Skip to main content

Security solutions #104

Page 1

A U S T R A L A S I A’ S L E A D I N G S E C U R I T Y R E S O U R C E F O R B U S I N E S S A N D G O V E R N M E N T

ISSUE #104 NOV/DEC 2016

ISSN 1833 0215

Grey Imports

$9.95 inc GST / $10.95 NZ

Caveat Emptor The Danger of


NEED SERIOUS SECURITY? THE ANSWER IS EZI!

Ezi Security designs, manufactures and installs a premium range of electronic perimeter security products designed for both vehicle and pedestrian control. These consisting of a wide range of security products suitable for low to high-risk applications. Ezi Security Systems has been manufacturing quality security products for over twenty-one years with equipment is installed in some of the very harshest of environments the planet has to offer. And all with outstanding results. While Ezi has a commitment to innovative design and quality products we also fully understand the importance of easy and efficient after sales service. Ezi Security Systems services and maintain the products we sell to ensure that your critical infrastructure and personnel are protected at all times. “ALL EZI SECURITY SYSTEM PRODUCTS ARE BUILT TO LAST A RELIABLE THIRTY YEAR (PLUS) PRODUCT LIFE SPAN WHEN MAINTAINED”

Ezi Security Systems has the most extensive offering of Hostile vehicle barrier products (HVB’s) and has the expertise to design and secure any critical infrastructure or site of national importance. Ezi has an extensive range AVB and HVB Crash Certified products such as the world famous TruckStopper, the renowned K12 Wedge, crash boom beams and crash rated static and automatic bollards. Ezi Security Systems has all the realistic solutions to meet your high security requirements while maintaining an aesthetically pleasing solution for your site. All Ezi Security System AVB & HVB have been vigorously crash tested and certified to meet all ASTM, IWA and PAS 68 stipulations. Ezi Security and its partners continue to the push boundaries on all crash products with our in-house R&D security experts providing market leading products designs. This specialist ability also involves our renowned installation expertise and advice with the all important civil work design & engineering. Ezi Security believes in pushing design frontiers for its products to keep pace with marketplace and security priorities. This year alone Ezi and PPG have successfully worked with CTS and crash tested to Pas 68 in 2016 the following products:

•

M30 Bollard Performance rating V/7500[N2]/48/90:0.0/0.0

•

M50 Bollard Performance rating V/7200[N3C]/80/90:5.5

•

Wedge II Performance rating V/7500[N3]/80/90:0.0/20.7 (tested with 4 m blocking width)

With our highly chosen business partners being the best in their field and coupled with our own Ezi Security R&D in house design team Ezi Security continue to push boundaries on market leading and state of the art crash rated designed products. Our ability also involves installation expertise and advice with all important civil work design & engineering.


Ezi also takes pride to provide our clients with more than just perimeter security solutions. We also offer a quality range of internal pedestrian control products from Werra Entrance Control. The Werra Entrance Control range compliments perfectly the already strong offering of pedestrian security control that Ezi Security currently offers to the market. The range includes a wide variety of systems suitable for pedestrian access management that includes the ability to hold and isolate persons of interest and/or concern. Ezi Security again has a quality product for every threat and contingency for building personnel security. All products offer quick access for authorised persons and reliable protection against unauthorised access. With a flow rate of up to 35/min even large flows of people can be monitored and controlled effectively. Werra Entrance Control not only stands for innovative for the individual’s passage of person, but also is an extension for our philosophy of being a professional fullservice provider of all components within perimeter security and access control. Ezi Security Systems, and their business partners, are privileged to be protecting some of the most prestige and iconic man made marvels of the modern era from the Burj Khalifa Tower in Dubai to Australia’s very own Parliament House in Canberra.

IF SERIOUS SECURITY IS YOU REQUIREMENT, LOOK NO FURTHER THAN EZI! FIND OUT MORE ABOUT US!

AUSTRALIA NATIONAL

1300 558 304 11 Cooper Street Smithfield NSW 2164 www.ezisecurity.com.au sales@ezisecurity.com


CUSTOMISABLE ELECTRIC HEIGHT ADJUSTABLE SIT STAND CONSOLES

Does your control room meet

Australian Ergonomic Standards?

www.activconsole.com

Clayton VIC 3168


Safe Work Australia, Nov 2015

“...in 2012-13 the cost impact of work-related injuries and illnesses was estimated to be just over $61 billion...�

State-of-the-art ergonomic lifting technology Lifetime Australia phone support AS/NZS 4443:1997 & ISO 11064

+61 3 9574 8044

sales@activconsole.com


CONTENTS104

COVER STORY: CAVEAT EMPTOR – THE CHALLENGE OF GREY IMPORTS

052 032

As the quest for cheaper and cheaper prices continues to drive the race to the bottom within the security industry, the issue of grey or ‘parallel’ imports continues to grow. We look at why the grey import market is a problem in Australia for manufacturers and distributors, as well as the dangers grey imports pose to installers and end-users.

SECURITY RISK MANAGEMENT: INEFFECTIVE AT BEST, DANGEROUS AT WORST Since the late 1990s, the protective security services of both government and private sectors have been motivated by the belief that the implementation of risk management and security risk management practices will reduce the likelihood of criminal attacks. But do they?

058

HONOURING OUTSTANDING PROFESSIONALS Now in its sixth year, we look at the outstanding individuals and their achievements recognised at this year’s Australian Security Medals Foundation gala dinner.

060

A STRATEGIC APPROACH TO PHYSICAL SECURITY When designing a new security system, what factors should drive the design process?

068

WHAT EXECUTIVE PROTECTION PERSONNEL REALLY THINK Clive Williams, one of Australia’s leading international counter-terrorism and security commentators, sheds light on what the close personal protection (CPP) teams really think about the people they protect based on his interactions with some of the leading CPP teams from around the globe.

084

INDUCTIVE OBSERVATION: PART 1 Experienced security director, consultant, trainer, operator and business developer Ami Toben looks at how security operatives can apply surveillance observation skills to their own security.

004 SECURITY SOLUTIONS


THE ALL-NEWTXF-125E BATTERY OPERATED QUAD BEAM Introducing the eagerly anticipated TXF-125E; a high performance Quad Beam sensor designed for battery operation - perfectly suited for rapid deployment in creating temporary or permanent secure perimeter intruder systems. With 4 selectable frequencies, multiple beam sets can be used without crosstalk, whilst adjustable detection distance allows a single beam set to be re-deployed in a variety of installations throughout its operational life. Two 3.6V (17Ah) batteries power each unit for up to 5 years of service.

NEW!

ACTIVE IR BEAMS The ultimate in trouble free perimeter detection for distances up to 200m outdoor / 400m indoor.

+61 (3) 9544 2477

email: oz_sales@takex.com

HIGH-MOUNT PIR Triple mirror optics for maximum detection performance at 2 to 6m.

BEAM TOWERS Rugged floor and wall mounted enclosures in 1/1.5/2/3m heights.

INDOOR PIR Spot, 360°, wide angle, and curtain detection from 2 to 4.9m height.

OUTDOOR PIR Hard-wired or battery operated outdoor PIR up to 180° x 12m .

1300 319 499 csd.com.au www.takex.com

TAKEX AMERICA SECURITY SOLUTIONS 005

VIC: Mulgrave, Tullamarine NSW: Northmead, Waterloo ACT: Fyshwick QLD: Loganholme SA: Marleston WA: Balcatta


CONTENTS104 010

LETTER FROM THE EDITOR

012 LEADERSHIP How do you determine a good leader versus a bad leader?

014

036 ALARMS We look at future opportunities for control room technology and service providers.

CYBER SECURITY Are mobile payments more secure than traditional credit card and online payments?

040

OPERATIONS Richard Kay looks at the basics of courtroom survival.

016 RESILIENCE How resilient is your organisation to external risks and

044 CCTV How can ergonomically designed control rooms increase

018

HUMAN RESOURCES Why is it important that we build learning and

048

BUSINESS Why do most attempts to attract women to cyber security

development capacity in the security industry?

roles actually achieve the opposite?

productivity?

shocks?

020 RISK MANAGEMENT Is risk psychology important?

072 AVIATION Reflections on changes in aviation security.

024 LEGAL We revisit the principals of arrest.

076 ACCESS CONTROL Why is the global access control market growing

026

everywhere except in the Asia-Pacific region?

THINKING ABOUT SECURITY What is the cost of security?

028 EVENTS A look at upcoming industry events.

032

080

PROFESSIONAL DEVELOPMENT Part three in our special series on detecting deceptive behaviour.

060

068

088

SECURITY STUFF

106

PRODUCT SHOWCASES

090

SPOTLIGHTS

110

SHOPTALK Company announcements from within the industry.

100

PROFILES

006 SECURITY SOLUTIONS


SOLUTION 007


www.securitysolutionsmagazine.com

Editorial Editor: John Bigelow john@interactivemediasolutions.com.au Sub-Editing: Helen Sist, Ged McMahon

Contributors: Gary Barnes, Jason Brown, Greg Byrn, Rod Cowan, Vlado Damjanovski, Kevin Foster, Tony Haddad, David Harding, Elly Johnson, Morris Johnson, Richard Kay, Blake Kozak, Steve Lawson, Callan Lyons, Joke Noppers, Rita Parker, Daniel Pinter, Alex Richardson, Ami Tobin, Clive Williams, Don Williams, Tony Zalewski.

Advertising keith@interactivemediasolutions.com.au Phone: 1300 300 552

Marketing & Subscriptions admin@interactivemediasolutions.com.au $62.00 AUD inside Aust. (6 Issues) $124.00 AUD outside Aust. (6 Issues)

Design & Production Graphic Design: Jamieson Gross graphics@interactivemediasolutions.com.au Phone: 1300 300 552

Accounts accounts@interactivemediasolutions.com.au Phone: 1300 300 552

Publisher

Interactive Media Solutions ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au Disclaimer The publisher takes due care in the preparation of this magazine and takes all reasonable precautions and makes all reasonable effort to ensure the accuracy of material contained in this publication, but is not liable for any mistake, misprint or omission. The publisher does not assume any responsibility or liability for any loss or damage which may result from any inaccuracy or omission in this publication, or from the use of information contained herein. The publisher makes no warranty, express or implied with respect to any of the material contained herein. The contents of this magazine may not be reproduced in ANY form in whole OR in part without WRITTEN permission from the publisher. Reproduction includes copying, photocopying, translation or reduced to any electronic medium or machine-readable form.

RS A DE VI

SSOCIATI

ON

ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au

O

SECURIT Y

PR

RALIA LTD UST FA

O

Written Correspondence to:

Or i g i n a l Si z e

O C I AT I

ON

Y P R OVI D

RIT

CU

D LT

SE

PR O

ASS

SPAAL

AU S T R A L I A

STRALIA LTD AU

SECURITY

RS

OF

E

Official partners with:

SSOCIAT IO N

OF

RS A DE VI

blue colour changed to this colour green.

COPY/ARTWORK/TYPESETTING APPROVAL Please proof read carefully ALL of this copy/artwork/typesetting material BEFORE signing your approval to print. Please pay special attention to spelling, punctuation, dates, times, telephone numbers, addresses etc, as well as layout.It is your responsibility to bring to our attention any corrections. Minuteman Press assumes no responsibility for errors after a proof has been authorised to print and print re-runs will be at your cost. Signed.................................................................. Date........................

008 SECURITY SOLUTIONS


GAIN CONTROL WITH ONEVIEW Defuse situations quicker with a truly unified security control room solution Saab’s OneView is a next-generation physical security information management integration platform that provides unprecedented levels of subsystem integration in mission-critical infrastructure environments. OneView empowers operators to respond effectively and efficiently to the most stressful situations. Offering accurate intuitive situation awareness, a simple operator interface, fast detection-response and comprehensive support for post action analysis, OneView is the ultimate choice for modern surveillance and security operations. You can rely on Saab’s thinking edge to bring your control room under real control. saab.com/australia

SECURITY SOLUTIONS 009


LETTER FROM THE EDITOR

The security industry faces a number of significant challenges in Australia, many of which appear to stem from a never ending ‘race to the bottom’ as end-users and consumers seek to drive prices lower and lower. While we have touched on this subject in previous issues of the magazine, it appears things are only getting worse, not better. Providers of security services and personnel are finding markets more and more competitive as end-users require tighter and tighter margins. This translates to low wages for guards and personnel, which in turn impacts the ability of the industry to attract new personnel. Similarly, in the electronic security market, manufacturers, wholesalers and distributors are feeling the pinch as integrators and end-users continually push for lower prices on product and projects. Not surprisingly, in an effort to find lower prices while maintaining higher margins, many integrators and installers are turning to the internet to purchase product online. However, much of this product falls into the category of ‘grey imports’, which might seem like a great idea at the time, but comes with significant risks to the people importing, installing and using the product. In this issue’s cover story, we examine the challenge of grey imports in the Australian security market, along with the implication of these imports for the people selling, installing and using them. We speak to a number of industry experts about the dangers of grey imports and their potential risk to not just the industry, but also to end-users. If you have ever thought about buying security product from the internet, if you have installed product purchased from the internet or, as an end-user, you have never asked exactly where your security products have come from, then you need to read this issue’s cover story – you might well be sitting on a ticking time bomb.

John Bigelow Editor

010 SECURITY SOLUTIONS


REGULAR

LEADERSHIP The Leadership Game By Jason Brown

In a previous article in this series, I identified the need for leaders to have the ability to: • communicate effectively • recognise the developmental requirements of team members • set goals and motivate the team to achieve them • provide enthusiastic and creative encouragement • model acceptable behaviour. In the last article, I provided the model for the leadership game. As readers may recall, this game is part of the process I used in the development program for middle ranking staff. It was aimed at getting them to examine the leadership behaviours of previous bosses they had experienced and write these down on the four-part framework. In the top left-hand quadrant, participants wrote down the negative professional/technical behaviours of their worst boss/bosses. Here is what they came up with: • Worst Boss Technical Capacity – did not have competence in key areas, blames others for his mistakes, blames you for mistakes, fails to provide clear instructions, misunderstands requirements, claims your work as his to cover up his failings, provides inadequate resources, and so on. In the top right-hand quadrant, participants wrote down the positive professional/technical behaviours of their best boss/bosses. Here is what they came up with: • Best Boss Technical Capacity – expert in his field, passes on knowledge, provides training, keeps up with latest issues, effectively interprets and passes on directions, explains complex

012 SECURITY SOLUTIONS

issues, provides clear instructions, and so on. In the bottom left-hand quadrant, participants wrote down the negative personal behaviours of their worst boss/bosses. Here is what they came up with: • Worst Boss Personal Behaviour – a verbal or physical bully, a liar, lazy, ignores requests, negative, plays favourites, often unexplained absences, and so on. In the bottom right-hand quadrant, participants wrote down the positive personal behaviours of their best boss/bosses. Here is what they came up with:

• Best Boss Personal Behaviour – always has time to help with problems, praises when praise is due, provides training and development, keeps the team safe, tells it how it is, and so on. So, which boss do you want to work for? Which boss do you want to be? And now for the private part of the exercise. Draw up your own matrix and plot out your behaviours in the boxes. Be honest. Decide who you are and what sort of boss (person) you want to be.


PR N O EW D U C T!

For over 30 years Perimeter Systems Australia has been delivering Perimeter Intrusion Detection Systems (PIDS) to Critical Infrastructure, Government, Industrial and large Commercial customers.

The latest threat to security, just got [detected]

Features • • • • •

360° Asymmetrical Detection 1,000 metre detection Radius Radio Frequency Detection Drone and Operator GPS Coordinates Integrates with existing systems

Palmgrove Business Park, D413-15 Forrester St. Kingsgrove NSW info@perimetersystems.com.au | www.perimetersystems.com.au

In the wrong hands drones literally add a new dimension to eavesdropping and spying on facilities, individuals and infrastructures in a wide variety of environments and industries. They have the power to shrink the realm of public safety, privacy and physical security. Few other technologies have this much power.

Call us on (02) 9150 0651 or visit www.perimetersystems.com.au SECURITY SOLUTIONS 013


REGULAR

CYBER SECURITY Are Mobile Payments More Secure Than Traditional Credit Card And Online Payments? By Garry Barnes Mobile wallet tokenisation technology is hard to hard, but industry is still sceptical. With the recent Google launch of Android Pay in Australia, it is a good time to explore current perceptions around mobile payment technology and whether the technology is proving more secure than traditional credit card payments and online e-commerce sites. Due to numerous cyber hacks and data breaches of payment cards, IT professionals and consumers are cautious about mobile payments, with research showing that the perception is that mobile payments are risky. The results of ISACA’s 2015 Mobile Payment Security Study (2015) show that 87 percent of cybersecurity professionals expect to see an increase in mobile payment data breaches over the next 12 months, and only 23 percent believe that mobile payments keep personal information safe. Additionally, a 2015 study of payment industry executives in the Americas, Europe and Asia Pacific by Edgar, Dunn & Company (2015) and Payments Cards & Mobile (2015) reports that 66 percent of those surveyed believe that security is the biggest concern with mobile and online payments in the future. Despite these doubts, global IT association ISACA recently published new guidance noting that mobile payment is significantly more secure than most people believe. Additionally, the global number of mobile payment users continues to grow, according to Ovum. In 2014, there were 44.55 million users and that number is expected to reach 1.09 billion users by 2019. Of this, it is predicted that 939.1 million will be using near field communication (NFC) technology – the technology that makes in-store payment as easy as a tap for these mobile device users (Zoller, 2016). Mobile payment security technology has improved since it was first developed. The advent of technologies such as tokenisation, device-specific cryptograms and twofactor authentication are advancements the industry has made. This article will focus

014 SECURITY SOLUTIONS

on tokenisation technology, since it is the current security solution that is pushing mobile payments ahead of card payments in protecting consumers’ financial information. Tokenisation is the use of secure mobile payment applications or mobile wallets that do not transmit a card’s primary account number (PAN) and personal information, but replaces it with a randomly generated ‘token’ to the payment network. Because the token is not the PAN, the token deters fraud if the payment transmission is intercepted and stolen. Only the issuing bank and authorised entities can securely map tokens back to their original payment card data. PAN and other payment card data are never used during a mobile payment. The mobile wallet sends a token and a device-specific cryptogram to the point-of-sale (POS) terminal for a payment transaction. The device-specific cryptogram ensures that the payment originated from the cardholder’s device. Therefore, if a hacker obtains mobile payment transaction data, it is unforgeable and useless. A hacker can never translate the token into a PAN because the token is a random number that cannot be mathematically reversed. The hacker cannot use the token in a transaction because the device-specific cryptogram that is sent to the POS terminal with a token cannot be used on another mobile device. If a transaction is intercepted, the token can only be used once, with the same wallet application, device and merchant store. Traditional payment at a store or online can be compromised through theft or loss, card tampering, transaction spoofing, recording/ skimming magnetic data and copying card verification codes. In each of these attack opportunities, most modern mobile payment systems have some advantages. For example, because NFC technology is used rather than a magnetic stripe reader, the ability for a nefarious party to use a ‘skimmer’ to record the PAN does not apply to mobile payments and is relative to only a physical

card transaction. Or, if a mobile device is lost or stolen, the mobile device can potentially be remotely erased. Since the consumer’s payment card information is not on the mobile device, the payment cards do not need to be replaced. Businesses also benefit from mobile payments since the enhanced security should lower overall costs resulting from theft. It also allows businesses to integrate loyalty programs into the mobile payment system, further up-selling and increasing data collection. As with any new technology, mobile payments add value and risk to an enterprise, and both must be understood to make a holistic risk decision about the technology, including regulatory compliance and the required protection mechanisms for cardholder data that are stored, processed or transmitted. Tokenisation is the current solution to keep payment card data and transactions safe, and should allay business and customer fears around using mobile devices for mobile payments. However, criminals can be expected to search for ways to attack tokenised payment systems; therefore, the payment card industry must continue to be diligent in creating innovative security technologies for protecting mobile devices and payment transactions. For more detailed technical guidelines around mobile payments, ISACA has launched a white paper Is Mobile the Winner in Payment Security?, which can be downloaded free of charge at www.isaca.org/mobile-payments

For a full list of references, email admin@interactivemediasolutions.com.au Garry Barnes is practice lead, Governance Advisory at Vital Interacts (Australia). He has more than 20 years of experience in information and IT security, IT audit and risk management and governance, having worked in a number of New South Wales public sector agencies and in banking and consulting.


SECURITY SOLUTIONS 015


REGULAR

RESILIENCE External Risks And Shocks – How Resilient Is Your Organisation? By Dr Rita Parker The fact that today’s businesses are global is not news, but the extent of the globalisation of trade and commerce – and the risks it presents – are far from understood. In an increasingly interdependent world, organisations are often on the frontline when it comes to systemic shocks, catastrophic events or unanticipated political upheaval. The recent Brexit referendum in the United Kingdom produced a far from united outcome, with global repercussions of uncertainty and risk. Whether it is political and policy uncertainty, abrupt currency shifts, energy price shocks, cyber attacks, sudden changes in supply arrangements or unexpected staff absences due to pandemic health issues, there is an implicit demand that organisations are resilient to global risks. Organisations need to have the ability to anticipate, to adapt and recover from shocks, whether local or global in origin. The resilience of any individual business depends heavily on the resilience of its suppliers and purchasers, particularly when those supply chains span many countries. From environmental to economic and political risks, companies are vulnerable even if they have no immediate presence in the geography where the risk arises. For example, following the Fukushima Daiichi nuclear disaster in 2011, although just three percent of total companies were directly affected, this figure increased to 50–60 percent for secondorder companies and to 90 percent for third-order companies. After the Brexit referendum, UK companies immediately faced higher import costs as the pound sterling dropped in value against other currencies to a lower point than at any time during the global financial crisis. Workers also saw a corresponding reduction in their buying

016 SECURITY SOLUTIONS

power for imported goods from Europe. It raises the question of how many organisations had or have plans in place for such an outcome. Clearly, businesses need to strengthen their planning capacity to analyse complex and often uncertain interdependencies – even if the uncertainties seem unlikely – if they are to build resilience to external and global risks. In particular, scenario and emergency planning are essential attributes. To assess and evaluate an organisation’s resilience to global and other risks requires defining such risks in their most appropriate organisational context. It is important here to understand the qualitative distinctions among the types of risks that organisations face. Drawing on the work of Harvard Business School Professors Robert Kaplan and Annette Mikes, three types of risks need to be distinguished: 1. Preventable risks, such as breakdowns in processes and human error. 2. Strategic risks, which are undertaken voluntarily after weighing them against the potential rewards. 3. External risks, which are beyond one’s capacity to influence or control. As noted by Kaplan and Mikes, the first two types of risk can generally be approached through traditional risk management methods, focusing mostly on organisational culture and strict compliance with regulatory, industry or institutional directives. Such approaches contribute to the overall resilience of an organisation. However, given the exogenous nature of external risks, cultivating resilience is the preferred approach for this last type of risk. Two questions can help to categorise risk and to identify a way forward. First, how predictable is its likelihood and potential impact, and how

much is known about how to deal with it? If it can be predicted and a lot is known about it, such as where it emanated, specific strategies can be identified to anticipate the risk, mitigate its effects and minimise losses. However, it is not as straightforward when risks are difficult to predict and/or where there is little knowledge about handling such risks. The lack of preparedness in the UK for a majority ‘leave’ outcome of the Brexit referendum is staggering and demonstrates the lack of foresight and lack of planning to maintain the resilience of commerce, trade, the community and government. It is a salutary lesson for all organisations to be resilient by having the ability to anticipate, to adapt and recover from local or global risks – in all of their forms.

Dr Rita Parker is a consultant advisor to organisations seeking to increase their corporate and organisational resilience and crisis management ability. She is an adjunct lecturer at the University of New South Wales at the Australian Defence Force Academy campus where she lectures on resilience and nontraditional challenges to security from non-state actors and arising from non-human sources. Dr Parker is also a Distinguished Fellow at the Center for Infrastructure Protection at George Mason University Law School, Virginia, USA. She is a former senior advisor to Australian federal and state governments in the area of resilience and security. Dr Parker’s work and research has been published in peer reviewed journals and as chapters in books in Australia, Malaysia, the United States, Singapore and Germany, and presented at national and international conferences. Rita holds a PhD, MBA, Grad. Dip., BA, and a Security Risk Management Diploma.


SECURITY SOLUTIONS 017


REGULAR

HUMAN RESOURSES Building Learning And Development Capacity In The Security Industry By Greg Byrne This article focuses on the importance and necessity of the security industry in Australia increasing the capability of its people through

To increase L&D capabilities, the challenge is to build momentum in the L&D environment and to shift attitudes of individual employees who may

and be aware that public police forces are moving to full professionalisation, which could halt the expansion of private policing. To ensure this does

learning and development (L&D). Companies are not being told how they should train their

not see the benefit of upgrading a Cert III to a Cert IV, or a Cert IV to a Diploma. However, if the

not happen, the industry needs to stay in front of the learning curve, maintain growth in L&D

staff and what they should train them in because

industry and individual companies are to attract

investment and ensure continued allocation of

each company’s training needs are different. The intent is to discuss the importance of individual

and retain staff, to be an employer of choice, and to continue to grow and expand, the security

sufficient funds. Research shows high-performing organisations

enterprises and the industry as a whole in increasing L&D capability.

industry must find a way. L&D must become part of business planning to ensure it aligns with

align and integrate L&D initiatives with corporate and business planning through:

company and industry needs.

• integrating learning programs into corporate

There are many strategies individual businesses and the industry can follow to overcome some of these challenges, including: • Writing training targets into business plans. This does not just include measuring the number of staff who have been trained or who have increased their qualifications, but also to evaluate the effectiveness of this enhanced knowledge. • Integrating people and business planning. The obvious way of doing this is through the HR manager or the establishment of a Chief Human Resource Officer (CHRO) position. This is more than just rebranding the HR manager, but an entire re-build of the role in much the same way the company accountant was re-built into the CFO in the 1980s. • Increasing capacity and devolving accountability to line managers, so they are more adaptive, creative, innovative and target focused.

plans • developing corporate culture to support learning programs and ensuring cultural barriers are broken down • ensuring managers invest in and are accountable for learning and development • generating a focus on the business application of training rather than the type of training and considering appropriate learning options • de-emphasising classroom training and ensuring consistency with adult learning principles to allow staff time to process what they have learned on the job • evaluating L&D formally, systematically and rigorously.

Increased L&D capacity is vital to improved industry performance and requires commitment from all levels of individual companies and the industry as a whole. If done right, it will put the right people with the right skills in the right place and maintain the growth in the Australian security industry at current levels. Staff and increased competition in the private and public security sectors are the key drivers of L&D in the security environment in Australia. Australian police forces, who historically shouldered the burden of public safety, are increasingly being confronted and challenged by a more professional and growing private security industry. Maintaining growth and relevance in the face of increased professionalisation of state and federal law enforcement agencies will require a concerted effort from the security industry as a whole. L&D encompasses a broad range of activities designed to improve the capabilities of people. Capabilities comprise not only technical skills and knowledge, but also attributes, attitudes and behaviours. L&D activities can be designed to deliver specific competencies in a short period of time to meet an immediate need, or to achieve broader requirements over a longer period. Activities to enable people to acquire new capabilities can include on-the-job training, development opportunities, such as special projects, conferences, secondments and mentoring, as well as formal classroom training.

018 SECURITY SOLUTIONS

Law enforcement agencies in Australia acknowledge the growing professionalisation of the Australian security industry. They are also aware that private policing is pluralising law enforcement in Australia and that this pluralisation is due to the increased levels of education in the Australian security industry. However, it is important for the industry to maintain the edge

Greg Byrne is the Managing Director of Multisec Consultancy Pty Ltd. He lectures part-time at the Western Sydney University for an undergraduate diploma in policing and is a sub-editor for and board member of the Australian Police Journal. His academic qualifications include Master of Management, Diploma of HR, Grad Cert in Leadership and a Diploma a Security Risk Management. Greg can be contacted via email greg@multisec.com.au


Contact us on 1300 364 864 Follow us on

Delivering Proven Solutions for Security & Safety We Protect People & Assets SECURITY SOLUTIONS 019 www.magneticautomation.com.au


REGULAR

RISK MANAGEMENT Is Risk Psychology Important? By Dr Kevin J. Foster

I first started developing security risk assessment models in the late 1980s. Prior to that time, in the national security sphere, there were set ways of assessing risks, usually based on a known threat (Australia’s Cold War enemies) and clearly identified vulnerabilities to that threat. As far as national security was concerned, the consequences of the enemy accessing state secrets was always considered unacceptable. The definitions of classified material provided the description of the consequences of concern in the risk equation. For example, the International Dictionary of Intelligence defined the consequences of unauthorised disclosure of ‘Top Secret’ material (including information) as those that would cause exceptionally grave damage to the nation. Many countries, including Australia, had similar definitions in their security policies. In Australia, espionage was a major focus of risk assessments at the national level, and at facilities important for national security operations. While there had been some terrorist incidents in Australia before the late 1980s, there was a general perception that the threat from terrorism was not high. However, the first gulf war (1990– 91), and Australia’s involvement, raised some feeling in some parts of the Australian community which led to some people believing the threat of terrorism in Australia was rising, possibly rapidly. Security decision making became a little confused in the post Cold War era. However, it was clear by the early 1990s that the terrorism threat, at least in Australia, was generating more fear or dread than the threat of espionage.

020 SECURITY SOLUTIONS

Terrorism, like any violent crime, has very personal consequences, very well understood by everyone; whereas espionage has consequences that are a little harder to understand for those who have little knowledge of what goes on in the secret operations of governments. Psychologists such as Daniel Kahneman and Amos Tversky had been studying risk decision making since the 1970s. They identified a number of biases that influence how people perceive risk and make decisions involving uncertainty. Their prospect theory led to a Nobel Prize in 2002 for Kahneman. Sadly, Tversky had died in 1996. The biases they identified are easily recognisable today, but I rarely hear security or enterprise risk professionals expressing an understanding of these biases. Another group of psychologists that improved the industry’s understanding of how people make decisions about risk were Paul Slovic, Baruch Fischhoff, Sarah Lichtenstein and their colleagues. In 1981, they wrote a book entitled Acceptable Risk, in which they described the research necessary to improve the way experts and lay people make decisions about risk. In that year, there was a conference that specifically addressed ‘The Analysis of Actual Versus Perceived Risks’. Slovic, Fischhoff and Lichtenstein put forward a very strong argument that the distinction between actual and perceived risk is misconceived. They proposed the view that “although there are actual risks, nobody knows what they are. All that anyone does know about risks can be classified

as perceptions.” Some of the work they did was very relevant to security risk analysis. To this day, I still hear clients and some security professionals asking their risk analysts to assess the real risks, not the perceived risks! When I am asked to do this, I always tell my client that all risks are perceived. If I knew what was actually going to happen in the future, then I would be describing future facts not risks. In their paper Facts and Fears: Understanding Perceived Risk (1980), Slovic, Fischhoff and Lichtenstein described their two-factor model, which showed how lay people’s perception of risk, or their response to it, is determined by certain risk characteristics. This model was described in a number of later papers and one of these well worth a read is Perception of Risk (Slovic, 1987 in Science, Volume 236). This psychometric model of risk perception shows that when lay people (not experts) make decisions about risk they are not very concerned about the statistical probability of the risk event. They are more concerned about the dread which they may perceive is associated with the risk, whether the risk is understood by them or not. For example, if there is a low level of dread associated with the consequences, and the risk is believed to be well known, then high risks may be deemed acceptable. People who engage in high-risk activities, such as dangerous sports, understand this well. In business, if there is a significant payoff and the risk is believed to be well understood, then that risk may be accepted, even if there is a relatively high probability of failure.


SPEND LESS ON VIDEO SURVEILLANCE STORAGE

SO YOUR CLIENTS CAN SPEND MORE ON OTHER TOOLS

Quantum’s multi-tier storage solution provides total usable capacity for less of the overall budget, allowing your clients to invest more in cameras, retention times, and analytics.

See us at Security Expo Melbourne 20-22 July, Booth F36 Find out more from Quantum ANZ: ANZsales@quantum.com or 1 800 999 285 (Aus) or 0800 105 999 (NZ) www.quantum.com/video-surveillance © 2016 Quantum Corporation. All rights reserved.

SECURITY SOLUTIONS 021


REGULAR

RISK MANAGEMENT

Buying a lottery ticket is another example where a high probability of loss of the investment may be accepted because there is a perception that the benefit of winning outweighs the risk of losing. A second type of psychometric risk might be one where there is no dread attached to the outcome, but the risk is not known very well. For example, most people use a microwave oven in their kitchen without attempting to understand the risk involved, not even using a microwave leak detector to check the safety of the device. In this case, there is no particular interest in trying to understand the risk. In security, this is often the case in the world of espionage, especially in a business environment. The threat may be hard to assess and be not well known. If the consequences are not obvious then decision makers may not be too concerned and may choose not to spend sufficient resources on the protection of information assets. A third type in the scheme is when the risk is not well understood but there is a high dread attached to the consequences. These risk types are often manifested as societal risk issues such as religious intolerance, immigration from culturally different parts of the world, or in the Brexit example, perhaps a fear that UK sovereignty was being lost to the European Union. The fourth and most unacceptable type of risk is one where the dread factor is high and people believe they do understand the risk. Terrorism and violent crime are examples. In this case, people will have extreme views about the unacceptability of the risk and, in some cases, will have extreme responses. In practice, risk perceptions can change as knowledge increases. For example, a low dread unknown risk can evolve into a high dread known risk as information becomes available through news channels and social media. Sometimes the

022 SECURITY SOLUTIONS

While there had been some terrorist incidents in Australia before the late 1980s, there was a general perception that the threat from terrorism was not high.

dread increases through awareness campaigns. Therefore, the acceptability of the risk changes even though the likelihood and consequences may remain static! Much research into the psychological aspects of risk decision making has been completed in more recent years and the topic is becoming better known in Australia; however, it has been well known in the US and Europe for the past three decades. While Australia was a leader in the development of risk management standards, arguably Australia has been slow to recognise the psychological factors in risk management. In short, the standards in use (written by experts) tend to ignore how risk decision making actually occurs and instead specify what an ideal objective decision system might be like. Perhaps Slovic et al were right when they said that lay people and experts are solving different

problems, talking different languages and see facts differently. For security professionals, the lay people are often the generalist managers that they advise. Many security professionals want to present objective (evidence-based) risks, whereas the generalist managers only want to address the risks they perceive as dreadful. There is still much to learn about the psychology of risk!

Dr Kevin J. Foster is the managing director of Foster Risk Management Pty Ltd, an Australian company that provides independent research aimed at finding better ways to manage risk for security and public safety, and improving our understanding of emerging threats from ‘intelligent’ technologies.


S K Y H AW K FOR VIGILANT SURVEILL ANCE

L E A R N M O R E AT S E A G AT E . C O M / A U

SECURITY SOLUTIONS 023


REGULAR

LEGAL Arrest: The Principles Revisited By Dr Tony Zalewski It is well accepted across the security industry that arrest of perpetrators in and around the workplace occurs infrequently, except for those involved as covert operatives in the retail sector. However, as arrest can occur in or around any workplace and it is a high-risk activity that can involve use of force, it is important that principles associated with arrest are revisited and understood. Security professionals are generally familiar with justifications to arrest, albeit there are some operational considerations supported by law that should be known. Some recent cases have highlighted relevant considerations for arresting security officers. This article consolidates the general principles as applied to arrest by security officers. Each Australian state and territory has legislative authority for arrest with a process that applies to what is commonly termed a ‘citizen’s arrest’. Security officers rely on this legislative authority in making arrests. Of course, it must be remembered that security officers have no more authority than any other citizen to make an arrest, albeit industry training means intervening security officers have a distinct advantage due to their higher level of competency. For example, security officers generally understand they are not authorised to make an arrest based upon suspicion or an uncorroborated complaint of another, that a particular offence has been committed rather than some general offence, and not to use more force than is reasonably necessary to complete the arrest. The common law also assists further in understanding requirements for arrest, of course assuming a lawful arrest has been effected and any power exercised by the arresting officer has not been exceeded. A lawful arrest has been effected if: • the arrested person was deprived of his or her

024 SECURITY SOLUTIONS

liberty; that is, the person has been detained or confined in some way (it is not necessary that an arrested person is actually seized or subjected to physical force); • the arrested person was informed he was under arrest prior to, at the time or as soon as possible after the arrest; that is, it is not always possible to use formal words of arrest where there is excessive violence, an immediate attempt to abscond, the person does not speak English, is affected by alcohol or drugs and the like. However, any communication must align with all that a reasonable person in the circumstances would do to inform a person he is under arrest; • the arrested person was informed of the general reason for the arrest; that is, for theft, assault or the like. It is not necessary to use technical or precise words. If the requirements listed above are not satisfied, then the arrest will be unlawful. An unlawful arrest can result in an action for damages through torts such as assault, battery and false imprisonment. Security leaders should ensure this high-risk area of work is regularly reviewed within the relevant system of work. Activity should include: • Review and enhance where required the organisation’s protocols, such as standard operating procedures relating to use of force and arrest. This should include version controls, relevant dates and a clear history of any protocol enhancements. • Delivery of induction and professional development training to reinforce pre-licensing and any earlier training. Such induction and further training must include more than the operational security officer merely reading protocols and the like. There should be some practical delivery and assessment to ensure operational staff clearly understand their responsibilities in this high risk area. Assessment also confirms and provides evidence of competence.

• Maintenance of organisational records that disclose induction and professional development training that includes duration, method of delivery and method of assessment to determine an appropriate level of competency. • Regular review of the work system against incident reports involving arrest. To minimise the risk of operational errors and therefore potential future claims against the organisation, it is important the formal approach listed above is adopted. Careful thought given to issues relative to arrest in any workplace is essential. All staff, irrespective of their experience and qualifications, should proceed through the organisation’s training and assessment strategy. The fact an experienced operative has been recently engaged by an organisation does not guarantee his competence in this high-risk area of work. As many experienced security leaders understand, competence and experience do not necessarily go hand-in-hand, hence the importance of training, re-training and system review. Security leaders adopting this formal approach will minimise workplace problems and related issues in this area of security operations.

Dr Tony Zalewski is a Director of Global Public Safety and a forensic security specialist with qualifications in law, criminology and the social sciences. He provides advice and training to governments and the private sector in Australia and abroad on matters relating to operational risk, security and safety. He is also an expert with practical experience in some of Australia’s leading civil actions involving security and safety.


Why do you have to do a strange dance to try and open a door?

Instinctive technologies for a world without constraint

Card mode

Slide mode

Tap Tap mode

Remote mode

Hands free mode

Be STid, be smart Intuitive solutions for mobile access control

SECURITY SOLUTIONS 025


REGULAR

THINKING ABOUT

SECURITY

The Cost of Security By Don Williams

Security is expensive, particularly bad security. The following is an example from friends who attended an outdoor event as vendors where they had paid a considerable fee to trade until 5pm each day. On this occasion, at 4.30pm each afternoon, the hired security guards would start shepherding the patrons out the gates and quite forcibly advising the vendors that they had to stop trading by 5pm, including the food and beverage sites that were licensed until much later. The cost to the vendors was considerable. There was the lost sales for the last half hour of each day, as well as the lost sales to the other vendors that traditionally happened informally in the hour or so after the patrons left. The food and beverage vendors lost hours of trading. In addition, there was the attitude of the guards, which was reported as being rude and arrogant towards both patrons and vendors – hardly the image the organisers or vendors wanted to portray. The vendors apparently made their views about the guards known to the organisers and overheard some of the public commenting on the somewhat forceful manner of the security staff. It is possible, if not probable, that the majority of the guards were engaged until 5pm and that neither the organisers nor the provider wanted the guards on site for a minute longer. If this was the case, then the way the security contract was scoped, costed and implemented may have been economic in the short-term but expensive in the longer term.

026 SECURITY SOLUTIONS

The manner in which guards were employed cost the vendors real money and damaged their opinion of the event and the organisers. It may cost the organisers in the long-term as vendors consider whether the event is worthwhile next year, particularly with the aggressive security presence at what should be a family-friendly and welcoming experience. Elements that can affect the ‘value’ of security staff are attire and attitude. The attire of the security staff is important as it must reflect the image of the event. In an open, family-friendly activity, having security staff dressed in quasimilitary uniforms can detract from the whole visitor experience. Some years ago at a worldfamous circus, the guards wore military-style trousers and boots and stomped around the venue in a manner that might be compared to Stormtroopers. Their presence detracted from the experience and patrons were seen watching the security staff and even moving their children out of the way. The client can specify how the security staff will be dressed to support the image to be portrayed. Attitude is a matter of selection and training of the staff, over which the venue has little control. What the venue can control is an agreement

that security staff be personable, friendly and civil. The client should also be willing to review the staff provided and to request/insist any that do not meet the requirement be replaced. At another outdoor, family event the guards wore black, infantry-like uniforms complete with webbing belts and projected an aggressive attitude that was a magnet for the more unruly youths and which resulted in incidents that may have been avoided with a more appropriate attire and attitude. The immediate cost to demanding an appropriate security presence will be additional effort with the contract and possibly an addition to the hourly fee. The long-term return on investment is in happy patrons, happy vendors and a good reputation, leading to a desire to support future events. While security guards can be seen as an unwanted expense, poorly planned and provided security is more expensive.

Elements that can affect the ‘value’ of security staff are attire and attitude.

Don Williams CPP RSecP ASecM can be contacted via email: donwilliams@dswconsulting.com.au


MULTIPLE CAPABILITIES SUPERIOR SOLUTION

Volvo Group Governmental Sales Oceania

IN HOSTILE ENVIRONMENTS, IT’S IMPORTANT THE SYSTEMS THAT YOU DEPEND ON CAN

STAND THE TEST OF TIME.

At Volvo Group Governmental Sales Oceania, our core business is the manufacturing, delivery and the support of an unparalleled range of military and security vehicle platforms; a range of platforms that are backed by an experienced, reliable and global network with over one hundred years of experience

superior solutions, providing exceptional protected mobility SECURITY SOLUTIONS 027 www.governmentalsalesoceania.com


REGULAR

EVENTS ASIAL Awards For Excellence 20 October 2016 The Westin, Martin Place, Sydney Hundreds are expected to attend the prestigious awards ceremony and dinner to celebrate winners of the 2016 Security Industry Awards for Excellence and Outstanding Security Performance Awards (OSPAs). Media personality James O’Loghlin (from Good News Week, Rove Live, Sunrise, Lateline, The Evening Show and more than 300 episodes of The New Investors) is back by popular demand and will once again emcee the awards. The OSPAs is a worldwide scheme for recognising outstanding performers in the security sector. They have also been launched in Norway and Germany and other countries are about to follow. Australia is at the forefront. The OSPAs are supported by ASIAL, ASIS Australia and the Security Professionals Registry (although the OSPAs is independent of all groups) in an initiative that is designed to unite the security sector in celebrating the success of its outstanding performers. They are set to bring new life to security excellence. In this first year of the OSPAs, there are nine categories open to enter in Australia.

028 SECURITY SOLUTIONS

Total Facilities 29–30 March 2017 International Convention Centre Sydney They are: • Outstanding In-House Security Team • Outstanding In-House Security Manager • Outstanding Guarding Company • Outstanding Security Consultant • Outstanding Customer Service Initiative • Outstanding Security Training Initiative • Outstanding Security Installer • Outstanding Security Partnership • Outstanding Investigator Awards will be presented to winners between courses and James will provide light comedic entertainment. There will also be an opportunity to pose in front of the photo wall, have your happy snap taken by a professional photographer and network with other security professionals. Visit www.asial.com.au for more information.

Returning to Sydney with an exciting new proposition, Total Facilities now unites both facilities and workplace professionals in the ultimate industry destination for the built and work environment. Held annually between Sydney and Melbourne, TFX is Australia’s largest learning and networking event for facilities and workplace management professions seeking solutions for creating more efficient, sustainable and productive facilities and workplaces. Total Facilities is comprehensive and efficient in its delivery and provides real solutions to every day operational challenges by connecting buyers and sellers to source innovation, debate current issues, share insights and create opportunities for an invaluable community of professionals. Our vision We champion professionals who support the built and work environment with a sense of belonging and advocacy – the unsung heroes and behind the scenes forces. We will evolve and grow our offer year on year to:


Keeping access under control

Who has a key for the meeting room? Is Mr Smith already authorised to enter the warehouse? Who has the key to the workshop? How long was the external company and its trademen in the building? Kaba exos provides the answers to these and many other questions.

Kaba exos can control all access points and locking systems in your building. Kaba exos for enhanced security and efficiency.

T: 1800 675 411 www.dormakaba.com.au

SECURITY SOLUTIONS 029


REGULAR

EVENTS • bring new and leading solutions in operational efficiency to the market • deliver forefront trends for running more sustainable facilities and workplaces • foster a community of multidisciplinary professions to have a voice and achieve recognition • redefine the future of the industry and challenge traditional perceptions of facility management. For more information visit: www.totalfacilities.com.au

ISC West 5–7 April 2017 Sands Expo Centre, Las Vegas ISC WEST is THE largest security industry trade show in the U.S. At ISC West you will have the chance to meet with technical reps from 1,000+ exhibitors and brands in the security industry and network with over 28,000 security professionals. Find out about new and future products and stay ahead of the competition. Encompassing everything from access control to Facial Recognition software you are sure to find products and services that will benefit your company and clients. This year don’t miss our new IT Pavilion featuring the latest cyber security solutions. Working with SIA, ISC also features world class education to learn about every facet of the security industry. For more info on SIA Education@ISC visit: www.iscwest.com

030 SECURITY SOLUTIONS

IFSEC International 20–22 June 2017 ExCeL London The global stage for security innovation and expertise IFSEC International is the biggest security exhibition in Europe taking place over three days between 20 to 22 June 2017 at London ExCeL. IFSEC welcomes over 27,000 global security professionals to experience the latest technological innovations and hear from industry leaders – all under one roof, over three days. The event caters to everyone within the security buying chain from manufacturers, distributors, installers, integrators and consultants to end users. With over 600 exhibitors showcasing over 10,000 products, you will be able to find the perfect security solution your business is looking for. There’s more to it than just security. IFSEC International is co-located with FIREX International, Facilities Show, Safety & Health Expo and Service Management Expo, catered for those working across many platforms in building management and protection of people and information. For more information or to register please visit www.ifsec.co.uk

Security Exhibition & Conference 2017 26–28 July 2017 International Convention Centre Sydney We’re excited to be heading back to Sydney from 26–28 July, 2017 to the brand new International Convention Centre in Darling Harbour and the anticipation is palpable. Early bird registrations will get access to one off exclusive VIP Early Bird rates for the ASIAL Conference 2017. Get in early to take advantage of this special discount and avoid disappointment as the 2016 program SOLD OUT. By visiting the site and registering early, you will also be entered into the VIP Early Bird prize draw for your chance to WIN 2 tickets to the annual Security Gala Dinner PLUS one night accommodation including breakfast at the Novotel Darling Harbour. The Security Gala Dinner is the annual celebration of the industry’s successes and with this prize you can really make a night of it with overnight accommodation at the Novotel Darling Harbour in a Loft Suite with Harbour views. To register now visit securityexpo.com.au


032


SECURITY RISK MANAGEMENT: INEFFECTIVE AT BEST, DANGEROUS AT WORST

033


By David Harding

Since the late 1990s, the protective security services of both government and private sectors have been motivated by the belief that the implementation of Risk Management and Security Risk Management practices will reduce the likelihood of criminal attacks. Some states within Australia have actively enforced this concept through legislation, specifically requiring the acquisition of knowledge and the implementation of Risk Management practices within organisations. But do Security and Risk Management processes prevent or reduce the likelihood of attacks by criminal offenders? Do the specifically developed processes outlined in the Standards Australian HandBook HB 167:2006 actually work? This article will identify that implementing Security and Risk Management practices, especially those outlined in ISO 31000:2009, or its predecessors AS/NZS 4360:1999 and AS/NZS 4360: 2004, and the Australian Standards hand book HB 167:2006, does not lead to a decrease in crime. Instead, the article will show that where these standards have been implemented, crime rates increase. The concept of Risk Management and Security Risk Management is a well established discipline within the protective security services. For example, the Australian Government, through the Attorney General’s Department, promotes the Protective Security Policy Framework (PSPF). This framework requires all federal government agencies to apply Security Risk Management processes. These processes are outlined in the International Organisation of Standardisation (ISO) Standard ISO 31000:2009 and the Australian Standards Hand Book HB167:2006. Also, individual states require (sometimes through legislative enforcement) processes that those persons who provide consultative advice on protective security requirements, must have as a minimum knowledge of ISO 31000:2009, and HB 167:2006. For example, the NSW Security Industry Act of 1997 legislates that “a person who provides advice on security issues must have completed a Certificate IV Security and Risk Management course, to gain a licence”.

034

As can be seen from the above, Risk Management and Security Risk Management play an important role in determining the knowledge required to advise organisations on methods to prevent or reduce the likelihood of criminal attack. The Australian Standards Handbook HB 167:2006, states that Security Risk Management is a new paradigm, “which provides a means of better understanding the nature of security threats and their interaction at an individual, organisational, or community level”. Also, that Security Risk Management “has become a powerful tool in assisting prevention and management of the consequences of events that are often outside an ‘organisation’s’ normal understanding and experience”. As HB 167:2006 notes, “Security Risk Management introduces the concept of a person intentionally seeking to harm an organisation by deliberately seeking to overcome controls that are in place”. The above belief is also reinforced by government. For instance, in a Fact Sheet published by the NSW Justice Department, it is stated that current reductions in the incidents of robbery have been made possible due to the implementation of security risk treatment options such as quality locks on doors, irregular banking procedures and appropriate lighting. This belief is further reinforced with data provided by the Australian Institute of Criminology (AIC) which in the latest report ‘Australian crime: Facts & figures 2013’ found that there has been an overall reduction in crime rates across a variety of crime types. These rates, which include the incidence of robbery, have been generally falling since 2002. In addition the AIC, through the National Armed Robbery Monitoring Program (NARMP), monitors the incidence of armed robbery at a variety of locations such as Post Offices, pubs and licensed premises, private residences, and service stations. In the most recent publicly available report, the AIC identified that there is a general decreasing trend in the incidence of armed robbery across Australia. However, taking credit for the drop in armed robbery crime rates due to the implementation of Security and Risk Management practices

Government and private industry place significant emphasis and importance on the concepts of Security and Risk Management... may be presumptuous. Although general trends in crime rates have been reducing since the early 2000s, closer analysis of the crime types specifically targeted by Risk Management and Security Risk Management practices show an entirely different view. For instance, in commercial organisations there is a strong financial, and sometimes legislated, requirement to implement Security and Risk Management practices. Where these practices are implemented, it would be reasonable to expect a decrease in the incidence of crime. This would especially be the case where the ‘self-stated’ paradigm changing Australian Standards HandBook HB167:2006 is implemented. It would also be expected that the incidence of criminal attack at these locations would, at a minimum, mirror the downward trend seen in the general incidence of armed robbery. However, it is precisely the opposite trend that is occurring. At licensed premises, the implementation of security risk treatment options such as closed circuit television, additional security guards, strict cash handling procedures and controlled access to high risk areas is common. It would be reasonable to expect that with these mechanisms in place, the incidence of crime would decrease. In fact, and according to the NARMP, since 2004 the incidence of armed robbery at these locations has increased by approximately 20%.


Risk Management and Security Risk Management play an important role in determining the knowledge required to advise organisations on methods to prevent or reduce the likelihood of criminal attack.

Likewise in the case of service stations which have been a target of armed robbers since the 1980s. Although service stations have implemented such mechanisms as security guard patrols, surveillance systems and anti robbery screens, the incidence of armed robbery attacks has increased. The AIC’s latest publicly available data showing the increase to be around 30%. Finally, the Cash In Transit (CIT) industry. This industry, which has even undergone Industrial Relations Commission inquires, routinely uses security control mechanisms such as armoured vehicles, CCTV, and uniformed and covert security guards. It would be reasonable to expect that the incidence of armed robbery attacks would decrease since the implementation of Security and Risk Management practices. This should especially be the case with the implementation of AS/ NZS 4360:1999 in the year 1999. However, the AIC report ‘Cash in transit armed robbery in Australia’ identified that since the year 2000, and specifically following the implementation of Australian Standards AS/NZS 4360:1999, the incidence of armed robbery against CIT operations has increased by around 900%. There is limited available information that would provide evidence as to the reasons for these findings. However, if the organisations concerned followed the sometimes enforced implementation of processes outlined by ISO 31000:2009, its predecessors AS/NZS 4360:1999 and AS/NZS 4360:2004, and HB 167:2006, there should have been an increase in efficiency and effectiveness in risk treatment measures designed to prevent or reduce the likelihood of crime. At the very least, the implemented security risk treatments should reduce the incidence of crime to match the overall societal decrease in crime. This has not occurred. Statistically, if a large data population set, such as the overall armed robbery crime rates in Australia, indicated a decreasing trend, it would be reasonable to expect that smaller sub-data sets, such as armed robbery at service stations, CIT and licensed premises, would also indicate a decreasing trend during the same period. As identified above,

the deliberate utilisation of Security Risk Management risk treatment measures has not led to a decrease in the incidence of criminal attacks. In fact the reverse has occurred. Such opposing trends in subordinate population data is significant, and highlights a flaw within the structural methodologies of the practice of Security and Risk Management practice. This trend strongly suggests that the implementation of Security Risk Management processes is counter-productive to the aim of preventing or reducing the likelihood of criminal attack. In short, crime seems to be increasing specifically where Security and Risk Management is being implemented. Government and private industry place significant emphasis and importance on the concepts of Security and Risk Management and in some cases these concepts and methods have been legislatively enforced for use. However, the above research has identified the ineffectiveness of Security and Risk Management as a way and means to prevent or reduce the likelihood of crime. Given this identified ineffectiveness, it would seem appropriate for research to be conducted into more effective and directed methods to prevent and reduce the likelihood of crime. The above article is a brief outline of an academic essay published in the Australian Security Research Centre (ASRC). That essay titled ‘Security Risk Management: a dangerously over-rated and broken paradigm’, can be obtained by contacting the ASRC. David Harding has over 30 years experience working within government and private security fields, including service in the Australian Army’s Special Air Service Regiment, and the Australian Federal Police’s Air Security Officer Program. As Director of Anshin Consulting, David has conducted security operations across the Middle East, Asia and Australasia. This includes advising leading business persons and diplomats on non-state security threats. David holds a Masters degree, is a Registered Security Professional, and has researched, lectured, written, and blogged about international risk, threat and security management.

SECURITY SOLUTIONS 035


ALARMS

Future Opportunities For Control Room Technology And Service Providers 036 SECURITY SOLUTIONS


By Alex Richardson

The command and control room and public-safety answering point (PSAP) market is expected to grow at a compound annual growth rate of 7.1 percent, from $5.4 billion in 2015 to $7.6 billion in 2020. Major factors spurring market growth include national public-safety initiatives like FirstNet and NG911 in the US, technology integration and system interoperability, increased value placed on big data and analytics, and control room consolidation. While growth in the public safety sector – the control room market’s largest industry – has recently been stagnant, strong growth is expected over the next four years. It is evident that US public safety agencies are taking a wait-and-see approach with regard to FirstNet. Licensed mobile radio (LMR) infrastructure projects are slowing down, as agencies await further decisions on the national public-safety broadband network. There is an increasing interest in services related to these control rooms to optimise systems already in place and to expand existing capabilities with addon applications. Overall, the control room market has become extremely dynamic lately, because of the variety of suppliers competing and the range of technologies used within command and control rooms and PSAPs. Although voice dispatch and LMR infrastructure markets are currently experiencing slower growth, investment in computer-aided dispatch (CAD), geographic information systems (GIS), records-management software (RMS) and other systems is picking up, according to the IHS Markit Command and Control Intelligence Service. In the US, for instance, a number of public safety agencies have refreshed their CAD systems over the last two years as the technologies reached their end of life after 12 to 15 years in service. In India, by comparison, large states are placing an emphasis on regionally integrated CAD and GIS systems to improve emergency-response efficiency. Control room consolidation is a major trend that is affecting investment in new technologies. Especially in the US, agencies

attempting to manage increasing budget restrictions are helping foster consolidation to improve efficiency and enhance interagency interoperability. Consolidation depends heavily on the productivity metrics that a control room uses, which means the agency must evaluate call-taking and dispatching capabilities closely. A typical consolidation might include rolling up smaller city control rooms into a larger county or regional entity’s centre. For example, a state may have one mid-sized to large system with 20 seats, while three nearby towns might have just five seats each within their individual facilities. In a consolidation, the county would take in 15 seats on top of the existing 20 seats. However, the county might only increase its seat count to 32, thanks to actions taken to improve productivity. While consolidation may result in fewer individual emergency-response systems, consolidated systems are often larger and more advanced, requiring a greater investment in technologies and integration. Larger and more expensive consolidated systems provide significant operational benefits to end-users, in addition to financial benefits, because budgets can be shared across several stakeholder groups. The result is that revenue grows, because of a more complex and capital-intensive system. Physically combining the control rooms is not the only way consolidations occur. For example, Estonia has only four regional emergency response control centres, but the centres coordinate through one virtual control room. All centres use the same information systems and each has situational awareness over the entire country. Several agencies work within these facilities – including the employees of the emergency communications centres, police and border guard officials, who dispatch their respective resources. Similar structure is evident in other more developed countries across Europe. Across industries, IHS Markit has observed a convergence in control room functions. Where there were once

SECURITY SOLUTIONS 037


ALARMS

dedicated communications and security control centres, operators are now seeking to combine these capabilities. The CAD system is the focal point of this movement, paving the way for the integration of various forms of data. Video dispatching is now also becoming a reality, with trials taking place in Asia and Africa. It is evident that the dispatcher’s role is changing, as more data becomes available and GIS is used to visualise the location of this information. Big changes in emergency response are expected over the next 15 to 20 years, especially in the public safety sector. Not only will 911 become just another number, but Cloud, broadband networks and video surveillance are also spurring changes in control rooms, offering huge growth potential to the market. While growth in voice dispatch and LMR technology markets will be influenced by the traction of public safety broadband networks, other market forecasts for CAD, GIS, RMS, 911 call-taking software and other technologies are very favourable. Further integration of video surveillance into emergency response systems – and the increased access of live and recorded video by dispatchers – will continue to support market growth. More affordable network video surveillance equipment (both from a camera and back-end storage, management and infrastructure point of view) has led to more cameras entering the market than ever before. With camera prices falling, end-users can now purchase more cameras than before. The installed base of security cameras in North America is expected to grow from 33 million in 2012 to 62 million by the end of this year. The majority of installed cameras are privately owned city surveillance, which often comes under the umbrella of safe city initiatives, which is one of the fastest growing destinations for the equipment. While equipment price erosion is high, operational costs can still spiral if not managed carefully. The global safe cities initiative is causing tremendous changes in the way governments view city management, beyond just emergency response and communications. Historically, law enforcement, traffic management and other city agencies were often operating

038 SECURITY SOLUTIONS

independently and without the ability to share data seamlessly. This silo mentality has become evident in many cities worldwide, but is not a sustainable model for city management or emergency response. Natural disasters and terrorism require collaboration and communication across a range of agencies, and law enforcement may often have limits placed on the intelligence they are able to gather. These types of incidents cause regulations surrounding data privacy and national security to shift. For instance, after the September 11 attacks, the US Congress passed the Patriot Act, which set up fusion centres to surveil and then aggregate vast amounts of data, including closed circuit television (CCTV) streams, social media, arrest records, warrants and even mug shots. These centres, now known as real-time crime centres, are becoming increasingly important, as agencies emphasise predictive policing – a major goal of these initiatives. While the safe city concept and agencyrelated collaboration and interoperability are certainly highly desirable outcomes, many challenges can hamper complete success of these projects. Most notably, larger, more developed cities often require vast integration of legacy equipment and software into their video surveillance networks. To have a truly unified safe city, many agencies must be involved, each of which may rely on their own legacy systems that must be integrated onto a single network. Further considerations and challenges include: • the network’s size, which depends on the expanse of the city and the density of the camera installations • the incorporation of additional data feeds from sensors, traffic flow monitors, lighting and other assets • the data rates from each camera and their respective resolution requirements • the standards across technologies and whether they allow for interoperability • the city’s budget and its ability to generate revenue to cover maintenance costs • the current level of connectivity and available infrastructure to mount surveillance cameras.

Established cities in North America and Western Europe are well on their way to achieving smart city or safe city status. Many US cities like Atlanta, Boston and Washington D.C. have substantial initiatives underway. Abu Dhabi, in the United Arab Emirates, is also one of the leaders in the smart and safe cities concept, with integration spanning airports, hotels and even malls. The uptake of safe cities is actually strongest in Asia and the Middle East. India, for example, is making significant headway. China will also become a huge opportunity, but mainly for technology vendors native to China; however, consultants from western countries might have better opportunities in China surrounding architecture and concept design. The Middle East boasts some of the largest safe cities programs, due to massive available budgets, a highly regulated security environment and topdown leadership structure. The ability to make decisions quickly is critical in widescale safe cities projects, which often have a large number of people making decisions across various agencies and levels of management. Europe, while quite developed, will continue to require extensions to existing systems. Technology vendors will also have an opportunity to capitalise on refresh cycles to sell upgraded technologies and expansions to systems. Complete technology refreshes are usually needed every 10 years but, in the interim, cameras and servers must be replaced to ensure mission-critical reliability. Overall, IHS Markit predicts substantial growth in the control room environment, especially owing to the convergence of various key functions. Emergency response is becoming a unified capability with a range of involved stakeholders so, as emergency response expectations and requirements change, technologies must also evolve.

Alex Richardson is a Market Analyst within the Security Group at IHS Markit | Technology, working on the Critical Communications team and is currently the lead analyst on the command and control room/PSAP market and ‘Safe Cities’ research.


ZKTeco Biometric technology, the next generation of access control is at your finger tips. Make your life sparkle with biometric innovations

EDUCATION | HEALTH | GOVERNMENT | FINANCE | HOSPITALITY | OFFICE SUPPLY | CHAIN RETAIL RESIDENTIAL | CONSTRUCTION | PROPERTY MANAGEMENT | REAL- ESTATE | PUBLIC FACILITIES Standalone Bio Finger RFID Backlit Keypad Face Recognition Finger and Vein

IP based Door Access Control Management C3 – 100/200/400 TCP/IP and RS-485 communication Built -in auxiliary inputs and outputs Advance access control functions 1 door, 2 door, 4 door models Lift controls and Expansion boards

www.mainline.com.au VICTORIA 221 Nepean Hwy Gardenvale, VIC 3185 +61 3 9596 6688

QUEENSLAND 54 Caswell St. East Brisbane, QLD 4164 +61 7 3891 2222

www.zktecoaustralia.com.au WESTERN AUSTRALIA Unit 8/14 Halley Rd Balcatta, WA +61 8 9344 2555

SECURITY SOLUTIONS 039


040


Courtroom Survival

Operational Safety After The Fact By Richard Kay The purpose of operational safety training is to prepare officers for that aspect of their job that has the potential to put them in harm’s way, and includes knowledge for officers to make correct decisions within lawful and procedural parameters, physical skills for officer safety and subject control, and strategies to manage the stressful aftermath of confrontations. One aspect that is often not addressed properly is courtroom procedure. In the course of operational work, it is possible that officers may have to attend court to testify, either as a key person in a case (for example, as the arresting officer), a witness (for example, to testify on the actions of others), or in the event officers act outside proper protocols, as a defendant (for example, accused of a crime in a criminal prosecution or against whom civil relief is sought in a civil case). When it is time to go to trial, officers may be called to testify, so their courtroom skills need to be solid enough to help win the case, or else their lack of skill and preparation may endanger it. Officers should also be mentally prepared to testify effectively, as the consequences of failing to do so have been seen too often and are simply too dire. Officers can get snagged on the stand by issues that have nothing to do with their credibility or level of professionalism. They get caught up in little things that are preventable through training and practice. Testifying in court may be the most difficult and important task officers face in their career. No other assignment subjects officers and agencies to more intense scrutiny than an officer’s credibility, competency and conduct in a courtroom. If an officer fails to be an effective witness in the courtroom, all the work that he and other officers did on the case, all that the victims and their families endured, all that other witnesses may have done over many months or years it takes for a case to go to trial, will have accomplished nothing more than a procedural process. An officer’s ineffective presentation in the courtroom can result in the acquittal of a subject, no matter how much evidence they have or how well they followed procedure during the actual incident. The reputation of officers and agencies can be enhanced or harmed by a courtroom presentation. It is a high pressure situation, but if officers educate themselves they can hone their skills as a witness to match those they have in operations and prepare themselves to be as effective in the courtroom as they are on the job.

041


Court Preparation When compiling a brief of evidence, it is essential to have a clear understanding of what will constitute admissible evidence and what material is likely to be ruled inadmissible or excluded in the exercise of judicial discretion. The law of evidence consists of the rules and principles that govern the means of proving the facts in issue. The rules are concerned with regulating that part of the law of procedure that determines what facts may or may not be proved, what sort of evidence may be given of such facts, and by whom and in what manner the evidence may be proved. The facts in issue are those that a party has to prove in order to succeed and are determined by the charge, the plea, substantive rules of law and the way the case is conducted. Cases proceed to court on the strength of the evidence, including whether it is corroborated, the reliability of the evidence, the credibility of witnesses and the weight likely to be given to their evidence. There is no point in proceeding with a case that has no prospect of success because it will only waste the time of all involved and result in unnecessary costs. Preparation for court appearance ensures that all relevant evidence has been properly prepared, who is to present what evidence, and that each person is prepared to attend court and thoroughly understands what is required of them. Legal counsel may collaborate with witnesses, but a witness must not discuss their testimony with other witnesses before or during the case. Prior to attendance in court, officers should speak with legal counsel in relation to the matter being heard. This allows both parties to clarify all issues prior to officers taking the witness stand. Officers should ensure that all material to be used or referred to has been thoroughly reviewed. They should look at their reports through the eyes of an attorney. Be aware of holes and possible angles of attack. Officers should make sure the report is as thorough, detailed and iron clad as possible and then be ready to discuss issues they can predict attorneys will bite down on. It is imperative that they are totally familiar with the information to be tendered, that it is complete and all items are immediately available when requested. Court is not the place for surprises, as officers may harm their credibility and the credibility of the case.

042

Court Protocol The following guidelines are offered for professional officer conduct during court proceedings. Presentation Officers should present for court with the same attention to detail they would going on duty. They should be exceptionally neat – fingernails clean, hair trimmed, clothes pressed, shoes shined. Carry only the essentials and avoid unnecessary items that may distract. Agency policy may dictate whether officers wear uniform or civilian clothes when they testify; often, on-duty officers wear uniform and off-duty officers wear civilian attire. Credibility starts with conduct. Officers should mentally prepare themselves for the fact that when they enter the courtroom everyone will most likely be watching their entrance. Stay poised and remember that this is how every witness is viewed. Officers should bow their head to the presiding magistrate or judge as a sign of respect for the court and the authority they hold when entering and leaving the courtroom and after being excused from the stand. Officers should not avoid looking at the judge or jurors; look at them as if speaking normally to a person. Swearing In Officers who frequently testify in court often view the swearing in process as a rote exercise, which can be communicated in their attitude and demeanour, such as only partially raising their hand and holding the fingers in a relaxed, cupped posture, failing to look at the person swearing them in, engaging in other action or starting to seat themselves while the process is being administered. Officers should be mindful of what this communicates about their respect for the truth. Much of a juror’s impression about witness credibility is based upon witness demeanour rather than what they actually say on the stand and officers should not communicate a cavalier attitude towards the truth. Swearing in is an excellent opportunity for officers to make a strong, credible first impression within which all subsequent testimony will be viewed. During the process, look at and seriously listen to the person administering it. Keep the right hand at shoulder level with wrist and fingers

extended until the process is completed. Give it the respect it deserves, and make eye contact with the jury. The oath is a word of honour, a personal promise to the jury that they can trust officers. Demeanour It is normal for officers to be nervous on the stand – they might sweat, shake, have trouble focusing, forget names, speak too rapidly or in a monotone voice, the voice may involuntarily raise or lower – all of these symptoms are normal. A normal reaction to the stress of being on the stand is slouching, so officers should sit up straight, but not stiffly. Orient themselves in the courtroom by looking at each of the walls within their vision without turning around, and looking at each person or groups of persons in the courtroom. Officers can control anxiety the same way they control stress in operations, by breathing properly. Officers should be calm and confident but not try to look or sound smarter or more self-assured than they are, as this may convey the impression of being cocky or faking it. Everyone has different personalities, presentations and ways of filtering information. Officers cannot change who they are as a witness, so they should not try to. They should talk as they normally would in a professional manner. It is okay to be nervous, and most officers are when they testify. The jury needs to understand the officer, relate to and believe him. If officers are working a night shift or have otherwise been up all night before testifying, tell the prosecutor and suggest that he establish this in the beginning of the direct examination. Sleeplessness (or illness) will affect officer demeanour, and the jury should have this information so they can evaluate it for what it is and avoid drawing negative inferences. Testifying Listen carefully, think before speaking and be attentive. This communicates that officers care about being accurate and responsive. They should take time as needed to fully understand the question and give a proper response. It does not hurt to appear thoughtful, so officers should organise their thoughts.


Swearing in is an excellent opportunity for officers to make a strong, credible first impression within which all subsequent testimony will be viewed.

A common misconception officers have is that they need to have an answer for every question and remember everything. That is not true and it can prove dangerous to believe otherwise. If officers do not know something or cannot recall specific details or events, by all means they should say so. Trying to fill in memory gaps or making up answers can wreck a case and put officers in professional peril. Do not fabricate. Only ever tell the truth. Remember, officers are there to perform a job – to testify truthfully and accurately. Answer the question being asked. It is tempting for officers to add information that they think helps the case, but they should resist doing this. This is the prosecutor’s job, so officers should let them develop their testimony. Do not jump ahead and do not anticipate. When officers elaborate for one side and then are very reserved when cross examined by the other, they appear biased and this undermines officer credibility as an objective reporter of facts. Adding extraneous information to answers also opens up other areas for cross examination. Experienced officers can be particularly susceptible to trying to help cases by angling their answers in a manner they believe will aid the outcome. Sometimes that can affect their ability to be completely neutral when they get in to court. An officer’s job is to remain neutral. He is there to present factual evidence on behalf of the incident. There are a lot of ways for judges to make a decision, and a key one is in believing the

officer. If officers look like they are an advocate for something as opposed to being neutral, they may end up being less credible from the viewpoint of the judge. Speak a little louder and slower than is necessary. Do not inject long pauses between words, phrases or sentences, but do concentrate on making each word clearly heard and understood. Be sincere and dignified. Trials are serious matters for everyone involved. Officers should refrain from wise cracks and clever remarks, but it is okay for them to laugh at themselves or an unexpected occurrence, if appropriate. Avoid appearing frozen, calculated or completely devoid of emotion. Remain calm and respectful. If officers lose their cool on the stand they lose credibility with the jury. The jury, as citizens, have granted officers with authorities and responses they do not permit themselves. If officers cannot control themselves in a courtroom, they are justified in being gravely concerned about their ability to control themselves on the job, where officers are subjected to much greater stress and no one is watching. In a case where an officer’s choice of tactical response option is questioned, the first thing a defence attorney is going to try to show in court is that the level of force used was excessive. The attorney is going to try to show the jury that the officer is a hot head with a short fuse and an explosive temper, that officer behaviour on the stand supports the accusation that he cannot

control himself or he is prone to violence and acted inappropriately. To achieve this outcome, the attorney will agitate the officer and lure him into demonstrating some kind of physical or verbal aggression. Officers should resist the temptation to fire off cynical remarks or a negative glance, point fingers aggressively, squirm in their seat like they want to strangle the attorney, and should avoid getting cute with their answers or firing a question back at the attorney out of frustration. Officers should know things can get adversarial on the stand, and many times officer credibility is the only thing attorneys have to attack, so they should prepare themselves ahead of time to spot an emotional luring tactic and immediately be ready to counter it with calm rationale. Officer patience and temper can be tested with interruptions, delays, argumentative questions and character attacks, but they should not become arrogant, antagonistic, impatient or excited. The worse it gets, the greater an opportunity officers have to impress the jury with their strength of character and integrity. Like it or not, jurors hold officers to a higher standard than they do lay witnesses and they expect officers to be able to withstand more pressure and still remain professional. Officers should prepare for the totality of their operational roles. An officer’s task in court is to educate people that he is just doing his job and does not have a personal stake in the outcome for subjects. Knowledge of procedural guidelines, having appropriate physical skills for safety and control, and managing residual emotional fallout after an incident are all critical for operational effectiveness. Being able to professionally and competently see the process through in court to ensure a successful outcome is an equally important aspect that officers should be well versed in. The personal stake is that officers did a good job, handled themselves professionally and their credibility is accepted. Richard Kay is an internationally certified tactical instructor-trainer, Director and Senior Trainer of Modern Combatives, a provider of operational safety training for the public safety sector. For more information, please visit www.moderncombatives.com.au

SECURITY SOLUTIONS 043


CCTV

044 SECURITY SOLUTIONS


Ergonomically Designed Workstation Can Improve Productivity

SECURITY SOLUTIONS 045


CCTV

By Morris Jacobs

Security businesses are no different to any other business in that the people who work in them want to be treated well. If business owners wish to get the best out of their staff, they need to listen actively to staff concerns, express gratitude for a job well done and be willing to compromise when necessary. The positive momentum and enhanced morale engendered by kind and fair treatment lead directly to a more motivated and productive workforce. However, too few business owners and managers realise that considerate treatment of workers is just part of the puzzle. The full picture needs to encompass physical factors as well as emotional. Nowhere in the security industry is this more prevalent than in the control room environment where workers spend long shifts sitting and watching computer screens. Providing an ergonomic environment can not only protect workers against injury, but also fuel productivity while reducing the number of workers compensation claims and days lost to injury. According to findings published in 2014 around research led by the University of Sydney, and conducted by an international team of researchers, lower back pain linked to workplace factors accounts for a third of all work-related disability worldwide. Lead author Professor Tim Driscoll, Sydney School of Public Health, said that lower back pain arising from ergonomic exposures at work is a major cause of disability, “The people most at risk were those aged 35 to 65 years.” Published data shows that in Australia, back pain is the leading cause of work loss days, with 25 percent of sufferers in the 18 to 44 age group taking 10 or more days off per year, and costing Australia around $4.8 billion each year for health care. On any given day in Australia, one quarter of the population is suffering back pain, and nearly 80 percent of adult Australians will experience back pain some time during their lives. In the study, disability arising from work was measured as disability adjusted life years (DALYs), calculated from a

046 SECURITY SOLUTIONS

combination of years of life lost due to premature death and years of life lived with disability. “The calculations showed that in 2010 there were nearly 22 million DALYs worldwide caused by workplace-related low back pain,” Professor Driscoll said. “Lower back pain arising from ergonomic exposures at work is a major cause of disability worldwide,” Professor Driscoll said. According to Peter Parker (no, not Spiderman), a Melbourne-based osteopath and expert in work-related injury, “Sitting as little as two hours continuously increases risk for: • heart disease • diabetes • back and neck pain • repetitive stress injuries • pelvic floor dysfunction • hip and knee disorders. Furthermore, Parker states that there is a growing body of research which clearly identifies the negative impact of sitting for long periods. Cardiovascular issues, gut problems, musculoskeletal instability and poor breathing are all clearly defined and affected negatively by sitting. What is more, people who stand more throughout the day tend to burn 25 to 35 percent more calories in their days. This effect becomes even more pronounced in people who are overweight or obese. Parker explains, “When we sit,

our breathing is shallow and confined more to the upper lungs. Our diaphragm, the huge muscle that sits between the lungs and gut, is compressed. This powerhouse region or solar plexus is extremely important and needs to move with softness and full amplitude to oxygenate the body.” The incidence of conditions like OsgoodSchlatter disease (inflammation of the patellar ligament) and Sever’s disease (inflammation of the growth plate in the heel) has never been higher in society than it is right now. Parker believes this can be directly attributed to the tightness through the front of the hips that causes people to overarch their lower back and load the front of knees and backs of ankles. Maintaining the ability to squat, lunge, twist, pull and push without the epidemic of sitting is paramount to long-term health. Beyond the extremely important and life-saving physical factors involved in workplace ergonomics, there are a number of other important factors to consider:

1

Employees who are given ergonomic workstations feel cared about and are thus more engaged. Providing employees with an ergonomic environment shows that employers take their health and wellbeing seriously, a message which has been strongly linked to increased productivity. According to a worldwide study

The positive momentum and enhanced morale engendered by kind and fair treatment lead directly to a more motivated and productive workforce.


Published data shows that in Australia, back pain is the leading cause of work loss days, with 25 percent of sufferers in the 18 to 44 age group taking 10 or more days off per year, and costing Australia around $4.8 billion each year for health care.

conducted by Towers Watson, “The single highest driver of employee engagement is whether or not workers feel their managers are genuinely interested in their wellbeing.” When an employee is given ergonomic equipment to work with, employers effectively say to him or her, “How you feel matters to me; I want you to be happy and comfortable and I want to protect you from harm.” Some of the most famously successful companies in the world, notably Google, have mastered the creation of ergonomic and enriched workspaces in a bid to ensure that their employees have high morale and feel free to think creatively.

2

Workers who are more comfortable have more energy and a higher working capacity. Workers who are in pain often report feeling tired and drained, which makes them less able to work quickly and effectively. They must also take frequent breaks in order to stretch, walk around, or lie down in an attempt to reduce muscle strain and ease aches. Physical pain negatively impacts mental energy too; it is hard to feel inspired, solve problems, generate new ideas or focus one’s concentration when constantly distracted by physical discomfort.

3

Workers with ergonomic equipment can work more quickly. Ergonomic equipment often makes an employee’s work easier to do as it cuts down on repetitive motions and optimises posture. For example, computer monitors

which are designed to reduce eye strain allow employees to focus on their screens for longer periods of time without developing headaches (and they can read more accurately). Desks that can be adjusted to the height of individual users not only keep monitors at the right height, thereby reducing neck and upper back pain and strain, they also allow people to type without contributing to issues like carpal tunnel syndrome. The ability to alternate between sitting and standing also significantly decreases the myriad of negative side effects outlined earlier in this article. All of this leads to greater productivity and a higher quality of work.

about the initial investment ergonomics require, they should think about the amount they might currently be paying in lost productivity, workers’ compensation claims or having to recruit and train new staff as a result of high staff turnover.

Providing employees with an ergonomic environment shows that employers take their health and wellbeing seriously, a message which has been strongly linked to increased productivity.

4

Employees using ergonomic equipment make fewer errors. Not only do workers concentrate better when they are not being distracted by discomfort; in industries where workers must concentrate for long periods, ergonomic workstations often result in fewer mistakes being made. When one adds up the various costs incurred by failing to invest in ergonomics, it quickly becomes clear that having ergonomic equipment is not a luxury, it is a necessity. If business owners are worried

SECURITY SOLUTIONS 047


BUSINESS

048 SECURITY SOLUTIONS


That Girly Touch:

Why Many Attempts To Attract Women To Cybersecurity Might Actually Achieve The Opposite

SECURITY SOLUTIONS 049


BUSINESS

By Joke Noppers The problem is familiar. Cybersecurity is still a male-dominated field. Women make up only 10 percent of the global cybersecurity workforce. The field is missing out on a lot of capable people and women are missing out on an interesting, well-paid career path. There have been numerous initiatives trying to change the situation, but fighting existing stereotypes has proven to be hard. The underlying problem: society still views technology as a ‘boy thing’. Boys are the inventors, the hackers, the tinkerers. Girls are not expected to have the same interest in building the cool stuff. They are expected to be better at soft skills like empathy, talking and feelings. These expectations still drive girls toward people-focused careers and away from science and technology, despite all efforts. Or perhaps, ‘despite’ is not the right word here… Do not Focus on the T-word There are several articles that aim to get girls interested in a career in cybersecurity. But even those articles cannot avoid that tech-avoidant girly girl stereotype from popping up from time to time. It is very telling that the tech part is often assumed to be the ‘bad’ part. It is the part that needs to be sugarcoated somehow. Yes, it is somewhat reluctantly admitted that the field has its roots in technology. But these roots are to blame for the field’s poor reputation. The articles try to lure attention away from this ‘bad’ part by repeating over and over again that the field is so much more than ‘just tech’. They keep going on about how the field needs to broaden its definition beyond the technical domain and that it is such a misconception to think that cybersecurity is only about keeping information and computers safe. Girls should not think that the domain is highly technically focused. They must know that cybersecurity is so much more than ‘hacking and passwords’. It is a multidisciplinary field, and if they do not like tech, there are plenty of non-technical areas to go into as well! And do not worry; a technical background or technical skills are not needed to get a job in cybersecurity. Looking for tech skills and technical qualifications in cybersecurity candidates is condemned as a bad practice. It ‘puts women off’ and even ‘naturally excludes’ them. Girls and tech do not mix very well, apparently.

050 SECURITY SOLUTIONS

Cybersecurity is still a male-dominated field. Women make up only 10 percent of the global cybersecurity workforce. Girly Skills Wanted Next to the assumption that the tech part in a career needs to be downplayed in order to sell it to women, there is the assumption that women will be naturally attracted by the people part. This is the part that gets advertised as a strong selling point. These articles point out how professionals in cybersecurity have to deal with all kinds of different people. They argue how important it is to know a thing or two about business and organisational psychology. They stress the field’s connection with fields like behavioural science and politics. And they discuss the need for people who can serve as translators and bridge-builders. That is where the girls come in, with their naturally superior soft skills as strong communicators and collaborators. This is not to downplay the importance of the people part in cybersecurity. It is just as important as the technology part. But it is very typical that in articles aimed at women, it is this people part that gets emphasised over the technology part. This echoes existing stereotypes of tech-avoidant, people-oriented females versus technical, tinkering males. A lot of the opinions expressed in those articles come from women in cybersecurity themselves. But women can have gender prejudices too. These societal expectations are deeply ingrained in everyone and, as this article shows, it is hard to fight them, even with the best of intentions. Back in the Real World But what if the writers of those articles have intentionally sugarcoated the tech bits? What if they know that that is the only way to get their message across? What if too much talk about tech really does scare the girls away? The people interviewed in those articles have years of experience as experts in the field. If there is anybody who knows what works and what does not, it is them. And, probably, they are

right. Emphasising all the different and interesting social aspects of the field is more likely to draw the attention of girls than talking about technical challenges. But this preference is, for a large part, the result of the subtle (and not so subtle) messages society keeps sending to girls: they are helpers, not tinkerers. A message this kind of article keeps reinforcing. As long as this keeps happening, things are not going to get any better. If girls keep seeing themselves as non-tech people persons first, they are less likely to choose a career in cybersecurity. Cybersecurity might be broad and multidisciplinary, but it is still a tech field. Professionals work with tech people and get to deal with tech-related issues. Why would people go into a tech field when their natural talents lie in an entirely different domain? Not even cybersecurity’s bright career prospects seem enough to change women’s minds about this. If the field really wants to get more diverse, playing into existing preferences (and reinforcing them) is not enough. It is those preferences themselves that need to be changed. Of course, that is going to be a difficult job. But unfortunately, no one said that changing the world was going to be easy… What do readers think? Is it realistic to expect those preferences to change anytime soon? Or should the cybersecurity field accept gender preferences as they are today and play into those preferences in order to attract a more diverse workforce? This article was originally posted at medium.com/ storro-blog Joke Noppers is a freelance cybersecurity writer working with Storro B.V. Storro is an application for secure collaboration, without the cloud. Visit: storro.com for more information.


SECURITY SOLUTIONS 051


Turn static files into dynamic content formats.

Create a flipbook
Security solutions #104 by Security Solutions - Issuu