Showing posts with label detetction. Show all posts
Showing posts with label detetction. Show all posts

Sunday, March 15, 2020



I Became a Meth Head, Won an Award and Am Now Recruiting Others


“Mom, tell him to stop”, I would hear that all the time from my son as he would tell his Mom I was obsessing over work.  I don’t hear that nearly as often now-a-days, not because I’ve stopped but because he doesn’t live with us anymore.  He’s in New York and we’re in California.  The other evening, while I was drying dishes, my wife said to me.  “You know you’re obsessed.  It’s like a drug for you”.  Perplexed, I said, “What do you mean?”  

“I’m telling you that the cat used the litter box and you’re telling me about bollards in Las Vegas”. 

OMG, she was right!  I can’t get it out of my system.  My every thought is about physical security design – both good and bad.  I’m always analyzing and comparing and thinking; does that work, is it effective, could they have done it cheaper or better?  My mind is on overdrive,  I had become a METHodology addict. 

My addiction was simple - use a proven assessment method to look at criticality, threats, vulnerabilities and subsequent risks of high occupancy buildings and their supporting energy systems.  I guess, that’s why I’m so fond of the Asset Based Risk Analysis (ABRA) and Critical Asset and Infrastructure Risk Analysis (CAIRA) methodologies (both Platinum Award winners; ABRA a GOVIE in 2017 and CAIRA an ASTOR in 2018).  Not because they won awards after having been recognized by teams of experts but because they take allot of the thinking out of the analysis process.  It’s pretty basic math and not allot of calculating.  It’s all already done with macros.  But, the final result answers the questions cited before, will the implemented security measure be truly effective in reducing risk, is there an alternative that can be just as effective and will it bring costs down to a reasonable price.


ABRA ARTICLE https://view.joomag.com/march-2019-ast-magazine-march-2019-ast-magazine/0952115001553308799/p4?short


CAIRA ARTICLE https://view.joomag.com/july-2019-ast-magazine-ast-july-2019-magazine/0612002001563068627/p60?short

Over the years, I’ve noticed that the best thing when it comes to thinking is not to start.  Once you get a thought, it seems to get out of control rather quickly.  “Kind of hard to put the genie back in the bottle”, as they say.  The thoughts just keep coming, no matter what I try to do.  So sorry, Honey, I can't turn it off.  

P.S.  I cleaned the litter box.

Sunday, February 16, 2020

Security - It Really is a T or F Question



I know many of you when you read the title thought, “Yep, security is a true or false question.  You’ve either got it or you don’t.  Well, purposefully I didn’t spell out what the T and F stood for. It isn’t true or false.

As many of you know, for some time now I’ve been advocating for a softer approach to security, especially when it comes to the design and layout of high-occupancy spaces.  And during my years of advocacy I’m come across some, who will agree, and others that play lip service and say, “Oh yea, that’s what we should do.”  And when they have their next opportunity to make the change they go back to their olds ways with the bigger, better, faster, stronger, in your face approach.
Recently, while collaborating with a local school district we took a softer approach.  After an active shooter threat (fortunately stopped prior to being carried out due to social media monitoring), parents wanted the District to heighten security by adding guards and cameras, and constructing fences on the perimeter.  They wanted this because that’s what they’ve been seeing on TV.  After every school shooting, there’s a rush to install more cameras, higher fences, and to hire more guards.  I don’t blame the parents; I blame the security companies who are selling their products with the idea that if one is good, two must be better – the more products sold the better for the bottom-line.  Some may argue that adding visible, in your face, deterrence works.  I’ll admit, there is some benefit; however, a dedicated threat will not be deterred – they will bring the tools necessary to circumvent whatever is in place. That said, we can argue until the cows come home about the benefits.  From my point of view, it’s not about effectiveness.  It’s about the psychological impact it has on our youth.  Recently, a local school board approved a bond for security upgrades.  The newspaper ran a picture of a ten foot metal fence gate to allow campus entry and mentioned that everyone would go through a metal detector.  I showed the article to a Latino friend of mine and he said, “They’re always looking at us like we’re all criminals.  The guys are in gangs and the girls are ‘ho’s.”  Is this the intended message?

Additionally, research shows us that “hardening” causes anxiety and even affects performance.  
https://network.aia.org/HigherLogic/System/DownloadDocumentFile.ashx?DocumentFileKey=110227d5-dde4-9c0d-fa52-a23257148cca


Our approach is to add security features that are “hidden in plain sight”.  For example, instead of a fence to keep out trespasser we suggest a buried co-axial cable sensor system.  It provides a warning that someone has breached the perimeter, yet is unseen.  Another example, to keep unauthorized folks off of the roof we suggest placing large flower pots with bougainvillea near drainage pipes or next to other features that a person could climb to get to the roof.   Again, a solution that is unseen.

My article published in American Security Today magazine January 2020 https://view.joomag.com/2019-champions-edition-2019-champions-edition/0683429001578075665/p148?short

So which message do we want to send?  The message that we don’t trust you and we think there will be an incident or the message that we trust you, we expect you to act trustworthy and you can expect the same of others?

My book, The Solutions Matrix: a  Practical Guide to Soft Security Engineering for Architects, Engineers, Facility Managers, Planner and Security Professionals has a Quick Glance Checklist that will allow you to list your current security solutions and then list your ideas on how to take a softer approach.  Order your copy today via the CONTACT US link at https://hainessecuritysolutions.com



Sunday, December 15, 2019


What Message Does Your Security Send – Fear or Trust?




In order to have proper physical security, mitigation strategist and those responsible must understand the types of aggressor groups, what motivates them and the tools they need in order to be successful.
  

Aggressors fall into four main categories: criminals (sophisticated/unsophisticated, organized/unorganized), protesters (organized/unorganized), terrorist (domestic/transnational/State sponsored) and subversives (intelligence agents [State/non-State sponsored]).


And, there are four main aggressor objectives; to inflict injury or death on people, to destroy or damage equipment, facilities or other resources, to steal equipment, material or information, and to create adverse publicity.


Tools on the other hand, don’t fall into any category and are virtually unlimited.


Unfortunately, the security industry has been approaching school security from the wrong angle.  We keep thinking, if one is good two must be better and we can harden our way to a perfect world.  We can’t.  School shootings and worse will continue, I’m sad to say, until we start eliminating the causes that promote this behavior. 


School systems have developed a variety of multi-disciplinary programs that address prevention and response to mental health issues if a student manifests behavior that might precipitate violence on a grand scale; i.e., bullying, addiction and interpersonal violence.  But this is still not enough.

Some security companies offer “social media behavioral monitoring” and are analyzing a person’s social media presence in “real time” and reporting actionable intelligence of patterns or suspicious behaviors to authorities, but this alone isn’t enough.  Using artificial intelligence, and deep learning are great but they’re just another tool.   And, just because a person manifests some type of anxiety or disruptive behavior it doesn’t necessarily mean they’ll act out and it doesn’t mean that that person will become a school shooter.


I believe we need to get to the cause of the angst.  Why does a “perfectly normal kid” decide to go to a school and shoot it up?  Does the “prison look” of many schools contribute to this phenomenon?  Is it possible, that the chain-linked fence surrounding the school yard, the metal detector that everyone passes through and the roaming armed guard all contribute in some way?  Now, just because that has become the “new normal” it doesn’t mean every kid will grow up and commit a criminal act, but there is no doubt that they will carry this angst with them into adulthood.


You don’t have to look very far to see examples of the “big dog” in your face approach and the subliminal message of something bad is expected to happen.  

We can address behavior in the built environment in a non-traditional way as a substitute to the confrontational in your face kind of way.  The approach must be more subtle, in fact, the more transparent it is the more effective it will be.  

Normally, to deter crime, we put up signs that say, “Cameras in Use” and some folks get creative saying, “Smile you’re on camera”.  For access control, we usually mark our territory by placing a chain-linked fence or some other type of “barrier” on our boundary-line.  It has a limited effect because a dedicated threat will bring the tools needed to circumvent it.  Build a big fence; they’ll bring a bigger ladder.  Make it even higher and they’ll bring an even bigger ladder or tunnel under it.  Sure, there is somewhat of a deterrent, but the reality is, a dedicated “bad actor” will bring the tools needed in order to be successful.   


In the early “90’s, Crime Prevention through Environmental Design was introduced to connect these two worlds – unwanted behavior and a physical deterrent.  Research shows that the concepts of natural surveillance, natural access control, territorial reinforcement and maintenance contribute to the deterrence and reduction of criminal activity.  CPTED is not the sole reason, but it helps. https://www.cptedtraining.net/


The basic concept of CPTED is if we can design the space so that it is almost always under observation “bad actors” won’t act bad.  I believe it needs to go further than that.  Not only do we need to design the space using these concepts, but we also must design the space so that “bad acting” can’t occur.  Additionally, in the off chance it does the built environment should help to reduce its effects and not contribute to its severity.  


A couple of years ago researchers in the European Union conducted a survey.  They asked elementary school kids who had emigrated from a country where there was war to draw what they considered safety or security to be.  The kids drew pictures of fencing with razor-wire and “gunships” overhead.  Then the researchers asked the same question to kids from Europe who had not be exposed to hostile environments and those kids drew houses with trees, stick families, a dog and sunshine.  Shouldn’t we be striving for the “sunshine” scenario?


The harder we make it for the “bad guy” to do things the more of a deterrent there is.  There is some truth to that but on the other hand, if security is a tax your people won’t pay it and they will figure out a way to circumvent it.  This in turn defeats its purpose.


Getting away from hardening schools after every incident by using “big dog” philosophies will take time, nonetheless, we can begin immediately.  I submit that beginning this school year, administrators should use the checklist provided by the Partner Alliance for School Safety (PASSK-12) www.PASSK12.org to conduct a physical security risk assessment of their campus and whenever possible replace traditional mitigation solutions they would normally opt for with a hardscaping, landscaping or art strategy.  Creativity and student, staff and community involvement are essential.


Success in security is sloppy.  It’s entangled.  It’s very hard to distinguish where detection, assessment, policy and procedures, response and engagement begin and end.  Addressing behavior must be coupled with addressing the physical environment.  They require a different amount of time, effort and commitment to produce positive results but nonetheless are equally important.  In order for students, and later as adults, to thrive we must create environments, internal and external, that address the need for “well-being” in both the social and physical ecosystems, and if we can do that in a more aesthetically pleasing way, then why not?

More about a softer approach to security: https://www.securityindustry.org/2018/04/05/the-puppy-movement/

My Book The Solutions Matrix: A Practical Approach to Security Engineering for Architects, Engineers, Facility Managers, Planners and Security Professionals is on sale at https://www.hainessecuritysolutions.com  

Haines Security Solutions is a contributor to the Security Industry Association’s education platform, “Center of Excellence” at https://www.securityindustry.org/center-of-excellence/

Sunday, October 20, 2019

Go Where there is No Path. But, I Can't, I'm Afraid of Snakes


A few months ago, my wife and I were shopping and came across this saying on a night shirt, “Go where there is no path”.  When I showed it to her, her reaction caught me a little off guard.  She said, “I can’t I’m afraid of snakes”. And, of course, being the person I am, I immediately translated that into a language I can understand – security-ish.  My first thought was, that explains why people don’t conduct risk analysis or even more importantly why they don’t even start the process.  They don’t tread into uncharted territory because there are snakes hiding in all that tall grass, so they stay where they’re comfortable – on the path.  Doing what is comfortable causes two problems.  

First, as Defense Secretary Don Rumsfeld, said, “We don’t know what we don’t know”, which translates into, we’re only protecting ourselves against what we can see, expect and believe is likely to occur.  Since, we don’t know what we don’t know, we’re not planning on dealing with its affects either.  This can be extremely more sinister because a lack of action could result in someone getting seriously injured or worse.  

Fortunately, there are methodologies out there that can get rid of the snakes.  I’m consulting on security matters with a local school district.  During our initial meeting, the District Superintendent, said, “Okay, where do we start? With an assessment to see where we are?”  Absolutely! 

Risk management is about managing risks.  In order to do that, you have to accept five factors:
1) You can’t prevent or deter everything
2) Protection from one threat may allow for some protection against another unrelated threat
3) Protection options must be in place before the event occurs
4) Risk Management must address the following pillars; detection, assessment, plans and procedures, response and engagement
5) Risk management and the assessment process is continual and is just part of what we do.

For ways to tame the snakes, read related articles here:



Sunday, September 15, 2019


How Preventing the Wrong Threat Will Cost You




My nephew used to work for an IT company.  Upon returning to work after Christmas holiday, they noticed that the rear windows of the building had been broken and all of the computer equipment had been stolen.  The owner of the company did what anyone would do.  He called a security consultant. 

The consultant recommended fixing the windows, adding motion sensors in the hallway and an access management system at the main entrance.  


When the company employees returned after the Easter weekend, they noticed the rear windows had been broken out – again, and all of the computer equipment had been stolen – again. 


Why did this occur?  The security company had misanalysed the Design Basis Threat or DBT.  

Everything of value has a threat that goes with it.  If it has value then someone wants it - either the owner or someone else.  It is also possible that a treat can be naturally occurring, like a earthquake or tornado. Usually, protection from these types of threats are governed by ordinances or laws; i.e., earthquake or tornado protection in construction standards.  For man-made threats, on the other hand, there really isn't any legislation that governs prevention or protection, so it's up to us to focus on man-made threats.  There are four general categories of aggressor types; 1) criminals (sophisticated/unsophisticated and organized/unorganized), 2) protestors (both organized/unorganized), 3) terrorist (domestic/trans-national/state-sponsored, and 4) subversives (saboteurs/foreign intelligence agents).  Each type of threat has an Modus Operandi or tactic and tool it uses to execute its objective.  If you make a list of what those may be you can actually design the space so that it provides protection to the things of value inside.  It is also important to understand the objective of man-made threats, too.  They fall into one or more of these categories; 1) inflict injury or death to people,2) destroy or damage property, equipment or resources, 3) steal equipment, material or information, or create adverse publicity. Understanding the motives, the tactics and tools they use will go a long way in prevention and protection.

The solution the security company had provided failed because, they didn't address the correct DBT; which was, breaking and entering and not unauthorized access.  Although, entering through the window is a form of unauthorized entry.  They had recommended the solutions they normally would suggest to deter or reduce the effects of theft, and focused on electronics, but they hadn’t addressed the DBT of the windows being breakable in the first place and didn’t add non-electronic solutions to the mix.  Had the windows been replaced with laminated glass they would not have been able to be broken and then the other countermeasures would have been effective.  Another solution would have been to prevent access to the parking lot behind the building.  I don't prefer this method because it would be more aggressive and unsightly to use a gate or fence with gate.  Just replacing the windows would not have changed the aesthetics of the space, so that is my preferred solution.

More about non-aggressive/aesthetically pleasing security measures can be found here: https://www.securityindustry.org/2018/04/05/the-puppy-movement/

Sunday, June 16, 2019


Case Study: Unimpeded Access Allows Illegal Dumping

The issue was that people were driving up to the banks of a stream and dumping trash; i.e., tires, mattresses, rubbish, etc.  The city called a security consultant.  And as expected, he recommended adding a camera to the site so that “things” could be monitored.  The camera fed back to the superintendent’s desk.  Of course, when the supervisor wasn’t there (weekends, evening/late at night, attending meetings, lunch, naps, etc.), all the time when someone would dump trash the dumping occurred and continued.  The superintendent was scratching his head on what to do.  After all, he just spent several thousands of dollars on the latest technologies and they didn’t seem to work.
Our solution was not electronic.  Instead, we suggested that they build a raised berm/curb using natural landscaping (trees/boulders/bushes, even park benches) so that the vehicle couldn’t drive up to the water’s edge in the first place.  We suggested specific landscaping strategies due to low cost and ability to prevent vehicles from reaching the stream.   We imagined that since the culprits couldn’t physically access the stream embankment without using a vehicle they would be  less likely to want to carry heavy objects from the roadway, across a bicycle/walking path and then into the wood clearing to reach the stream.  Our second reason was to ensure the aesthetics of the area were kept intact.  Sure, we could have suggested a fence along the embankment to deny access and achieve the same effect, but who wants to walk along a fence with barbed wire when they’re taking the dog out or jogging or cycling.
Related articles: 

Sunday, March 17, 2019


YEP – IN SECURITY WE STILL NEED TO OCCUPY THE GROUND, WE CAN’T LEAVE IT ALL UP TO ELECTRONIC TECHNOLOGIES 



Despite the advances in electronic security technologies one fact remains, we (“the good guys”)still need to occupy the ground.

As many of you know, I’m a former Air Force Security Policeman – a blue grunt, if you will.  So consequently am a little partial to “zoomies” when it comes to the defense of the country.  Our strike capabilities are so sophisticated that we really don’t need the other services (now, don’t get your knickers in a twist and let me explain).  We could just bomb the hell out of the bad guys until they surrender.  But bombing the hell out of them doesn’t do anything for us, because in the end we still have to occupy the ground.  And that’s why the Air Force is just not enough.

The same holds true in the security business.  Everyone is moving towards electronic technologies and the advances in predictive behavioral analyses and other artificial intelligence (AI) technologies is “mind blowing”.  
In the ‘80’s we posted guards, in the ‘90’s we put cameras because guards became expensive and since that time we’ve been using analytics to understand better what we are observing.  With the technologies that are currently “off the shelf” we can do allot more than we used to be able to do.  We can have one guard monitor several cameras and with analytics s/he uses can monitor even more as the software interprets what it’s seeing and notifies those responsible when something is amiss.

This is all well and good, but electronics can’t do it alone.  We still need to “occupy ground”.  By that I mean we need to design the built environment so that it complements the technology we use.   The use of non-electronic technologies will become even more important in the future, and especially in the urban environment.

The city of New York employs thousands of cameras around the city but they also deploy thousands of beat officers.  Both rely on each other to enhance the other‘s effectiveness.  If a patrolman sees something, she/he can have a colleague at the central station bring the field of view into focus and zoom in.  And by looking at adjourning screens or from different angles maybe get a clearer picture of what is happening.  Likewise, if the monitor sees something suspicious, he/she can dispatch a patrol to investigate further and cover those areas that the camera can’t see.

So with the utmost respect, we still need the grunts.

Sunday, February 17, 2019

What the LA Ram Superbowl Game Plan Teaches Us about Home Security


What the LA Rams Superbowl Game Plan 
Teaches Us about Home Security





First, I have to admit I had hoped the Rams would win the Superbowl.  It would have made my blog sound allot better.  I could have boosted about how Sean’s crew had analyzed their adversaries and implemented the perfect countermeasures and protected the home front (after all they were the home team).

Then secondly, I admit I’m not a football buff and understand everything about the do’s and don’ts of the game.   But I can with confidence make some comparisons and analogies that I believe most of us can understand.

So, anyway, congratulations to the New England Patriots on their win.

The more I think about it the more I realized that the Rams loss actually teaches us more about sizing up the threats than I first thought.  It teaches us, that not only do we have to look at the attacking forces from our perspective but we also must consider how they see themselves and will adjust.

In security design, we call this the design basis threat or DBT.  In other words, what you’re trying to protect your asset (thing of value) from – whether it’s a natural threat; such as, wind, fire,  rain or a man-made threat; like, graffiti, burglary or theft of property.

The Rams coaching staff had to analyze what the Patriots were capable of (their modus operandi [MO] and then figure out how thwart it.  They also needed to formulate a plan that covered the entire field.  In essence, defense in depth – the front line, the linebackers, the safeties.  We’ve all heard, “The best defense is offense”.  How true.  Ask the Patriots.

Unless, you have a comprehensive plan for the protection of your home, the attacker, be it a burglar, tagger, etc. will circumvent your security by finding the weak spot and exploiting it.  Remember, just having a security camera or system is not enough.  You have to have security built in to every facet of your daily routine. 

For home security that starts with your on-line social media presence.  Don’t give too much information away.  I laugh when I think that someone couldn’t believe she was robbed while in Paris.  Like duh, if you brag about how expensive the stuff is that you have there’s a very strong likelihood that someone also sees the value and will try to take it from you.  There was a case this week in Los Angeles were a rapper was flashing a big wad of cash and posted it on social media.  Well, guess what, he got robbed. 

Next, are you doing other things that tip off those with bad intention?  Do you put boxes out on the curb the night before the trash truck comes by?  Do you put papers in the trash that someone could take out under the cover of darkness and open-up credit card accounts in your name?  When you got that big screen to watch the Superbowl on, did you mount it on the wall so that someone walking on the sidewalk in front of your house could see it through the window?

Your plan has to be comprehensive.  It covers not only what you do but also where you do it.  Start from the roadway and work your way inward, assessing what the bad guy is able to see.  Make sure all lights work and all gates, windows and doors lock.  We lock our car even when it’s parked in the garage and the door from the garage into the house.  These little things delay the perpetrators actions and may possibly give us enough time to call 911.

I few years ago, I posted that the best home security system is actually a plate of cookies.  I still believe that, if you take some freshly baked chocolate chip cookies to the neighbors.  They’ll thank you for them and inadvertently watch out for your stuff because now they think they owe you.  

Maybe if the Rams would have taken some cookies to the Patriot’s locker room before the game things would have turned out differently.

Sunday, January 20, 2019


The Truth About Walls (Fencing)




A few years ago, I was asked by the editors of Security Middle East magazine[1] to write an article about perimeter security.  During the conversations with the editor that lead to the eventual article, she asked me to summarize what the article would be about.  I told her that in order to understand perimeter security you first needed to accept the fact that if you have a ten-foot fence the bad guy will bring an eleven-foot ladder. 



The idea that you can build a fence or wall and keep the bad guys out faded out sometime after the medieval ages when new technologies and new ways of conducting warfare came about.  Well, the same holds true today.



If you look up on Google the difference between a wall and a fence you’ll get the following explanation: “A fence is usually a wooden or metal structure that encloses a yard, pasture or other area…The difference between a fence and a wall is that you can almost always see through a fence, at least to some degree, while a wall is solid”.



If you look up fence purposes, you’ll get the following explanation; “A fence is a structure that encloses an area, typically outdoors, and is usually constructed from posts that are connected by boards, wire, rails or netting.  Alternatives to fencing include a ditch (sometimes filled with water, forming a moat)”.



Both definitions suggest that a boundary is formed between property that is not controlled and property that is controlled. 



Whether using a wall or fence, the purpose is to delineate a boundary; usually at a property boundary.  This is the true meaning of fencing or "walling", if you will.  To delineate property boundaries, in other words, you’re over there and I don’t care what you do but it you come over here you need to go down to the access point so I can check you out.  With that in mind, you could paint a line on the ground and put up a sign that says, “stay out or go over there for access”.  Both would achieve the same effect as a wall of fence.  So, why not just paint a line.  Because the value in constructing a fence or wall, is 1) to identify the boundaries of the controlled space, 2) to cause a delay in unauthorized access, and 3) to identify unwanted behavior.  An authorized person will not climb over a fence or wall, tunnel under it or cut through it.  An unauthorized person will, especially if they have nefarious intentions.  So, with that in mind, the fence serves an early warning system.  It tells us when someone breaches it that they have  “bad intentions”.  If they didn’t, they would not breach the fence/wall and would proceed to an access control point to display the proper credentials to gain entry.  Hopefully, the fence will be constructed in such a way as to delay their unauthorized access.  Sadly, even without tools a eight foot chain link fence with three strand barbed wire outrigger can be scaled or climbed over in about four seconds.  With tools, like a ladder or a truck to stand on it takes even less time.



Which brings us to the next truth, unless there is a guard or technology monitoring the fence-line in real time, we have no way of knowing if the boundary has been breached.  We must monitor for unauthorized access, respond to it, and engage the aggressor in real time.  The operative word here is “real time”.  If we don’t what’s the use?



Another thing to remember, no matter how solid, sturdy, high or how many bells and whistles are added, there will always be a way to circumvent whatever is put in place.  The key is, making sure there is enough time to delay the “bad guy or gal” so that his or her behavior can be identified and the “good guys/gals” have time to respond and engage.





[1] Security Middle East magazine article More Power to the Perimeter link https://issuu.com/securitymiddleeastmagazine/docs/sme_july-_aug_2015_web?e=0/14330179

Sunday, November 18, 2018

Architects Meet Security Halfway

Architects Meet Security Halfway
What Should They Do to Go All the Way? 


The normal process for building or inhabited space design goes something like this:  the client goes to the architect and describes his/her vision.  The architect interprets that vision using their creative juices.  That’s a good thing! Once the client approves the vision then project is handed over to an engineering firm to “build the guts”. Once the infrastructure is done and the project is finalized.  The client accepts the project.  At that point, it’s up to the client to coordinate the security features of the designed environment.

Sometimes, this process works.  But more often than not, it doesn’t for a very simple reason.  Everyone sees the project differently.  The first questions the architect asks the client is how many people, what type of space (open/shared/closed offices, how many floors, etc.?  During that conversation there should be questions asked that regard the Design Basis Threat; i.e, what types of threats are we trying to protect against? This particularly the case when it comes to man-made threats; such as, active shooter, hostile vehicle, insider threats.  Natural threats to buildings and people are usually governed by ordinances or codes; fire, earthquake, high winds, etc.  Man-made threats on the other hand are not usually governed by ordinance.

That said, when understanding man-made threats it is important to identify several keys elements of the threat:
1) Types of aggressors threats (covert or overt, group or individual, organized or not)
2) Aggressor motivations or objectives (inflict injury or death, damage or destroy property, steal equipment or materials, and create adverse publicity)
3) Aggressor tactics (both the modus operandi and the tools needed to be successful)

Unfortunately, these elements are usually left up to the security consultant towards the end of the project.  If they were considered during the initial 15% phase or 35% phase of the project, it could easily accommodate countermeasures that mitigate these identified threats purely by designing the space to do just that while still maintaining functionality and aesthetics.

The Department of Defense, Department of State and Veteran’s Administration mandate that a security representative be part of the design team from the very beginning.  The civilian world should follow suit, instead of the current halfway method.

Other trends in the built environment are discussed here:
Security Industry Association Technology Insight, Spring edition

Security Industry Association Technology Insight, Fall edition



Sunday, October 21, 2018

The 310 Year Gamble


The Federal Government’s 310 Year Gamble on Your Child’s School Safety






In the days following the Parkland High School shooting, my emotions were out of control; first, because of the lack of “adult” leadership by the Federal government officials and secondly, because when called out by the high school’s young adults they (politicians) attacked the teens.  Whenever asked about how they intended to keep another active shooter event from happening they hid behind thinly veiled comments about how it was someone else’s responsibility to address the causes and fix them.



Let’s be realistic, it’s about guns, it’s about mental help, it’s about a person’s desire for fame, it’s about lack of protection, it’s about lack of designed evacuation routes and the list goes on…  Some causes can be fixed in the short term and others, like mental health issues will take many years to devise systems that are effective in identifying “at risk behaviors” and getting the person the proper treatment.  We also need to address the way schools are designed not only should they be great environments for learning by they must also be safe.  One example is there should always be two ways to egress a space in an emergency.  Currently, many times there is only one and if there are two, they lead into the same hallway.



So, in the meantime, if students and faculty are going to be taught to “hide” in the back of the classroom then the space must provide ballistic protection.  If it doesn’t, the AR-15 bullet will travel through the hallway locker, drywall or classroom furniture.  I thought, if we don’t have specific ballistic protection in place couldn’t we design a system similar to have hotels create additional space by mobile walls.  I reached out to my friends at Amulet Ballistic Technologies and come up with a design for retrofitting existing classrooms or new construction.



In 2018, the Federal government allocated $100 million for security upgrades to schools.  The deadline for application to receive some of that money was 31 July 2018.  If your school district didn’t apply, it for sure won’t get any of the money, so you’ll have to wait until next year.  Fortunately, many State legislatures have been setting aside funding and the process seems to be continuous.

Another unfortunately circumstance when it comes to funding is that most of the money will go to hiring school resource officers (RSO) from the local sheriff or police department.  Placing an armed guard is not in of itself sufficient.  While it will help deter possibly, the truth is if a RSO is present he/she will become the first victim and/or will not be where the shooting starts when it starts.  Another key security feature will be electronic surveillance and access control.  Both are useful and effective but have their limits as well.  Cameras must be monitored in “real-time” AND a response must be immediate.  Access control is only effective if it doesn’t become a burden to day-to-day operations.  If it becomes “taxing” people will figure out how to get around it.  

Now, back to $100 million per year for the next 10 years ($1Billion total).  There are an estimated 50.2 – 58 million students in America’s schools.  The average class size in the US is somewhere between 17 and 26, so let’s just say 20-22 students.  If we divide the average size class occupancy into the lower number of total students that tells us we have about 2.5 million classrooms (give or take).  Now, if the average cost of constructing or retrofitting one classroom with ballistic protection is $15,000 (I suspect that once we get going the costs will be lower and more likely to be about $10-12k for a classroom of 20 using the Department of Homeland Security recommended square footage for safe-haven/shelter space occupancy.) then it will take $3,750,000,000,000 to retrofit all existing classrooms.  At one billion every ten years that will be 375[1] years to protect every classroom in the US.

Let me put that into context.  Most people think that during the 2008 financial crisis[2], the treasury department used $700M to save the banks.  This is not true.  The Special Inspector General for the Troubled Asset Relief Program (TARP) in their summary report says that the total commitment of the government is $16.8 trillion with about $4.6 trillion already paid out.

According to a team at Bloomberg News, at one point last year the U.S. had lent, spent or guaranteed as much as $12.8 trillion to rescue the economy.[3]

In either case, more than enough to protect America’s kids in less than 10 years instead of over 300. 

Sunday, July 15, 2018


Using Landscaping to Control Access




I want to tell you about two incidents that required a security solution and how the first attempt at providing an adequate solution failed miserably.

First case – illegal dumping

The issue was that people were driving up to the banks of a stream and dumping trash; i.e., tires, mattresses, rubbish, etc.  The first solution provided added a camera to the site so that “things” could be monitored.  The camera fed back to the superintendent’s desk.  Of course, when he wasn’t there (weekends, evening/late at night, attending meetings, lunch, naps) the dumping occurred and continued.  The superintendent was scratching his head on what to do.  After all, he just spent several thousands of dollars on the latest technologies and they didn’t seem to work.

Our solution was not electronic.  Instead, we suggested that they build a raised berm/curb using natural landscaping (trees/boulders/bushes, even park benches) so that the vehicle couldn’t drive up to the water’s edge in the first place.  We suggested landscaping due to the ability to prevent the vehicle from reaching the stream.  We imagined the culprits wouldn’t want to carry the heavy objects from the roadway, across a bicycle/walking path and then into the wood clearing to reach the stream.  Our second reason was to ensure the aesthetics of the area were kept intact.  Sure, we could have suggested a fence along the embankment to deny access and achieve the same effect, but who wants to walk along a fence with barbed wire when they’re taking the dog out or jogging or cycling.

Second case – unwanted access to school property

The issue in this case was that community members were cutting across school grounds in order to shorten the distance to retail shops located near the school campus.  The first security company suggested erecting a chain-link-fence with 3-strand barbed wire outrigger around the entire campus perimeter with a gate for buses and parents/administrators.  When not in use the gate would be kept locked.  The administrators weren’t buying it.  What if a student climbed the fence and was injured?  And where were they going to get the manpower to manage the gate? 

Our solution was to construct on three sides a wooden split-rail fence approximately 4 feet high (similar to those used in the Atlantic Piedmont region) and then to place flower beds in front of the fence and thorny shrubbery and trees behind it so that it would be difficult to cut through.  The front of the campus was left open.  We also suggested installing "speed cushions" to allow just buses to enter the "drive up/drop off" area.  And to have a separate loading/unloading zone for the parent's cars, that would be controlled by school staff.  These solutions provided the aesthetic qualities the administrators were looking for.  We also suggested changing procedures but I don't want to give too much away here.  Needless to say a comprehensive change was needed to address the concerns of the school.

These are just two examples of how not all security solutions need to be electronic.  Unfortunately, surveillance companies will tell you that CCTV is the solution to everything.  The reality is it isn’t.  In both cases we used “natural access control” (Crime Prevention through Environmental Design [CPTED]) as a fundamental principle in our approach to reducing crime.

Additional CPTED ideas and other principles on deterring crime and the effects of terrorist attack will be discuss during a 3-day workshop, Designing Secure Buildings: Integrating Security Technologies being held in New York City, 11-13 Sep 18.

Our ROI Toolkit is available.  The Toolkit will help you justify to your boss why you need to attend this training.

Contact us at info@hainesssecuritysolution.com or call +1 805 509-8655 to register.

Visit us at https://hainessecuritysolutions.com/Training to find out about other classes we offer or to host a workshop. 

Sunday, February 18, 2018


The Marriage of Cyber and Physical Security is Not a
Match Made in Heaven








Megatrend #2 from Security Megatrends, The 2018 Vision for the Security Industry, produced and published by the Security Industry Association (SIA) is, “Cyber Meets Physical Security, Threats Magnify with Digital Innovation[1]  hits the proverbial nail on the head.   With the connectivity of electronic devices to the internet, more and more of the different technologies we use in our daily lives are susceptible to compromise.  I read an article about a year back that talked about how in theory your new toaster could get hacked by someone with nefarious intentions and through that connectivity could steal your personal identifying information (PII).  While I believe that scenario to be a little far-fetched, I do believe the point was made.  The point being, that my smart phone, smart TV and even my smart refrigerator, especially if I had it set up to automatically order milk or bread for me directly with the store, is highly susceptible since I would most certainly have payment information in my stored profile.

The connectivity to the IoT is inherently vulnerable.  Since there’s an electronic connection, eventually given enough time, a “bad guy” will figure out a way to breach whatever security systems are in place.  Just ask Equifax, Sony Pictures, Target, etc.

The only absolute way to keep a breach from happening is not to connect to the IoT.  Unfortunately in today’s world that is just not possible.  We cannot function without being connected.  Now even my wife’s Jeep’s telling her she need servicing, before it was, “Hey, Honey, there’s a red light on on  the dashboard.  What’s that mean? “  Now, she gets a message on her phone that tells her  the tire pressure’s too low.

This convergence of cyber and physical means that physical security must be much tighter than it’s been in the past.  We can’t rely on the good guys to build a strong enough firewall, while vitally important, equally important is the physical security piece.  We need to teach our folks and ourselves how to spot vulnerabilities and how to protect those vulnerabilities from being exploited in a language they can understand.  I know a software engineer and whenever I talk with him, I have no idea what he’s talking about.   Listen if it’s a burden – I can’t understand it – I won’t do or use it. 

The vetting process, to ensure the right folks are working on our systems has to be comprehensive and continual.  Just because a person gets the job, it doesn’t mean the vetting process stops.  The vetting process must be continuing.  Physical security measures must also make sure that only people that have been cleared can physically access systems that they’ve been cleared for and not have a general run of the place.   I believe the DIY days are over.  Sure, there are some things any person should be able to do, like follow the tutorial on setting up a TV but other things that are in the Settings should probably be left up to an expert to change.  There is a tremendous assumption that just because I can read I can also understand the code being spoken.

Cyber security focuses on cyber-threats and the ability to detect and mitigate ransom ware attacks, especially as they’ve become a popular mechanism to extort businesses, will become more and more important.  I’m beginning to understand less and less about computers, how they work and what they can do to make my life simpler, because I have to do more and more of what use to be done by that weird guy down the hall.

I’m not sure I’m ready to have a micro-chip make all of the decisions of my daily life for me.  I have a feeling, it’s going to be a “rocky” marriage because I can't divorce her.
Next month:  If Data is the New Currency of the Modern World Then Why Is My Account Overdrawn?