Showing posts with label business security. Show all posts
Showing posts with label business security. Show all posts

Take Me To Your Leader



Space aliens, at least in B-movies of the 1950’s, immediately order the first person encountered to, “Take me to your leader.” Of course, you have to wonder how an alien smart enough to fly across the galaxy could not have figured out how to land on the south lawn of the White House.
"Take me to your leader."

Even so, these slightly wayward aliens may be on to something. After all, the best way to get something done is to ask the person with the authority to make any necessary decisions. Sales people stress the need to ‘sell’ to the decision-maker – anyone else is a waste of time. Even so-called customer service centers have figured this out. They avoid actually solving customer problems by making sure the leaders who can make a decision are never available. Try it. Call with a complaint and ask to speak to a supervisor – they are always in a meeting and not available so you get the promise of a call back, which never happens. No matter the perspective, alien, customer service or sales, leadership matters. It is every bit as important when it comes to protecting a business as well.

When it comes to security, many companies have no leadership. The end result, as you would expect, is a disjointed and unfocused security program at best, or worse, no security at all.

Many businesses may not be large enough to justify a full-time security leader. That does not mean then that there should be no leader. It may be a collateral, or side, duty of another leader in the business. For example, the facility director may be assigned security leader functions as well.

This leadership should be identified in the job description and included in any future job postings. Be sure to tie the role to a clearly identified position rather than one individual. If that person leaves, there may be confusion about who will take over. For many organizations, there will be even more confusion on what those security duties are.

By identifying a leader, you provide focus and direction. There is also one person responsible for security decisions. The security leader becomes the primary focal point and can work with other leaders to coordinate security concerns. For example, it may be necessary to coordinate the issuance of keys with HR and maintenance departments. This ensures that employees have the appropriate access that they need to do their job.

So who should be the security leader? First, it should be someone with a direct reporting relationship to the c-suite. This ensures the right level of authority to act if there is a serious safety issue or concern. 

Second, if it is a collateral duty, the primary role of the leader should overlap the security role. This could vary on the type of business industry or specific needs. Security can be found in a broad range of company functions. It may fall under legal, human resources, facilities or operations. If your company is focused on physical security of the buildings, the best fit may be facilities. However, if the focus is on protecting employees then HR may be the best fit. If compliance or regulatory requirements are the focus, the legal department is the better option.

Security is truly inter-related into so many areas, the best fit may be director of operations. For many companies, operations covers or works with other departments and security may be a perfect complement.

Make sure that your business has a security leader. This is the only way to have a cohesive protection program that keeps employees and visitors safe, protects vital assets and reduce losses. And any visiting space aliens will know where to go with any security questions.

For more ideas on how to protect your business, check out Workplace Security Essentials. For a limited time, the publisher is offering 25% off the cover price so act now.

-------
Get a Business Black Belt for your organization – visit www.businesskarate.com/karate-belts.



Learn self-defense for your business with Eric Smith’s new book, Workplace Security Essentials! Every aspect of protecting a workplace is compared to a self-defense skill taught to budding karate students, all in a practical and entertaining style, drawing on Eric’s law enforcement and security experience.


Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces. To learn more email Eric at businesskarate dot com.

Awareness – The Foundation of Good Security


If you were learning a martial art, such as karate, one of the first steps would be to learn how to stand. Not standing as if you were waiting in line at the grocery store; but standing in a stance that helps you maintain balance. A karate student learns several different stances for different positions and situations, all of which keep the weight distributed more evenly and have a lower center of gravity than normal, making it easier to stay on your feet rather than getting knocked down.

           
In my book, Workplace Security Essentials, I looked at how martial art skills translate to the protection and security of organizations, such as businesses, schools or hospitals. The stance is the basic posture or position, such as a business’ awareness of security risks forms its posture or position related to risks.

In short, if a business wants to improve security or protect itself from crime, leaders must create awareness and share information about security concerns. But how is that done?

The heart of awareness is knowledge – knowledge about the real-life problems, challenges and threats facing a business or workplace. That means an organization needs to have a record of crimes that have happened at the site or immediate surroundings. Even small businesses with less activity can still look at crime in the area, using local police information about risks in the community.

In fact, tracking criminal activity is considered so important that higher education, such as colleges and universities, are required to maintain records and logs of criminal events per the Clery Act.
The Clery Act requires universities and colleges to track crime. (photo from Wiki Commons)

To be even more effective, knowledge has to be shared. Use the crime log to keep employees up-to-date on any security alerts or warnings. This should include crime prevention tips related to any ongoing crime patterns or even BOLOs (Be On the Look Out) to help employees recognize suspects or suspicious activity.

Unfortunately, some leaders feel that sharing crime information only creates alarm or undue distractions for employees. My experience has been the opposite. Not sharing information, especially about any crimes that have occurred on the company grounds or to employees, will be passed along – often through rumors that grow and change until the original minor crime has morphed into the most heinous crime of the century. Sharing information, along with practical prevention tips, will build real awareness. Perhaps more importantly, it builds trust. Employees will feel that the organization is looking out for them, not keeping them in the dark.

Going back to the Clery Act for higher education, the Act requires that alerts or warnings be issued for specific crimes, including violent and property crimes. Institutions are encouraged to issue warnings for other crimes as well, but leave that up to the school.

Building a base level of knowledge about the real risks and sharing information about those risks is the best way to begin building awareness and developing your security stance. This forms the basis of the security program.

To get more ideas on how to build security awareness, check out Workplace Security Essentials.

Get a Business Black Belt for your organization – visit www.businesskarate.com/karate-belts.


Learn self-defense for your business with Eric Smith’s new book, Workplace Security Essentials! Every aspect of protecting a workplace is compared to a self-defense skill taught to budding karate students, all in a practical and entertaining style, drawing on Eric’s law enforcement and security experience.

Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces. To learn more email Eric at businesskarate dot com.


 

If you would like to reprint this post, please contact Eric at Eric at businesskarate dot com.

Turning a New Page


Some of you who routinely read my posts already know that I’ve been working on a new book. The original idea stems back several years ago when I had the idea that the same self-defense techniques taught to karate students could apply to a business, or any other type of organization.

The idea eventually grew into the whole concept of Business Karate, which I incorporated into this blog and my website. It is a way to combine my interest in martial arts with the business of protection and the protection of business.

The book, Workplace Security Essentials, covers all the basic principles throughout the 14 chapters. For example, one chapter covers employee threats based on the idea of learning to throw a punch. A punch is really best for a very close target as compared to a kick that has more reach. Employees are very close to the most vital assets of an organization and can often cause the most damage and loss.

Throughout the book, I used real-life examples, many from my own experience in law enforcement as well as security management. There are numerous examples, such as tables, forms and other tools throughout the book to help a reader enhance their own organization’s security program.

Of course, it has not been an easy process. In fact, it was very eye opening. I had always pictured writers working alone over a typewriter in some remote country home. Instead, I quickly learned that writing was a matter of putting in a busy day doing all the normal work, then stealing every little block of time to work on the book. There were also many evenings and weekends, I had to tell my kids ‘no’ when they wanted to do something fun – taking them to the park to play basketball or even going for one of their favorite “zombie runs.”

But, finally, the book is done and just released on Amazon by the publisher, as well as on the publisher’s site (Elsevier). I got my copies about a week ago and I have to say that it was thrilling to see and hold the finished product in my hand!

So now, in a manner of speaking, it is time to turn a new page. With the book done, I will be turning to marketing it. Not only that, but I am ready to start work on more books. I have several ideas, including some fiction novels and want to get those written in the near future. I will take a more realistic view of any schedules and deadlines so I don’t miss those valuable family times. I also plan to spend more time working on this blog again.

Speaking of turning a new page – if you are looking to turn a new page, may I suggest turning the pages in my latest book, Workplace Security Essentials. I’ll make it easy for you – you can order a copy by just clicking this link: http://www.amazon.com/Workplace-Security-Essentials-Organizations-Environments/dp/0124165575/

 

Get a Business Black Belt for your organization – visit www.businesskarate.com/karate-belts.

Eric Smith, CPP is the leading authority on organizational self-defense. He has extensive experience in law enforcement as well as security management. Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces. To learn more email Eric at businesskarate dot com.

 

 

If you would like to reprint this post, please contact Eric at Eric at businesskarate dot com.

The Irony of Government Solutions to Data Breaches


The U.S. Attorney General, Eric Holder, urged Congress to pass Federal laws to regulate how retail outlets handled data breaches. This was in response to the breach at Target where hackers stole credit card information from customers in December of 2013.

Holder stated that retailers who fail to protect data should be held liable. He also stated that a Federal law would assist law enforcement with prosecution.

At first glance, it may seem like a good idea. After all, we all deserve to have our identities protected when shopping. However, several questions come to mind. As is so often the case with good intentions, the results may not be everything hoped for.

First, there is a problem with where the blame is focused. Too often, we see cases where the victims are held liable for the actions of crooks. By holding the retailer accountable, the focus shifts to punishing the victim organization rather than focusing on the criminals behind a breach. This same mentality is used at local levels, such as when police will patrol neighborhoods on cold mornings looking for “puffers.” These are cars that someone starts to warm up while waiting inside. True, there are suspects who will steal the warming cars. If the police can take the time to stop and write parking tickets to the would-be victims, then wouldn’t that time be better spent looking for suspicious people hanging out in the areas where the cars are being stolen? Education about the risks and ways to protect yourself, rather than blaming victims, is a much better approach. Of course, as with any harmful event, there is the risk of a company being held liable, especially if the data protection measures were negligent or lacking. Assuming appropriate measures were in place, blaming the organization is counter-productive.

From WikiCommons
Second, it is ironic that the government would be in a position to dictate what standards other industries should follow. After all, one of the most famous cases of a data breach is the government’s loss of hundreds of thousands of confidential documents to a contractor in the case of the National Security Agency and Edward Snowden. It hardly instills confidence in a government solution.

Third, I am doubtful that establishing Federal standards would provide any real assistance to local police. Local jurisdictions do not have the legal ability to enforce Federal laws and Federal prosecutors are often swamped and, in my experience, will not even touch smaller cases. There would be benefit with information sharing between local law enforcement to facilitate investigations, but in many computer crimes, the suspects are out of the country and there is no way local police can ever prosecute. I would like to see more of the details about how these cases could be investigated with a successful prosecution before just accepting that another political solution would actually achieve any benefit.

Last, most states already have laws related to how companies need to respond to and address data breaches. A new Federal mandate could override state laws and might not be as effective as the current law. Plus, any time there are legal changes, there will be additional costs and those will ultimately be passed onto the consumer. There are already limits on how much consumers can be liable for in regards to identity theft. New laws or changes could potentially be more costly to the consumer, the very group these laws are designed to protect.

Too often, when there is a real problem to address, the knee-jerk reaction, especially of politicians, is to announce solutions that may or may not work. As always, look at the goals and the consequences of new measures. These decisions should be carefully vetted and reviewed and the best course of action taken for the good of all, not just as a ‘feel good’ idea. Keep the focus on stopping criminals, not finding someone else to blame.



Eric Smith, CPP is the leading authority on organizational self-defense. He has extensive experience in law enforcement as well as security management. Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces. To learn more email Eric at businesskarate dot com.


 

If you would like to reprint this post, please contact Eric at Eric at businesskarate dot com.



The Security Outlook for 2014



               This is the time of year when we find ourselves thinking of New Year Eve’s parties, confetti, Auld Lang Syne and resolutions for the new year (usually around getting rid of the pounds we put on during Christmas). There is also the stream of news stories about the past year, the top stories and the events and people that shaped the year. It is also a good time to take a glimpse into the coming year and think about the changes, challenges and rewards that lie ahead.

               Security, and how security relates to business, is constantly changing as well, so this is a good time to reflect and plan for the future.

Information Security
Cyber risks are a global concern

               Information security will continue to be a top focus when it comes to security. With the latest breach of credit and debit cardholders who shopped at Target, there is the ongoing fear of identity theft. The investigation continues on how hackers were able to collect all that information, including PINs for debit cards. How much of this was actually used remains to be seen or if it was an inside job. However, it has garnered a lot of media attention and brought identity theft and information security back into the spotlight. It would be surprising if there were not a push for some new legislation as a result of this, including penalties to businesses that expose customers.

               Another top concern related to information security and hacking is the risk of cyber-attacks, especially on critical infrastructure such as power grids. There have been various attacks, including some coming from foreign governments, such as China and Iran. A serious attack on utilities could essentially put the United States back in the stone ages in moments and would certainly wreak havoc.

               The hidden risk is the continued shift of focus away from physical security. Protection from physical attacks should never be overlooked. There have been a number of actual attacks, including active shooters, even the recent suicide bombs in Russia. 

NSA
               The story of Edward Snowden, the wayward NSA contractor, fleeing the country with tens of thousands of confidential documents is not going to disappear any time soon. There are legal repercussions ongoing and the question of how much information the NSA (National Security Agency) can legally gather from citizens will almost certainly end up before the U.S. Supreme Court.

               In the meantime, Snowden still has tens of thousands of additional documents that could be released and we can only speculate what kind of information might be within. The revelations have re-ignited the debate between security and liberty. Benjamin Franklin is known for saying that those who value security over liberty deserve neither. In 2014, we will certainly see more debates on how to balance protection from terrorists while protecting individual privacy and our constitutional rights. There is an additional question related to security; how did the NSA, of all groups, miss the dangers of allowing a contractor, not even a full employee, access to so many confidential documents. You have to wonder what kind of background screening was done as well. That leads to the question of how the NSA can manage gathering so much information and find the true threats when probably 99% of the information is useless.

Pay Inequality

               The World Economic Forum’s annual report has identified economic disparity has one of the top risks facing the globe. It is certainly an area getting a great deal of attention, not just between poor and wealthy nations, but even within developed countries. The U.S. president routinely brings up the issue as a champion of the downtrodden, who in turn express their outrage at being poor across social media with their iPhones. 

               In truth, there is a growing problem. Historically, top executives once earned about 20 times what the average employee made. Today, it is not uncommon for top executives to earn 200 or even 500 times what the average employees earn. Worse, household income has dropped over the last few years while corporate profits have been increasing. That is a recipe for discontent and social unrest. Switzerland, a business-friendly nation, nearly passed a restriction that would have limited executive pay to only 12 times the pay of the lowest-paid employee.
 
News Photo
               The risk is disturbances or even riots, is a very real threat that could impact supply chains and disruptions of service or even strikes. We have seen a variety of businesses that boast of being ‘green’ or promoting ‘fair trade’ and it is likely that some forward thinking businesses will promote themselves for caring for employees and having more equitable pay scales.

Obamacare

               A look at business risks cannot ignore health insurance reform, a top issue in the United States, specifically the Affordable Care Act, aka Obamacare. Within the healthcare industry there is great uncertainty and talk of cost control, i.e., lay-offs. Meanwhile of the 40 million uninsured Americans, only 1 million signed up for Obamacare. Most Americans are finding that the costs are anything but affordable. 

               Certainly, health insurance is going to be a hot topic, within both politics and healthcare, but also one that impacts every business and individual with insurance. The deductibles and monthly premiums are increasing. Businesses that provide services to hospitals should be particularly wary, as the hospitals will squeeze every contract for savings. Likely, the only things that will not change are the salaries paid to the physicians.

Active Shooters


               Shootings in Colorado and at Sandy Hook Elementary have sparked debate on care for mental health patients and gun control. School security has been a particular focus. Just like after 9-11, when there was a sudden emersion of so-called terrorist experts, there is now a rush of school security experts with arrays of solutions. Training teachers how to fight armed attackers with knee strikes and elbows is becoming more commonplace, although there still seems to be reluctance to add well-trained, armed guards to schools (expense is part of the concern). Learning to fight back is great, but it would be better yet to have the right tools for the job.

               The risk is that attackers also learn from news coverage and will adapt their plans to harm as many people as possible. Schools and all organizations need to consider other potential tactics, such as explosives, chemicals or gas attacks and so forth. Terrorists have used similar methods around the world for decades, sometimes with horrific effect. Do not get tunnel vision.

All the Usual

               In 2014, we will see our share of bizarre and strange crimes. Lust and greed fuel evil people into all sorts of crazy schemes. If any involve beautiful women or tales of sex as part of it, you can expect the usual media frenzy. Oh. Don’t forget the usual celebrity stories with drugs, alcohol, rehab and relapses and whatnot. Did I mention Duck Dynasty?

               Fasten your seat belt and hold on. 2014 will certainly be another interesting year.



Eric Smith, CPP is the leading authority on organizational self-defense. He has extensive experience in law enforcement as well as security management. Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces. To learn more email Eric at businesskarate dot com.

  

If you would like to reprint this post, please contact Eric at Eric at businesskarate dot com.

To Arm Or Not to Arm - That is the Question!


            It has been 400 some years since Shakespeare’s Hamlet first posed the question, “To be or not to be.” Today, a modern twist seems to be a recurring question; to arm or not to arm.


Edwin Booth as Hamlet
By J. Gurney & Son, N.Y. (19th century) Public domain, via Wikimedia Commons
            Since the shooting at LAX that left one TSA agent dead, the question of arming TSA officers has come up. I’ve seen arguments both for and against arming TSA. It is not unlike the arguments about having armed security in schools or even arming teachers.

            It is not a simple question to answer. First and foremost is to avoid making decisions in a knee-jerk reaction. It is amazing how often within the security realm that an event happens and suddenly there is a rush to make changes. It may be within an organization that experiences a crime, such as an attack on a staff member, resulting in new measures that may or may not always make sense. In other cases, such as this with the LAX shooting, the response and attention is in the public eye, not just an internal matter.

            When there is a major incident or security breach, it is common sense, even wise to review what happened, and make changes when necessary. However, the changes should be well-thought out and address the situation at hand. Following a shooting, there is almost an element of surprise that it happened in that location or type of organization. However, we’ve seen shootings occur almost anyway, from churches, hospitals, museums, small businesses, universities, rural and urban schools and even an Amish school. The bottom line is that a shooting can happen in any location, in any state, in the city or in the country. So a better reaction would be to avoid the next shooting or protect the next target instead of thinking about stopping the last event. Often military leaders are accused of training and preparing to fight the last war, instead of looking to what will be needed to fight and win the next war.

            It is easy to focus on the past instead of looking to the next steps and it is natural, in this case to wonder about arming TSA officers. I have seen some opinion pieces by airline employees argue against arming TSA. The bottom line seemed to be a lack of trust or maybe even an underlying fear of firearms in general. It strikes me as odd, that a group who are entrusted with protecting our airlines from terrorists would be untrustworthy to carry firearms. On the other hand, this was a single incident and does not automatically mean that TSA officers are a target. In fact, I would argue that airports are far safer than many other public venues. Airports have more security and a large contingent of armed police officers to respond to any types of violent acts. I have also seen TSA officers, in uniform, on their way to work, sometimes using public transportation. If TSA is such a high risk target then those employees should be instructed not to wear the uniform on the way to or from work and change at the airport. In fact, that would create a risk that someone could follow an employee home; steal their uniform and perhaps identification to pose as a TSA officer to gain access to secure parts of the airport.

            Self-defense techniques and training unarmed individuals on how to respond to an active shooter have been growing more popular as well. I certainly believe in the benefits of learning self-defense and think that unarmed individuals should not just give up and become victims during a shooting. However, there is an old saying about bringing a knife to a gunfight being a sure way to lose. Bringing nothing to a gunfight is even more risky. Many of the techniques appear to be good ideas and could help save lives. However, most of these attacks are carefully planned and the shooter will certainly see the same news stories and watch the same online videos and adapt their tactics to counteract any resistance.

            So the question really comes back to what is the best way to protect individuals from armed attacks. Lots of money and training has gone into teaching unarmed response. Perhaps we need to reconsider the response yet again.

            Most active shooters have ended when the shooter is confronted by armed response. The real solution may be to train on-site security personnel how to respond the way law enforcement does to an active shooter. This is certainly one solution not getting much attention and is especially suited for organizations that do have a dedicated security force. Hospitals are one example. Shopping malls are another, as are many office buildings in urban downtowns. For enterprises or locations that do have onsite security, the focus should shift to training those personnel how to respond to and stop an active shooter.

            Following the shooting at Columbine High School, law enforcement began developing new tactics to respond to active shooters. At the time, I was a police firearms instructor so was very involved in that training. For the first few years afterwards, the tactics changed repeatedly. As police officers, we finally settled into accepted tactics that we focused on learning and practicing. However, as important as this training was, the amount of time spent for patrol officers was one time a year, often not even a full day. In fact, officers might only run through a couple of active shooter scenarios during the training.

            The point is that private security could easily train and learn some of the same tactics in a relatively short amount of training time. In fact, private security officers would know the building and organization much better than outsiders would and, being onsite, could respond much quicker than law enforcement. Just the presence of armed security would likely deter a shooter, at least away from that target.

            The decision about arming or not arming security is certainly daunting. However, for those organizations that do have security, serious thought should be given to providing private security with the training and tools that would be the strongest deterrence and most protection from an active shooter attack.

 

Eric Smith, CPP is the leading authority on organizational self-defense. He has extensive experience in law enforcement as well as security management. Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces. To learn more email Eric at businesskarate dot com.

 

 

If you would like to reprint this post, please contact Eric at Eric at businesskarate dot com.