Showing posts with label risks. Show all posts
Showing posts with label risks. Show all posts

Sunday, May 17, 2020

Everything I know about security I learned in kindergarten and I've been updating ever since

I know many of you remember that in kindergarten we learned to play fair, share tools, put things back in “the cubbie” where they came from, put your name on your stuff, be quiet during nap time and in general to be good neighbors.  Well, I learned something else, too.  LESSON LEARNED: HE WHO HAS THE TOYS GETS TO CONTROL THE GAME AND IS THE BOSS OF THE OTHER KIDS.

Fast forward to the third grade, I learned that if someone was bullying me,  I had to fight them to get them to stop or get someone else who would do that for me.  I know, can you believe that this beautiful face was getting bullied in the third grade.  Well, it’s true and all because I kissed a girl who was a fifth grader.  So I did what every skinny, respectable guy would do – I got her to beat him up. LESSON LEARNED: GET SOMEONE ELSE TO DO YOUR DIRTY WORK!

When I was in the fifth or sixth grade, my criminal career started and ended in a span of a few minutes.  You see, there was a pack of rubber bands on the shelf at the Ben Franklin store and I really wanted them but I didn’t have the money.  I put some in my jacket pocket and left the store.  As soon, as I was walking out a county sheriff car pulled into the parking spot directly in from of the store.  The store had a revolving door, which allowed me to reenter the store without ever really exiting.  I put the rubber bands back on the shelf and waited for the sheriff to leave the store before I went home, scared to death.  I have to admit, every time I’d see a police car while growing up I always wondered if “they knew about that” incident. LESSON LEARNED: ONCE YOU’VE DONE IT YOU’VE DONE IT FOR LIFE.

And then upon entering the military, I became an Air Policeman.  God works in crazy ways.  Since I was mostly stationed in Europe from the time I was twenty until I retired in 1993, my biggest security lesson was tracking terrorist activities and fighting the “the Communist, the bastards”.  LESSON LEARNED: THERE ARE BAD PEOPLE OUT THERE WHO WISH ME (US) HARM.

Later in my career, I thought and was taught to think this way, that all you had to do was put a camera on it to watch or post a guard and crime would stop.  Your stuff would be protected. Neither a camera or a guard will prevent, they may deter, and unless the response force is within a reasonable distance to respond they probably won’t deter either.  I’ve always wondered why organizations spend thousands and still get “ripped off”.  Upon analysis it usually comes down to them using the wrong mitigation strategy for the wrong threat or the security is “so tight”  it becomes a burden or tax and people don’t want to pay the tax, even those who are authorized to do so.  They’ll find a way around it so that life is convenient. So, unless your security system is specifically designed to deter and prevent unwanted behaviors, it won’t do that. Sure there is always some deterrence but a dedicated aggressor will not be detoured.  They will bring the tools they need.  Also, if there isn’t a dedicated response force, all you’ll be doing with your fancy system is taking pictures of what happened. LESSON LEARNED: SECURITY IS SUPPOSED TO BE ABOUT DETERRENCE/PREVENTION AND INSTEAD IT’S ABOUT CONVENIENCE.

Well, after my heart attack a couple years ago, my cardiologist said I’d probably live another 30 years.  I’ve used three so far, so who knows what I’ll learn in the next 27?

Sunday, April 19, 2020


4 Spring Cleaning Tips for Keeping Criminals from Acting Criminal





I’m sitting here in my office writing this Blog post, while wearing a surgical mask.  My wife says, “I don’t have to wear it because I’m not out in public”.  I answered, “Well, I’ve heard my computer can get a virus, and I don’t want it to come from me, lady”. Touché


Like every good spring cleaning job, you have to set some goals.  My wife’s  - windows.  Mine - not falling off the ladder.


When it comes to security spring cleaning though, our first goal needs to be keeping criminals from acting criminal around my property.  Here are 4 tips:


Understanding that your property has a number of layers that you can use to you advantage is essential.  Those layers, if you have them are: property line, internal fence-line (if present), building facade and special spaces within the house.  For instance, I don’t have a fence in the front of my house but I do on the sides and back of the property, so my property line and fence-line are one in the same.  So for that reason, I look at every layer I do have and determine if I can deter, delay, detect and defend against a would-be aggressor breaking in and stealing my stuff.


Deterrence is kind of hard to define.  Mainly, because if the deterrent is perceived to be too tough, then it will get circumvented by those who are actually authorized, and then what’s the purpose of having it in the first place.  Besides, a dedicated threat will not be deterred.  He/she will bring the tools necessary to defeat whatever the deterrence is designed to do. Now, don’t get me wrong I’m not a defeatist.  I do believe you have to do whatever it is you can and evaluate what you’ve done honestly.  If there is still pain, do it some more.


Secondly, my goal is to slow a person down if they have ill-intent enough so that I can detect them.  So instead of a straight sidewalk up to my door, I have a sidewalk that meanders or crosses my front lawn, so while standing inside my living room or office I can see them as they approach.  If someone doesn’t follow the path of the sidewalk and traipses across my lawn then that is an indicator to me that something’s not quite right.  Now, it could be that the person is just lazy or too tired or it could mean something far worse.


Next remove all possibilities of hiding.  So bushes and shrubs that are within 10 feet of windows and doors should be removed.  If you simply must have them for aesthetic purposes, then they should be located away from the building so that as a person approaches they can see around them.  Bushes should be trimmed to a height of three/four feet above ground level and trees down to seven/eight.  Anything higher or lower causes opportunities.


And finally, check windows and doors, to make sure they close properly.  And, while cleaning the windows and gutters, check the outside lights, especially those on a sensor.   

Another thing, stand at your property line at dusk and see if someone can see inside your house while the lights are on and can see that you’re at home.  If they can, then even if you leave lights on to give the appearance that someone’s home they can see that you’re not.  We draw our curtains at dusk so that you can’t see through.


When I said, defend above I didn’t mean confront the bad guy and whip out a gun.  Trust me your stuff is not worth someone’s life.  On the other hand, if they are physically harming or threating harm to my family I can guarantee you that they’d wish that I only had a gun. 


Send me an email and I’ll send you a 28 question checklist you can follow.  FREE.

Sunday, November 17, 2019


Known knowns and unknown unknowns






"There are known knowns" is a phrase from a response United States Secretary of Defense Donald Rumsfeld gave to a question at a U.S. Department of Defense (DoD) news briefing on February 12, 2002 about the lack of evidence linking the government of Iraq with the supply of weapons of mass destruction to terrorist groups[1]



This quote tells us something about risk management.  Basically there are threats we know about and there are threats we don’t know about and there are threats that we don’t know we don’t know about.



From a risk management standpoint, that’s pretty disconcerting. 



In order to understand the unknowns you have to look at things from the “bad guys” perspective.  In other words, see what the "bad guy" sees.  And to do that you must understand that there are four aggressor types of criminal/man-made threat groups; criminal (sophisticated/unsophisticated, organized/unorganized), protestors (organized/unorganized), terrorist (domestic/transnational/state-sponsored), subversives (saboteurs/intelligence agents [state/non-state sponsored]).  In an effort to design better mitigation strategies planners must understand the “bad guys” motives or the reason(s) behind why they do what they do.  There are also four primary aggressor objectives; inflict injury or death to people, destroy or damage facilities, property, equipment or resources, steal equipment, material or information and create adverse publicity.



So how can I plan to reduce their effects let alone mitigate them?  The answer is really easier than you think.   Traditionally in risk management, we look at things from a probability standpoint.  We ask the question. “Will it happen here, and if so, what will the impact be”?  I believe, likelihood has little influence on risk.  I believe likelihood comes into play when talking about funding.  Our risk management methodologies assume the threat will be successful 100 percent of the time.  We calculate likelihood when it comes to cost benefit.



Our Asset Based Risk Analysis (ABRA) and Critical Asset and Infrastructure Risk Analysis (CAIRA) methodologies combine the aggressors motives and objectives with what the asset owner sees; thereby, giving a complete picture of risk.  



More about ABRA (Platinum GOVIES Award 2017 for Best Government Security Risk Methodology) https://view.joomag.com/march-2019-ast-magazine-march-2019-ast-magazine/0952115001553308799/p4?short



More about CAIRA (Platinum 2018 ASTOR Award for Best Risk Analysis Methodology in Homeland Security) https://view.joomag.com/july-2019-ast-magazine-ast-july-2019-magazine/0612002001563068627/p60?short



More about risk management and developing mitigation strategies can be found in my new book, The solutions Matrix: A Practical Guide to Soft Security Engineering for Architects, Engineers, Facility Managers, Planners and Security ProfessionalsOrder here  https://americansecuritytoday.com/dont-surrender-to-fear-new-book-the-solutions-matrix-by-doug-haines/





[1] Full quote: Reports that say that something hasn't happened are always interesting to me, because as we know, there are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns—the ones we don't know we don't know. And if one looks throughout the history of our country and other free countries, it is the latter category that tends to be the difficult ones.

Sunday, February 17, 2019

What the LA Ram Superbowl Game Plan Teaches Us about Home Security


What the LA Rams Superbowl Game Plan 
Teaches Us about Home Security





First, I have to admit I had hoped the Rams would win the Superbowl.  It would have made my blog sound allot better.  I could have boosted about how Sean’s crew had analyzed their adversaries and implemented the perfect countermeasures and protected the home front (after all they were the home team).

Then secondly, I admit I’m not a football buff and understand everything about the do’s and don’ts of the game.   But I can with confidence make some comparisons and analogies that I believe most of us can understand.

So, anyway, congratulations to the New England Patriots on their win.

The more I think about it the more I realized that the Rams loss actually teaches us more about sizing up the threats than I first thought.  It teaches us, that not only do we have to look at the attacking forces from our perspective but we also must consider how they see themselves and will adjust.

In security design, we call this the design basis threat or DBT.  In other words, what you’re trying to protect your asset (thing of value) from – whether it’s a natural threat; such as, wind, fire,  rain or a man-made threat; like, graffiti, burglary or theft of property.

The Rams coaching staff had to analyze what the Patriots were capable of (their modus operandi [MO] and then figure out how thwart it.  They also needed to formulate a plan that covered the entire field.  In essence, defense in depth – the front line, the linebackers, the safeties.  We’ve all heard, “The best defense is offense”.  How true.  Ask the Patriots.

Unless, you have a comprehensive plan for the protection of your home, the attacker, be it a burglar, tagger, etc. will circumvent your security by finding the weak spot and exploiting it.  Remember, just having a security camera or system is not enough.  You have to have security built in to every facet of your daily routine. 

For home security that starts with your on-line social media presence.  Don’t give too much information away.  I laugh when I think that someone couldn’t believe she was robbed while in Paris.  Like duh, if you brag about how expensive the stuff is that you have there’s a very strong likelihood that someone also sees the value and will try to take it from you.  There was a case this week in Los Angeles were a rapper was flashing a big wad of cash and posted it on social media.  Well, guess what, he got robbed. 

Next, are you doing other things that tip off those with bad intention?  Do you put boxes out on the curb the night before the trash truck comes by?  Do you put papers in the trash that someone could take out under the cover of darkness and open-up credit card accounts in your name?  When you got that big screen to watch the Superbowl on, did you mount it on the wall so that someone walking on the sidewalk in front of your house could see it through the window?

Your plan has to be comprehensive.  It covers not only what you do but also where you do it.  Start from the roadway and work your way inward, assessing what the bad guy is able to see.  Make sure all lights work and all gates, windows and doors lock.  We lock our car even when it’s parked in the garage and the door from the garage into the house.  These little things delay the perpetrators actions and may possibly give us enough time to call 911.

I few years ago, I posted that the best home security system is actually a plate of cookies.  I still believe that, if you take some freshly baked chocolate chip cookies to the neighbors.  They’ll thank you for them and inadvertently watch out for your stuff because now they think they owe you.  

Maybe if the Rams would have taken some cookies to the Patriot’s locker room before the game things would have turned out differently.

Sunday, November 18, 2018

Architects Meet Security Halfway

Architects Meet Security Halfway
What Should They Do to Go All the Way? 


The normal process for building or inhabited space design goes something like this:  the client goes to the architect and describes his/her vision.  The architect interprets that vision using their creative juices.  That’s a good thing! Once the client approves the vision then project is handed over to an engineering firm to “build the guts”. Once the infrastructure is done and the project is finalized.  The client accepts the project.  At that point, it’s up to the client to coordinate the security features of the designed environment.

Sometimes, this process works.  But more often than not, it doesn’t for a very simple reason.  Everyone sees the project differently.  The first questions the architect asks the client is how many people, what type of space (open/shared/closed offices, how many floors, etc.?  During that conversation there should be questions asked that regard the Design Basis Threat; i.e, what types of threats are we trying to protect against? This particularly the case when it comes to man-made threats; such as, active shooter, hostile vehicle, insider threats.  Natural threats to buildings and people are usually governed by ordinances or codes; fire, earthquake, high winds, etc.  Man-made threats on the other hand are not usually governed by ordinance.

That said, when understanding man-made threats it is important to identify several keys elements of the threat:
1) Types of aggressors threats (covert or overt, group or individual, organized or not)
2) Aggressor motivations or objectives (inflict injury or death, damage or destroy property, steal equipment or materials, and create adverse publicity)
3) Aggressor tactics (both the modus operandi and the tools needed to be successful)

Unfortunately, these elements are usually left up to the security consultant towards the end of the project.  If they were considered during the initial 15% phase or 35% phase of the project, it could easily accommodate countermeasures that mitigate these identified threats purely by designing the space to do just that while still maintaining functionality and aesthetics.

The Department of Defense, Department of State and Veteran’s Administration mandate that a security representative be part of the design team from the very beginning.  The civilian world should follow suit, instead of the current halfway method.

Other trends in the built environment are discussed here:
Security Industry Association Technology Insight, Spring edition

Security Industry Association Technology Insight, Fall edition



Sunday, July 15, 2018


Using Landscaping to Control Access




I want to tell you about two incidents that required a security solution and how the first attempt at providing an adequate solution failed miserably.

First case – illegal dumping

The issue was that people were driving up to the banks of a stream and dumping trash; i.e., tires, mattresses, rubbish, etc.  The first solution provided added a camera to the site so that “things” could be monitored.  The camera fed back to the superintendent’s desk.  Of course, when he wasn’t there (weekends, evening/late at night, attending meetings, lunch, naps) the dumping occurred and continued.  The superintendent was scratching his head on what to do.  After all, he just spent several thousands of dollars on the latest technologies and they didn’t seem to work.

Our solution was not electronic.  Instead, we suggested that they build a raised berm/curb using natural landscaping (trees/boulders/bushes, even park benches) so that the vehicle couldn’t drive up to the water’s edge in the first place.  We suggested landscaping due to the ability to prevent the vehicle from reaching the stream.  We imagined the culprits wouldn’t want to carry the heavy objects from the roadway, across a bicycle/walking path and then into the wood clearing to reach the stream.  Our second reason was to ensure the aesthetics of the area were kept intact.  Sure, we could have suggested a fence along the embankment to deny access and achieve the same effect, but who wants to walk along a fence with barbed wire when they’re taking the dog out or jogging or cycling.

Second case – unwanted access to school property

The issue in this case was that community members were cutting across school grounds in order to shorten the distance to retail shops located near the school campus.  The first security company suggested erecting a chain-link-fence with 3-strand barbed wire outrigger around the entire campus perimeter with a gate for buses and parents/administrators.  When not in use the gate would be kept locked.  The administrators weren’t buying it.  What if a student climbed the fence and was injured?  And where were they going to get the manpower to manage the gate? 

Our solution was to construct on three sides a wooden split-rail fence approximately 4 feet high (similar to those used in the Atlantic Piedmont region) and then to place flower beds in front of the fence and thorny shrubbery and trees behind it so that it would be difficult to cut through.  The front of the campus was left open.  We also suggested installing "speed cushions" to allow just buses to enter the "drive up/drop off" area.  And to have a separate loading/unloading zone for the parent's cars, that would be controlled by school staff.  These solutions provided the aesthetic qualities the administrators were looking for.  We also suggested changing procedures but I don't want to give too much away here.  Needless to say a comprehensive change was needed to address the concerns of the school.

These are just two examples of how not all security solutions need to be electronic.  Unfortunately, surveillance companies will tell you that CCTV is the solution to everything.  The reality is it isn’t.  In both cases we used “natural access control” (Crime Prevention through Environmental Design [CPTED]) as a fundamental principle in our approach to reducing crime.

Additional CPTED ideas and other principles on deterring crime and the effects of terrorist attack will be discuss during a 3-day workshop, Designing Secure Buildings: Integrating Security Technologies being held in New York City, 11-13 Sep 18.

Our ROI Toolkit is available.  The Toolkit will help you justify to your boss why you need to attend this training.

Contact us at info@hainesssecuritysolution.com or call +1 805 509-8655 to register.

Visit us at https://hainessecuritysolutions.com/Training to find out about other classes we offer or to host a workshop. 

Sunday, January 21, 2018


Security Opportunities within the Booming IoT Market

The Future is Bright for Non-electronics, Too






The term Internet of Things was coined back in the late 90’s.  The somewhat official definition is “A network of dedicated physical objects that contain embedded technology to interact internally or externally”.  I think we can all agree that is a very broad brush definition.  I would rephrase it to be, basically “an ecosystem that includes electronic things, and the communications and data analysis between them”.



With that in mind, let’s look at where we are today and where we’re going.



Today there are an estimated 7billion devices connected via the internet and applications that use the internet.  That’s a device for every human on the planet.  In just five years that number will increase to over 50billion.  The use of The Cloud is fueling this increase.



What does this mean for the security profession?  Simply put lots of openings and an unlimited number of chances.  In other words, if you can think it, you can make it happen. 



This increase in the realm of possibilities will affect every aspect of our daily lives.  So whether you’re involved in the residential, small business or corporate security market, you can make it.



I usually think of security solutions as following into one of two spheres – electronic or non-electronic.



ELECTRONIC TECHNOLOGIES



Electronic technologies are just that – technologies that are electronic.  Kind of a no brainer, don’t you think?  These technologies run the gamut from intrusion detection systems to access control to surveillance and beyond.  They’re becoming ever more sophisticated and complex.



Unfortunately, as technology evolves it will probably become more invasive.  It will collect more and more data about you. 



These invasive technologies already assault our daily lives.  Just imagine how that will change in the future.  While there is tremendous resentment about governments collecting data on individuals.  Companies, such as, Google, Amazon, Microsoft and other major retailers are doing it and no one really seems to care.



The use of cellphones will become almost an extension of ourselves.  We will be able to do everything from or with our phone.  I suspect someone is going to develop a security app that will read your blood pressure or your heart rhythm to authenticate that you are the correct user, instead of the fingerprint reader or PIN code of today.  Your phone will become your “Mini-me”.  It will know your behavior patterns well enough to “help” you make choices.



If you’re a dealer, distributor, integrator, system installer or work in a parallel vertical the opportunities abound, as you provide solutions for your customers.  It really won’t matter which product or service you provide, as there is a place and need for all of it, and combining technologies will provide even more opportunities.



The development of “predictive analytics” based on data collection will allow companies to forecast their customers buying habits better.  My personal opinion is that “predictive analyst” will become a job title and many security companies will hire them to determine future sales projections and to forecast their future markets.  With that in mind, there is already some technology out there that can analyze behavioral patterns.  Does this mean that access control will be determined by a biometric sensor and as a back-up analysis app that says, this is you because you always show up for work at this time or an even more sophisticated analysis by the pressure you apply to the pin-pad as you type in your PIN code?



NON-ELECTRONIC TECHNOLOGIES



Non-electronic technologies on the other hand don’t use electricity to function. They can range from windows and doors to landscaping or even the way a particular building or inhabited area is designed. 



Fortunately, to counter the invasiveness of the electronic age, non-technologic innovation will become less invasive as we develop better materials and strategies as we design inhabited space. 



I believe we can “socially engineer” inhabited space.  We can incorporate specific urban design strategies that cause positive behaviors so that there is less reliance on the invasive use of electronic means to keep us safe.  Ultimately citizens don’t want cameras that watch their every move; instead they want space that is functional and free of crime and unwanted behaviors.  By increasing the effectiveness in controlling the social behaviors of the people using or transiting the space, the environments will become safer and need fewer electronic gadgets.



We are at the cusp of an explosion in technologies, both electronic and otherwise.  Whether you are in the business of providing solutions directly in the form of a product or service or in the business of providing solutions indirectly, i.e., architect, engineer, security consultant or government official strap yourself in and hold on to your hat because it’ going to be a great ride with lots of opportunities for all to excel.

Sunday, July 16, 2017


Threats, Designs and Delphic predictions: Designing-in Security for Major Sporting Infrastructure and Other High-Occupancy Spaces (Part 2)



Building on the strategy

The first part of this article (published in our Blog 18 June) on this topic proposed four strategic guidelines that should influence the design, build and operation of a sporting venue:
·         Consider the security aspects at the beginning of the design process, not as something to be added at the end;
·         Place these security considerations in a wider context – e.g., as part of a national government’s overarching security strategy or policy;
·         Take an impact driven approach to the design – focus on the impact of a hostile event (e.g., terrorist attack) taking place, not its likelihood;
·         Consider security from a holistic perspective.  All security is a combination of people, procedures and technology, but an holistic approach goes further     – balancing the physical and cyber considerations and developing a positive culture amongst the staff so that their everyday actions work effortlessly     towards a safe, secure and enjoyable celebration of sport.
Early engagement between security professionals, designers and architects was stressed as being essential.  This can save money in the long term and produce a design that enhances the spectator experience by inducing a greater feeling of safety and security for both them and the competitors.  We will now consider the importance of continuing this process of engagement throughout the construction phase as the real venues start to emerge and the number of people involved in the project rises.  This throws up a seemingly different set of challenges, but most, if not all of the same guiding principles apply, combined with the need for good communication between those with the vision and those responsible for making it happen. 

Getting the security requirement right

The architects and designers of the sporting infrastructure should be seeking to build security features in to the very fabric of the structures themselves.  The best security is usually the most discreet, but there will be occasions when obvious measures will provide deterrence to those with malicious intent, as well as reassurance and comfort to competitors and spectators.   However, there will also be times when features separate from a main building will be necessary.  The most obvious example of this is a perimeter fence. 
All stadium systems should be designed and installed in a way which will maximise through-life flexibility to support both changing operational needs and emerging technology.  In order to achieve this it is important that a structured mechanism for the capture of the numerous requirements for the functioning of system components is agreed by all relevant stakeholders.  The temptation at this stage is to think in terms of solutions, rather than requirements, but this is a false economy.  Take the simple example of a perimeter fence.  The designer may ask for a fence of a certain height, but on what is that decision making based?  Is it just because a similar stadium had a fence of a certain height surrounding it?  Or, was that fence the most prominent in some catalogue?  It is important that rigour is applied to the specification of security components based on what they are seeking to achieve in the environment in which they will operate. 
The generally agreed best approach to this issue is through the drafting of an Operational Requirement (OR) for a security component.  This is a statement of need based upon a thorough and systematic assessment of the problem to be solved and the hoped for solutions.  A structured process for the development and agreement of ORs has been successfully used to deliver the security systems for numerous parts of the UK’s infrastructures and many permanent and temporary sporting venues.  Among the questions to be answered during the preparation of an OR are:
·         What is the output desired of the system / component?  For example, in general terms ‘a fence’ is a solution rather than a requirement.  What is seeking to be achieved?  Demarcating one area from another, giving one area more protection than another, channelling people in a certain direction?  All of these requirements could be solved in a number of differing ways.  It is also worth remembering that it is a mistaken belief that fences will keep people out of a certain area.  Whilst this is true for most law abiding people, the same does not apply for those determined to enter a restricted area.  In this case, the fence will only delay their entry (as it is climbed, burrowed under or cut through), although sensors will be able to detect this activity and alarms raised.  If the requirement was instead for surveillance, was this to provide continuous coverage of a particular area, or only at certain times?
·         What are the options by which the output could be achieved?  For example, fences come in all shapes and sizes.  Some are harder to climb; others more difficult to cut through.  Sensors to detect this activity can be discreet and sound silent alarms or noisy triggering claxons and spotlights.  In the case of surveillance, this can be achieved through the deployment of people, technology, or a mix of the two.
·         What are the key environmental and technical requirements for system components?  Harsh environmental conditions will affect the materials that a security component is made from, especially if it is part of a permanent structure.  CCTV cameras are particularly sensitive to the prevailing weather – those designed to function well in wet or damp conditions may not perform so well in hot and sandy conditions and vice-versa.  
·         What are the residual risks and weaknesses in the proposed solutions?  A fence might have sensors to detect when someone has cut it or is scaling it, but what happens then?  How are resources mobilised to respond to the intrusion and how quickly will they arrive?  In the case of surveillance, the effectiveness of this could be reduced during heavy rain, fog, sand storms, etc.
·         What are the interdependencies between various system elements?  This is a simple question, but the answers might be highly complex and take a long time to answer.  This article is not long enough to tackle this part of the process in anything other than a superficial level of detail.  For example, the level of security of a fence needs to be matched to the response time of the manned guarding. The shorter the delay the fence can provide, the faster the manned guarding needs to respond.  This may require more guards at shorter distances from the perimeter.
It is important that rigour is applied to the specification of ORs and the focus is not allowed to drift back to thinking in terms of solutions.  It is unlikely that the fundamental requirement for a security feature will change much (if at all) over the life-time of the infrastructure whereas the technologies that might be employed to achieve a particular outcome may change a lot.  It is important that the replacement technologies do not weaken the overall security stance or remove features that were present in the original build.  Focusing on the requirement rather than the solution is the best way to achieve this.
Designing for the future 
Once the ORs and interdependencies of security system components are understood and agreed, the system can be designed and installed.  However, remembering that any form of permanent sporting infrastructure will last a considerable number of years, it is necessary to adopt a strategy that seeks to maximise the capabilities of new technologies as they emerge and minimise the disruption and change necessary to embrace them.  Such a strategy is likely to include the following principles:
  • Modular.  Systems will be specified and delivered in a way which makes it easy to upgrade one element without changing numerous other components.Internet Protocol (IP) based. The historical separation between the physical and logical worlds is no longer applicable as so many of the physical entities in a stadium (entry gates, CCTV monitors, Public Address, display screens, etc.), will all be controlled across communications networks based on IP.  Modern stadia can all be flood-wired with IP networks to achieve this.  Such networks will be flexible and able to adapt to changing requirements of the terminating equipment.  However, care needs to be applied in the way in which such networks are configured and protected to prevent them becoming a weakness that can be exploited via cyber attack, rather than a strength that delivers flexibility and adaptability. 
  • Based on open protocols.  Wherever possible, system components will be specified to use open, rather than manufacturer-proprietary, protocols for interfaces and data transfer.  This will be particularly important for the control of numerous physical entities as discussed above.  It is inevitable that the degree to which a cyber environment is used to control physical entities will only increase over time and the number of manufacturers offering products in this area will increase.
  •  Flexible at the Security Management System – this is the point at which the inputs from the various systems are combined and then presented to the system operators. 
Ongoing operator training is an important element which is often forgotten or minimised after system commissioning has been completed.  Ongoing refresher training programmes need to be planned and executed to ensure that operators remain conversant with the latest aspects of the system.  These programmes will also be the best route to introduce new capabilities.
Designers of security systems need to devote time to keeping themselves up to date with developments in the technology market through a mixture of:
       ·         Attendance at trade shows, exhibitions and conferences.
      ·         Ongoing dialogue with suppliers and manufacturers to understand both new uses / improvements to existing products and new products / capabilities in development.
·         Regular engagement with relevant Government or national bodies responsible for research and applied science and technology.  Each national government will have slightly different structures and processes to cover this[1]. 
This engagement will allow the designers of sports infrastructure to understand the strengths and weaknesses of products as assessed by independent experts, as well as to aid the implementation of current best practice.  This will enable a judgement to be made as to whether an emerging capability offers a significant improvement (both technically and financially) over those currently proposed.  This kind of activity could be swept up in the design integration meetings that often take place in major projects when each engineering discipline determines how it is affected by security requirements and vice versa.
Information security aspects
It is during the design and construction phases that the layers of security for the venues will be specified and installed.  Once this phase starts and the number of people involved in the project starts to rise significantly, it is important that a structured approach to the handling of information is introduced.  The importance of this was highlighted in part 1 of this article.  Information in many forms will be vital to the successful design, construction and operation of all major sporting venues for the many years of their legacy use.  The protection of information will normally be achieved by the definition and implementation of an Information Security Policy (ISP) that needs to be written in collaboration with all relevant stakeholders.  This should be designed to ensure that sufficient information relating to security systems is incorporated into master designs, but that sensitive information (e.g., camera fields of view) is only released on a need to know basis.
To facilitate this process, a single authority should be established with the responsibility for writing the ISP and also deciding the relative sensitivity of information to be disseminated.  This authority should specify how sensitive information will be marked, stored, transmitted and handled by users.  Different countries will have their own established processes for this, such as some form of national protective marking scheme for sensitive documents (Restricted, Confidential, etc). 
The ISP needs to cover appropriate elements of the supply chain.  The challenge here is to ensure that information is appropriately cascaded down the chain to facilitate the purchase of the right goods and services, but without exposing the overall security posture of the venue.  This will be particularly tricky when dealing with overseas suppliers or organisations with an unknown or weak cyber security posture.  This is a new area which may require the venue designers and builders to seek specialist advice to ensure that they can balance the advantage of going to the market for goods and services against the exposure of potentially sensitive information through the same route.
It is important that the ISP covers the protection of the numerous industrial control systems that are necessary for the operation of physical systems at the venues, or that a separate policy is written to address these risks.  A modern venue will have innumerable systems such as those for crowd access, lighting, air-conditioning, display screens, etc., as well as many aspects of security (command and control rooms, CCTV networks), all of which will be controlled via data networks and electronic infrastructures.  Complete or partial loss of control of any of these types of systems would result in serious consequences for the safe and secure operation of the venue.  The challenges of securing these from cyber threats are brought into sharp focus when considering the projected life of the control units that turn cyber commands into real action on the ground.  On average, an item of corporate IT equipment (desk computer, etc.) will have a refresh or replacement rate of about 4 to 5 years.  A typical industrial control unit may have a refresh rate of 20 to 25 years.  The cost of replacing the remote control units and the disruption to essential services while this happens are among the reasons for this sharp difference in refresh rates.  Over that period of time it is impossible to predict what cyber threats may emerge.  This is why it is important to adopt an impact driven approach to security as described in part one.  Focusing on a threat that cannot be judged so far in advance may ultimately lead to an inaccurate assessment of the risks resulting in either inadequate or over specified security features. 
It is certain that those who wish to compromise information assets belonging to a sporting venue will be imaginative in their approach.  In response to this, it is necessary to understand the threat to assets and build solid defences against incidents that could ultimately impact the security of venues and/or supporting infrastructures.  In particular the ISP needs to have a flexible response that adapts to changing technologies and attack methodologies.  The pace of change in information systems is such that it will be necessary to keep the designs flexible and able to adopt appropriate new technologies as they emerge.  But new threats also emerge at a significant rate.  The ISP should ensure that venue owners can be confident that they are able to manage their risks effectively throughout the lifetime of the venues.   This reinforces the need to adopt an impact focused, risk based approach that will build the appropriate information security controls (for cyber and other mediums) into the fabric of the venue.  This will ensure that it is capable of deterring, detecting and defending against the inevitable attempts to compromise its operations.  It is impossible to prevent all compromises from internal and external threats, but an effective ISP will support a security architecture necessary to create a resilient operation; respond to incidents effectively; learn from security breaches; and most importantly, manage risk within proportionate tolerance levels. 
There are numerous internationally recognized Information Security standards and frameworks that could be adopted[2].  Most national governments also provide protective security advice through specialist organisations.
Building begins
The engagement of security specialists as part of the multi-disciplinary design team will ensure that all the physical infrastructures are inherently secure and resilient, and relatively easy to search for suspect devices prior to the public being admitted.  Once construction of the stadium is underway, it is important that there is a controlled process to review proposed design changes from a security perspective.  This process needs to encompasses both substantive changes to building layouts, (e.g. redesign of a layout), and changes to elements such as the cladding to be applied to a wall.  Such cladding could easily be seen as ‘cosmetic’, but might have been selected for the way it resists explosive blast.  However, this is unlikely to be known to the supply chain, who might propose a similar looking material that was less resistant to blast. 
During the construction phase it is important that: the site is physically segregated from the wider world; the workforce has been vetted prior to being allowed on site; goods and materials are screened prior to site admission;  and frequent verification visits are undertaken.  There are a number of models that could be adopted that could achieve this, for example:
·         An appropriate perimeter barrier, with supporting technology, will be specified to separate the construction site from the surrounding areas.  A typical set-up for a major sporting venue or site would consist of a perimeter fence, supported by CCTV, lighting, perimeter intrusion and an operational guard force around the whole of the construction site.  Individual areas within that, e.g., a Main Stadium, would have their construction site boundaries.  A central ‘Construction Command and Control’ location should be specified to be responsible for monitoring installed systems (e.g., CCTV and intrusion detection) and managing the guard force.  If deemed necessary by a threat assessment, measures to guard against vehicle attack will be installed to protect the construction site.  However, such measures need to be considered carefully to ensure that the barriers are suitable for that environment and their installation will not impede the required flow of constructions vehicles.
·         Deliveries of construction plant and materials should be controlled through the use of a Delivery Management System to record details of loads, delivery vehicles and their drivers.  To minimise risk to the construction site, one or more offsite centres should be used to process and check vehicles, drivers and their loads before they are sealed for final delivery to the site.
·         Checks on vehicles should then be undertaken at the boundary to the construction site. For vehicles entering the site, the checks should confirm that the vehicle and occupant details are as expected and that the load has not been tampered with since the offsite checks. For vehicles leaving the site the checks should confirm that no unauthorised goods are being removed.
·         Throughout construction, verification and assurance visits should be undertaken to confirm that potential issues are identified early and addressed. This will include a process for certifying that voids are empty before they are sealed.
Thinking of the staff
It should now be obvious that the number of people working on the project either in offices or on site has risen dramatically from the levels involved at the pure design stage.  This means more people with access to information (some of which may be sensitive) and more people with access to sites and systems that may be vulnerable to malicious activity.  It is therefore necessary to consider carefully the personnel aspects of the overarching security strategy.  This is so often overlooked with attention instead focused on the physical and cyber elements and the people who operate both forgotten about.  It is wrong at this stage to suggest that all staff need to go through comprehensive vetting in order to establish their bona fides and levels of integrity.  That is unnecessary and too time consuming and expensive.  However, care should be devoted to ensuring that, as a very minimum, the true identities of all staff and contractors are fully established and that they all have the appropriate right to work from the host country.  Some staff and contractors will require extra clearance to have access to more sensitive data. 
This is an area where the importance of taking an holistic approach and not operating in silos cannot be overstated.  The security professionals for the venue should take an active interest in this area and not simply leave the matter to the Human Resources or Personnel department.  High quality leadership from the top management layers of the organisation will be necessary to articulate a vision of how the everyday actions of all staff involved in the infrastructure and delivery contribute seemingly effortlessly to the overall security of the event.  If the leadership are clear about the type of event they want to achieve, then it is so much easier for staff to be clear about what they need to do.  So often, weak or absent leadership will be filled by staff doing what they feel is right.  Quite often they will get the tone wrong and this could adversely impact on the overall security stance or inhibit the spectator experience.
Let the games begin
Security does not end when the building phase is over.  Towards the end of this and prior to the venues being used, there needs to be a final process of assurance to test whether the various security infrastructures and systems are fit for purpose.  This is when their actual operation is tested against the original Operational Requirement.  The quality of finish should also be examined.  If the processes described here were followed, then the need for remedial action or reconstruction should be minimal, but as the case studies illustrate, this is not always the case. 
If security has been integrated into the very fabric of the building then it will also support the handling of incidents or emergencies.  An integrated design will enable the event organisers, Police, emergency services and others to respond to incidents, disrupt threats, etc.  The way that security is designed into the structure should aid this and produce an integrated response to a wide range of circumstances, e.g., through the location and functioning of control rooms.  This is the point at which people, processes and technology should all come together in perfect harmony.
Conclusion
So often, security is considered as an afterthought; something to be applied after the design is over.  Not only can this be expensive, but frequently it will not produce the desired levels of protection.  By considering security at the very beginning of the design process, taking an holistic approach, thinking in terms of impact and involving relevant experts throughout that and the building phase, it is possible to produce discreet yet effective measures at reasonable cost that can deliver high levels of assurance to event organisers and others that competitors, spectators and the venue itself will all be protected against malicious activity.  This takes dynamic leadership from general management, supported by appropriate security professionals.  Working together from the very beginning of a project they can make security enhance a sporting event rather than being seen as a tax upon it which is often the (wrong) perception.   

October 2013

The author (Roger Cumming) is the Technical Director of Atkins’ security business. Atkins, an international design, engineering and project management consultancy, was heavily involved in the design of the infrastructure for the Olympic Park and temporary venues for London 2012.





[1] In the UK the Home Office Centre for Applied Science and Technology is responsible for the testing and assessment of security equipment.  The Centre for the Protection of National Infrastructure (CPNI) provides advice to the companies that run the UK’s infrastructure on how to protect themselves from national security threats.
[2] For example: ISO: 27001 and ISO: 27002, Information Security Management Standards; the 800 series from the USA’s National Institute of Standards and Technology (NIST), in particular NIST 800-53 and 800-82 for Industrial control systems.  There may also be applicable standards from the International Society of Automation (ISA) and others such as IEC62443 which covers the protection of plant networks.