Showing posts with label natural threats. Show all posts
Showing posts with label natural threats. Show all posts

Sunday, March 15, 2020



I Became a Meth Head, Won an Award and Am Now Recruiting Others


“Mom, tell him to stop”, I would hear that all the time from my son as he would tell his Mom I was obsessing over work.  I don’t hear that nearly as often now-a-days, not because I’ve stopped but because he doesn’t live with us anymore.  He’s in New York and we’re in California.  The other evening, while I was drying dishes, my wife said to me.  “You know you’re obsessed.  It’s like a drug for you”.  Perplexed, I said, “What do you mean?”  

“I’m telling you that the cat used the litter box and you’re telling me about bollards in Las Vegas”. 

OMG, she was right!  I can’t get it out of my system.  My every thought is about physical security design – both good and bad.  I’m always analyzing and comparing and thinking; does that work, is it effective, could they have done it cheaper or better?  My mind is on overdrive,  I had become a METHodology addict. 

My addiction was simple - use a proven assessment method to look at criticality, threats, vulnerabilities and subsequent risks of high occupancy buildings and their supporting energy systems.  I guess, that’s why I’m so fond of the Asset Based Risk Analysis (ABRA) and Critical Asset and Infrastructure Risk Analysis (CAIRA) methodologies (both Platinum Award winners; ABRA a GOVIE in 2017 and CAIRA an ASTOR in 2018).  Not because they won awards after having been recognized by teams of experts but because they take allot of the thinking out of the analysis process.  It’s pretty basic math and not allot of calculating.  It’s all already done with macros.  But, the final result answers the questions cited before, will the implemented security measure be truly effective in reducing risk, is there an alternative that can be just as effective and will it bring costs down to a reasonable price.


ABRA ARTICLE https://view.joomag.com/march-2019-ast-magazine-march-2019-ast-magazine/0952115001553308799/p4?short


CAIRA ARTICLE https://view.joomag.com/july-2019-ast-magazine-ast-july-2019-magazine/0612002001563068627/p60?short

Over the years, I’ve noticed that the best thing when it comes to thinking is not to start.  Once you get a thought, it seems to get out of control rather quickly.  “Kind of hard to put the genie back in the bottle”, as they say.  The thoughts just keep coming, no matter what I try to do.  So sorry, Honey, I can't turn it off.  

P.S.  I cleaned the litter box.

Sunday, October 20, 2019

Go Where there is No Path. But, I Can't, I'm Afraid of Snakes


A few months ago, my wife and I were shopping and came across this saying on a night shirt, “Go where there is no path”.  When I showed it to her, her reaction caught me a little off guard.  She said, “I can’t I’m afraid of snakes”. And, of course, being the person I am, I immediately translated that into a language I can understand – security-ish.  My first thought was, that explains why people don’t conduct risk analysis or even more importantly why they don’t even start the process.  They don’t tread into uncharted territory because there are snakes hiding in all that tall grass, so they stay where they’re comfortable – on the path.  Doing what is comfortable causes two problems.  

First, as Defense Secretary Don Rumsfeld, said, “We don’t know what we don’t know”, which translates into, we’re only protecting ourselves against what we can see, expect and believe is likely to occur.  Since, we don’t know what we don’t know, we’re not planning on dealing with its affects either.  This can be extremely more sinister because a lack of action could result in someone getting seriously injured or worse.  

Fortunately, there are methodologies out there that can get rid of the snakes.  I’m consulting on security matters with a local school district.  During our initial meeting, the District Superintendent, said, “Okay, where do we start? With an assessment to see where we are?”  Absolutely! 

Risk management is about managing risks.  In order to do that, you have to accept five factors:
1) You can’t prevent or deter everything
2) Protection from one threat may allow for some protection against another unrelated threat
3) Protection options must be in place before the event occurs
4) Risk Management must address the following pillars; detection, assessment, plans and procedures, response and engagement
5) Risk management and the assessment process is continual and is just part of what we do.

For ways to tame the snakes, read related articles here:



Sunday, September 15, 2019


How Preventing the Wrong Threat Will Cost You




My nephew used to work for an IT company.  Upon returning to work after Christmas holiday, they noticed that the rear windows of the building had been broken and all of the computer equipment had been stolen.  The owner of the company did what anyone would do.  He called a security consultant. 

The consultant recommended fixing the windows, adding motion sensors in the hallway and an access management system at the main entrance.  


When the company employees returned after the Easter weekend, they noticed the rear windows had been broken out – again, and all of the computer equipment had been stolen – again. 


Why did this occur?  The security company had misanalysed the Design Basis Threat or DBT.  

Everything of value has a threat that goes with it.  If it has value then someone wants it - either the owner or someone else.  It is also possible that a treat can be naturally occurring, like a earthquake or tornado. Usually, protection from these types of threats are governed by ordinances or laws; i.e., earthquake or tornado protection in construction standards.  For man-made threats, on the other hand, there really isn't any legislation that governs prevention or protection, so it's up to us to focus on man-made threats.  There are four general categories of aggressor types; 1) criminals (sophisticated/unsophisticated and organized/unorganized), 2) protestors (both organized/unorganized), 3) terrorist (domestic/trans-national/state-sponsored, and 4) subversives (saboteurs/foreign intelligence agents).  Each type of threat has an Modus Operandi or tactic and tool it uses to execute its objective.  If you make a list of what those may be you can actually design the space so that it provides protection to the things of value inside.  It is also important to understand the objective of man-made threats, too.  They fall into one or more of these categories; 1) inflict injury or death to people,2) destroy or damage property, equipment or resources, 3) steal equipment, material or information, or create adverse publicity. Understanding the motives, the tactics and tools they use will go a long way in prevention and protection.

The solution the security company had provided failed because, they didn't address the correct DBT; which was, breaking and entering and not unauthorized access.  Although, entering through the window is a form of unauthorized entry.  They had recommended the solutions they normally would suggest to deter or reduce the effects of theft, and focused on electronics, but they hadn’t addressed the DBT of the windows being breakable in the first place and didn’t add non-electronic solutions to the mix.  Had the windows been replaced with laminated glass they would not have been able to be broken and then the other countermeasures would have been effective.  Another solution would have been to prevent access to the parking lot behind the building.  I don't prefer this method because it would be more aggressive and unsightly to use a gate or fence with gate.  Just replacing the windows would not have changed the aesthetics of the space, so that is my preferred solution.

More about non-aggressive/aesthetically pleasing security measures can be found here: https://www.securityindustry.org/2018/04/05/the-puppy-movement/

Sunday, August 18, 2019


The Need to Push Down Silos





A few years ago, a friend of mine, trying to generate additional students for the classes I teach, asked his cousin who works for a very large architecture and engineering firm in the new World Trade Center in New York City, if they would be interested in attending training on integrating security technologies into building design.  His cousin answered something to the effect, “No, we leave that up to the client after we turn the building over to them”.  While his cousin’s answer is not surprising it is disappointing and confusing to me. 



Not surprising because I’ve heard that so many times before.  In essence, everyone stays in their silo and the connection between the disciplines usually only involves answering questions about the project and clarifying requirements; architects architect – engineers engineer – and security securities, if you will.



It’s confusing on two levels.  First, at the beginning of every project the architect gets the client’s desires list; i.e., the building should be blah, blah, blah. Right from the start the architects develop a mental picture of what the building should look like.  Next he or she begins to include all of the regulatory requirements or “best practices” for design.  Best practices are nothing more than this is how it’s normally done.  In New York City, for multi-story buildings in Manhattan the façade default material is glass in the Mid-West it is reinforced concrete or masonry units.  Meeting regulatory requirements deal with disability act, fire and safety codes, such as, hallway width, stairs, doors and windows, and elevator placement, etc. and depending on the region some weather related events.  And second, very seldom are man-made threats considered.  This contributes to the fact that man-made threats continue to occur despite large amounts of money being spent on security measures. I guess the argument could be made, that “well, we’re not required to consider them like we are for natural threats so we don’t need to; besides it will drive up costs”.  On the surface this makes sense but if you dig just under the surface your next thought should be, why don’t “best practices” apply?



The Department of Defense, and some other federal government agencies to a limited degree, requires that integration mitigation strategies be included in their building design review process regardless of where or what type of threat is involved.  In fact, it’s mandated that all threats, including man-made threats be addressed by a group of stakeholders at the onset of any new building construction project and for renovation projects that meet certain thresholds or “triggers”.   The stakeholder group determines the “design basis threat” to the building and its occupants and the level of protection required based on the number of people occupying the space.   These two factors ensure that the appropriate amount of money is spent on protection options and in the unlikely event a catastrophe does occur; injury and death will be kept to a minimum.



By bringing all stakeholders together from a variety of disciplines, everyone 1) has a chance to air their requirements and needs, 2) buys-in to the group’s decision on which threats will be addressed and support the “DBT” and the level of protection required, and costs are kept down.  Adding electronics in the form of surveillance or other technologies lies with the owner after the project is completed.  So in the short term, the cost of this equipment and its installation is currently absorbed by the owner/client and is not part of the building costs.  This “trick” helps keep the building design costs down but doesn’t adequately protect people or the facilities they use.  But more importantly, the real costs to the client come after the installation from the long term requirement for equipment maintenance and manpower. 



Since buildings are currently designed with everyone, remaining in their silos, with  limited exception, the process is treated as if it were a vertical process, when in reality it’s a horizontal one.  The “silo effect” and the isolation it causes make security an “add-on” and limits its efficiency and effectiveness.  

Sunday, February 17, 2019

What the LA Ram Superbowl Game Plan Teaches Us about Home Security


What the LA Rams Superbowl Game Plan 
Teaches Us about Home Security





First, I have to admit I had hoped the Rams would win the Superbowl.  It would have made my blog sound allot better.  I could have boosted about how Sean’s crew had analyzed their adversaries and implemented the perfect countermeasures and protected the home front (after all they were the home team).

Then secondly, I admit I’m not a football buff and understand everything about the do’s and don’ts of the game.   But I can with confidence make some comparisons and analogies that I believe most of us can understand.

So, anyway, congratulations to the New England Patriots on their win.

The more I think about it the more I realized that the Rams loss actually teaches us more about sizing up the threats than I first thought.  It teaches us, that not only do we have to look at the attacking forces from our perspective but we also must consider how they see themselves and will adjust.

In security design, we call this the design basis threat or DBT.  In other words, what you’re trying to protect your asset (thing of value) from – whether it’s a natural threat; such as, wind, fire,  rain or a man-made threat; like, graffiti, burglary or theft of property.

The Rams coaching staff had to analyze what the Patriots were capable of (their modus operandi [MO] and then figure out how thwart it.  They also needed to formulate a plan that covered the entire field.  In essence, defense in depth – the front line, the linebackers, the safeties.  We’ve all heard, “The best defense is offense”.  How true.  Ask the Patriots.

Unless, you have a comprehensive plan for the protection of your home, the attacker, be it a burglar, tagger, etc. will circumvent your security by finding the weak spot and exploiting it.  Remember, just having a security camera or system is not enough.  You have to have security built in to every facet of your daily routine. 

For home security that starts with your on-line social media presence.  Don’t give too much information away.  I laugh when I think that someone couldn’t believe she was robbed while in Paris.  Like duh, if you brag about how expensive the stuff is that you have there’s a very strong likelihood that someone also sees the value and will try to take it from you.  There was a case this week in Los Angeles were a rapper was flashing a big wad of cash and posted it on social media.  Well, guess what, he got robbed. 

Next, are you doing other things that tip off those with bad intention?  Do you put boxes out on the curb the night before the trash truck comes by?  Do you put papers in the trash that someone could take out under the cover of darkness and open-up credit card accounts in your name?  When you got that big screen to watch the Superbowl on, did you mount it on the wall so that someone walking on the sidewalk in front of your house could see it through the window?

Your plan has to be comprehensive.  It covers not only what you do but also where you do it.  Start from the roadway and work your way inward, assessing what the bad guy is able to see.  Make sure all lights work and all gates, windows and doors lock.  We lock our car even when it’s parked in the garage and the door from the garage into the house.  These little things delay the perpetrators actions and may possibly give us enough time to call 911.

I few years ago, I posted that the best home security system is actually a plate of cookies.  I still believe that, if you take some freshly baked chocolate chip cookies to the neighbors.  They’ll thank you for them and inadvertently watch out for your stuff because now they think they owe you.  

Maybe if the Rams would have taken some cookies to the Patriot’s locker room before the game things would have turned out differently.

Sunday, April 15, 2018


THE EVOLUTION OF RISK MANAGEMENT,
WAS DARWIN RIGHT?



In the Theory of Evolution, Darwin suggests that evolution is about survival of the fittest.  Was he right?  While he was talking about the natural world, his theory also applies to the security business.

In order to survive in today’s world businesses must adapt to their environments.  The threats that were around twenty years ago have changed.  They’ve become more sophisticated and must be adapted to.  What worked before won’t necessarily work in today’s world.  Not only have threats scenarios evolved but with the increase in technologies so have a new variety of threats come about. 

It used to be that a person who wanted to commit a breach of security had to be physically present in the space in order to carry out the attack.  That is no longer the case.  Since just about everything that has a moving part to it is somehow connected to the Internet of Things (IoT), a hacker does not have to be present in the physical sense in order to disable a closed circuit television (CCTV) camera, for example.  This means, a new way of thinking about threats, vulnerabilities and risk is necessary.

Threats used to be pretty much two-dimensional.  That no longer is true.  Those involved in the risk management business must think in three-dimensional terms.  In fact, they need to think about security as if it were a cube or box.  It’s six-dimensional and the approach to risk management must be carried-out that way.  This will require, pardon the pun, “outside of the box” thinking.

Additionally, without the “it’s part of the culture” way of doing business threat scenarios will continue to be played out with varying degrees of impact – and, some will be catastrophic.  Since we cannot prevent threats from occurring one hundred percent of the time we have to get the results down to a level that we can accept and handle with available resources.  This requires us to include scenario that are improbable but the results will overwhelm resources.  I call this “impact centric planning”.   I know most of us will not encounter an active shooter situation within our lifetime but active shooter threats must be planned for wherever high concentrations of people gather.  The adage, it won’t happen here cannot be the flavor of the day.  You’re right it probably won’t happen here, BUT if it does?  What will be the impact?

Not only must we deal with threats that are likely but we also must deal with threats that would be catastrophic even though very unlikely.   An excellent example of a highly unlikely event is the Las Vegas shooting incident.  That event was so improbable that if I would have brought it up during a planning session those in the room would have thrown their coffee at me. 

In order to survive, we must ensure we are the fittest.  So, Darwin was absolutely right.

Monday, July 25, 2016


The Myth About Size – It Doesn’t Matter


 


Most small businesses and homeowners, for that matter, think that due to their small size they are exempt from conducting analysis of their crime risks or other threats.  Larger organizations; however, understand the necessity to conduct a formal vulnerability assessment and risk analysis review on a regular basis – usually once a year or sooner if necessary.

Every organization, large or small, MUST conduct a formal assessment of their risks.  If they don’t they won’t know what their risks are or what mitigation strategies to employ. The process doesn’t have to be too complicated or lengthy or expensive.  But some type of formal analysis MUST be done.  When conducting a risk assessment, the formula goes something like this; assess the criticality of the asset (see definition below), determine what threats there are (both natural and man-made should be considered), and what vulnerabilities there are.  Once you’ve done that you have your risk.  For you math geeks the formula is written C x T x V = R.

Asset

Assets are anything of value to the owner and can also be anything the owner has that is of value to someone else (the bad guy, for instance).  A diamond ring, a house or a store full of products – anything of value.  You also have to determine how critical the asset is to you.  So, yes, even your kids and other relatives.  Although some of my relatives I wouldn’t mind if they were to get taken by aliens. 

Something else to remember, assets can have many parts that should be evaluated; i.e., a gas station - has gas pumps, a cashiers cage, and retail space.  Each piece of the asset should be evaluated, so that a clear picture of what needs protecting emerges.  I found it best to use, a quantitative system, using numbers to assign value.  One to ten works fine but one to 100 works, too.  Find a numbering system that works best for you.

Threat

Next, what are you protecting your asset against (threat).  Threats come in all shapes and sizes.  I can in very short order come up with several dozen natural threats and almost as many man-made threats.  And, as the recent incident in France just showed us, threat scenarios can be almost limitless.  Suffice it to say, concentrate on the one or two most likely to occur AND the ones that would be the most disruptive.  Again use a numbering system to assign value.

Vulnerability

Another way to look at vulnerability is to ask the question, “How much trouble am I in”?  Vulnerabilities can be physical in nature; i.e., a fence isn’t high enough to deter a burglar or it could be procedural, we don’t lock the gate to the backyard for example.  Both are vulnerabilities that can and will be exploited by a would be perpetrator.

Risk

These factors combined are your risk.  The risk tells you how much trouble you’re in. 

Solutions

Once you know what kind of shape you’re in, you need to develop mitigation solutions, determine the cost benefit (like you wouldn’t put a $500 lock on a $100 bike) and what solution you are going to do first.

I recommend implementing solutions that produce the highest reduction in risk to the largest number of people first. 

The Trap

Don’t fall in to the trap of thinking the solution to mitigate all threats is to buy and install a close circuit television camera (CCTV) system or home security system.  While CCTV can be a very effective solution, it has to be connected to a response force of some type that is capable of responding to the treat in an adequate amount of time.  A recent article in the Chicago Tribune revealed that CCTV solves crimes less than three percent of the time.  This is primarily due to the fact that the cameras are not continuously monitored or responded to when bad behavior is detected.  If you rely on a police agency or security company to respond, you need to make sure they guarantee response within 5 minutes.  Research conducted by the National Institute of Justice in 2015 revealed that a burglar spends about seven minutes on average on site.  So if the responding force doesn’t get there when the bad guy is there, there’s a 97 percent chance he won’t get caught.  This is the reason large organizations have dedicated security forces on site.

Ultimately our goal and that of every asset owner is to deter, prevent and respond to a variety of threats, regardless of the size of the organization.  Whether large or small, everyone asset owner MUST conduct a formal assessment to know what their risks are.  So size, doesn’t matter.

Other risk management strategies and assessment methodologies will be discussed 6 – 8 September in Jacksonville, FL.  Call 805 509-8655 for more information about seat availability.

On-line assessment tools for small businesses, homeowners and schools are available at https://hainessecuritysolutions.com/Technology_Improvements.html

Sunday, April 17, 2016


IMPACT CENTRIC PLANNING

Planning for Low Probability-High Impact Events





TRADITIONAL RISK MANAGEMENT METHODOLOGIES

The traditional mindset of most leaders, whether government or civilian (yes, even in the corporate sector) is that a crisis, situation or event that has the potential to disrupt service or mission capabilities can be planned for by writing a comprehensive emergency plan.  Once that’s done, when an event, situation or crisis occurs, they’ll simply pull out the plan and follow it.  This thought-process is flawed from the beginning.  While plans are a good thing to have they are not what they are made out to be unless the crisis follows it.  Unfortunately, most crisis haven’t seen what you written and won’t do what you’ve outlined for it to do.

The mindset of most folks charged with developing the emergency management policy, procedures and plan focus on most likely scenarios first.  They do this because of limited resources, usually in the form of funding.  It’s always about the money! So they plan for what’s most likely and then hope and pray “the BIG One” doesn’t happen on their watch.

UNCONVENTIONAL CRISIS AND THE READINESS FACTOR

Crises can be divided into two categories – conventional and unconventional.  Their nomenclature pretty much says it all. 

Conventional events occur daily somewhere and we’ve usually prepared for them in terms of resources, training and response.  Mainly because we are used to dealing with them, so we make sure we have the resources on hand.  And if we can’t have our own resources then we set up mutual aid agreements with agencies in our neighborhood of the country to provide support.  Unconventional events on the other hand, are a completely different animal.  They are either so rare or so great we have no way of planning or containing them.  Severe novelty events occur infrequently – they are novel, at least we think that.  Honestly, they occur all the time somewhere.  Just watch the news and you’ll get a sense of how common they are.  So the other half of the definition is severe.  Unfortunately, when combined with novelty sever events can immediately overwhelm local resources, know-how and response.

How often do we hear community leaders say, “we never thought it would happen here”?  This attitude causes a failure in “readiness”, communities are “prepared”; i.e., resources stockpiled and training’s been conducted but really are they ready to handle to event because it is outside of their scope of possibilities. 

Community leaders often get paralyzed and delay critical decisions until the crisis fits into a more recognizable model they can get their arms around.  The delay in action causes a delay in achieving “on the ground” superiority over the event.  This in turn can perpetuate the condition, make it worse and cause for a longer timeline in gaining the upper hand.

OFF-SET OR WELL BANKING

Since managers cannot fund every project or procedure that will cope with a crisis scenario there is a way to program money into future planning and that’s through a process called “off-set” or “well banking”.  Think of it as money set aside for the “what if – worst case” scenarios that we have every intention on spending once we’ve programmed it into our budget cycle and we’ve saved enough.  I contend that corporations, communities, and other entities can set aside a small portion of their budgets for these worst case events.

More about Impact Centric Planning and other methodologies discussed during workshop at Naval Air Station Jacksonville 14-16 June.  Contact us at 805 509-8655 or https://hainessecuritysolutions.com to register.


Sunday, August 16, 2015


DESIGNING INHABITED SPACE
Social Engineering
Spaces that are occupied are designed with a specific purpose in mind.  If the space is private then the space is designed to perform a particular function, such as, office space or a factory work floor.  On the other hand, if the space is public it is normally designed to allow open access to it, to allow people to either use the space or transit through it.

The concept of using design to “socially engineer” public and private space has been around for some time now.  Building designers have been designing spaces to achieve a variety of desired effects.  Back in the Middle Ages, castles were designed to withstand an enemy’s siege and when that didn’t work and the invaders breached the walls divide the aggressors into small enough numbers in order for the hometown folks to kill them.

So it really should come as no surprise that over the years new concepts and technique have been developed to address new threats.  Although we’ve come a long way in our tactics based on new threats the purpose remains the same – cause people to do what we want them to do or suffer the consequences of their actions; detection or capture.
In the modern era, threats come in a multitude of forms, either natural and man-made.  We’ve done a pretty good job in regulating construction standards for natural threats, such as, high winds, tornadoes, earthquake and fire but we’ve done less of a good job for man-made threats.
THE ENVIRNOMENT
In 1991, Crime Prevention through Environmental Design (CPTED) was introduced as a concept to reduce crime in neighborhoods.  The program has become so successful that most cities have ordinances that require implementation of CPTED principles during all new construction projects or phased in during major renovations.
CPTED controls the surrounding environment of a building thru four strategies:
Natural Surveillance – developing opportunities for observation of all spaces within an area by those occupying, using or transiting the area.
Natural Access Control – causing access control to be part of the environment by allowing design to create “choke points” and paths to and from buildings so that there is no doubt this is the proper way to enter/egress the area, even for first time users.  Non-adherence would cause detection and a response by authorities.
Territorial Reinforcement – identifying public and private space.  There should be a clear distinction of who the property belongs to.  This doesn’t mean putting up a fence; instead this can be achieved by using different materials, shrubbery/bushes, and cobble stone paver instead of poured concrete for example.
Maintenance – although not really a concept, the fact remains, if the space doesn’t have continuous upkeep it will come into disrepair through normal use and before too long become unsightly and bred criminal activity.
THE BUILDING ITSELF
After the Khobar Tower terrorist attack in Saudi Arabia in 1993, the Department of Defense identified the lack of a comprehensive overarching standard for building construction for the protection of personnel.  During the investigation of that incident it was observed that most of the victims were not killed or injured by the blast itself but instead were injured because of how the building reacted to the blast.  This was again proven in Oklahoma City in 1995.  Most fatalities were the result of the building collapsing upon them and not from the bomb blast itself.  Over the course of the next few years, through analysis and a lot of painstaking work, 21 standards were developed for the construction of DOD Buildings.  When implemented correctly the standards will reduce the effects of terrorist attack to personnel in the inhabited space.  While these standards are regulatory for DOD buildings the concepts are proven and can, and I believe should be implemented for all new construction or during major renovation projects for buildings that house 10 or more folks.  Implementing these standards at the beginning of a project may add 2-5% in increased costs to the project.  Adding the features later can add an additional 20-30% in cost overruns.  So just from a cost benefit perspective it makes good sense.  Not to mention, the reduction of injuries and number of dead during a catastrophic event.  You can’t put a price on that.
THE INTERIOR
Over the course of the last 10 years or so, we have seen a dramatic increase in criminal activity within inhabited space – in schools, hospitals, theaters, police station, etc.  Those involved in planning mitigation strategies and designing inhabited and uninhabited spaces, basically anywhere the public gathers, should now consider criminal activity within the confined spaces they are designing.  Recent events prove this activity can include, knife attacks in hospitals, shootings in schools, theaters and police stations and bombings at military facilities.  Unfortunately, this trend will continue for the foreseeable future.

So what can we do about it?  First, we would be well served if we required our leaders to implement legislation that addresses these current crises and looks to the future for emerging threats.  Unfortunately, the criminal threat and terrorist threat will be with us for some time to come, probably forever.  Both have changed over the years and as we address them we need to change too.  Second, even without the government we can start designing spaces addressing these three components; the environment, the building and its interior.  We really shouldn’t wait on the government to act; we should take it upon ourselves to do the right thing even without government intervention or supervision.  We can start by implementing these concepts on all new construction or whenever a renovation project meets a certain threshold (to be established locally).
I sincerely believe that when all three design components are incorporated into the building design “from the curb inward”, risks to personnel can be significantly reduced and their effects on people minimized.  We have to design the inhabited space so that people do what we want them to do and when they don’t they’re detected and captured, and the results of their bad actions are kept to a minimum.  It won’t happen on its own – we have design it that way!

Sunday, June 21, 2015




 
How to Use Building Design To Increase Security Effectiveness
 
The Aesthetics vs Design Basis Threat Approach
 
Did you know that adding security measures after the design process has reached the 35% designed phase can increase the cost of a construction project by 20% in the short term and much more long term.  Think about it.  Adding security at the beginning may add a mere 2% to the overall project costs.  Why is that?

Most buildings are designed for aesthetics and not the threat that the building must face – whether those threats are man-made or from natural causes.

There are plenty of regulations that address fire and earthquakes but rarely are their construction codes for incorporating security measures for the myriad of other threats.  That can change.  By bringing architects, engineers, planners, facility managers and security professionals together at the beginning of the design process the building design including the surrounding area can actually be used to deter criminal activity and reduce the effects of catastrophic events; such as, high winds or terrorist attack.

The design team needs to know and agree on what possible threats there are to the building, people and information inside.  This is called the “design basis threat” or DBT.  By knowing the DBT the design team can ensure each potential threat is mitigated through the design of the building.  Possible mitigation measures could be maximizing the stand-off distance from legal parking spaces to the building façade.  For example, the further the stand-off distance is, the less likely it is that the building will be affected by a stationary vehicle borne improvised explosive device.  Also by keeping the “unobstructed space” (the area immediate adjacent to the façade) free of shrubs or other places where small explosive devices or tools could be concealed, will eliminate that potential threat.  These are just two threats that can be affected through design.  Most others can be too.

In order to be effective the design team must consider all threats that are capable of effecting the building, whether they control the surrounding property or not.  If adjacent property offers the opportunity for people will “ill intent” to compromise the building then that area must also be considered. 

We usually call this “designing from the curb”.  There are four general rules to follow in providing mitigation strategies in building design. 

First, deter bad behavior.  We do this by training personnel on what is expected of them during on-boarding orientation.  We should also teach what constitutes “bad behavior” and how to report it.  An additional deterrent is a well-trained and well-equipped security force.  A common practice is to post a warning sign or a fence but rarely will this deter a determine advisory.  That said, we can design inhabited space so that a would be perpetrator will choose another “softer” target.

Secondly, we should delay “the bad guy” so that through effective design their presence and the activity they are conducting will be noticed.  A very effective way of doing this is creating as much distance as possible from the entrances of the building to the uncontrolled/public space.  The longer it takes to transit the space the more likely it is that someone will notice.  We commonly forget that each perimeter layer provides an opportunity to delay.  Perimeter layers are:

o   Layer 1 – property boundary
o   Layer 2 – exterior enclave or enclosure
o   Layer 3 – facility façade or elevation
o   Layer 4 – internal enclave or controlled/restricted space

Third, detect bad behavior. We can do this by limiting the number of access points, so that someone attempting to enter in a different fashion will stand-out and be noticed.  The use of combined landscaping; i.e., rocks, meandering pathways, shrubs, trees, water obstacles can be very effective tools in channeling persons to the correct access point.   Another good design tool is to make walkways pass by windows where people in the building, either from their workstations or a public space, such as, a break room, will be able to see people approaching.  In the 80’s we relied on security guards to do the watching for us.  As man-power cost rose over the next couple of decades, we replaced the guards and started to rely heavily on electronic security systems (ESS); i.e., Close Circuit Television (CCTV) or Access Control Systems (ACS).  While ESS is a great force multiplier, I submit that by designing approaches to the building so that they can be observed by persons inside will add tremendous detection capability and reduce long term costs in maintaining and monitoring the ESS systems.  Some assistance is provided by biometrics and analytical video but remember technology is a tool to be used by a human.  A recent article in the Chicago Tribune reported that less than one half of one percent of crime is solved by cameras. 

And finally, the fourth element of design is to defend against bad behavior.  One of the most common mistakes in using too much technology is that the requirement to respond to bad behavior is forgotten.  Therefore, a response force must be readily available.  They must be well-trained through drills and exercises and they must be well-equipped. 

Remember, the building does not have to look like a fortress in order to be secure.   By working together, architects, engineers, planners, facility managers and security professional can ensure it’s aesthetically pleasing and still provide adequate measures of security that are transparent to the public.  When these disciplines collaborate and security is incorporated at the beginning of the project, an immediate gain can be realized in keeping the project costs down and in the long term by limiting the need for maintenance and manpower. 
 
 

Sunday, May 17, 2015

Unconventional Crises Require Unconventional Leadership


 
 
Unconventional Crises
Require Unconventional Leadership
by
Ed Beakley
 Director, Project White Horse 084640

If you “Google” leadership, you will find that there are 158 million sites noted. Yet the events of this century make me wonder if we really understand what leadership must be in our current environment, and lead me to ask on the opening page of my Project White Horse  website, that what if nothing leaders have ever been taught or experienced is sufficient to face the problem? 
The implication is that there is more to survival in worst case disasters than just “who’s in charge,” and that we as citizens need to be less expectant of the arrival of duex ex machina by way of the cavalry is on the way, and become more able to be an active part in our own survival when worst cases occur. Leadership required – but maybe of a different kind.
The nature of worst cases is that the complexity and chaos generated, almost by definition mean that no leader by himself is capable of the multi-faceted decisions required.
Many types of emergencies occur every day and are routinely mitigated by local first responders. In certain areas hurricanes, flooding, earthquakes and fire are seasonal or typical of the area. The manifestation is well understood and planning well thought out and resourced. While they move past routine emergencies based on magnitude of destruction and/or significant loss of life, physical response assistance goes no higher than county or state mutual aid and the need for federal assistance is basically limited to financial aid.  Command and control during the event and recovery follows the locally developed “playbook.”  A Category 3 level (CAT 3) hurricane is a good example of a large emergency or conventional level disaster event, with potential for significant damage, yet normally it is well understood with only a small possibility of response being overwhelmed at the local level.
But researchers note that there are “disasters that go beyond typical disasters.” The latter have come to be noted as “catastrophes.”  Most notably would be 9/11, the 2004 Tsunami, Hurricane Katrina in 2005, and in 2010, the earthquakes in Haiti and the Deepwater Horizon Oil Spill. indeed, earthquakes, heat waves, floods, volcanoes, super typhoons, blizzards, landslides and droughts killed at least a quarter million people in 2010 — the deadliest year in more than a generation. More people were killed worldwide by natural disasters that year than have been killed in terrorism attacks in the past 40 years combined.
By virtue of unusual scale, a previously unknown cause, or an atypical combination of sources, responders face challenges that are indeed novel, the facts and implications of which cannot be completely assimilated in the moment of crisis.  These events are not only characterized by high stakes—the likelihood of major losses (to life, limb, property, heritage, or other highly valued social or private assets) – but they have shared striking similarities, inasmuch as they foster destabilization of leaders in charge of response and reconstruction efforts, and the whole of communities. 
Dr. Erwan Lagadec in  Unconventional Crises, Unconventional Response: Reforming Leadership in the Age of Catastrophic Crises and Hypercomplexity further defined these events as follows:
Conventional crises rarely require high levels of inbuilt resiliency from our systems. This is because such events tend to affect circumscribed “ground zeros,” and therefore can be tackled by bringing to bear the “normal” assets and strategies of the unscathed outside on the impacted area.  On the other hand, catastrophic or hyper-complex events will destabilize entire systems, forcing leaders and public alike to abandon “normality” altogether, and look for a coherent fallback position. However, it is eminently difficult to organize an orderly general retreat, especially when leaders must redefine a new line of defense while on the run, and from the ground up. Miracles at Dunkirk are precisely that: miracles.  Even before the planning phase, and more fundamentally, the makeup of our systems itself must anticipate the destabilizing effects of unconventional events by weaving resiliencies (visible or “hidden”) into their fabric.”
The level of personnel training, system performance and system-system interoperability acceptable for routine or conventional crisis events does not guarantee usefulness when the environment becomes hyper- complex and severely stochastic. Nor does the 1) training and experience of key decision makers in the lower end of the spectrum, nor 2) “planned for in the playbook script” leadership insure that the magnitude and novelty of the emerging catastrophe does not overwhelm communities and emergency management, or simply negate “the plans” and won’t destabilize the entire response structure. 
Unconventional/Hyper-complex/Catastrophic level events are often noted as Low Probability, High Impact events. but we should keep in mind that these events are actually Absolute-Certainty, Low-Predictability, High-Impact incidents that take place all the time.
Hyper complexity makes it near impossible for “traditional” leaders to plan, let alone coordinate response efforts.  Extrapolation of training and system evaluation suitable for routine emergencies and conventional disasters as suitable for unconventional or catastrophic operational response is an intrinsically flawed strategy.
So, what can be done?                                                                                                    
To start, we must recognize and acknowledge the differences between crisis/disaster types and the different set of challenges in planning, execution, and required forms of leadership. Additionally, we must accept that we will most probably require new and innovative analytical methods and metrics, and methods for learning - not just training.
We must ask what accounts for whether the first response process will be able to provide effective mitigation of unfolding disaster incidents. How can that effort best be organized to respond to novel or unconventional crises? 
Then, what must be done in advance to create the capacities needed in the face of unconventional crises?   The real "new" must be recognizing the need to put higher level leadership - beyond incident management and the trained response force - into complex crisis exercises with intent on learning how to think and not on "feel good" check in the block exercises, that leave senior decision makers with the parting thought " all is good, I got this."
More information about Project White Horse 084640 can be found at:  http://projectwhitehorse.com/