grounds/campus, physical facilities, administrative/operational business components, and policies/procedures of the organization for which I am doing the assessment. I have these filled out to the extent possible by organizational representatives prior to my physical inspections/interviews. I then personally conduct a site inspection (to verify all information developed via the background/ “inventory” forms and to assure that nothing important was overlooked), conduct personal and focus group interviews, and review all relevant policies/procedures for adequacy and sufficiency. Finally, I compile all information along with my analyses and recommendations into a narrative report which is the final work product.

During my career this process, along with my experience in serving as a Court-recognized Expert Witness, has confirmed by belief that every place has to be assessed and analyzed separately and independently to fulfill the legal standard for adequate and sufficient security – namely, reasonable security at a particular place and time, under a particular set of circumstances, based on reasonable foreseeability; and thus my process which combines self-developed tools for gathering information along with objective analysis according to the needs and culture of each particular project assures that my assessments are personalized for each client.

I have been using this process for the past 25+ years, and it has served me well.

Sunday, April 22, 2012

Preparing for Testimony

Practitioners in the security industry may occasionally be called on to provide testimony in some legal proceeding (either a criminal or civil case; during a deposition or at trial; as a fact witness or an expert). While those practitioners who have served as case consultants and/or expert witnesses will probably have had testimony experience, other security personnel may be faced with giving testimony for the first time. Regardless of the inherent knowledge or expertise of a witness, he/she still needs to be credible, effective and persuasive to the Judge and/or jury. To this end, preparation of the witness is very important.

Each attorney has a unique style and strategy and will undoubtedly have an established procedure for prepping witnesses. But here are a few issues that should be considered by anyone preparing to testify:

(1)  One issue that is sometimes overlooked in the preparation of a witness is the fact that he can only respond to the questions asked (a good witness can sometimes find a way to include additional information, but not always). So close collaboration with counsel is very important, not only to prepare for testimony expected during direct examination at trial, but for anticipated cross-examination. There needs to be a clear understanding and agreement of what information needs to be conveyed, the best manner to convey it, and the best manner to counteract aggressive cross examination, including attacks on both personal credibility and the credibility of testimony.

(2)  Even if not specifically demanded in the deposition or trial subpoena, availability of any relevant case materials/files is a good idea. Specific information such as dates, times and/or other technical information is likely to be a subject at issue, so it is better to refer to notes than to give erroneous information which may later be challenged or used to impeach the witness.

(3)  Answering questions “yes” or “no,” or at least as briefly as possible, is always a good idea. But when such a brief answer is not sufficient – such as when additional clarification or expansion is necessary – it is often best not to begin the answer with “yes” or “no” (such as “Yes, but…”) because an experienced attorney may not allow the “but” portion. Rather, it is sometimes better to begin a longer answer with a qualifying statement such as “Unfortunately, that question cannot be answered with a simple ‘yes’ or ‘no’, ” then go on with the full answer.

(4)  It is usually helpful for a witness to be advised of the personality and usual strategies/tactics of the opposing attorney. This helps the witness to better prepare for the demeanor and “personality” of the anticipated proceeding (for example, knowing that a particular attorney focuses just as much on the witness’s background as he does on specific case issues). Knowing what to expect from a particular attorney is a great asset for testimony preparation.

(5)  A witnesses should pause briefly before giving any answer, to allow his attorney the opportunity to object before potentially damaging or unnecessary information is inadvertently given.

Testifying in any legal proceeding is often a stressful and challenging ordeal. So having as much information as possible about what to expect, and being as prepared as possible, goes a long way towards doing a thorough, competent and professional job.

Tuesday, March 06, 2012

"Absolute" vs. "Perfect" Security

“Absolute security” and “perfect security” are not one and the same – the terms are not synonymous. And let’s be clear from the outset: There is no absolute security; and while perfect security may be hypothetically possible at any given moment in time, long-term perfect security is also not possible.

First, some working definitions: Absolute security is the theoretical state of total, complete and unqualified protection and safety of a given asset (some specific person, place or thing, including intellectual “things”). Perfect security is the practical state of utilizing the most appropriate security measures and strategies for a given asset at a given moment in time to protect against immediate, specific threats. A subtle but important difference.

From another perspective: Absolute security would protect against any conceivable or possible threat at all times. This condition simply cannot exist: No security program or strategy can ever totally assure that assets will not be lost or that a legal challenge to security efficacy will not be successful. Depending on a number of uncontrollable variables – such as the commitment, motivation, resources and persistence of an attacker; the inexplicable failure of a protective measure at a crucial moment; or even the whims of a jury – the best security measures may sometimes fail or be deemed to be inadequate. Nothing can be done to assure that nothing will ever happen.

On the other hand, perfect security keeps whoever/whatever is being protected safe right now, from whatever threat is occurring right now. This is attainable, albeit for limited periods of time because situations and conditions change constantly and continuously, and that which is adequate and sufficient right now may not be adequate and sufficient in a few minutes or hours or days. The best that can be hoped for – and what those responsible for security should strive for – is to control as many facets of the security strategy as possible for the longest time possible, and to monitor the strategy continually to assure that emerging threats and unanticipated failures can be best and most expediently mitigated.

As with most issues related to security, one should hope for the best while planning for the worst.

Tuesday, January 17, 2012

The Value Of A Security Consultant

Many organizations – even, or perhaps especially those with in-house security operations – frequently fail to recognize the benefits of an occasional security assessment conducted by an outside, independent security consultant.

A security assessment of a business is conducted to identify factors which create potential risk to employees, customers, guests and facilities; to analyze and prioritize those potential risks; to analyze current security countermeasures in relation to the identified risks; and to offer recommendations, ranging from physical security measures to security personnel to security policies and procedures, to prevent and/or mitigate as many potential risks as possible. Many organizations have come to realize the value of an outside, independent, objective security audit process – such a review assures that all issues of potential concern have been identified and addressed.

Smaller businesses which do not have a proprietary security operation rightly utilize their local law enforcement agencies to provide basic protective efforts and believe that such involvement is sufficient for their security planning needs, but that is not necessarily the case – law enforcement agencies focus primarily on problem response and resolution, and rarely have the knowledge or experience to conduct thorough assessments of a business’s total security program which should focus primarily on development of prevention and mitigation strategies. While both components – prevention/mitigation and response/resolution – are essential for a thorough security plan, it is obviously much more beneficial to prevent problems whenever possible. So inclusion of the expertise of a security professional is something that should be considered. And in organizations that already have a proprietary security program, an occasional independent security assessment provides a fresh perspective to processes routinely managed by persons who may be too close to the situation to see it clearly and completely.

A security review of any business or security program by a totally independent security consultant, with no affiliations with equipment or personnel providers, can be invaluable in assuring that all security concerns have been identified and addressed in an objective manner, with recommendations geared to the particular needs and circumstances of a specific business.

Wednesday, December 28, 2011

Difference Between A Security Assessment and A Risk Analysis

The security assessment process is a common method used to determine specific security needs for a specific business based on the issue of foreseeability – the standard that Courts will use to determine if security was adequate and sufficient when security is legally challenged as a result of some incident that has occurred (something bad happens, someone gets hurt, you get sued). Pretty basic.

The security assessment process takes into account 4 specific issues: The inherent nature of the business (every place has its own inbuilt problems and vulnerabilities); the history of problems at the business (while not an exact predictor, past problems at any given place demonstrate the potential for future problems, all else being equal); history of problems in the area surrounding the business (problems which occur in the neighborhood have a tendency to affect everything within the neighborhood; nothing is immune); and industry standards/guidelines/best practices (what has been determined to work in similar places under similar circumstances is at least a good starting point to identify potential security strategies and tactics as related to identified threats and risks). Pretty straightforward for determining foreseeability – that which may occur.

But the concern for being sued shouldn’t be the only reason why a good security program should be part of a sound business plan – it’s just plain good business to maintain a place where assets are protected and employees and customers are safe.

So before a strategy to prevent and mitigate problems is formulated, perhaps we should first remember why security is important in the first place. And that determination can be accomplished by a risk analysis.

Before we begin figuring out why security is important, there are two basic premises that must be clearly understood:

1. There is no such thing as absolute or perfect security: No security program can ever totally assure that bad things will not occur or that a legal challenge will not be successful. Depending on a number of uncontrollable variables – such as the commitment, motivation and persistence of a bad guy; the inexplicable failure of a protective measure at a crucial time; or even the whims of a jury – the best security measures may sometimes fail. So the best that can be hoped for is to control as many facets of the security strategy as possible, and to monitor the strategies sufficiently to assure that unanticipated failures can be best and most expediently mitigated.

2. There are always alternatives to how security measures can be implemented: Because the practice of security is both science and art – the science being the body of knowledge used in protective efforts; the art being the most appropriate application of that knowledge to a given circumstance – there will always be alternate ways to blend the stuff and the applications into a sound, workable and efficient protective strategy.

So here’s what we know thus far:

· Every business and its stuff needs to be protected.

· Every business needs to be concerned about liability.

· Since every business and its stuff is different from everyone else’s business and stuff, efforts to protect anyone’s business and stuff will necessarily be different from the efforts to protect anyone else’s business and stuff.

If we accept these enumerated hypotheses, it becomes obvious that some formal or at least conscious consideration must be given to the development of a security program – if I want to adequately protect my stuff and my liability, I need to consider my situation and develop a security plan accordingly. So how do I do that?  Here’s the outline for our risk analysis:

· If I need to protect my business and my stuff and my liability, I need to know exactly what my business and my stuff and my liability is (these are my “assets” and they include not only my building and equipment but my employees and customers and vendors and my reputation and my business practices and anything else that is valuable to me).

· If I need to protect my business and my stuff and my liability, I need to know all of the potential problems and threats I might encounter (these are my “risks” and they include all the manmade and natural problems, both deliberate and inadvertent that pose a threat to my business).

· If I’ve identified all my potential problems and threats, I need to know how likely it is that each of those problems and threats might occur (all of the bad things that can potentially happen at my business do not all have the same potential for happening – an assault is more likely than a tornado, employee theft is more likely than an armed robbery, etc. – so we need to figure out what is most likely to occur so that we can determine which security measures will be most appropriate).

· If I’ve determined the likelihood of occurrence of each of my potential problems and threats, I need to know what the impact would be to my business, stuff and liability if any of those potential problems or threats occurred (even if/when something bad occurs the impact on business will be different – the loss from an employee caught stealing on his first day of work has less impact on the bottom line than the loss from an employee who has been stealing for the past 3 years, an attempted robbery in which an innocent bystander is seriously injured has greater impact on a business’s reputation than a loud disagreement about incorrect change – so we need to figure out which of the bad things most likely to occur will have the greatest negative impact if/when they do occur so that we can determine how best to allocate the limited resources for security measures) .

· If I need to develop a plan to protect my business and stuff from liability, I need to know if any adequate safeguards are currently in place (we need to determine if existing security measures are adequate to protect all identified assets and meet all identified risks, and to determine what additional security measures might need to be implemented).

So there you have it – we’ve come full circle: We know how to implement appropriate security strategies that will protect our businesses and do so in a manner that is legally defensible (by determining foreseeability via a security assessment); and we now know how to determine why we need a security program (as identified via a risk analysis).

Thursday, October 06, 2011

Private Security / Law Enforcement Partnerships

There are probably a few readers who are wondering why this issue is even being discussed, since there are still a few security practitioners who do not (or cannot) see the importance and value of developing good working relationships and partnerships with our law enforcement counterparts. While it may not be the most current trendy management philosophy, I can state categorically after more than 30 years in private security that having good relationships with public law enforcement is not only desirable, but it is absolutely necessary to the success of a security or loss prevention program. Without belaboring the issue, let me illustrate just a few salient points:

· There will undoubtedly come a time when some type of criminal act occurs at the organization for which you have security responsibility; and there will undoubtedly be a time when that criminal act requires, for whatever reason, some form of law enforcement involvement. That type of incident should not be the first time that you have had communication with the appropriate law enforcement agency. Knowing each other beforehand will go a long way towards a satisfactory, timely and successful resolution to your problem. (And this relationship will prove even more important if the problem becomes complicated or difficult.)

· There will undoubtedly come a time when some form of emergency situation occurs at the organization for which you have security responsibility (a fire; a bomb threat; a power outage; a lost child; a domestic dispute involving an employee; etc. etc. etc.). Knowing who to contact and what to expect from the appropriate law enforcement agency will prove essential to successful problem resolution.

· There will undoubtedly come a time when a company investigation in which you are involved requires more information or resources than you have internally. Having a good working relationship with the appropriate law enforcement agency will provide at the very least a sounding board for discussing your situation and getting an informed second opinion; and may even provide the information and/or resources that you are lacking to continue or complete your investigation.

These are only a few obvious examples of the practical need for sound working relationships between the private security sector and public law enforcement. But the benefits of such relationships go beyond the boundaries of an individual security practitioner’s needs for his own organization. As far back as the 1970’s, there has been a realization that public law enforcement cannot do its job alone: increases in criminal activity and public outcry against continually-rising taxes has created a situation in which public law enforcement is spread dangerously thin. It is unrealistic and unreasonable to expect that law enforcement can immediately respond to every citizen’s – or every business’s – wants and needs. So, along with the increased necessity for a business organization to be more self-reliant with regard to its own security needs, so, too, does that necessitate a sound partnership with involved law enforcement agencies so that both sides know what to expect from the other, to insure proper strategic and operational planning. And this concept was dramatized and heightened even more after the tragic events of 9/11.

And then there is the altruistic reason. We in the security and LP industries frequently don’t give ourselves enough credit for the importance of our role (perhaps because we are all too often held in relatively low esteem by our employers – but that is another topic for discussion). Maybe it’s time to view ourselves from a different perspective. Since business and industry is the backbone of the American economy and culture, doesn’t it seem crucial for business and industry to be protected? Isn’t the protection of our business places (corporate citizens) as important as the protection of our individual citizens? So...from this viewpoint, maybe our role is a little more important than we have heretofore realized or given ourselves credit for. Perhaps there is not significant importance individually, but certainly collectively. And our role is becoming ever more important because of the myriad of threats that the American businessplace is experiencing in today’s social and economic reality – the stability of the American economy is unquestionably a target; and the economy goes as its individual components (i.e., our organizations) go. Whether we admit to it or not, and whether we like it or not, we are part of the overall criminal justice system. And, as such, we play a vital part in the protection of our society via the protection of our companies; and we must learn to work with other protective agencies to assure that we can successfully do our jobs.

I hope I have at least provided some sound arguments for the need for good working relationships and partnerships with public law enforcement.