Showing posts with label crisis management. Show all posts
Showing posts with label crisis management. Show all posts

Sunday, August 16, 2020

 The New Centurions

New Concepts for Policing


 

When I first started to outline this article, I was thinking about big bold steps to be taken in order to re-direct police services.  I got the idea from a tweet by Sen Harris, in which she said, “We need to demilitarize the police”.  Well, I couldn’t disagree more.  The reason police departments have military equipment is so that they can deal with the most serious violent crimes and criminals.  Police departments need armored vehicles and high caliber weapons, so that they can deal with gangs and organized criminal enterprises which are using those tactics, but they don’t need to bring them every time they engage the public (we’ll talk about that as a separate issue next time).  Those enterprises have no regard for human life, if they did they wouldn’t be kidnapping kids or young adults and forcing them into slavery, they wouldn’t be selling drugs to the most vulnerable within our society, just so they can make money.  So, to fight in this war the police have to have military style weaponry and they should be using them with efficiency and effectiveness.  You wouldn’t throw rocks at someone with a bazooka, so why would we expect the police to fight without the right tools.

But for the purpose of this article I’ll leave the strategic planning up to those responsible for administration of police departments whether at the local, State or federal level. 

Great interview about the changes needed in policing here:

https://twitter.com/FareedZakaria/status/1272231871896850434

Instead I want to concentrate on a more tactical or operational approach with simple solutions that will most probably be unpopular, especially with the rank and file, but I believe will go a long way in changing the culture within departments, assist in avoiding corruption or unwanted police behaviors and change the way the public views and interacts with the police.  The good news is, these ideas for change don’t need the rule of law.  They just need to be implemented as a new way of thinking and conducting business.  This will take real leadership; change is driven from the top.  While the need for change may be driven from the masses, change actually comes about because those in-charge decide to make the changes being requested. 

In ancient Rome, the Centurions were the professional officers of the Roman Army.  They commanded the troops, which sometimes meant that from time to time they enforced Roman law outside of the military legions they commanded.  Unfortunately in those times they also administered punishment by cutting or burning people’s hand off for stealing or other petty crimes or used a vine staff, with which they disciplined even Roman citizens who were protected from other forms of beatings by the Porcian and Valerian Laws (what punishments Roman citizen could be subjected to; they were not allowed to be humiliated or demeaned with degrading or shameful forms of punishment; such as, whipping, scourging or crucifixion.  Non-citizens and slaves had a different set of rules).  Hopefully, we’re way beyond that.  

At least, I like to think we are, but we can create new Centurions by:

First, stop appointing police chiefs based on political affiliation.  Currently, for the most part chiefs are either appointed by the city/county board, mayor or other elected officials or are elected themselves. Both methods are political.  Since laws are apolitical and should be enforced apolitically, so should the appointment of the police charged with enforcing those laws equally and justly.

Second, first and second-line supervisors should take a test that includes police administration, social – emotional, non-escalating skillsets, leadership skills, human rights and the protection of personal dignity training.  Allot more time needs to be spent of developing social skills needed in conflict resolution, at least at the same level that they spend on equipment usage techniques.

Thirdly, patrolman should be assigned “beats” randomly but with purpose and clarity.  The most troublesome neighborhoods should be assigned to those officers with the most experience.  There should always be a senior and a junior officer together whenever possible.  We should get rid of the notion of “Partners”, whereby, the same two people are assigned a specific sector each and every shift, so that they always work together.  Sure, there is an advantage to having “partners” as the patrolmen become familiar with each other and the neighborhoods they serve.  But conversely, they also become “too friendly” with each other or the residents, and worse, by becoming either complacent or tolerant of bad behaviors.   Additionally, the argument will be made that the patrolman needs to be able to trust his/her partner with their life.  That’s true, but if you can’t do that with everyone in the department, then there’s a problem.  The public also demands the same expectation. 

Over the years we got away from two man patrols due to budget cuts and other factors.  I think we should go back to them.  No more single patrols.  I’m not saying just to double everyone up by consolidating patrol zones.  No, this will only lead to longer response times.  Instead, I’m saying double force sizes by bringing on new officers.  Many will say, “We don’t have the money”.  To me that’s just another way of saying, I’m too lazy to do the hard work to figure out how this can be done.  So, I don’t buy the argument that it will be too costly.  Think about this, we just spent several trillion dollars on corporate and public welfare for COVID relief and didn’t bat an eye.  Not to mention the 10’s of trillions we’ve spent and are spending on the bank bailout of 2008.  It’s not about money, it’s about deciding.

Fourth, everyone in an administrative position, who is physically capable, should work “the road” once a week or a couple days a month – maybe a weekend or night shift.  Even those will mobility issues could have a role.  This gives fresh eyes and reminds everyone why they are there – to serve and protect.

And finally, move personnel around within departments, within organizations.  The military does this with regularity and at tremendous costs.  But the benefits far outweigh the costs.  Each move brings “new life”.  Getting a fresh set of eyes on things is invaluable.  It brings with it; fresh and innovative ideas, opportunities for personal growth, problem solving, and deters complacency and stagnation.  It also roots out those who have a history of misconduct.  New supervisors usually don’t tolerate bad behaviors that old supervisors allowed to go unaddressed. 

A recent study of police training revealed, that on average policeman in the US receive less than a thousand hours of training, whereas their European counterparts receive thousands of hours.  Most police chiefs in Europe are also lawyers or have law degrees, as do many mid-level supervisors.  I don’t believe this requirement exist within the US.  Maybe it should?  

Calls for defunding the police are just wrong.  Police departments need more resources not less.  That said, so do social programs that address the root causes of criminality and unwanted behaviors.  We need to add funding that teaches non-aggressive tactics and de-escalation techniques, social – emotional learning skills, and coping tools that deal with attitudes and behaviors.

I worked for ten years with the Carabinieri, the Italian National Police.  In those ten years I never once saw them man-handle anyone.  Sure they put people in handcuffs and took them to jail but I never witnessed any aggressive tactics on their behalf.  They always talked the guy into getting handcuffed. 

Great article about Carabinieri tactics, here:

https://foreignpolicy.com/2020/06/10/american-cops-could-learn-a-lesson-from-italys-carabinieri/

To illustrate my point, a few years ago, my son was travelling from Italy to the US.  He had been visiting his aunt and grandma.  At the airport in Rome, he placed his backpack on the conveyor belt at the x-ray machine.  After it was scanned, a Policeman approached him and asked my son to accompany him.  They went to a room, and the policeman pulled an apple, sandwich and serrated kitchen knife from his backpack.  The Policeman said, “Young man, we have one question, who packed your lunch your Mom or your Grandma?”  The Policeman knew, my son being in his thirties was old enough to know better than to bring a knife through the checkpoint.  He also knew that Moms being Moms in Italy meant, someone else had packed his lunch; Mom or Grandma had packed the knife so he could peel the apple, it was just logical. Clearly my son wasn’t a threat.  The Policeman kept the knife and my son boarded his plane.  I believe that had a similar incident occurred here in the States my son, would most probably have gotten arrested for possession of a deadly weapon, would subsequently have a criminal record, which could have an impact on his employment possibilities. 

We have a saying in the military that, “soldiers will be soldiers”.  In other words without supervision they will do stupid stuff.  Good behaviors AND bad behaviors are learned.  Shouldn’t we be doing everything we can to make sure good behaviors are nurtured, if so it’s about leadership?

Change comes from big and bold thinking.  Look at, putting a man on the moon.  Pretty big stuff there!  We didn’t know how we would do it but we decided we would.  Then it came down to many, and I mean many, small steps to get us there.  Well, if we are to truly reform the police, policing and the interactions they have with the public, we’ll need to take many small steps to get there.  NASA had many failures along the way, but eventually they figured it out.  I believe we can too, after all this is America – this is who we are.


Sunday, November 17, 2019


Known knowns and unknown unknowns






"There are known knowns" is a phrase from a response United States Secretary of Defense Donald Rumsfeld gave to a question at a U.S. Department of Defense (DoD) news briefing on February 12, 2002 about the lack of evidence linking the government of Iraq with the supply of weapons of mass destruction to terrorist groups[1]



This quote tells us something about risk management.  Basically there are threats we know about and there are threats we don’t know about and there are threats that we don’t know we don’t know about.



From a risk management standpoint, that’s pretty disconcerting. 



In order to understand the unknowns you have to look at things from the “bad guys” perspective.  In other words, see what the "bad guy" sees.  And to do that you must understand that there are four aggressor types of criminal/man-made threat groups; criminal (sophisticated/unsophisticated, organized/unorganized), protestors (organized/unorganized), terrorist (domestic/transnational/state-sponsored), subversives (saboteurs/intelligence agents [state/non-state sponsored]).  In an effort to design better mitigation strategies planners must understand the “bad guys” motives or the reason(s) behind why they do what they do.  There are also four primary aggressor objectives; inflict injury or death to people, destroy or damage facilities, property, equipment or resources, steal equipment, material or information and create adverse publicity.



So how can I plan to reduce their effects let alone mitigate them?  The answer is really easier than you think.   Traditionally in risk management, we look at things from a probability standpoint.  We ask the question. “Will it happen here, and if so, what will the impact be”?  I believe, likelihood has little influence on risk.  I believe likelihood comes into play when talking about funding.  Our risk management methodologies assume the threat will be successful 100 percent of the time.  We calculate likelihood when it comes to cost benefit.



Our Asset Based Risk Analysis (ABRA) and Critical Asset and Infrastructure Risk Analysis (CAIRA) methodologies combine the aggressors motives and objectives with what the asset owner sees; thereby, giving a complete picture of risk.  



More about ABRA (Platinum GOVIES Award 2017 for Best Government Security Risk Methodology) https://view.joomag.com/march-2019-ast-magazine-march-2019-ast-magazine/0952115001553308799/p4?short



More about CAIRA (Platinum 2018 ASTOR Award for Best Risk Analysis Methodology in Homeland Security) https://view.joomag.com/july-2019-ast-magazine-ast-july-2019-magazine/0612002001563068627/p60?short



More about risk management and developing mitigation strategies can be found in my new book, The solutions Matrix: A Practical Guide to Soft Security Engineering for Architects, Engineers, Facility Managers, Planners and Security ProfessionalsOrder here  https://americansecuritytoday.com/dont-surrender-to-fear-new-book-the-solutions-matrix-by-doug-haines/





[1] Full quote: Reports that say that something hasn't happened are always interesting to me, because as we know, there are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns—the ones we don't know we don't know. And if one looks throughout the history of our country and other free countries, it is the latter category that tends to be the difficult ones.

Sunday, October 20, 2019

Go Where there is No Path. But, I Can't, I'm Afraid of Snakes


A few months ago, my wife and I were shopping and came across this saying on a night shirt, “Go where there is no path”.  When I showed it to her, her reaction caught me a little off guard.  She said, “I can’t I’m afraid of snakes”. And, of course, being the person I am, I immediately translated that into a language I can understand – security-ish.  My first thought was, that explains why people don’t conduct risk analysis or even more importantly why they don’t even start the process.  They don’t tread into uncharted territory because there are snakes hiding in all that tall grass, so they stay where they’re comfortable – on the path.  Doing what is comfortable causes two problems.  

First, as Defense Secretary Don Rumsfeld, said, “We don’t know what we don’t know”, which translates into, we’re only protecting ourselves against what we can see, expect and believe is likely to occur.  Since, we don’t know what we don’t know, we’re not planning on dealing with its affects either.  This can be extremely more sinister because a lack of action could result in someone getting seriously injured or worse.  

Fortunately, there are methodologies out there that can get rid of the snakes.  I’m consulting on security matters with a local school district.  During our initial meeting, the District Superintendent, said, “Okay, where do we start? With an assessment to see where we are?”  Absolutely! 

Risk management is about managing risks.  In order to do that, you have to accept five factors:
1) You can’t prevent or deter everything
2) Protection from one threat may allow for some protection against another unrelated threat
3) Protection options must be in place before the event occurs
4) Risk Management must address the following pillars; detection, assessment, plans and procedures, response and engagement
5) Risk management and the assessment process is continual and is just part of what we do.

For ways to tame the snakes, read related articles here:



Sunday, May 19, 2019


Getting Everyone to Speak a Common Language




A couple weeks ago, I was teaching a class about using building design to deter criminal activity, including terrorist attack, and when it fails reduce its effects and prevent mass casualties.  After the obligatory introductions, I said something to the effect, that building design is a matter of reducing risk whenever and wherever possible.  But in order to do that you have to the know your “DBT”.

Based on the blank stares, I got back, I knew something was wrong.  So, I said it again.  Still the deer in the headlights looks.  So, I said, “Everyone knows what DBT stands for, right”?  Still nothing.  Not one person raised their hand.  I was taken aback.  After all the class was made up of seasoned architects, engineers, planners and security folks.  I would have thought, at least, one or two would have known what I was talking about.

So, we spent the new few minutes talking about Design Basis Threat or DBT, if you will.  DBT is identifying your threats, their tactics, the tools they may use and then designing your building to deter or prevent them from happening, in the first place, and understanding that if they do happen you can reduce their effects if you’ve included reduction strategies into the design.

The very first thing to do is to assemble “the planning team”.  The idea that “it takes a village” needs to be used here.  The team should include architects, engineers, facility manager, security, end users and others.  It’s important to bring these folks together, so that they can discuss the parameters of what they are trying to accomplish and “buy in” to the project.  If done correctly at the beginning of a project, security costs can be kept to a minimum, usually somewhere around five percent of the total project costs.  If security comes in at the end of the project this cost may skyrocket to thirty-forty percent, because of the long term cost of equipment maintenance and especially, personnel costs.

Once the team is assembled, the first step is to identify the threat or threats.  Threats can be divided into two categories; natural and man-made.  Fortunately, laws and ordinances exist that address natural threats in building design; i.e., earthquake, flooding, fire, tornado, etc.  Man-made threats on the other hand – not so much.  Although, that is changing slowly.  Last year, federal legislation was signed into law that addresses the use of hostile vehicles as a method of attack in public spaces.  We’re still waiting for the DHS report the law requires and its subsequent findings and recommendations.  I’m particularly concerned that our government hasn’t the courage to attack hostile shooter legislation, when it is so needed.  But that’s another Blog topic for another time.

The second step is to identify the motives of the man-made threat,; i.e., causing injury or death, theft or unlawful removal of property or equipment, damage to property or facilities and causing adverse publicity.  Then we need to figure out what type of groups commit these acts; criminals (sophisticated/non-sophisticated, organized/unorganized), protesters (organized/non-organized), terrorist (domestic/trans-national/state-sponsored) and subversives.  

Then we look at the tactics they use; stationary or moving vehicle, different types of weapon usage, forced entry, etc.  Each tactic uses a different set of tools. That said, each type of tool use has a countermeasure available to reduce its effectiveness.

If we understand their motives, tactics and tools, we can design countermeasures into inhabited space that reduces the possibility that they will occur and when that falls short reduces their effects. 

My book, The Solutions Matrix: A Practical Guide to Soft Security Engineering for Architects, Engineer, Planners and Security Professionals, will be available in September.  It will outline the processes used to determine DBT, have a quick reference chart that outlines how to counter each type of man-made threat and provide examples of practical real-world solutions.  

Sunday, March 17, 2019


YEP – IN SECURITY WE STILL NEED TO OCCUPY THE GROUND, WE CAN’T LEAVE IT ALL UP TO ELECTRONIC TECHNOLOGIES 



Despite the advances in electronic security technologies one fact remains, we (“the good guys”)still need to occupy the ground.

As many of you know, I’m a former Air Force Security Policeman – a blue grunt, if you will.  So consequently am a little partial to “zoomies” when it comes to the defense of the country.  Our strike capabilities are so sophisticated that we really don’t need the other services (now, don’t get your knickers in a twist and let me explain).  We could just bomb the hell out of the bad guys until they surrender.  But bombing the hell out of them doesn’t do anything for us, because in the end we still have to occupy the ground.  And that’s why the Air Force is just not enough.

The same holds true in the security business.  Everyone is moving towards electronic technologies and the advances in predictive behavioral analyses and other artificial intelligence (AI) technologies is “mind blowing”.  
In the ‘80’s we posted guards, in the ‘90’s we put cameras because guards became expensive and since that time we’ve been using analytics to understand better what we are observing.  With the technologies that are currently “off the shelf” we can do allot more than we used to be able to do.  We can have one guard monitor several cameras and with analytics s/he uses can monitor even more as the software interprets what it’s seeing and notifies those responsible when something is amiss.

This is all well and good, but electronics can’t do it alone.  We still need to “occupy ground”.  By that I mean we need to design the built environment so that it complements the technology we use.   The use of non-electronic technologies will become even more important in the future, and especially in the urban environment.

The city of New York employs thousands of cameras around the city but they also deploy thousands of beat officers.  Both rely on each other to enhance the other‘s effectiveness.  If a patrolman sees something, she/he can have a colleague at the central station bring the field of view into focus and zoom in.  And by looking at adjourning screens or from different angles maybe get a clearer picture of what is happening.  Likewise, if the monitor sees something suspicious, he/she can dispatch a patrol to investigate further and cover those areas that the camera can’t see.

So with the utmost respect, we still need the grunts.

Sunday, October 21, 2018

The 310 Year Gamble


The Federal Government’s 310 Year Gamble on Your Child’s School Safety






In the days following the Parkland High School shooting, my emotions were out of control; first, because of the lack of “adult” leadership by the Federal government officials and secondly, because when called out by the high school’s young adults they (politicians) attacked the teens.  Whenever asked about how they intended to keep another active shooter event from happening they hid behind thinly veiled comments about how it was someone else’s responsibility to address the causes and fix them.



Let’s be realistic, it’s about guns, it’s about mental help, it’s about a person’s desire for fame, it’s about lack of protection, it’s about lack of designed evacuation routes and the list goes on…  Some causes can be fixed in the short term and others, like mental health issues will take many years to devise systems that are effective in identifying “at risk behaviors” and getting the person the proper treatment.  We also need to address the way schools are designed not only should they be great environments for learning by they must also be safe.  One example is there should always be two ways to egress a space in an emergency.  Currently, many times there is only one and if there are two, they lead into the same hallway.



So, in the meantime, if students and faculty are going to be taught to “hide” in the back of the classroom then the space must provide ballistic protection.  If it doesn’t, the AR-15 bullet will travel through the hallway locker, drywall or classroom furniture.  I thought, if we don’t have specific ballistic protection in place couldn’t we design a system similar to have hotels create additional space by mobile walls.  I reached out to my friends at Amulet Ballistic Technologies and come up with a design for retrofitting existing classrooms or new construction.



In 2018, the Federal government allocated $100 million for security upgrades to schools.  The deadline for application to receive some of that money was 31 July 2018.  If your school district didn’t apply, it for sure won’t get any of the money, so you’ll have to wait until next year.  Fortunately, many State legislatures have been setting aside funding and the process seems to be continuous.

Another unfortunately circumstance when it comes to funding is that most of the money will go to hiring school resource officers (RSO) from the local sheriff or police department.  Placing an armed guard is not in of itself sufficient.  While it will help deter possibly, the truth is if a RSO is present he/she will become the first victim and/or will not be where the shooting starts when it starts.  Another key security feature will be electronic surveillance and access control.  Both are useful and effective but have their limits as well.  Cameras must be monitored in “real-time” AND a response must be immediate.  Access control is only effective if it doesn’t become a burden to day-to-day operations.  If it becomes “taxing” people will figure out how to get around it.  

Now, back to $100 million per year for the next 10 years ($1Billion total).  There are an estimated 50.2 – 58 million students in America’s schools.  The average class size in the US is somewhere between 17 and 26, so let’s just say 20-22 students.  If we divide the average size class occupancy into the lower number of total students that tells us we have about 2.5 million classrooms (give or take).  Now, if the average cost of constructing or retrofitting one classroom with ballistic protection is $15,000 (I suspect that once we get going the costs will be lower and more likely to be about $10-12k for a classroom of 20 using the Department of Homeland Security recommended square footage for safe-haven/shelter space occupancy.) then it will take $3,750,000,000,000 to retrofit all existing classrooms.  At one billion every ten years that will be 375[1] years to protect every classroom in the US.

Let me put that into context.  Most people think that during the 2008 financial crisis[2], the treasury department used $700M to save the banks.  This is not true.  The Special Inspector General for the Troubled Asset Relief Program (TARP) in their summary report says that the total commitment of the government is $16.8 trillion with about $4.6 trillion already paid out.

According to a team at Bloomberg News, at one point last year the U.S. had lent, spent or guaranteed as much as $12.8 trillion to rescue the economy.[3]

In either case, more than enough to protect America’s kids in less than 10 years instead of over 300. 

Sunday, April 15, 2018


THE EVOLUTION OF RISK MANAGEMENT,
WAS DARWIN RIGHT?



In the Theory of Evolution, Darwin suggests that evolution is about survival of the fittest.  Was he right?  While he was talking about the natural world, his theory also applies to the security business.

In order to survive in today’s world businesses must adapt to their environments.  The threats that were around twenty years ago have changed.  They’ve become more sophisticated and must be adapted to.  What worked before won’t necessarily work in today’s world.  Not only have threats scenarios evolved but with the increase in technologies so have a new variety of threats come about. 

It used to be that a person who wanted to commit a breach of security had to be physically present in the space in order to carry out the attack.  That is no longer the case.  Since just about everything that has a moving part to it is somehow connected to the Internet of Things (IoT), a hacker does not have to be present in the physical sense in order to disable a closed circuit television (CCTV) camera, for example.  This means, a new way of thinking about threats, vulnerabilities and risk is necessary.

Threats used to be pretty much two-dimensional.  That no longer is true.  Those involved in the risk management business must think in three-dimensional terms.  In fact, they need to think about security as if it were a cube or box.  It’s six-dimensional and the approach to risk management must be carried-out that way.  This will require, pardon the pun, “outside of the box” thinking.

Additionally, without the “it’s part of the culture” way of doing business threat scenarios will continue to be played out with varying degrees of impact – and, some will be catastrophic.  Since we cannot prevent threats from occurring one hundred percent of the time we have to get the results down to a level that we can accept and handle with available resources.  This requires us to include scenario that are improbable but the results will overwhelm resources.  I call this “impact centric planning”.   I know most of us will not encounter an active shooter situation within our lifetime but active shooter threats must be planned for wherever high concentrations of people gather.  The adage, it won’t happen here cannot be the flavor of the day.  You’re right it probably won’t happen here, BUT if it does?  What will be the impact?

Not only must we deal with threats that are likely but we also must deal with threats that would be catastrophic even though very unlikely.   An excellent example of a highly unlikely event is the Las Vegas shooting incident.  That event was so improbable that if I would have brought it up during a planning session those in the room would have thrown their coffee at me. 

In order to survive, we must ensure we are the fittest.  So, Darwin was absolutely right.

Sunday, March 18, 2018


If Data is the New Currency of the Modern World Then Why
Is My Account Overdrawn?



According to a recent report in Security Megatrends: The 2018 Vision for the Security Industry published by the Security Industry Association 99.5 percent of all data collected via electronic devices goes unused.  Let that sink in for a second.  99.5% is wasted.  Less than .5 percent is accessed, analyzed and used in some type of constructive way.  I can’t imagine any other industry or area of life where less than one-half of one percent is good return on investment (ROI).



Here’s some data provided in the article "Accessing and Analyzing Smart and Big Data, Moving into Artificial Intelligence and Augmented Reality", using 60 seconds as the baseline, on just the social media platforms that I use:



·         Google – more than 3.8 million searches

·         Twitter – more than 350,000 tweets

·         Facebook – more than 243,000 photos uploaded and 70,000 hours of video content viewed

·         Linked-In – 120 new accounts created



So, why does this occur.  Well, it has to do with automation and the progressive nature of technology.  We’ve all heard the standard cliché that your phone has more data processing capability than the spaceships that went to the moon.  There have been surprising advancements in just about every sector of society.

I read an article some time back, that said your bank account could be hacked through your toaster.  At the time, I thought it a bit far-fetched,  But now the home improvement stores are selling refrigerators that can order food for you, if programed properly.  While, I think that was a little exaggerated but the point the author was making was, if your toaster has a microchip in it and that sensor report data somewhere, there is the potential that a person with malicious intent could through that sensor get to my bank account.



But is this a good thing?  For the most part yes.  I mean, think about it, only a few decades ago, if you were diagnosed with the big “C”, you started counting your days.  Now, more people survive and overcome the disease than don’t.  But on the other hand, let’s not get too carried away.  Technology is a tool and should be used as such; a tool that allows us to make better decisions about life choices.  Let’s remember that technology is not the solutions but it can be used to find the solution.



One of the areas where there is promise, within the security industry, is the area of “augmented reality” or AR.  We’ve all heard of “virtual reality” where the user is immersed in a fictional environment.  With AR the data augments the natural environment.  A simple example would be the ability to super-imposed a data screen on the visor of a motorcycle policeman that presents him or her with information about traffic up ahead, including accidents or breakdowns.  Or data information relayed to first responders during active shooter events.  This ability will undoubtedly save lives.



Estimates are that the Internet of Things (IoT) will mushroom in the coming years to between 34 Billion and 58 Billion devices connected to the data grid in some way by 2020.   Even if the world population doubles in the next two years (which is highly unlikely) that’s more than two devices per person.  


The hard part, in all of this is, will be figuring out what data to analyze, what to keep for the future and when to give it to someone to use now.    

Sunday, November 19, 2017




First Responders Require Specialized Training to Deal with

 Special Needs Individuals





By Patricia O’Connor (Guest contributor)


Death of individuals with alleged disabilities through the actions of law enforcement has been reported in the media and has contributed to citizens of the United States protesting and seeking changes in methods used by law enforcement agencies.

NBC News reported on March 14, 2016 that almost half the people who die at the hands of police officers have some type of disability. According to an investigation conducted by Portland Press Herald in 2012 approximately half of the 500 people killed each year by police were mentally ill.

Police officers have become the default responders for incidents, including those involving mental health calls. They often find themselves in situations where urgent medical care by trained and certified professional practitioners would be more appropriate.

Misdiagnosis of symptoms or the misinterpretation of displayed behavior as being aggressive, resisting arrest, or threatening by law enforcement and by medical responders has resulted in the unnecessary injury or death of persons with special needs. Communities are ultimately legally liable. The question for community leaders has to be, “Why is this misunderstanding occurring and how do we fix it?”

So let’s examine this phenomenon – lack of training for first responders.

FIRST RESPONSE

First, let’s admit first responders do not face the daily challenges of their jobs with intentions of hurting, maiming or killing individuals with special needs. They are merely faced with circumstances which are unfamiliar to them. These circumstances require specialized training and knowledge. So often initial training has not been conducted and certainly, on-going training isn’t provided either.

First responders are required to have specialized training in other areas of their complex duties; i.e., weapons training, first aid, social behavioral skills, etc. in their particular field in order to serve their communities and respond appropriately to the needs of those whom they serve. Individuals with exceptional needs require exceptional care. First responders must have knowledge and training with the appropriate skill sets to deal with specific disabilities and needs so that their response is suitable. Interaction with people afflicted with mental disabilities requires specific and focused interaction just as interactions with people having other medical disabilities require special treatment.

TRAINING, TRAINING AND MORE TRAINING

As they say in the real estate industry, it’s all about “location, location, location”, well in dealing with mental health issues it’s all about “training, training, training”. Training must be relevant, engaging and consistent. Training sessions including both theoretical application and practical “role playing” exercises work best. Training is a continuous occurrence. It needs to occur routinely but not so often that it neither detracts from everyday duties nor develops into something so mundane that it becomes stale and ineffective. Training would save lives, both for the individuals encountered by first responders and the first responders themselves, especially those arriving on scene first – law enforcement officers.

THE WAY FORWARD

Whether responding to a scuffle at a convenience store or a major natural disaster as witnessed recently in northern California those responding need to be equipped not only with the physical tools needed for the job but also with the mental tools for resolving these highly charged situations. People with mental disabilities present special challenges during these extreme emotionally events. First responders should be equipped to deal with them. We can prepare for these situations through a serious of preventive measures; such as, placing placards on doors or windows indicating that special needs individuals are inside, creating communication systems with access to databases that first responders can “call up” while responding in order to ascertain what they might find at the incident scene and to alert them to obstacles or challenges they may encounter upon arrival. Just knowing when and where won’t be enough. Responding units will need to have skills sets that de-escalate the situation and resolve them in an appropriate manner. Additionally, it is essential for communities (civil authorities, medical, fire, law enforcement and citizens) to come together to address these issues.

A humane society is measured by its care for those who are most vulnerable. How will we be judged?

AUTHOR BIO

Patricia is a Doctoral student in Educational Administrative, with emphasis on Special Needs Education. She regularly provides insight and input to the Department of Homeland Security as they prepare Federal Emergency Management Agency (FEMA) guidance for dealing with special needs issues during times of crisis.  She is the founder and CEO of SirenUSA, an on-line training tool for first responders. 

“I can do things you cannot, you can do things I cannot; together we can do great things” – Mother Teresa


Friday, August 25, 2017

"Don't Make Me Come Over There."


How many times did we hear that phrase when we were growing up?  Or, "You just wait 'til your father gets home!"  I know I did.  I was scared to death, at least, until I was twelve or so and my Grandma whacked me with a wooden yard stick and it broke.  Then I knew I was too big to get a spanking any more.  Besides, by then I figured out I could blame my younger brothers and they'd "take it for me".  Love those guys!
Well, the same holds true in corporate America.  Sure, the boss isn't going to paddle anyone.  At least, I hope not.  But "unwanted behaviors" in the work place must be dealt with and it doesn't always have to be the boss or the security folks to deal with it. 
When "unwanted behaviors" occurred someone needs to step in.  That can be a co-worker or colleague.  Not that they need to "tattle" but behaviors outside of what's acceptable puts everyone at risk - from both a safety and a security perspective.
Non Security Personnel Can Play a Part
Non-security members of the organization can play a major role in identifying behavior that is unwanted.  But, they must be trained on when to interact on their own and when to keep their distance and report.  Smart leaders will develop scenario based training that includes all the members of their organization and promotes the interactions of the groups.  This can go a long way in instilling confidence in each other and creating a culture of unity and capability.  Which in turn, creates a feeling of safety and security within the organization.
But sometimes, even the best trained staff member is not capable of responding or diffusing the situation.  In this case, security force personnel should be called in.
Security Forces Compliment Non-security Forces 
Security response forces actually compliment other staff members and not the other way around.  That said, security personnel must receive additional training and have ability to accurately assess and engage the threat.  The operative word is “accurately” assess.  If they misunderstand the actions of the threat or assume aggressive behavior when there isn’t any the situation will quickly spiral out of control and actually escalate.  How many time have we heard, “I thought he had a gun”?
With that in mind, training is fundamental and paramount.  Training must be physically and mentally challenging.   Virtual, “situation based awareness” scenarios can be developed so that they stress the participants.  Role playing is always a benefit. Unless stressful conditions are trained for, guard forces won’t react properly when confronted by them.
The mindset that the responding officer must always be in control is correct.  That doesn’t mean they are superior it means they have the skills to neutralize the threat, sometime that requires force and sometimes not.  The use of de-escalating tactics is a learned behavior.  As such, highly aggressive and chaotic training scenarios serve the response forces well in learning how to deal with these types of behaviors. 
Cultural norms also play a big part is calming the confrontation between response forces and perpetrators.  What works in Los Angeles doesn’t necessarily work in Amsterdam or New Delhi. 
Responding forces must remember, the continuum of use of force is scalable and that deadly force is only used as a last resort.

Sunday, May 21, 2017

Case Study at European Simulation and Validation Center (ESVC)


Protecting Students and Staff from Active Shooters

A Case Study at the European Simulation and Validation Center (ESVC)



THE TASK AT HAND – PROTECTING STUDENTS AND STAFF

Protecting the students at the European Simulation and Validation Center (ESVC) was our objective and specifically, reducing the mass casualty count during active shooter scenarios.  With the increase in terrorist attack, it was only logistical that the Executive Director would seek out protection for her staff and cadre of instructors, but primarily, for the students attending simulation modeling at the ESVC.

“We pride ourselves in being a professional organization with extensive safety and security knowledge. Protection of our staff and students in any way is a main priority”, says, Karen Zwart, Executive Director from her offices in Ede, The Netherlands.  

Because CPK United BV is known for their expertise in training senior government leaders and industry executives, as well as, their key staff elements, especially in the transportation and aviation fields, the ESVC is the “go to” place when it comes to conducting serious gaming models for evaluating emergency plans and the actions required by them.  The ESVC provides a comfortable environment that is conducive to leadership training at the highest levels in lieu of costly field exercises.  The ESVC can create an organization specific built (physical) environment virtually; use existing company or agency plans, while allowing “players” to travel down a variety of decision paths in a virtual environment.  This allows them to test plans through their interaction, individually and collectively to evaluate efficiencies – without the additional expense of a full-scale exercise and without anyone getting hurt.   Using ESVC simulation allows plans and procedures to be tweaked before a real incident occurs and damage or injury occur.   

KNOWN COMPONENTS OF THE RISK FORMULA

All good risk formulas have some commonalities.  The formula usually goes something like this; C (asset criticality) X Threat (What can harm us) X Vulnerability (How susceptible we are to the harm) = Risk (How bad is it?).  In this particular instance, two of the essential elements in calculating risks were already known to the assessment team.  Those elements included the criticality of the asset, (high value targets/students).  To understand the criticality, imagine for a second, if a multi-national corporation’s entire senior leadership along with key staff were on-site being trained and ESVC were involved in a catastrophic incident.  It would not only mean damage and death but could also influence the future of the organization and could very well be the end of that company. 

And, the second known element – threat – was an active shooter scenario.

ASSESSING VULNERABILITIES – A SNAPSHOT IN TIME

The next element of the formula was to determine the vulnerabilities of the site as they related to the threat.  Haines Security Solutions was called in to do the assessment due to its extensive experience in conducting risk analysis and developing mitigation strategies as they relate to building design.  Experts in forced entry, building design, antiterrorism and structural engineering repaired to the site to conduct the evaluation.

It should be noted that during conversations with the staff it was noted there was a low-moderate probability of occurrence of this type of attack; however, due to the catastrophic impact on the corporate structure of an organization attending training if impacted (low/moderate risk – critically high impact), it was determined to be of extremely high importance to conduct a full range of assessments.

Each area of the facility (reception area, training facility, staff offices, storage areas, coffee/snack center, bathrooms and print shop) was examined from both the owner’s and the aggressor’s points of view.

USING THE ASSET BASED RISK ANALYSIS METHODLOGY

This dedicated team of subject matter experts collected physical security, as well as, operational data on-site in order to allow them to fill-in the vulnerability element and complete the risk formula

They then started collecting physical data from the curb inward.   Data was collect on three layers where vulnerabilities could occur; i.e., property perimeter, building façade and internally controlled spaces.  Data about the IT system or software used at the ESVC was not collected because the ABRA, in this case, did not call for the protection of data on the IT system.  Instead, it called for the protection of lives.

Once back at their offices, the Haines Security Solutions team members used an assessment methodology called Asset Based Risk Analysis[1] or ABRA to analyze the data and make effective recommendations. 



The primary purpose of ABRA is to quantitatively measure threats, assets, vulnerabilities, and risks associated with large and/or small government or private facilities.  It establishes a security baseline, explores upgrades, recalculates vulnerabilities and risks, and recommends optimized features or improvements for facilities.  In essence, ABRA identifies current levels of vulnerability and risk and then identifies improved levels with the implementation of specified countermeasures.  Basically, a snapshot of where the organization is today and where it could be after countermeasures are implemented.  In addition, ABRA identifies the associated cost and impact of the improvements.  ABRA includes the performance of six sub-analyses: threat, target, vulnerability, optimization, risk, and cost–benefit.

  

Threat Analysis



The treat analysis is based on information collected during the site visit.  The information produces a threat rating, which measures the threat likelihood (the probability an attack will occur), and an effectiveness rating (the probability that an attack will be successful).



ABRA takes into account the current local threat environment for five conditions; i.e., stand-off, explosive; covert, overt and chem/bio.  Although the project only called for the assessment of an active shooter threat, since we were already on site, it only made sense to conduct all five analyses.

The assessment team started the assessment asking a series of about 50 questions to the staff to further determine the asset’s criticality and threat environment.   Additional soft intelligence was collected via the internet and a clear threat picture emerged.

Target Analysis



The target analysis is designed to evaluate and measure the value of all targets to the user and to the aggressor.  Targets could include any type of asset or target including facilities, people, equipment, money, processes and systems.  The end result of the target analysis is a numeric rating based on the target value or criticality to the user and the target value or usefulness to the aggressor.



Vulnerability Analysis



Our vulnerability analysis is designed to quantitatively evaluate and measure how vulnerable a specific asset is to a specific threat. This phase of ABRA identifies the countermeasures currently in place for a specific target and is assigned a value based on their effectiveness in mitigating threats (Baseline Vulnerability Rating [BVR]).



Optimization Analysis



The optimization analysis is the reapplication of the vulnerability analysis after implementing hypothetical improvements resulting from countermeasures that could be used for a specific asset.  Hypothetical countermeasures could include programmatic or procedural options.  The end result is an optimized vulnerability rating (OVR) associated with the specific target being analyzed, in this case, a training facility.  Based on the optimization analysis, the average vulnerability and risk rating can be identified and stated as a percentage.



Risk Analysis



The risk analysis is the aggregation of the threat, target, vulnerability, and optimization analyses to determine the calculated value of risk associated with a specific asset that is being targeted by a specific threat.



Cost–Benefit Analysis



The cost–benefit analysis compares the potential results of specific countermeasures for reducing or mitigating threats against specific assets.  The cost–benefit analysis is based on cost versus reduction in vulnerability and risk.



MAKING RECOMMENDATIONS THAT WORK

Most risk analyst make recommendations that bring the facility up to code compliance or base solutions on costs.  The recommendations made during this assessment were made based on risk reduction and not costs.   Our analysis showed that all recommendations were either extremely or highly cost effective.  Those recommendations included four main or specific areas.

Inhabited Space Hardening

Windows – Replacing the existing exterior windows with 6 mm laminated or poly-bicarbonate glazing.

Walls – Retrofitting the walls with a ballistic resistant material and continuing that concept to other features.

Furniture – Retrofit any interior elements, such as, reception desk, student chairs, tables, white-board (basically, anything or anywhere a student could hide behind if they were unable to exercise their first option of running away).

Electronic Security Systems

Electronic Security Systems – Install integrated access control and surveillance (CCTV) systems.

Mass notification system – Install internal and external speakers, alarm signals and visual message boards.

Crime Prevention through Environmental Design (CPTED)

Natural Surveillance/Natural Access Control – Use landscaping to reroute pedestrian traffic entering the building, so that as people approach they are observed from within the building.

Plans, Policies and Procedures

Use internal resources/corporate expertise to update plans, policies and procedures

IN SUMMARY

The recommendations would be implemented in all areas of high occupancy or critical areas (inhabited spaces); i.e., training facility, staff offices, coffee/snack center and stairway.  It should be pointed out that normally stairways or other transit type spaces would not receive the same level of protection because they are usually considered to have low occupancy, but input from the ESVC indicated it to be mission critical and a single-point-failure location for their operations.

Bathrooms, storage rooms, print shop and garage were not recommended to be retrofitted with ballistic protection because of their low occupancy density (uninhabited spaces).

Overall the risk reduction to the active shooter threat was calculated at 84 percent.  In other words, the Delta if you will, from where the risk is today to where it will be when all of the recommendations are implemented.   If implementation of all of the recommendation in the report were accomplished the risk reduction of the other threat scenarios would be between 74 and 98 percent.  The total project costs, including the data collection, evaluation and analysis and implementation of all of the recommendations was Euro72,130 ($76,200).  If only the recommendations pertaining to ballistic protection from the shooting threat were adopted the costs would be Euro53,560 ($56,700).  Recommendations were also prioritized to be implemented based on risk reduction and protection to the largest number of people first, and to allow their implementation as funding becomes available.

In summary, that’s a very small amount to pay to protect the lives of students and staff.  The added protections afforded by the recommendations help reduce risk and provide safety from a host of criminal and terrorist activities.  

Zwart added, “The conclusions made were rock solid and provided clear vision of the budget choices we need to make in the years to come.  By using their proprietary formula, Haines Security Solutions was able to demonstrate the tangible risk reduction of their recommendations.  Something we’ve not seen in other assessment methodologies”. 
Making it a safe and secure environment for those attending training – after all isn’t that what it’s all about?


[1] Haines Security Solutions was awarded a 2017 Platinum level Government Security award in the Risk Analysis category for its Asset Based Risk Analysis (ABRA) methodology.  The GOVIE awards are presented by Security Today magazine to outstanding products that address security challenges within the municipal, government, Safe Cities and law enforcement markets.