{"id":40,"date":"2011-03-06T14:16:37","date_gmt":"2011-03-06T14:16:37","guid":{"rendered":"http:\/\/futureriskmanagement.co.uk\/?page_id=40"},"modified":"2016-04-14T14:07:00","modified_gmt":"2016-04-14T14:07:00","slug":"risk-management","status":"publish","type":"page","link":"https:\/\/futureriskmanagement.co.uk\/?page_id=40","title":{"rendered":"Risk &#038; Security Management"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><strong><span style=\"font-size: large; color: #333399;\">The Illusion of Security<\/span><\/strong><\/p>\n<p><span style=\"color: #000000; font-family: 'times new roman', times;\">It would seem axiomatic that if threats and hazards remain unidentified, vulnerabilities unacknowledged, incidents unrecorded and risk unqualified, that security must fail. In reality, however, it often succeeds, albeit more by good fortune than sound, strategic planning. It succeeds at one specific level, in that the most common threats can be guarded by the most common defences, in other words, those defences provided by physical security assets. There is, therefore, an illusion created, both objectively and subjectively that security is visible, (CCTV cameras and access controls) working, and is effective; objective in the sense that a seeming strong physical feature is a defence against all vulnerabilities and subjective in the sense that the resultant complacency becomes a by-product of the \u2018visual.\u2019<\/span><\/p>\n<p><span style=\"color: #000000; font-family: 'times new roman', times;\">The illusion of security at work satisfies a variety of demanding issues; corporate management\u2019s requirement to discharge, (mistakenly, as it often transpires), best practice, deterrence by means of the visual existence of security assets, and the comfort and morale of staff. Security manpower provision, with the hours of deployment of staff inherited, unquestionably from contractor to contractor, and a by-product of stultified tender processes, may further enhance the deterrence factor sometimes in a positive way, but more often further compounding the illusion that security is working. The test of manpower\u2019s efficacy is the extent to which deployed security officer\u2019s duties morph into pseudo-security and facilities management. The more non-core duties that security personnel adopt, the more obvious it is that security is failing.<\/span><\/p>\n<p><span style=\"color: #000000; font-family: 'times new roman', times;\">The question as to whether security fails is not absolute, as whilst it may fail the test, of a value sensitive, risk driven and strategically thought out process, it often succeeds, albeit as we have said, against the most common threats. Security, as practiced by the many organisations, works against what may be considered, seemingly, the most common denominators of threats and hazards \u2013 break-ins and fire.<\/span><\/p>\n<p><span style=\"color: #000000; font-family: 'times new roman', times;\">The conclusion, drawn from our many years of experience, is that security does fail the test of value and nowhere is this more obvious, from the businesses surveyed, than in the provision of security manpower. Inherited hours of manpower deployment are often accompanied by the narrowest of inherited site assignment instructions, predicated and mandated in ignorance of the wide range of potential security weaknesses that, in the absence of risk analysis and assessment, remain unexposed. Investigation also reveals that the tasks and duties of the manpower equation of the overall security jigsaw, operates at one speed, taking no cognisance of the rise and fall of the macro-environmental, national risk. When the nation\u2019s threat level increases, it can be observed form the assignment instructions that the tasks and aims of security personnel will invariably remain unaffected and not mirror the necessity for increased vigilance and tasks appropriate to reflect the heightened risk.<\/span><\/p>\n<p><span style=\"color: #000000; font-family: 'times new roman', times;\"><a rel=\"attachment wp-att-182\" href=\"http:\/\/futureriskmanagement.co.uk\/?attachment_id=182\"><\/a><a rel=\"attachment wp-att-182\" href=\"http:\/\/futureriskmanagement.co.uk\/?attachment_id=182\"><img loading=\"lazy\" title=\"peghole\" width=\"200\" class=\"alignright size-medium wp-image-182\" src=\"http:\/\/futureriskmanagement.co.uk\/wp-content\/uploads\/2013\/01\/peghole-200x300.jpg\" alt=\"\" height=\"300\" srcset=\"https:\/\/futureriskmanagement.co.uk\/wp-content\/uploads\/2013\/01\/peghole-200x300.jpg 200w, https:\/\/futureriskmanagement.co.uk\/wp-content\/uploads\/2013\/01\/peghole-682x1024.jpg 682w, https:\/\/futureriskmanagement.co.uk\/wp-content\/uploads\/2013\/01\/peghole.jpg 800w\" sizes=\"(max-width: 200px) 100vw, 200px\" \/><\/a><br \/>\n<span style=\"color: #000000; font-family: 'times new roman', times;\">Technology solutions fare little better in the \u2018value test\u2019 and whilst the acknowledgement by corporate management that an apparent solution to manpower costs may well be the application of sophisticated security systems, most substitutions are driven by the suppliers sales efforts, with the emphasis on equipment complexity, not operational functionality, or even necessity. The absence of an Operational Requirement (OR), carried out to assess the operational needs and functionality of security systems prior to instalment, be they CCTV, access management or alarms and signalling, further \u2018tilts a lance\u2019 at the \u2018value test\u2019 in terms of success or failure of the security operation.<\/span><\/span><\/p>\n<p><span style=\"color: #000000; font-family: 'times new roman', times;\">Enterprise risk management is now an established element of the body corporate, driven in the main, especially within those \u2018main board\u2019 listed companies, by the need to comply with the risk specified issues outlined in the Combined Code of Corporate Governance, or qualify their annual accounts accordingly and face the potential ire of the markets. There is an evident, disconnect, or \u2018firebreak\u2019 passed which, in most investigated organisations, that the enterprise risk matrix stops and that is at the door of the \u2018downside\u2019 risks from security threats of man and the hazards of the environment. The \u2018Code\u2019 it should be said, however, makes no distinction and expects a company to approach risk in a \u2018top to toe\u2019 manner, not distinguishing between the potential upside risks of the companies enterprises and the downside risks of security threats.<\/span><\/p>\n<p><span style=\"color: #000000; font-family: 'times new roman', times;\">There is consistent evidence of what can be termed \u2018management snobbery\u2019 when compiling what may be a very sophisticated enterprise wide risk register, leading to a tendency to ignore those singularly \u2018downside security issues perceived as \u2018below the waterline.\u2019 This disconnect is often subjective, not simply a function of the fact that systems are not in place within the security division to produce their threat narrative, rather it is symptomatic of the role in which security, as a corporate department is perceived. The \u2018man on the gate\u2019 and the \u2018camera on the wall\u2019 become a visual metaphor for how unsophisticated in its operation, senior management perceive the role of security.<\/span><\/p>\n<p><a rel=\"attachment wp-att-181\" href=\"http:\/\/futureriskmanagement.co.uk\/?attachment_id=181\"><img loading=\"lazy\" title=\"physical-security-equipment\" width=\"300\" class=\"alignleft size-medium wp-image-181\" src=\"http:\/\/futureriskmanagement.co.uk\/wp-content\/uploads\/2013\/01\/physical-security-equipment-300x219.jpg\" alt=\"\" height=\"219\" srcset=\"https:\/\/futureriskmanagement.co.uk\/wp-content\/uploads\/2013\/01\/physical-security-equipment-300x219.jpg 300w, https:\/\/futureriskmanagement.co.uk\/wp-content\/uploads\/2013\/01\/physical-security-equipment.jpg 458w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><span style=\"color: #000000; font-family: 'times new roman', times;\">The objective of security to protect against criminal and malicious acts can become secondary to the imperative for it to be able to face the day-to-day challenges of operating within what can be termed the organisational culture. Entities operating within certain industries, where ideas and the flow of information are key, can develop a culture, one consequence of which is to labour under the mistaken impression that locking a door, managing strict access and access to sensitive information, all restrict the intellectual flow of information, thereby becoming an impediment to core, business processes. Where a higher than average staff intellect is added to the mix, then resistance to these apparent and inconvenient restrictions on the \u2018individual,\u2019 even for the benefit of the many is likely to further challenge even the simplest of security practices and procedures. The security department will be continuously dealing with a variety of arguments against its mandated procedures, however specious the argument may be.<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"font-size: medium; font-family: 'times new roman', times;\">R<span style=\"font-family: 'times new roman', times;\">isk Managem<\/span><\/span><\/span><span style=\"font-size: medium; font-family: 'times new roman', times;\"><span style=\"color: #000000;\">ent can be defined as<\/span> &#8220;<span style=\"color: #000000;\">a <\/span><span style=\"color: #000000;\">systematic way o<\/span><span style=\"color: #000000;\"><span style=\"color: #000000;\">f<\/span> p<\/span><span style=\"color: #000000;\">rotecting the resources and income of a business against losses, so that the aims of the organisation can be reached without interruption.&#8221; No<\/span><span style=\"color: #000000;\"><span style=\"color: #000000;\"> security programme can be effective unless it is based on a clear <\/span><\/span><span style=\"color: #000000;\">understanding of the actual risks it is designed to control and the value of the programme depends on its appropriateness and the relevance of resources. In other words, cost justification means not spending more than the benefits derived are worth.<\/span><\/span><\/p>\n<p><strong><span style=\"font-family: 'times new roman', times; color: #000000; font-size: medium;\">Our range of consultancy services include;<\/span><\/strong><\/p>\n<ul>\n<li><span style=\"font-size: medium; color: #000000; font-family: 'times new roman', times;\">Threat, Risk and Vulnerability Assessments<\/span><\/li>\n<li><span style=\"font-size: medium; color: #000000; font-family: 'times new roman', times;\">Socio-Political Risk Analysis<\/span><\/li>\n<li><span style=\"font-size: medium; color: #000000; font-family: 'times new roman', times;\">Security Audits<\/span><\/li>\n<li><span style=\"font-size: medium; color: #000000; font-family: 'times new roman', times;\">Strategic Reviews of Organisational Security Infrastructure<\/span><\/li>\n<li><span style=\"font-size: medium; color: #000000; font-family: 'times new roman', times;\">Preparation of Security Policy, Strategy and Procedures<\/span><\/li>\n<li><span style=\"font-size: medium; color: #000000;\">Integrated System Design<\/span><\/li>\n<li><span style=\"font-size: medium; color: #000000;\">Incident, Crisis and Contingency Planning <\/span><\/li>\n<li><span style=\"font-size: medium; color: #000000;\">Business Continuity Management Systems &#8211; Impact Analysis and \u00a0Design<\/span><\/li>\n<li><span style=\"font-size: medium; color: #000000;\">Developing Operational Requirements (OR) for both systems and manpower<\/span><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; The Illusion of Security It would seem axiomatic that if threats and hazards remain unidentified, vulnerabilities unacknowledged, incidents unrecorded and risk unqualified, that security must fail. In reality, however, it often succeeds, albeit more by good fortune than sound, &hellip; <a href=\"https:\/\/futureriskmanagement.co.uk\/?page_id=40\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":84,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"onecolumn-page.php","meta":[],"_links":{"self":[{"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/40"}],"collection":[{"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=40"}],"version-history":[{"count":31,"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/40\/revisions"}],"predecessor-version":[{"id":267,"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=\/wp\/v2\/pages\/40\/revisions\/267"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=\/wp\/v2\/media\/84"}],"wp:attachment":[{"href":"https:\/\/futureriskmanagement.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=40"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}