Physical security threat assessment

LOGO

 Physical security threat assessment

First of all, if you think this is just for professionals, don't be misguided! A threat assessment can be implemented by any person eager to improve their security at home, place of business, office, ranch, farm, flat, or even just a single room! It is just a simple step-by-step system that has been developed over a couple of years, and can be used by anyone willing to put some thought and research into it!

Why use it?

One of the most common risks an organization runs is stagnant and non-evolving security measures. Unfortunately, these things can only be addressed if it is known to the organization. For that reason, it is necessary to perform a complete threat assessment. Sadly, too often a comprehensive threat assessment is missing completely or never updated. So it's your responsibility as the Advisor/Consultant/Team-leader/Security manager or head of the house to make sure that all the risks are reduced to an acceptable level.

The biggest mistake most organizations make is waiting for a safety breach or incident to happen before they implement mitigation strategies. Preparing a thorough threat assessment will undoubtedly help in improving overall security. It will also help in identifying which preventative measures to implement and reduce the risk of possible threats.

Any organization will always have some form of physical threat. Whether it's from general crime, human error, or even natural elements. Physical security is not a one-size-fits-all package. It gets very specific to the organization itself, especially when it comes down to demographics and location.

Before we start

Before we go any further, you should have a clear knowledge of the differences between risk, threat, and vulnerability. If you are unsure or just need a little refresher to make sure you are on the right track, you can learn the difference >Here<. It's also important to note that there are different methodologies out there and each one probably works, but will not necessarily be comfortable for everyone. That's why you need to learn from each of them and develop something that you are comfortable to use.

That being said, you should make sure that the following points are covered in your assessment:

  •  Buildings, assets, and vehicles are characterized
  • Undesirable events should be identified
  • The consequences of those events should be determined
  • The types of threats should be identified
  • Testing and analyzing the protection security systems and procedures
  • Complying with law and regulations
  • Identifying reasonable control measures needed

To formulate the assessment:

Formulating a threat assessment can be done by following these 5 steps:

1) Characterizing facilities

So it should be obvious that you should first know what the actual basis is that your working with. The boundaries of the site, where buildings are on the site, all access points, floor plans, procedures in place, and current security measures if any should be noted. You will need to reach out to some contacts to get all of this information and make sure it is as accurate as possible. Depending on how long the organization has been up and running, you will be able to use things like building blueprints, municipal reports, security SOP's and IAD's, previous threat assessments and reports, environmental reports, site surveys, and a few more.

2) Now you need to determine what events are undesirable to the organization (the risks)

This will vary for every organization. Any crime or disruption in operations is undesirable, and sometimes you might be called in to address something specific, like for instance theft among employees or a physical threat that has been made known to the organization. The following are things to look for:

  • The crime rate in that specific area and also if there are high-risk areas close by.
  • Industry-specific crimes, for example, drug stores and banks will have different types of specific risks related to their trade.
  • Common crime, things like theft and crimes of opportunity.
  • The number of people who will be accessing the organization's infrastructure
  • Cameras and other monitoring systems
  • Lack of manpower
  • The political and religious standing of the organization can also attract more risks
  • Training of staff or team members
  • If there are any direct threats to the organization or one of its high-ranking officials

So now that you have your whole list of risks compiled. Its time to rank them in order of probability, frequency, and impact. Let's say you score each risk on each of these factors on a scale of 1 to 5. Then add up the total of each risk. So the higher the total (the probability and impact), the higher the risk, and that is a threat to the organization. In another column, you can add the control measures that are currently in place if any, and deduct that from the total of the other 3 columns. So if there is good access control currently in place you would score that higher than no access control.

Another important thing to look for is any vulnerabilities the organization has. These will be risks that are not addressed at all and have a good probability of happening, and also possible risks that will have a significant impact but are not being controlled. However, this is only vulnerabilities visible on paper, when on-site and assessing the buildings and controls, you will most likely find more vulnerabilities. This includes out-dated and defective equipment and uncontrolled areas.

3) SOP and IAD's

I would like to separate Standard Operational Procedures and Immediate Action Drills a bit as it is something that is being badly neglected. SOP's and IAD's are as important as any other security system in place, without it there is no guidance in reaction and things often turn out quite bad or undesirable to an organization. Once again the organization's aim should be kept in mind when drawing up these procedures. I like to look at procedures before implementing mitigation as it will assist a great deal when it comes to cost, as you will likely see how much man-power and how much equipment is needed to achieve operational objectives.

The way your system integrates and reacts to threats is an important risk to look at. If the response is slow, the risk is greater, if the response is incorrect, the risk increases. I am pretty sure you get the picture here. A common risk when it comes to applying IAD's or responding to a threat is when all staff members rush to the location of the threat, leaving their areas of responsibility unattended and opening up the proverbial back-door for intruders to sweep in unnoticed. Identify roles and responsibilities for each threat and make sure every staff member knows it!

SOP's and IAD's should also be time/shift relevant! During holidays and night shifts for example there might be fewer staff members on duty. This can change things dramatically. There should never be any regulation changes, strict procedures should be attained at all times! The last thing you want is a burglary at night because staff members or cleaners left a door/gate unlocked or open.

Another thing to remember here is a detailed plan and list of immediate contacts that should be activated during emergencies or incidents. A touch of automation can be good in certain situations and again not so good during other situations. You do not want to be dropping security barriers and trapping employees inside when a fire breaks out, but dropping barriers when a deranged shooter tries to get access can be a good move. And also having a procedure of who to be contacted in case of more serious threats is very important! Will a tactical team be needed to respond from outside? Who will that be? do you have the relevant contacts and procedures to follow in case of a bomb threat? Who has to be contacted in case buildings need to be evacuated? Neighboring buildings could start burning, who do you contact then?

4) Addressing the threats

After you have compiled your list of risks and figured out what lacks in the procedures you should now be able to see the threats to the organization. Now you need to determine the course to be taken to minimize the risk of these threats. It should come as no surprise that the cost will greatly affect the course you will take. Staying within budget and getting maximum security optimization is not easy at all! Tip -This is where your contact list can be a great source of success.

Start by looking at the biggest threat on your list (the highest score one). What equipment will be needed to address it? Think of detection, cameras, man-power, and every other piece of equipment and training needed to reduce this threat to a lower score. A lot of times the same type of equipment and so on will automatically improve the other threats too. Or at least some of the same equipment and manpower can be used to tackle other threats.

Now re-asses the other threats according to the equipment, etc. that was added to the security system. From there, again, take the highest ranking threat and address it like the first one. Just continue this cycle until you can reach a reasonable level of risk from each threat. Always remember to KISS it as far as possible or use automation as much as possible, just be cautious of the cost factor, especially when it comes to software updates and such.

5) Analyzing system effectiveness

Physical protection systems should be described in detail before it can be tested! Ideally, you would like to stop a threat immediately and without any delay or negative outcomes and with as little as a possible disturbance in normal operations. But in reality, this rarely happens and one will always have to deal with some sort of shortcoming.

So to stop any threat you should first be able to identify it. A continuous threat assessment will outline threats and should be communicated with team members to remain effective and ahead of the threat. Team members should be trained in identifying abnormal behavior and activities, technology implemented and physical barriers used for this purpose. Strategically designing entries and exits can be just as valuable, to make sure any threat has to pass the detection phase before being able to access any facilities or inflict any damage to the organization.

After a threat has been detected, there should be a way to confirm that the detection is valid and of real concern and not just a nuisance alarm. This can be done via team members in contact with a Control-room/Security management or Team-leader. There should be good knowledge in the team about how criminals operate and how target selection works and everything that goes hand-in-hand with it. One can use the OODA loop to great effect here. Find out more about how the OODA loop works and the different phases criminals or a probable threat uses to select their attack right >Here<.

Once a threat has been confirmed, the aim is to delay the threat to get reaction forces to the threat and minimize its undesired actions. Of course, it is ideal for a team member that is in the vicinity already, to be able to neutralize the threat. But it is also ideal to have more than necessary force available. One adversary can be extremely determined or under the influence of narcotics and over-power or out-think a team-member and then become a more aggressive threat.  The effectiveness of response is measured by the time taken to get to the threat and to neutralize the threat.

So keep in mind that some organizations might require you to try and neutralize a threat without using aggressive force, I know, it's not something I am very much happy to say but to spare you a potential client or project you need to know how to act. And in this instance you need to know non-lethal options available, but, it is your job to convince these organizations about the reality we face each day. Organizations would likely want to avoid PR damage because of an unjustified shooting on their premises.

Testing effectiveness

To test the effectiveness you should be sure to fully understand all of the above points and what is required of your system to achieve maximum effectiveness. Only then can you define what is required and to be implemented. Once that has been put in place, there are a few ways to test its effectiveness, you could use penetration testing, call in other experts and run some drills over different times to see if detection and neutralization systems work. Nothing can prove effectiveness more than an actual criminal attempt, it's important for organizations to immediately assess their response after an attempt and identify any issues and improve on them.

Upgrading systems

If for whatever reason you can identify any viable threats after implementing mitigation strategies, you need to check for possible upgrades or changes in the system. This includes equipment, manpower, procedures, and software. When you implement new strategies or add anything you should again test for effectiveness, and repeat until the level of risk is acceptable. Always remember the cost affected with upgrades and additions or changes.

More on this topic

To follow up on this piece will be a few more posts regarding principal profiling and equipment and some more tips and tricks to help you formulate a threat assessment.

Until then, feel free to comment below!

Please subscribe to the site or follow me on Facebook @https://web.facebook.com/ALPHADefense

Home defense

Conclusion

Conclusion

Thank you for spending valuable time to work through this guide. I hope it will benefit you as much as it does others. This guide only covers the very basics of each subject and there is more to it than what is mentioned here. But it would be impossible to add everything on one guide or even in a complete book.

The biggest reason is that crime trends change constantly and by the time you have read through the 11 posts this guide consists of, new crime trends would have already been identified. With that said, I would like to invite you to check out more on my website at www.alphadefense.co.za for coverage of all things important to physical and personal security.

I sincerely encourage anyone to continue your training and improve your knowledge on all things related to personal security, whether it's through the internet, local coaches, or participation in any other form of training. It is never too late to start! Planning now, to mitigate threats and risks at a later stage, might just be the key to your safety and security.

It is all too often that I witness the horrific turn out of events just because people refuse to actively implement what they learn, especially those who talk about it but never act on it. If you just talk about dieting and never really follow a proper diet and get active, then you never really get any results. Security is no different, don’t just read about what anyone says, try it, and who knows, maybe you just start to like it!

Feel free to engage with me on your concerns and suggestions. I also suggest you visit these posts often, and that you implement as much of the advice as possible, and add your knowledge of course. Drop me an email if you like.

Look out for any updates on the website.

Until then, keep safe and keep on learning.

Home defense

Barrier 1

Barrier 1

By now you should be able to successfully avoid or deter a serious threat to your family. Now you have time to work on a crucial element of security to any home. A barrier can be anything that prevents anyone from trying to enter your yard who does not have access. Examples of your first barrier can be concrete walls, palisades or fencing, etc.

Barriers have proven to be an invaluable system to keep out unwanted intruders and trespassers. The increase in crime has demanded more and more barriers be erected all over the world. After all, prevention is key. Barriers are not just walls marking out the end of your yard anymore. Those walls are now probably the least effective if they don’t have any spikes or electrical fencing installed on top of them! And even that can easily be overcome if an intruder thinks it is worth the risk. The greatest threat to barriers today is the influx and availability of technology, ladders, hammers, wire clippers, and blankets are cheap and cost-effective for criminals today. Some even get them for free from their actual day jobs.

The older designs like flat walls and six-foot slabs are now as much of a challenge to criminals like small hurdles are to professional athletes.  We have been chasing criminals in communities for centuries now and just cannot keep up to those little guys jumping those walls like it’s no issue. While we see police officers having to boost each other over because of the weight of their body armor and gear.

Although this can turn out to be the most expensive element in your security system, it can be the most invaluable one. When installed correctly and with some good planning. The trickiest thing with barriers is choosing one. You don’t want it too small, too high, too bulky or too expensive to maintain.

If you are not sure that your current barrier is suitable for your yard, or you are now considering installing one, follow these basic guidelines:    

  • Your barrier should be heavy and strong enough to resist anyone who tries to push it over or ram it with a light vehicle.
  • It should not be completely closed so to prevent anyone from seeing into your yard, that way no one will ever notice an intruder in your yard when a patrol is conducted. And you will never be able to see any threats in the yard when approaching the gate.
  • It should have some form of spikes or electrical shock wiring with an alarm system for when someone is tampering with the wiring.
  • It should be sloped outwards if possible as to make climbing over it harder.
  • It should be installed on all sides of your yard. Many times I find large gates and high palisades coming in from the front, only to find a small fence at the back or some gap right next to the neighbor’s barrier.
  • Electronic gates are preferable, to reduce time wasted on opening and closing the gate.

Keep in mind that these barriers can be costly, and it in no way guarantees to keep criminals out, but it does indeed require more effort to breach. There is not much more to be said about these barriers as most of it comes down to budget and preference. There are multiple building materials in today's world and great new advances and techniques are developed across the world.

How strong is your first barrier?

Home defense

Reaction unit

Reaction unit

For every situation that can occur, it will always be the best option to have an external reaction force to assist. This does not have to be an armed response company, as your local policing service might even be more efficient, and that will strongly depend on your specific country and location. This can even be a community policing project in your area with which you can have constant contact. At no point in any situation will I suggest that anyone as the man/protector of the home go out into danger to try and approach the threat. One great reason for this is that your family will be more vulnerable than ever when you are taken out of the equation.

The main purpose of a reaction unit is to scare off or possibly even arrest the invader/s. Any reaction unit you choose should be able to face the types of emergencies that you will most likely encounter. Whatever reaction unit you choose should generally comply with the following aspects:

When it’s your local police service:

  • You need them to react as fast as possible, but please keep in mind that at any given moment they might be busy with more calls than they can handle or anything that requires more attention than normal and this will greatly influence their response times.
  • Research and ask around about your local police service, what is their average response times, are they equipped for the job? Do they act professionally?

When you are looking at hiring a professional service:

  • The company should be registered with the relevant authorities of your country.
  • The company should comply with all the relevant laws on the service they are providing and the laws implemented by your country in regards to using firearms or lethal weapons used by the company.
  • The response personnel should be trained appropriately.
  • The company should have a reputable name, you don’t want a fly-by-night company to come to the rescue in your moment of need.
  • The company should regularly send their response personnel for updated training.
  • Preferably you want a company that wants to instruct you on their expertise and not one who wants to know what you prefer to have unless both agree on the same input. Once a company wants to know what you prefer, you need a more professional company. (You never hire an expert just to tell them what to do, because then you didn’t need them in the first place).
  • The company should have enough infrastructure to be able to respond to all their clients.
  • Price, of course, plays a great role, don’t settle for the cheapest and don’t expect the most expensive ones to be the best in the industry.

If you are considering utilizing your neighborhood watch or community policing service:

  • You need a community that is big enough to have someone on standby or constantly out on patrol, who can react immediately.
  • They should not try and be the Rambo’s of town, they have no more power or authority than any natural person do.
  • They don’t necessarily care about you, they care more about getting a piece of the action.
  • They will have to wait for professional assistance when there is a real threat.

How strong is your reaction unit?