Showing posts with label threat. Show all posts
Showing posts with label threat. Show all posts

Sunday, May 17, 2020

Everything I know about security I learned in kindergarten and I've been updating ever since

I know many of you remember that in kindergarten we learned to play fair, share tools, put things back in “the cubbie” where they came from, put your name on your stuff, be quiet during nap time and in general to be good neighbors.  Well, I learned something else, too.  LESSON LEARNED: HE WHO HAS THE TOYS GETS TO CONTROL THE GAME AND IS THE BOSS OF THE OTHER KIDS.

Fast forward to the third grade, I learned that if someone was bullying me,  I had to fight them to get them to stop or get someone else who would do that for me.  I know, can you believe that this beautiful face was getting bullied in the third grade.  Well, it’s true and all because I kissed a girl who was a fifth grader.  So I did what every skinny, respectable guy would do – I got her to beat him up. LESSON LEARNED: GET SOMEONE ELSE TO DO YOUR DIRTY WORK!

When I was in the fifth or sixth grade, my criminal career started and ended in a span of a few minutes.  You see, there was a pack of rubber bands on the shelf at the Ben Franklin store and I really wanted them but I didn’t have the money.  I put some in my jacket pocket and left the store.  As soon, as I was walking out a county sheriff car pulled into the parking spot directly in from of the store.  The store had a revolving door, which allowed me to reenter the store without ever really exiting.  I put the rubber bands back on the shelf and waited for the sheriff to leave the store before I went home, scared to death.  I have to admit, every time I’d see a police car while growing up I always wondered if “they knew about that” incident. LESSON LEARNED: ONCE YOU’VE DONE IT YOU’VE DONE IT FOR LIFE.

And then upon entering the military, I became an Air Policeman.  God works in crazy ways.  Since I was mostly stationed in Europe from the time I was twenty until I retired in 1993, my biggest security lesson was tracking terrorist activities and fighting the “the Communist, the bastards”.  LESSON LEARNED: THERE ARE BAD PEOPLE OUT THERE WHO WISH ME (US) HARM.

Later in my career, I thought and was taught to think this way, that all you had to do was put a camera on it to watch or post a guard and crime would stop.  Your stuff would be protected. Neither a camera or a guard will prevent, they may deter, and unless the response force is within a reasonable distance to respond they probably won’t deter either.  I’ve always wondered why organizations spend thousands and still get “ripped off”.  Upon analysis it usually comes down to them using the wrong mitigation strategy for the wrong threat or the security is “so tight”  it becomes a burden or tax and people don’t want to pay the tax, even those who are authorized to do so.  They’ll find a way around it so that life is convenient. So, unless your security system is specifically designed to deter and prevent unwanted behaviors, it won’t do that. Sure there is always some deterrence but a dedicated aggressor will not be detoured.  They will bring the tools they need.  Also, if there isn’t a dedicated response force, all you’ll be doing with your fancy system is taking pictures of what happened. LESSON LEARNED: SECURITY IS SUPPOSED TO BE ABOUT DETERRENCE/PREVENTION AND INSTEAD IT’S ABOUT CONVENIENCE.

Well, after my heart attack a couple years ago, my cardiologist said I’d probably live another 30 years.  I’ve used three so far, so who knows what I’ll learn in the next 27?

Sunday, April 21, 2019



Street Market, Outdoor Café, and Pedestrian Zone Security is Lacking

Street Markets

I’m probably stating the obvious here.  But most street markets are temporary in nature (farmer’s, or harvest markets) and only occur on a certain day or two of the week or for a short period (Christmas Markets).  Local police department’s put up metal stanchions and post a traffic cop more for crowd and traffic control, than anything else.  They are not a deterrent to a dedicated threat using a vehicle as a weapon or an errant driver.  Now before you go and tell the mayor or the police commissioner his cops are ineffective let me explain.

It’s a matter of physics and not “goodwill or attentiveness” on the part of the policeman.  A vehicle traveling at just 10 mph covers a distance of approximately 73 to 102 feet in the 5-7 seconds it takes a trained officer to view, identify and react to an errant vehicle – intentional or otherwise.   Unless the speed of the vehicle is severely reduced to below that speed the vehicle will travel significantly further before it is recognized as a potential threat.  Cops are doing a great job everyday but they can’t beat physics – no matter their super hero powers, unfortunately.

Shameless plug here:  My friends at Marshalls Landscaping Protection USA have developed a super-shallow mount bollard that can be easily installed/removed because of the depth of the footing (3.9 inches or about the width of two girl scout cookies laid end-to-end).

Outdoor Cafes

And then there are outdoor cafes.  By nature they are more permanent.  I have to admit, I enjoy sitting in the piazza sipping an espresso just like any other caffeine addicted tourist.  Whole sections of city centers have rows of restaurants and outdoor cafes where you can sit and “take in life” as it passes by.  In response to the current “ramming vehicle threat” some cities are now placing very ugly “jersey” barriers[1] made from reinforced concrete) around these areas. 

A solid planter filled with dirt weighs several thousands of pounds and is an effective barrier, especially if struck by a vehicle at a high rate of speed.  A large vehicle could nudge it out of the way if it is not somehow anchored, but hopefully someone would notice that and sound the alarm.  Fortunately there is “street furniture” in the form of benches, planters, way signs, lighted bollards that are shallow mounted. These devices are permanently affixed, so they can’t be nudged, and can absorb the kinetic energy of a moving vehicle threat as described above.

What about large pedestrian zones?

My concern comes from the idea that besides establishing a perimeter and depending on which city you are in will determine how porous that perimeter is, is there really a separation of the different types of traffic that frequent the space; i.e., delivery vehicles, bicycle, pedestrians.  Each category of traffic poses a threat to the others.  Of course, a vehicle crashing into someone is much more likely to cause injury to.

Many cities are creating large “pedestrians zones” in city centers that cover many city blocks.  This is great but traffic is still mixed within these spaces in some places.  Unless the entire zone is vehicle traffic free, a pedestrian or cyclist must cross the street at some point.  These crosswalks are particularly vulnerable and offer great target selection. 

We need to further separate the traffic within these zones, so that only the traffic we want within a particular zone is allowed[2]; vehicles with vehicle with vehicles, cyclist with cyclist and pedestrian within their assigned zone.  We can design the space so that only the type of travel that we want will be in its particular zone because the unwanted traffic types can’t enter.   To separate vehicles from the rest, we could easily designed higher-than-normal-curbs and reduce speeds by creating a serpentine effect.  We could use the same idea for cyclist either permanently designed as part of the bicycle path or by using planters with trees.  And for the pedestrian only zone, we can design the space so that bicycles and vehicles cannot enter while pedestrians are present.   Again, we can borrow our idea from the outdoor café and place street furniture throughout.  Thereby, allowing pedestrians to duck for cover if something goes wrong.



[1] Security Industry Association Technology Insight 2018 Spring edition, https://www.securityindustry.org/2018/04/05/the-puppy-movement/

Sunday, January 20, 2019


The Truth About Walls (Fencing)




A few years ago, I was asked by the editors of Security Middle East magazine[1] to write an article about perimeter security.  During the conversations with the editor that lead to the eventual article, she asked me to summarize what the article would be about.  I told her that in order to understand perimeter security you first needed to accept the fact that if you have a ten-foot fence the bad guy will bring an eleven-foot ladder. 



The idea that you can build a fence or wall and keep the bad guys out faded out sometime after the medieval ages when new technologies and new ways of conducting warfare came about.  Well, the same holds true today.



If you look up on Google the difference between a wall and a fence you’ll get the following explanation: “A fence is usually a wooden or metal structure that encloses a yard, pasture or other area…The difference between a fence and a wall is that you can almost always see through a fence, at least to some degree, while a wall is solid”.



If you look up fence purposes, you’ll get the following explanation; “A fence is a structure that encloses an area, typically outdoors, and is usually constructed from posts that are connected by boards, wire, rails or netting.  Alternatives to fencing include a ditch (sometimes filled with water, forming a moat)”.



Both definitions suggest that a boundary is formed between property that is not controlled and property that is controlled. 



Whether using a wall or fence, the purpose is to delineate a boundary; usually at a property boundary.  This is the true meaning of fencing or "walling", if you will.  To delineate property boundaries, in other words, you’re over there and I don’t care what you do but it you come over here you need to go down to the access point so I can check you out.  With that in mind, you could paint a line on the ground and put up a sign that says, “stay out or go over there for access”.  Both would achieve the same effect as a wall of fence.  So, why not just paint a line.  Because the value in constructing a fence or wall, is 1) to identify the boundaries of the controlled space, 2) to cause a delay in unauthorized access, and 3) to identify unwanted behavior.  An authorized person will not climb over a fence or wall, tunnel under it or cut through it.  An unauthorized person will, especially if they have nefarious intentions.  So, with that in mind, the fence serves an early warning system.  It tells us when someone breaches it that they have  “bad intentions”.  If they didn’t, they would not breach the fence/wall and would proceed to an access control point to display the proper credentials to gain entry.  Hopefully, the fence will be constructed in such a way as to delay their unauthorized access.  Sadly, even without tools a eight foot chain link fence with three strand barbed wire outrigger can be scaled or climbed over in about four seconds.  With tools, like a ladder or a truck to stand on it takes even less time.



Which brings us to the next truth, unless there is a guard or technology monitoring the fence-line in real time, we have no way of knowing if the boundary has been breached.  We must monitor for unauthorized access, respond to it, and engage the aggressor in real time.  The operative word here is “real time”.  If we don’t what’s the use?



Another thing to remember, no matter how solid, sturdy, high or how many bells and whistles are added, there will always be a way to circumvent whatever is put in place.  The key is, making sure there is enough time to delay the “bad guy or gal” so that his or her behavior can be identified and the “good guys/gals” have time to respond and engage.





[1] Security Middle East magazine article More Power to the Perimeter link https://issuu.com/securitymiddleeastmagazine/docs/sme_july-_aug_2015_web?e=0/14330179

Sunday, March 18, 2018


If Data is the New Currency of the Modern World Then Why
Is My Account Overdrawn?



According to a recent report in Security Megatrends: The 2018 Vision for the Security Industry published by the Security Industry Association 99.5 percent of all data collected via electronic devices goes unused.  Let that sink in for a second.  99.5% is wasted.  Less than .5 percent is accessed, analyzed and used in some type of constructive way.  I can’t imagine any other industry or area of life where less than one-half of one percent is good return on investment (ROI).



Here’s some data provided in the article "Accessing and Analyzing Smart and Big Data, Moving into Artificial Intelligence and Augmented Reality", using 60 seconds as the baseline, on just the social media platforms that I use:



·         Google – more than 3.8 million searches

·         Twitter – more than 350,000 tweets

·         Facebook – more than 243,000 photos uploaded and 70,000 hours of video content viewed

·         Linked-In – 120 new accounts created



So, why does this occur.  Well, it has to do with automation and the progressive nature of technology.  We’ve all heard the standard cliché that your phone has more data processing capability than the spaceships that went to the moon.  There have been surprising advancements in just about every sector of society.

I read an article some time back, that said your bank account could be hacked through your toaster.  At the time, I thought it a bit far-fetched,  But now the home improvement stores are selling refrigerators that can order food for you, if programed properly.  While, I think that was a little exaggerated but the point the author was making was, if your toaster has a microchip in it and that sensor report data somewhere, there is the potential that a person with malicious intent could through that sensor get to my bank account.



But is this a good thing?  For the most part yes.  I mean, think about it, only a few decades ago, if you were diagnosed with the big “C”, you started counting your days.  Now, more people survive and overcome the disease than don’t.  But on the other hand, let’s not get too carried away.  Technology is a tool and should be used as such; a tool that allows us to make better decisions about life choices.  Let’s remember that technology is not the solutions but it can be used to find the solution.



One of the areas where there is promise, within the security industry, is the area of “augmented reality” or AR.  We’ve all heard of “virtual reality” where the user is immersed in a fictional environment.  With AR the data augments the natural environment.  A simple example would be the ability to super-imposed a data screen on the visor of a motorcycle policeman that presents him or her with information about traffic up ahead, including accidents or breakdowns.  Or data information relayed to first responders during active shooter events.  This ability will undoubtedly save lives.



Estimates are that the Internet of Things (IoT) will mushroom in the coming years to between 34 Billion and 58 Billion devices connected to the data grid in some way by 2020.   Even if the world population doubles in the next two years (which is highly unlikely) that’s more than two devices per person.  


The hard part, in all of this is, will be figuring out what data to analyze, what to keep for the future and when to give it to someone to use now.    

Sunday, December 17, 2017

Question You Should Ask Before Getting a
Home Security System For Christmas


Is a home security system on your wish list from Santa?  If so, here are a couple of things you need to ask before Santa puts your system in his bag.
The first two questions to ask yourself are, “What am I going to protect by buying this type of system?" Then, "Will it do what I want it to do?”  These sound like no-brainers don’t they?  Most of us would say, “I want it to catch the bad guy”.  Well, not really, because it won’t catch a bad guy.  It will let you know when there is behavior inside of your house or when your perimeter is breached. But it won’t tell you if the behavior is good or bad.  YOU have to do that.  YOU have to assess the behavior and determine if it's good or bad.  So, you want to be able to analyze the behavior, like your kids coming home from school or the mailman delivering a package and determine if it is friend or foe.  Which brings us to the next question, which is, “Who will monitor what the system 'sees' and who will respond when there is unwanted behavior?”
If you are relying on your local 911 or a police department response, then you need to find out what the local policy is for home invasion.  Some departments don’t respond immediately for a variety of reasons; sometimes due to competing priorities and sometimes because they don’t want to get there when the bad guy is still on the premises which may cause a “stand-off”.  They don’t want that and neither do you.
If you are relying on a service provider for response, you need to ask, “What is the guaranteed respond time?”  If it’s less than seven minutes the good guys will catch the bad guys.  If it’s more than that, the bad guy will get away with your stuff.  Actually you don’t want the good guys to get there while the bad guy is still there, as it increases the likelihood that someone is going to get hurt.
The National Institute of Justice reported a couple years ago that perpetrators of housebreaking/ burglary usually stay on site less than seven minutes.   I doubt it’s changed much in the last couple of years.
DO-IT-YOURSELF (DIY) SYSTEMS
Many professional installers will swear up and down that home owners cannot do this alone.  But let’s face it.  Just about anybody can do just about anything, given the right tools and knowledge.  Most home kits include instructions, so they’re pretty simple.  Tab A goes into Slot B.  If you can put together IKEA furniture you certainly can install a couple of cameras and sensors around your house.  That’s the tools part.  Now for the knowledge part – where to put cameras and where to put sensors?  Think of your house as an onion.  Start on the outer skin (property line) and work your way in.  Use a combination of sensors and camera that overlap so that all areas are covered by at least two components of your system.  Say a sensor and camera, or two cameras.  By using a combination of different technologies and creating an overlapping system you will, in all likelihood, get notified that something’s going on.  The chances of both systems failing simultaneously is very low.  Make sure you get "real time" notification.  The ability to talk into the system and tell the perpetrator that you're watching him or her (sorry ladies) is a plus.  However, it also let's the bad guy or gal know you are not at home.  So make sure you system covers the perimeter and you can engage before they ever get to the house.
HOME DELIVERY SERVICES
When Amazon recently announced that they would place your parcels just inside your front door if you signed up for this service many security folks cried “foul”.  They cited this service as basically allowing an intruder to enter your house.   Well, not really.  Amazon vets their delivery folks/employees during the hiring process.  If Amazon trusts them then why shouldn’t you?  Sure, there are always a few bad apples, but I see the risk of the delivery person rummaging through your house as a very low possibility since they don’t know if you’re going to come home suddenly and find them in the bedroom.  That just doesn’t make sense.  There are really two factors that are in play here that make this a good idea.  First, Amazon vets their employees and secondly the door lock and code is specific to your home. Additionally, the kit comes with a closed circuit television camera that you can set up to see if the person does more than deliver the package(s).   Plus there’s an electronic record of when the lock opened and when it closed.  Anything more than a minute or two, the amount of time to place the packages inside, would be cause for alarm and indicate something out of the ordinary happened.
If I ordered stuff on line and wasn’t home all day I’d use this service.
NO SYSTEM IS FOOL PROOF
Just remember that no system no matter how sophisticated is fool proof or offers one hundred percent protection one hundred percent of the time.  There will always be some risks involved.  The goal is to reduce the risks as much as possible and accept some risk.   




Sunday, May 21, 2017

Case Study at European Simulation and Validation Center (ESVC)


Protecting Students and Staff from Active Shooters

A Case Study at the European Simulation and Validation Center (ESVC)



THE TASK AT HAND – PROTECTING STUDENTS AND STAFF

Protecting the students at the European Simulation and Validation Center (ESVC) was our objective and specifically, reducing the mass casualty count during active shooter scenarios.  With the increase in terrorist attack, it was only logistical that the Executive Director would seek out protection for her staff and cadre of instructors, but primarily, for the students attending simulation modeling at the ESVC.

“We pride ourselves in being a professional organization with extensive safety and security knowledge. Protection of our staff and students in any way is a main priority”, says, Karen Zwart, Executive Director from her offices in Ede, The Netherlands.  

Because CPK United BV is known for their expertise in training senior government leaders and industry executives, as well as, their key staff elements, especially in the transportation and aviation fields, the ESVC is the “go to” place when it comes to conducting serious gaming models for evaluating emergency plans and the actions required by them.  The ESVC provides a comfortable environment that is conducive to leadership training at the highest levels in lieu of costly field exercises.  The ESVC can create an organization specific built (physical) environment virtually; use existing company or agency plans, while allowing “players” to travel down a variety of decision paths in a virtual environment.  This allows them to test plans through their interaction, individually and collectively to evaluate efficiencies – without the additional expense of a full-scale exercise and without anyone getting hurt.   Using ESVC simulation allows plans and procedures to be tweaked before a real incident occurs and damage or injury occur.   

KNOWN COMPONENTS OF THE RISK FORMULA

All good risk formulas have some commonalities.  The formula usually goes something like this; C (asset criticality) X Threat (What can harm us) X Vulnerability (How susceptible we are to the harm) = Risk (How bad is it?).  In this particular instance, two of the essential elements in calculating risks were already known to the assessment team.  Those elements included the criticality of the asset, (high value targets/students).  To understand the criticality, imagine for a second, if a multi-national corporation’s entire senior leadership along with key staff were on-site being trained and ESVC were involved in a catastrophic incident.  It would not only mean damage and death but could also influence the future of the organization and could very well be the end of that company. 

And, the second known element – threat – was an active shooter scenario.

ASSESSING VULNERABILITIES – A SNAPSHOT IN TIME

The next element of the formula was to determine the vulnerabilities of the site as they related to the threat.  Haines Security Solutions was called in to do the assessment due to its extensive experience in conducting risk analysis and developing mitigation strategies as they relate to building design.  Experts in forced entry, building design, antiterrorism and structural engineering repaired to the site to conduct the evaluation.

It should be noted that during conversations with the staff it was noted there was a low-moderate probability of occurrence of this type of attack; however, due to the catastrophic impact on the corporate structure of an organization attending training if impacted (low/moderate risk – critically high impact), it was determined to be of extremely high importance to conduct a full range of assessments.

Each area of the facility (reception area, training facility, staff offices, storage areas, coffee/snack center, bathrooms and print shop) was examined from both the owner’s and the aggressor’s points of view.

USING THE ASSET BASED RISK ANALYSIS METHODLOGY

This dedicated team of subject matter experts collected physical security, as well as, operational data on-site in order to allow them to fill-in the vulnerability element and complete the risk formula

They then started collecting physical data from the curb inward.   Data was collect on three layers where vulnerabilities could occur; i.e., property perimeter, building façade and internally controlled spaces.  Data about the IT system or software used at the ESVC was not collected because the ABRA, in this case, did not call for the protection of data on the IT system.  Instead, it called for the protection of lives.

Once back at their offices, the Haines Security Solutions team members used an assessment methodology called Asset Based Risk Analysis[1] or ABRA to analyze the data and make effective recommendations. 



The primary purpose of ABRA is to quantitatively measure threats, assets, vulnerabilities, and risks associated with large and/or small government or private facilities.  It establishes a security baseline, explores upgrades, recalculates vulnerabilities and risks, and recommends optimized features or improvements for facilities.  In essence, ABRA identifies current levels of vulnerability and risk and then identifies improved levels with the implementation of specified countermeasures.  Basically, a snapshot of where the organization is today and where it could be after countermeasures are implemented.  In addition, ABRA identifies the associated cost and impact of the improvements.  ABRA includes the performance of six sub-analyses: threat, target, vulnerability, optimization, risk, and cost–benefit.

  

Threat Analysis



The treat analysis is based on information collected during the site visit.  The information produces a threat rating, which measures the threat likelihood (the probability an attack will occur), and an effectiveness rating (the probability that an attack will be successful).



ABRA takes into account the current local threat environment for five conditions; i.e., stand-off, explosive; covert, overt and chem/bio.  Although the project only called for the assessment of an active shooter threat, since we were already on site, it only made sense to conduct all five analyses.

The assessment team started the assessment asking a series of about 50 questions to the staff to further determine the asset’s criticality and threat environment.   Additional soft intelligence was collected via the internet and a clear threat picture emerged.

Target Analysis



The target analysis is designed to evaluate and measure the value of all targets to the user and to the aggressor.  Targets could include any type of asset or target including facilities, people, equipment, money, processes and systems.  The end result of the target analysis is a numeric rating based on the target value or criticality to the user and the target value or usefulness to the aggressor.



Vulnerability Analysis



Our vulnerability analysis is designed to quantitatively evaluate and measure how vulnerable a specific asset is to a specific threat. This phase of ABRA identifies the countermeasures currently in place for a specific target and is assigned a value based on their effectiveness in mitigating threats (Baseline Vulnerability Rating [BVR]).



Optimization Analysis



The optimization analysis is the reapplication of the vulnerability analysis after implementing hypothetical improvements resulting from countermeasures that could be used for a specific asset.  Hypothetical countermeasures could include programmatic or procedural options.  The end result is an optimized vulnerability rating (OVR) associated with the specific target being analyzed, in this case, a training facility.  Based on the optimization analysis, the average vulnerability and risk rating can be identified and stated as a percentage.



Risk Analysis



The risk analysis is the aggregation of the threat, target, vulnerability, and optimization analyses to determine the calculated value of risk associated with a specific asset that is being targeted by a specific threat.



Cost–Benefit Analysis



The cost–benefit analysis compares the potential results of specific countermeasures for reducing or mitigating threats against specific assets.  The cost–benefit analysis is based on cost versus reduction in vulnerability and risk.



MAKING RECOMMENDATIONS THAT WORK

Most risk analyst make recommendations that bring the facility up to code compliance or base solutions on costs.  The recommendations made during this assessment were made based on risk reduction and not costs.   Our analysis showed that all recommendations were either extremely or highly cost effective.  Those recommendations included four main or specific areas.

Inhabited Space Hardening

Windows – Replacing the existing exterior windows with 6 mm laminated or poly-bicarbonate glazing.

Walls – Retrofitting the walls with a ballistic resistant material and continuing that concept to other features.

Furniture – Retrofit any interior elements, such as, reception desk, student chairs, tables, white-board (basically, anything or anywhere a student could hide behind if they were unable to exercise their first option of running away).

Electronic Security Systems

Electronic Security Systems – Install integrated access control and surveillance (CCTV) systems.

Mass notification system – Install internal and external speakers, alarm signals and visual message boards.

Crime Prevention through Environmental Design (CPTED)

Natural Surveillance/Natural Access Control – Use landscaping to reroute pedestrian traffic entering the building, so that as people approach they are observed from within the building.

Plans, Policies and Procedures

Use internal resources/corporate expertise to update plans, policies and procedures

IN SUMMARY

The recommendations would be implemented in all areas of high occupancy or critical areas (inhabited spaces); i.e., training facility, staff offices, coffee/snack center and stairway.  It should be pointed out that normally stairways or other transit type spaces would not receive the same level of protection because they are usually considered to have low occupancy, but input from the ESVC indicated it to be mission critical and a single-point-failure location for their operations.

Bathrooms, storage rooms, print shop and garage were not recommended to be retrofitted with ballistic protection because of their low occupancy density (uninhabited spaces).

Overall the risk reduction to the active shooter threat was calculated at 84 percent.  In other words, the Delta if you will, from where the risk is today to where it will be when all of the recommendations are implemented.   If implementation of all of the recommendation in the report were accomplished the risk reduction of the other threat scenarios would be between 74 and 98 percent.  The total project costs, including the data collection, evaluation and analysis and implementation of all of the recommendations was Euro72,130 ($76,200).  If only the recommendations pertaining to ballistic protection from the shooting threat were adopted the costs would be Euro53,560 ($56,700).  Recommendations were also prioritized to be implemented based on risk reduction and protection to the largest number of people first, and to allow their implementation as funding becomes available.

In summary, that’s a very small amount to pay to protect the lives of students and staff.  The added protections afforded by the recommendations help reduce risk and provide safety from a host of criminal and terrorist activities.  

Zwart added, “The conclusions made were rock solid and provided clear vision of the budget choices we need to make in the years to come.  By using their proprietary formula, Haines Security Solutions was able to demonstrate the tangible risk reduction of their recommendations.  Something we’ve not seen in other assessment methodologies”. 
Making it a safe and secure environment for those attending training – after all isn’t that what it’s all about?


[1] Haines Security Solutions was awarded a 2017 Platinum level Government Security award in the Risk Analysis category for its Asset Based Risk Analysis (ABRA) methodology.  The GOVIE awards are presented by Security Today magazine to outstanding products that address security challenges within the municipal, government, Safe Cities and law enforcement markets.

Sunday, April 16, 2017


Electronic Technologies vs Non-electronic Technologies


Many folks think this is the question to ask themselves, “Since there is so much electronic technology out there that can replace the human being, then that must be enough”.  Actually it’s more of a way of thinking than it is a question.

Security companies have been especially good over the last few years in getting people to believe that their “new widget” is the end-all solution to the security dilemma.  The reality is electronic technology is a tool to be used by a person for assessment and analysis.  Ultimately, a human must decide what action to take. 

Having returned this week from the largest U.S. security industry tradeshow, ISC-West 2017, in Vegas I can tell you there were tens of thousands of people looking for the latest “widget”.  Hundreds of companies were professing to have “THE solution”.  Granted a lot of progress has been made in the past few years in regards to taking away some of the pitfalls in the security industry.  Number one among them is the issue of complacency that comes with standing or sitting monotonous hours of guard duty.  Through intelligent analytics and predictive analysis software programs can assist with the assessment.  While helpful, in the end a human must decide how to respond.

Which brings us to the use of non-electronic technologies.  Security is an everybody business.  It cannot be left up to guard personnel or the police.  It takes everyone’s “eyes and ears”.  Smart companies provide security awareness training to their staff on a regular basis.  The training must include how to recognize “wanted and unwanted” behavior, when and how to report it and to whom.  Training should also include when to intervene without jeopardizing their own safety or those around them and when reporting unwanted behavior is the first and only course of action.  While routine, it cannot be done every Friday afternoon nor can it be the same scenario week after week.  The Post Katrina Emergency Management Reform Act, Public Law 109-29, recognizes that training and drills must be a mix of “live, virtual and constructive” scenarios.  While this legislation applies to exercise planning for government agencies the same holds true for non-disaster type training in the private sector.  Interactive scenarios that challenge staff to think, sometimes outside of the box, will go a long way in making them ready for whatever comes their way.

Relying solely on electronic technologies is not the answer.  Nor is it a good idea to exclude these technologies in today’s world.  Electronics provide assistance.  They should be treated that way – as a tool that helps us do our jobs.  Likewise, procedures and policies, including awareness and training, are not definitive solutions either. A good security program will have a combination of electronic technologies intertwined with non-electronic technologies for the protection of all.

Sunday, March 19, 2017


Do-It-Yourself (DIY) or Credentialed Security Consultant, That Is the Question






My brother built his house.  He borrowed a back-hoe and dug the hole.  He set the foundation and built his house from the ground up.  I look at him and say, “why can’t I even drive a nail straight?”  Well, there are two reason, first he has the knowledge and secondly, he had the right tools.  I, on the other hand, don’t have the knowledge nor have I ever purchased any tools.  Oh sure, I can unplug the toilet or figure out that a fuse is blown but much more than that, I’m in the dark.  The pun was not intentional, I swear. 



This got me to thinking.  Whenever I have something around the house that needs more than my minimum skills I have to call someone.  They usually arrive and the first thing they ask is, “Who did this?” as they look at the thousand mile-an-hour tape or screwdriver wedged against the window or the string hanging from where the handle should be on the screen door.  Then they go about fixing it and charging me the equivalent of a mortgage payment.  They leave with a smile on their face and say, “Call us before you try to FIX IT again.  You’ll save money in the long run”. 



I asked my brother, where he got his knowledge and he told me that he asked lots of questions to people in the know and when he needed to, he bought or rented the tools.  If they had the skill set for roofing he asked roofing questions, same for plumbing and so on.  I was glad when he told me this because up to this point, I thought my Dad shared house building skills with him but not with me.  I was made at my Dad.  Forgive me Dad.



Well, the same holds true in security.  There are projects you can do on your own and there are things you really should get an expert to handle.  With the advancement in technologies in recent months you can basically, “plug and play” all types of electronic security systems.  This is a good thing.  I remember a day when programming the VCR was a disaster.  Even though my English is pretty good, I could never understand the instructions.  I had to get a friend to do it for me.  But back to security.  Electronic security systems have become sophisticated but you don’t have to be an “IT geek” to use them.  Most can be monitored on your phone with an App download.



But, if you’re going to assess your property and take a holistic approach you probably want someone with knowledge in vulnerability assessment/risk analysis or in developing mitigation strategies or someone with a Physical Security Engineering (PSE, SPSE or MPSE) designation.  If you have a very large project or are worried about cost overruns, you could also get someone with credentials from the Security Industry Association (SIA) in project management or a Certified Security Project Manager (CSPM®).  Another reputable organization is the American Society of Industrial Security (ASIS), which provides a variety of designations.   The security consultant having one of these credentials or designation is your guarantee that the person doing the job has the right tools sets and the knowledge to use them.



DIY is okay but remember one thing; good advice has a cost but free advice may cost you more.

Sunday, January 22, 2017


Acknowledging Your Own Behavior in

Becoming a Stronger Leader





We all know the stories of how life used to be when we were younger. Even better remember the tales your parents, grandparents told you over and over about how life used to be easier, safer back in the good old days? You could leave the door open and nobody would take anything from your house? It is safe to say the world has changed so much. That sense of security found in the community and groups our grandparents talk about has been overshadowed by the focus on individual achievement. It seems we experience more pressure, more speed, and more complexity and consequently more fear.  Fear of the unknown.  Fear of things we can control and extreme fear from those we can’t.  “Not being good enough”, or not fitting into our collective peer groups, or being able to compete on all levels in today’s very competitive and complex societies all fuel this anxiety.  Our personal behavioral issues are not the only thing we have to worry about.  We also have to react to events that we can’t control yet affect us somehow none the less.  Dealing with terrorist or other types of criminal behaviors or even our psychotic neighbors adds to that angst. The reasons behind these fears are an interesting point of research.  To me, what is even more interesting is the idea that we can overcome this fear by controlling it.  While we can’t control every situation, many of which are outside our realm of personal influence, we can control how we react to each situation, whether from an innate moral perspective or a learned one.

People have a profound need to feel safe.  It’s a basic human instinct.  In order to do that, people need to be able to protect themselves and their loved ones by any means possible. Unfortunately, due to the increased focus on individual talents and lack of group cohesiveness an individual must most often “fend for themselves”.  This means an individual must deploy mental and physical strategies.  Since most of us aren’t big enough to just “pound some sense into” the other guy, we must rely on our mental abilities to defuse or de-escalate the situation before it becomes physical. 

What if the alienation of society and the “stand alone” approach is exactly why we got here in the first place?  Remember the stories about the good old days?

We at BLACK believe that the key lies in returning the stability of the community through individual effort.  By bringing this aggravated anxiety level to a more acceptable one within the individual, society can function as it should.  At BLACK we not only look at the community in general, but also within a company or a team of people.  Our way of working focuses on the individual’s improvement. Being aware of your own strengths and having confidence in using them in your own environment benefits the society as a whole.

Companies, groups and teams of people manifest the same characteristics as individuals and therefore, experience the exact same problems, albeit on a different scale. Results driven, “the bottom line” and ICT are the key words within which any (major) organization operates these days.  Even though people are considered the most important asset, in general, we seem to misplace the personal touch due to the pressures of results minded actions.  We get so lost in the management process that we lose sight of the individual’s contribution toward the whole.  This process of managing people as just another asset in the company inventory doesn’t allow for the organization to achieve its true potential.  The days of sound management are over, and the move from efficiency to productivity is starting. To achieve productivity, organizations must have effective leaders.  Leaders can only guide an organization to achieve greatness, if they recognize and acknowledge their own weaknesses and strengths.  A long-term self-actualization process is needed.  With the world’s increasing population and the burden of more complex societies the need for leadership will become paramount.  While the focus will be on efficient and effective system management, it will only be achieve through the transformation from sound management to truly effective and inclusive leadership.  In the future, leaders will play a greater part in every organization and will be essential to all organizational structures – both, private and public, large and small. 

Through our B.L.A.C.K. methodology we provide leaders the skills they need for organizational success by inspiring them to acknowledge their own personal behavior traits.  By doing so, they gain confidence in their abilities to motivate team members “toward greater things”.                                        

Within our vision of training, we firmly believe that we can achieve these goals by changing the way individuals and groups reacted to situations.  We have no illusion in thinking we can  banish criminality, threats or unwanted behavior as a whole, but we believe we can be a factor in creating more self-awareness by acknowledging how we all contribute to the feeling of fear, environmental pressure and loss of control.  All authority figures will play a huge part in this vision. After all he or she must lead by example and create a feeling of a calm and safe environment. Community members, whether within an organization or a neighborhood, must have a sense of confidence in their leaders because of their ability to create “safe environments”.  Only then can we degrade fear and go from “standing-alone” to “standing together”.  In the last year we have seen an escalation in the appalling interaction between private and public authorities and the societies they govern. There is no need to point fingers as to who is to blame, but perhaps we can all take a good look at ourselves and make the decision to do better by being better.

To quote a great leader, President Thomas Jefferson:

“ Laws made by common consent must not be trampled on by Individuals. It is very much the Interest of the good to force the unworthy into their due Share of Contributions to the Public Support, otherwise the burthen on them will become oppressive indeed.”

BLACK

BLACK is a Dutch company specialized in leadership training.  It is run by (former) armed forces with a high success rate. For further information we kindly refer to our website http://www.cpk-black.com