Sunday, June 18, 2017


Threats, Designs and Delphic predictions: Designing-in Security for Major Sporting Infrastructure and Other High-Occupancy Spaces (Part 1)


Looking into the future

In the summer of 480 BC, the Athenian celebration of their Olympic games was disrupted by fears of a second invasion by the Persians, the first having been defeated at the Battle of Marathon, ten years earlier.  The Athenians consulted the Oracle of Delphi for guidance about how to defend themselves and were advised to place their trust in a “wall of wood”.  Taking this to be a reference to ships, the Athenians prepared their fleet and subsequently used it to evacuate Athens and later defeat the Persians at sea.
The organisers of today’s major international sporting events do not need to rely on Delphic predictions for security advice; there are highly sophisticated systems available to assess and respond to immediate threats and great levels of information sharing and international cooperation to support the host country.  However, the infrastructure for the sporting event may have been designed many years earlier when it would have been impossible to know with accuracy what kind of threats it would need to withstand.  This article looks at some of the challenges facing architects, designers and engineers to ensure that sporting events can take place safely and securely in a variety of threat environments.

Strategic approach

Infrastructure of any type, sporting or other, takes a long time to plan and build and will last even longer.  A recent Experts’ Summit organised by the International Centre for Sport Security (ICSS) concluded that it took an average of eight years from a decision to build a new piece of sporting infrastructure before it was in operation[1].  The prevailing threat that might bear upon that infrastructure when it is used will be impossible to predict accurately that far in the future.  Furthermore, the threat can change much more quickly than any defensive posture arranged to protect it.  An unexpected terrorist attack, for example, is likely to cause an abrupt re-assessment of the threat.  New cyber threats and avenues of attack can appear very rapidly, a situation that is unlikely to diminish in the short term and may get significantly worse.  Where protective measures need to be added retrospectively, it is invariably at great expense in terms of time, money and disruption.
How do those designing infrastructure and sports venues build-in protection against threats that they cannot accurately predict?  The answer is that by following a few strategic guidelines, it is straightforward to produce designs that not only satisfy the sporting requirements, but do so in a safe and secure manner, are aesthetically pleasing and are capable of withstanding changes to the risk environment in a flexible and cost effective way throughout any legacy use.
Wider context
The first guideline is that the design needs to take place against a wider context, for example a national security strategy or plan that is set by a higher authority (normally the national government).  The security planning for most international sporting events will take place within the context of the host country’s strategic planning framework.  This is likely to consider a range of risks to people, events, and physical and logical infrastructure.  Underpinning this should be a comprehensive set of relationships between the event organisers and the relevant Law Enforcement and other government agencies that are responsible for assessing security threats and disseminating advice about how to mitigate them.  The organisers of a major sporting event must work with these agencies to address any issues relating to threats that might bear upon the event; they cannot reduce the threat by themselves.  It is therefore important for them to understand the broader risk environment and how the national (and local) response machinery is organised.  The way to achieve this is to establish long term working relationships with the relevant organisations, which then can be utilised to respond to a particular event, from a one-off match to a sporting fiesta like the Football World Cup or Olympics.
Impact driven
The second guideline is that the focus of the design should be on minimising the impact of a hostile event (e.g. terrorist bomb, cyber attack).  Designers and architects are very familiar with the need to ensure that sports stadia and other infrastructures are built to ensure the highest levels of safety at times of an emergency such as a fire.  There is no reason why security should not figure as prominently in their considerations.  There is a considerable body of knowledge about how to protect against the effects of blast from a terrorist bomb (whether vehicle or person borne) or against shots from a weapon.  There is a similar wealth of knowledge about how to defend against cyber attacks.  It is essential, therefore, that designers and architects engage early with security practitioners to understand the impact that a catastrophic event might have on the sporting venue and its occupants.  However, all too often designers focus on the likelihood of an attack, rather than on what impact it would have.  A mindset that considered impact ahead of likelihood is much more likely to produce a design that is capable of withstanding a variety of threat scenarios including new ones and those that may change in nature over the lifetime of the infrastructure.
To achieve this, the designer should have a clear understanding of what is critical to the functioning of the infrastructure, venue, etc.  Some of this may emerge naturally from consideration of the safety aspects (e.g. having multiple entrances and exits that can be used in the case of a fire), but others may not be so evident.  Sometimes, good design and good security design may not be the same thing.  For example, placing the back-up to a critical system alongside its master may be elegant in design terms and cheap to implement, but a bomb designed to damage one may take out the back-up as well.  The designer needs also to place critical systems as far away as possible from the public domain to minimise the chances that intruders can quickly penetrate a protective perimeter and cause damage.
Good physical security need not detract from the aesthetic impact of the venue.  Planned in advance, it can be built into the fabric of the venue and its surroundings in such a way as to be pleasing on the eye, discreet and highly effective.  The challenge for the designer is to use the natural lie of the land, and existing geographical features to avoid the need to construct defences that might present a more stark appearance.  A stream or ditch might easily be adapted to control the flow of vehicles or block potentially hostile ones.  Earth banks planted with attractive foliage can protect buildings from the effects of blast.  Where defensive structures need to be built, they should be merged into the surrounding ‘streetscape’ as much as possible.  Raised flower planters, bicycle racks and street lighting fixtures might all be adapted to act as hostile vehicle mitigation of some form.  A major north London football club has some of its hostile vehicle mitigation measures constructed in the form of giant letters of the club’s name.  Other barriers might be hidden behind stone balustrades or constructed from materials that blend in with the surrounding architecture and heritage of the site.  All that is required is for the designer to have early engagement with the security professionals so that the artistry of the former might blend with the requirements of the latter in as attractive a way as possible.

Holistic approach

Acquiring a comprehensive understanding of what is critical to the functioning of a venue leads to the third of the strategic guidelines – taking an holistic approach.  The complex nature of modern communications and control systems throws up highly complex interdependencies between the physical and logical elements in a modern stadium.  Entry gates, CCTV monitors, Public Address, display screens, etc., will all be controlled across communications networks which themselves are based on Internet Protocols (IP).  Such networks will be flexible and able to adapt to changing requirements, but unless they are properly protected, they will be vulnerable to a cyber attack.  This could result in sound physical protection measures being compromised in some way.  Any holistic approach must also include the people who operate the physical and cyber measures at a venue.
However, an holistic approach means much more than just considering physical, cyber and personnel risks together in some way.  Security functions that are organised in silos are inefficient and obstruct the identification and mitigation of risk.  It is important that the governance of the various security functions is structured in such a way as to support an holistic approach.  Having different reporting or line management chains for these functions will stretch channels of communication and introduce potential gaps from which greater risk is likely to emerge.  In our follow-up article in the next edition of this journal, it will also become clear as to why it is important to embed this holistic approach throughout the supply chain for both the build and operation of an event.
Effective security starts at the top of the organisation and should be embedded throughout it by a culture in which the everyday attitudes of staff contribute effortlessly towards an organisation’s protective security regime.   It is vital that event organisers work to achieve such a positive culture and one that takes an holistic, not silo-ed, approach to security – designed to minimise physical, information and personnel risks and protect spectators and staff.
The cyber threat to a venue will manifest itself in many ways, not just those relating to the operation of physical elements.  Information in many forms will be vital to the successful design, construction and operation of any sporting venue, not only for its immediate use, but possibly for many years of legacy beyond that.  The protection of information needs to be considered in a number of circumstances such as:
·         The documents relating to the design and construction of the venues.  Inappropriate disclosure of these could allow the identification of weak points or vulnerabilities in the construction that could be exploited.
·         The operation of the venues, especially during sporting events when the risks are greatest.  Again, inappropriate disclosure of this could allow security regimes to be subverted or compromised.
·         In either electronic or paper form.  Whilst the majority of information will be carried via electronic systems and networks, the use of paper will still be necessary in certain cases.  It is important that the information protection plan encompasses both mediums and enables venues to be confident that hard copy (paper, electronic media, CDs, etc.) is protected as effectively as that carried on the numerous (cyber) networks that will be necessary to support events.
·         The identification of new threats as they emerge.  The rapid development of cyber threats is unlikely to diminish in the short term and may get significantly worse.  It will be particularly important for sporting venues to have confidence that appropriate protection is in place to counter the most sophisticated of these.
The last point, underlines why it is so important to adopt an impact driven approach to the security of cyber infrastructures.  Focusing on a threat that can change so rapidly and far more quickly than defences can be reconfigured will not lead to a secure cyber infrastructure that will remain resilient in the face of uncertainty.  However, by understanding what is critical to its operations, a venue can start to build a cyber system that can deter, detect and defend against the inevitable attempts to compromise its operations.
An effective and holistic security risk management regime will therefore have a number of components including: senior management support; capable people; efficient processes; and the selection of appropriate physical and technical controls.  Each component should interact with and support others in an holistic manner.  It is important to seek a balance between these components as the model is compromised if any one component is deficient or fails.  Organisers should understand that technology is just one piece of a complex jigsaw that will eventually deliver a safe and secure celebration of sport.  A multidisciplinary team is needed to ensure that physical assets and information are safeguarded appropriately and a positive security culture is fostered amongst staff.
At this stage it will also be necessary to consider any legal and compliance issues set by a higher authority (e.g., regional or national government).  There are numerous relevant national and international industry standards that might be adopted.  However, it will be important for the leadership of the venue to ensure that the focus remains on effective and proportionate risk management and not just the slavish obedience of a particular standard.  The danger of adopting standards is that the focus of management effort switches to achieving compliance with the standard rather than holistic management of the risk.

Getting there

The three guiding principles of considering a wider context; being impact driven; and taking an holistic approach may be easy to say yet much more difficult to achieve.   It is vital to get things right from the start and have security considered at the beginning of the design stage, not as a post-build ‘add-on’.  As we have already seen, early engagement between security professionals, designers and architects is essential.  This can save money in the long term and produce a design that enhances the spectator experience by inducing a greater feeling of safety and security.
Achieving this requires nothing more than good communication skills and the ability to keep that going throughout the design and build of a project and its subsequent operation.  But that is easier to say than do as personal relationships, group dynamics and overarching governance structures can all interfere in the process and allow differing elements to drift off in their own directions.  So often, security is considered well after the start of the design process when changing plans becomes expensive and time consuming.  Whilst getting it right at the start is vital, so is the ability to keep that level of engagement going.  This requires continuing commitment and leadership from the management and an engaged and supportive workforce that understand their roles and work seamlessly to embed the security objectives into their everyday actions.  As we will consider in part two of this article, it becomes even more important to achieve this once the design phase is over and construction begins.  During this phase, as the real venues start to emerge and the number of people involved in the project rises, a different set of challenges emerge.  However, by following a simple set of guidelines it is possible to achieve a safe, secure and highly enjoyable celebration of sport that can provide a lasting legacy for generations to come, whatever the prevailing threats of the time and despite our continuing inability to see into the future.
The author (Roger Cumming) is the Technical Director of Atkins’ security business. Atkins, an international design, engineering and project management consultancy, was heavily involved in the design of the infrastructure for the Olympic Park and temporary venues for London 2012.

Part 2 coming 16 July at 4pm (PST).





[1] Insert reference to the Experts’ Summit in Vienna in May 2013.

Sunday, May 21, 2017

Case Study at European Simulation and Validation Center (ESVC)


Protecting Students and Staff from Active Shooters

A Case Study at the European Simulation and Validation Center (ESVC)



THE TASK AT HAND – PROTECTING STUDENTS AND STAFF

Protecting the students at the European Simulation and Validation Center (ESVC) was our objective and specifically, reducing the mass casualty count during active shooter scenarios.  With the increase in terrorist attack, it was only logistical that the Executive Director would seek out protection for her staff and cadre of instructors, but primarily, for the students attending simulation modeling at the ESVC.

“We pride ourselves in being a professional organization with extensive safety and security knowledge. Protection of our staff and students in any way is a main priority”, says, Karen Zwart, Executive Director from her offices in Ede, The Netherlands.  

Because CPK United BV is known for their expertise in training senior government leaders and industry executives, as well as, their key staff elements, especially in the transportation and aviation fields, the ESVC is the “go to” place when it comes to conducting serious gaming models for evaluating emergency plans and the actions required by them.  The ESVC provides a comfortable environment that is conducive to leadership training at the highest levels in lieu of costly field exercises.  The ESVC can create an organization specific built (physical) environment virtually; use existing company or agency plans, while allowing “players” to travel down a variety of decision paths in a virtual environment.  This allows them to test plans through their interaction, individually and collectively to evaluate efficiencies – without the additional expense of a full-scale exercise and without anyone getting hurt.   Using ESVC simulation allows plans and procedures to be tweaked before a real incident occurs and damage or injury occur.   

KNOWN COMPONENTS OF THE RISK FORMULA

All good risk formulas have some commonalities.  The formula usually goes something like this; C (asset criticality) X Threat (What can harm us) X Vulnerability (How susceptible we are to the harm) = Risk (How bad is it?).  In this particular instance, two of the essential elements in calculating risks were already known to the assessment team.  Those elements included the criticality of the asset, (high value targets/students).  To understand the criticality, imagine for a second, if a multi-national corporation’s entire senior leadership along with key staff were on-site being trained and ESVC were involved in a catastrophic incident.  It would not only mean damage and death but could also influence the future of the organization and could very well be the end of that company. 

And, the second known element – threat – was an active shooter scenario.

ASSESSING VULNERABILITIES – A SNAPSHOT IN TIME

The next element of the formula was to determine the vulnerabilities of the site as they related to the threat.  Haines Security Solutions was called in to do the assessment due to its extensive experience in conducting risk analysis and developing mitigation strategies as they relate to building design.  Experts in forced entry, building design, antiterrorism and structural engineering repaired to the site to conduct the evaluation.

It should be noted that during conversations with the staff it was noted there was a low-moderate probability of occurrence of this type of attack; however, due to the catastrophic impact on the corporate structure of an organization attending training if impacted (low/moderate risk – critically high impact), it was determined to be of extremely high importance to conduct a full range of assessments.

Each area of the facility (reception area, training facility, staff offices, storage areas, coffee/snack center, bathrooms and print shop) was examined from both the owner’s and the aggressor’s points of view.

USING THE ASSET BASED RISK ANALYSIS METHODLOGY

This dedicated team of subject matter experts collected physical security, as well as, operational data on-site in order to allow them to fill-in the vulnerability element and complete the risk formula

They then started collecting physical data from the curb inward.   Data was collect on three layers where vulnerabilities could occur; i.e., property perimeter, building façade and internally controlled spaces.  Data about the IT system or software used at the ESVC was not collected because the ABRA, in this case, did not call for the protection of data on the IT system.  Instead, it called for the protection of lives.

Once back at their offices, the Haines Security Solutions team members used an assessment methodology called Asset Based Risk Analysis[1] or ABRA to analyze the data and make effective recommendations. 



The primary purpose of ABRA is to quantitatively measure threats, assets, vulnerabilities, and risks associated with large and/or small government or private facilities.  It establishes a security baseline, explores upgrades, recalculates vulnerabilities and risks, and recommends optimized features or improvements for facilities.  In essence, ABRA identifies current levels of vulnerability and risk and then identifies improved levels with the implementation of specified countermeasures.  Basically, a snapshot of where the organization is today and where it could be after countermeasures are implemented.  In addition, ABRA identifies the associated cost and impact of the improvements.  ABRA includes the performance of six sub-analyses: threat, target, vulnerability, optimization, risk, and cost–benefit.

  

Threat Analysis



The treat analysis is based on information collected during the site visit.  The information produces a threat rating, which measures the threat likelihood (the probability an attack will occur), and an effectiveness rating (the probability that an attack will be successful).



ABRA takes into account the current local threat environment for five conditions; i.e., stand-off, explosive; covert, overt and chem/bio.  Although the project only called for the assessment of an active shooter threat, since we were already on site, it only made sense to conduct all five analyses.

The assessment team started the assessment asking a series of about 50 questions to the staff to further determine the asset’s criticality and threat environment.   Additional soft intelligence was collected via the internet and a clear threat picture emerged.

Target Analysis



The target analysis is designed to evaluate and measure the value of all targets to the user and to the aggressor.  Targets could include any type of asset or target including facilities, people, equipment, money, processes and systems.  The end result of the target analysis is a numeric rating based on the target value or criticality to the user and the target value or usefulness to the aggressor.



Vulnerability Analysis



Our vulnerability analysis is designed to quantitatively evaluate and measure how vulnerable a specific asset is to a specific threat. This phase of ABRA identifies the countermeasures currently in place for a specific target and is assigned a value based on their effectiveness in mitigating threats (Baseline Vulnerability Rating [BVR]).



Optimization Analysis



The optimization analysis is the reapplication of the vulnerability analysis after implementing hypothetical improvements resulting from countermeasures that could be used for a specific asset.  Hypothetical countermeasures could include programmatic or procedural options.  The end result is an optimized vulnerability rating (OVR) associated with the specific target being analyzed, in this case, a training facility.  Based on the optimization analysis, the average vulnerability and risk rating can be identified and stated as a percentage.



Risk Analysis



The risk analysis is the aggregation of the threat, target, vulnerability, and optimization analyses to determine the calculated value of risk associated with a specific asset that is being targeted by a specific threat.



Cost–Benefit Analysis



The cost–benefit analysis compares the potential results of specific countermeasures for reducing or mitigating threats against specific assets.  The cost–benefit analysis is based on cost versus reduction in vulnerability and risk.



MAKING RECOMMENDATIONS THAT WORK

Most risk analyst make recommendations that bring the facility up to code compliance or base solutions on costs.  The recommendations made during this assessment were made based on risk reduction and not costs.   Our analysis showed that all recommendations were either extremely or highly cost effective.  Those recommendations included four main or specific areas.

Inhabited Space Hardening

Windows – Replacing the existing exterior windows with 6 mm laminated or poly-bicarbonate glazing.

Walls – Retrofitting the walls with a ballistic resistant material and continuing that concept to other features.

Furniture – Retrofit any interior elements, such as, reception desk, student chairs, tables, white-board (basically, anything or anywhere a student could hide behind if they were unable to exercise their first option of running away).

Electronic Security Systems

Electronic Security Systems – Install integrated access control and surveillance (CCTV) systems.

Mass notification system – Install internal and external speakers, alarm signals and visual message boards.

Crime Prevention through Environmental Design (CPTED)

Natural Surveillance/Natural Access Control – Use landscaping to reroute pedestrian traffic entering the building, so that as people approach they are observed from within the building.

Plans, Policies and Procedures

Use internal resources/corporate expertise to update plans, policies and procedures

IN SUMMARY

The recommendations would be implemented in all areas of high occupancy or critical areas (inhabited spaces); i.e., training facility, staff offices, coffee/snack center and stairway.  It should be pointed out that normally stairways or other transit type spaces would not receive the same level of protection because they are usually considered to have low occupancy, but input from the ESVC indicated it to be mission critical and a single-point-failure location for their operations.

Bathrooms, storage rooms, print shop and garage were not recommended to be retrofitted with ballistic protection because of their low occupancy density (uninhabited spaces).

Overall the risk reduction to the active shooter threat was calculated at 84 percent.  In other words, the Delta if you will, from where the risk is today to where it will be when all of the recommendations are implemented.   If implementation of all of the recommendation in the report were accomplished the risk reduction of the other threat scenarios would be between 74 and 98 percent.  The total project costs, including the data collection, evaluation and analysis and implementation of all of the recommendations was Euro72,130 ($76,200).  If only the recommendations pertaining to ballistic protection from the shooting threat were adopted the costs would be Euro53,560 ($56,700).  Recommendations were also prioritized to be implemented based on risk reduction and protection to the largest number of people first, and to allow their implementation as funding becomes available.

In summary, that’s a very small amount to pay to protect the lives of students and staff.  The added protections afforded by the recommendations help reduce risk and provide safety from a host of criminal and terrorist activities.  

Zwart added, “The conclusions made were rock solid and provided clear vision of the budget choices we need to make in the years to come.  By using their proprietary formula, Haines Security Solutions was able to demonstrate the tangible risk reduction of their recommendations.  Something we’ve not seen in other assessment methodologies”. 
Making it a safe and secure environment for those attending training – after all isn’t that what it’s all about?


[1] Haines Security Solutions was awarded a 2017 Platinum level Government Security award in the Risk Analysis category for its Asset Based Risk Analysis (ABRA) methodology.  The GOVIE awards are presented by Security Today magazine to outstanding products that address security challenges within the municipal, government, Safe Cities and law enforcement markets.

Sunday, April 16, 2017


Electronic Technologies vs Non-electronic Technologies


Many folks think this is the question to ask themselves, “Since there is so much electronic technology out there that can replace the human being, then that must be enough”.  Actually it’s more of a way of thinking than it is a question.

Security companies have been especially good over the last few years in getting people to believe that their “new widget” is the end-all solution to the security dilemma.  The reality is electronic technology is a tool to be used by a person for assessment and analysis.  Ultimately, a human must decide what action to take. 

Having returned this week from the largest U.S. security industry tradeshow, ISC-West 2017, in Vegas I can tell you there were tens of thousands of people looking for the latest “widget”.  Hundreds of companies were professing to have “THE solution”.  Granted a lot of progress has been made in the past few years in regards to taking away some of the pitfalls in the security industry.  Number one among them is the issue of complacency that comes with standing or sitting monotonous hours of guard duty.  Through intelligent analytics and predictive analysis software programs can assist with the assessment.  While helpful, in the end a human must decide how to respond.

Which brings us to the use of non-electronic technologies.  Security is an everybody business.  It cannot be left up to guard personnel or the police.  It takes everyone’s “eyes and ears”.  Smart companies provide security awareness training to their staff on a regular basis.  The training must include how to recognize “wanted and unwanted” behavior, when and how to report it and to whom.  Training should also include when to intervene without jeopardizing their own safety or those around them and when reporting unwanted behavior is the first and only course of action.  While routine, it cannot be done every Friday afternoon nor can it be the same scenario week after week.  The Post Katrina Emergency Management Reform Act, Public Law 109-29, recognizes that training and drills must be a mix of “live, virtual and constructive” scenarios.  While this legislation applies to exercise planning for government agencies the same holds true for non-disaster type training in the private sector.  Interactive scenarios that challenge staff to think, sometimes outside of the box, will go a long way in making them ready for whatever comes their way.

Relying solely on electronic technologies is not the answer.  Nor is it a good idea to exclude these technologies in today’s world.  Electronics provide assistance.  They should be treated that way – as a tool that helps us do our jobs.  Likewise, procedures and policies, including awareness and training, are not definitive solutions either. A good security program will have a combination of electronic technologies intertwined with non-electronic technologies for the protection of all.

Sunday, March 19, 2017


Do-It-Yourself (DIY) or Credentialed Security Consultant, That Is the Question






My brother built his house.  He borrowed a back-hoe and dug the hole.  He set the foundation and built his house from the ground up.  I look at him and say, “why can’t I even drive a nail straight?”  Well, there are two reason, first he has the knowledge and secondly, he had the right tools.  I, on the other hand, don’t have the knowledge nor have I ever purchased any tools.  Oh sure, I can unplug the toilet or figure out that a fuse is blown but much more than that, I’m in the dark.  The pun was not intentional, I swear. 



This got me to thinking.  Whenever I have something around the house that needs more than my minimum skills I have to call someone.  They usually arrive and the first thing they ask is, “Who did this?” as they look at the thousand mile-an-hour tape or screwdriver wedged against the window or the string hanging from where the handle should be on the screen door.  Then they go about fixing it and charging me the equivalent of a mortgage payment.  They leave with a smile on their face and say, “Call us before you try to FIX IT again.  You’ll save money in the long run”. 



I asked my brother, where he got his knowledge and he told me that he asked lots of questions to people in the know and when he needed to, he bought or rented the tools.  If they had the skill set for roofing he asked roofing questions, same for plumbing and so on.  I was glad when he told me this because up to this point, I thought my Dad shared house building skills with him but not with me.  I was made at my Dad.  Forgive me Dad.



Well, the same holds true in security.  There are projects you can do on your own and there are things you really should get an expert to handle.  With the advancement in technologies in recent months you can basically, “plug and play” all types of electronic security systems.  This is a good thing.  I remember a day when programming the VCR was a disaster.  Even though my English is pretty good, I could never understand the instructions.  I had to get a friend to do it for me.  But back to security.  Electronic security systems have become sophisticated but you don’t have to be an “IT geek” to use them.  Most can be monitored on your phone with an App download.



But, if you’re going to assess your property and take a holistic approach you probably want someone with knowledge in vulnerability assessment/risk analysis or in developing mitigation strategies or someone with a Physical Security Engineering (PSE, SPSE or MPSE) designation.  If you have a very large project or are worried about cost overruns, you could also get someone with credentials from the Security Industry Association (SIA) in project management or a Certified Security Project Manager (CSPM®).  Another reputable organization is the American Society of Industrial Security (ASIS), which provides a variety of designations.   The security consultant having one of these credentials or designation is your guarantee that the person doing the job has the right tools sets and the knowledge to use them.



DIY is okay but remember one thing; good advice has a cost but free advice may cost you more.

Sunday, February 19, 2017


FOUR TRICKS TO THE PRINCIPLES OF

EFFECTIVE PHYSICAL SECURITY DETECTION



 I recently had a newcomer to the security business ask me, “So, how would you describe what security is?”  I looked at her like, what a stupid that question is.  But after I thought for a second, actually it was a pretty good question.  A question many of us would provide varying definitions of.   My answer was pretty short.  Security is, the detection of behavior – good, we reward; i.e., password or PIN and we allow you access to the computer or ATM, bad, we deny access. 

Simple, right?  Yes.  So, the questions become, “How do we ensure effectiveness?  How do WE determine good or bad behavior?  Where should we do it? And, how do we make sure we know the difference?”

AS FAR AWAY AS POSSIBLE

Detect activity as far from the asset, thing you’re trying to protect, as possible.  We want to detect all behavior.  Then we can decide if it’s good or bad.  Good behavior – we allow access and bad – we don’t.  When it comes to valuables or assets, anything of value can be considered an asset.  An asset is something you place value on.  It could be a building, a process, an object or people.  Even my crazy cousin back in Indiana could be considered an asset.  Ok, well maybe not my cousin.  But you get the gist.

An asset doesn’t have to have value to the owner.  As long as it has value to somebody, then it is an asset.  I guess that means my cousins back in.

We want to protect those things we value at the furthest opportunity we can afford; either at the property line or even before, if possible.  Usually we do this by defining our property line.  We use fences or signs or other materials that say, “Hey, this is my space, so stay over there and I don’t care what you do, but come over here.  I want to know about it”.  In the old days, we had to post a guard to detect penetration.  Today, we can use electronic technologies that assist us in detecting when people come into our space.

You can access my article “More Power to the Perimeter” starts on page 31. http://issuu.com/securitymiddleeastmagazine/docs/sme_july-_aug_2015_web?e=0/14330179

IT’S ABOUT DETECTING UNWANTED BEHAVIOR

Electronic or non-electronic detection, it really doesn’t matter.  It’s about detecting behavior and then deciding if it should be rewarded (allowed entry) or not (denied access).  I often ask my students if they think we should detect all behavior or just the “bad”.  Most say, just the “bad”.  We don’t have the time to watch everything.  Well, actually we do. It’s just that we’re a lot quicker in rewarding “good” behavior than when something wrong happens.  As long as the rules are followed, everything’s fine.  Let someone forget their badge or password and well, and then the problems start.

BEST DETERRENCE IS A WELL-TRAINED STAFF (YOU WERE EXPECTING ME TO SAY GUARD FORCE, WEREN’T YOU?)

Actually, having a well trained staff in knowing what constitutes good behavior is the best deterrence you can achieve.  Trained staff is a force multiplier.  That means more eyes on your environment.  Trust me; your staff knows when things are out of place or when something is just not right.  That doesn’t mean you’re going to get them to “rat” on each other but you can get them to think about protecting themselves and their colleagues.  I recently read an article about the creation of open office spaces adding to efficiency and productivity.  The psychological impact of the space adds to a sense of belonging and our natural instinct to protect ourselves and each other.  Use that to your advantage.

Teach folks what “suspicious” looks like, when and how to report it and when it’s okay to intervene themselves without getting hurt.  Sometimes “bad” behavior can be corrected on the spot.  Other times the “authorities” need to get involved.  When reporting suspicious behavior, describe the “bad guy/gal” by comparing them to yourself; i.e., taller than me, heavier than me, blond hair like me.  While clothes description are important folks should focus on things that are less likely to be changed quickly; shoes or pants, complexion, color and length of hair.  The responding forces will need to know if any weapons were involved and if anyone has been hurt and where to find you.

DRILLS & EXERCISE STAFF & GUARD FORCE (OFTEN, CREATIVELY AND REWARDING)

Administrators and decision makers can increase the likelihood of detecting unwanted behaviors by conducting routine, periodic and creative drills.  Some drills should be done just for small groups, while others should involve everyone.  Sometimes with the guard forces and sometimes the guard should train alone.  There’s a difference between “preparedness” and “readiness”.  “Preparedness” is having material stockpiled and “readiness” is knowing where to get materials and what to do with them.
Follow me on twitter @hainessecurity for more security tips.