A U S T R A L A S I A’ S L E A D I N G S E C U R I T Y R E S O U R C E F O R B U S I N E S S A N D G O V E R N M E N T
ISSUE #102 JUL/AUG 2016
Inside the Panama Papers Leak What Security Lessons Can We Learn?
ISSN 1833 0215
$9.95 inc GST / $10.95 NZ
intelligent storage the creone keybox is a new solution for management of valuables & keys. absolute control easy to use With the Creone KeyBox range you will have complete control over your keys and valuables. Whatever your requirements you can choose a basic or more advanced solution.
There is one important requirement when it comes to storage systems that are used by a number of different people: the easier to use, the better.
Creone offer everything from key cabinets and value boxes that will meet your basic needs to advanced systems that monitor every single key and user.
Creone intelligent technology automatically keeps things in good order, and thanks to the user-friendly software, it is easy for the administrator to monitor key use and control.
Total flexibility
Key Features
Creone KeyBox systems are flexible, which makes it easy for you to adapt your system when your needs change. Start with a solution that is suitable for your current needs, and expand it as your needs grow. Your storage solutions are future-proof when you invest in a Creone KeyBox to manage your keys and valuables.
• A simple and flexible solution • Over 40 different models and styles available • Easily expandable • Intuitive management software • Made in Sweden
visit us at...
Visit lsc.com.au/creone for more information.
Creone develop intelligent storage systems. They have being doing this since they started in 1979, and today supply solutions to companies in 30 countries. Creone have three keywords for their storage solutions; Control, Flexibility and User-Friendliness. Whatever your needs, they have a solution you can offer with security and good order – both today and in the future.
A Solution to Suit Creone’s extensive KeyBox range will offer storage solutions to a variety of industries.
Pharmacies
Banks
Car dealerships
Shops
Hotels & Hostels
Offices
Police
Taxis
Aged care facilities
NEED SERIOUS SECURITY? THE ANSWER IS EZI!
Ezi Security designs, manufactures and installs a premium range of electronic perimeter security products designed for both vehicle and pedestrian control. These consisting of a wide range of security products suitable for low to high-risk applications. Ezi Security Systems has been manufacturing quality security products for over twenty-one years with equipment is installed in some of the very harshest of environments the planet has to offer. And all with outstanding results. While Ezi has a commitment to innovative design and quality products we also fully understand the importance of easy and efficient after sales service. Ezi Security Systems services and maintain the products we sell to ensure that your critical infrastructure and personnel are protected at all times. “ALL EZI SECURITY SYSTEM PRODUCTS ARE BUILT TO LAST A RELIABLE THIRTY YEAR (PLUS) PRODUCT LIFE SPAN WHEN MAINTAINED”
Ezi Security Systems has the most extensive offering of Hostile vehicle barrier products (HVB’s) and has the expertise to design and secure any critical infrastructure or site of national importance. Ezi has an extensive range AVB and HVB Crash Certified products such as the world famous TruckStopper, the renowned K12 Wedge, crash boom beams and crash rated static and automatic bollards. Ezi Security Systems has all the realistic solutions to meet your high security requirements while maintaining an aesthetically pleasing solution for your site. All Ezi Security System AVB & HVB have been vigorously crash tested and certified to meet all ASTM, IWA and PAS 68 stipulations. Ezi Security and its partners continue to the push boundaries on all crash products with our in-house R&D security experts providing market leading products designs. This specialist ability also involves our renowned installation expertise and advice with the all important civil work design & engineering. Ezi Security believes in pushing design frontiers for its products to keep pace with marketplace and security priorities. This year alone Ezi and PPG have successfully worked with CTS and crash tested to Pas 68 in 2016 the following products:
•
M30 Bollard Performance rating V/7500[N2]/48/90:0.0/0.0
•
M50 Bollard Performance rating V/7200[N3C]/80/90:5.5
•
Wedge II Performance rating V/7500[N3]/80/90:0.0/20.7 (tested with 4 m blocking width)
With our highly chosen business partners being the best in their field and coupled with our own Ezi Security R&D in house design team Ezi Security continue to push boundaries on market leading and state of the art crash rated designed products. Our ability also involves installation expertise and advice with all important civil work design & engineering.
Ezi also takes pride to provide our clients with more than just perimeter security solutions. We also offer a quality range of internal pedestrian control products from Werra Entrance Control. The Werra Entrance Control range compliments perfectly the already strong offering of pedestrian security control that Ezi Security currently offers to the market. The range includes a wide variety of systems suitable for pedestrian access management that includes the ability to hold and isolate persons of interest and/or concern. Ezi Security again has a quality product for every threat and contingency for building personnel security. All products offer quick access for authorised persons and reliable protection against unauthorised access. With a flow rate of up to 35/min even large flows of people can be monitored and controlled effectively. Werra Entrance Control not only stands for innovative for the individual’s passage of person, but also is an extension for our philosophy of being a professional fullservice provider of all components within perimeter security and access control. Ezi Security Systems, and their business partners, are privileged to be protecting some of the most prestige and iconic man made marvels of the modern era from the Burj Khalifa Tower in Dubai to Australia’s very own Parliament House in Canberra.
IF SERIOUS SECURITY IS YOU REQUIREMENT, LOOK NO FURTHER THAN EZI! FIND OUT MORE ABOUT US!
AUSTRALIA NATIONAL
1300 558 304 11 Cooper Street Smithfield NSW 2164 www.ezisecurity.com.au sales@ezisecurity.com
CONTENTS102
COVER STORY: THE PANAMA PAPERS AND THEIR SECURITY IMPLICATIONS FOR AUSTRALIA
058 034
The Panama Papers have caused major reverberations around the world; in governments and businesses. There has been massive media and public interest in the content of this huge tranche of commercial documents. The disclosure of the offshore tax details of over 214 000 shelf companies has some quite extraordinary implications – including in Australia. What security lessons can we learn from this extraordinary leak?
THE TIME FOR MICRO-SEGMENTATION IS NOW Corporate security strategies are failing, so leaders must re-tool to face the latest cyber threats.
066
ARE YOU TRUSTING? How can you tell the difference between truth and deception?
068
WHEN THE WAR IS OVER: SECURITY AND RISKS TO CONSIDER WHEN WORKING IN POST-CONFLICT ENVIRONMENTS Hugh Morris, managing director at The Development Initiative, looks at the security challenges of operating a business in a post-conflict environment.
072
HARMONISATION OF THE SECURITY INDUSTRY Brett McCall looks at the past attempts to harmonise licensing in the Australian security industry with a view to determining if it is feasible or a disaster.
076
IN-FLIGHT REVENUE RISKS In-flight purchases are an important revenue stream for airlines globally, but how do you manage the associated risks to protect revenue and ensure profitability?
092
SECURITY 2016 SHOW GUIDE Find everything you need to get the most out of this year’s Security 2016 conference and exhibition, including floor plans, exhibitor list, conference programs and more.
004 SECURITY SOLUTIONS
touch . identify . control
First upgradable High Security range of access control readers using RFID, Bluetooth® and NFC technologies Card mode
Tap Tap mode
Place your smartphone in front of the reader.
Tap your smartphone twice while in your pocket for a proximity or a remote opening.
Slide mode
Remote mode
Place your hand to the reader without leaving your smartphone.
Control your access points remotly.
RFID leader manufacturer since 1996
France United Kingdom America Australia
info@stid.com
SECURITY SOLUTIONSm005 www.stid.c
CONTENTS102 010
LETTER FROM THE EDITOR
028
012
BRIGHT IDEAS
014 LEADERSHIP What is the difference between good and bad 016
030 EVENTS A look at upcoming industry events. 040 ALARMS What does it take to build an A1 grade control room?
CYBER SECURITY How can Australian businesses close the
044
cybersecurity skills gap?
planning?
the new normal rather than the exception?
leadership?
018 RESILIENCE What role do exercises play in effective resiliency 020
THINKING ABOUT SECURITY Is it time that we accept that terrorism is
versus close fist use of force in public safety.
048 CCTV What role does storage play in a modern IP-based CCTV system?
HUMAN RESOURCES Just how big are the risks of non-compliance with human resources and industrial laws?
022 RISK MANAGEMENT Dr Kevin Foster reviews ARPI’s Strategic Risk
054
024 COMMUNICATIONS Rod Cowan looks at why security should never be
happened to Egyptair flight 804.
084 ACCESS CONTROL Dr G. Keith Still looks at the challenges and misconceptions around crowd safety.
an excuse for discrimination.
026 LEGAL How can you minimise risk by aligning with standards when contracting security services?
BUSINESS What is the key to effective communication in a crisis?
080 AVIATION Steve Lawson speculates on what might have actually
Policy for 2016.
034
OPERATIONS Richard Kay looks at the practical applications of open
088
PROFESSIONAL DEVELOPMENT Do the challenges around corporate acceptance of the security function really rest with the board, or are security professionals actually to blame?
068
076
096
SECURITY STUFF
114
PRODUCT SHOWCASES
098
SPOTLIGHTS
118
SHOPTALK Company announcements from within the industry.
104
PROFILES
006 SECURITY SOLUTIONS
SECURITY SOLUTIONS 007
www.securitysolutionsmagazine.com
Editorial Editor: John Bigelow john@interactivemediasolutions.com.au Sub-Editing: Helen Sist, Ged McMahon
Contributors: Gary Barnes, Rita Parker, Greg Byrn, Kevin Foster, Rod Cowan, Tony Zalewski, Don Williams, Tom Patterson, Joe Paravizzini, Richard Kay, Vlado Damjanovski, Caroline Sapriel, Neil Fergus, Brett McCall, Hugh Morris, Lizz Corbett, David Foley, Steve Lawson, Keith G Still, Colin Robbins.
Advertising admin@interactivemediasolutions.com.au Phone: 1300 300 552
Marketing & Subscriptions admin@interactivemediasolutions.com.au $62.00 AUD inside Aust. (6 Issues) $124.00 AUD outside Aust. (6 Issues)
Design & Production Graphic Design: Jamieson Gross graphics@interactivemediasolutions.com.au Phone: 1300 300 552
Accounts accounts@interactivemediasolutions.com.au Phone: 1300 300 552
Publisher
Interactive Media Solutions ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au Disclaimer The publisher takes due care in the preparation of this magazine and takes all reasonable precautions and makes all reasonable effort to ensure the accuracy of material contained in this publication, but is not liable for any mistake, misprint or omission. The publisher does not assume any responsibility or liability for any loss or damage which may result from any inaccuracy or omission in this publication, or from the use of information contained herein. The publisher makes no warranty, express or implied with respect to any of the material contained herein. The contents of this magazine may not be reproduced in ANY form in whole OR in part without WRITTEN permission from the publisher. Reproduction includes copying, photocopying, translation or reduced to any electronic medium or machine-readable form.
RS A DE VI
SSOCIATI
ON
ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au
O
SECURIT Y
PR
RALIA LTD UST FA
O
Written Correspondence to:
Or i g i n a l Si z e
O C I AT I
ON
Y P R OVI D
RIT
CU
D LT
SE
PR O
ASS
SPAAL
AU S T R A L I A
STRALIA LTD AU
SECURITY
RS
OF
E
Official partners with:
SSOCIAT IO N
OF
RS A DE VI
blue colour changed to this colour green.
COPY/ARTWORK/TYPESETTING APPROVAL Please proof read carefully ALL of this copy/artwork/typesetting material BEFORE signing your approval to print. Please pay special attention to spelling, punctuation, dates, times, telephone numbers, addresses etc, as well as layout.It is your responsibility to bring to our attention any corrections. Minuteman Press assumes no responsibility for errors after a proof has been authorised to print and print re-runs will be at your cost. Signed.................................................................. Date........................
008 SECURITY SOLUTIONS
SPEED UP! with Aperio® V3
Experience the next generation of Wireless Access Control
WIRELESS LOCKS REACT IN A HEARTBEAT WITH THE NEW V3 PLATFORM! ASSA ABLOY’s Aperio® V3 platform is a new generation of battery-powered locks packing more powerful electronics, enabling faster response times. Its remote unlocking commands pass from access control systems to doors and locks almost instantly, providing users with an effective remote opening function. With a comprehensive lock range covering almost every door style and opening there’s no reason to delay upgrading to faster wireless access control with Aperio® V3.
Cost-effective Increased battery performance
Multi credential Supports multiple high frequency RFID technologies and SEOs mobile access
Real-time Heartbeat communication: 5-10 seconds
Scan the QR code to find out more or phone 1300 LOCK UP aperiotechnology.com.au
SECURITY SOLUTIONS 009
LETTER FROM THE EDITOR In our increasingly digital world, we are putting more and more of our lives online every single day. In fact, according to some sources, we have created more data in the past two years than in every other year in history combined! This begs the question, where is the line between privacy and security? On one side of the argument, we have governments the world over pushing for greater access to our personal information and communications. In the UK, we have seen the recent introduction of the so-called Snoopers Charter, draft legislation proposed by Home Secretary Theresa May which would require internet service providers and mobile phone companies to maintain records of each user’s internet browsing activity (including social media), email correspondence, voice calls, internet gaming and mobile phone messaging services and store the records for 12 months. Last year saw the introduction of sweeping new surveillance laws in Pakistan, Poland, Switzerland and more. In France right now, in the wake of the Paris attacks, the government is considering introducing prison sentences and fines for companies if they refuse to comply with decryption orders. In the US, we recently saw the legal battle between the Federal Bureau of Investigation (FBI) and Apple where the FBI and US investigators working on the San Bernardino shooting approached Apple with a US court order, asking Apple to circumvent their own security and crack the iPhone of one of the shooters. Of course, in reality, the FBI were not simply asking Apple to unlock that one single phone, but were instead trying to force Apple to install a backdoor in their own software that would give the US Government access to Apple devices whenever the courts deemed it necessary. The problem, however, as Apple argued, was that once such a backdoor is created, it makes all devices running that software vulnerable to hackers, cyber criminals and a multitude of other people who might wish to exploit it. Furthermore, if Apple were to give in to the demands of the US Government, then what would stop any other government making the same demands? This demand from governments to increase surveillance of personal data arises from the argument that the proliferation of digital communications without proper oversight is making it easier for terrorist organisations to plan and execute terrorist attacks. However, experience and history show us that this argument is flawed in that a terrorist group sufficiently motivated to carry out an attack will find ways to communicate offline where they cannot be detected or monitored. On the other side of the argument, there is the belief that the average person has an inalienable right to a reasonable level of privacy. The question is, what is reasonable? This issue’s cover story by Neil Fergus looks at some of the security lessons that can be learned as a result of the recent Panama Papers leaks and the implications of those leaks for businesses, individuals and governments. The balance between security and privacy, much like the balance between security and convenience, has been and will continue to be a very fine line. Where that line rests will undoubtedly continue to be the source of much debate, but one thing remains clear – commonsense continues to be the best defence against unwanted leaks. If you do not want people to know something, then it is probably best not to communicate or store information in a manner or forum that can be easily accessed.
John Bigelow Editor
010 SECURITY SOLUTIONS
GAIN CONTROL WITH ONEVIEW Defuse situations quicker with a truly unified security control room solution Saab’s OneView is a next-generation physical security information management integration platform that provides unprecedented levels of subsystem integration in mission-critical infrastructure environments. OneView empowers operators to respond effectively and efficiently to the most stressful situations. Offering accurate intuitive situation awareness, a simple operator interface, fast detection-response and comprehensive support for post action analysis, OneView is the ultimate choice for modern surveillance and security operations. You can rely on Saab’s thinking edge to bring your control room under real control. saab.com/australia
REGULAR
BRIGHT IDEAS Engineers Patent Limited-Range Projectile To Reduce Collateral Damage Imagine a bullet that could self-destruct if it missed its target. Apparently, it is not as farfetched an idea as we might think. Three employees of the US Army Armament Research, Development and Engineering Center (ARDEC) were recently awarded with a US patent for their proof of concept work on a limited-range projectile. Brian Kim, Mark Minisi and Stephen McFarlane filed collectively for the patent on 7th May 2013 and were notified of its approval on 1st September 2015. According to reports by www.army.mil, the official homepage for the US military, the concept for the limited-range projectile includes pyrotechnic and reactive material. The pyrotechnic material is ignited at projectile launch. The pyrotechnic material ignites the reactive material and, if the projectile reaches a maximum desired range prior to impact with a target, the ignited reactive material transforms the projectile into an aerodynamically unstable object. The practical use that the three men intended to apply the concept to is .50 calibre ammunition. However, the patent covers the idea and technology behind the concept as a whole, so it could theoretically be used in various calibres of small arms munitions. “We wanted to protect the US government’s interests and position,” McFarlane said about filing the patent.
012 SECURITY SOLUTIONS
Trial and Error Computerised modelling and simulation were performed to compare the inventive projectiles to the .50 calibre M33 projectile and the .50 calibre M8 projectile. “Conceptual designs were run through and evaluated via modelling and simulation,” Kim said. “Three concepts were submitted with the patent; however, not all were feasible,” he said. “A proof of concept test was perfected and results indicated the need for concept refinement and pyrotechnic mix improvement,” Kim said. The group states that there are significant benefits to the warfighter in using a limitedrange projectile. “The biggest advantage is reduced risk of collateral damage,” McFarlane said. “In today’s urban environments, others could become significantly hurt or killed, especially by a round the size of a .50 calibre, if it goes too far.” McFarlane said that the distance in which the round disassembles can be adjusted based on the choice of reactive material used. The benefit of this is that the round does not continue to travel, therefore reducing collateral damage. This benefit can best be described as “a design programmed maximum range” according to McFarlane. The ballistics also match and/or exceed the standard round out to the max effective range
of the round. In theory, the projectile may be any calibre from 5.56mm to 155mm. How the Disassembling Projectile Works The concepts vary; however, in theory the process would work like this: During launching of the projectile, pyrotechnic initiating material is ignited by energy produced by propellant in the cartridge case. Or, pyrotechnic initiating material may be ignited by energy produced by bagged propellant, if the projectile is a separately loaded projectile. Pyrotechnic initiating material ignites the reactive material. Prior to impact of the projectile or with a target, and while the projectile is airborne, energy produced by the ignited reactive material transforms the projectile into an aerodynamically unstable object. The transformation into an aerodynamically unstable object renders the projectile incapable of continued flight. In one concept, the projectile is rendered unstable by the melting of the copper jacket, which produces a highly irregular shape. In another, the projectile is rendered unstable by the separation of the cylindrical portion from the base portion and the separation of penetrator from the projectile assembly. Visit www.army.mil/article/162556/ for more information.
SECURITY SOLUTIONS 013
REGULAR
LEADERSHIP The Leadership Game By Jason Brown
In my last article, I identified the need for leaders to have the ability to: • communicate effectively • recognise the developmental requirements of team members • set goals and motivate the team to achieve them • provide enthusiastic and creative encouragement • model acceptable behaviour. In summary, there are a range of positive behaviours that demonstrate good leadership and get results and there are clearly some bad ones that can lead to disaster. In this column, I will introduce readers to a leadership game that anyone can play. The Leadership Game This game is part of the process I used in the development program for middle-ranking staff. It was aimed at getting them to examine the leadership behaviours of previous bosses they had experienced and write these down on the four-part framework (see illustration). In the top left-hand quadrant, write down the negative professional/technical behaviours of your worst boss/bosses. Do not just write down a compilation of multiple bosses, but think in terms of a specific individual for each statement. For example, if ‘John’ was your worst boss ever, you might start with – ‘John pretended to know his material but bluffed his way through’ or ‘He never kept up with technical advances and suppressed innovation’.
014 SECURITY SOLUTIONS
Similarly, in the top right-hand quadrant, write down the behaviours of the better boss. For example, ‘Jane was always up-to-date and provided the newest technical information’ or ‘Her presentations were standouts’. The bottom left-hand quadrant is about bad personal behaviours. For example, ‘Mary was a bully’ or ‘She took credit for my work’. The bottom right-hand quadrant is about good personal behaviours, such as ‘Harry always had time to help with problems’ or ‘He provided praise when praise was due’. Have some fun filling them in and maybe thinking about how these behaviours made you feel about work. In the next issue, I will take you through the results of this type of activity. If you want to see your results included, just send me your chart. Draw up a chart in PowerPoint, fill it in and send it to me when it is completed.
Jason Brown is the National Security Director for Thales in Australia and New Zealand. He is responsible for security liaison with government, law enforcement and intelligence communities to develop cooperative arrangements to minimise risk to Thales and those in the community that it supports. He is also responsible for ensuring compliance with international and commonwealth requirements for national security and relevant federal and state laws. He has served on a number of senior boards and committees, including Chair of the Security Professionals Australasia; Deputy Registrar Security Professionals Registry – Australasia (SPR-A); Chair of the Steering Committee for the International Day of Recognition of Security Officers; member of ASIS International Standards and Guidelines Commission; Chair of Australian Standards Committee for Security and resilience.
REGISTER FOR OUR NEW WEB SHOP & PURCHASE ONLINE 24/7 ESHOP.SECURITYMERCHANTS.COM.AU
A complete Intrusion and Access Control solution for your businesses.
Engineered to provide exceptional sensing and detection performance.
Superior video surveillance capabilities to meet modern commercial application needs.
Formerly Sentrol, ITI provide hard-wired intrusion detection options, including switches and magnetic contacts.
IFS® delivers cost-effective, high-performance network transmission solutions for IP Video, Access and Life Safety Applications.
MELBOURNE | SYDNEY | BRISBANE | ADELAIDE | PERTH
1300 663 904 securitymerchants.com.au
SECURITY SOLUTIONS 015
REGULAR
CYBER SECURITY How Can The Cybersecurity Skills Gap Be Closed? By Garry Barnes
There is a need for businesses to take a planned approach to cybersecurity awareness, training and education to ensure visibility and capacity to respond. According to a recent speech in Parliament, Julie Bishop, Foreign Minister, stated, “The Australian Signals Directorate detected more than 1,200 cyberattacks against Australian interests in 2015.” These attacks primarily targeted Australian government and businesses in defence, energy, finance and transport. And that is just the number of cyberattacks detected. Joint research between the Information Systems Audit and Control Association (ISACA) and RSA Conference shows that in 2015, 82 percent of Australian/ New Zealand (ANZ) IT professionals expected their business would experience a cyberattack in 2015, indicating the number is probably even higher. Unfortunately, the threats are increasing, and the cybersecurity skills gap is worsening too. There are three things that will help to narrow this gap, but it will take time and considered planning. First and most importantly, the highest levels of management need to recognise that cybersecurity is not just an IT issue – it is a business issue. According to the ISACA and RSA Conference survey, globally 82 percent of board of directors report being concerned or very concerned about cybersecurity, yet only one in seven chief information security officers reports to the CEO. With the monetary and brand damage already experienced by local businesses, cybersecurity must be viewed as a business issue and budgeted for accordingly. For businesses that do recognise the importance of the issue, another problem lies with finding staff that are adequately skilled and know how to deal with cyber threats.
016 SECURITY SOLUTIONS
According to the 2016 ISACA Cybersecurity Snapshot, the cybersecurity skills gap is a significant challenge to businesses trying to expand their cyber workforce. Close to half (47 percent) of those surveyed in Australia said they need to hire more cybersecurity professionals this year, yet a whopping 94 percent of those hiring said it will be difficult to find skilled candidates. One way to address the skills gap is to provide on-the-job training. Ron Hale, Chief Knowledge Officer at ISACA, states, “Hands-on, skills-based training is critical to closing the cybersecurity skills gap and effectively developing a strong cyber workforce.” Upskilling those already employed can reduce time spent trying to find staff in a shallow pool of applicants where determining the skill level can often be challenging, particularly with the dynamic nature of cyber threats. There are a myriad of training courses businesses can provide to staff, including those offered through ISACA’s vendor agnostic, Cybersecurity Nexus (CSX), which now includes a career road map tool that can highlight areas of future growth and development. Not only should IT professionals obtain on-the-job training, but businesses should invest in basic security training for all employees. Understanding the basics and having policies in place, especially in password protection and social engineering, allows employees to be more responsible and alert for potential threats and attacks, and enhances the protective and responsive capabilities of the organisation. Another tactic for overcoming the skills shortage is to proactively engage tertiary students. A number of major universities are providing courses in cybersecurity; however, students do not necessarily understand the job opportunities that are available to them.
Local chapters of ISACA are actively engaging students through career fairs and guest lecturers to discuss the opportunities and skills required for these roles. Businesses should do the same as a way to embolden digitally savvy students to work in the IT industry. Through this active engagement and awareness, students will be able to see the possibilities and opportunities that are available to them. Further to this, ensuring a diverse workforce is needed. According to Girls in Tech MasterCard research, which surveyed teenagers in Australia and Asia about Science, Technology, Engineering and Mathematics (STEM), young Australian women are the least interested in these subjects in the region. If this level of disinterest remains, the cybersecurity skills gap will continue to increase. The research suggests that providing positive female role models and highlighting the attractive salaries may assist in encouraging more women into IT roles. There are amazing female role models who continually inspire and provide thoughtprovoking insights into the security industry. They are leaders and pioneers, and businesses need to profile these career opportunities so that there is an even greater pool of talent to tackle the cybersecurity issue. In her address to Parliament, Julie Bishop said the Australian Government will pledge $30 million to develop a Cyber Security Growth Centre which will create business and employment opportunities for the cybersecurity industry. This is just the beginning when it comes to tackling the major cybersecurity issues within Australia. How a business approaches the concept of cybersecurity is imperative in today’s marketplace. Upskilling the current workforce and encouraging a diversified workforce are steps in the right direction to ensure an organisation is prepared and its capacity to respond is adequate.
NEW!
SECURITY SOLUTIONS 017
REGULAR
RESILIENCE Exercises And The Resilient Organisation By Dr Rita Parker
“Any business plan will not survive its first encounter with reality. The reality will always be different. It will never fit the plan.” – Jeff Bezos, Amazon That is why the key to planning lies in creating strategies that are resilient, particularly to deal with unlikely disruptions and events. The likelihood of a complex emergency or crisis situation is a very real consideration for senior managers and security professionals and such a situation can occur with little or no warning, affecting a broad range of people and resources. When such a situation occurs, people feel the need to take action – to respond. Therefore, the governance of emergencies or crisis situations has become part of everyday life. Organisations are realising that traditional corporate strategies are not protecting them from an unexpected event. Resilience – the capacity to self-organise, to learn and to adapt to disruption – offers a useful mechanism of governing emergency and crisis situations. Resilience has been adopted into policy and response strategies because it provides a response to life-threatening situations and events that cannot be averted in time. Organisations need to be resilient to survive and thrive; they need to be able to absorb an event that necessitates change, to adapt and continue to maintain their competitive edge and profitability. The viability and sustainability of organisations continues to be tested in a world that is constantly changing and with such change comes a range of new risks, threats and challenges – often unexpected or unanticipated. This has led to a shift in security management practices for emergency events and crisis situations. This new
018 SECURITY SOLUTIONS
framework recognises that non-professionals are directly and indirectly involved in security practices. Such involvement can range from reporting suspicious behaviour to more active participation in specific resilience practices, including exercises that seek to educate and train potential or likely at-risk corporate populations. The only way to know if a plan is effective is to use it. The next best thing is to test it through an exercise. Such exercises are critical for any organisation, whether it is a multi-national corporation or a smaller company, so that people learn to function under duress in a safe environment rather than be thrown in the deep end – with only an untested plan! Conducting regular testing of existing corporate plans through exercises is part of an organisation’s duty of care to its staff and other stakeholders. However, the value of such exercises is often criticised by some senior managers and employees who argue that they are too busy to be away from ‘their real job’! They need to keep in mind they will not have a job to do if the organisation does not or cannot function properly. Conducted effectively, exercise activities develop the capabilities of managers and employees; they offer opportunities to make mistakes and to learn from them and, in doing so, validate the organisation’s resilience process and build confidence. Exercises provide an ideal opportunity to gain real hands-on experience in a safe and secure learning environment, by using realistic and relevant scenarios. Importantly, conducting relevant and timely exercises helps to evaluate organisational plans to ensure resilience processes are fit for purpose. The other key value of conducting exercises is that the findings provide valuable evidence, particularly for the
security professionals in charge of the exercises. In this 21st century of global risks and threats unheard of by previous generations of managers, the development of the human capacity of individual leaders and their enabling teams to handle unplanned eventualities is critical. The use of well-thought-out exercises helps people in organisations better understand the risks and threats, as well as their own vulnerabilities. Importantly, it allows them to put in place useful, tested and relevant plans that will help them achieve a resilient organisation that has demonstrated its duty of care to its people and other stakeholders.
Dr Rita Parker is a consultant advisor to organisations seeking to increase their corporate and organisational resilience and crisis management ability. She is an adjunct lecturer at the University of New South Wales at the Australian Defence Force Academy campus where she lectures on resilience and nontraditional challenges to security from non-state actors and arising from non-human sources. Dr Parker is also a Distinguished Fellow at the Center for Infrastructure Protection at George Mason University Law School, Virginia, USA. She is a former senior advisor to Australian federal and state governments in the area of resilience and security. Dr Parker’s work and research has been published in peer reviewed journals and as chapters in books in Australia, Malaysia, the United States, Singapore and Germany, and presented at national and international conferences. Rita holds a PhD, MBA, Grad. Dip., BA, and a Security Risk Management Diploma.
SECURITY SOLUTIONS 019
REGULAR
HUMAN RESOURSES The Risk Of Non-Compliance With HR And Industrial Laws By Greg Byrne
This article will discuss how important it is for all businesses, in or out of the Australian security industry, to comply with basic rules of industrial and human resource (HR) management. No better an example can be found in the contemporary Australian industrial arena than the 7-Eleven debacle of the last two years. An investigation by the Fair Work Ombudsman (FWO) and joint investigation by Four Corners and Fairfax Media uncovered systemic underpayment of wages, doctoring of payroll records and the flagrant disregard for Australia’s laws regarding employment of foreign nationals. The investigation found that the average 7-Eleven worker in Australia was being ripped off on a grand scale by one of the biggest multinational franchises in the world. Workers were being paid wages that were half that of the award; employees were mostly foreign nationals working illegally and under threat of deportation if they complained; time sheets and rosters were doctored; and, most alarmingly, head office was fully implicit. The media investigation led to an investigation by the FWO, raids on numerous franchisees and, ultimately, a scathing final report. Numerous judgements have been made, millions of dollars in fines and compensation ordered and unimaginable damage done to reputation. Headlines like these have littered the media landscape for years and will continue to do so for months to come: • 7-Eleven: Wage compensation bill may top $100 million • 7-Eleven: Fair Work Ombudsman says admit exploitation complicity • 7-Eleven store owner hit with record fine • Workers at 7-Eleven get almost $10 million in compensation. The debacle that is now the 7-Eleven investigation highlights the risk, no the catastrophic threat,
020 SECURITY SOLUTIONS
non-compliance with the Fair Work Act 2009, the National Employment Standards (NES) and the various industrial laws poses to all businesses in Australia. 7-Eleven failed at just about every step. Between 2008 and July 2009, the FWO raided dozens of convenience stores, including 7-Eleven, recovering $162,000 for 168 aggrieved staff. Again, between September 2009 and September 2010, the FWO audited 56 stores and found wideranging discrepancies in wages. Between 2014 and 2016, the FWO and the joint investigation between Four Corners and Fairfax Media uncovered numerous examples of breaches of foreign worker rules and discrepancies in wages. The Chairman, Russ Withers, and CEO, Warren Wilmot, both resigned and the company was ordered to repay millions of dollars to aggrieved workers. 7-Eleven, like all businesses in Australia, is required to adhere to the minimum wage, the NES, which are 10 minimum employment entitlements, and whatever the industrial agreement is for its workforce or industry. The minimum wage is determined annually by the specialist Minimum Wage Panel of the Fair Work Commission and takes effect in the first full pay period on or after the 1st of July every year. The NES make up the minimum entitlements for employees in Australia. An award, employment contract, enterprise agreement or other registered agreement cannot provide for conditions that are less than the national minimum wage or the NES. The ten standards are: • maximum weekly hours of 38 hours • requests for flexible working arrangements • parental leave and related entitlements • annual leave of four weeks • personal carer’s leave and compassionate leave • community service leave
• • • •
long-service leave public holidays notice of termination and redundancy pay Fair Work Information Statement must be
displayed in the workplace. Casual employees are only entitled to: • unpaid carer’s leave • unpaid compassionate leave • community service leave • the Fair Work Information Statement. Those early raids in 2008 and again in 2010 should have raised alarms with 7-Eleven management that something was amiss, but they did not. It is unimaginable to think that such a large and seemingly highly structured company, and obviously a very successful one, failed to take heed of the warning signs. The messages from this incident are clear and lessons for all are there to be learnt: the risk of non-compliance with basic industrial and HR law and agreements can be catastrophic, both financially and reputationally. The most amazing thing with this is that the rules are not hard to follow and place nowhere near the burden on the organisation that noncompliance does. Greg Byrne is the Managing Director of Multisec Consultancy Pty Ltd. He also lectures part-time at the Western Sydney University where he teaches an under-grad diploma in policing as well as working as a sub-editor for the Australian Police Journal and serving as a member of the board of directors. He possesses a number of academic qualifications including; Master of Management, Diploma of HR, Grad Cert in Leadership and a Diploma a Security Risk Management. He can be contacted via email; greg@multisec.com.au. Also see www.multisec.com.au.
P
R NE O W D U C T
For over 30 years Perimeter Systems Australia has been delivering Perimeter Intrusion Detection Systems (PIDS) to Critical Infrastructure, Government, Industrial and large Commercial customers.
• • • • •
360° Asymmetrical Detection 1,000 metre detection Radius Radio Frequency Detection Drone and Operator GPS Coordinates Integrates with existing systems
Electronic Taut Wire Fence System • Utilises very reliable strain gauge technology • Software sensitivity adjustment • Each sensor can be adjusted separately • Very reliable and difficult to defeat
Don’t forget, we also have competitive pricing on Takex products. Call for a quote!
Palmgrove Business Park, D413-15 Forrester St. Kingsgrove NSW info@perimetersystems.com.au | www.perimetersystems.com.au
In the wrong hands drones literally add a new dimension to eavesdropping and spying on facilities, individuals and infrastructures in a wide variety of environments and industries. They have the power to shrink the realm of public safety, privacy and physical security. Few other technologies have this much power.
NE W !
Passive Infrared & Microwave Intrusion Protection False Alarm Free performance and lowest nuisance alarm rate possible. The only outdoor motion sensors that really works!
Call us on (02) 9150 0651 or visit www.perimetersystems.com.au SECURITY SOLUTIONS 021
REGULAR
RISK MANAGEMENT Review of ARPI’s Strategic Risk Policy 2016 By Dr Kevin J. Foster
A not-for-profit organisation called the Australian Risk Policy Institute (ARPI) recently published a paper entitled Strategic Risk Policy 2016. In the paper, ARPI argues that they have devised a new approach to avoiding risk that is different to conventional risk management. The paper is not an academic argument, nor is it in the form of an industry standard for practitioners. ARPI describes it as a guide to risk policy for leaders. This is distinct from risk-based policy such as defence policy, immigration policy, crime prevention policy and so on. ARPI is advocating a policy that is not necessarily specific to identifiable risks. ARPI advocates an adaptive risk culture, not just in hierarchical organisations but more broadly across networks of organisations. Of course, this concept is well known to high reliability organisations and cultural risk theorists. Indeed, the literature in the field is quite rich and not as new as ARPI suggests. ARPI argues that ‘traditional risk management’ is a relatively new discipline. This sounds like a contradiction in terms. It is assumed they mean that it is a new management discipline. This could be a flaw in the ARPI argument. Risk management is certainly not new. Human society has always managed risk. Many risk management policies and tools have been developed over thousands of years. The risk management methodologies used in some ancient civilisations were quite similar to the methodologies used today. A very good paper on this history is entitled Risk Analysis and Risk Management: A Historical Perspective, written by Covello and Mumpower and published in 1986. Many policies, laws and regulations over the centuries have been risk-based. For example, the Code of Hammurabi was written in about 1760BC. Building regulations written since then have been mostly risk-based. Indeed, many laws directed at public safety are risk-based. Insurance is a risk
022 SECURITY SOLUTIONS
management strategy used since about 3000BC. The Ashipu people in ancient Mesopotamia provided risk management advice as early as 3200BC. Any security professional knows that security decision making has always been riskbased. Perhaps ‘traditional risk management’ is a term poorly selected by ARPI. For the moment, assume that ARPI meant to use the term ‘conventional risk management’, perhaps as advocated by ISO31000:2009. ARPI argues that vulnerability is a new concept and that vulnerability needs to be considered in risk policy. Security professionals, defence experts and foreign policy analysts have always considered vulnerabilities, so this is not a new idea. However, ARPI is correct in stating that in many cases there is a need to enhance risk management systems in order to consider risks that affect networks of organisations and not just isolated organisations. While this is not a new idea, it is worthy of consideration; indeed, it is an important point. Risk researchers have been working on these ideas of reliability for a considerable length of time. Many will differentiate between simple and complex systems. A simple system might be a supply chain where any organisation downstream in the chain may be adversely affected by a failure or incident at any point upstream. Another example of a simple system is a typical building project where there are numerous subcontractors working in a hierarchy for a main contractor who, in turn, delivers the project for a client, such as a building owner. In high reliability theory, redundancy is typically used to improve the reliability of simple systems that may be disturbed by unexpected events. It is not clear if ARPI’s use of the term ‘vulnerability’ is intended to imply that redundant measures
are needed to reduce vulnerability. ARPI is not specific about how vulnerabilities should be addressed. In complex systems, the designer, builder or policy maker may not be aware of all the possible interactions between the component parts and even between subsystems. The risk analyst will consider some failure states, but uncertainties will remain about the interactions of failed components with other failed (or working) components of subsystems. This is especially true in the case of a system which is becoming increasingly complex; for example, electrical energy generation and distribution in most Australian states. The ARPI strategic risk policy model in one sense recognises that complex networks of organisations and their operating environments need to be managed in more sophisticated ways than often is the case with routine risk management processes like those described in ISO31000. However, at the same time, the ARPI model does not offer any new ways to manage complex risks; indeed, it seems mostly to ignore the wealth of ideas that have been developed in high reliability theory, the cultural theory of risk and normal accidents theory. The ARPI model is clearly not intended to reflect academic thinking on the subject of complex systems risk analysis and management. However, ARPI could produce a much better, and more useful, strategic risk policy framework if it operationalised the state-of-the-art in academic thinking in this field. Dr Kevin J. Foster is the managing director of Foster Risk Management Pty Ltd, an Australian company that provides independent research aimed at finding better ways to manage risk for security and public safety, and improving our understanding of emerging threats from ‘intelligent’ technologies.
SECURITY SOLUTIONS 023
REGULAR
COMMUNICATIONS
Not In Security’s Name By Rod Cowan
For the past two months, I have been in the Middle East, teaching investigative report writing to over 200 security personnel, both men and women, from around the globe – from the Philippines to Punjab, from Guyana to Kenya. Me being the only person with English as my first language throws into sharp relief the difficulties of not only dealing with language barriers, but also cultural, gender and religious issues, in a region where every morning I read in the newspapers the latest body count of failure to communicate across such boundaries. Meanwhile, mainstream media coverage in the West on issues relating to Muslims is fuelling mounting Islamophobia. A University of Cambridge study conducted over 2015 found an “atmosphere of rising hostility” towards the UK’s 2.7 million Muslims, who comprise less than five percent of the 64 million-strong population. Reportage using negative stereotypes, however, is not restricted to the UK. In February, the Sydney Morning Herald ran an inflammatory column by Paul Sheehan on Muslim males brutally raping and bashing an off-duty nurse, with graphic details of anal, oral and vaginal rape by Arabic-speaking men. The story was quickly proven to be false. Sheehan went unpunished. How does fuelling fear and suspicion play out in practice from a security viewpoint? Take aviation security as an example. In March, an Arab– American family was offloaded from a United Airlines flight in Chicago and the only reason offered was that it was “a safety of flight issue”. In April, a Muslim woman of Somali descent wearing a headscarf was kicked off a Southwest Airlines
024 SECURITY SOLUTIONS
flight after a flight attendant said she “did not feel comfortable” with her. A few days later, an Iraqi-born immigrant studying at UC Berkeley was escorted off another Southwest flight, patted down, subjected to a bag search, questioned by the Federal Bureau of Investigation (FBI), and prevented from returning to the flight – all because a woman overheard him speaking Arabic on his mobile phone. What was he saying? “Inshallah”; a common expression (meaning God willing) used not only by Arabs but by just about everyone working in the Middle East. Southwest said, “We would not remove passengers from flights without a collaborative decision rooted in established procedures… We regret any less than positive experience on board our aircraft. Southwest neither condones nor tolerates discrimination of any kind.” Review reports of such incidents and there are common themes: • The offloaded passengers have the appearance of being Muslims or Arabs, and it seems many people conflate the two. • People making the fuss are allowed to continue on their travels unhindered; one wonders how serious they would be about their concerns if told they would be offloaded too. • The people removed are usually found to be harmless; open source research fails to reveal a single validated case. There is no logic behind the removal of these passengers and no signs of any serious risk assessment. Yet it is all done in the name of security. If these are “collaborative decisions rooted in established procedures”, someone
should take a hard look at the decision-making process and the procedures from a security and risk viewpoint. The reality is that the most troublesome – and for that matter violent – passengers on aircraft worldwide are drunk, white males. The problem is not as simple as discrimination; racism is easy to define and identify. The problem is one of fear being amped up by politicians eager for coverage and an indolent media industry all too desperate for easily manufactured clickbait. Security managers need to be aware of such developments and should act to combat them within their organisations. Although there is no research data, it is clear from anecdotal evidence and observations that security employs a high number of immigrants. It makes sense, therefore, if only from a duty-ofcare perspective, it should be an industry that does not tolerate racism and discrimination. Moreover, it is an industry that could and should openly challenge racism in all its forms in the broader community. Why? Because living in a contemporary pluralistic world means crosscultural communication is increasingly becoming a matter of necessity for global survival. Incidents of discrimination in the guise of security are not likely to dwindle in the near future. It behoves security managers and operators to act if they are to provide authentic security.
Rod Cowan is a Contributing Editor to Security Solutions Magazine. He can be contacted via email mail@rodcowan.net
SECURITY SOLUTIONS 025
REGULAR
LEGAL Contracting For Security Services: Minimising Risk By Aligning With Standards By Dr Tony Zalewski
It is well reported that many organisations have moved from in-house to contracted security services. However, outsourcing or contracting does not necessarily transfer operational risks to the contractor; it merely provides another level of risk exposure to the organisation, hence the importance of contracting appropriately. It is often argued there are many operational and financial benefits for using a contract security service. These include engagement of licensed security personnel whom have already completed pre-licensing training and probity checks; avoidance of internal human resource issues relating to in-house security staff; predictable costings for security services; access to a pool of licensed security staff if required; and potential engagement of a greater level of security-related competence. If the decision is made to move from an in-house to contracted security model or a contracted security service is to be renewed or tendered, it is important that various terms and conditions of service are clearly specified. Standards promote best or appropriate practice that can assist in this process, as they have been developed by subject matter experts and industry specialists. It is important these standards are identified and content included within any agreement as relevant to the security service and the standard(s) listed within any contract. The Australian Standard AS/NZS 4421:2011 Guard and patrol security services can assist to understand the minimum requirements that form
026 SECURITY SOLUTIONS
the basis for a contracted security service, such as: • Unless declined by the client prior to the commencement of the contract, a site inspection of the client’s premises shall be conducted by a competent person who will advise the client of the identified safety needs and will provide practical and reasonable proposals for protection (Section 2.6.1); • Further under ‘Notes’, a security survey and physical security advice are regarded as additional to the provision of security officers, which may be purely to meet the requirements of the client’s own specification and, where provided, should be the subject of additional insurance provisions in respect to professional negligence (Section 2.6.1); and • The company (security firm) shall formulate assignment instructions for the effective security of the site, dealing with emergency procedures, lines of communication and accountability. The assignment instructions should be agreed between the parties (Section 2.8). The Standard recommends that any contract for security services should be based upon agreements resulting from the security survey or instructions as agreed between the parties. Of course, if the organisation does not have appropriate security competence amongst its staff to conduct a security survey, the contract arising from the organisational requirements will more likely than not have omissions and therefore be deficient. This can be overcome by engaging an
appropriately qualified and experienced security consultant. It may seem trite that such a basic approach outlines the need for a risk assessment, operating procedures and a services contract as recommended within the Standard and discussed in this article. However, many contract providers merely introduce a generic risk document as the basis for their security services, supported by generic operating procedures. This results in a deficiency across the system of security as riskrelated issues, including vulnerabilities in the context of the relevant workplace, have not been adequately identified nor suitably treated. Prudent organisations contracting with a security provider insist that the process of risk management involves carefully thought through and agreed methods for addressing identified security risks that are relevant to the particular workplace and clearly outlined within the contract for security services. Failing to contract appropriately increases risk for all parties involved.
Dr Tony Zalewski is a Director of Global Public Safety and a forensic security specialist with qualifications in law, criminology and the social sciences. He provides advice and training to governments and the private sector in Australia and abroad on matters relating to operational risk, security and safety. He is also an expert with practical experience in some of Australia’s leading civil actions involving security and safety.
ELVOX PIXEL Video Door Entry Systems Stylish and ultra-thin, the Pixel and Pixel Heavy is the latest innovation in Video Door Entry Panels from Elvox. Pixel is available in Module panels or a Digital panel. Ideal for large apartment blocks, with capacity of up to 6,400 units. Its elegant, versatile yet tough. Intuitive functionality and easy to install.
SECURITY SOLUTIONS 027
REGULAR
THINKING ABOUT
SECURITY
Terrorism Is The New Norm By Don Williams
The security manager can no longer believe that terrorism is an extreme and unlikely event. It is now part of the normal operating environment and every organisation should recognise that armed assailant / active shooter, bombings and hostage takings are to be expected. There is no excuse for the defence “we did not think it could happen to us”. Terrorism is actually a definition of motive; the underlying purpose being to promote a political, cultural or religious ideal rather than for personal gain or the result of mental illness, although they are not mutually exclusive. Extreme events may not be a terrorist event by definition, but the nature of the attack and the preventative and response options are similar regardless of motive. What terrorism has done is bring awareness of these events to the forefront of the community, government and corporate minds. Therefore, there is an expectation that security managers have an awareness of the potential for such events, and plans in place to prevent and respond. Australia has a long history of workplace violence, with shootings and stabbings in office and public areas, a history of bombings for criminal and political reasons going back to the Eureka stockade and even hostage takings, usually family related but sometimes for commercial or social reasons. The arrests and convictions over the last decade of groups committed to acts of mass violence have informed society that the threat exists. But, by preventing the attacks, the arrests have made everyone complacent in that Australia has yet to suffer the atrocities seen overseas. This will change and there will be many surprised
028 SECURITY SOLUTIONS
looks and cries of “why were we not warned”. As the Lindt Café event demonstrated, any business may be a target. Those other businesses in and near the building were also victims of the event. Every business needs to have within its security and emergency plans how it will prevent, detect and respond to incidents such as an armed assailant, a bomb attack (particularly a post-blast scenario) and how it will deal with a hostage taking. The plans should address not only how they will deal with such an event on their premises, but also if it should happen next door. What can be done will, of course, depend on the size of the organisation, the resources, whether the organisation is the sole occupant or one of a number of tenants on site, the site layout and the existing management plans. Some common considerations include: the ability to recognise that an incident is occurring either on site or in a neighbour’s site/office; the ability for one person to have authority to initiate an appropriate response; the ability to communicate with staff and visitors / the public; and a clear idea of the options available to move or secure people and other assets. Terrorists have different drivers to profitmotivated criminals and, as a result, their target
selection is also different. Sometimes their selection of what is important or will help them achieve their aim exceeds rational analysis – the stabbing of police officers in Victoria may be seen as an attack on the enforcement arm of the oppressive government, but the shooting of a police accountant in Parramatta has no apparent rational basis other than he was walking out of a police building. Similarly, Timothy McVeigh’s choice of the federal building in Oklahoma City was as much a surprise as if someone was to bomb an office in Dubbo because it was their closest target. All businesses must recognise that extreme events are no longer unlikely (if they ever were) and should have plans in place to deal with them.
Terrorists have different drivers to profit-motivated criminals and, as a result, their target selection is also different.
Don Williams CPP RSecP ASecM is a recognised thought leader in the field of security management. He is a member of relevant security and engineering professional associations and often sits on their committees. Don can be contacted via email donwilliams@dswconsulting.com.au
ZKTeco Biometric technology, the next generation of access control is at your finger tips. Make your life sparkle with biometric innovations
EDUCATION | HEALTH | GOVERNMENT | FINANCE | HOSPITALITY | OFFICE SUPPLY | CHAIN RETAIL RESIDENTIAL | CONSTRUCTION | PROPERTY MANAGEMENT | REAL- ESTATE | PUBLIC FACILITIES IP based Door Access Control Management C3 – 100/200/400
Standalone Bio Finger
TCP/IP and RS-485 communication Built -in auxiliary inputs and outputs Advance access control functions 1 door, 2 door, 4 door models Lift controls and Expansion boards
RDF Backlit Keypad Face Recognition Finger and Vein
mainline.com.au VICTORIA 221 Nepean Hwy Gardenvale, VIC 3185 +61 3 9596 6688
QUEENSLAND 54 Caswell St. East Brisbane, QLD 4164 +61 7 3891 2222
WESTERN AUSTRALIA Unit 8/14 Halley Rd Balcatta, WA +61 8 9344 2555
FIND US IN BOOTH K28
SECURITY SOLUTIONS 029
REGULAR
EVENTS IFSEC International 21–23 June 2016 ExCel, London
Australia – A Risk Assessment Conference 28–29 June 2016 Hotel Realm, Barton
IFSEC International is the biggest security exhibition in Europe, taking place over three days between 21 and 23 June 2016 at London ExCeL. IFSEC welcomes over 27,000 global security professionals to experience the latest technological innovations and hear from industry leaders – all under one roof. The event caters to everyone within the security buying chain from manufacturers, distributors, installers, integrators and consultants to endusers. With over 600 exhibitors showcasing over 10,000 products, you will be able to find the perfect security solution for your business. There is more to it than just security. IFSEC International is co-located with FIREX International, Facilities Show, Safety & Health Expo and Service Management Expo, catering for those working across many platforms in building management and protection of people and information.
The Australian Security Research Centre (ASRC) is hosting a two-day conference with the theme of Australia, a Risk Assessment. The conference will feature a wide range of papers, presentations and discussion sessions designed to examine the actual risks to Australia and its citizens; what mitigation measures are available and/or appropriate; what they might cost; and what might the costs be of doing nothing. Featuring expert speakers from the public and private sectors, professional associations, academics and interested individuals, the presentations and discussions will cover the actual and real risks to Australia in a range of sectors. The conference program is themed into a number of sessions, including: • Defence and Security • Environment and Disasters • Law Enforcement • Economic and Financial Security • Population • Infrastructure and Resilience.
Visit www.ifsec.co.uk for more information or to register.
030 SECURITY SOLUTIONS
Keynote speakers: • Mr Tony Pearce – Inspector-General for Emergency Management, Victorian Department of Justice and Regulation • Mr Mark Sullivan – PwC, Risk Management Institute of Australia Visit http://asrc.com.au for more information.
Security Exhibition & Conference 2016 20–22 July 2016 Melbourne Exhibition Centre, Melbourne As an industry you have spoken and your event is returning to Melbourne in 2016! The Security Exhibition & Conference will return to Melbourne again in 2016 following another outstanding event last year. Having held the Security Exhibition & Conference in Sydney for 12 consecutive years, it’s great to remain in Melbourne to consolidate relationships and to nurture business in this market. For more information visit securityexpo.com.au
Safe Work Australia Nov 2015
“...in 2012-13 the cost impact of work-related injuries and illnesses was estimated to be just over $61 billion...”
Does your control room meet
Australian Ergonomic Standards?
State-of-the-art ergonomic lifting technology Lifetime Australian phone support AS/NZS 4443:1997 & ISO 11064
AUSTRALIAN MADE CUSTOMISABLE ELECTRIC HEIGHT ADJUSTABLE SIT STAND CONSOLES www.activconsole.com
Clayton VIC 3168
+61 3 9574 8044
sales@activconsole.com SECURITY SOLUTIONS 031
REGULAR
EVENTS The Australian Security Medals 26 August 2016 Australian War Memorial, Canberra The Australian Security Medals Foundation (ASMF) will once again celebrate the achievements of outstanding personnel in the security industry at its annual gala dinner and awards night to be held at the Australian War Memorial in Canberra on Friday 26th August. Launched in 2010, ASMF was established to publicly recognise outstanding security operatives, security professionals and their achievements and contributions to our community. The Foundation, through these awards, aims to promote security as a profession by: • raising awareness of the outstanding service(s) the medal recipients have provided • promoting awareness of what the security industry really ‘looks like’ – beyond the ‘guns, guards and gates’ image • raising funds for beyondblue in an effort to help tackle the issue of depression in Australia. Money raised from the event helps to provide material support for the families and loved ones of security personnel killed or seriously injured in the line of duty. If you would like to help celebrate the outstanding achievements of the men and women of the security profession
032 SECURITY SOLUTIONS
and network with some of the industry’s leading luminaries, then be sure to book your tickets for this amazing event now. Visit www.inspiringsecurity.com for more information.
ASIAL Awards For Excellence 20 October 2016 The Westin, Martin Place, Sydney Hundreds are expected to attend the prestigious awards ceremony and dinner to celebrate winners of the 2016 Security Industry Awards for Excellence and Outstanding Security Performance Awards (OSPAs). Media personality James O’Loghlin (from Good News Week, Rove Live, Sunrise, Lateline, The Evening Show and more than 300 episodes of The New Investors) is back by popular demand and will once again emcee the awards. The OSPAs is a worldwide scheme for recognising outstanding performers in the security sector. They have also been launched in Norway and Germany and other countries are about to follow. Australia is at the forefront. The OSPAs are supported by ASIAL, ASIS
Australia and the Security Professionals Registry (although the OSPAs is independent of all groups) in an initiative that is designed to unite the security sector in celebrating the success of its outstanding performers. They are set to bring new life to security excellence. In this first year of the OSPAs, there are nine categories open to enter in Australia. They are: • Outstanding In-House Security Team • Outstanding In-House Security Manager • Outstanding Guarding Company • Outstanding Security Consultant • Outstanding Customer Service Initiative • Outstanding Security Training Initiative • Outstanding Security Installer • Outstanding Security Partnership • Outstanding Investigator Awards will be presented to winners between courses and James will provide light comedic entertainment. There will also be an opportunity to pose in front of the photo wall, have your happy snap taken by a professional photographer and network with other security professionals. Visit www.asial.com.au for more information.
SECURITYEXPO.COM.AU | 03 9261 4500 | SECURITYEXPO@DIVCOM.NET.AU
034
The Time For Micro-Segmentation Is Now
035
By Tom Patterson
Corporate security strategies are failing, so leaders must re-tool to face the latest cyber threats. It could be said that 2015 was the year cybercrime became mainstream. Companies from all over the world, including the likes of Kmart, David Jones, Aussie Farmers Direct and Queensland TAFE locally, as well as JP Morgan Chase and Ashley Madison globally, all came under scrutiny as their breaches became mainstream news. It is repeatedly on the news agenda as it is pervasive and growing in complexity and persistence. Breaches are not only detrimental to business, but major brands also run the risk of reputational damage due to the inconvenience and the exposure their customers are subjected to. As a result, 2016 is the year when the priority is to shift tactics to combat the increasing number of hackers by abandoning outdated security strategies to protect intellectual property and other assets. But how can this be achieved? Security Openness Of course, as with all change, the first step is for more security leaders to admit that their current processes are falling short in the first place, and look at new strategies and methods which have a more realistic chance of protecting the organisation. These failings are no fault of the security teams and technology of old, but rather recognition that businesses function differently these days and, therefore, require a different approach to securing them. This is not a new theory by any means and is something which many experts have been stating for a while. However, despite the obvious ‘clean slate’ advantages of starting afresh with security solutions, there is still a large number of chief information security officers (CISOs) who are unwilling to let go of their sunken costs and look forward. Einstein said it best when he said, “Insanity is doing the same thing over and over again and expecting different results.” Simply put, more IT leaders in government and commercial enterprises need to realise that investing more
036
in yesterday’s ineffective technologies will, this year, not yield any different results. To succeed, they need to abandon the old ways of securing the organisation – with bigger walls and more event tracking – and adopt the new micro-strategy which takes advantage of network virtualisation and Internet Protocol Security (IPsec) to isolate the underlying infrastructure in a much more granular and controlled way by authenticating and encrypting each IP packet of a communication session.
Breaches are not only detrimental to business, but major brands also run the risk of reputational damage due to the inconvenience and the exposure their customers are subjected to. Year of the Micro The answer to this is micro-segmentation; it allows enterprise managers to quickly and easily divide physical networks into thousands of logical micro-segments, without the historic security management overhead. This approach gives control back to the enterprise networks, without them having to deal with the firewall rules and outdated applications, while embracing remote users, cloud-based services and third parties that have all become targets for attack in today’s world. This new micro-segmentation model will start giving the good guys the advantage in the fight against cyber attacks. With new containment strategies, organisations will have the ability to work at the IP packet level, which
makes it easier to apply anywhere a company’s data goes – from data centres to public clouds, to employees on the move, to suppliers around the world. Micro-segmentation is driven by existing identity management systems, so it is simple to establish communities of interest for authorised users across all of these technologies. It is one of the ways which CISOs can ensure that their organisations stay ahead of the pack and in the strongest position possible when it comes to security. Micro-segmentation also helps to address the question of how to secure public and community clouds. Major cloud service providers such as Amazon Web Services and Microsoft have made substantial investments in security to help ensure their subscribers’ data is safe and their cloud experience is exceptional. In fact, the security from such cloud service providers is better than in many companies’ own data centres. However, the thought of putting critical data on the cloud accessible by just about anyone is really scary and the perceived added vulnerability is preventing many organisations from fully leveraging the cloud – often they use the cloud for non-critical data such as test and development, but not for their core business applications that access their most sensitive data. New micro-segmentation offerings provide organisations with added layers of cloud security to instil the confidence they need to put more of their applications on the cloud. In doing so, they have the opportunity for tremendous cost savings, to make their products and services more globally accessible and to dynamically adjust to business conditions in real time. There are five security advantages these new micro-segmentation offerings provide to the cloud that have not previously been obtainable: 1. Micro-segmentation enables companies to use a consistent set of tools for both their local data centres and the cloud. 2. Micro-segmentation technologies provide encryption within the cloud from virtual machine to virtual machine. 3. Micro-segmentation technologies use concealment as a basis for security strategy.
SECURITY SOLUTIONS 037
4. Micro-segmentation prevents lateral movement of security infiltrations to the data centre. 5. Micro-segmentation can prevent security breaches in the cloud. A Business Priority The Ponemon Institute estimates that the total average cost of a data breach to Australian organisations was AU$2.82 million in 2015. It is clear that the impact of the major breaches ensured that security is no longer just a technology issue. Instead, it is now seen as a business issue that requires prioritisation from the top down. The security function will evolve to no longer report solely to the chief information officer. Boards will start to care and take real action and make cyber security expertise a requirement across the C-suite. Security is now a top agenda point in the boardroom as business reputations are once again at risk. Organisations will no longer be allowed to take the position of standing by and watching cyber attacks unfold – they will finally have the power to react rather than prevent. As a result, proactivity is the key word for 2016, with microsegmentation being a major player and step in the right direction for innovative organisations that are serious about security. Being seen to take such proactive measures is key to earning and maintaining consumer trust. For example, 58 percent of Australians expect a personal information data breach in the next 12 months at a telco, yet the majority of Australians say a data breach is not likely at a healthcare provider, airline and transport company, or bank (Unisys Security Insights research, 2015). Many Australians have personally experienced a data breach or have seen media reports of high-profile breaches by government and telcos, so they have a low level of trust in the ability of those organisations to protect their data. Conversely, public scrutiny around the introduction of e-health records and the resulting assurances for how data would be protected has built community trust in healthcare providers’ ability to protect personal information. Airlines and other transport companies are the most trusted type of organisations. However, they will need to
038
The answer to this is microsegmentation; it allows enterprise managers to quickly and easily divide physical networks into thousands of logical micro-segments, without the historic security management overhead.
work to maintain this trust as they continue to capture more and more information about their passengers in a bid to provide personalised end-to-end services – including assistance with border security measures.
Telecom
58%
Government
49%
Banking & Finance
46%
Retailers
45%
Utilities
40%
Healthcare
36%
Airlines
33%
Percentage of Australians expecting a data breach in next 12 months by industry
Consumer trust is not just a warm and fuzzy feeling – today’s customer is in a strong position of choice. It is easy for consumers to change their bank, telco, insurance provider or who they shop and fly with, as well as what channel they use to engage with government agencies. Previous Unisys research (2011) revealed that data breaches impact a consumer’s willingness to deal with an organisation. The majority of Australians surveyed (85 percent) said that they would stop dealing with an organisation if their data was breached. When asked if they would continue dealing with the same organisation but not use online services, only 24 percent of Australians said they would continue. Next year, let us hope that 2016 will be remembered as the year businesses faced cybercriminals head on.
For a full list of references, email: admin@interactivemediasolutions.com.au
R O B UST. S E C UR E. Our award winning full height turnstiles keep your building secure with style. Find out which high security turnstile is right for you.
1300 858 840 www.entrancecontrol.com.au
Centaman Entrance Control Ad 4.indd 1
17/02/2016 11:26:48 AM
MASTER LOCKSMITHS Master Locksmith Association members are highly trained, fully qualified security professionals with access to the very latest in restricted key systems, from mechanical keys and locks to the world-leading electronic master key systems.
Find your nearest locksmith and MLA member at
THE MLA ADVANTAGE
DOMESTIC
COMMERCIAL
AUTOMOTIVE
SAFES
RESTRICTED KEY SYSTEMS
ELECTRONIC SECURITY
CCTV
FOLLOW US ON
SECURITY SOLUTIONS 039
ALARMS
040 SECURITY SOLUTIONS
Building an A1 Control Room
SECURITY SOLUTIONS 041
ALARMS
By Joe Paravizzini
It was late last year when Staysafe Monitoring embarked on building a new A1 graded control room built to Australian Standards (AS2201) to provide a continuing level of service to its existing and new customers. Initially, the project started with a consultant from the security industry who had considerable experience with this type of project. The consultant was extremely knowledgeable and became the key to understanding the Australian standard and the requirements of the build. Other than the obvious with council regulations and building permits for the company’s existing location, the current building zoning was the first hurdle and it took a fair amount of time to get this through council. Council had interesting viewpoints that were addressed and the zoning issue was approved. Next was building permits, which required drawings and specifications for the new control room. The designers and engineers worked hard to design a control room that met the brief. Many hours were spent discussing the requirements and design to determine the size of the box itself. After three months of applications and council approvals, permits were granted to build the new control room. Some issues were encountered with the technicalities of building a box within a box. Cranes could not fit through the existing openings; however, this was overcome by building with blocks with concrete filling and reinforcement (steel). This became the most cost-effective way to build the control room. Once the blocks were complete, the engineering feat of suspending nine tons of steel as the support system for the 26ton concrete slab roof of the control room began. Countless hours were spent in the engineering design and the practical installation of this steel works. It was achieved with some difficulty – engineering is sometimes not an exact science and practicality is often an understated commodity. As they prepared to pour the suspended
042 SECURITY SOLUTIONS
The consultant was extremely knowledgeable and became the key to understanding the Australian standard and the requirements of the build.
slab on top of the control room and the ground slab, the issue of including a staircase to enable access above the room arose. With the help of a clever crew of builders and concreters, this was achieved. There was now a completed box and it was time to fit it out with many different services. Air conditioning was of great importance as the control room is sealed by doors that weigh approximately 350kg and is made of solid concrete walls all round. The contractor sourced a unit that could fit into a smaller space but still provide the correct airflows required to meet the consultants’ conditions. Door construction as per AS2201 required doors to be solid timber 45mm thick with 3mm steel on both sides. This is why the doors weighed so much. The door and hinge system was amazing to see once the doors were installed. Again, it took a few men to install and weld these doors on – achieved with ease and a professional crew. Then came the issue of disability access and a disabled bathroom that needed to be factored in. A consultant was engaged to
provide the requirements for all. Staysafe was extremely happy to be able provide this in its new control room. It supports the company’s vision for wheelchair-disabled people to be candidates for employment at Staysafe. Staysafe is looking forward to its new control room opening in the near future around July/August of this year. The importance of Staysafe having an A1 control room is for the future of the business and staff. Staysafe want be able to provide its customers with a great service that ensures growth as a company and sustains the employment of great staff. The greatest challenge over the last eight months was being the project manager for this building project; although I would do it again with the knowledge gained through this experience. It was actually fun. Joe Paravizzini is currently the owner and Manager at Staysafe Monitoring services, a fully Australian owned and operated graded Monitoring Station specialising in the electronic monitoring of Security Systems, primarily to the system installers within the security industry.
Contact us on 1300 364 864 Follow us on
Delivering Proven Solutions for Security & Safety We Protect People & Assets SECURITY SOLUTIONS 043 www.magneticautomation.com.au