A U S T R A L A S I A’ S L E A D I N G S E C U R I T Y R E S O U R C E F O R B U S I N E S S A N D G O V E R N M E N T
ISSUE #105 JAN/FEB 2017
Security?
ISSN 1833 0215
TRUMP
$9.95 inc GST / $10.95 NZ
Will Rhetoric
NEED SERIOUS SECURITY? THE ANSWER IS EZI!
Ezi Security designs, manufactures and installs a premium range of electronic perimeter security products designed for both vehicle and pedestrian control. These consisting of a wide range of security products suitable for low to high-risk applications. Ezi Security Systems has been manufacturing quality security products for over twenty-one years with equipment is installed in some of the very harshest of environments the planet has to offer. And all with outstanding results. While Ezi has a commitment to innovative design and quality products we also fully understand the importance of easy and efficient after sales service. Ezi Security Systems services and maintain the products we sell to ensure that your critical infrastructure and personnel are protected at all times. “ALL EZI SECURITY SYSTEM PRODUCTS ARE BUILT TO LAST A RELIABLE THIRTY YEAR (PLUS) PRODUCT LIFE SPAN WHEN MAINTAINED”
Ezi Security Systems has the most extensive offering of Hostile vehicle barrier products (HVB’s) and has the expertise to design and secure any critical infrastructure or site of national importance. Ezi has an extensive range AVB and HVB Crash Certified products such as the world famous TruckStopper, the renowned K12 Wedge, crash boom beams and crash rated static and automatic bollards. Ezi Security Systems has all the realistic solutions to meet your high security requirements while maintaining an aesthetically pleasing solution for your site. All Ezi Security System AVB & HVB have been vigorously crash tested and certified to meet all ASTM, IWA and PAS 68 stipulations. Ezi Security and its partners continue to the push boundaries on all crash products with our in-house R&D security experts providing market leading products designs. This specialist ability also involves our renowned installation expertise and advice with the all important civil work design & engineering. Ezi Security believes in pushing design frontiers for its products to keep pace with marketplace and security priorities. This year alone Ezi and PPG have successfully worked with CTS and crash tested to Pas 68 in 2016 the following products:
•
M30 Bollard Performance rating V/7500[N2]/48/90:0.0/0.0
•
M50 Bollard Performance rating V/7200[N3C]/80/90:5.5
•
Wedge II Performance rating V/7500[N3]/80/90:0.0/20.7 (tested with 4 m blocking width)
With our highly chosen business partners being the best in their field and coupled with our own Ezi Security R&D in house design team Ezi Security continue to push boundaries on market leading and state of the art crash rated designed products. Our ability also involves installation expertise and advice with all important civil work design & engineering.
Ezi also takes pride to provide our clients with more than just perimeter security solutions. We also offer a quality range of internal pedestrian control products from Werra Entrance Control. The Werra Entrance Control range compliments perfectly the already strong offering of pedestrian security control that Ezi Security currently offers to the market. The range includes a wide variety of systems suitable for pedestrian access management that includes the ability to hold and isolate persons of interest and/or concern. Ezi Security again has a quality product for every threat and contingency for building personnel security. All products offer quick access for authorised persons and reliable protection against unauthorised access. With a flow rate of up to 35/min even large flows of people can be monitored and controlled effectively. Werra Entrance Control not only stands for innovative for the individual’s passage of person, but also is an extension for our philosophy of being a professional fullservice provider of all components within perimeter security and access control. Ezi Security Systems, and their business partners, are privileged to be protecting some of the most prestige and iconic man made marvels of the modern era from the Burj Khalifa Tower in Dubai to Australia’s very own Parliament House in Canberra.
IF SERIOUS SECURITY IS YOU REQUIREMENT, LOOK NO FURTHER THAN EZI! FIND OUT MORE ABOUT US!
AUSTRALIA NATIONAL
1300 558 304 11 Cooper Street Smithfield NSW 2164 www.ezisecurity.com.au sales@ezisecurity.com
CUSTOMISABLE ELECTRIC HEIGHT ADJUSTABLE SIT STAND CONSOLES
Does your control room meet
Australian Ergonomic Standards?
www.activconsole.com
Clayton VIC 3168
Safe Work Australia, Nov 2015
“...in 2012-13 the cost impact of work-related injuries and illnesses was estimated to be just over $61 billion...�
State-of-the-art ergonomic lifting technology Lifetime Australia phone support AS/NZS 4443:1997 & ISO 11064
+61 3 9574 8044
sales@activconsole.com
CONTENTS105
COVER STORY: WILL RHETORIC TRUMP SECURITY?
052 032
On 8th November 2016, global politics went into a tailspin. A world still struggling to come to terms with the shock of Brexit was confronted by the Donald Trump bandwagon rolling into Washington, D.C. on the back of a mainly white, some would say racist, backlash against the political, intellectual and economic establishment. What might this mean for regional security and the potential for increased instability?
RISK MANAGEMENT AS A BUSINESS GAME Alex Sidorenko of the Institute for Strategic Risk Analysis looks at ways security professionals can game out risk management scenarios to determine better risk management outcomes.
058
INDUCTIVE OBSERVATION: PART 2 Experienced security director, consultant, trainer, operator and business developer Ami Toben looks at how security operatives can apply surveillance observation skills to their own security.
060
WHY TOP EXECUTIVES NEED TO RETHINK CRISIS MANAGEMENT Dr Tony Jacques looks at changes in the current crisis management paradigm, advocating that security managers work toward moving beyond traditional crisis management to a position of crisis proofing an organisation.
068
EXPLOSIVES: NOT MY PROBLEM From mining to construction and all manner of industries in between, explosives have become an important tool in many industries. However, with a high potential to be mishandled or even misused, what responsibilities do security managers have to safeguard both their business and the public from the dangers presented by explosives?
084
THE CRIME-TERROR NEXUS Australian civil-military think tank Info Ops HQ recently published its inaugural report from its open-source investigation into Australian Foreign Fighters and Domestic Actors. What it found was local evidence supporting the global trend of criminal and antisocial behaviour being observed as one of the many precursors to radicalisation.
004 SECURITY SOLUTIONS
NEW INT-QUADIP For PB- Series Quad Beams
IP INTERFACE MODULE
LAN/WAN
With the new IP interface module, our intelligent PB- series Quad Beams are as easy as IP cameras to install and integrate with leading VMS solutions.
VMS
Most intruder detection systems rely on legacy technologies which require a number of third-party products and man-hours to install. The INT-QUADIP module utilises infrastructures already in place with CCTV, Access Control, and other security systems; dramatically reducing installation costs whilst providing a fully integrated security system which can be easily expanded and configured as desired.
KEY SPECIFICATIONS ● ● ● ●
PoE Class 3 IEEE 802.3af VMS Compatible Direct control for cameras including: - Axis - Bosch - Hikvision - Sony
● Plug & play web browser interface ● No software installation required ● One cable installation
PB-IN-HF/HFA The ultimate in trouble free perimeter detection for distances up to 200m.
1300 366 851 www.seadan.com.au
PB-F/FA Single channel quad beams ideal for simple perimeter systems.
PB-IN-100AT Anti-crawl beam for high security perimeters up to 100m.
PB-KH TAKEX quad beam performance for use in beam towers.
(02) 9427 2677 www.sprintintercom.au SECURITY SOLUTIONS 005
CONTENTS105 010
LETTER FROM THE EDITOR
012 LEADERSHIP Jason Brown looks at why effective crisis management is about much more than just leading people.
014
028 EVENTS A look at upcoming industry events. 036 ALARMS How can you future-proof your security systems to ensure return on investment.
CYBER SECURITY Are Australian SMEs more vulnerable to cyber
attack?
040
016 RESILIENCE What is the relationship between human and
organisational resilience from a leadership perspective in the creation of a culture of resilience?
OPERATIONS What can security companies do to better recognise and manage post trauma stress?
044 CCTV How do you calculate Total Cost of Ownership when evaluating a new CCTV system?
018
HUMAN RESOURCES Why is leadership such an important factor in managing human resources?
020 NATIONAL SECURITY Why is the Liberal Government so focused on
064
LOSS PREVENTION With the biggest sale period of the year fast approaching, how can you more effectively prevent losses in a retail environment?
counter-terrorism?
022 COMMUNICATIONS Does airport screening really offer any assurance? 024 LEGAL How prepared is your organisation to deal with workplace
072 AVIATION How can you stay safe when travelling through airports this holiday season?
076 ACCESS CONTROL What is the role of the access control system in
trauma?
026
improving safety and security on university campuses?
THINKING ABOUT SECURITY What role should security managers play after an atrocity?
032
080
BUSINESS What three things can large corporations learn from SMEs when managing risks?
060
068
088
SECURITY STUFF
104
PRODUCT SHOWCASES
090
SPOTLIGHTS
110
SHOPTALK Company announcements from within the industry.
094
PROFILES
006 SECURITY SOLUTIONS
SECURITY SOLUTIONS 007
www.securitysolutionsmagazine.com
Editorial Editor: John Bigelow john@interactivemediasolutions.com.au Sub-Editing: Helen Sist, Ged McMahon
Contributors: Gary Barnes, Jaroslav Barton, Jason Brown, Michael Brookes, Greg Byrn, Rod Cowan, Darren Egan, Winston Goh, Tony Jacques, David Harding, Richard Kay, Blake Kozak, Justin Lawrence, Steve Lawson, Nicole Matijec, Rita Parker, Alexei Sidorenko, Ami Tobin, Clive Williams, Don Williams, Tony Zalewski.
Advertising keith@interactivemediasolutions.com.au Phone: 1300 300 552
Marketing & Subscriptions admin@interactivemediasolutions.com.au $62.00 AUD inside Aust. (6 Issues) $124.00 AUD outside Aust. (6 Issues)
Design & Production Graphic Design: Jamieson Gross graphics@interactivemediasolutions.com.au Phone: 1300 300 552
Accounts accounts@interactivemediasolutions.com.au Phone: 1300 300 552
Publisher
ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au Disclaimer The publisher takes due care in the preparation of this magazine and takes all reasonable precautions and makes all reasonable effort to ensure the accuracy of material contained in this publication, but is not liable for any mistake, misprint or omission. The publisher does not assume any responsibility or liability for any loss or damage which may result from any inaccuracy or omission in this publication, or from the use of information contained herein. The publisher makes no warranty, express or implied with respect to any of the material contained herein. The contents of this magazine may not be reproduced in ANY form in whole OR in part without WRITTEN permission from the publisher. Reproduction includes copying, photocopying, translation or reduced to any electronic medium or machine-readable form.
RS A DE VI
SSOCIATI
ON
ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au
O
SECURIT Y
PR
RALIA LTD UST FA
O
Written Correspondence to:
Or i g i n a l Si z e
O C I AT I
ON
Y P R OVI D
RIT
CU
D LT
SE
PR O
ASS
SPAAL
AU S T R A L I A
STRALIA LTD AU
SECURITY
RS
OF
E
Official partners with:
SSOCIAT IO N
OF
RS A DE VI
blue colour changed to this colour green.
COPY/ARTWORK/TYPESETTING APPROVAL Please proof read carefully ALL of this copy/artwork/typesetting material BEFORE signing your approval to print. Please pay special attention to spelling, punctuation, dates, times, telephone numbers, addresses etc, as well as layout.It is your responsibility to bring to our attention any corrections. Minuteman Press assumes no responsibility for errors after a proof has been authorised to print and print re-runs will be at your cost. Signed.................................................................. Date........................
008 SECURITY SOLUTIONS
Series 400 is a fully welded 19” rack mount wall cabinet with heavy duty load carrying capabilities.
When you choose Australian made, you’re choosing more than quality and reliability, you’re choosing peace of mind.
DESIGNERS & MANUFACTURERS OF 19” RACK SYSTEMS
MFB’s range of innovative racking solutions is proudly made onshore, to ensure quality and consistency above all others. Backed by constant development, unsurpassed customer support and expedited delivery. MFB proves a solid project partner whatever your requirements. Australian made, makes Australia. With a solid history of over 45 years of supplying innovative, off-the-shelf and custom built racking systems, you can rely on MFB to ensure when you buy Australian, you’re investing and supporting Australian industry.
AUSTRALIAN MADE MAKES AUSTRALIA
www.mfb.com.au
VIC NSW -
P (03) 9801 1044 P (02) 9749 1922
F (03) 9801 1176 F (02) 9749 1987
E sales@mfb.com.au E sydney@mfb.com.au
SECURITY SOLUTIONS 009
LETTER FROM THE EDITOR It would seem that one of the unforeseen side effects arising from the growth of social media is that society has largely lost perspective on personal boundaries. I find I am constantly astounded by the things people say and post on social media. The recent US Presidential election serves as a perfect example. US President-elect Donald Trump made all sort of outlandish statements throughout his campaign, which he has since attempted to recant or deny, despite the voluminous, publically available sources in the media and on social media which clearly outline his remarks. Security managers are no longer simply responsible for the protection of people, property (intellectual and physical) and assets. The modern security manager is also responsible for, amongst other things, the protection of the brand and reputation of the organisation he or she represents. Yet, for reasons which remain inexplicable to me, some people appear to believe that they can say or do whatever they like and that it will have no bearing on the reputation of the organisation they represent. I understand that some people feel they should have a right to hold any belief or voice any opinion in private, but here is the thing – if you mix your professional connections with your personal connections on social media, then the things you say are no longer private. It seems that some people are yet to grasp the fact that posting something on social media is akin to putting it on an outdoor billboard. People are going to see it and those same people will form value judgements, not just about you, but about the organisation you represent and, more to the point, the industry you represent! This phenomenon does not appear to be limited to security managers either. The number of company owners I have encountered who insist on having the one social media account for both professional contacts and personal contacts is astounding. I doubt most people would wish to invite their most important clients or political allies to their buck’s night, yet they have no problem posting images, videos, photos and opinions on their social media feeds that make the buck’s night look tame by comparison. If you had not yet noticed, this is something of a sore point for me. The security industry receives no small amount of negative press as it is, despite the amazing work being done by so many brave, professional and highly educated individuals. Why some people are okay with perpetuating the negative stereotypes that plague this industry is beyond me. If you are creating a social media profile on a professional network like LinkedIn, as opposed to Facebook for example, do you really need to be told that a profile picture of you chugging a beer in a Bintang singlet in a bar in Bali is not really an appropriate image? Is that how you would dress or behave at an important work function? Knowing what is appropriate and what is not in a professional setting really should not be that difficult. Similarly, knowing who you want to invite into your closest inner circle should not be a challenge.
John Bigelow Editor
010 SECURITY SOLUTIONS
Contact us on 1300 364 864 Follow us on
Delivering Proven Solutions for Security & Safety We Protect People & Assets www.magneticautomation.com.au
REGULAR
LEADERSHIP Crisis Leadership – more than managing people By Jason Brown In the last column, I focused on the results of what makes a good boss, but not every situation can be managed in the ‘business as usual’ mode. Often, particular leadership characteristics are required that are not normally expected or exhibited dayto-day. “A crisis can arise when threats posed by adverse events or emerging issues are permitted to escalate beyond thresholds. Such a situation may result from natural distasters (such as flood, earthquakes), man-made events (such as legal disputes, protest campaigns, major power failures) or perceived issues (such as uncorrected, negative media speculation). It may also come about as a result of where, in the eyes of stakeholders, we did not react to any of the above situations appropriately…” Chris Jenkins, CEO Thales Australia. Such events will vary considerably in terms of seriousness but, if left unresolved, they may have the potential to threaten life, seriously harm an organisation’s reputation or affect its operations. An organisation must be prepared to act quickly and positively to: • protect life and health • maintain service continuity and the trust of its stakeholders • minimise damage to assets, business and operations • communicate with, and maintain the confidence of, internal and external stakeholders • cooperate in the maintenance of critical infrastructure and the environment. Leaders must maintain an awareness of those real and potential risks. They must also be prepared to deal with events outside their direct control in order to influence favourable outcomes wherever appropriate.
012 SECURITY SOLUTIONS
A crisis can attract considerable interest and scrutiny from both internal and external stakeholders. These stakeholders will form an impression of the crisis and how it is being handled from the quality, accuracy and promptness of information communicated. Poorly handled, the communication of key messages can damage the reputation of the company and can further escalate a crisis. When communicating to internal or external stakeholders, the leader or the spokesperson must adhere to the communications principles listed below. Communications Principles • The health and safety of employees, customers and the public comes first. Offer help immediately and communicate it and show sincere concern for those affected and a desire to help in any way possible. • Response must be rapid. Acknowledge the situation to all audiences, including the media, quickly. The perfect solution debated for two weeks is a disaster. The organisation will be judged on how it handles the crisis during the first critical minutes and hours. • Strive for a balance between the response needs and the legal concerns. • Do not make up answers in the absence of fact, under the pressure of questioning. • Commit to notifying key stakeholders of the situation and consequent actions (as far as possible, they should hear first from the leader or the designated representative, not the media). • Assessment of appropriate communications mediums must be performed and reviewed. • Provide a media response as soon as is practically possible and provide media updates on a regular basis. • A campaign management approach must be adopted to ensure tight management, integration of messages and refinement following reaction to initial communication.
So, what are the characteristics of such a leader? At the Security Associations Seminar in November, the participants came up with the following elements, in no particular order: Intellectual
Physical
Emotional
Objectivity
Stamina
Controlled
Listener
Active
Centred
Understanding
Resilient
Empathetic
Negotiator
Good health
Calm
Clarity
Manage stress
Assertive
Strategic thinker
Reflective
Operationally aware
Confident (not arrogant)
Results/outcome focus
Stable
Dependable
Resilient
Decisive
Empowering
Communicator
Rational
Planner
Now you have this list, add it to the list from the last article and start some self-awareness by considering these elements against your own characteristics. Ask, where am I weak and where am I strong, then plan the activities and exercises to overcome weaknesses and build and reinforce the strengths. Jason Brown is the National Security Director for Thales in Australia and New Zealand. He is responsible for security liaison with government, law enforcement and intelligence communities to develop cooperative arrangements to minimise risk to Thales and those in the community that it supports. He is also responsible for ensuring compliance with international and Commonwealth requirements for national security and relevant federal and state laws. He has served on a number of senior boards and committees, including Chair of the Security Professionals Australasia; Deputy Registrar Security Professionals Registry – Australasia (SPR-A); Chair of the Steering Committee for the International Day of Recognition of Security Officers; member of ASIS International Standards and Guidelines Commission; Chair of Australian Standards Committee for Security and resilience.
• INNOVATIVE PRODUCT DESIGN • BULLET RESISTANT CERTIFIED • BURGLARY RESISTANT CERTIFIED • UNIQUE HPJ CONCEPT
High Security Anti-Tailgating Portals
44
YEARS IN SECURITY
With over 40 portals in the range here is a closer look at two C3 Security Portal
HPJ140 Security Portal
The C3 Security Portal offers
The HPJ140 Security portal offers
•
Ultra Sonic Tailgate Detection
•
Unique Half Portal design to ‘cap’ an existing access controlled door
•
890mm entrance for DDA compliance
•
Ultra Sonic Tailgate Detection
•
Open design for maximum user comfort
•
900mm to 1200mm entrance for DDA compliance
•
P1A all the way up BR4 and WK4 glass construction
•
P1A all the way up BR4 and WK4 glass construction
www.pathminder.com.au
Phone: 1300 750 740 SECURITY SOLUTIONS 013
REGULAR
CYBER SECURITY Australian SMEs More Vulnerable To Cyberattacks By Garry Barnes According to the Small Business Association of Australia, small and medium enterprises (SMEs) in Australia make up 97 percent of Australian businesses and employ over 4.7 million people. And latest figures from the Australian Bureau of Statistics count over two million small businesses nationwide. Having consulted with many SMEs, and as a small business owner myself, there is a drive, passion and unparalleled dedication to provide value and services that proudly account for a third of Australia’s gross domestic product (GDP). Unfortunately, IT security solutions are often not up to industry standard and provide ready access to cyberattacks, such as ransomware, malware, phishing and denial of service, which have the potential to destroy SMEs’ finances and brand credibility overnight. According to Anne Robins, research director at Gartner, Australia is the second most commonly attacked country after the US for ransomware. Additionally, a recent report found the number of new ransomware attacks in the first half of 2016 alone has already eclipsed the total 2015 volume by 172 percent. And the attacks are becoming more personal. Hackers are spending time gathering detailed information about the business and its employees, and using that information to gain access and take sensitive business data. SMEs are now being actively targeted by hackers for two main reasons. Firstly, many larger organisations have shored up their resources, and hackers have realised small businesses are not as well equipped. Hacking methods are constantly changing, which makes it hard to keep ahead of security developments and cybercrimes. Allocating proper resources often requires specialist management and finding and affording these resources is challenging for SMEs.
014 SECURITY SOLUTIONS
Secondly, SMEs are also an easy target, as many companies outsource key functions such as IT and data management, financial services and human resources (HR) functions. While focusing on a company’s core competencies and outsourcing other services makes business sense, it can lead to multiple constituents handling sensitive company information and make the business vulnerable to data leaks if the information is not securely managed by the third parties. Yet responsibility for this data still lies with the SME. Understanding these issues, ISACA created a guideline document which includes eight key principals for SMEs to understand cybersecurity and how best to protect their business. They are: Understand the potential damage and the consequences of cyberattacks on the business and how end-users may be targeted and affected by cyberattacks and incidents. Understand end-users, their cultural values and their behaviour patterns. Clearly state the business case for cybersecurity and the risk appetite of the company and include clear cost-benefit statements that are based on risk and potential impact. Establish cybersecurity governance. Ensure that the SME’s cybersecurity approach clearly accepts and incorporates the overall values and objectives of the enterprise. Manage cybersecurity using Control Objectives for Information Related Technologies (COBIT) principles and enablers – COBIT is the leading framework for the governance and management of enterprise IT. Define clear, plausible and manageable cybersecurity assurance objectives. Define the three lines of defence within the enterprise to provide reasonable assurance over cybersecurity.
1 2 3 4
8
Establish and evolve systemic cybersecurity. Consider the dynamic and always changing nature of cybersecurity as an organisational process and function. Thankfully, the Australian Government also recognises the need to assist SMEs. The Cybersecurity Strategy states the Government will offer businesses the opportunity to have their cybersecurity tested by certified practitioners. The Government is also planning to create a cyber threat sharing portal to allow businesses to detect and quickly share threats and offer practical advice to become aware of and strengthen a company’s cyber defences. However, testing will only address issues once cybersecurity measures have been established and will validate the choices an SME has made in terms of security. The ISACA guidelines outlined above are preventative cybersecurity measures and protocols to establish at the start, while the Cybersecurity Strategy enables a ‘health check’ to make sure the systems are working as required. Prevention and protection are the best methods for warding off cyberattacks and ensuring companies (of any size) protect their economic interests and intellectual property and are critical to their ongoing success. This in turn adds to Australia’s economic prosperity and grows its overall resilience to cyber threats.
5 6 7
Garry Barnes is practice lead, Governance Advisory at Vital Interacts (Australia). He has more than 20 years of experience in information and IT security, IT audit and risk management and governance, having worked in a number of New South Wales public sector agencies and in banking and consulting.
S K Y H AW K FOR VIGILANT SURVEILL ANCE
L E A R N M O R E AT S E A G AT E . C O M / A U
SECURITY SOLUTIONS 015
REGULAR
RESILIENCE The Culture Of Resilience By Dr Rita Parker This article focuses on the relationship between human and organisational resilience from a leadership perspective in the creation of a culture of resilience. All leaders are likely to face situations where members of a group, community or organisation experience challenges and uncertainty. However, few leaders are likely to encounter the life and death leadership situations experienced by Ernest Shackleton and his Antarctic polar expedition. Shackleton and his crew from the aptly named ship, Endurance, were trapped aboard their ship by pack ice between February and September in 1915. However, they had to abandon the ship when it was crushed and sank and they were adrift on an ice floe for hundreds of days before reaching land. Notwithstanding enduring harsh conditions, all members of the crew survived and returned to civilisation. Their survival was largely attributed to Shackleton’s leadership behaviours, which inspired the resilience of his stranded crew throughout their harrowing ordeal. Today, global events expose people to crises and disaster almost on a daily basis. Organisations operate within increasingly complex environments brought about by different external and internal influences, sudden unforeseen events, and global political, economic and social trends. Individually, people face situations that test their personal levels of resilience and as part of a group, such as in the workplace or organisation. While this may present a daunting picture, there is some evidence to suggest that groups, organisations and even communities can learn to develop a culture of resilience – particularly with the right leadership. In the same way that individuals can learn to develop personal traits of resilience, organisations
016 SECURITY SOLUTIONS
can also learn to develop a culture of resilience. It is a combination of a set of principles, a process and capabilities, and where leadership plays a significant role. Effective leaders understand that an organisation needs more than an enduring or recognisable brand for it to be a resilient organisation. Appropriate leadership can inspire group cohesion by acting as a catalyst for shared organisational values, by articulating the vision of the organisation and, importantly, by exhibiting traits and behaviours associated with resilience. They also recognise that uncertainty can undermine or inspire resilience, but this depends on the culture of the organisation and the capability of individuals to choose to be inspired rather than to be uncertain because the strategies, processes and procedures within an organisation guide and lead them in that direction. It can therefore be argued that workplace cultures that build resilience create more productive, effective and safer environments and the organisation itself is likely to survive and thrive rather than flounder. An organisation with a culture of resilience is built on several characteristics; most notably, leadership, shared values and flexible and adaptive capabilities. In practice, there is a matrix approach – horizontally as well as vertically (or to put it another way, top-down, bottom-up and even side-to-side) – where there is a shared identity and where critical knowledge and practices are known and understood. As a result, when faced with adversity, an organisation with a culture of resilience is capable of maintaining and developing itself. The capacity for resilience is a vital component of authentic leadership development and this is sometimes referred to in the context of
transformational leadership. Transformational leaders may convert crises into developmental challenges by presenting them as challenges that can be overcome, as Shackleton did. Converting crises into developmental challenges underscores the notion of resilience as growth through adversity. How people respond to challenges and uncertainty is a function of resilience. Resilient individuals have the ability to meet adversity through resourcefulness, creativity and to be strengthened by the experience. This can be enhanced if they have an inspiring leader who models the characteristics of resilience, as demonstrated by Shackleton.
Dr Rita Parker is a consultant advisor to organisations seeking to increase their corporate and organisational resilience and crisis management ability. She is an adjunct lecturer at the University of New South Wales at the Australian Defence Force Academy campus where she lectures on resilience and nontraditional challenges to security from non-state actors and arising from non-human sources. Dr Parker is also a Distinguished Fellow at the Center for Infrastructure Protection at George Mason University Law School, Virginia, USA. She is a former senior advisor to Australian federal and state governments in the area of resilience and security. Dr Parker’s work and research has been published in peer reviewed journals and as chapters in books in Australia, Malaysia, the United States, Singapore and Germany, and presented at national and international conferences. Rita holds a PhD, MBA, Grad. Dip., BA, and a Security Risk Management Diploma.
Why do you have to do a strange dance to try and open a door?
Instinctive technologies for a world without constraint
Card mode
Slide mode
Tap Tap mode
Remote mode
Hands free mode
Be STid, be smart Intuitive solutions for mobile access control
SECURITY SOLUTIONS 017
REGULAR
HUMAN RESOURSES Leading Human Resources By Greg Byrne
Recent headlines like ASQA cancels 2,700 security qualifications and How private security can support police responses to domestic violence are timely reminders of the importance of leadership in the Australian security industry. The cancellation of 2,700 qualifications is a bad news story for the Australian security industry. Conversely, the Australian private security industry supporting public police forces in responding to domestic violence is a good one. Without analysing the internal performance of the company that let the situation develop whereby their performance was so badly discredited that their qualifications were cancelled, leadership must have played a role. Reading past the headline reveals that there was a failure to meet the national training standards and, in particular, a failure to adequately assess the competence of its students. Experience tells me that leadership is the reason for success, the reason for failure and the reason for mediocre outcomes in all organisations and work groups/units. I have been a law enforcement professional and had involvement with the Australian security industry for over 35 years, most of that time in positions of leadership. I have led large teams of operatives and in turn reviewed the performance of those who have or had. I have also audited, restructured and consulted on the performance of large government and private enterprises. I have also investigated workplaces for breaches of industrial awards and represented employers in mediations. As I grew in experience, I learnt to look to the top tier of leadership of the work unit, section or the organisation for a reason as to why the organisation or work unit was performing well, badly or indifferently. In other words, I learnt that it was leadership that influenced employer and
018 SECURITY SOLUTIONS
organisation behaviour more than any other facet or any stakeholder. The reason for this was that leadership controlled policy and interpretation of policy, stakeholder interaction and employee performance. It is for this reason that training myself on effective and authentic leadership has been a major focus of my professional life. And once learnt, I instructed and consulted others on how to do it effectively. The importance of education in leadership development cannot be understated. I recall working through a Graduate Certificate in Education and Leadership at the Australian Catholic University many years ago and being told by the course director that education was the only way forward. I reflected on those words and applied them to my professional life. I also instructed many employees on its virtues and had the pleasure of seeing many managers follow my advice and flourish, and their workplaces and companies prosper accordingly. A simple internet search on ‘what is leadership’ results in millions of hits and just about as many definitions. However, I have tested the definition learnt in that graduate certificate and found it never to be wanting. An effective leader is credible in that he or she has been there and done that; is competent, with a proven track record in the profession in which they purport to lead; uses candour or honesty at all times; and is authentic. An accurate definition of authenticity would lend itself to a 1,000-word essay; suffice to say, it is being true to self and true to those around you (true in the context of being the same and not purporting to be someone you are not). A leader is able to form professional relationships based on those four words; he has the capacity to build relationships with those he leads based
on the characteristics of being authentic, credible and honest. If a manager or CEO (or anyone) does not have the emotional intelligence to form relationships based on those words, then that person is not a leader. So why is leadership so important to the security industry in Australia? Because without it, headlines like ASQA cancels 2,700 security qualifications will dominate. Comments from senior police officers such as “the security industry in Australia is becoming more professional than some police forces” would not be made and iBooks like Plural Policing: A Comparative Perspective by Trevor Jones and Tim Newburn would not be written. Read the book Maverick: The Success Story Behind the World’s Most Unusual Workplace by Ricardo Semler, who took over the running of his family’s ageing manufacturing business in Brazil and turned it into “the most revolutionary business success story of its time”. Semler is an excellent example of effective and courageous leadership. I have espoused his virtues ever since I read his book in 1995 and continue to do so. If the Australian security industry is to continue to flourish, then leadership training and development needs to remain at the forefront of our thinking.
Greg Byrne is the Managing Director of Multisec Consultancy Pty Ltd. He lectures part-time at the Western Sydney University for an undergraduate diploma in policing and is a sub-editor for and board member of the Australian Police Journal. His academic qualifications include Master of Management, Diploma of HR, Grad Cert in Leadership and a Diploma a Security Risk Management. Greg can be contacted via email greg@multisec.com.au
MULTIPLE CAPABILITIES SUPERIOR SOLUTION
Volvo Group Governmental Sales Oceania
IN HOSTILE ENVIRONMENTS, IT’S IMPORTANT THE SYSTEMS THAT YOU DEPEND ON CAN
STAND THE TEST OF TIME.
At Volvo Group Governmental Sales Oceania, our core business is the manufacturing, delivery and the support of an unparalleled range of military and security vehicle platforms; a range of platforms that are backed by an experienced, reliable and global network with over one hundred years of experience
superior solutions, providing exceptional protected mobility SECURITY SOLUTIONS 019 www.governmentalsalesoceania.com
REGULAR
NATIONAL SECURITY National Security By Clive Williams Prime Minister Turnbull returned from the AsiaPacific Economic Cooperation (APEC) Leaders’ Summit in Peru all fired up about counterterrorism and that was the theme of his national security statement to the House on Wednesday 23rd November 2016. Terrorism is often included as a safe topic at international talks because just about everyone can contribute without there being major disagreements. However, there are many types of terrorism and it is frequently the case that separatist terrorism – which is usually down to central government mismanagement – gets included in the mix, particularly if there is any possibility of the regime concerned connecting it to Islamic State (IS) or Al-Qaeda. In East Asia, terrorism in China, the Philippines and Thailand is mostly of the mismanaged separatist kind. The Prime Minister noted that Australia has increased counterterrorism spending by $1.5 billion since September 2014, and there is no doubt that within Australia the security agencies have done well – and done a good job of protecting Australia’s security. Australia’s regional efforts have been less convincing. For example, the Australian Bomb Data Centre (ABDC) was a key part of the regional network of bomb data centres, most of which the ABDC had been instrumental in setting up post-Bali 2002. However, in 2015, the Australian Federal Police, which hosted the ABDC, quietly closed it down and moved the function into its forensics area. I was told at the 2016 International Association of Bomb Technicians and Investigators Conference in Canada in July that the level of regional support from Australia has
020 SECURITY SOLUTIONS
declined significantly. (Most regional terrorism incidents are bombings.) In addition, the ABDC’s well-respected annual ‘bomb’ conference that brought together international experts will not run this year for the first time since 1996, and may be permanently discontinued. It is certainly true that the world faces a new type of threat from supporters of IS, but perhaps not as dangerous as the threat faced from Al-Qaeda, which had always been more interested in causing mass casualties. IS generally prefers simple operations using knives and vehicles because it thinks that the newsworthiness of the killing is more significant than the number of casualties. The brutal killing and attempted beheading of Fusilier Lee Rigby in London in May 2013 was an example of how a low casualty attack can be very effective in generating publicity. While knife and vehicle attacks usually kill only a few people, the Nice attack using a large cargo truck on 14th July 2016 killed 86 people, showing that a large vehicle can be a deadly weapon at a mass gathering. There should be no large vehicle access for major events in Australia like the ANZAC Day marches. Where there are combat-hardened IS returnees from Syria and/or availability of automatic weapons, IS-influenced attacks can be particularly deadly, as in Paris in November 2015 or Orlando on 12th June 2016, where 137 and 50 people were killed respectively. Firearm attacks with automatic weapons are far less likely in Australia. Australia does, however, need to be wary in the long-term of a resurgence of Al-Qaeda, which has been quietly rebuilding capability while the West has been fixated on IS. The most likely
type of Al-Qaeda attack is a person or vehicleborne improvised explosive device (IED); pressure cooker IEDs are also favoured. The Prime Minister also mentioned the potential threat to Australians overseas. This is certainly an ongoing security concern. The Sinai affiliate of IS was responsible for bombing a Russian Metrojet passenger aircraft in October 2015 with the loss of 224 lives. It is not beyond the bounds of possibility that a plane carrying Australian tourists out of somewhere with inadequate airport security – like Bali – could be similarly targeted. Australia could probably be doing more to help Indonesia improve its airport security. President Obama is still travelling to international meetings and assuring all and sundry of the US’s enduring security commitment to its friends, but the reality is that he is a lameduck president trying to protect his legacy and American interests. We will not really know where the US stands on national security until President Trump is in office. Trump is talking about stepping up US defense expenditure, which is already at 4.35 percent of gross domestic product (GDP). While Australia has always been a willing coalition ally, he may look at Australia less sympathetically in terms of the Australia, New Zealand, United States Security Treaty (ANZUS) and pulling its own weight when he learns Australia is spending only 1.71 percent of its GDP on defence.
Clive Williams is an honorary professor at the Australian National University’s Centre for Military and Security Law. He is also an adjunct professor at the Australian Defence Force Academy.
When a high level of security is essential, dormakaba Security Interlocks provide the ideal solution. Benefits include accurate people processing and the highest degree of separation.
Maximum security for sensitive areas
Security levels can be set according to individual requirements, including authorisation of access by external card reader, and additional interior checks, such as biometric verification, weight checking and two-zone contact mats. To learn more about our complete range of smart and secure access solutions, contact dormakaba. T: 1800 675 411 www.dormakaba.com.au
SECURITY SOLUTIONS 021
REGULAR
COMMUNICATIONS Airport Screening Offers No Assurance By Rod Cowan
If you are one of the 60 million passengers a year shuffling through security at Australian domestic airports, divesting yourself of belts and laptops and wondering if all these security measures have any point, you are not alone. Not even the Office of Transport Security (OTS) – the department responsible for the implementation and ongoing regulation of security controls at airports – can tell you, according to the Australian National Audit Office (ANAO). The ANAO, which operates under the Federal Auditor-General, recently tabled in Parliament a report of an independent performance audit of the Department of Infrastructure and Regional Development, titled Passenger Security Screening at Domestic Airports. Maybe it was the lack of a snappy title, or maybe the photo opportunity of former Prime Minister Tony Abbott having a cuppa with Pauline Hanson proved to be too alluring, but the report went entirely unnoticed by the media. In it, the ANAO notes the department is responsible for setting minimum standards and running compliance programs for airport screening. It goes on to say, “However, the Department is unable to provide assurance that passenger screening is effective, or to what extent screening authorities comply with regulations, due to poor data and inadequate records.” It adds, “The Department does not have meaningful passenger screening performance targets or strategies and does not direct resources to areas with a higher risk of non-compliance.”
022 SECURITY SOLUTIONS
The OTS has spent $272,428 on several aviation security reviews since 2009 that have all identified gaps and recommended improvements. As it turns out, the ANAO spent a further $521,345 to discover nothing new, “The Department has not addressed a number of systemic issues that hamper its ability to implement a risk-based regulatory regime and provide assurance as to the effectiveness of passenger screening. The need to develop performance measures, analyse compliance data, implement an enforcement policy and provide adequate training have been identified in successive reviews but solutions are yet to be delivered.” One example of such delays is in testing the detection of firearms, which one would think would be pretty fundamental. Among the system tests, one involves a replica gun used to check the screening process and its ability to detect firearms in carry-on baggage. The OTS suspended the test in March 2014 because of “firearms licencing and work health and safety concerns”. A 2016 risk mitigation plan identified “safety and operational risks” associated with the test, but pointed out additional risk controls and strengthened operating procedures could reduce that risk to an acceptable level. “Nevertheless, a decision on the future of this test is yet to be made, two years after it was suspended,” the report says. If you have ever thought things seemed just a little chaotic – such as screeners in one airport allowing one thing and those in another airport
saying differently – six procedural documents relating to the application of risk to the compliance program were provided to the ANAO during the audit, with the report stating, “All of the documents were undated and contained inconsistencies, primarily with regard to the number of applicable security mitigation categories in the compliance program. Some documents referred to eight categories and some referred to seven. Some documents listed eight categories in one part of the document and seven in another.” What hope does a screening officer have? To be sure, some people within the department have had a crack at getting things moving and, in fairness, there are some exceptionally dedicated people working in the OTS, but according to the ANAO report, “progress has been delayed”. However, lack of attention to aviation security of late suggests that it has somewhat gone off the boil. If you bear in mind the 9/11 hijackers used domestic aircraft to carry out their heinous attacks, if (when?) something happens in the future, no doubt someone, somewhere will be digging up this report as evidence that someone, somewhere dropped the ball. Meanwhile, we will have to keep shuffling through airport screening, never really knowing whether it is achieving anything. Rod Cowan is editor-at-large for Security Solutions Magazine and director of SecurityIsYourBusiness. com. He can be contacted via email: ssm@securityisyourbusiness.com
SECURITY SOLUTIONS 023
REGULAR
LEGAL Workplace Trauma: How Prepared Is Your Organisation? By Dr Tony Zalewski
Recent data on mental health and its prevalence across workplaces revealed it costs Australian businesses over $10B annually. However, despite this cost, it is reported that most organisations do not consider the impact of traumatic events until a crisis occurs. Being reactive in this foreseeable area of work means organisations are exposed to risks that can include reputational damage, operational disruptions, litigation and financial burdens. A recent case in Victoria considered two psychological concepts relevant to trauma suffered by a worker. These concepts are known as direct trauma and vicarious trauma. Direct trauma is first-hand involvement in a traumatic event, such as being immersed or witnessing death, serious injury or threat to the physical integrity of another, such as bullying. Vicarious trauma is attributed to a condition associated with regular or ongoing exposure to traumatic materials or hearing about traumatic events without direct exposure. The Victorian case settled with a monetary payment and the employer meeting costs for future counselling and support of the worker. Although there have been no reported studies that directly relate to trauma and stress for operational security officers, a recently reported US police study provides some insight that post-traumatic stress disorders (PTSD) in the operational environment are prevalent. Australian statistics for security staff and work-related injuries that include PTSD disclose those working in public safety are more exposed to traumatic types of incident, hence the importance of an
024 SECURITY SOLUTIONS
organisational risk strategy from both proactive and reactive perspectives. Organisations owe a range of duties and responsibilities to their employees. These are most evident under workplace health and safety, common law actions involving negligence or intentional infliction of mental suffering, and workers compensation law, hence the importance of careful and thorough planning in the context of workplace trauma. Safe Work Australia reports mental stress claims are the most expensive form of workers compensation claim, thus further exposing organisations to increased costs associated with traumatic events. Those suffering from post-traumatic stress typically will block reminders of the trauma (avoidance), replay the event (intrusion) or have increased arousal (hyperarousal), such as feeling irritable, being easily startled and having trouble falling asleep or concentrating. Sufferers of PTSD may also experience anxiety disorders, poor coping, depression, substance abuse, selfmutilating or other types of self-harm and often a breakdown in long-term relationships. This knowledge means organisations need to consider how operational risks in this regard might be managed as evidenced within the workplace health and safety ‘hierarchy of controls’ and post-incident supports offered to staff through an Employee Assistance Program that is: • accessible • confidential • trusted • well-regarded • supported by the organisation.
Of course, not all security officers exposed to traumatic events will suffer PTSD and many will merely return to work and continue performing at an acceptable level. However, organisations should remain cognisant that those exposed directly or indirectly to traumatic events should be offered support and monitored from a welfare perspective. Organisations on an ongoing basis need to consider risks associated with worker exposures to traumatic events and adopt a formal approach to eliminate or minimise risk in this regard. Such approaches must be carefully thought through. Improvements evident in such an approach should result in the retention of valuable employees, a reduction in absenteeism, improved productivity and an enhanced work environment.
Dr Tony Zalewski is a Director of Global Public Safety and a forensic security specialist with qualifications in law, criminology and the social sciences. He provides advice and training to governments and the private sector in Australia and abroad on matters relating to operational risk, security and safety. He is also an expert with practical experience in some of Australia’s leading civil actions involving security and safety.
THE ALL-NEWTXF-125E BATTERY OPERATED QUAD BEAM Introducing the eagerly anticipated TXF-125E; a high performance Quad Beam sensor designed for battery operation - perfectly suited for rapid deployment in creating temporary or permanent secure perimeter intruder systems. With 4 selectable frequencies, multiple beam sets can be used without crosstalk, whilst adjustable detection distance allows a single beam set to be re-deployed in a variety of installations throughout its operational life. Two 3.6V (17Ah) batteries power each unit for up to 5 years of service.
NEW!
ACTIVE IR BEAMS The ultimate in trouble free perimeter detection for distances up to 200m outdoor / 400m indoor.
+61 (3) 9544 2477
email: oz_sales@takex.com
HIGH-MOUNT PIR Triple mirror optics for maximum detection performance at 2 to 6m.
BEAM TOWERS Rugged floor and wall mounted enclosures in 1/1.5/2/3m heights.
INDOOR PIR Spot, 360°, wide angle, and curtain detection from 2 to 4.9m height.
OUTDOOR PIR Hard-wired or battery operated outdoor PIR up to 180° x 12m .
1300 319 499 csd.com.au www.takex.com
TAKEX AMERICA SECURITY SOLUTIONS 025
VIC: Mulgrave, Tullamarine NSW: Northmead, Waterloo ACT: Fyshwick QLD: Loganholme SA: Marleston WA: Balcatta
REGULAR
THINKING ABOUT
SECURITY
After The Atrocity By Don Williams Hopefully this column will appear as a discussion paper towards the end of a quiet year, not as points to be considered now the atrocity has occurred. Once the ‘incident’ has happened, security will once again be the centre of attention as it was after 9/11 and Bali. Security managers will find themselves being presented to the C Suite executives to explain what happened, why and what is in place to stop it happening to their organisation. There will be no shortage of advice as all of a sudden everyone will be a security expert, including accounting companies, as happened in 2001 and 2002. There will be a surge of marketing for security systems and hardware, whether they are relevant to the threat vector or not. The increased marketing will reflect the sudden, if probably short-lived, increase in security budgets. The security manager is in the unique position of being able to provide large doses of common sense and perspective, this being the sort of thing that security managers think about, study and discuss amongst themselves. So, what can the security manager do to cut through all the noise to actually improve security? Probably the first thing is to see if the probability of the attack method used can be reduced. Did it happen outside the targeted site? Did it happen in a public area where there are limited opportunities for control? Did it happen inside an access controlled area and, if so, why? If reasonable additional measures that will enhance rather than damage the functions and image of the site can be identified, then the wish list in
026 SECURITY SOLUTIONS
The postatrocity period is when the security manager is going to be the most popular, challenged and busy person in the organisation.
the bottom drawer can be brought out and funding demanded, realising that new hardware and supporting systems will take some time to install and implement. There may be a case for additional security guards to help monitor for copy-cat incidents and to reassure the executive and staff that security is responding. Noting that there will be a large demand for security personnel, the manager will need to ensure the guards are capable, briefed, trained, aware of what is expected and not working back-to-back shifts. Awareness training of staff can happen relatively quickly. Part of this may be working with the emergency manager and human resources to reassure staff that, while the atrocity was horrendous, measures are in place to protect them as much as reasonably possible and the whole issue is being reviewed in light of the latest attack. Probably the biggest benefit will be from observing how the attacked site responded and checking to see if the manager’s business would do any better. Are the security and emergency
plans and procedures adequate for this type of incident? Do the chief warden and security supervisor really understand their roles and responsibilities in this sort of catastrophe? When does the business continuity plan kick in and would it have worked in this scenario? Is the business really resilient? Are HR, media, legal, insurance, environment, workplace health and safety and other disciplines aware of their roles in such a crisis? Can the facility manager arrange urgent engineering inspections and repairs, particularly if everyone else around is also looking for glaziers? The post-atrocity period is when the security manager is going to be the most popular, challenged and busy person in the organisation. It is also when he can have the greatest influence. Hopefully, there is time to think about the ‘what if’ before the ‘what now’. Don Williams CPP RSecP ASecM can be contacted via email: donwilliams@dswconsulting.com.au
Recognize and Analyze How often was he here this month?
Is he a known suspect?
How old is she?
Are they employees?
When, where did she enter?
Is this valued customer Mia Clark?
How many people are here? Is it too crowded in this area? New: Recorded media import and advanced investigation tools upload sets of videos recorded at a specific location and time to track possible participants in a crime find a person enrolled in an image database or search for an unknown person locate appearances in multiple videos make use of filters that specify age ranges, gender, ethnicity and glasses
FaceVACS-VideoScan uses premier face recognition technology to detect and identify persons of interest while computing demographic and behavioral data, supporting security staff, marketing teams and operations management.
SECURITY SOLUTIONS 027
REGULAR
EVENTS Total Facilities 29–30 March 2017 International Convention Centre, Sydney Total Facilities presents two-days of discussion and discovery for FM and like-minded professionals. It combines Australia’s largest offering of innovative facility products and services with forward-thinking strategies to optimise facility and workplace performance. A thriving exhibition floor featuring over 150 leading brands will showcase real solutions to meet operational challenges, whilst freeto-attend educational seminars offering bold perspectives and latest FM thinking will raise methodologies to drive business performance. Join Australia’s largest community of FM minds for unrivalled networking and engaging discussion for enhancing our living-working environments..
Learning options Three categories of attendance have been devised to provide attendees and their organisations with flexibility and return on investment: 1. Conference: for senior and aspiring leaders in need of the most complete learning experience, including keynotes, masterclasses, executive sessions and exhibition access. 2. Training: for team members and managers seeking to gain focused, practical skills with well-defined learning outcomes. 3. Show Pass (exhibition + technology & solutions track + career centre): for professionals primarily interested in dialogue with leading innovators and advisors about designing future-proof security solutions and professionals seeking advice and experience sharing to boost their security management career
For more information visit: www.totalfacilities.com.au
Visit www.asiseurope.org for full details on the packages available and applicable fees.
ASIS Europe 2017 From Risk To Resilience 29–31 March 2017 Mico, Milan, Italy
ISC West 5–7 April 2017 Sands Expo Centre, Las Vegas
At a time when the Internet of Things is making established lines of responsibility obsolete and the risk of terrorism and political turmoil mean physical threats remain all too real, ASIS Europe 2017 tackles the most challenging issues. Cyber-physical threats in hyper-complex, connected environments are the core themes of the event. ASIS, as a global community of security practitioners tasked with the protection of assets – people, property and information – is uniquely positioned to deal with enterprisewide risks. If you are responsible for keeping organisations secure, sustainable and resilient, join ASIS in Milan in March 2017.
ISC WEST is THE largest security industry trade show in the US. At ISC West you will have the chance to meet with technical reps from 1,000+ exhibitors and brands in the security industry and network with over 28,000 security professionals. Find out about new and future products and stay ahead of the competition. Encompassing everything from access control to Facial Recognition software, you are sure to find products and services that will benefit your company and clients. This year don’t miss our new IT Pavilion featuring the latest cyber security solutions.
028 SECURITY SOLUTIONS
Working with SIA, ISC also features world class education to learn about every facet of the security industry. For more info on SIA Education@ISC visit: www.iscwest.com
Safeguarding Australia 2017: Turning Points in Security 3–4 May 2017 QT Canberra, Canberra Competing priorities, growing threats and increasing complexity will continue to present fundamental challenges to Australia’s national security agenda in the coming years. Public and private security professionals – policy makers, practitioners and providers – will be forced to address a wide range of issues which have developed over recent decades and continue to grow, such as violent extremism, cyber threats (from lone and state actors), border control and legislation. In coming years, they will need to also contend with the security issues inherent in societal issues, adding known-unknown dimensions to an already complex national security agenda, most notably an ageing population, technology creeping into all facets of life and diversity in the workplace reflecting an increasingly cosmopolitan society. Safeguarding Australia 2017 will help face those challenges and shape the security agenda, by taking on its most demanding theme to date: Security at a Turning Point – Innovation, Leadership and Diversity. For over 14 years, the Research Network for a Secure Australia (RNSA), a not-for-profit network of security policy makers, professionals and academics, has gathered at the Safeguarding Australia annual national security summit to hear from high-level speakers representing both government and corporate
SECURITY SOLUTIONS 029
REGULAR
EVENTS viewpoints, exchange ideas, debate issues, and learn about techniques, cases studies and ground-breaking research, to meet the security challenges of today and the solutions for tomorrow. In addition to briefings on current policies, trends and activities, Safeguarding Australia 2017 will go further by drawing on local and international experts to examine three overarching themes affecting the way security and risk is managed to protect the nation, namely: 1. Innovation – exploring knowledge around technology, standards and research. 2. Leadership – focusing on the next generation, the greying population and education. 3. Diversity – in particular, the role of communications as a security tool addressing disparate ethnicities, genders and culture. In addition to a pre-conference workshop currently being designed, Safeguarding Australia 2017 will begin by outlining current challenges and activities and lead into defining future directions and solutions. Safeguarding Australia is the only high-level conference run by and for leading thinkers, policymakers and practitioners in the national security domain, working across wholeof-government at state and federal levels, including law enforcement and intelligence agencies, as well as engaging with corporate and private security practitioners and providers. Past attendees and current bookings include: • senior representatives from security, intelligence, military and law enforcement
030 SECURITY SOLUTIONS
• risk and security managers and consultants • agency security advisors • critical infrastructure owners and operators • engineers, scientists, technologists, researchers and academics • corporate and business executives responsible for security and risk.
Expo and Service Management Expo, catered for those working across many platforms in building management and protection of people and information.
Visit safeguardingaustraliasummit.org.au for more information.
Security Exhibition & Conference 2017 26–28 July 2017 International Convention Centre, Sydney
IFSEC International 20–22 June 2017 ExCeL London The global stage for security innovation and expertise IFSEC International is the biggest security exhibition in Europe taking place over three days between 20 to 22 June 2017 at London ExCeL. IFSEC welcomes over 27,000 global security professionals to experience the latest technological innovations and hear from industry leaders – all under one roof, over three days. The event caters to everyone within the security buying chain from manufacturers, distributors, installers, integrators and consultants to end users. With over 600 exhibitors showcasing over 10,000 products, you will be able to find the perfect security solution your business is looking for. There’s more to it than just security. IFSEC International is co-located with FIREX International, Facilities Show, Safety & Health
For more information or to register please visit www.ifsec.co.uk
We’re excited to be heading back to Sydney from 26–28 July, 2017 to the brand new International Convention Centre in Darling Harbour and the anticipation is palpable. Early bird registrations will get access to one-off exclusive VIP Early Bird rates for the ASIAL Conference 2017. Get in early to take advantage of this special discount and avoid disappointment as the 2016 program SOLD OUT. By visiting the site and registering early, you will also be entered into the VIP Early Bird prize draw for your chance to WIN 2 tickets to the annual Security Gala Dinner PLUS one night accommodation including breakfast at the Novotel Darling Harbour. The Security Gala Dinner is the annual celebration of the industry’s successes and with this prize you can really make a night of it with overnight accommodation at the Novotel Darling Harbour in a Loft Suite with Harbour views. To register now visit securityexpo.com.au
GAIN CONTROL WITH ONEVIEW Defuse situations quicker with a truly unified security control room solution Saab’s OneView is a next-generation physical security information management integration platform that provides unprecedented levels of subsystem integration in mission-critical infrastructure environments. OneView empowers operators to respond effectively and efficiently to the most stressful situations. Offering accurate intuitive situation awareness, a simple operator interface, fast detection-response and comprehensive support for post action analysis, OneView is the ultimate choice for modern surveillance and security operations. You can rely on Saab’s thinking edge to bring your control room under real control. saab.com/australia
032
Risk Management As A Business Game
033
By Alexei Sidorenko
In 2014, I collaborated with Ernst and Young (EY) to develop Russia’s first risk management business game. It was great fun and, as a result, we created a pretty sophisticated business simulation. In the game, participants are split into teams of 10, with each person receiving a game card that describes their role (CEO, CFO, risk manager, internal auditor and so on). At the start of the game, each team must choose one of four industry sectors (telecom, oil and gas, energy or retail) and name its company. The game consists of four rounds; in each round, teams must make risk-based decisions. Each decision has a cost associated with it and a number of possible outcomes. Teams must analyse and document the risks inherent in each decision they make. The riskier the decision, the higher the probability of an adverse outcome. At the end of each round, a computer simulation model chooses a scenario and the outcome is announced to each team. Each decision has consequences and the outcome may either make money for the business or lose money. The aim of the game is to increase the company’s valuation by properly weighing up risks and making balanced business decisions. The winning team is the one that increases its company’s value the most after four rounds. This game was successfully played by participants at two risk management conferences, as well as by postgraduate students at the Moscow Institute of Physics and Technology. More information about the game is available here: http://www.riskac ademy.r u / en / r isk- m anagem ent- g am e version-a/ (Let me know if your company is interested in sponsoring the translation and running the game in English.) Risk Management Business Game 2015 In 2015, I started working with Palisade to develop something a little different. Just like in the previous version of the game, the participants are split up into teams of 10. However, the game mechanics changed
034
substantially. Each player still receives a card describing his/her role, but this time the card provides a complete history of the character’s role within the company and assigns each player a unique secret mission. The aim of the game is to successfully complete a merger between a large holding company and an innovative startup. The game, as before, consists of four rounds. The first round involves performing a risk assessment of the target company. Each team must identify 10 significant risks using only the information provided on the cards. The second, third and fourth rounds are dedicated to the management of these risks. Each identified risk has between five and 10 possible mitigation strategies that can be selected by the team. Each team has a limited budget dedicated to risk mitigation and each mitigation action has a cost. The effects of each mitigation action selected by the teams were modelled using Palisade @RISK to determine whether it increases or decreases the value of the target company. The winning team is the one which increases the value of the target company more than the others and is then able to successfully complete the merger. More information is available at: http://www.risk-academy.ru/ en/risk-management-game-version-b/ (Let me know if your company is interested in sponsoring the translation and running the game in English.) Risk Management Business Game 2015 (online version) With the help of eNano, we went even further and produced an interactive risk management business game (only available in Russian). This game combines an e-learning course and an interactive business simulator. Each participant takes on the role of general manager of one of three innovative companies. They then receive tasks that need to be completed throughout the e-learning course. Participants need to: Conduct interviews with all colleagues to identify and document risks.
1
2
Evaluate risks using the information presented (note that just like in real world, most of the information presented is biased). Make difficult decisions relating to risk mitigation given a limited budget. Develop an action plan designed to improve risk culture. All of these steps increase or decrease the company valuation. You can find out more about this course at: risk.edunano.ru
3 4
Risk Management Game 2016 This game is the result of collaboration between Risk-academy, Palisade, Institute for Strategic Risk Analysis (ISAR) and Deloitte. Together, we have created an amazing business game to teach non-financial management and staff how to perform risk modelling on day-to-day management decisions. Participants play the role of an aircraft engine manufacturing company. Each team has prepared a business case for a multimillion dollar plant modernisation. Unfortunately, the project plan has just been rejected by the Board, so teams only have a couple of hours to conduct in-depth risk analysis and present an updated business case to the Board. The game focuses around risk modelling, requiring participants to identify and validate management assumptions, identify relevant risks, establish ranges and select possible distributions for each assumption, perform Monte Carlo simulation using Palisade @ RISK and present the final results. All of this has to be performed in limited time and with incomplete information, just like in real life. And just to add a little bit of drama, like in real life, participants have to deal with unexpected ‘black swans’ during the game. The team with the highest risk-adjusted rate of return wins. This game has also become one of the modules in the risk management training ran by ISAR. More information is available here: www.isar.institute (in Russian).
What is Next? The latest game was both hard and entertaining, so we began talks with our partners to turn it into an online risk quantification championship. The games will require online registration, have downloadable content and require proper risk modelling. Championships will run once a quarter and winners will receive wonderful prizes. More information will be coming soon. Alexei Sidorenko is an expert with over 13 years of strategic, innovation, risk and performance management experience across Australia, Russia, Poland and Kazakhstan. In 2014 Alexei was named the Risk Manager of the Year by the Russian Risk Management Association. As a Board member of Institute for strategic risk analysis in decision making, Alexei is responsible for G31000 risk management training and certification across Russia and CIS, running numerous risk management classroom and e-learning training programs. Alexei represents the Russian risk management community at the ISO Technical Committee 262 responsible for the update of ISO31000:20XX and Guide 73 since 2015. Alexei is the co-author of the global PwC risk management methodology, the author of the risk management guidelines for SME (Russian standardization organization), risk management textbook (Russian Ministry of Finance), risk management guide (Australian Stock Exchange) and the award-winning training course on risk management (best risk education program 2013, 2014 and 2015).
SECURITY SOLUTIONS 035
ALARMS
036 SECURITY SOLUTIONS
By Michael Brookes
The time has come to upgrade that outdated security system you have been operating for what seems like an eternity. You have done your homework and built your business case, and you have finally been granted approval to proceed. As your mind fast-forwards with visions of an intuitive security-centric design, multi-camera views, synchronised and instant playback, and motion searching for improved forensic analysis, you know that your security operators will be able to better manage threats and reduce reaction time. As you head for the door to share the great news with your colleagues, you hear a sound, the corporate bean-counter saying “Before you get too excited, I want you to make sure this system is future-proof. We don’t want to be doing this again in two years.” There is always a catch! So what does future-proof really mean? A quick look at the online dictionary defines future-proof as being protected from consequences in the future, especially pertaining to a technology, that protects it from early obsolescence. With the rapid rate of change in technology, how can you then expect to future-proof your security system? To start with, your new security solution should be flexible. By deploying a system that subscribes to global standards for open integration you will be able to take advantage of either a dedicated or existing IT infrastructure. This makes it easier to interoperate with other business systems, and is adaptable to future requirements that may arise. The ability to integrate with thirdparty software and hardware field devices promotes freedom of choice in deploying a comprehensive solution that can be delivered in any combination for increased workplace performance. An investment in an open integration platform is a forward thinking investment, providing you with the power to design your technology roadmap to the unique operational requirements of your business.
New capabilities in service-oriented architecture (SOA) enable the rapid development of applications and real-time open communication between critical systems over your network. Enterprise Web Services make it easier to develop custom applications to meet your facility’s unique operational challenges. Features include: • Improve ROI over life cycle – Converged solutions reduce complexity, often resulting in lower operational and maintenance costs. • Investment longevity – IP networking provides a longer-lasting open system. • Flexibility to expand – Integrating with open system protocols supports future system growth to optimise ROI. Business resilience is another key consideration in future-proofing your security system. Business resilience is the ability an organisation has to quickly adapt to disruptions while maintaining continuous business operations and safeguarding people, assets and overall brand equity. A solution that is designed with high-availability architecture can insulate you from single-point-failure and can be distributed across multiple facilities to promote maximum system up-time. Business resilience goes a step beyond disaster recovery by offering post-disaster strategies to avoid costly downtime, shore up vulnerabilities, and maintain business operations in the face of additional, unexpected breaches. Response is better supported because networked physical security solutions are collaborative. Collaboration drives operational flexibility. For example, security personnel are able to view, monitor and respond to incidents from anywhere and from any device. Prevention of loss, connecting physical and logical IT security can be more easily and quickly supported, and policies can be implemented on a global basis.
SECURITY SOLUTIONS 037
ALARMS
Deterrence is better supported because Network Physical Security solutions are more scalable, and can be quickly deployed with thousands of endpoints using an existing converged IP network infrastructure at a lower cost. Network Physical Security solutions also make better and more flexible use of human resources. Detection is better supported because Network Physical Security solutions enable open standards, APIs and eco-system partners and applications. The end result is that new common-off-the-shelf applications and capabilities can be more easily and quickly deployed, further driving business results and competitive advantage. Network physical security solutions are more adaptive and never obsolete, thus reducing the need to overhaul infrastructure to upgrade technology. Increasing focus on developing standards in the IT world enables end-users to upgrade technology easily, be it a wired or wireless environment. Designing a security solution with this in mind means that you will need to consider a broader section of the business to fully understand what is required to protect your people, business and data. This deeper engagement with other stakeholders is also useful to identify what other requirements of the business can be met. It is important to understand how a business can leverage its investment in technology not just today, but five or 10 years from now. This can only be achieved by understanding the vision of the business and the other departments so that their needs can be catered for in the future. Video surveillance systems with embedded content analytics can help the business collect marketing data and improve operational efficiency. Data collection around retail spaces in particular can be used to see what kiosks and stores attract shoppers’ attention and help increase revenues in stores. Similarly, digital signage presents the opportunity for businesses to bring information to life in new and exciting ways. In public spaces or within an organisation, it is a way of enhancing an environment, improving communication and influencing customer behaviour. Whether across an airport, a university campus, a stadium or a retail
038 SECURITY SOLUTIONS
branch network, it is easy to connect and centrally control large, disparate systems, yet tailor content and messages to specific locations. This is driving additional revenue streams by providing dynamic content to help customers get directions and maps to local attractions, look for a place to eat or go shopping, review area entertainment options, check in for their flights and print boarding passes, even access the internet if they want to. This same signage can integrate with the security system and act as an emergency warning display if an evacuation is ever required.  So it seems that future-proofing your security system is actually possible; however, it requires focus in a number of areas. Organisational alignment By obtaining a thorough understanding of the organisational tolerance to risk, the depth of security requirements can be ascertained. This needs to take into account the security requirements at a business unit level. Roles and responsibilities for security need to be defined throughout the organisation with involvement from physical security personnel, IT, business units and vendors. Process alignment The security requirements of business processes and operations should be defined, with enterprise-wide security solutions being integrated into processes and applications. Process owners and users need to be made aware of the importance of security. Strategies and architectures Security strategies and architectures need to be clear and actionable, with a level of flexibility to address potential changes to the organisation or technology. Technology integration It is important to be involved in selecting the technology solutions to ensure that organisational requirements are met. It is wise to pilot selected technology to validate the solution. Once validated, the solution should be implemented in phases, allowing
for the highest priority areas to be dealt with first, with ongoing testing of performance and functionality. Roll-out A roll-out strategy should be developed that allows for the solution to be deployed in phases. It is vital to ensure that all of the stakeholders are adequately trained in order to gain their continued buy-in. Once rolled out, ownership should be transferred to the appropriate business units or functions. Maintenance Ongoing maintenance of corporate security management requires adherence to the initial business policies and procedures. Regular audits should be performed to confirm that policies and rules are being abided by and the solutions modified in line with changes to the business. There are clear benefits to be derived from an active and strategic approach to corporate security management and the implementation of a converged security infrastructure. Organisations can take a holistic view towards risk management and compliance, whilst reaping the rewards of systems that have lower costs of administration and support. Organisations seeking to embark on such a strategy need to be clear on the outcomes expected and ensure that buyin is gained at all levels; these strategies need to be closely aligned with business objectives, and not be viewed as simply a security project. A phased approach should be taken and appropriate time allocated to the process. Key objectives should be set to measure the benefits of each stage as it is rolled out. It is important to work with organisations capable of delivering comprehensive and best-of-breed security solutions. This provides the benefits of accountability, risk mitigation and knowledge transfer, not typically available from a multi-vendor approach.
Michael Brookes is the Regional Leader, Marketing & Strategic Development – Pacific, Honeywell Building Solutions.
PR N O EW D U C T!
For over 30 years Perimeter Systems Australia has been delivering Perimeter Intrusion Detection Systems (PIDS) to Critical Infrastructure, Government, Industrial and large Commercial customers.
The latest threat to security, just got [detected]
Features • • • • •
360° Asymmetrical Detection 1,000 metre detection Radius Radio Frequency Detection Drone and Operator GPS Coordinates Integrates with existing systems
Palmgrove Business Park, D413-15 Forrester St. Kingsgrove NSW info@perimetersystems.com.au | www.perimetersystems.com.au
In the wrong hands drones literally add a new dimension to eavesdropping and spying on facilities, individuals and infrastructures in a wide variety of environments and industries. They have the power to shrink the realm of public safety, privacy and physical security. Few other technologies have this much power.
Call us on (02) 9150 0651 or visit www.perimetersystems.com.au SECURITY SOLUTIONS 039
040
Post-Trauma Stress: Officer Wellbeing Post Confrontation [ Part 1 ]
041
By Richard Kay Post-traumatic stress disorder (PTSD) is often referred to as a self-inflicted malady, and this is true to some extent. But it is inflicted out of ignorance. Once individuals have knowledge of what can occur under stress and how to ‘release it’ through breathing and debriefing, they are no longer ignorant. Part one of this two-part article discusses the emotional reactions officers may experience after experiencing or witnessing a traumatic event. Officers may have little control over when confrontations occur, but they do have control over how they respond to these events before, during and after. This is critical, because if there is no sense of intense fear, helplessness or horror, there is no post trauma. There is no fear because tactical breathing keeps the heart rate down. There is no helplessness because the training was appropriate and taught officers what to do. There is no horror because officers were inoculated against trauma. Officers have undergone a critical incident debriefing and worked their way through the event to make peace with the memory. They knew what to expect and, even though it may have been ‘different’ to what they expected, they were forewarned, and therefore forearmed, to survive. Listed below are the diagnostic criteria for PTSD (Diagnostic & Statistical Manual of the American Psychiatric Association): A. Exposure to a traumatic event in which both of the following were present: 1. experienced, witnessed or was confronted by events involving actual or threatened death or serious injury… of self or others 2. response involved intense fear, helplessness or horror (the disorder may be especially severe or longer lasting when the stressor is of human design, for example, torture, rape) B. Traumatic event is persistently re-experienced in one or more of the following ways: 1. recurrent, intrusive, distressing recollections of the event 2. acting or feeling as if the event were recurring including: ‘sense of reliving’ the experience, illusions, hallucinations and flashbacks, including while awakening or intoxicated 3. intense psychological distress at exposure
042
to internal or external cues that symbolise or resemble an aspect of the traumatic event 4. psychological reactivity on exposure to internal or external cues that symbolise or resemble an aspect of the traumatic event C. Persistent avoidance of stimuli associated with the trauma, or numbing of general responsiveness, as indicated by at least three of the following: 1. efforts to avoid thoughts, feelings or conversations associated with the trauma 2. efforts to avoid activities, places or people that arouse recollections of the trauma 3. inability to recall an important aspect of the trauma 4. markedly diminished interest or participation in significant activities 5. feelings of detachment or estrangement from others 6. restricted range of affect (for example, unable to have loving feelings) D. Persistent symptoms of increased arousal (not present before the trauma), as indicated from two or more of the following: 1. difficulty falling or staying asleep 2. irritability or outbursts of anger 3. difficulty concentrating 4. hyper-vigilance 5. exaggerated startle response 6. [self-medication] E. Duration of the disturbance (symptoms in B, C, D) of at least one month F. The disturbance causes clinically significant distress or impairment in social, occupational or other important areas of functioning Acute: if duration of symptoms is less than three months Chronic: if duration of symptoms is greater than three months With delayed onset: if symptoms were at least six months after the trauma Emotional Reactions Relief: The first response of most people upon seeing sudden, violent death is relief; they are relieved it did not happen to them. The midbrain, that part concerned about survival, sends out a message saying ‘hey, that could have been me’. This is not selfish, or inhuman, or cold; it is a normal survival reaction. If officers know in
Officers may have little control over when confrontations occur, but they do have control over how they respond to these events before, during and after.
In the stress of a violent encounter, the tendency to accept responsibility for what happened can be a powerful one.
advance that it is normal upon seeing trauma and death to think, ‘thank goodness it was not me’, then that thought will not have the power to hurt them later. Guilt: Witnessing a person suffer trauma causes the normal response of ‘I am glad that was not me’. Later, on reflection, the person feels guilty because no one ever said that the normal response of most people upon seeing a traumatic event is to focus on themselves and feel relief. In the stress of a violent encounter, the tendency to accept responsibility for what happened can be a powerful one. The midbrain can hit the person with an ‘it is all my fault’ response. Proper debriefing is important for officers to understand their role in the overall event. Doubt: There are many burdens that weigh upon an officer, and one of the greatest is uncertainty. The constant anticipation of being involved in violent encounters can have a profoundly toxic effect, especially when this stress continues over months or years. For officers, there is a constant possibility that just around the next corner there might be an individual who will dedicate all his energies to causing them harm. When they are warned that something might happen, they can more easily control the amount of stress experienced. However, if they spend their life in denial and then something happens, it can hurt officers seriously. Uncertainty will dissipate when officers are mentally prepared and accept the fact that their job has the potential to place them in harm’s way. Fear: If a stressful trauma is severe enough, it can create an associated fear response that lingers well after the event. This is where situations of a similar nature, or stressors related to the event, set off arousal mechanisms under actual circumstances that are not threatening to an officer at all. It is also common for officers to relive the event, or parts of the event. This type of response is related to PTSD and, once recognised by the officer or others, it should be examined and dealt with. Anger: Officers may feel anger after a traumatic event has passed, commonly anger at the fact that the event happened in the first place. No one has the right to harm officers, and they are likely to feel very indignant if they are put
in danger by the very people they are working to protect. There is no use trying to rationalise the irrational, but officers will attempt to do it anyway. This is where professional counselling can be of use to provide an officer with a framework to hang the event on and tools for making sense of it. Officers may also experience anger from their loved ones, surprising as it may seem. If someone has tried to harm them, it is common for officers to experience anger from their spouses. Rather than react to this, officers should keep in mind that they are not actually angry at them, but rather the person who caused the trauma and the irrationality of such events, but since these factors are not readily available to remonstrate with directly and they are, then they will receive this deferred anger. Understanding and emotional openness are important to work through this, not shutting off and distancing themselves from loved ones. Denial: Some officers, after experiencing a traumatic event, enter a state of denial. This may take several forms, such as denying the event ever occurred, or denying specific parts of the event, to even trying not to think about the event at all. None of these reactions are positive or healthy, and they will not help the officer deal with the event. It is important to make peace with the memory of the event, and the first step in this process is to delink the memory with the emotions. This means eliminating the associated stress-related arousal symptoms that may occur when recalling or reliving the event. The aim is to reach a stage where the officer can remember the event without creating arousal. Proper debriefing, support and counselling are important in this process. Part two of this article in the next issue of Security Solutions Magazine will discuss the debriefing process and post-event protocols that help officers heal.
Richard Kay is an internationally certified tactical instructor-trainer, Director and Senior Trainer of Modern Combatives, a provider of operational safety training for the public safety sector. For more information, please visit www.moderncombatives.com.au
SECURITY SOLUTIONS 043
CCTV
044 SECURITY SOLUTIONS
Analysing The Total Cost Of Ownership Of Video Surveillance Systems
SECURITY SOLUTIONS 045
CCTV
By Winston Goh
Imagine you are responsible for a safe city project and you are tasked with deploying a multimillion-dollar video surveillance system. Where would you start? How would you evaluate tenders? How would you assess upfront costs in relation to the longterm operating costs? And which areas of the system should you focus on to optimise its total lifecycle cost? These are just some of the questions you need to ask to minimise risk and avoid unpleasant surprises once the system is deployed. This total cost of ownership (TCO) study presents a comprehensive picture of the total cost for a large hypothetical surveillance system in a major city. It shows how costs are divided between different parts of the system, as well as the different phases over the 10-year lifecycle of the system. It also includes an analysis of certain factors that sit outside the TCO, such as business costs due to system downtime. Finally, this model shows how camera technology and product reliability could impact the total cost of ownership in a significant way. Definition of TCO TCO is a financial estimate model that intends to capture all the costs associated with an activity over its complete lifecycle. TCOs are used in many industries as a tool to correctly estimate the direct and indirect costs of deploying a system, and as a tool to compare different systems with different characteristics and cost distribution. In a fact sheet from 2009, Accenture defines total cost of ownership as “defining the range of costs associated with the asset lifecycle including research, development, procurement, operation, logistical support and disposal of an asset.” Purpose of a TCO – how can it be used? A TCO, when included in any financial analysis, provides a cost basis for determining the total economic value of an investment and as a product/process comparison tool. A TCO can: • help project teams understand how the cost is distributed over time, from installation to operation and decommissioning
046 SECURITY SOLUTIONS
• help to understand the distribution of costs between different system components • minimise the risk of unforeseen costs that can erode budgets • help to focus efforts and reduce costs over time • help during discussions with stakeholders about long-term perspective and lifetime expectancy of a system • be a contributing factor, out of many, when evaluating project tenders. Methodology and Considerations Every TCO is unique. It is important to point out that there is no single uniform TCO model that fits every project. On the contrary, every project has a unique cost distribution, and it is up to each project team to determine which cost factors to take into account and how to judge the monetary aspect of each factor. Industry differences Even though many of the cost factors presented here are common in surveillance projects across different industries, there are many that will be different. For example, in an airport or critical infrastructure installation, the consequences of system downtime are vastly different from a school district. Another example is the lifespan: in some industries, such as city surveillance,
a system could be expected to remain in place unchanged for years, while in others, such as a retail environment, cameras may be moved around and the system upgraded on a regular basis. Who carries the cost? This TCO model captures and assesses a number of system costs that occur during acquisition, as well as over time, in a hypothetical city surveillance project. However, this analysis does not define who actually has to carry the cost in the end. In some projects, it might be the end customer that pays for everything, while in other projects the system integrator will carry the cost for some areas. Naturally, it will also depend on the warranty agreements, service level agreements, financing and so on. Developing the TCO To develop this model TCO, the following steps have been taken: 1. Determining the cost factors 2. Defining an example system 3. Analysis of the results Data sources and research This TCO information is based on data gathered from a number of sources to determine cost factors and reasonable values to enter into the system. Sources for
TCO is a financial estimate model that intends to capture all the costs associated with an activity over its complete lifecycle
While the acquisition costs and the decommissioning costs only occur once, the operating costs occur continuously throughout the system lifecycle. The size of the operating cost is then heavily dependent on the expected length of the system service time.
this project include: • interviews with system integrators • interviews with end customers • data from Axis using existing similar projects • knowledge, experience and statistics from Axis support, sales and field engineering organisations • data available from security industry organisations and other security sources. The data gathering and development of the model took place during 2015, which means factors such as equipment prices, labour and maintenance costs represent a snapshot of the market situation during that period of time. Determining the Cost Factors The lifecycle phases of a surveillance system To create a simple overview of all the costs that affect the TCO of a video surveillance solution, the cost factors have been categorised according to the activities and the chronological order in which they appear throughout the system lifecycle. The ownership of a product can be divided into three phases: acquisition, operation and decommissioning. Following these phases, the costs are then divided into three main categories: total cost of acquisition, total operating cost and total decommissioning cost. The costs in each of the main categories vary in nature. While the acquisition costs and the decommissioning costs only occur once, the operating costs
occur continuously throughout the system lifecycle. The size of the operating cost is then heavily dependent on the expected length of the system service time. Factors covered in this TCO As stated above, some direct costs as well as some indirect costs are obvious when purchasing a surveillance system. For example: • hardware investment • software investment • costs for warranties • installation and integration cost • user education. However, these are only a few of the costs that can be incurred during a system’s lifecycle. In this TCO, a total of 40 cost factors have been taken into account, including project management, operation, maintenance, decommissioning and much more. Examples of factors not covered in this TCO There are a number of factors that could have been included in the TCO model, but were omitted. One reason for not including these costs is that estimates vary considerably between industries. This could skew the TCO in the wrong way. For example, the costs for alarm failures and costs incurred in the business operation due to system downtime will have very different consequences for a headmaster in a school compared to the security manager at a nuclear power plant.
There are other costs that have been excluded from the TCO because they are potentially so huge that they dwarf the overall system cost – for example, salary costs for staff that operate a monitoring centre, or the cost of a climate-controlled server room for storage. Examples of costs not included in this TCO are: • extended warranty • freight • system inspection • insurance • server room • software failure • alarm failure • business costs as a consequence of system downtime • staff costs in operations centre. The latter two will, however, be explored in separate sections later in this article. Defining an Example Project The example project in this TCO model is a large-scale city surveillance project in a mature market. The project includes 1,500 outdoor cameras and an enterprise-class video management, network and storage solution. Attaching values to each factor Values/costs have been defined for all factors based on the extensive input as described in an earlier section. Examples include: • prices for all products are manufactured suggested retail prices (MSRP) without any discounts
SECURITY SOLUTIONS 047
CCTV
• 13 labour roles are defined, ranging from an administrator to a senior consultant • labour costs range from USD 35 (AUD 47) to USD 200 (AUD 271) per hour depending on role • electricity cost is USD 0.13 (AUD 0.18) per kWh • cable installation time is estimated at four hours per camera • camera installation time is estimated at two hours per camera • camera maintenance is estimated to happen twice a year. Analysis of the Results Total cost of ownership for the city surveillance project The analysis of the TCO in this section focuses on the relative distribution of cost in percentages and less on the actual dollars and cents. But to create an understanding of the magnitude of this system, the first conclusion is that the total cost of ownership for this 1,500-camera system over a 10year period amounts to approximately USD 17,000,000 (AUD 23,035,543).
From a sustainability perspective, it is essential to properly dismount and recycle equipment at the end of its lifetime, and these costs must be factored into the system’s lifecycle.
Costs for products vs. other costs Another top view of the TCO is the division between product costs and other costs. In this TCO, as shown in Figure 2, about half (49 percent) of the total costs relate to direct upfront costs for the purchase of cameras, software and other equipment – also referred to as contract costs. The other 51 percent are costs relating to design, installation, maintenance and so on.
Cost per system phase See Figure 1 for the percentage of cost split during the lifecycle of the system. The cost per system phase amounts to: 1. total acquisition cost: USD $11,400,000 (AUD 15,447,364), or around 67 percent 2. total operating cost: USD 5,200,000 (AUD 7,046,166), or around 31 percent 3. total decommissioning cost: USD 300,000 (AUD 406,510), or around two percent Figure 2. Contract costs compared to other costs
Detailed costs per area Looking closer at the TCO, Figure 3 and Figure 4 present two different views of the detailed distribution of costs during the lifecycle.
Figure 1. Share of costs during the lifecycle
048 SECURITY SOLUTIONS
Acquisition As stated above, almost half the TCO is made up by the initial product investment, also referred to as contract cost. Around two thirds of that contract cost, or 34 percent of the whole TCO, is for video management software, network, storage and hardware
other than cameras. A third of the contract costs is camera cost, making up around 16 percent of the TCO for the system. The other costs that occur during ‘year zero’ of the system in this model are precontract and deployment costs. Precontract costs include, among other things, system design and vendor evaluation. Deployment costs cover everything connected to installation, configuration and integration. Together, pre-contract and deployment costs account for around 18 percent of the TCO. Operation During operation of the surveillance system, a number of costs are incurred, the main one being system maintenance. This covers all planned and regular maintenance (for example, cleaning) of cameras, servers, software and so on. Operation also includes costs due to system failure as well as software licence fees and power consumption. Maintenance costs represent the single largest share of the TCO for this system, amounting to around 20 percent of the TCO. Other operating costs add up to approximately 12 percent. Decommissioning The decommissioning of a surveillance system is very important and is often overlooked in the initial costing stage of a project. From a sustainability perspective, it is essential to properly dismount and recycle equipment at the end of its lifetime, and these costs must be factored into the system’s lifecycle. In this TCO model, the decommissioning costs represent 2 percent of the total cost.
Figure 3. Cost distribution of the TCO in percentages
For example, in an airport, if the surveillance system fails, it could lead to very high costs as extra security guards may need to be dispatched, or flights might be delayed. In a retail store, a failed surveillance system may impact the ability to prosecute perpetrators for fraud and shrinkage, leading to substantial losses. In some city surveillance situations, camera maintenance crews need to be accompanied by police or guards when going out on site, which would increase the downtime costs substantially. In the TCO, when operating costs are calculated, business downtime costs have been excluded. However, the TCO model makes it possible to make an estimate and see how business downtime costs could impact the TCO. For example, assume that it is necessary to dispatch one security guard to protect the installer as he goes to a camera location to fix a problem or replace the camera. Adding the security guard cost – only labour in this case – increases the share of the operating cost from 31 percent in Figure 1 to 33 percent, as you can see in Figure 5.
Figure 4: The cost distribution of the TCO in money (USD)
Observations on costs not included in the TCO Security costs due to system downtime When compiling this TCO model, security costs that appear from the downtime of a failed surveillance system were excluded. However, when it comes to protection of valuable corporate assets, the costs of a security breach can of course be catastrophic, especially if confidential business information or other intellectual property is destroyed, stolen or made available to competitors. Business costs due to system downtime Unplanned events that cause a system to fail can lead to excess costs for a business.
Figure 5. Share of costs during the lifecycle when an example of business downtime is added
Labour costs in the operations centre When calculating the operating costs of the TCO, the labour cost of the staff needed to man the operations centre during the 10year system lifespan has been excluded. However, the TCO model makes it possible to estimate this cost and factor it in to see how it impacts the TCO.
SECURITY SOLUTIONS 049
CCTV In an enterprise city surveillance installation, it is likely to have operators active 24 hours a day, 7 days a week. Assuming that five people are constantly present in the room, it is possible to make a rough calculation on the cost distribution. As can be seen in Figure 6, the total operating cost now jumps from 31 percent to 73 percent of the TCO, almost triple the acquisition cost. This is in line with the findings in the TCO studies from other industries.
Figure 6. Share of costs during the lifecycle when staff for the operations centre is taken into account
A Closer Look at Product Quality Maintenance and repair costs play a significant part of any TCO. The importance of product reliability is often underestimated when considering the cost of maintaining and operating a system. High product quality is of course one critical aspect to keeping maintenance and repair costs to a minimum. The TCO presented so far is built on typical failure and maintenance frequency, as captured by support statistics.
Conclusions This paper presents the results from a comprehensive TCO study conducted in 2015 by Axis Communications, resulting in a model with 40 costs relating to different system components and stages. The model was populated with a largescale 1,500 camera city surveillance project, with data taken from internal Axis sources as well as interviews and comparative surveillance industry information. The TCO is based on current equipment, labour and maintenance prices sourced during 2015, so market situation and costs may differ at time of reading. The result showed among other things that about 50 percent of the total cost is made up of investments in hardware and software, and 50 percent are in installation, maintenance, operating and decommissioning. To highlight the importance of product reliability, the TCO was used to simulate a scenario where product failure would increase by a factor of four. This resulted in the additional costs making a huge negative impact on the TCO, increasing the failure cost from 5 percent to 13 percent of the total cost. A TCO like the one presented here can be a useful tool when calculating project costs or assessing tenders. It presents examples of costs which can be expected during a system’s lifecycle, and indicates areas to focus on to reduce costs and improve the quality of the surveillance solution. However, be aware that this TCO is not applicable in all its details for all projects. Every project is unique and the TCO will of course vary considerably depending on the project size, industry application, system requirements and other unforeseen attributes. Winston Goh is the Head of Marketing, South Asia Pacific Region for Axis Communications.
Figure 7. The TCO with an increased product failure rate
050 SECURITY SOLUTIONS
Do You Know This Person?
This person has made a difference to someone’s life. It may be that he or she, through an act of courage or valour, has stepped in harm’s way so that someone else may be safe. It may be that he or she has put in tireless hours, made great personal sacrifices and dedicated a career to making the security industry a better place. Please, help us find and reward this person. Nominations are now open for the 2017 Australian Security Medals. Whether you are nominating a medal recipient, making a donation to the Foundation or booking seat (or table) at the industry’s premier charitable event, you will be helping to create a more professional security industry of which we can all be proud. For more information about making a nomination or providing sponsorship, please visit the Australian Security Medals Foundation website today!
www.inspiringsecurity.com SECURITY SOLUTIONS 051