A U S T R A L A S I A’ S L E A D I N G S E C U R I T Y R E S O U R C E F O R B U S I N E S S A N D G O V E R N M E N T
ISSUE #101 MAY/JUN 2016
ISSN 1833 0215
WILL POPULARITY TRUMP SECURITY?
$9.95 inc GST / $10.95 NZ
I DON’T WANT YOU
intelligent storage the creone keybox is a new solution for management of valuables & keys. absolute control easy to use With the Creone KeyBox range you will have complete control over your keys and valuables. Whatever your requirements you can choose a basic or more advanced solution.
There is one important requirement when it comes to storage systems that are used by a number of different people: the easier to use, the better.
Creone offer everything from key cabinets and value boxes that will meet your basic needs to advanced systems that monitor every single key and user.
Creone intelligent technology automatically keeps things in good order, and thanks to the user-friendly software, it is easy for the administrator to monitor key use and control.
Total flexibility
Key Features
Creone KeyBox systems are flexible, which makes it easy for you to adapt your system when your needs change. Start with a solution that is suitable for your current needs, and expand it as your needs grow. Your storage solutions are future-proof when you invest in a Creone KeyBox to manage your keys and valuables.
• A simple and flexible solution • Over 40 different models and styles available • Easily expandable • Intuitive management software • Made in Sweden
visit us at...
Visit lsc.com.au/creone for more information.
Creone develop intelligent storage systems. They have being doing this since they started in 1979, and today supply solutions to companies in 30 countries. Creone have three keywords for their storage solutions; Control, Flexibility and User-Friendliness. Whatever your needs, they have a solution you can offer with security and good order – both today and in the future.
A Solution to Suit Creone’s extensive KeyBox range will offer storage solutions to a variety of industries.
Pharmacies
Banks
Car dealerships
Shops
Hotels & Hostels
Offices
Police
Taxis
Aged care facilities
CONTENTS101
COVER STORY: IF POPULARITY TRUMPS SECURITY
058
034
What if US presidential candidate Donald Trump continued to defy all expectations and was elected to be the 45th President of the US? According to the Economist Intelligence Unit, the election of Trump could be one of the top 10 greatest risks to global stability. Colin Wight, Professor of Government and International Relations at The University of Sydney, looks at what kind of foreign policy we might expect from Trump and the security implications of that policy.
THE LETHAL COCKTAIL OF TERRORISM: THE FOUR NECESSARY INGREDIENTS – PART ONE In the first of a special two-part series, international terrorism expert and researcher Dr Anne Speckard looks at the four main factors instrumental in driving potential recruits into terrorist organisations.
076
CRISIS MANAGEMENT PLANNING Paris, Brussels, Sydney, Boston and Parramatta all provide examples of where local businesses were caught up in bombings or shootings. Do you have a crisis management plan? When was it last updated? Don Williams looks at pertinent points of crisis management planning.
092
EFFECTIVE SECURITY LEADERSHIP Gone are the days of guns, guards and gates. Today’s security professionals are expected to be business professionals alongside HR, finance and operations. To achieve this, you must first be an effective leader. Jason Brown looks at some real-life examples of effective leaders and the lessons they can teach security professionals.
096
2016 TRENDS IN ACCESS CONTROL Blake Kozak of the internationally renowned market research group IHS looks at the emerging trends in access control for 2016–17.
002 SECURITY SOLUTIONS
SECURITY SOLUTIONS 003
CONTENTS101 008
LETTER FROM THE EDITOR
010
BRIGHT IDEAS
026 LEGAL What happens when we fail to act on the risk of terrorism? 028
THINKING ABOUT SECURITY When the risk is identified and the incident has occurred, who is responsible for managing the consequences?
012 CRIMINAL ODDITY It should be called “What not to do to end up in this section”, but alas, we find a special home for those who are met with odd criminal situations and a lack of intellect.
030 EVENTS A look at upcoming industry events. 040 ALARMS Why do we still need to be fingerprinted and hold licences
014 LEADERSHIP How does culture impact strategy? 016
CYBER SECURITY How can you address the need for greater awareness of advanced persistent threats amongst company staff?
018 RESILIENCE How can you apply resilience in a security context? 020
HUMAN RESOURCES What are the dangers of casual employees in the
in every state of Australia?
044
OPERATIONS Richard Kay looks at the reality of phone cameras in the age of social media.
048 CCTV What is HVEC? 054
BUSINESS What are the little things that can have a major impact
on the success of your security business?
070
LEGAL Q&A How does social media impact workplace bullying?
072
LOSS PREVENTION How can you achieve loss prevention on a budget?
security industry?
022 RISK MANAGEMENT Dr Kevin Foster explores a new risk assessment standard for security and operations.
024 COMMUNICATIONS Why do we need to make more noise as an
080 AVIATION Steve Lawson looks at the need to think differently about airport security following the recent Brussels attacks.
industry?
034
076
084 ACCESS CONTROL Can the traditional access token survive the Internet of
092
102
SPOTLIGHTS
110
PRODUCT SHOWCASES
114
SHOPTALK Company announcements from within the industry.
Things?
088
PROFESSIONAL DEVELOPMENT How well do you understand the cues to
deceptive behaviour?
100
SECURITY STUFF
004 SECURITY SOLUTIONS
SECURITY SOLUTIONS 005
www.securitysolutionsmagazine.com
Editorial Editor: John Bigelow john@interactivemediasolutions.com.au Sub-Editing: Helen Sist, Ged McMahon
Contributors: Jason Brown, Gary Barnes, Rita Parker, Greg Byrne, Kevin Foster, Rod Cowan, Tony Zalewski, Don Williams, Richard Kay, Anna Richards, Darren Egan, Steve Lawson, Jonathan Johnson, Bob Ansett, Brett McCall, Vlado Damjanovski, Ray Hodge, Colin Wight, Liz Corbett, Blake Kozak.
Advertising rdias@interactivemediasolutions.com.au Phone: 1300 300 552 Publication Co-Ordinator: Ranjit Dias
Marketing & Subscriptions admin@interactivemediasolutions.com.au $62.00 AUD inside Aust. (6 Issues) $124.00 AUD outside Aust. (6 Issues)
Design & Production Graphic Design: Jamieson Gross graphics@interactivemediasolutions.com.au Phone: 1300 300 552
Accounts accounts@interactivemediasolutions.com.au Phone: 1300 300 552
Publisher
Interactive Media Solutions ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au Disclaimer The publisher takes due care in the preparation of this magazine and takes all reasonable precautions and makes all reasonable effort to ensure the accuracy of material contained in this publication, but is not liable for any mistake, misprint or omission. The publisher does not assume any responsibility or liability for any loss or damage which may result from any inaccuracy or omission in this publication, or from the use of information contained herein. The publisher makes no warranty, express or implied with respect to any of the material contained herein. The contents of this magazine may not be reproduced in ANY form in whole OR in part without WRITTEN permission from the publisher. Reproduction includes copying, photocopying, translation or reduced to any electronic medium or machine-readable form.
RS A DE VI
SSOCIATI
ON
ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au
O
SECURIT Y
PR
RALIA LTD UST FA
O
Written Correspondence to:
Or i g i n a l Si z e
O C I AT I
ON
Y P R OVI D
RIT
CU
D LT
SE
PR O
ASS
SPAAL
AU S T R A L I A
STRALIA LTD AU
SECURITY
RS
OF
E
Official partners with:
SSOCIAT IO N
OF
RS A DE VI
blue colour changed to this colour green.
COPY/ARTWORK/TYPESETTING APPROVAL Please proof read carefully ALL of this copy/artwork/typesetting material BEFORE signing your approval to print. Please pay special attention to spelling, punctuation, dates, times, telephone numbers, addresses etc, as well as layout.It is your responsibility to bring to our attention any corrections. Minuteman Press assumes no responsibility for errors after a proof has been authorised to print and print re-runs will be at your cost. Signed.................................................................. Date........................
006 SECURITY SOLUTIONS
AME System produces its customisable ActivConsole range of electric height adjustable and fixed height control room consoles from their local design studio and manufacturing facility in southeast Melbourne, Australia. The ActivConsole range has revolutionised control rooms throughout Australia and worldwide, introducing state-of-the-art ergonomic technology into a 24/7 monitoring environment. Able to be customised to suit any application, the ActivConsole plays
a vital part in keeping your workplace and employees healthy and productive. By utilising new modern production methods and combining them with high quality materials and finishes, the ActivConsole range continues to adapt to new technologies and trends, ensuring unparalleled versitility and flexibility in every design. Customising ergonomic solutions for over 20 years, we continually ensure safety and quality for a whole new generation of operators. Contact us now for a tailored solution.
SECURITY SOLUTIONS 007
LETTER FROM THE EDITOR For generations, Australia has been referred to as the lucky country. This description has been bestowed upon Australia for a multitude of reasons, including but not limited to our beautiful, wide open country and pristine beaches, our amazing mineral wealth and abundance of natural resources, our quality of living and prospering cities – but more recently, the lack of a Brussels or Paris-type terrorist attack. And while it is true that we have been very fortunate to date, I do not think it is fair to say that we have been lucky. Undoubtedly, luck has played a small role, but I believe most of the credit should go to our intelligence and law enforcement agencies, as well as the Muslim community itself. I recently wrote a piece in which I stated that blaming the Islamic faith for terrorism is akin to blaming fast food advertising for the obesity epidemic. I stand by this comment. That said, I am not so naïve as to believe that all Islamic leaders within Australia are supportive of Australia’s involvement in recent conflicts. That not withstanding, we achieve nothing by further demonising Islam and refugees or immigrants to Australia. In fact, we only make it easier for people preaching hate and dissent to perpetuate such nonsense. Untangling the complex and incredibly intricate problem of terrorism in the modern context is not something that can be done in a day, week, month or even a year. It will take years and will be something that, in my opinion, our children’s children might finally overcome. But one thing is for sure; we cannot solve the problem with an ‘us and them’ mentality, which is why this issue’s cover story looks at the possible security implications of Donald Trump being elected as the next US president. We have already seen and heard Trump talk on numerous occasions about banning all Muslims from the US; deporting Muslims already living in the US; building a wall between the US and Mexico and other such outlandish, headline-grabbing propaganda. Now Trump has expressed reservations about the security alliance between the US and Japan and suggested that perhaps the best way to secure peace in the Asia Pacific region would be to encourage Japan and South Korea to develop a nuclear arsenal of their own with a view to keeping China and North Korea at bay. Colin Wight, a professor in the Department of Government and International Relations at The University of Sydney, has drawn on his extensive understanding of both international relations and terrorism to provide an overview of what he believes might be the likely challenges arising from the US moving forward. That said, regardless of what happens in the US, we cannot hope to be the lucky country forever. We need to do all we can to strengthen ties to the Islamic community in Australia, not erode the relationship. The Australian Islamic community has traditionally been something of an early warning system in so far as it provides information about people making the kind of noise that might lead to a potential problem. By alienating that community, I truly believe we erode our ability to detect, deter and prevent incidents.
John Bigelow Editor
008 SECURITY SOLUTIONS
GAIN CONTROL WITH ONEVIEW Defuse situations quicker with a truly unified security control room solution Saab’s OneView is a next-generation physical security information management integration platform that provides unprecedented levels of subsystem integration in mission-critical infrastructure environments. OneView empowers operators to respond effectively and efficiently to the most stressful situations. Offering accurate intuitive situation awareness, a simple operator interface, fast detection-response and comprehensive support for post action analysis, OneView is the ultimate choice for modern surveillance and security operations. You can rely on Saab’s thinking edge to bring your control room under real control. saab.com/australia
REGULAR
BRIGHT IDEAS Mining Everyday Technologies To Anticipate Possibilities
DARPA’s ‘Improv’ effort asks the innovation community to identify commercial products and processes that could yield unanticipated threats. For decades, US national security was ensured in large part by a simple advantage: a nearmonopoly on access to the most advanced technologies. Increasingly, however, offthe-shelf equipment developed for the transportation, construction, agricultural and other commercial sectors features highly sophisticated components, which resourceful adversaries can modify or combine to create novel and unanticipated security threats. To assess this growing security challenge and identify specific potential risks, a new Defense Advanced Research Projects Agency (DARPA) effort will ask experts across multiple disciplines to look at today’s bustling tech marketplace with an inventor’s eye and imagine how easily purchased, relatively benign technologies might be converted into serious security threats. The endeavour is dubbed ‘Improv’, an abbreviated reference to the potential for improvising with widely available technology to create new and unanticipated risks.
010 SECURITY SOLUTIONS
“DARPA’s mission is to create strategic surprise, and the agency primarily does so by pursuing radically innovative and even seemingly impossible technologies,” said program manager John Main, who will oversee the new effort. “Improv is being launched in recognition that strategic surprise can also come from more familiar technologies, adapted and applied in novel ways.” Improv will explore ways to combine or convert commercially available products such as off-the-shelf electronics, components created through rapid prototyping, and open-source code to cost-effectively create sophisticated military technologies and capabilities. To bring a broad range of perspectives to bear, DARPA is inviting engineers, biologists, information technologists and others from the full spectrum of technical disciplines – including credentialed professionals and skilled hobbyists – to show how easily accessed hardware, software, processes and methods might be used to create products or systems that could pose a future threat. DARPA will assess candidate ideas and offer varying levels of support to develop and test selected proposals. The emphasis will
be on speed and economy, with the goal of propelling winning submissions from concept to simple working prototypes within about 90 days. “DARPA often looks at the world from the point of view of our potential adversaries to predict what they might do with available technology,” Main said. “Historically, we did this by pulling together a small group of technical experts, but the easy availability in today’s world of an enormous range of powerful technologies means that any group of experts only covers a small slice of the available possibilities. In Improv, we are reaching out to the full range of technical experts to involve them in a critical national security issue.” DARPA intends to fund selected Improv proposals through a short feasibility-study phase, during which performers will refine their ideas and compete for the opportunity to build prototypes. DARPA will evaluate the results of that work and a subset of the prototypes will proceed to a detailed evaluation regimen. If performance warrants, DARPA may advance the relevant capabilities in separate follow-on efforts.
SECURITY SOLUTIONS 011
REGULAR
CRIMINAL ODDITY
Making A Clean Getaway Anyone who has ever had their home broken into knows the horrible feeling of coming home and finding one’s possessions scattered all over the floor – minus the things that were taken. Now, imagine coming home and finding that, instead, the house had been broken into and someone had cleaned up. I have known a few people in my time to whom I may have been tempted to do this to. It may sound ridiculous but according to a report in the Huffington Post, a woman in Indiana of The United States came home from a night out only to find a man had broken into her apartment, swept her floors, folded her clothes and then started to cook a meal of chicken and onions. According to reports, when confronted, the offender refused to leave the apartment even after police had been called. Police arrived a short time later and arrested the offender who claimed that he thought it was his apartment and that he lived there. I don’t know about you, but I am fairly sure that I would know if I was folding someone else’s clothes. I am also pretty sure that if I
012 SECURITY SOLUTIONS
had to kick the door in because my key didn’t fit the door lock, I might realise I was in the wrong apartment.
A Short Story Every cloud has a silver lining – so the saying goes. Therefore, it stands to reason that the silver lining in the cloud of the criminally stupid is that, so long as no one is injured or permanently deprived of assets in the course of their antics, they keep the rest of us amused. Sometimes we laugh at them. Sometimes we laugh with… no, hang on, we just laugh at them. Take for example, 43-yearold Eli Escaldera of Stock Island in The United States. Mr Escaldera wanted money. He wanted money quickly. So, he walked into a bank in the Florida Keys and passed the teller a note which, according to Miami New Times, read, “Give me what are 20’s and 50’s.” Now, if you are having trouble understanding the note, never fear, so did I when I first read about it and, apparently, so did the bank teller – who was further confused by the fact that Mr
Escaldera appeared to be wearing his shorts on his head… Yes, according to the story, and the accompanying images, Mr Escaldera had decided that the best way to disguise his identity was to wear a pair of shorts, on his head. Because that’s what I do when I want to remain inconspicuous and anonymous. According to a report by Monroe County Sheriff’s Officers, when the bank teller confronted Mr Escaldera, asking him in a somewhat confused and bewildered tone of voice “is this a bank robbery?”, Mr Escaldera simply mumbled “never mind” and walked away. According to the report, the teller informed his manager of the incident, who then informed police, who found Mr Escaldera only a few blocks from the bank, attempting to get away on his pushbike. In Mr Escaldera’s defence, the police had an unfair advantage given that there probably were not too many Hispanic men wearing a blue shirt, dark cargos and shorts on their head in the area. So many questions, so few answers.
OFFICE BUILDINGS WAREHOUSES DAY CARE CENTERS HOSPITALS SCHOOLS ACCOMMODATION & HOSTELS RETAILSTORES AIRPORTS GYMS SMALL BUSINESSES PROPERTIES
Triview CCTV, We’ve got “YOUR” solution Covered ! WHY TRIVIEW VISION? WE STRIVE TO PROVIDE OUR CUSTOMERS WITH HIGH QUALITY FULL HD 1080P PRODUCTS AT AN AFFORDABLE PRICE. OUR PRODUCTS ARE BACKED UP BY OUR TECHNICAL KNOW HOW AND FOCUS ON CUSTOMER SERVICE AND SATISFACTION.
w w w . t r i v i e w . c o m . a u For more information contact Nidac Security
T: 03 9808 6244
THE EXCLUSIVE DISTRIBUTOR OF
E: sales@nidac.com CCTV PRODUCTS
SECURITY SOLUTIONS 013
REGULAR
LEADERSHIP Seizing The Moment By Bob Ansett
In an interview about his military career, Australian Victoria Cross winner Corporal Ben Roberts-Smith noted that “culture trumps strategy every time”. It was a phrase I had not previously heard but, after thinking about it, I realised how right he was. Having placed so much emphasis on building and maintaining a powerful culture within my business over the years, it truly resonated, even though I had never thought of it in those terms. But realistically, whether it is a business, or the military, a security department or government, to effectively develop a strategy there must first be in place a culture capable of implementing the strategy. Intuitively, good leaders know their first task when taking on a leadership role is to determine the quality of the existing culture within the organisation they are about to lead. If it is weak or fragmented, it has to be repaired or rebuilt from scratch before new objectives can be launched. I had the good fortune to start my business from scratch, so I was able to create rather than change a culture. This enabled me to put my personal imprimatur on every aspect of the business from day one. I focused on teamwork driven by a ‘can-do’ attitude, always putting the customer first (which in the case of a security department might be the other departments within the organisation), thus running the business to suit the customer, not employees. No matter how difficult the task might be, it was embraced with energy, enthusiasm and good humour. The foundation for this culture was an environment where everyone worked hard to make the job as interesting and satisfying as possible. Four basic rules were employed that
014 SECURITY SOLUTIONS
management were expected to implement and maintain, as they wanted employees to really look forward to coming to work each morning: 1. Ensure employees (team members) got satisfaction out of their day’s work. 2. Employees were to be recognised for their work ethic. (This could be a pat on the back or something more substantial if appropriate.) 3. Constant reinforcement of the team principal, ‘all for one and one for all’. 4. To make it as much fun as possible by celebrating successes and then setting higher goals. In time, this environment morphed into a very powerful culture where expectations of one another grew exponentially to the point everyone was ‘match fit’ and truly believed they could achieve any realistic objective. Leadership is the key element in building positive cultures or changing them within organisations. The latter is clearly more difficult than the former, but nevertheless doable through leading by example with that can-do spirit. Unfortunately, courageous leaders in business these days are in short supply. Industrial relation laws have dumbed down the entrepreneurial spirit in organisations. Rampant fear has sent many business cultures into a downward spiral. Workplace stress is at its highest level in many years as workers fear for their jobs. So these times call for strong, courageous leaders prepared to take risks and focus on improving every aspect of their business in preparation for the economic upturn that will inevitably arrive. But it is not easy, even with a strong can-do
culture within the organisation. It calls for bold confident leadership applying all the basic traits of leadership. Start with a clear concise message outlining the plan and the way in which it will be implemented. Set the example by always doing the right thing even when no one is watching. Take personal responsibility for all that goes on, never go it alone and, most importantly, be fearless. Shakespeare wrote, “Some are born great, some achieve greatness and others have greatness thrust upon them.” Perhaps in the case of Ben Roberts-Smith, greatness was thrust upon him, but he seized it with all his might. His Victoria Cross citation records he showed conspicuous gallantry under enemy fire. With members of his patrol pinned down by enemy machine gun fire, Corporal Roberts-Smith exposed his own position in order to draw enemy fire away from his patrol. Then, with total disregard for his own safety, he stormed the enemy position, killing the two machine gunners. Leadership is all about seizing the moment.
Bob Ansett is the founder of Bob Ansett Marketing, a consulting firm in the field of customer service. Bob is also a familiar name in Australian business, synonymous with Budget Rent a Car, which he established in 1965. Bob can be contacted at bob@bobansett.com.au
THE ALL-NEW TXF-125E BATTERY OPERATED QUAD BEAM Introducing the eagerly anticipated TXF-125E; a high performance Quad Beam sensor designed for battery operation - perfectly suited for rapid deployment in creating temporary or permanent secure perimeter intruder systems. With 4 selectable frequencies, multiple beam sets can be used without crosstalk, whilst adjustable detection distance allows a single beam set to be re-deployed in a variety of installations throughout its operational life. Two 3.6V (17Ah) batteries power each unit for up to 5 years of service, and integrated wireless transmitter battery sharing provides a customisable low-battery warning notification output.
NEW!
ACTIVE IR BEAMS The ultimate in trouble free perimeter detection for distances up to 200m outdoor / 400m indoor.
+61 (3) 9544 2477
email: oz_sales@takex.com
HIGH-MOUNT PIR Triple mirror optics for maximum detection performance at 2 to 6m.
BEAM TOWERS Rugged floor and wall mounted enclosures in 1/1.5/2/3m heights.
INDOOR PIR Spot, 360°, wide angle, and curtain detection from 2 to 4.9m height.
OUTDOOR PIR Hard-wired or battery operated outdoor PIR up to 180° x 12m.
TAKEX AMERICA www.takex.com
SECURITY SOLUTIONS 015
REGULAR
CYBER SECURITY Advanced Persistent Threats
Addressing The Growing Need For APT Awareness By Garry Barnes Advanced persistent threats (APTs) continue to enjoy the spotlight in the wake of their successful use to launch several high-profile data breaches. Every year, the damage and costs related to cyberattacks multiply at a shocking rate. Cybercriminals continue to exploit individuals and enterprises while increasing profits from more than US $300 billion in 2012 to an estimated US $1 trillion in 2014. Juniper Research has predicted that profits will top US $2 trillion in 2019. Major cyberattacks targeting financial, retail, healthcare, government and the entertainment industries have resulted in the stealing of sensitive data, exposed records and money, with billions spent on remediation and with significant damage to many brands. Opinions differ on what makes a threat an APT. Some state that APT is just a marketing term; others believe there is no difference between an APT and a traditional threat; yet others say that an APT is a nation-statesponsored activity that is geared toward political espionage. This article adopts ISACA’s definition of APTs – they are prolonged, stealthy attacks aimed at the theft of intellectual property (espionage) as opposed to achieving immediate financial gain. APTs also employ different attack methodologies and display different characteristics from those evidenced by traditional threats. Furthermore, as technology changes and information security tools evolve, so too do the tactics, techniques and procedures of threat actors. Social engineering remains at the centre of APT activity to gain footholds into information systems. Early APT efforts began with phishing, often involving an attachment or a link that contained malware or an exploit. However, over the past three years, APTs have moved on to the Internet as the main attack vector (for example, websites,
016 SECURITY SOLUTIONS
social media and mobile applications). Despite the damaging nature of APTs, a gap in the understanding of what they are and how to defend against them remains. A 2015 ISACA study designed to uncover information security professionals’ understanding and opinions of APTs, revealed that 67 percent of the respondents believe that they are ready to respond to APT attacks to some degree, representing a decrease from 2014’s statistic of 74 percent. It is evident that efforts to stay ahead of cybercriminals and APTs are not being aided due to advances in technology, coupled with the existing skills gap in the information security workforce. Of the ISACA survey respondents who categorised their enterprises as ‘not very likely’ targets of an APT, only 48 percent reported feeling prepared for an attack to some extent. The data indicates that enterprises have not really changed the ways in which they protect against APTs. The technical controls most often cited as being used to prevent APTs are network perimeter technologies such as firewalls and access lists within routers, as well as anti-malware and antivirus. While these controls are proficient for defending against traditional attacks, they are not as well suited for preventing APTs because APTs exploit zero-day threats, which leverage unknown vulnerabilities, and many APTs enter the enterprise through well-designed spear phishing attacks. This indicates that different types of controls – an increased focus on email security and user education – could benefit an enterprise immensely. With that said, the survey reveals that there is a strong correlation between the perceived likelihood of an APT attack on the enterprise and the enterprise’s adoption of improved cybersecurity practices. In almost all cases, the
higher the perceived likelihood of becoming a target, the more consideration is being given to APTs in terms of technology, awareness training, vendor management, incident management and increased attention from executives. This activity and corresponding effort form an excellent base for information protection. Yet not all avenues for APT intrusion are fully locked down. Mobile device security is lagging, despite acknowledgment that the bring your own device (BYOD) trend increases APT risk, and a preference is seen for technical controls over education and training, even though many successful APT attacks gain entry by manipulating individuals’ innate trust and/or lack of understanding. Enterprises and governments need to be continually vigilant and ensure they are well staffed and trained to deal with these everchanging threats. ISACA recently established Cybersecurity Nexus (CSX) to help enterprises take a skills-based approach to cybersecurity workforce development. It is critical for all staff to receive cybersecurity training, and for cybersecurity teams to receive continuous development that focuses on building their capability to protect and defend against these insidious attacks.
Garry Barnes is practice lead, Governance Advisory at Vital Interacts (Australia). He has more than 20 years of experience in information and IT security, IT audit and risk management and governance, having worked in a number of NSW public sector agencies and in banking and consulting. The above article is based on ISACA’s 2015 Advanced Persistent Threat Awareness Report. For a more detailed analysis of the report, go to http://www.isaca.org/apt-wp
SECURITY SOLUTIONS 017
REGULAR
RESILIENCE Resilience And Identifying Potential Disruptions By Dr Rita Parker As noted in the previous article in this column, definitions of the concept of resilience vary within different disciplines and sectors, such as critical infrastructure, homeland security and emergency, and disaster management response. However, the common characteristics of adaptability, transformation and flexibility appear generally consistent. While resilience has been described as “the capacity for complex systems to survive, adapt, evolve and grow in the face of turbulent change” (US Council of Competitiveness, 2006), by extending this description, it is possible to extrapolate that resilience is a counter to insecurity. In this extended context, resilience addresses unknown future challenges and uncertainty; that is, the inability to know what combination of conditions will occur in the future. If the future were predictable, resilience would lose its importance because all planning would be based on a known set of conditions. But because the future is unpredictable, it is necessary to plan for a wide range of possible conditions and outcomes, including some which may be unlikely but could result in significant harm if they are not anticipated. To apply the resilience concept it needs to be considered in a specific context; that is, who or what needs to be made resilient to whom or what threat or risk. This is where the role of security professionals can contribute to achieving resilience in an organisation. Within the context of a business or a corporation, resilience means having the capability and skills to adapt quickly to disruptions while safeguarding people, assets and reputation and while maintaining business operations. This is directly linked to the security of those people, assets and resources. Not all personnel or resources will be essential to maintain an organisation’s functions or
018 SECURITY SOLUTIONS
Whatever approach is used [to detect risks and threats], the results need to be constantly reviewed because internal and external factors change. critical services during a disruption. Security professionals are well placed to assist and to advise C-Suite executives to identify which assets and resources would be essential and therefore need to be made resilient, as well as identifying essential personnel. To do this requires defining what functions, elements or systems are critical and, therefore, need to be resilient to changes that may lead to disruption. Keep in mind that an organisation is an interconnected system composed of many different components that form different system levels. This means that an organisation can be resilient at some of the levels but not necessarily at others, meaning other parts of the organisation can be vulnerable. Resilience is similar to vulnerability in that it cannot simply be measured in a single metric; its importance lies in the ultimate multi-dimensional outputs (the consequences) of the system for any specific inputs (risks and threats). Detecting those risks and threats is a constant challenge. Different organisations use different processes and types of analysis to identify future potential disruptions. Some organisations do this by using trends analysis, which is a simple approach based on historical events and data to project into the future. The problem with this
approach is that it assumes past events are likely or may recur, and it assumes an absence of unprecedented future events. Other organisations use a process of horizon scanning to detect early signs of potentially important developments that may lead to disruptions. It does this by determining what is constant, what changes and what constantly changes both inside and outside the organisation. This approach enables identification of unexpected issues as well as identification of persistent trends and problems that may be potential risks or threats that contribute to or cause a disruption. Whatever approach is used, the results need to be constantly reviewed because internal and external factors change. This means that a simple tick-the-box approach cannot be used to achieve resilience. Dr Rita Parker is a consultant advisor to organisations seeking to increase their corporate and organisational resilience and crisis management ability. She is an adjunct lecturer at the University of New South Wales at the Australian Defence Force Academy campus where she lectures on resilience and nontraditional challenges to security from non-state actors and arising from non-human sources. Dr Parker is also a Distinguished Fellow at the Center for Infrastructure Protection at George Mason University Law School, Virginia, USA. She is a former senior advisor to Australian federal and state governments in the area of resilience and security. Dr Parker’s work and research has been published in peer reviewed journals and as chapters in books in Australia, Malaysia, the United States, Singapore and Germany and presented and national and international conferences. Rita holds a PhD, MBA, Grad. Dip., BA, and a Security Risk Management Diploma.
For over 30 years Perimeter Systems Australia has been delivering Perimeter Intrusion Detection Systems (PIDS) to Critical Infrastructure, Government, Industrial and large Commercial customers.
High end detection with minimal false alarms NE W !
Passive Infrared & Microwave Intrusion Protection False Alarm Free performance and lowest nuisance alarm rate possible.
The only outdoor motion sensors that really works!
Electronic Taut Wire Fence System • • • •
Utilises very reliable strain gauge technology Software sensitivity adjustment Each sensor can be adjusted separately Very reliable and difficult to defeat
Don’t forget, we also have competitive pricing on Takex products. Call for a quote today!
Palmgrove Business Park, D413-15 Forrester St. Kingsgrove NSW info@perimetersystems.com.au | www.perimetersystems.com.au
Call us on (02) 9150 0651 or visit www.perimetersystems.com.au SECURITY SOLUTIONS 019
REGULAR
HUMAN RESOURSES Legislative Requirements For Australian Employers This edition’s column details the industrial and employment legislative requirements of all employers in Australia. This flows on from last edition’s column that outlined what casual employment and sham contracting is. The intent of the first three or four columns is to work through the human resource issues as they are for the security industry in Australia and the potential risks they pose. Next edition’s column will discuss how relevant the requirements, as discussed here, are to the security industry in Australia and the level of risk posed by non-compliance. All businesses in Australia with employees are required to comply with the Fair Work Act 2009 (Cth) and the Fair Work Regulations 2009 (Cth). These regulations affect all employee/employer relationships in Australia and are designed to provide a safety net of minimum standards, flexible working arrangements and to prevent discrimination against employees. Under provisions of the Fair Work (State Referral and Consequential and Other Amendments) Act 2009 (Cth) and the Fair Work Amendment (State Referrals and Other Measures) Act 2009 (Cth), the states are able to refer matters to the Australian Federal Government to form a national workplace relations system. Before this, workplace laws were set and administered by most individual states. States kept their workplace relations powers over state and local government employees. In addition to the legislative requirements of employment, all businesses in Australia (with employees) are required to comply with the National Employment Standard (NES). The NES is a document detailing the 10 minimum employment entitlements that must be provided to all employees. An award, employment contract, enterprise agreement or other registered agreement cannot provide for conditions that are less than the national minimum wage or the NES. The 10 minimum entitlements of the NES are: • Maximum weekly hours No employee in Australia can be directed to work more than 38 hours per week. The spread of
020 SECURITY SOLUTIONS
hours is 7am to 7pm, meaning any hours worked outside those hours can attract penalty rates. • Requests for flexible working arrangements Employees (including casuals) who have worked for an employee for more than 12 months have the right to request flexible working arrangements. The conditions of the request are that they are: a parent and need special consideration to care for children, older than 55 years, a carer under the Carer Recognition Act 2010 (Cth), and/or a victim of domestic violence. • Parental leave and related entitlements Parental leave is leave following the birth or the adoption of a child. Both the mother and father are entitled. Casuals who have a claim to regular ongoing employment are also entitled to parental leave. • Annual leave All employees (except casuals or those on leave without pay) are entitled to four weeks of annual leave per year. The accrual is at the rate of 2.923 hours per completed week of service (for full-time employees) and pro-rata for part-time employees. • Sick and carer’s leave, and compassionate leave All employees, apart from casuals, are entitled to sick and carer’s leave. Both entitlements come under the same entitlement, which is 10 days per year for full-time employees and pro-rata for parttime employees. All employees, including casuals, are entitled to two days of carer’s leave without pay per year; however, full-time and part-time employees are only entitled to avail themselves of unpaid leave if they do not have any sick days left. • Community service leave Employees are entitled to unpaid community service leave. There is no limit to the amount of leave that can be taken. • Long service leave Entitlements vary from state to state, but generally are accessible after seven years’ employment. • Public holidays Entitlements for public holidays vary from state to state. The salient points are employees’
entitlements are based on where they are based and not where they happen to be working at the time, and the manner in which the entitlement is satisfied is dependent on the particular award or workplace agreement. The accepted methods of payment or compensation are additional pay, days off, or time in lieu. • Notice of termination and redundancy pay This is the most controversial part of the current employment standards and will be addressed in more detail in later columns. The salient point is that, in most cases, certain periods of notice for termination (from both employee and employer) must be given. • Fair Work Information Statement All new employees must receive a copy of the Fair Work Information Statement as soon as they start a new job. The statement provides information on conditions of employment including: o the National Employment Standards o modern awards o making agreements under the Fair Work Act o individual flexibility arrangements o freedom of association and workplace rights (general protections) o termination of employment o right of entry o the role of the Fair Work Ombudsman and the Fair Work Commission.
Greg Byrne is the Managing Director of Multisec Consultancy Pty Ltd. He also lectures part-time at the Western Sydney University where he teaches an under-grad diploma in policing as well as working as a sub-editor for the Australian Police Journal and serving as a member of the board of directors. He possesses a number of academic qualifications including; Master of Management, Diploma of HR, Grad Cert in Leadership and a Diploma a Security Risk Management. He can be contacted via email; greg@multisec.com.au. Also see www.multisec.com.au.
Series 400 is a fully welded 19” rack mount wall cabinet with heavy duty load carrying capabilities.
When you choose Australian made, you’re choosing more than quality and reliability, you’re choosing peace of mind.
DESIGNERS & MANUFACTURERS OF 19” RACK SYSTEMS
MFB’s range of innovative racking solutions is proudly made onshore, to ensure quality and consistency above all others. Backed by constant development, unsurpassed customer support and expedited delivery. MFB proves a solid project partner whatever your requirements. Australian made, makes Australia. With a solid history of over 45 years of supplying innovative, off-the-shelf and custom built racking systems, you can rely on MFB to ensure when you buy Australian, you’re investing and supporting Australian industry.
AUSTRALIAN MADE MAKES AUSTRALIA
www.mfb.com.au
VIC NSW -
P (03) 9801 1044 P (02) 9749 1922
F (03) 9801 1176 F (02) 9749 1987
E sales@mfb.com.au E sydney@mfb.com.au
SECURITY SOLUTIONS 021
REGULAR
RISK MANAGEMENT A New Risk Assessment Standard For Security And Operational Risk By Dr Kevin J. Foster Many organisations claim their risk management structures and processes comply with the International Standard on Risk Management Principles and Guidelines, ISO31000:2009. However, if risk assessments used by these ‘compliant’ organisations are poor, then risk management failures will almost certainly occur. If a security manager guesses that a risk is low, medium or high, then questions need to be raised about whether or not this is a suitable risk assessment. It is common for security managers to have only some of the information needed for a comprehensive assessment. However, information gaps may not be documented in the assessments provided to decision makers in management roles (who may not have security expertise), so the latter may be unaware that they are making important decisions without all of the pertinent information. Late in 2015, ASIS International and the Risk and Insurance Managers Society published a new American National Standard titled Risk Assessment. The standard is designated ANSI/ASIS/RIMS RA.1-2015. This attempts to provide guidance on how to establish and maintain a reliable risk assessment program. This new standard is intended to supplement ISO31000:2009 and provide more detailed guidance than the International Standard on Risk Assessment Techniques, ISO31010:2009. RA.1-2015 provides more operational advice than ISO31000 on the risk identification, risk analysis and risk evaluation processes needed to produce a reasonable risk assessment. Similar to ISO31000, this new standard utilises the PlanDo-Check-Act (PDCA) cyclic model: • The Plan stage of the assessment cycle defines and analyses threats, hazards and consequential
022 SECURITY SOLUTIONS
issues, and contexts. • The Do stage focuses on solving problems by developing a detailed action plan that is then systematically implemented. This may involve, for example, finding more information to fill a knowledge gap, or determining options to reduce risk or to increase opportunities. • The Check stage ensures quality control in the risk assessment process to make sure the assessment outcomes are in accordance with plans and, if necessary, initiates measures to rectify deviations from the plan. • The Act stage aims to standardise solutions and define new issues that need to be addressed in the Plan stage of the next cycle of the assessment. The risk assessment guidance provided by RA.1-2015 is structured in a way that makes sense to security practitioners and their managers. Firstly, the principles of risk assessment are explained. For example, the standard describes a risk assessment as “an effective tool for evaluating the organisation’s risk and resilience challenges and maturity, and to drive performance improvements. In addition, the risk assessment provides assurance to decision makers that the adopted risk- and resilience-based management system and risk management measures are achieving their intended objectives.” The standard explains the principles that need to be followed to achieve this. These include impartiality and objectivity, trust and due professional care, honest and fair representation, responsibility and authority, a consultative approach, a fact-based approach, confidentiality, change management, and continual improvement. Following the principles section of the standard is a description on managing a risk
assessment program. This goes into much more detail than ISO31000 and includes the roles and responsibilities of people who contribute to the risk assessment process. Note that the security manager should not perform all the roles on his or her own! The standard recognises that risks of strategic importance and complexity must be assessed differently to those that are routine, simple and frequent. The standard has a section on performing individual risk assessments across a portfolio of risk categories, including strategic, operations, financial and external. This section includes a number of analysis ideas, including the T4RA model that was first used by some Australian Government security analysts in the early 1990s. There are many good ideas in this section of the standard, including guidance on how best to assess the level of risk and how to present risk assessments to decision makers. Finally, there is a section on confirming the competence of risk assessors. There are also some appendices that provide additional information such as data gathering, ‘root cause analysis’, contents of a typical risk assessment report, document protection and business impact analysis. This risk assessment standard, ANSI/ASIS/ RIMS RA.1-2015, written by practitioners for practitioners, is well worth a read.
Dr Kevin J. Foster is the managing director of Foster Risk Management Pty Ltd, an Australian company that provides independent research aimed at finding better ways to manage risk for security and public safety, and improving our understanding of emerging threats from ‘intelligent’ technologies.
TM
SECURITY SOLUTIONS 023
REGULAR
COMMUNICATIONS Integrity Means Finding Ways To Speak Out By Rod Cowan Perth TV reports a vicious attack on a security guard trying to remove gatecrashers from a concert. Footage of teenagers kicking in the guard’s head while he lies on the ground is sickening. Sydney news reports that a security guard was attacked at a bar in Sydney’s CBD in the early hours of Australia Day – the guard was hospitalised with facial fractures and head injuries. When a patient almost killed a police officer and security guard, media talk turns to a “rise in violent assaults due to [the fact that] ICE is turning hospitals into battlegrounds” and a deepening “security crisis” in NSW hospitals. Outside a Sydney pub, a passer-by films a woman repeatedly slapping and racially abusing security officer Ali Hamam. The evidence is all there on video and played on the nightly news. No arrests though. The woman is allowed to go on her way. In that case, the media focused solely on the racist nature of the assault. Physical and verbal abuse, however, is a daily reality for security officers. Compared to all other Australian occupations, security is in the top three for work-related injuries and deaths from occupational violence, with security officers ranking number one in both instances. Missing from all of these reports and many others is a complete lack of outrage. At best, the Australian Security Industry Association Ltd (ASIAL) posts a media release
024 SECURITY SOLUTIONS
following what it calls a “spate of violent attacks against security officers”, including the stabbing of a 72-year-old security officer in Moss Vale and another being knocked unconscious in Padstow during an armed robbery. ASIAL responds that it is “encouraging all Governments to ensure that appropriate protections are in place to enable security officers to perform their duties”. Encouragement is what is offered to pre-schoolers learning to finger paint. When attacks, verbal abuse and attackers are allowed to go scot-free and to become business as usual, leadership demands strident calls for the government and the police to do their jobs, and to do them properly. If the industry is silent in the most heinous of circumstances, what chance is there of being taken seriously when it comes to, say, misuse of security funding or budget cuts? There are many cases of security being used as a blatant excuse to rip off the public, and plenty where lives are at stake because of continual cutbacks to a point where good luck plays a larger role than good management in keeping people safe. Admittedly, there was a time when access to the media was difficult and expensive. Today, however, media tools are readily available, and journalists are gagging for stories they do not have to work for, not to mention radio shows scrambling for material for their morning audiences. If ISIS can readily grab media attention by pumping out videos from a cave in Pakistan,
there is no excuse for security failing to make its views loud and clear. Maybe people do not care because they see security as a secondhand industry, taking the cast-offs of policing and intelligence, accepting people that could not get a job elsewhere, or retired cops and spooks supplementing their pensions. On the contrary, many people in the industry choose security as a career and see not only a future but also honour in protecting lives and property. Some argue that lack of time due to budget cuts leaves them overstretched. So, when it comes to bragging rights about dealing with their Board, it appears access is not the same as being listened to. Other managers, consultants and selfappointed industry representatives whine that they cannot speak in the media because of the brands they work for or people they represent. Maybe their superannuation is a higher priority than their obligation to lead. There it is, three reasons for silence: not caring, sloth or cowardice. But there is no reason the silence should continue, and every reason it should not.
Rod Cowan is a Contributing Editor to Security Solutions Magazine. He can be contacted via email mail@rodcowan.net
KeyWatcher is a reliable and extremely easy to use electronic key management system, designed to prevent mismanaged, misplaced, or stolen keys. KeyWatcher eliminates outdated metal boxes, unreliable manual logs and messy key identification tags utilising a computerised storage cabinet. The system releases keys only to the individuals with correct authorisation, recording each user transaction and providing total system accountability.
KEYWATCHER SYSTEM OFFERS to 14,400 keys and 10,000 user per site l “Site” concept uses a common database l Numerous high level interfaces for access control, contractor management and vehicle fleet systems l Longer user IDs can be up to any 6 digits, plus a 4 digit PIN l Bright 7” full colour, touch screen l “Key Anywhere” allows keys to be returned to any KeyWatcher Touch within a site l On-screen guides for users, along with voice commands l Up
Available in Australia through: AST Pty Ltd T: +61 2 8020 5555 | M: +61 417 089 608 | F: +61 2 9624 7194 E: di@astpl.com.au | www.astpl.com.au
SECURITY SOLUTIONS 025
REGULAR
LEGAL Failing To Act On The Risk Of Terrorism By Dr Tony Zalewski
Risks associated with a terrorist incident are should adopt reasonably practicable positive well reported within Australia and abroad. The action such as aligning with the considerations Australian Government raised its terror alert level listed under the National Guidelines For in 2014 from medium to high. In Protecting Critical Infrastructure CERTAIN 2015, a new National Terrorism From Terrorism. Threat Advisory System was Although the workplace may EXPECTED launched that replaced the not be part of the sector for critical previous four-step approach to infrastructure, the guideline a scale of five levels. still provides some relevant PROBABLE The new scale provides considerations in the context of public advice about the work. For example, there should be POSSIBLE likelihood of a terrorist act a general review of the system for occurring in Australia. This workplace security and safety as it NOT EXPECTED public advice will also enable relates to: authorities, businesses and individuals to take • staff and contractors, so they are aware of the appropriate measures to minimise security- and increased risk and measures being implemented safety-related risks as part of their preparedness • control of people and property on-site through and response planning. Of course, such public use of staff and visitor identification and inspection advice should also allow employers such as of property such as parcels prior to entering a site security leaders to ensure an appropriate level or designated area of precaution and vigilance is maintained across • staff awareness to increase the likelihood of their workplace. detecting suspicious people, items and vehicles There are various guidelines to assist employers in and around the workplace to respond to changing levels within the National • perimeter protection to increase the effort of a Terrorism Threat Advisory System. For example, perimeter breach and the risk of an early breach the current level is ‘Probable’ and the National detection Guidelines For Protecting Critical Infrastructure • liaison or communication with local emergency From Terrorism (2015) list 11 considerations in services seeking advice about local issues response. • emergency preparedness and business As discussed in the previous article in this continuity planning column, employers and those responsible for • protocols to ensure they remain adequate to workplace safety and security owe a duty of care assist and guide staff in terms of proactive and under common law. A duty of care is a legal reactive measures, including the issues outlined obligation imposed that requires adherence to a above. standard of reasonable care that could foreseeably Prudent organisations have also reviewed harm others. In the context of this article, one their current insurance protections to ensure would consider that an employer or person there is adequate coverage should a terrorist responsible for workplace safety and security incident occur. In some cases, it has been
026 SECURITY SOLUTIONS
determined that nuclear, biological, chemical or radiological terrorist events are excluded, hence the importance of a policy review. A relevant case, although outside the jurisdiction, disclosed risks with failing to act. The case arose from a carpark bombing incident in which six people were killed. The New York State Supreme Court (2005) found the local Port Authority had failed to heed warnings based upon the 9/11 attacks to close or substantially improve its carpark security. The costs were an estimated US$2 billion in claims. As the risk of a terror-related event is well known, it is important that employers, those responsible for systems of work and security leaders take reasonably practicable actions to minimise the risk of terror-related incidents in and around their workplace. These risks must be formally addressed proactively and reactively in line with public advice. Failing to act on the risk of terrorism exposes those responsible for workplace safety and security to litigation, plus various risks including operational, financial and reputational. In addition to reviewing the system of work through a risk assessment, it is recommended that frequent reference is conducted to the Australian National Security website.
Dr Tony Zalewski is a Director of Global Public Safety and a forensic security specialist with qualifications in law, criminology and the social sciences. He provides advice and training to governments and the private sector in Australia and abroad on matters relating to operational risk, security and safety. He is also an expert with practical experience in some of Australia’s leading civil actions involving security and safety.
MORE REACH
than ever before
Security Solutions Magazine digital version is now available via ISSUU on every platform, everywhere! Download it now and enjoy your favourite security magazine when you like, where you like, however you like. PC, MAC, Linux, Apple, Android, Google and more...
issuu.com/interactivemediasolutions
SECURITY SOLUTIONS 027
REGULAR
THINKING ABOUT
SECURITY
Managing the Consequences By Don Williams
Security is often seen as preventative – stopping the villains from taking or damaging what people have, and addressing the ‘likelihood’ element of risk management. This is true enough, as most of security management is about identifying assets and functions, determining threats (who wants to do harm), identifying exposures and vulnerabilities, and putting measures in place to prevent the bad guys from doing what they wish. But when the risk is realised and the event occurs, who is responsible for managing the consequences? The security manager will certainly be involved in the investigation and will be the centre of the questions such as, “Why did this happen?”, “Why did we not know this was going to happen?” and “What are you going to do to stop it from happening again?”. All are questions that a sound risk analysis, risk mitigation plan and records of requests for resources may address. Managing the consequences of the incident will probably rest with a combination of management disciplines. In a large business, ownership of these disparate elements may be dispersed both geographically and organisationally. In a small business, they may all fall to the one person. In
all cases, the interdependency of the plans, their ability to reduce immediate and future losses, and to protect the reputation of the business and the owners needs to be recognised. If there is a risk to life, then the chief warden will have a major role. It is worth asking if the emergency plans are suited to protecting staff, clients, visitors, contractors and the public if the incident is security rather than safety related. Discussions between the security and emergency manager can identify possible trigger events and appropriate response measures for inclusion in the emergency plans and training. The business’ media plan will play an important part in presenting the appropriate message to the public, staff and stakeholders. With the prevalence of mobile technology and the active encouragement by news media organisations for ‘live’ amateur feed, the ability to control what is hitting the airwaves and Internet is severely limited. So what can the business media plan hope to achieve and how fast can it respond? The security manager may help identify the types of incidents that may occur, the types of messages that can be sent and even help draft templates for use in different situations. A key difference
Managing the consequences of the incident will probably rest with a combination of management disciplines.
028 SECURITY SOLUTIONS
when considering a security incident is that it was a deliberate act by a human and, therefore, has a different social impact to, say, an industrial accident. Human resources (HR) will be important in responding to a security incident in the immediate and longer term. If there are injuries, then HR will need to be involved in tracking the staff members, advising family and so on. If the site is to be closed for any length of time, then how staff will be informed, paid, employed and otherwise managed are also HR issues. There may be the need for ongoing monitoring and counselling of all those directly or indirectly involved. Legal, insurance, business continuity/ resilience, facility management and environmental management will probably have roles to play in managing the immediate and longer term responses to a security incident. Even a relatively minor incident such as a punch-up in the workplace, theft of some goods or graffiti attacks will involve more than one manager. As part of the responsibility of protecting the business, it is up to the security manager to ensure that the other managers are aware of their involvement in consequence management and that the plans are at least vaguely aligned.
Don Williams CPP RSecP ASecM is a recognised thought leader in the field of security management. He is a member of relevant security and engineering professional associations and often sits on their committees. Don can be contacted via email donwilliams@dswconsulting.com.au
SECURITY SOLUTIONS 029
REGULAR
EVENTS ISC West 6–8 April 2016 Sands Expo Centre, Las Vegas ISC West is THE largest security industry trade show in the U.S. At ISC West you will have the chance to meet with technical reps from 1,000+ exhibitors and brands in the security industry and network with over 28,000 security professionals. Find out about new and future products and stay ahead of the competition. Encompassing everything from access control to Facial Recognition software, you are sure to find products and services that will benefit your company and clients. This year don’t miss our new IT Pavilion featuring the latest cyber security solutions. Working with SIA, ISC also features world class education to learn about every facet of the security industry. For more info on SIA Education@ISC visit: www.iscwest.com
Safeguarding Australia 2016: Protecting The Homefront The 13th National Security Annual Summit 11– 12 May 2016, QT Canberra The national security threat posed by contemporary terrorism ranges from organised
030 SECURITY SOLUTIONS
attacks against societies, to inspired attacks against individuals. At the core of the threat is the spread of extremist propaganda used to radicalise, recruit and inspire others. The frontline of this conflict spans the globe and reaches the homes of ordinary citizens through traditional media and social networking platforms. Today’s counterterrorism initiatives include interdicting and disrupting terrorists operations, but they focus more than ever on Countering Violent Extremism (CVE) and combating terrorist propaganda. Safeguarding Australia 2016 will bring leading industry experts from state and federal governments, the corporate sector and Australian and international universities to explore evolving national security threats and opportunities for improving Australia’s resilience to violent extremism Key Conference Themes Include: • Professional Development Session: Career management in the national security sector • The internet as a force multiplier for violent extremists • Counterterrorism Intelligence Simulation: The Bayzhanov Deception
• Australia’s Countering Violent Extremism (CVE) policy • Radicalisation and extremist propaganda • Foreign fighter recruitment and disruption • Partnering with local communities For more information, visit safeguardingaustraliasummit.org.au
AusCERT2016: Ubiquitous 23–27 May 2016 Surfers Paradise Marriott, Gold Coast AusCERT is hosting AusCERT2016, the 15th annual AusCERT Information Security Conference. As society increasingly moves towards ubiquitous computing and the Internet of Things, the innovations and benefits for society, health and wellbeing are profound and exciting. We are seeing innovation in sensors and data analytics, context aware systems, wearable devices, drones and robotics, and machines and critical systems that have not previously been accessible remotely now being connected.
CivSec 2016 A FREE FORUM FOR PROFESSIONALS IN SECURITY, SAFETY, EMERGENCY SERVICES & PUBLIC PROTECTION 31 MAY - 1 JUNE 2016
MELBOURNE, AUSTRALIA
CIVIL SECURITY AND CIVIL DEFENCE FOR THE INDO-ASIA-PACIFIC A COMPREHENSIVE FORUM FOR LEADERS AND PROFESSIONALS Border Control l Transport, Resource and Infrastructure Security l Physical, Cyber and CBRNE Security l Policing and Emergency Services l Surveillance, Intelligence and Response l Community Safety and Public Protection l Disaster Relief and Humanitarian Assistance l Remediation, Reconstruction and Resilience l Safety, Search and Rescue l Capability and Research l Technology and Innovation
l
FREE ADMISSION - PRE-REGISTRATION REQUIRED
www.civsec.com.au
SECURITY SOLUTIONS 031
REGULAR
EVENTS Advances in medical science using embedded medical devices that can prolong life, restore hearing and allow the visually impaired to ‘see’ through machines are some remarkable examples of ubiquitous computing. However, ubiquitous systems also create challenges and risks for everyone and everything. The interconnectivity of devices and systems; the ability for them to be remotely accessed or controlled; and the ability for them to be exploited and misused can have adverse consequences for individuals and societies that were not intended by their designers. The information security community must address and respond to these challenges and risks while nurturing the innovations that benefit society and individual wellbeing. Come to AusCERT2016 to hear a great line up of talented speakers discuss and explore the security challenges and risks associated with ubiquitous computing, and network with your peers. Visit conference.auscert.org.au for more information.
Biometrics Institute Asia-Pacific Conference 2016 25–26 May 2016 Dockside, Sydney The Biometrics Institute is delighted to announce the dates of their annual event for 2016. If you are interested in sponsorship or speaking opportunities, please email: steven@biometricsinstitute.org
032 SECURITY SOLUTIONS
CIVSEC 2016 31 May – 2 June 2016 Melbourne Convention and Exhibition Centre, Melbourne CIVSEC 2016 is an international forum dealing with the acutely relevant and inextricably interconnected imperatives of civil security and civil defence in the preservation of sovereignty, the protection of people and the safety of communities. It confronts the complex and increasingly interdependent challenges of the control of borders, the maintenance of law and order, the prevention of terrorism, the defence against threats to society, the protection of people and communities, the security of infrastructure and resources, the provision of emergency services, the response to disasters, the coordination of relief and the management of crises. Comprising a congress of specialist conferences and an associated exposition of equipment, technology and services, CIVSEC 2016 will bring together leaders and decision makers, policy makers and advisers, managers and officials, operational professionals, technical specialists, strategists and academics, researchers and consultants, technology developers and industry suppliers. While focusing on the Indo-Asia-Pacific region, CIVSEC 2016 will address issues of global significance. From the Indo-Asia-Pacific to Africa and the Middle-East, from Europe to the Americas, the world faces similar challenges with respect to the preservation of sovereignty and the protection of people. The peace,
prosperity, safety and cohesion of societies and communities everywhere are threatened by natural disasters and emergencies, by human catastrophe and civil disorder, by criminal activity and terrorism and by the movement of distressed populations across porous frontiers. The key players who respond to these challenges are diverse: governments and non-government organisations, aid agencies and emergency first responders, police and paramilitary law enforcers, national armed forces, immigration and customs authorities, border protection agencies and specialists in the law, medicine, infrastructure, civil affairs and search and rescue. Visit www.civsec.com.au for more information.
Security Exhibition & Conference 2016 20–22 July 2016 Melbourne Exhibition Centre, Melbourne As an industry you have spoken and your event is returning to Melbourne in 2016! The Security Exhibition & Conference will return to Melbourne again in 2016 following another outstanding event last year. Having held the Security Exhibition & Conference in Sydney for 12 consecutive years, it’s great to remain in Melbourne to consolidate relationships and to nurture business in this market. For more information visit securityexpo.com.au
SECURITYEXPO.COM.AU | 03 9261 4500 | SECURITYEXPO@DIVCOM.NET.AU
034
The Lethal Cocktail of Terrorism: The Four Necessary Ingredients Part One
035
By Anne Speckhard
The author recently returned from an interview trip in Belgium, the European country with the highest per capita rate of foreign fighters going to Syria; young men and women who travel there sometimes for good, but mainly to join groups like ISIS and Jabhat al-Nusra (the Syrian franchise of Al Qaeda). With over 500 Belgians having gone to fight jihad and over 100 foreign fighters now having returned (half of them put in prison, half returned into society) authorities are struggling with the staggering numbers that have been attracted into militant jihadi groups. They are wondering why and how that comes to be, as well as what can be done to prevent and turn back those already entered onto the terrorist trajectory. After interviewing almost 500 militant jihadi terrorists, their family members, close associates, and even their hostages, from places ranging from Palestine, Lebanon, Iraq, Jordan, Syria, Russia, Chechnya, Israel, Canada and Western Europe, the author believes she has a good idea of how and why some people get onto the terrorist trajectory. This is her explanation of the necessary ingredients for the lethal cocktail of making a terrorist, along with an explanation of the individual vulnerabilities/motivations that may also play a role, depending on the context and the individuals involved. First, there is nearly always a group. Ted Kaczynski (the Unabomber) and Chris Dorner (the former LA policeman and shooter) each formed their own manifestos and attacked on their own, but these types of true lone wolves are rare. There is usually a group purporting to represent some faction of society and offering terrorism as an answer. Second, the group offers an ideology – one that always wrongly attempts to justify terrorism and the attacking of innocent civilians for the cause. Third, there is some level of social support that can vary widely by context. A youth in Gaza thinking about joining a terrorist group, for instance, is likely to have many friends who are also part of Hamas or Fatah and may choose his group the way youth in other countries choose a football team. In contrast, a youth growing up in Boston, as Tamerlan Tsarnaev
036
did, will have to dig deeper in his community to find other like-minded individuals; although with the Internet, having a smartphone or computer handy means that one can quickly and easily tap into social networks supportive to terrorist groups. ISIS currently maintains a 24/7 presence on the Internet and produces thousands of videos, posters and memes for individuals to interact with on all of the social media sites. When a person shows interest in their activities, they quickly swarm in, providing him with one-on-one attention, care and nurture that is often lacking in his own life to recruit him further into the group. Lastly, there is some individual vulnerability that resonates with the first three factors – the group, its ideology and the social support
Lastly, there is some individual vulnerability that resonates with the first three factors – the group, its ideology and the social support provided by the group. provided by the group. This article identifies 50 factors that have to do with individual motivations and vulnerability (see Table One) and these can be broken into two groups: by whether or not the person lives inside or outside a conflict zone. According to the author’s research, those who reside in conflict zones are most often primarily motivated by trauma and revenge, as well as frustrated aspirations. They most often have family members who have been killed, raped, tortured, imprisoned or otherwise unfairly treated. They may have lost their home, territory, jobs and resources, and may be living under occupation. Often, there are checkpoints and conflicts that keep them from engaging in their studies or block them from steady employment. They are angry, hurt and easily resonate to a group that
offers to equip them to strike back. They often want their enemy to feel the same pain they do and, even if they know their terrorist act may be futile in every other way, they may be willing to even engage in a suicide attack in order to express their outrage, make the enemy suffer similarly, and sometimes even to end their own pain. If they are highly traumatised, a suicide mission may offer them psychological first aid of a short-term nature – they can honorably exit a life overtaken by psychological trauma, painful arousal states, flashbacks, horror, anger, powerlessness, survival guilt and traumatic bereavement. If the group is good at selling suicide, they may even believe that they will immediately go to Paradise, also earn Paradise for their family members, and that they will reunite with lost loved ones by taking their own lives in a suicide attack. But what about those residing in nonconflict zones like Belgium? What are the individual vulnerabilities that may contribute to their entering the terrorist trajectory? There are many. In places like Belgium, the Moroccan second- and third-generation still live uneasily, segregated from their white neighbours. They find themselves easily able to gain an education, but less easily hired and allowed into the mainstream middle class, which can lead to anger over marginalisation and discrimination. Unemployment, underemployment and frustrated aspirations can all lead to feelings of alienation and a longing for personal significance that a terrorist group may offer. When interviewing youth in Belgium (long before ISIS arose), the author found that youth of Moroccan immigrant descent reported being told “Go home Moroccan” at nightclubs, and at job interviews that prospective employers could never hire a Moroccan for the front office. One youth, Jamal, told, “If this country does not want me, I can find one that does,” referring to joining a militant jihadi movement. Now with ISIS having declared its caliphate, this draw is even more powerful to the socially alienated, the person falling off his tracks or unable to succeed in the society in which he lives. In the city of Brussels where the commune of Molenbeek has been labelled a
SECURITY SOLUTIONS 037
hotbed of terrorism, unemployment levels for Belgian citizens of Moroccan descent hover at around 30 percent. Yet ISIS currently offers any Muslim who is finding it hard to make his life in Europe or elsewhere a job, a wife, a sex slave, a house, perhaps even a car, and the promise of being a significant part of building the so-called caliphate. Anger over geopolitics, particularly if it is mirrored on the micro-level in one’s own life, can also play a very important part in providing a fertile ground for terrorist recruitment. Hamid in Antwerp, Belgium, told that he answered the call to Al Qaeda terrorist recruitment after the recruiter brought the conflict back home to local politics for him – asking if he did not live uneasily with his ‘white’ Belgian neighbours and fear what might happen if things rapidly fell apart in Belgium someday as they had in the Balkans when Muslim women became mass rape victims. Terrorist groups today use video, images and the Internet to portray extreme traumas and perceived, as well as actual, injustices in conflict zones such as in Syria, Iraq, Kashmir, Palestine and Chechnya. They argue the traumas are caused by an enemy other than the terrorist group and then call the viewer to fight against that enemy to restore justice and defend the defenseless. Al Qaeda for years argued that Islamic people, lands and even Islam itself were under attack by the West and therefore people all over the world had a duty to rise up and join a defensive jihad. The same is being argued today by ISIS. In a sense, these groups instil secondary trauma in the viewers of their raw and graphic videos. A Moroccan friend of the Casa Blanca bombers told, “We all viewed these videos of the war in Iraq and what was happening in Fallujah and we began to shake from the emotions of it all.” He surmised that the terrorist recruiter of his friends referred to what they had all seen on these videos and how they could fight against it. “You see how we have nothing here and will never get jobs or be able to be married. The most we can be is drug addicts as you see us, but their recruiter cleaned them up and showed them another way.” That way was self-sacrifice, attacking on behalf of others, and terrorism. He did clean the youth he recruited of their drug addiction, as well as provide purpose and significance
038
Unemployment, underemployment and frustrated aspirations can all lead to feelings of alienation and a longing for personal significance that a terrorist group may offer.
and he used the secondary trauma that the video recruiting materials caused to put them on a path that tragically and violently ended their lives and the lives of others. Part two of this article in the next edition of Security Solutions Magazine will continue the examination of individual motivations and vulnerabilities that may contribute to the making of a terrorist. Anne Speckhard Ph.D. is Adjunct Associate Professor of Psychiatry at Georgetown University in the School of Medicine and
Director of the International Center for the Study of Violent Extremism. She is author of Talking to Terrorists and Bride of ISIS and co-author of Undercover Jihadi. Anne was responsible for designing the psychological and Islamic challenge aspects of the Detainee Rehabilitation Program in Iraq to be applied to 20,000 detainees and 800 juveniles. She has interviewed nearly 500 terrorists, their family members and supporters from various parts of the world, including Gaza, the West Bank, Chechnya, Iraq, Jordan, Russia, Canada and many countries in Europe. Visit www. AnneSpeckhard.com for more information.
FAST. SIL ENT. STYL I S H . Our award winning speedgates keep your building secure with style. Find out which speedgate is right for you.
1300 858 840 www.entrancecontrol.com.au
Centaman Entrance Control Ad 2.indd 1
17/02/2016 11:27:40 AM
MASTER LOCKSMITHS Master Locksmith Association members are highly trained, fully qualified security professionals with access to the very latest in restricted key systems, from mechanical keys and locks to the world-leading electronic master key systems.
Find your nearest locksmith and MLA member at
THE MLA ADVANTAGE
DOMESTIC
COMMERCIAL
AUTOMOTIVE
SAFES
RESTRICTED KEY SYSTEMS
ELECTRONIC SECURITY
CCTV
FOLLOW US ON
SECURITY SOLUTIONS 039
ALARMS
040 SECURITY SOLUTIONS
Alarm Online By Kim Khor
Physical security systems have benefited from the technology revolution. Control modules are network-aware, or at least they connect to a PC. Some are PCs. They interact with a website account, or they contain a website. They provide remote access. They get system updates. The great thing about this is that users can interact with the system and configure and review it without needing all those special tools used in the old days. The convenience of using common software to configure systems, monitor online, send emails and SMS alerts, remotely access video feeds, and zoom in and out, is all too curious to resist. So, also, say the hackers. As an adversary, anyone can jump online and buy a zero-day, spear-phishing template for a few dollars. This lets a hacker create an email to send to a target, infect and control his PC, find out what software he uses, what gadgets are connected, what passwords he uses, and what web addresses he frequents. If he has remote video monitoring, the hacker now has that too. Neat. Included here are all detection, analysis, surveillance and alarm systems. For example, many people have global positioning system (GPS) trackers on their car for when it is stolen. What treasure might this decision expose to online adversaries? Could they hack the website account and monitor the car at whim? Would that let them turn on the hands-free kit and listen to a conversation?
History Physical security systems have a long history. In recent decades, they have become quite sophisticated and have followed the evolution of other digital embedded systems; that is, mechanical systems that contain computer software. Bigger or older physical security systems needed maintenance from skilled technicians with special cables. This meant that hacking these systems required high levels of creativity. As time passed, security systems became more like network devices that happened to relate to security. They were integrated into building management and automation systems, telecom systems and office networks. They were made easier to operate, and more feature-rich. This is a natural evolution for such systems. It is necessary for these systems to keep pace with the population’s appetite for risk, convenience and gadgetry. But there is a downside. While there is a range of sophistication and maturity in the systems, there is also a spectrum of self-preservation capability. The hardness of the system is often balanced against its ease of use. Concessions are also made for reasons of commercial efficiency. Sometimes, comically, there is no rational explanation for a risky design decision. A lack of operator expertise can compromise the state of the system in terms of IT security. The end result is a wide range of vulnerabilities being exposed with little awareness of the associated risks.
Scenarios Networked camera vulnerability A few years ago, a significant manufacturer of domestic security cameras accidently introduced a bug into its camera software. The bug allowed an intruder to view the camera feed on the internet, without the need for a password. Bulletin board websites and internet newsgroups started listing the web addresses at which the camera images could be viewed. Numerous breaches occurred, exposing the private video surveillance of households and elsewhere. The bug remained active in the software for the cameras for a number of years! It was estimated that only five percent of customers had registered with the manufacturer, so it is difficult to know how many people were affected, or how many know of the compromised camera systems. Data breaches The fact that people’s information is held by a third party means it can be improperly obtained from another source. The infamous Sony data breach (an arbitrary example among many) demonstrates that big budgets and ‘terms of use’ do not necessarily guarantee security. If a physical security provider is compromised in this way, what information and capability is exposed? Now that so-called advanced persistent threat resources are available for hire on the internet, the attack surface of physical security systems and their associated
SECURITY SOLUTIONS 041
ALARMS
technology must be re-thought as “From where am I visible?” Stuxnet The Stuxnet computer worm became famous for targeting nuclear fuel refinement robots (centrifuges) in Iran. It is said to have caused real physical damage in an unmanned sabotage operation. In broad terms, the malware turned up the rev limiter on the robots so they spun out of control and blew up. Although not a completely accurate description, it shows the concept. The systems it targeted were not connected to the internet. It jumped, morphed and hid. The studies have revered the design of the malware as if it were a magnificent mythical beast. This shows that a properly motivated intruder can overcome almost any obstacle via design ingenuity in the tactics or the tools. Social mechanics Quite often, the hardness of the system alone is not the deciding factor. Much hacker folklore is based on combination attacks. Social engineering is the practice of exploiting human behaviour for tactical advantage. In computer hacking, it is typified by examples such as: • Arrive at reception dressed like a maintenance guy. Ask for a visitor pass to get in, perhaps to clear a blocked drain (and plug in a little box). • Use 100 points of identification to change someone’s password or personal identification number (PIN) over the phone. • Get hold of a support guy’s toolkit. They often contain master passwords – back doors. • Drop a USB gadget in the car park for an employee to find, inherit and use at work. • Follow someone through a secured door, like the door to the shared bathrooms corridor, which also has the telco wiring riser and a wiring distribution frame to play with – piggybacking.
042 SECURITY SOLUTIONS
While there is a range of sophistication and maturity in the systems, there is also a spectrum of self-preservation capability. The hardness of the system is often balanced against its ease of use.
Whose responsibilities are these? Do not consider computer security and physical security as separate forces. They must interweave. Solutions Resist gimmicks The manufacturers of systems rush to give consumers a reason to be interested in them. They will give consumers half-baked software as long as the list of features sounds right. What many people fail to realise is that the gimmick which enticed them to purchase the software, or one of its many unused features, may be the very thing that makes it interesting to an intruder.
Include it in the risk matrix Anyone on the risk committee, or who gives advice to such committees, should get these issues on the table and state that there are connections between systems and there may be vulnerabilities. What to do? It is okay to just say, “We acknowledge the question, and will consider how to increase our knowledge.” That is an important step. Ask suppliers questions in writing Especially if there are any specific concerns, consumers should ask questions via email so they get a written reply and therefore a record of the supplier’s stated position. If the supplier dodges the question, politely restate it. If the consumer ends up in a bad corner, it can be valuable to be able to show that he made conscious efforts. Test suppliers Users should ask suppliers for logs, or something, and see how they respond. Tell them an IT security scenario is being firedrilled. Do they email a text-based log file that can be easily analysed, or do they fax shadowy pages that can hardly be read? Does it take minutes, or days? Use security awareness education Spear phishing cannot be forced on anyone; they have to fall for it. If consumers know what it looks like, they probably will not fall for it anymore. Staff, clients and system users are the best guardians of the systems, and the best coaches for each other. Empower them to do the work. They will enjoy being competent, and their confidence will spread beyond the office to their personal lives.
Kim Khor is a computer forensics expert. He consults on network security, incident response, risk and compliance, investigations, and electronic evidence management in the Asia Pacific region. He can be contacted at kimkhor@gmail.com
Contact us on 1300 364 864 Follow us on
Delivering Proven Solutions for Security & Safety We Protect People & Assets SECURITY SOLUTIONS 043 www.magneticautomation.com.au
Conflict And Cameras: Facing The Reality Of Social Media
044
045
By Richard Kay Technology can benefit public safety operations in many ways. With advances in technology increasing at a staggering rate, there are many options available for public safety agencies to increase operational efficiency. However, pointof-view (POV) technology is now prevalent in people’s daily lives and, in the age of smartphones and CCTV, security personnel need to understand that they are always under scrutiny. This article examines the risk POV technology may pose to officers in the form of cameras and uploaded content to the public domain. Most readers will have seen, or at the very least heard about, incidents of interpersonal conflict and violence being videoed and uploaded to social media websites such as YouTube or Facebook. Most smartphones now have inbuilt apps that upload content directly to the user’s page with the simple press of a button. There have been numerous incidents of violence in schools that have been filmed and uploaded as a form of bullying and victimisation, sometimes with tragic consequences. A recent incident in Queensland involved a transit security officer who was verbally abused by a young offender whilst his friend filmed the whole thing on his smartphone and later put the video online. In this instance, the security officer remained calm and professional and did not react to the harassment from the offenders and, as a result, the incident was resolved without escalation – certainly a credit to the officer involved. With so many people in modern society having ready access to a camera, what can security officers do in relation to this matter? The key is to remain calm and employ appropriate interpersonal strategies to resolve incidents in a professional manner, the basis of which is taught during security licensing training. Harm Minimisation The objective in conflict situations is to defuse conflict before it reaches the level of physical aggression, so officers should be aware of the levels of conflict escalation. People often resort to aggression as a last resort, acting out of fear or desperation, whilst some choose violence as an ‘easy’ option, intimidating others to get their way rather than communicating rationally. Violence rarely occurs without reason and there
046
are usually precipitating factors to any violent episode. Officers should be aware that what they bring personally to the interaction can contribute to conflict, and this includes assessment of stressors and their style of interacting: • Are there ongoing problems in their life that are affecting their work? • How stressful is their work and is there greater stress on a particular day? • Are there clients or colleagues that ‘push their buttons’? • What is their attitude towards the subject? With additional stressors, anxiety increases and people become susceptible to errors in judgement. It is important to make a deliberate effort to diminish the impact of stressors by developing an awareness of personal style, as self-control is important to achieve situation control. Negative language reflects the mindset of the speaker and affects the outcome of a situation. It is common for people to view the world as dichotomous – only two possible choices, positive or negative – which leads to judgements and a closed mind. When resolving conflict, keep an open mind to all possibilities and opportunities. Once a pattern is developed, it takes effort to change this entrenched behaviour, so practice maintaining a flexible mind every day. It is important to accept each person and situation on its own merits and only deal with the situation at hand. Previous history can be useful, but do not let it affect the management of a situation. To effectively negotiate conflict situations, officers should endeavour to: • control breathing to stay calm • be patient and avoid arguing with the subject(s) • be aware of emotional triggers and ignore them • be objective and neutral • offer options, not ultimatums • incite empathy so the aggressor sees them as a person, not an object • adopt an assertive, not a confrontational, approach. The ability to ‘step back’ from an escalating conflict is an extremely valuable skill. Taking a step away or physically withdrawing can provide space, time and an opportunity to reassess.
It also sends a conciliatory, non-threatening message to the other party. Mentally stepping back is a process of reviewing, assessing and rethinking the strategy in a conflict situation. Interpersonal Communication To effectively communicate with people, it is important to understand the factors that affect interpersonal communication and seek to diminish their negative impact on the situation. Language should be clear, concise and appropriate to the situation, and communication should be courteous and reflect sensitivity to social and cultural differences. The verbal aspect (the words used) has the least impact in communication, but tends to be the aspect most people focus on. Obviously, the choice of words should be carefully considered at all times, as it can be as simple as having a single word misinterpreted for conflict to escalate. Officers should be adept at communicating with people at many different levels.
The key is to remain calm and employ appropriate interpersonal strategies to resolve incidents in a professional manner, the basis of which is taught during security licensing training. Tone (how the words are said) includes rate of speech, volume, pitch and inflection. The tonal aspect of communication is important, as any particular phrase can have a different meaning depending on how it is spoken and, therefore, how it is perceived. For example, loud volume, fast rate and high pitch can indicate anxiety and stress. Low volume, even rate and low pitch indicate calmness and assertiveness.
Body language makes up the bulk of interpersonal communication. The body gives a true expression of what a person is feeling, so it is important to observe for signals that indicate whether they are positive or negative in relation to an officer’s message. Officers should ensure consistency in their verbal and non-verbal messages, as the subject will perceive body language messages more accurately. An important feature of aggression is that it does not generally occur as an isolated act, but as part of a process. Awareness of this cycle can assist in assessing the subject’s immediate potential and choose an appropriate method for dealing with a situation before it escalates. Early intervention begins with detecting the subject’s emotive state and involves: • questioning: ask how he feels; does he have needs that are not being met • listening: hearing ‘feelings’ allows for identifying the source of agitation and can provide clues on how to assist him • validation: acknowledging feelings is extremely important, even if it is difficult to attend to the need or request. Verbal and Non-Verbal Strategies People have a personal space which they regard as their own. Officers need to respect this personal space whilst maintaining awareness of people entering theirs, especially in potentially violent situations where close proximity increases their vulnerability to attack. Maintain a balanced and relaxed posture to display confidence, and keep a safe distance of two-arm’s length; otherwise stand at 45 degrees to the side of the subject, if possible. Proper use of eye contact shows confidence and assertiveness and helps focus the subject’s attention on an officer. The incorrect use of eye contact may be deemed inappropriate and cause conflict by sending the wrong message to the receiver. Personalise communication by using names and terms like ‘us’ and ‘we’ to show involvement, rather than ‘you’ and ‘I’, which tends to separate. Officers should show respect for the subject’s position, display empathy and promote the benefits of taking their course of action, rather than consequences of choosing another. Ask questions to gather information and engage the subject’s brain, which assists in
reducing options for resistance; but give him an opportunity to answer in his own way. Active listening involves co-operation with the speaker, not competition. Using eye contact to focus on the subject and making listening noises indicates interest and shows him he is being ‘heard’. Provide feedback to clarify understanding, avoiding personal opinion or interpretation. Establish a cause for the subject’s behaviour. Encourage him to express his frustration or distress, but set reasonable limits and clear consequences. Clearly inform him that aggression is unacceptable, and outline the consequences if it occurs. Offer assistance by asking the subject what can be done to assist or help him and, where practicable, provide him with a choice of options. Keep requests to a clear, simple and direct manner. Remain neutral and avoid arguing. Do not criticise values or beliefs, or get involved in ‘power’ struggles. This supports a notion of being right and wrong, and will not support the process of resolution. Stay focused on the issue at hand and avoid being side-tracked. De-escalation versus Compliance Communication varies depending on the stage of conflict and what officers are aiming to achieve. The initial strategy will revolve around using language that de-escalates the intensity of the situation. If this does not work, then communication that asserts proactive control may be required. De-escalation phrases are used to defuse potentially violent situations by verbally offering alternatives to the subject’s current intentions, or outlining consequences of his course of action. Compliance commands are used for affecting assertive control. ‘Commands’ does not mean officers start screaming at the subject; it simply means they have chosen to take assertive control of the situation. Once this is achieved, return to normal communication, stressing calmness and cooperation.
Effective verbalisation during an incident is vital because it: • demonstrates reasonableness • informs the subject what the officer requires of him • creates witnesses from bystanders. A critical skill in officers developing effective conflict management strategies is the ability to assess a wide range of factors, including the subject, the situation/context, their own responses, the potential for escalation, risk factors and environmental issues. Assessment and strategic planning drive the choice of conflict management options, and it is important to ensure that this assessment is as thorough as possible. It is clearly important to acknowledge that assessment must sometimes be carried out in difficult situations, or even while trying to defuse a hostile confrontation. Focusing on assessment, however, helps to maintain a resolution-based approach and an awareness of any potential escalation features. Security companies should be proactive in creating awareness, through internal education strategies such as presentations, internal memos and updates to company orders, as officers representing the company in the workplace pose a risk through vicarious liability if they make poor operational decisions. It is only a matter of time before someone gets the idea to deliberately set up a security officer and video the confrontation in an effort to either gain social media notoriety or try to extract dollars from a security company through a lawsuit. No company wants their branding displayed over social media in a negative manner. Personal cameras and social media are a fact of life and officers need to remain alert to this in the operational environment. It is important that officers are not only seen to DO the right thing, but are heard to SAY the right thing. Officers should presume they are being filmed each and every time they conduct operations and act accordingly, because the reality is, they probably are! Richard Kay is an internationally certified tactical instructor-trainer, Director and Senior Trainer of Modern Combatives, a provider of operational safety training for the public safety sector. For more information, please visit www.moderncombatives.com.au
SECURITY SOLUTIONS 047