Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, August 16, 2020

 The New Centurions

New Concepts for Policing


 

When I first started to outline this article, I was thinking about big bold steps to be taken in order to re-direct police services.  I got the idea from a tweet by Sen Harris, in which she said, “We need to demilitarize the police”.  Well, I couldn’t disagree more.  The reason police departments have military equipment is so that they can deal with the most serious violent crimes and criminals.  Police departments need armored vehicles and high caliber weapons, so that they can deal with gangs and organized criminal enterprises which are using those tactics, but they don’t need to bring them every time they engage the public (we’ll talk about that as a separate issue next time).  Those enterprises have no regard for human life, if they did they wouldn’t be kidnapping kids or young adults and forcing them into slavery, they wouldn’t be selling drugs to the most vulnerable within our society, just so they can make money.  So, to fight in this war the police have to have military style weaponry and they should be using them with efficiency and effectiveness.  You wouldn’t throw rocks at someone with a bazooka, so why would we expect the police to fight without the right tools.

But for the purpose of this article I’ll leave the strategic planning up to those responsible for administration of police departments whether at the local, State or federal level. 

Great interview about the changes needed in policing here:

https://twitter.com/FareedZakaria/status/1272231871896850434

Instead I want to concentrate on a more tactical or operational approach with simple solutions that will most probably be unpopular, especially with the rank and file, but I believe will go a long way in changing the culture within departments, assist in avoiding corruption or unwanted police behaviors and change the way the public views and interacts with the police.  The good news is, these ideas for change don’t need the rule of law.  They just need to be implemented as a new way of thinking and conducting business.  This will take real leadership; change is driven from the top.  While the need for change may be driven from the masses, change actually comes about because those in-charge decide to make the changes being requested. 

In ancient Rome, the Centurions were the professional officers of the Roman Army.  They commanded the troops, which sometimes meant that from time to time they enforced Roman law outside of the military legions they commanded.  Unfortunately in those times they also administered punishment by cutting or burning people’s hand off for stealing or other petty crimes or used a vine staff, with which they disciplined even Roman citizens who were protected from other forms of beatings by the Porcian and Valerian Laws (what punishments Roman citizen could be subjected to; they were not allowed to be humiliated or demeaned with degrading or shameful forms of punishment; such as, whipping, scourging or crucifixion.  Non-citizens and slaves had a different set of rules).  Hopefully, we’re way beyond that.  

At least, I like to think we are, but we can create new Centurions by:

First, stop appointing police chiefs based on political affiliation.  Currently, for the most part chiefs are either appointed by the city/county board, mayor or other elected officials or are elected themselves. Both methods are political.  Since laws are apolitical and should be enforced apolitically, so should the appointment of the police charged with enforcing those laws equally and justly.

Second, first and second-line supervisors should take a test that includes police administration, social – emotional, non-escalating skillsets, leadership skills, human rights and the protection of personal dignity training.  Allot more time needs to be spent of developing social skills needed in conflict resolution, at least at the same level that they spend on equipment usage techniques.

Thirdly, patrolman should be assigned “beats” randomly but with purpose and clarity.  The most troublesome neighborhoods should be assigned to those officers with the most experience.  There should always be a senior and a junior officer together whenever possible.  We should get rid of the notion of “Partners”, whereby, the same two people are assigned a specific sector each and every shift, so that they always work together.  Sure, there is an advantage to having “partners” as the patrolmen become familiar with each other and the neighborhoods they serve.  But conversely, they also become “too friendly” with each other or the residents, and worse, by becoming either complacent or tolerant of bad behaviors.   Additionally, the argument will be made that the patrolman needs to be able to trust his/her partner with their life.  That’s true, but if you can’t do that with everyone in the department, then there’s a problem.  The public also demands the same expectation. 

Over the years we got away from two man patrols due to budget cuts and other factors.  I think we should go back to them.  No more single patrols.  I’m not saying just to double everyone up by consolidating patrol zones.  No, this will only lead to longer response times.  Instead, I’m saying double force sizes by bringing on new officers.  Many will say, “We don’t have the money”.  To me that’s just another way of saying, I’m too lazy to do the hard work to figure out how this can be done.  So, I don’t buy the argument that it will be too costly.  Think about this, we just spent several trillion dollars on corporate and public welfare for COVID relief and didn’t bat an eye.  Not to mention the 10’s of trillions we’ve spent and are spending on the bank bailout of 2008.  It’s not about money, it’s about deciding.

Fourth, everyone in an administrative position, who is physically capable, should work “the road” once a week or a couple days a month – maybe a weekend or night shift.  Even those will mobility issues could have a role.  This gives fresh eyes and reminds everyone why they are there – to serve and protect.

And finally, move personnel around within departments, within organizations.  The military does this with regularity and at tremendous costs.  But the benefits far outweigh the costs.  Each move brings “new life”.  Getting a fresh set of eyes on things is invaluable.  It brings with it; fresh and innovative ideas, opportunities for personal growth, problem solving, and deters complacency and stagnation.  It also roots out those who have a history of misconduct.  New supervisors usually don’t tolerate bad behaviors that old supervisors allowed to go unaddressed. 

A recent study of police training revealed, that on average policeman in the US receive less than a thousand hours of training, whereas their European counterparts receive thousands of hours.  Most police chiefs in Europe are also lawyers or have law degrees, as do many mid-level supervisors.  I don’t believe this requirement exist within the US.  Maybe it should?  

Calls for defunding the police are just wrong.  Police departments need more resources not less.  That said, so do social programs that address the root causes of criminality and unwanted behaviors.  We need to add funding that teaches non-aggressive tactics and de-escalation techniques, social – emotional learning skills, and coping tools that deal with attitudes and behaviors.

I worked for ten years with the Carabinieri, the Italian National Police.  In those ten years I never once saw them man-handle anyone.  Sure they put people in handcuffs and took them to jail but I never witnessed any aggressive tactics on their behalf.  They always talked the guy into getting handcuffed. 

Great article about Carabinieri tactics, here:

https://foreignpolicy.com/2020/06/10/american-cops-could-learn-a-lesson-from-italys-carabinieri/

To illustrate my point, a few years ago, my son was travelling from Italy to the US.  He had been visiting his aunt and grandma.  At the airport in Rome, he placed his backpack on the conveyor belt at the x-ray machine.  After it was scanned, a Policeman approached him and asked my son to accompany him.  They went to a room, and the policeman pulled an apple, sandwich and serrated kitchen knife from his backpack.  The Policeman said, “Young man, we have one question, who packed your lunch your Mom or your Grandma?”  The Policeman knew, my son being in his thirties was old enough to know better than to bring a knife through the checkpoint.  He also knew that Moms being Moms in Italy meant, someone else had packed his lunch; Mom or Grandma had packed the knife so he could peel the apple, it was just logical. Clearly my son wasn’t a threat.  The Policeman kept the knife and my son boarded his plane.  I believe that had a similar incident occurred here in the States my son, would most probably have gotten arrested for possession of a deadly weapon, would subsequently have a criminal record, which could have an impact on his employment possibilities. 

We have a saying in the military that, “soldiers will be soldiers”.  In other words without supervision they will do stupid stuff.  Good behaviors AND bad behaviors are learned.  Shouldn’t we be doing everything we can to make sure good behaviors are nurtured, if so it’s about leadership?

Change comes from big and bold thinking.  Look at, putting a man on the moon.  Pretty big stuff there!  We didn’t know how we would do it but we decided we would.  Then it came down to many, and I mean many, small steps to get us there.  Well, if we are to truly reform the police, policing and the interactions they have with the public, we’ll need to take many small steps to get there.  NASA had many failures along the way, but eventually they figured it out.  I believe we can too, after all this is America – this is who we are.


Sunday, April 19, 2020


4 Spring Cleaning Tips for Keeping Criminals from Acting Criminal





I’m sitting here in my office writing this Blog post, while wearing a surgical mask.  My wife says, “I don’t have to wear it because I’m not out in public”.  I answered, “Well, I’ve heard my computer can get a virus, and I don’t want it to come from me, lady”. Touché


Like every good spring cleaning job, you have to set some goals.  My wife’s  - windows.  Mine - not falling off the ladder.


When it comes to security spring cleaning though, our first goal needs to be keeping criminals from acting criminal around my property.  Here are 4 tips:


Understanding that your property has a number of layers that you can use to you advantage is essential.  Those layers, if you have them are: property line, internal fence-line (if present), building facade and special spaces within the house.  For instance, I don’t have a fence in the front of my house but I do on the sides and back of the property, so my property line and fence-line are one in the same.  So for that reason, I look at every layer I do have and determine if I can deter, delay, detect and defend against a would-be aggressor breaking in and stealing my stuff.


Deterrence is kind of hard to define.  Mainly, because if the deterrent is perceived to be too tough, then it will get circumvented by those who are actually authorized, and then what’s the purpose of having it in the first place.  Besides, a dedicated threat will not be deterred.  He/she will bring the tools necessary to defeat whatever the deterrence is designed to do. Now, don’t get me wrong I’m not a defeatist.  I do believe you have to do whatever it is you can and evaluate what you’ve done honestly.  If there is still pain, do it some more.


Secondly, my goal is to slow a person down if they have ill-intent enough so that I can detect them.  So instead of a straight sidewalk up to my door, I have a sidewalk that meanders or crosses my front lawn, so while standing inside my living room or office I can see them as they approach.  If someone doesn’t follow the path of the sidewalk and traipses across my lawn then that is an indicator to me that something’s not quite right.  Now, it could be that the person is just lazy or too tired or it could mean something far worse.


Next remove all possibilities of hiding.  So bushes and shrubs that are within 10 feet of windows and doors should be removed.  If you simply must have them for aesthetic purposes, then they should be located away from the building so that as a person approaches they can see around them.  Bushes should be trimmed to a height of three/four feet above ground level and trees down to seven/eight.  Anything higher or lower causes opportunities.


And finally, check windows and doors, to make sure they close properly.  And, while cleaning the windows and gutters, check the outside lights, especially those on a sensor.   

Another thing, stand at your property line at dusk and see if someone can see inside your house while the lights are on and can see that you’re at home.  If they can, then even if you leave lights on to give the appearance that someone’s home they can see that you’re not.  We draw our curtains at dusk so that you can’t see through.


When I said, defend above I didn’t mean confront the bad guy and whip out a gun.  Trust me your stuff is not worth someone’s life.  On the other hand, if they are physically harming or threating harm to my family I can guarantee you that they’d wish that I only had a gun. 


Send me an email and I’ll send you a 28 question checklist you can follow.  FREE.

Sunday, February 16, 2020

Security - It Really is a T or F Question



I know many of you when you read the title thought, “Yep, security is a true or false question.  You’ve either got it or you don’t.  Well, purposefully I didn’t spell out what the T and F stood for. It isn’t true or false.

As many of you know, for some time now I’ve been advocating for a softer approach to security, especially when it comes to the design and layout of high-occupancy spaces.  And during my years of advocacy I’m come across some, who will agree, and others that play lip service and say, “Oh yea, that’s what we should do.”  And when they have their next opportunity to make the change they go back to their olds ways with the bigger, better, faster, stronger, in your face approach.
Recently, while collaborating with a local school district we took a softer approach.  After an active shooter threat (fortunately stopped prior to being carried out due to social media monitoring), parents wanted the District to heighten security by adding guards and cameras, and constructing fences on the perimeter.  They wanted this because that’s what they’ve been seeing on TV.  After every school shooting, there’s a rush to install more cameras, higher fences, and to hire more guards.  I don’t blame the parents; I blame the security companies who are selling their products with the idea that if one is good, two must be better – the more products sold the better for the bottom-line.  Some may argue that adding visible, in your face, deterrence works.  I’ll admit, there is some benefit; however, a dedicated threat will not be deterred – they will bring the tools necessary to circumvent whatever is in place. That said, we can argue until the cows come home about the benefits.  From my point of view, it’s not about effectiveness.  It’s about the psychological impact it has on our youth.  Recently, a local school board approved a bond for security upgrades.  The newspaper ran a picture of a ten foot metal fence gate to allow campus entry and mentioned that everyone would go through a metal detector.  I showed the article to a Latino friend of mine and he said, “They’re always looking at us like we’re all criminals.  The guys are in gangs and the girls are ‘ho’s.”  Is this the intended message?

Additionally, research shows us that “hardening” causes anxiety and even affects performance.  
https://network.aia.org/HigherLogic/System/DownloadDocumentFile.ashx?DocumentFileKey=110227d5-dde4-9c0d-fa52-a23257148cca


Our approach is to add security features that are “hidden in plain sight”.  For example, instead of a fence to keep out trespasser we suggest a buried co-axial cable sensor system.  It provides a warning that someone has breached the perimeter, yet is unseen.  Another example, to keep unauthorized folks off of the roof we suggest placing large flower pots with bougainvillea near drainage pipes or next to other features that a person could climb to get to the roof.   Again, a solution that is unseen.

My article published in American Security Today magazine January 2020 https://view.joomag.com/2019-champions-edition-2019-champions-edition/0683429001578075665/p148?short

So which message do we want to send?  The message that we don’t trust you and we think there will be an incident or the message that we trust you, we expect you to act trustworthy and you can expect the same of others?

My book, The Solutions Matrix: a  Practical Guide to Soft Security Engineering for Architects, Engineers, Facility Managers, Planner and Security Professionals has a Quick Glance Checklist that will allow you to list your current security solutions and then list your ideas on how to take a softer approach.  Order your copy today via the CONTACT US link at https://hainessecuritysolutions.com



Sunday, November 17, 2019


Known knowns and unknown unknowns






"There are known knowns" is a phrase from a response United States Secretary of Defense Donald Rumsfeld gave to a question at a U.S. Department of Defense (DoD) news briefing on February 12, 2002 about the lack of evidence linking the government of Iraq with the supply of weapons of mass destruction to terrorist groups[1]



This quote tells us something about risk management.  Basically there are threats we know about and there are threats we don’t know about and there are threats that we don’t know we don’t know about.



From a risk management standpoint, that’s pretty disconcerting. 



In order to understand the unknowns you have to look at things from the “bad guys” perspective.  In other words, see what the "bad guy" sees.  And to do that you must understand that there are four aggressor types of criminal/man-made threat groups; criminal (sophisticated/unsophisticated, organized/unorganized), protestors (organized/unorganized), terrorist (domestic/transnational/state-sponsored), subversives (saboteurs/intelligence agents [state/non-state sponsored]).  In an effort to design better mitigation strategies planners must understand the “bad guys” motives or the reason(s) behind why they do what they do.  There are also four primary aggressor objectives; inflict injury or death to people, destroy or damage facilities, property, equipment or resources, steal equipment, material or information and create adverse publicity.



So how can I plan to reduce their effects let alone mitigate them?  The answer is really easier than you think.   Traditionally in risk management, we look at things from a probability standpoint.  We ask the question. “Will it happen here, and if so, what will the impact be”?  I believe, likelihood has little influence on risk.  I believe likelihood comes into play when talking about funding.  Our risk management methodologies assume the threat will be successful 100 percent of the time.  We calculate likelihood when it comes to cost benefit.



Our Asset Based Risk Analysis (ABRA) and Critical Asset and Infrastructure Risk Analysis (CAIRA) methodologies combine the aggressors motives and objectives with what the asset owner sees; thereby, giving a complete picture of risk.  



More about ABRA (Platinum GOVIES Award 2017 for Best Government Security Risk Methodology) https://view.joomag.com/march-2019-ast-magazine-march-2019-ast-magazine/0952115001553308799/p4?short



More about CAIRA (Platinum 2018 ASTOR Award for Best Risk Analysis Methodology in Homeland Security) https://view.joomag.com/july-2019-ast-magazine-ast-july-2019-magazine/0612002001563068627/p60?short



More about risk management and developing mitigation strategies can be found in my new book, The solutions Matrix: A Practical Guide to Soft Security Engineering for Architects, Engineers, Facility Managers, Planners and Security ProfessionalsOrder here  https://americansecuritytoday.com/dont-surrender-to-fear-new-book-the-solutions-matrix-by-doug-haines/





[1] Full quote: Reports that say that something hasn't happened are always interesting to me, because as we know, there are known knowns; there are things we know we know. We also know there are known unknowns; that is to say we know there are some things we do not know. But there are also unknown unknowns—the ones we don't know we don't know. And if one looks throughout the history of our country and other free countries, it is the latter category that tends to be the difficult ones.

Sunday, September 15, 2019


How Preventing the Wrong Threat Will Cost You




My nephew used to work for an IT company.  Upon returning to work after Christmas holiday, they noticed that the rear windows of the building had been broken and all of the computer equipment had been stolen.  The owner of the company did what anyone would do.  He called a security consultant. 

The consultant recommended fixing the windows, adding motion sensors in the hallway and an access management system at the main entrance.  


When the company employees returned after the Easter weekend, they noticed the rear windows had been broken out – again, and all of the computer equipment had been stolen – again. 


Why did this occur?  The security company had misanalysed the Design Basis Threat or DBT.  

Everything of value has a threat that goes with it.  If it has value then someone wants it - either the owner or someone else.  It is also possible that a treat can be naturally occurring, like a earthquake or tornado. Usually, protection from these types of threats are governed by ordinances or laws; i.e., earthquake or tornado protection in construction standards.  For man-made threats, on the other hand, there really isn't any legislation that governs prevention or protection, so it's up to us to focus on man-made threats.  There are four general categories of aggressor types; 1) criminals (sophisticated/unsophisticated and organized/unorganized), 2) protestors (both organized/unorganized), 3) terrorist (domestic/trans-national/state-sponsored, and 4) subversives (saboteurs/foreign intelligence agents).  Each type of threat has an Modus Operandi or tactic and tool it uses to execute its objective.  If you make a list of what those may be you can actually design the space so that it provides protection to the things of value inside.  It is also important to understand the objective of man-made threats, too.  They fall into one or more of these categories; 1) inflict injury or death to people,2) destroy or damage property, equipment or resources, 3) steal equipment, material or information, or create adverse publicity. Understanding the motives, the tactics and tools they use will go a long way in prevention and protection.

The solution the security company had provided failed because, they didn't address the correct DBT; which was, breaking and entering and not unauthorized access.  Although, entering through the window is a form of unauthorized entry.  They had recommended the solutions they normally would suggest to deter or reduce the effects of theft, and focused on electronics, but they hadn’t addressed the DBT of the windows being breakable in the first place and didn’t add non-electronic solutions to the mix.  Had the windows been replaced with laminated glass they would not have been able to be broken and then the other countermeasures would have been effective.  Another solution would have been to prevent access to the parking lot behind the building.  I don't prefer this method because it would be more aggressive and unsightly to use a gate or fence with gate.  Just replacing the windows would not have changed the aesthetics of the space, so that is my preferred solution.

More about non-aggressive/aesthetically pleasing security measures can be found here: https://www.securityindustry.org/2018/04/05/the-puppy-movement/

Sunday, August 18, 2019


The Need to Push Down Silos





A few years ago, a friend of mine, trying to generate additional students for the classes I teach, asked his cousin who works for a very large architecture and engineering firm in the new World Trade Center in New York City, if they would be interested in attending training on integrating security technologies into building design.  His cousin answered something to the effect, “No, we leave that up to the client after we turn the building over to them”.  While his cousin’s answer is not surprising it is disappointing and confusing to me. 



Not surprising because I’ve heard that so many times before.  In essence, everyone stays in their silo and the connection between the disciplines usually only involves answering questions about the project and clarifying requirements; architects architect – engineers engineer – and security securities, if you will.



It’s confusing on two levels.  First, at the beginning of every project the architect gets the client’s desires list; i.e., the building should be blah, blah, blah. Right from the start the architects develop a mental picture of what the building should look like.  Next he or she begins to include all of the regulatory requirements or “best practices” for design.  Best practices are nothing more than this is how it’s normally done.  In New York City, for multi-story buildings in Manhattan the façade default material is glass in the Mid-West it is reinforced concrete or masonry units.  Meeting regulatory requirements deal with disability act, fire and safety codes, such as, hallway width, stairs, doors and windows, and elevator placement, etc. and depending on the region some weather related events.  And second, very seldom are man-made threats considered.  This contributes to the fact that man-made threats continue to occur despite large amounts of money being spent on security measures. I guess the argument could be made, that “well, we’re not required to consider them like we are for natural threats so we don’t need to; besides it will drive up costs”.  On the surface this makes sense but if you dig just under the surface your next thought should be, why don’t “best practices” apply?



The Department of Defense, and some other federal government agencies to a limited degree, requires that integration mitigation strategies be included in their building design review process regardless of where or what type of threat is involved.  In fact, it’s mandated that all threats, including man-made threats be addressed by a group of stakeholders at the onset of any new building construction project and for renovation projects that meet certain thresholds or “triggers”.   The stakeholder group determines the “design basis threat” to the building and its occupants and the level of protection required based on the number of people occupying the space.   These two factors ensure that the appropriate amount of money is spent on protection options and in the unlikely event a catastrophe does occur; injury and death will be kept to a minimum.



By bringing all stakeholders together from a variety of disciplines, everyone 1) has a chance to air their requirements and needs, 2) buys-in to the group’s decision on which threats will be addressed and support the “DBT” and the level of protection required, and costs are kept down.  Adding electronics in the form of surveillance or other technologies lies with the owner after the project is completed.  So in the short term, the cost of this equipment and its installation is currently absorbed by the owner/client and is not part of the building costs.  This “trick” helps keep the building design costs down but doesn’t adequately protect people or the facilities they use.  But more importantly, the real costs to the client come after the installation from the long term requirement for equipment maintenance and manpower. 



Since buildings are currently designed with everyone, remaining in their silos, with  limited exception, the process is treated as if it were a vertical process, when in reality it’s a horizontal one.  The “silo effect” and the isolation it causes make security an “add-on” and limits its efficiency and effectiveness.  

Sunday, June 16, 2019


Case Study: Unimpeded Access Allows Illegal Dumping

The issue was that people were driving up to the banks of a stream and dumping trash; i.e., tires, mattresses, rubbish, etc.  The city called a security consultant.  And as expected, he recommended adding a camera to the site so that “things” could be monitored.  The camera fed back to the superintendent’s desk.  Of course, when the supervisor wasn’t there (weekends, evening/late at night, attending meetings, lunch, naps, etc.), all the time when someone would dump trash the dumping occurred and continued.  The superintendent was scratching his head on what to do.  After all, he just spent several thousands of dollars on the latest technologies and they didn’t seem to work.
Our solution was not electronic.  Instead, we suggested that they build a raised berm/curb using natural landscaping (trees/boulders/bushes, even park benches) so that the vehicle couldn’t drive up to the water’s edge in the first place.  We suggested specific landscaping strategies due to low cost and ability to prevent vehicles from reaching the stream.   We imagined that since the culprits couldn’t physically access the stream embankment without using a vehicle they would be  less likely to want to carry heavy objects from the roadway, across a bicycle/walking path and then into the wood clearing to reach the stream.  Our second reason was to ensure the aesthetics of the area were kept intact.  Sure, we could have suggested a fence along the embankment to deny access and achieve the same effect, but who wants to walk along a fence with barbed wire when they’re taking the dog out or jogging or cycling.
Related articles: 

Sunday, May 19, 2019


Getting Everyone to Speak a Common Language




A couple weeks ago, I was teaching a class about using building design to deter criminal activity, including terrorist attack, and when it fails reduce its effects and prevent mass casualties.  After the obligatory introductions, I said something to the effect, that building design is a matter of reducing risk whenever and wherever possible.  But in order to do that you have to the know your “DBT”.

Based on the blank stares, I got back, I knew something was wrong.  So, I said it again.  Still the deer in the headlights looks.  So, I said, “Everyone knows what DBT stands for, right”?  Still nothing.  Not one person raised their hand.  I was taken aback.  After all the class was made up of seasoned architects, engineers, planners and security folks.  I would have thought, at least, one or two would have known what I was talking about.

So, we spent the new few minutes talking about Design Basis Threat or DBT, if you will.  DBT is identifying your threats, their tactics, the tools they may use and then designing your building to deter or prevent them from happening, in the first place, and understanding that if they do happen you can reduce their effects if you’ve included reduction strategies into the design.

The very first thing to do is to assemble “the planning team”.  The idea that “it takes a village” needs to be used here.  The team should include architects, engineers, facility manager, security, end users and others.  It’s important to bring these folks together, so that they can discuss the parameters of what they are trying to accomplish and “buy in” to the project.  If done correctly at the beginning of a project, security costs can be kept to a minimum, usually somewhere around five percent of the total project costs.  If security comes in at the end of the project this cost may skyrocket to thirty-forty percent, because of the long term cost of equipment maintenance and especially, personnel costs.

Once the team is assembled, the first step is to identify the threat or threats.  Threats can be divided into two categories; natural and man-made.  Fortunately, laws and ordinances exist that address natural threats in building design; i.e., earthquake, flooding, fire, tornado, etc.  Man-made threats on the other hand – not so much.  Although, that is changing slowly.  Last year, federal legislation was signed into law that addresses the use of hostile vehicles as a method of attack in public spaces.  We’re still waiting for the DHS report the law requires and its subsequent findings and recommendations.  I’m particularly concerned that our government hasn’t the courage to attack hostile shooter legislation, when it is so needed.  But that’s another Blog topic for another time.

The second step is to identify the motives of the man-made threat,; i.e., causing injury or death, theft or unlawful removal of property or equipment, damage to property or facilities and causing adverse publicity.  Then we need to figure out what type of groups commit these acts; criminals (sophisticated/non-sophisticated, organized/unorganized), protesters (organized/non-organized), terrorist (domestic/trans-national/state-sponsored) and subversives.  

Then we look at the tactics they use; stationary or moving vehicle, different types of weapon usage, forced entry, etc.  Each tactic uses a different set of tools. That said, each type of tool use has a countermeasure available to reduce its effectiveness.

If we understand their motives, tactics and tools, we can design countermeasures into inhabited space that reduces the possibility that they will occur and when that falls short reduces their effects. 

My book, The Solutions Matrix: A Practical Guide to Soft Security Engineering for Architects, Engineer, Planners and Security Professionals, will be available in September.  It will outline the processes used to determine DBT, have a quick reference chart that outlines how to counter each type of man-made threat and provide examples of practical real-world solutions.  

Sunday, January 20, 2019


The Truth About Walls (Fencing)




A few years ago, I was asked by the editors of Security Middle East magazine[1] to write an article about perimeter security.  During the conversations with the editor that lead to the eventual article, she asked me to summarize what the article would be about.  I told her that in order to understand perimeter security you first needed to accept the fact that if you have a ten-foot fence the bad guy will bring an eleven-foot ladder. 



The idea that you can build a fence or wall and keep the bad guys out faded out sometime after the medieval ages when new technologies and new ways of conducting warfare came about.  Well, the same holds true today.



If you look up on Google the difference between a wall and a fence you’ll get the following explanation: “A fence is usually a wooden or metal structure that encloses a yard, pasture or other area…The difference between a fence and a wall is that you can almost always see through a fence, at least to some degree, while a wall is solid”.



If you look up fence purposes, you’ll get the following explanation; “A fence is a structure that encloses an area, typically outdoors, and is usually constructed from posts that are connected by boards, wire, rails or netting.  Alternatives to fencing include a ditch (sometimes filled with water, forming a moat)”.



Both definitions suggest that a boundary is formed between property that is not controlled and property that is controlled. 



Whether using a wall or fence, the purpose is to delineate a boundary; usually at a property boundary.  This is the true meaning of fencing or "walling", if you will.  To delineate property boundaries, in other words, you’re over there and I don’t care what you do but it you come over here you need to go down to the access point so I can check you out.  With that in mind, you could paint a line on the ground and put up a sign that says, “stay out or go over there for access”.  Both would achieve the same effect as a wall of fence.  So, why not just paint a line.  Because the value in constructing a fence or wall, is 1) to identify the boundaries of the controlled space, 2) to cause a delay in unauthorized access, and 3) to identify unwanted behavior.  An authorized person will not climb over a fence or wall, tunnel under it or cut through it.  An unauthorized person will, especially if they have nefarious intentions.  So, with that in mind, the fence serves an early warning system.  It tells us when someone breaches it that they have  “bad intentions”.  If they didn’t, they would not breach the fence/wall and would proceed to an access control point to display the proper credentials to gain entry.  Hopefully, the fence will be constructed in such a way as to delay their unauthorized access.  Sadly, even without tools a eight foot chain link fence with three strand barbed wire outrigger can be scaled or climbed over in about four seconds.  With tools, like a ladder or a truck to stand on it takes even less time.



Which brings us to the next truth, unless there is a guard or technology monitoring the fence-line in real time, we have no way of knowing if the boundary has been breached.  We must monitor for unauthorized access, respond to it, and engage the aggressor in real time.  The operative word here is “real time”.  If we don’t what’s the use?



Another thing to remember, no matter how solid, sturdy, high or how many bells and whistles are added, there will always be a way to circumvent whatever is put in place.  The key is, making sure there is enough time to delay the “bad guy or gal” so that his or her behavior can be identified and the “good guys/gals” have time to respond and engage.





[1] Security Middle East magazine article More Power to the Perimeter link https://issuu.com/securitymiddleeastmagazine/docs/sme_july-_aug_2015_web?e=0/14330179

Sunday, December 23, 2018

How to Protect Yourslf Against Burglary or Housebreaking by Using Surveillance Systems and Safe-rooms






I was watching the news the other night and just like every night, they were showing criminals that had broken in to homes while the owners were away.  There was even footage of the family dog chasing the burglar away.  But one story caught my eye.  It was the story of a homeowner who had installed a doorbell system with a camera.  We’ve all seen the ad where the bad guy approaches the home and the owner say “Get off my lawn” or something to that effect.  Then the perps run away.  It was one of those types.

In this particular case, the homeowner was inside the house with her son.  When the would-be burglar approached the door she got an image of the burglar standing by her front door.  He knocked on the door and pulled a gun from his waist band.  The homeowner took her son and hid in a closet and called 911.

Can’t say I blame her.  After all this was more than a burglary this had all of the potential of being a kidnapping, sexual assault or worse.  I think she did the right thing in hiding.  That said, however, a closet offers very little protection from a dedicated intruder.  What she needed was a closet that had been converted into a safe-room.  A room that was impenetrable from the outside.  There are materials out there that can be used in new construction or retrofitted to an existing closet space for a few thousand dollars. It could even be a DIY project over a weekend.  Shouldn’t every home have one? 

But the real problem here is that the homeowner had bought the security system thinking that it would protect them.  I guess it did, sort of, because she was able to see the perps and take action.  The standard action is to tell the perps to go away.  She didn’t do that, so in essence she didn’t use the system the way it was designed to be used.  Fortunately, the perps weren’t able to force the door open and eventually gave up and left. 

There are two things to remember about having a home security system; 1) it must be used the way it was designed in order to be truly effective, and 2) unless, there is a police or guard force’s immediate response, it really only collects evidence.



More tips on what you can do so it doesn’t happen to you, here:  https://reader.mediawiremobile.com/NYREJ/issues/203922/viewer?page=57



A one-day class on safe-room and shelter design and construction will be conducted on 20 June 2019.  Sign-up by calling 805 509-8655 or sending an email to info@hainessecuritysolutions.com  

Sunday, November 18, 2018

Architects Meet Security Halfway

Architects Meet Security Halfway
What Should They Do to Go All the Way? 


The normal process for building or inhabited space design goes something like this:  the client goes to the architect and describes his/her vision.  The architect interprets that vision using their creative juices.  That’s a good thing! Once the client approves the vision then project is handed over to an engineering firm to “build the guts”. Once the infrastructure is done and the project is finalized.  The client accepts the project.  At that point, it’s up to the client to coordinate the security features of the designed environment.

Sometimes, this process works.  But more often than not, it doesn’t for a very simple reason.  Everyone sees the project differently.  The first questions the architect asks the client is how many people, what type of space (open/shared/closed offices, how many floors, etc.?  During that conversation there should be questions asked that regard the Design Basis Threat; i.e, what types of threats are we trying to protect against? This particularly the case when it comes to man-made threats; such as, active shooter, hostile vehicle, insider threats.  Natural threats to buildings and people are usually governed by ordinances or codes; fire, earthquake, high winds, etc.  Man-made threats on the other hand are not usually governed by ordinance.

That said, when understanding man-made threats it is important to identify several keys elements of the threat:
1) Types of aggressors threats (covert or overt, group or individual, organized or not)
2) Aggressor motivations or objectives (inflict injury or death, damage or destroy property, steal equipment or materials, and create adverse publicity)
3) Aggressor tactics (both the modus operandi and the tools needed to be successful)

Unfortunately, these elements are usually left up to the security consultant towards the end of the project.  If they were considered during the initial 15% phase or 35% phase of the project, it could easily accommodate countermeasures that mitigate these identified threats purely by designing the space to do just that while still maintaining functionality and aesthetics.

The Department of Defense, Department of State and Veteran’s Administration mandate that a security representative be part of the design team from the very beginning.  The civilian world should follow suit, instead of the current halfway method.

Other trends in the built environment are discussed here:
Security Industry Association Technology Insight, Spring edition

Security Industry Association Technology Insight, Fall edition



Sunday, August 19, 2018





Parents and School Administrators are Buying
Security Equipment That Won’t 
Protect Children – Why?






Salesmanship and fear are the two main reasons.  Fear because active shooter events are more commonplace than a few years ago.  The recent discovery in New Mexico of abducted children being trained to carry out armed attacks at schools is frightening.  Since the federal government won’t address some of the underlying issues of gun violence by creating sensible legislation maybe they can concentrate instead on finding the horrifying number of missing kids that occur every year in America[1].  Just saying.



In the meantime, parents and school administrator know that something has to be done and have taken matters into their own hands.  

I applaud many States and school districts that have taken steps for comprehensive security improvements.  Unfortunately, there are an equal number of school districts that have only made superficial changes that really don’t offer protection from the active shooter threat or errant vehicle threats.  

Right after the February 14th event in Parkland, everyone wanted to put more resource officers on campuses, more cameras and more access control.  While on the surface these may be good ideas, just getting more is not enough.  There must be processes in place that make them effective.  For example, if a school increases the number of CCTV cameras, then who monitors them in real time becomes essential.  Unless monitored in real-time, they only have evidentiary value.  The real value of CCTV is that it allows investigators to go back in time and figure out what happened.  We don’t need after-the-fact protection. 

Students and staff need to rely on protection that will actually protect them[2].



Bulletproof - C'mon really?

I saw a news report a couple days ago about a company offering “bullet proof” backpacks.  My antennae went up – way up.  There is no such thing as “bullet proof”!  The correct term is “ballistic resistant” or “bullet resistant”.  It may stop some types of bullets but it won’t stop all.  Therefore it is bullet resistant and not bullet proof.  Shady salesmen will play on your fear and lack of knowledge in knowing the difference.  Anyway, the news reporter had a marksman fire two types of handguns, which the backpack manufacturer said would be stopped, and they were, but when rounds from an AR15 (the most common type of weapon used in school mass shootings) were fired and the rounds went straight through the backpack and into the dirt berm behind.  The reporter asked why, and a guy whom I believe to be a company spokesman, said something to the effect, “well, it was shot at without books and binders being inside. That would change everything”.  To suggest that books and binders offer ballistic protection is just ludicrous.  Backpack manufacturers if I’m wrong AND you have the data to prove it!  Then do so and I will publically admit I was wrong.  

I’m amazed that Walmart and Costco are selling these backpacks for upwards of $100 and apparently do not make this distinction.  

Even if the backpack will stop a .9mm or .45mm, a person would have to be wearing it and be shot from the back.

Use Whatever You Can  



Police Departments and some companies have made a very profitable business out of teaching Run-Hide-Fight.  A defense strategy that teaches: run if you can, hide if you can’t and fight if you have to.  At first, this concept makes sense but the reality is the instructions being given during the R-H-F training actually teaches people to hide and use whatever they can for protection, or in worse case scenarios, use whatever they can to fight.  With this in mind, the idea that a student could hold a backpack in front of them and hide behind it, to me seems a little unreasonable.  I have a hard time imagining a ten year old reducing herself down to the size of a book-bag.  

Instead we should be teaching, to get out - Run-Run-Run - no matter what. Throw a chair through the window, punch thru the dry-wall - but do something that allows you to escape.  The idea of waiting for the "cavalry" to arrive and save the day is just crazy.  We could start designing all occupied spaces with, at least, two avenues of escape.  

This will take a considerable amount of time because first, we have to change our mindset about how we think about high occupancy spaces and how to design them to our advantage, and second, we have to actually implement these concepts into retrofitting classrooms or building new ones.


Don't D-I-Y This


A couple weeks ago, I was sitting next to a second grade teacher on a flight to Houston.  Of course, the conversation got around to school safety.  She said, “I don’t think about it.  I mean, I know what the security measures are for sheltering-in-place and fire drills and such but I really don’t give it much thought, and especially the “big stuff”.  I assumed she meant events like active shooters or terrorist attacks.  She’s right – she shouldn’t be worrying about security.  She should concentrate on teaching.  Educators should not try to D-I-Y this.  Instead, they should contact security professionals that are agnostic to products and are concerned solely with providing effective security solutions.  
That way, educators will get honest protection options that address issues on multiple levels and not just be sold more products.



[1] National Center for Missing & Exploited Children   http://www.missingkids.com/KeyFacts
[2] One More Town – One More Family – One More Angel – One More Funeral February 22nd 2018 on-line edition of American Security Today.  https://americansecuritytoday.com/one-town-one-family-one-angel-one-funeral/