Readout 001

“Nothing Has Happened Yet” Is Not a Security Strategy.

Most companies would never operate without insurance. They wouldn't wait for a major lawsuit to hire legal counsel, or wait for a cyberattack to decide whether IT security matters, and yet, corporate security is often treated differently.

I've seen companies invest heavily in growth, operations, technology, facilities and people while the responsibility for protecting those investments remains fragmented across the organization, or in some cases, isn't clearly owned by anyone. The rationale is often that the company hasn't experienced a significant security event. That's a little like saying you don't need insurance because your building hasn't burned down yet.

Security is, in many ways, an insurance policy. You hope you never have to find out how badly you needed it. But unlike an insurance policy, a good security program isn't only there to help after something happens. Its real value is identifying the exposure early enough so that the event doesn't happen in the first place.

Risk also has a way of growing quietly. As a company expands into new markets, headcount increases, executives travel more frequently and the supply chain becomes more complicated. The company may rely more heavily on temporary labor, give more people access to buildings, systems and product, and become more recognizable as a brand. Each of those changes may make perfect business sense, but each one also changes the company’s risk.

The problem is that nobody sends the CEO a notification that says, "Congratulations! You've officially grown large enough to need a corporate security function.” Usually, something else delivers that message; That “something else” may be a major theft, an internal fraud investigation, a workplace violence incident, a threat against an executive or a disruption that suddenly exposes a vulnerability no one realized existed.

One of the problems I see is that security responsibilities often exist within a company long before there is an actual security function. HR may be responsible for workplace violence. Facilities manages cameras and access control. Operations handles theft at the site level. Legal becomes involved when an incident creates liability. IT handles cyber risk. Travel may be managed by another department entirely. All of those functions have legitimate responsibilities in those areas, of course, but the gap is that each one is looking at risk through the lens of its own function. Corporate security should be looking across all of them.

A workplace violence issue isn't exclusively an HR issue when there is a potential threat to employees or a facility. An internal theft isn't just an operations problem when the same process vulnerability may exist in multiple locations. Executive travel isn't simply a travel function when an employee is entering a country with elevated security or medical risk. A camera system isn't just a facilities expense if it isn't designed around the actual risks inside the building. When no one owns the broader security picture, companies tend to manage individual incidents instead of identifying patterns. That's an important distinction.

If I have the same type of theft occurring at several facilities, I don't have several unrelated theft problems. I may have a process problem, a training problem, an infrastructure problem or a larger gap in how we're assessing risk. If I'm seeing repeated workplace incidents tied to temporary labor, I need to understand more than what happened in each individual case. I need to understand how we're sourcing and onboarding that labor, what screening is being done, what relationships or conflicts are entering the workplace, and whether the same exposure exists elsewhere.

The role of corporate security isn't simply to respond when one of these things happens. It's to have enough visibility across the business to recognize when seemingly separate events are telling you the same thing. That becomes increasingly important as an organization grows, because risk rarely stays contained within the department where it first appears.

And this is where I think companies often misunderstand the return on a security investment. If finance prevents a significant financial loss, nobody asks why the finance department exists. If legal keeps the company out of litigation, we don't question the value of having good legal counsel. We buy insurance hoping we never experience the event that requires us to use it.

Security is one of the few functions that can be asked to justify its value by pointing to the bad things that happened. I'd argue the better measure is how well the organization understands its exposure, how quickly it recognizes a gap, and what it does about that gap before it becomes a significant event. By the time a company can easily calculate what a security failure cost, the security investment usually would have been cheaper.

So for CEOs, I think the question is less about whether your company is large enough to need a corporate security function. The better question is: Who in your organization is looking across the business and asking what could hurt your people, disrupt your operations, expose your assets or damage your reputation, and does that person have the experience and authority to do something about it?

If the answer is several different people in several different departments, that's worth examining. Shared responsibility is important. Fragmented responsibility is different.

You don't build a security program because you expect something bad to happen tomorrow. You build it because you've reached the point where the consequences of being unprepared are greater than the cost of being prepared.

If the first time you're seriously evaluating security is after a significant event, you've already paid for the lesson.

Previous
Previous

Readout 002