Ally Leonard – Director of Risk & Compliance at Assist Services Group writes ...

The nature of threats faced by organisations as we move into our new world are very different and the entire organisational culture and priorities of businesses have changed. Understanding where the security industry fits into this new world will be imperative to our industry.

 

With companies across various industries being hit financially we are seeing the provision of the traditional security officer role and the tiers above within the security framework either being reduced or removed entirely. However, has the risk profile organisation changed / reduced or has the security culture of the organisation changed / become less of a priority due to financial pressures within the business.

 

It is understandable that due to these “unprecedented times” (how many times have you heard that over the past 6 months!), businesses are looking at the bottom line – but security is an essential service. Would a business turn off their company wide anti-virus / firewall to save some money? Absolutely not as their infosec vulnerabilities, culpability and accountability risks far outweigh the cost of infosec security. So why is not necessarily the same for the physical security presence? One could argue that the current status of the physical world is as evolving as the cyber one as we do not know what our “new normal” is.

 

Managers of frontline officers need to look at current deployments as brand-new contracts. Operational risk register need to be reviewed and shared with clients and / or decision makers within the organisation. Review procedures and work instructions – do they still work? Are they still fit for purpose? Staff training matrixes – are they still fit for purpose? What are the new organisational priorities and how does the security culture fit in – or should the new organisational priorities fit into the current security culture? What is the risk vs reward for the change and what are the new organisational security vulnerabilities? Whether or not the security culture has changed within the organisation, you must analyse your operation from every angle.

 

You must then look further afield from your operation and consider the changes of those within your vicinity. Have other organisations changed their security culture / framework and how does that impact your operation? Previous partnership / schemes (i.e. Pubwatch, Shopwatch, local retail crime prevention groups, etc) may have had organisational changes that in turn affect your operation and where communication from a partner or an operation from a neighbour may have indirectly benefitted (i.e. building / area patrols) was relied upon previously and formed part of your operation, it may no longer be there, so does that create a vulnerability for your operation – has your grey space grown?

 

How does a CCTV operator know what the traditional ‘bad guy’ looks like now? Typically, behavioural analysis would occur and those previously displaying body language to avoid capture on CCTV would be the red herring for the operator’s eye for further investigation either through the lens or by sending security to the area. In our new world, how does the impact of face coverings (particularly in settings where they are compulsory) change the dynamic of suspicious behaviours? What are the implications of reduced staffing have on your security objective? Are you able to achieve the core of your security which at its core will always have the principle: Deny, Detect, Delay, Deter. Are you able to achieve these? Do you have the appropriate response to achieve your security objective principles?

 

Previous behavioural analysis training would look at anti-surveillance methods. Technology alone is insufficient as those true to their criminal trade go to great lengths to hide their true intentions and will use their tradecraft to avoid detection from technology. Additionally, society (Central Government and below) are encouraging persons to use face coverings – so how do our frontline officers now identify these individuals who are the threat to our organisations? How does your operative identify them or in fact are they even able to identify them? Are we allowing the physical threats to our organisations to hide in plain sight and exploit vulnerabilities as the principles of the security operation only work via an integrated approach between all.

 

A reduction in staff does not mean your operation is vulnerable, but it may mean that changes to your operation need to be made. How often are patrols occurring (CCTV or foot)? Does the CCTV system have an analytical feature to alert for certain vulnerable areas that can be employed if there is a reduction in Control Room staff? Is there a search regime in place at entry to offset a reduction in deployed staff? How are personnel vetted when employed – does it need strengthening? To harden an operation does not always mean extra resources – it could mean the implementation of a new policy or technology, but as society returns to the “new normal”, security in every aspect must be ahead of the game. Organisations must align the importance of physical security (electronic, staffed, etc) with the same level of importance as infosec and cyber. They will only do this, if we as the security professional ensure that the security culture is fully integrated into the organisational culture and business strategy.