Readout 002
Your Security Program Is Being Designed in Meetings It Isn’t Invited To.
A company selects a new facility. Real estate looks at location, price per square foot, access to transportation and whether the building meets the operational needs of the customer. The lease gets signed…..and then somebody calls security.
The problem is that by then, most of the security decisions have already been made.
I worked on a facility project for a high-profile customer with significant security requirements, including TAPA B certification. The location made sense because it was near a major seaport, which was an important requirement for the customer, but the building had open-air loading and unloading areas. Bringing those exposed areas into compliance would require additional layers of protection, much of which could have been avoided if security had been involved before the facility was selected.
Layers of protection are designed to delay and detect a bad actor long enough for security or law enforcement to respond to an attempted breach. Those layers are much easier to create when they are considered during facility selection and design. When they have to be added afterward, the solution can interfere with how people and product move through the operation.
The issue wasn’t limited to security. Open-air loading and unloading areas can allow birds, rodents and other pests into spaces where products are being handled, creating quality concerns as well. What appeared to be a real estate decision ultimately affected security, quality, operations and the customer.
Once the lease is signed, the company may be committed to that building for three to five years, and exiting early can involve significant penalties. Security can still develop additional processes, introduce guard procedures and find ways to protect a facility that was not designed for the risk, but in this case, doing so could cost hundreds of thousands of dollars and affect how people and product move through the operation.
Real estate is an easy example, but decisions like this are made throughout a business every day. Engineering decides where racking goes and how employees move through a facility. Tight work aisles, entrances and exits, smoking areas, break rooms and other places where employees regularly congregate are also places where workplace conflicts can and do occur. Understanding how people move through a facility helps determine camera placement, access control and other security measures.
IT makes decisions about IDF cabinets, MDF rooms, fiber and network infrastructure. Those are security decisions too. Physical security systems don’t operate independently anymore. Cameras and access control depend on that infrastructure, and if critical IT areas aren’t appropriately located and protected, an entire security network can potentially be taken down.
Even something as simple as where HR decides to put a time clock can have security implications. If we’re investigating time fraud, we may need to determine whether an employee actually came to work or had somebody else clock in for him. The placement of time clocks also matters when employees have to pass through guard stations or metal detectors. Security, HR, engineering and operations all have an interest in making sure employees can move through those areas efficiently, safely and in accordance with applicable wage-and-hour requirements.
HR decisions can also change a company’s threat environment very quickly. Reduction-in-force actions are a good example. An employee who has had an ongoing issue with another employee but hasn’t acted on it because of fear of losing his job may think differently if he believes he’s losing his job anyway. The same can be true for theft or other misconduct.
That is where the experience of a good security leader becomes important. HR may own the employment decision, but a good security leader is trained to understand the human factors surrounding it, including how to recognize behavioral warning signs, assess potential threats and anticipate when a difficult conversation or personnel action could escalate into a security concern. Advance notice allows security to consider the employee’s history, access and workplace relationships, then help HR and leadership determine how, when and where the action should take place. When security learns about a potentially high-risk termination twenty minutes beforehand, the company has already limited its options and lost the benefit of that expertise when it matters most.
So why isn’t security involved earlier?
Sometimes the answer is simply that collaboration requires additional effort. If real estate is evaluating five, ten or fifteen buildings, coordinating drawings and requirements with multiple departments isn’t easy. It can be easier to make the decision unilaterally and tell everyone else to figure it out on the back end. That’s not a good answer, and probably not one many people would admit to, but it happens.
The reluctance to involve security isn’t always about the additional effort. Some departments and leaders simply believe collaboration slows down the business. They see additional stakeholders, processes and toll gates as a hindrance to getting business done instead of a way to make sure business gets done effectively and efficiently.
Security has probably contributed to that perception over the years. The industry has traditionally been viewed as a reactive function. Something gets stolen, call security. There’s a threat, call security. An incident occurs, call security. The focus becomes “catching the bad guy on the back end” instead of working with the business to prevent the problem on the front end.
A good corporate security function shouldn’t operate that way, and a good security leader can’t simply be the person who says no.
Saying, “No, you can’t do that,” is a pretty effective way to stop getting invited to important conversations. Other business leaders don’t want to bring in a department that they believe is only going to create another obstacle.
A good security leader needs to be able to say, “Yes, but….”
Yes, we can do this, but here is the risk. Yes, we can use this facility, but here is what it will take to protect it. Yes, we can move forward, but here are the controls we need. That’s being a business partner.
There is a significant difference between a security department that protects the business and one that actually helps the business make decisions. The first may be good at preventing losses. The latter also helps grow the business by making better decisions possible.
That requires security to be involved not only with operations after business is won, but also with business development, client services and strategic business growth. Those probably aren’t the first three meetings most CEOs think their security leader needs to sit in on, but they should be.
By the time somebody calls security and says, “We need you to secure this,” the company may already have signed the lease, designed the building, committed to the customer, selected the vendor or made the decision. At that point, we’ll figure it out. That’s what good security leaders do.
The ability to solve a problem after the decision has been made should not be confused with the opportunity to prevent the problem from being built into the decision in the first place.
Your security program is being designed whether your security leader is in the room or not. The question is whether you want them helping design it.