Skip to main content

Security solutions #106

Page 1

A U S T R A L A S I A’ S L E A D I N G S E C U R I T Y R E S O U R C E F O R B U S I N E S S A N D G O V E R N M E N T

ISSUE #106 MAR/APR 2017

ISSN 1833 0215

Mapping the future Of Security Technology

$9.95 inc GST / $10.95 NZ

THE SHAPE OF THINGS TO COME


NEED SERIOUS SECURITY? THE ANSWER IS EZI!

Ezi Security designs, manufactures and installs a premium range of electronic perimeter security products designed for both vehicle and pedestrian control. These consisting of a wide range of security products suitable for low to high-risk applications. Ezi Security Systems has been manufacturing quality security products for over twenty-one years with equipment is installed in some of the very harshest of environments the planet has to offer. And all with outstanding results. While Ezi has a commitment to innovative design and quality products we also fully understand the importance of easy and efficient after sales service. Ezi Security Systems services and maintain the products we sell to ensure that your critical infrastructure and personnel are protected at all times. “ALL EZI SECURITY SYSTEM PRODUCTS ARE BUILT TO LAST A RELIABLE THIRTY YEAR (PLUS) PRODUCT LIFE SPAN WHEN MAINTAINED”

Ezi Security Systems has the most extensive offering of Hostile vehicle barrier products (HVB’s) and has the expertise to design and secure any critical infrastructure or site of national importance. Ezi has an extensive range AVB and HVB Crash Certified products such as the world famous TruckStopper, the renowned K12 Wedge, crash boom beams and crash rated static and automatic bollards. Ezi Security Systems has all the realistic solutions to meet your high security requirements while maintaining an aesthetically pleasing solution for your site. All Ezi Security System AVB & HVB have been vigorously crash tested and certified to meet all ASTM, IWA and PAS 68 stipulations. Ezi Security and its partners continue to the push boundaries on all crash products with our in-house R&D security experts providing market leading products designs. This specialist ability also involves our renowned installation expertise and advice with the all important civil work design & engineering. Ezi Security believes in pushing design frontiers for its products to keep pace with marketplace and security priorities. This year alone Ezi and PPG have successfully worked with CTS and crash tested to Pas 68 in 2016 the following products:

•

M30 Bollard Performance rating V/7500[N2]/48/90:0.0/0.0

•

M50 Bollard Performance rating V/7200[N3C]/80/90:5.5

•

Wedge II Performance rating V/7500[N3]/80/90:0.0/20.7 (tested with 4 m blocking width)

With our highly chosen business partners being the best in their field and coupled with our own Ezi Security R&D in house design team Ezi Security continue to push boundaries on market leading and state of the art crash rated designed products. Our ability also involves installation expertise and advice with all important civil work design & engineering.


Ezi also takes pride to provide our clients with more than just perimeter security solutions. We also offer a quality range of internal pedestrian control products from Werra Entrance Control. The Werra Entrance Control range compliments perfectly the already strong offering of pedestrian security control that Ezi Security currently offers to the market. The range includes a wide variety of systems suitable for pedestrian access management that includes the ability to hold and isolate persons of interest and/or concern. Ezi Security again has a quality product for every threat and contingency for building personnel security. All products offer quick access for authorised persons and reliable protection against unauthorised access. With a flow rate of up to 35/min even large flows of people can be monitored and controlled effectively. Werra Entrance Control not only stands for innovative for the individual’s passage of person, but also is an extension for our philosophy of being a professional fullservice provider of all components within perimeter security and access control. Ezi Security Systems, and their business partners, are privileged to be protecting some of the most prestige and iconic man made marvels of the modern era from the Burj Khalifa Tower in Dubai to Australia’s very own Parliament House in Canberra.

IF SERIOUS SECURITY IS YOU REQUIREMENT, LOOK NO FURTHER THAN EZI! FIND OUT MORE ABOUT US!

AUSTRALIA NATIONAL

1300 558 304 11 Cooper Street Smithfield NSW 2164 www.ezisecurity.com.au sales@ezisecurity.com


CUSTOMISABLE ELECTRIC HEIGHT ADJUSTABLE SIT STAND CONSOLES

Does your control room meet

Australian Ergonomic Standards?

www.activconsole.com

Clayton VIC 3168


Safe Work Australia, Nov 2015

“...in 2012-13 the cost impact of work-related injuries and illnesses was estimated to be just over $61 billion...�

State-of-the-art ergonomic lifting technology Lifetime Australia phone support AS/NZS 4443:1997 & ISO 11064

+61 3 9574 8044

sales@activconsole.com


CONTENTS106

COVER STORY: THE SHAPE OF THINGS TO COME

052

032

Nobel Prize-winning physicist Niels Bohr once remarked, “It is difficult to make predictions, especially about the future.” This somewhat comical observation is no less true today than it was when it was first made back in 1962. In fact, with the pace of technological innovation continuing to increase exponentially, especially over the last 20 years, predicating ‘the next big thing’ with any great certainty is arguably becoming more and more difficult. Cutting-edge technologies rise only to fall to the wayside before reaching completion in favour of newer, more exciting, reliable and affordable solutions to the same problem. We look at some emerging technologies with the potential to revolutionise the security industry.

THE GROWING THREAT OF TERRORISM IN AUSTRALIA The recent release of the respected 2016 Global Terrorism Index carries some worrying implications for Western nations such as Australia. Of particular concern is the increasingly migratory nature of the kind of fury that inspires terrorism in other parts of the world. Dr David WrightNeville examines the growing threat of terrorism in Australia.

060

THE KEY CONSIDERATIONS FOR IMPLEMENTING A CRISIS AND RECOVERY MANAGEMENT PLAN ACROSS BORDERS A corporate crisis can strike at any moment, in any location. Indeed, a crisis relates to an incident, human or natural, that requires urgent attention or action to protect life, property, environment or reputation. Barry Thomas looks at the four fundamental phases of dealing with a cross border crisis.

068

HOW TO SECURE YOUR SUPPLY CHAIN AGAINST CYBER THREATS IN 2017 In a world where data has become a form of currency, and modern business continues to shift heavily into the online environment, the need for businesses not to lose focus on the basics and ensure they stay informed about potential cybersecurity threats is as important as ever.

084

CREATING A RESILIENT ORGANISATION It is often said that the only thing you will ever get two risk management professionals to agree upon, is what the third one is doing wrong. Jason Gotch looks at the issue of resilience with a view to better understanding what this term means in a corporate context.

004 SECURITY SOLUTIONS


NEW INT-QUADIP For PB- Series Quad Beams

IP INTERFACE MODULE

LAN/WAN

With the new IP interface module, our intelligent PB- series Quad Beams are as easy as IP cameras to install and integrate with leading VMS solutions.

VMS

Most intruder detection systems rely on legacy technologies which require a number of third-party products and man-hours to install. The INT-QUADIP module utilises infrastructures already in place with CCTV, Access Control, and other security systems; dramatically reducing installation costs whilst providing a fully integrated security system which can be easily expanded and configured as desired.

KEY SPECIFICATIONS ● ● ● ●

PoE Class 3 IEEE 802.3af VMS Compatible Direct control for cameras including: - Axis - Bosch - Hikvision - Sony

● Plug & play web browser interface ● No software installation required ● One cable installation

PB-IN-HF/HFA The ultimate in trouble free perimeter detection for distances up to 200m.

1300 366 851 www.seadan.com.au

PB-F/FA Single channel quad beams ideal for simple perimeter systems.

PB-IN-100AT Anti-crawl beam for high security perimeters up to 100m.

PB-KH TAKEX quad beam performance for use in beam towers.

(02) 9427 2677 www.sprintintercom.au SECURITY SOLUTIONS 005


CONTENTS106 010

036 ALARMS What is the role of CEPTED in security system design?

LETTER FROM THE EDITOR

012 LEADERSHIP Jason Brown looks at ways leaders can more 014

040

OPERATIONS Richard Kay presents the second part of his special on

effectively align their leadership style to a particular situation.

ways in which security companies can better recognise and manage post trauma stress.

CYBER SECURITY How vulnerable is Australia’s credit card system to

044 CCTV Gary Palmer looks at the challenges and pitfalls of presenting CCTV footage as evidence in court.

cyber attack?

016 RESILIENCE How can you better understand the interface between

048 BUSINESS How can you build an effective risk culture within your

018

058

organisation?

organisational and infrastructure resilience?

HUMAN RESOURCES Learn how you can more effectively conduct workplace investigations with a view to better managing human resources. 020 RISK MANAGEMENT Is the DERK model for assessing human threats to facilities still relevant 25 years on?

022 COMMUNICATIONS Why is information sharing vital to the future of security?

026

064

LOSS PREVENTION Do retailers make better loss prevention managers

than security personnel?

072 AVIATION What is the value of the ‘what if’ test in aviation security? 076 ACCESS CONTROL We look at the opportunities for installers and locksmiths in the growing smart home market.

THINKING ABOUT SECURITY Why is it that the government seems to exhibit a lack of respect for the security profession?

080 PROFESSIONAL DEVELOPMENT What security lessons can be learned from the recent assassination of the Russian ambassador to Turkey, Andrei Karlov?

028 EVENTS A look at upcoming industry events.

032

LEGAL Q&A We look at the laws and your rights when using dash

cams.

060

068

088

SECURITY STUFF

102

PRODUCT SHOWCASES

090

SPOTLIGHTS

106

SHOPTALK Company announcements from within the industry.

092

PROFILES

006 SECURITY SOLUTIONS


SECURITY SOLUTIONS 007


www.securitysolutionsmagazine.com

Editorial Editor: John Bigelow john@interactivemediasolutions.com.au Sub-Editing: Helen Sist, Ged McMahon

Contributors: Jason Brown, Karissa Breen, Greg Byrn, Rod Cowan, Kevin Foster, Jason Gotch, Leon Founche, Richard Kay, Steve Lawson, Bill Nesbit, David Wright-Neville, Gary Palmer, Rita Parker, Anna Richards, Alexei Sidorenko, Anne Speckard, Barry Thomas, Ami Tobin, Don Williams.

Advertising keith@interactivemediasolutions.com.au Phone: 1300 300 552

Marketing & Subscriptions admin@interactivemediasolutions.com.au $62.00 AUD inside Aust. (6 Issues) $124.00 AUD outside Aust. (6 Issues)

Design & Production Graphic Design: Jamieson Gross graphics@interactivemediasolutions.com.au Phone: 1300 300 552

Accounts accounts@interactivemediasolutions.com.au Phone: 1300 300 552

Publisher

ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au Disclaimer The publisher takes due care in the preparation of this magazine and takes all reasonable precautions and makes all reasonable effort to ensure the accuracy of material contained in this publication, but is not liable for any mistake, misprint or omission. The publisher does not assume any responsibility or liability for any loss or damage which may result from any inaccuracy or omission in this publication, or from the use of information contained herein. The publisher makes no warranty, express or implied with respect to any of the material contained herein. The contents of this magazine may not be reproduced in ANY form in whole OR in part without WRITTEN permission from the publisher. Reproduction includes copying, photocopying, translation or reduced to any electronic medium or machine-readable form.

RS A DE VI

SSOCIATI

ON

ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au

O

SECURIT Y

PR

RALIA LTD UST FA

O

Written Correspondence to:

Or i g i n a l Si z e

O C I AT I

ON

Y P R OVI D

RIT

CU

D LT

SE

PR O

ASS

SPAAL

AU S T R A L I A

STRALIA LTD AU

SECURITY

RS

OF

E

Official partners with:

SSOCIAT IO N

OF

RS A DE VI

blue colour changed to this colour green.

COPY/ARTWORK/TYPESETTING APPROVAL Please proof read carefully ALL of this copy/artwork/typesetting material BEFORE signing your approval to print. Please pay special attention to spelling, punctuation, dates, times, telephone numbers, addresses etc, as well as layout.It is your responsibility to bring to our attention any corrections. Minuteman Press assumes no responsibility for errors after a proof has been authorised to print and print re-runs will be at your cost. Signed.................................................................. Date........................

008 SECURITY SOLUTIONS


SECURITY SOLUTIONS 009


LETTER FROM THE EDITOR We undoubtedly live in interesting times which, depending on your point of view, can be either a positive or negative thing. For example, if your world view is shaped by events directly relating to global security, then one might believe that while the civil unrest occurring in countries like the US, across parts of Europe and in the Middle East is ‘interesting’, it would not typically be categorised as positive. Alternatively, if your world view focuses more on the amazing technological changes occurring at breakneck speed across a wide and seemingly unending array of industries, including the security industry, then these ‘interesting’ times in which we live are marked by amazing innovations, developments and technological advances that have the power to fundamentally change the way we live. Therefore, interesting becomes positive. In reality, there is no separating the two; we take the good with the bad. It all simply comes down to your personal disposition. Are you the type of person who focuses on the positive aspects of something over the negative, or vice versa? In the last issue, we presented a piece by Dr Colin Wight on the potential global security impact of a Trump-led US Government – a situation which is being played out in the mainstream media as an ongoing three-ring circus. In this issue’s cover story, in an attempt to provide a sense of balance with regard to the argument around what sort of interesting times we might be living in, we have focused on pending technological developments set to have a major impact on not just the security industry, but the world as a whole. Typically, emerging tech articles of this type tend to focus on new products (usually those of the magazine’s advertisers) which are due to hit the market within the next six months. However, we have taken a slightly different approach, looking instead at the new and emerging technologies that are set to shape and radically alter the nature of the products we use every day – from deep machine learning to alien channels, atomic storage and speed of light communications. I hope that you enjoy this issue’s cover story and that, more importantly, it gets the juices flowing and promotes interesting ideas as we head into yet another interesting year. What type of interesting it turns out to be is up to you. You can either choose to focus your time and attention on the growing media circus that is US politics and lament the current state of global instability, or you can put your energy into looking at new and amazing opportunities in the security market that could change the way the industry operates. Have a great year!

John Bigelow Editor

010 SECURITY SOLUTIONS


Contact us on 1300 364 864 Follow us on

Delivering Proven Solutions for Security & Safety We Protect People & Assets www.magneticautomation.com.au


REGULAR

LEADERSHIP Aligning The Leader With The Situation

The two outer levels – public and private leadership – are what the leader must do behaviourally with individuals or groups to address the four dimensions of leadership (Scouller, 2011). These are: 1. A shared, motivating group purpose or vision 2. Action, progress and results 3. Collective unity or team spirit 4. Individual selection and motivation.

By Jason Brown As individuals, leaders come in all shapes, sizes, beliefs, sexual orientation and ethnic origins. The personal traits, the adaptive capacity and especially the capacity to emphasise particular styles of leadership behaviour in the face of changing and often complex situations separate those who fail as leaders and those who succeed. The Situational Leadership Model is a model developed by Paul Hersey and Ken Blanchard while working on Management of Organizational Behavior. In the late 1970s to early 1980s, the authors both developed their own models using the situational leadership theory; Hersey – Situational Leadership Model and Blanchard et al – Situational Leadership II Model. The fundamental underpinning of the Situational Leadership Model is that there is no single best style of leadership. Effective leadership is task relevant, and the most successful leaders are those who adapt their leadership style to the performance readiness (ability and willingness) of the individual or group they are attempting to lead or influence. Effective leadership varies, not only with the person or group that is being influenced, but it also depends on the task, job or function that needs to be accomplished. The Situational Leadership Model rests on two fundamental concepts; leadership style and the individual or group’s performance readiness level. Hersey and Blanchard categorised all leadership styles into four types of behaviour, which they named: • Telling – is characterised by one-way communication in which the leader defines the roles of the individual or group and provides the what, how, why, when and where to do the task. • Selling – while the leader is still providing the direction, he or she is now using twoway communication and providing the socio-

012 SECURITY SOLUTIONS

emotional support that will allow the individual or group being influenced to buy into the process. • Participating – this involves shared decision making about aspects of how the task is accomplished and the leader is providing fewer task behaviours while maintaining high relationship behaviour. • Delegating – the leader is still involved in decisions; however, the process and responsibility has been passed to the individual or group. The leader stays involved to monitor progress. No one style is considered optimal for all leaders to use all the time. Effective leaders need to be flexible and must adapt themselves according to the situation. The model has had some criticism and other researchers have named styles such as autocratic, democratic, laissez faire; the names give the characteristics away! An interesting model is James Scouller’s in Three Levels of Leadership (2016). The three levels referred to in the model’s name are public, private and personal leadership. The model is usually presented in a diagram form as three concentric circles and four outwardly directed arrows, with personal leadership in the centre. The first two levels – public and private leadership – are outer or behavioural levels. Scouller distinguished between the behaviours involved in influencing two or more people simultaneously (what he called public leadership) from the behaviour needed to select and influence individuals one-to-one (which he called private leadership). The third level – personal leadership – is an inner level and concerns a person’s leadership presence, know-how, skills, beliefs, emotions and unconscious habits. The idea is that if leaders want to be effective, they must work on all three levels in parallel.

The inner level – personal leadership – refers to what leaders should do to grow their leadership presence, know-how and skill. It has three aspects: 1. Developing one’s technical know-how and skill 2. Cultivating the right attitude toward other people 3. Working on psychological self-mastery. In the next few columns, I will examine these and other models to see if some commonalities can be synthesised. In the next edition, I will look at the characteristics of leadership in a post-tragedy or disaster situation.

Jason Brown is the National Security Director for Thales in Australia and New Zealand. He is responsible for security liaison with government, law enforcement and intelligence communities to develop cooperative arrangements to minimise risk to Thales and those in the community that it supports. He is also responsible for ensuring compliance with international and Commonwealth requirements for national security and relevant federal and state laws. He has served on a number of senior boards and committees, including Chair of the Security Professionals Australasia; Deputy Registrar Security Professionals Registry – Australasia (SPR-A); Chair of the Steering Committee for the International Day of Recognition of Security Officers; member of ASIS International Standards and Guidelines Commission; Chair of Australian Standards Committee for Security and resilience.


• INNOVATIVE PRODUCT DESIGN • BULLET RESISTANT CERTIFIED • BURGLARY RESISTANT CERTIFIED • UNIQUE HPJ CONCEPT

High Security Anti-Tailgating Portals

44

YEARS IN SECURITY

With over 40 portals in the range here is a closer look at two C3 Security Portal

HPJ140 Security Portal

The C3 Security Portal offers

The HPJ140 Security portal offers

•

Ultra Sonic Tailgate Detection

•

Unique Half Portal design to ‘cap’ an existing access controlled door

•

890mm entrance for DDA compliance

•

Ultra Sonic Tailgate Detection

•

Open design for maximum user comfort

•

900mm to 1200mm entrance for DDA compliance

•

P1A all the way up BR4 and WK4 glass construction

•

P1A all the way up BR4 and WK4 glass construction

www.pathminder.com.au

Phone: 1300 750 740 SECURITY SOLUTIONS 013


REGULAR

CYBER SECURITY #creditcards By Karissa A. Breen

Every day there are thousands of credit card transactions that occur around the world. But have you ever wondered how the transactional process works for transferring credit card funds? I have. I have always been fascinated about the mechanics of how our credit cards transact and talk to each other. So, off I went in search of further understanding of the geometrics of the payment card industry (PCI) and understanding the importance of this. In all honesty, compliance does not excite us at all, although it definitely plays an important role in our security world. I interviewed Jay Hira, who has an extensive background working with PCI and security compliance, to find out why. What is a merchant? The technical term: a merchant is any business that maintains a merchant account that enables them to accept credit or debit cards as payment from customers (cardholders) for goods or services that they provide. I like to think of it as you are David Jones (the merchant) selling clothes and shoes to consumers who buy them on their Amex cards. How does the transactional flow work? Imagine you are a consumer and you present your MasterCard issued by ANZ to the merchant (David Jones) at the CBA point of sale (POS) to buy a new pair of shoes. After you tap your credit card on the terminal, your credit card details are sent to the acquiring bank, in this case ANZ. The acquiring bank, or processor,

014 SECURITY SOLUTIONS

forwards the credit card details to the credit card network. The credit card network acts as a conduit between the two. The credit card network requests payment authorisation from the issuing bank. The issuing bank sends an approval to the credit card network to validate whether funds are available. The credit card network sends a ‘thumbs up’ to the acquiring bank. At that point in time, you see ‘Approved’ on the POS terminal. Off you go with your new pair of shoes! Who enforces the merchants? PCI Security Standards Council (SSC) develops and regulates the standards; the not so fun stuff, but still heavily important. The council is formed by the card brands, including VISA, MasterCard, American Express, Discover and JCB who create and set the PCI Data Security Standards (DSS). The banks are then responsible for enforcing the standards amongst their merchants, as well as reporting on a regular basis to the card brands on the status of compliance. PCI DSS is a set of requirements designed to ensure that the cardholder data is transmitted, processed and stored in a secure manner. Any merchant that accepts, processes or transmits cardholder data must comply with PCI DSS requirements. This helps to keep cardholders safe from any malicious interference. What happens if merchants fail to be compliant? Any merchant who fails to comply with PCI DSS is at risk of potentially having a major data breach. The risk increases depending

on the number of transactions the merchant makes per annum. Subsequently, there are other repercussions of non-compliance, which includes higher interchange fees charged by banks or even loss of merchant accounts and fines due to failure to comply. Why is PCI important? As a merchant, you want to ensure you are engendering trust with your clients. You do not want your company on the front page of the newspaper because their credit card details have now been breached and have permeated around the globe. It creates an inconvenience to consumers to then go and renew their credit cards. It may have impacts from a brand reputational point of view as being the untrusted merchant. As part of working within the cybersecurity market, it is crucial to uphold your company’s integrity, security posture and confidentiality to help protect your clients and ensure their trust is sustained. The next time you are shopping at David Jones you will understand the importance of PCI and you will have some insight into how the transactional flow operates and why PCI exists.

Karissa Breen is currently working as a BDM for Green Light who are an IT service provider and has a background in Cyber Security and has consulted to financial institutions. Karissa publishes her own IT blog.


S K Y H AW K FOR VIGILANT SURVEILL ANCE

L E A R N M O R E AT S E A G AT E . C O M / A U

SECURITY SOLUTIONS 015


REGULAR

RESILIENCE Understanding Interfaces Between Organisational And Infrastructural Resilience By Dr Rita Parker

In my previous article, I focused on the relationship between human and organisational resilience, and in this article I will extend attention to the interface between organisational and infrastructural resilience. Quite often, distinctions are drawn about different types of resilience in an attempt to explain them. However, in doing so, the connectivity between concepts and important application is often lost. In this article I will highlight the importance of keeping in mind that all forms of resilience are part of a connected complex system – particularly in the context of security. Security is as much a state of mind as it is a physical condition; indeed, for many the term ‘security’ has become a symbol of fear rather than a tool for strategic reasoning and judgement. It is in such circumstances that security professionals have a role in providing lucid reasoning and actionable solutions to top risks and threats. Part of the role of the security professional is to impart understanding to others about the relevance of resilience in security terms by developing and promoting a common understanding of, and body of knowledge about, resilience. This can be achieved by being clear about the relationships between and the importance of different types of resilience – that is, resilience in all its forms and applications is part of an integrated and

016 SECURITY SOLUTIONS

Quite often, distinctions are drawn about different types of resilience in an attempt to explain them. However, in doing so, the connectivity between concepts and important application is often lost.

interconnected system. Resilience is the ability of a complex system to absorb shock without losing normal function, and different types of resilience will depend on whether it is dealing with a chronic or acute disruption. The key point to keep in mind is that human, organisational and infrastructural resilience are all connected and interdependent. As we know, critical infrastructure underpins the delivery of essential services such as power, water, health, communications and banking, as well as our defence and national security. Importantly, some elements of critical infrastructure are not assets, but are in fact networks or supply chains. All these services contribute to our economic and social wellbeing. To operate effectively, we know that critical infrastructure needs coordinated planning across sectors and networks and requires flexible, timely and responsive recovery measures. Having such a resilience-based approach to organisational and critical infrastructure resilience means being better able to adapt to change, reduce exposure to risks and to be better able to survive and thrive. In practical terms, this means reduced failure probabilities, reduced consequences from failures and reduced time to recovery.

Dr Rita Parker is a consultant advisor to organisations seeking to increase their corporate and organisational resilience and crisis management ability. She is an adjunct lecturer at the University of New South Wales at the Australian Defence Force Academy campus where she lectures on resilience and nontraditional challenges to security from non-state actors and arising from non-human sources. Dr Parker is also a Distinguished Fellow at the Center for Infrastructure Protection at George Mason University Law School, Virginia, USA. She is a former senior advisor to Australian federal and state governments in the area of resilience and security. Dr Parker’s work and research has been published in peer reviewed journals and as chapters in books in Australia, Malaysia, the United States, Singapore and Germany, and presented at national and international conferences. Rita holds a PhD, MBA, Grad. Dip., BA, and a Security Risk Management Diploma.


Why do you have to do a strange dance to try and open a door?

Instinctive technologies for a world without constraint

Card mode

Slide mode

Tap Tap mode

Remote mode

Hands free mode

Be STid, be smart Intuitive solutions for mobile access control

SECURITY SOLUTIONS 017


REGULAR

HUMAN RESOURSES Conducting Workplace Investigations By Greg Byrne

Welcome to 2017. The festive season is always busy for the security and law enforcement industries in Australia and around the world. I hope that you all had a great Christmas and New Year, and your company and family prosper throughout 2017. We are in a period of increased social and political conservatism, which is heralding great change for us all, and no more so than for the security industry. With that change comes increased regulation and increased regulatory reporting. Human resources (HR) will of course be one of the leading sources of change. For the greater part of this year, I am going to keep readers updated on those changes as well as participate in some of the trends that the Security Solutions Magazine will follow throughout the year. In this edition, this column will start to address the issue of workplace investigations, outlining the first two of the four suggested steps. In the next edition, this column will participate in that issue’s theme of recovery from a crisis. I will detail how an organisation would best recover its HR functions and processes following any form of serious interruption to normal business, such as terrorist strike, the catastrophic meltdown of IT infrastructure including loss of HR records, destructive fire, or theft of HR and customer records. In the following edition, I will address the final two steps of the investigation process and in the edition after that, I will outline some of the pitfalls and suggest a process that should put an organisation on solid ground when attempting to manage workplace relationships, employee performance and/or breaches of policy/ procedure.

018 SECURITY SOLUTIONS

The Process There are four main steps to conducting a workplace investigation: 1. Preparation and information collection 2. Interviewing the relevant parties 3. Making a finding and report 4. Resolution activities. It is vitally important to ensure that communication and feedback take place throughout the investigative process so that all relevant parties are in the loop and understand what and why things are occurring. This includes communication with managers, team leaders and involved parties (where appropriate). Please note that this article is an overview of the workplace investigation and not a definitive stepby-step guide on how to conduct a workplace investigation. A workplace investigation should be conducted by a suitably qualified individual or organisation. It is vitally important, especially if the Fair Work Commission (FWC) or a court of any kind is the outcome, that due process is followed and most importantly that the investigation is fair. Preparing for a Workplace Investigation • Establish that there is need to conduct a workplace investigation in the first place. These processes can be very disruptive to a workplace and the decision to conduct one should not be taken lightly. • Is the appointed investigator the right person? Is there a conflict of interest, does he/she have the required skills and knowledge, are there any relationships that could/will affect the credibility of the outcome and so on. • Is it the right time for an investigation to take place?

• Do you have a suitable location for the investigation? • Identify the parties to the matter and their location and availability. • Conduct all relevant research, including: o obtaining the record of complaint o establishing any relevant policies and procedures and codes of conduct o identifying legislation that will affect the process and possible outcomes of the investigation o identifying all relevant training records o identifying relevant position descriptions (PDs) o locating any employment contracts and applicable award or workplace agreement and any relevant term(s) or obligations o obtaining past performance reviews, employment records and CVs o determining if there are any previous incidents/investigations or complaints and how were they managed o determining if there is an observed pattern of behaviour. Additionally, prepare an interview plan and ensure the manager has viewed and agrees with it. Plan for a second interview with both the complainant and the respondent to provide feedback on either the outcome or the process and to allow for clarification of prior statements or outcomes of interviews with others on the periphery of the issue/investigation. Interviewing Involved Parties Ensure: • that those being interviewed or who are affected or aggrieved in any way are offered adequate representation or support • that if any of the involved or aggrieved have special needs, that those needs are addressed;


HUMAN RESOURSES for example, non-English speaking people should be offered an interpreter (note: if there is a chance that the issue could end up at FWC or any type of court that a registered interpreter is used) • that if the interviewee is a member of a union, that a union representative is at least in the loop and, where appropriate, is present during the interview (as a support person) • the interviewee is fully aware of his rights and fully understands the allegation or reason for the interview and investigation • the complainant understands the process and is aware of the relevant policies/options open to him in having his complaint handled. Also consider: • confidentiality, including the need to protect the integrity of the investigation process • how information and material will be communicated to the respondent(s) • how statements and interviews will be recorded, for example, typed or audio recorded (ensure permission to audio record the conversation and,

given that, that permission is recorded somehow) • how notes and records will be stored, documented and lawfully obtained • that as much specific detail (evidence) as possible has been obtained • that there is a thorough (and dynamic) list of potential witnesses • that the information being gathered is relevant, reliable and fair • that the probative value of the information obtained is tested and that it is current • that, where possible, claims and gathered evidence is/are corroborated. When finalising interviews: • ask the interviewee if he has any further questions • explain timings and when the interviewee can expect feedback • ensure that (where required/appropriate/lawful) statements, records, exhibits and documents are reviewed and signed by interviewees or owners of the records.

When considering recommendations, also consider: • the appropriateness of existing work arrangements, having regard to the issues raised/ detected during the investigation • if investigtors are managing emotions and being empathetic where appropriate • how the interviewee is feeling, the impact of the issue being investigated, and the impact the interview process has or is having on him • if any ongoing support is required, for example, an Employee Assistance Program (EAP).

Greg Byrne is the Managing Director of Multisec Consultancy Pty Ltd. He lectures part-time at the Western Sydney University for an undergraduate diploma in policing and is a sub-editor for and board member of the Australian Police Journal. His academic qualifications include Master of Management, Diploma of HR, Grad Cert in Leadership and a Diploma a Security Risk Management. Greg can be contacted via email greg@multisec.com.au

FAST. SILENT. STYLISH. Our award winning speedgates keep your building secure with style. Find out which speedgate is right for you.

1300 858 840 www.entrancecontrol.com.au SECURITY SOLUTIONS 019


REGULAR

RISK MANAGEMENT The DERK Model For Assessing Human Threats To Facilities – Still Relevant 25 Years On? By Dr Kevin J. Foster A security risk assessment for a facility is a relatively simple process and it should always follow that described in ANSI/ASIS/RIMS RA.12015. However, a risk assessment that is inadequate can result in inappropriate, insufficient or unnecessary security measures. Therefore, a sound risk assessment is critical to effective risk management. An important element of a security risk assessment is the threat assessment. There are many ways of completing a threat assessment, but in this article I will introduce a method that I have found useful. While it goes under a few different names, it will be referred to here as the DERK method. I presented this model to a Security in Government conference in 1992 and have been using it for 25 years, especially when conducting protective security risk assessments. The theoretical basis of the DERK threat assessment model is a combination of two ideas. Firstly, to understand whether a person, an organisation or a nation is a threat, it is important to understand his/its intent and capability. Robert Jervis has described this in detail in his publications on threat perception. Secondly, Victor Vroom’s expectancy motivation theory suggests that for someone to be motivated to engage in a threatening activity, there usually needs to be a ‘valence’ attached to his desired outcome or goal. This is the importance the person places on the outcome. In a security context, this might be labelled as the adversary’s desire, for example, to steal information; or perhaps in the case of a terrorist, his desire to use fear or destruction for the purpose of amplifying the political point he wishes to make. The adversary must also have some level of expectancy that he can achieve his desired outcome. In a threat context, this would be instrumental upon him having the capability to achieve his goal, and specifically the resources and knowledge necessary. In the DERK model, the intent can be defined by describing the adversary’s desire

020 SECURITY SOLUTIONS

or objective and his expectance of success. The threat is not always from an adversary; sometimes it can come from a friend or competitor. The term ‘threat source’ is sometimes used instead of ‘adversary’ when conducting threat assessments. To understand the threat posed by a criminal, a terrorist, a competitor, a nation, or anyone, it is necessary to understand the following four factors: • The threat source’s Desire or goal: in practice, this may be expressed as the likelihood that his objective, if realised, will cause either deliberate or consequential harm to people. • The threat source’s Expectance of success: in practice, this is security’s best guess about how confident he would be of achieving his objective. Any deterrence that can be created in the security design might affect his expectance. This factor can be expressed as the probability of him expecting to succeed. Some people will be more easily deterred than others. • The threat source’s Resources needed to achieve his goal: this factor can be expressed as the likelihood that he has the resources necessary to achieve his objective. Improving security by hardening or building more layers may increase the resources necessary for the adversary to succeed in his objectives, thus reducing the likelihood that he will succeed. At a theoretical level, the ratio of resources available to resources required is being assessed. At a practical level, this would often be expressed using words such as likely or unlikely rather than numbers. This means security professionals can use the same or similar descriptors that they typically use in risk matrices. • The threat source’s Knowledge needed to achieve his goal: this factor can be expressed as the likelihood that he has the knowledge necessary to achieve his goal. By improving security, it is possible to increase the knowledge required for him to succeed, thus reducing the likelihood that he will have the knowledge required to succeed.

With an understanding of the D, E, R and K probability factors, it is possible to deduce the level of threat an adversary might pose. In this model, intent is described as a probability that someone has the desire and expectance of achieving a goal that would pose a threat. Capability is described as a probability that someone has the resources and knowledge to achieve his goal. The probabilities can be described using definitions taken from Standards Australia HB167:2006 Security Risk Management. However, these criteria need to be modified to suit the threat context. Intent and capability can then be combined in a threat matrix which provides the threat likelihood that can be used in a risk assessment.

I can describe this threat assessment model in more detail in future articles and provide case study examples. While I may be a little biased, I think this model is just as relevant now as it was in 1992. The difference today is that far more security professionals are familiar with risk assessment principles and therefore, arguably, this DERK model is easier to use now than it was 25 years ago. Dr Kevin J. Foster is the managing director of Foster Risk Management Pty Ltd, an Australian company that provides independent research aimed at finding better ways to manage risk for security and public safety, and improving our understanding of emerging threats from ‘intelligent’ technologies.


MULTIPLE CAPABILITIES SUPERIOR SOLUTION

Volvo Group Governmental Sales Oceania

IN HOSTILE ENVIRONMENTS, IT’S IMPORTANT THE SYSTEMS THAT YOU DEPEND ON CAN

STAND THE TEST OF TIME.

At Volvo Group Governmental Sales Oceania, our core business is the manufacturing, delivery and the support of an unparalleled range of military and security vehicle platforms; a range of platforms that are backed by an experienced, reliable and global network with over one hundred years of experience

superior solutions, providing exceptional protected mobility SECURITY SOLUTIONS 021 www.governmentalsalesoceania.com


REGULAR

COMMUNICATIONS Why Information Sharing Is Vital To Your Future By Rod Cowan

Lack of recognition for the vital role security plays results in too many security managers and agency security advisors – and to those readers who do not fit this profile, I apologise in advance, but it is nonetheless true of many others – being in the position because they are either parked there or waiting out their time to retirement. Precious few in the business would see themselves as leaders within their organisations, far less society. In some ways, the culture is changing already, albeit slowly, with a younger breed of security operatives joining the ranks and actually choosing security as their future. Culture is complex, however, and change is more than a rebranding exercise with a new coat of paint in the hope no one looks under the hood. It is necessary to first develop an ethos – values – and ways of thinking in order to plot a course. Then that philosophy needs to be embodied in the stories shared, heroes applauded and rituals created. One small step has been establishing an industry-based medals program recognising bravery and contribution. Another is the creation of the Outstanding Security Performance Awards (OSPAs), which is growing into a global event. More is needed, as technology is changing the shape of business, government and society, especially in the way people organise, communicate and collaborate, which in turn is changing the way people view authority and power. Nowhere is that more evident than in information sharing, especially in a world of cognitive capital, where knowledge has become

022 SECURITY SOLUTIONS

Thinking must move beyond extensions of bureaucratic control to establish networks, which inevitably means sharing information. an asset of institutions and organisations and a resource traded for money, social influence and political clout, creating barely-understood risks as well as opportunities. Letting go of old values and beliefs can be challenging in bureaucratic mindsets where knowledge is power, bringing to mind a poster on the wall of an Australian intelligence organisation’s office depicting a toad in the mouth of a crane, with the toad’s hands around the throat of the bird and a caption, “Whatever you do, don’t let go”. While the security, intelligence and law enforcement old guard refuse to let go, younger generations – so-called digital natives who are young adults and not kids anymore – accept sharing as part of life. All too often, solutions revolve around education and, preferably, control, and rarely innovative or fresh approaches, no matter what the marketing spin or political rhetoric

advises. Thinking must move beyond extensions of bureaucratic control to establish networks, which inevitably means sharing information. Information sharing, however, is what is known in policy development as a wicked problem; wicked not in the sense of evil – though some may see it that way – but in terms of being intractable because its complexity defies definition far less solution. A big help would be the academic and research community contributing beyond looking for funding opportunities. Industry insiders – government and corporate – also need to play their part. And they need the right environment to do so. In 2003, the Federal Attorney-General’s Department established the Trusted Information Sharing Network (TISN). For a while a promising initiative, of late the TISN has been waxing and waning to a point of being almost moribund;


When a high level of security is essential, dormakaba turnstiles and full-height gates provide the ideal solution. The robust turnstiles and full-height gates are especially suitable for securing the perimeter of buildings and property.

Secure your perimeters

Benefits include versatality in design, safe passage, minimal power consumption and lasting quality for any indoor or outdoor installation. For the complete range of smart and secure access solutions, contact dormakaba. 1800 675 411 www.dormakaba.com.au

SECURITY SOLUTIONS 023


REGULAR

LEGAL

COMMUNICATIONS The reality is the industry, or for that matter the country, cannot afford to wait for the government to fix problems; corporate security, individual agencies and all levels of government need to engage and support a TISN if it is to be anything more than a tick-a-box exercise.

almost because it has just enough of a pulse for the Government to publicly deny its ill health, thanks to some areas, such as the finance sector, working well together. The public water sector has made great strides too. Therein lies some precedents. As such, preventing the TISN’s death, thankfully at this stage, may mean CPR as opposed to open heart surgery. The UK’s Project Griffin, established in 2004 in the City of London to help the financial sector protect itself against terrorist threats, is often cited as an example of public/private information sharing. What is forgotten is that it was the banks that pushed for its inception. The reality is the industry, or for that matter the country, cannot afford to wait for the government to fix problems; corporate security, individual agencies and all levels of government need to engage and support a TISN if it is to be anything more than a tick-a-box exercise. The hard work of creating links and connections with knowledgeable individuals and networks, admittedly difficult given the nature of security, is needed to develop different avenues of engagement with embedded accountability. To date, organisations and governments have stuck to superannuated consultants, credentialled

024 SECURITY SOLUTIONS

academics, media darlings and other trusted insiders rather than seek fresh input. Given rapid change, how anyone could claim to be an expert in what is essentially new knowledge is hard to see. Not that that has stopped an entire courage industry growing around advising on cybersecurity, with people deemed ‘experts’ because they work for a university, prancing around glibly spreading fear as facts with less understanding than the spotty 12-year-old Ohio schoolboy known as glitterstick_007. “In an age of turbulent and unpredictable transition, institutions most need the very things – innovation, picking up the early signs of disruption, a capacity to move quickly and responsively – that tend to be found at the edge of large systems in dispersed networks of expertise close to people’s lives and experiences, rather than the more slower and more distant structures of power at ‘head office’,” writes Martin StewartWeeks and Lindsay Tanner in Changing Shape: institutions for a digital age. “Institutions in the digital age still need to access and exercise power and authority. But that will increasingly happen through their connections with surrounding networks of energy, insight and creativity.”

Historically, major change has always occurred at the edges of society. Finding that edge and having it feed back into the practices and culture in order to change larger systems entails learning new habits of influence and practices of persuasion that emerge from the process, thereby cultivating a network mindset and leadership through active participation, openness and decentralised decision making. In short, command-and-control – hanging on like the toad – no longer cuts it. And the rapid speed of change means even those who are parked or waiting out their time for retirement may have no choice but to contribute, or learn to enjoy the ride.

Rod Cowan is editor-at-large for Security Solutions Magazine and director of SecurityIsYourBusiness. com. He can be contacted via email: ssm@securityisyourbusiness.com


SECURITY SOLUTIONS 025


REGULAR

THINKING ABOUT

SECURITY

Government’s Lack Of Respect By Don Williams Governments issue security and emergency advice to the community and private sector operators that can, at times, be both disrespectful and demeaning. The Australia-New Zealand Counter-Terrorism Committee Improvised Explosive Device Guidelines for Places of Mass Gathering April 2016 is one example. Two main issues arise: a lack of understanding of those currently responsible for protecting such places; and a lack of respect for the knowledge and experience that exists in the private sector. There are at least 12 occasions in this particular example where managers are advised to consider factors or undertake tasks which are already their responsibility. Managers are advised to “do what they can to: save and protect life, facilitate the evacuation of those at risk, contain the incident or threat, (and) support emergency response and investigation activities” and “Planning and initiating evacuation should be the responsibility of the incident/security manager”. Managers know that they have responsibility for the safety and security of those on site and they seek to fulfil their legal, contractual, social and moral responsibilities. To suggest otherwise demonstrates a lack of knowledge and appreciation of the capabilities of the private sector. The guidance also states that “Owners and operators of places of mass gathering should consult with local law enforcement agencies when developing their plans.” This is essential, not only so the police can tell the managers what they expect, but so that managers can explain

026 SECURITY SOLUTIONS

the responsibilities, processes, procedures and considerations that they already have in place, and which are designed to protect the business as well as life and property. Consultation could result in a transfer of knowledge – not just oneway directives from emergency services. Government agencies, specifically the emergency services, have undeniable skills, knowledge and expertise that is required when planning for and responding to crises. But, not all knowledge resides within government; in fact, it could be suggested that the larger knowledge base is in the commercial, professional and academic libraries. Security is a management discipline in its own right, with a wealth of research and literature. Few government employees are members of the relevant security, emergency or facility professional organisations and even fewer have internationally recognised certifications such as Certified Protection Professional (CPP), Physical Security Professional (PSP) and Certified Facility Executive (CFE). Such certifications are becoming the standard in the corporate world, both as recognition of knowledge and experience, and as showing commitment to ongoing professional development. It would appear obvious that the authors of government advice would approach the major professional bodies, seek the advice of recognised subject matter experts and avail themselves of the wealth of information held in the professional libraries and academia. There are protestations that consultation is undertaken. But, going back

to the Improvised Explosive Device Guidelines for Places of Mass Gathering example and talking to the Facility Management Association of Australia (FMA), Venue Management Association (VMA), ASIS International, Australian Security Industry Association Limited (ASIAL) and the relevant organisations, no one who was consulted was identified. The result is that government produces advice that does not reflect current best practice, does not include the latest research and does not best help the corporate sector manage the issue raised. Perhaps government advice should be limited to the role and functions of government entities such as the emergency services? If the advice is to be broader, then it must recognise and respect the knowledge, skills and experience of the private sector. In return, the private sector must represent best practice; that is, be professional. It is up to managers to generate the respect they deserve and to ensure they have the skills and knowledge to underpin that respect.

Don Williams CPP RSecP ASecM can be contacted via email: donwilliams@dswconsulting.com.au


THE ALL-NEWTXF-125E BATTERY OPERATED QUAD BEAM Introducing the eagerly anticipated TXF-125E; a high performance Quad Beam sensor designed for battery operation - perfectly suited for rapid deployment in creating temporary or permanent secure perimeter intruder systems. With 4 selectable frequencies, multiple beam sets can be used without crosstalk, whilst adjustable detection distance allows a single beam set to be re-deployed in a variety of installations throughout its operational life. Two 3.6V (17Ah) batteries power each unit for up to 5 years of service.

NEW!

ACTIVE IR BEAMS The ultimate in trouble free perimeter detection for distances up to 200m outdoor / 400m indoor.

+61 (3) 9544 2477

email: oz_sales@takex.com

HIGH-MOUNT PIR Triple mirror optics for maximum detection performance at 2 to 6m.

BEAM TOWERS Rugged floor and wall mounted enclosures in 1/1.5/2/3m heights.

INDOOR PIR Spot, 360°, wide angle, and curtain detection from 2 to 4.9m height.

OUTDOOR PIR Hard-wired or battery operated outdoor PIR up to 180° x 12m .

1300 319 499 csd.com.au www.takex.com

TAKEX AMERICA SECURITY SOLUTIONS 027

VIC: Mulgrave, Tullamarine NSW: Northmead, Waterloo ACT: Fyshwick QLD: Loganholme SA: Marleston WA: Balcatta


REGULAR

EVENTS Total Facilities 29–30 March 2017 International Convention Centre, Sydney Total Facilities presents two days of discussion and discovery for FM and like-minded professionals. It combines Australia’s largest offering of innovative facility products and services with forward-thinking strategies to optimise facility and workplace performance. A thriving exhibition floor featuring over 150 leading brands will showcase real solutions to meet operational challenges, whilst freeto-attend educational seminars offering bold perspectives and latest FM thinking will raise methodologies to drive business performance. Join Australia’s largest community of FM minds for unrivalled networking and engaging discussion for enhancing our living-working environments.

Learning options Three categories of attendance have been devised to provide attendees and their organisations with flexibility and return on investment: 1. Conference: for senior and aspiring leaders in need of the most complete learning experience, including keynotes, masterclasses, executive sessions and exhibition access. 2. Training: for team members and managers seeking to gain focused, practical skills with well-defined learning outcomes. 3. Show Pass (exhibition + technology & solutions track + career centre): for professionals primarily interested in dialogue with leading innovators and advisors about designing future-proof security solutions and professionals seeking advice and experience sharing to boost their security management career

For more information visit: www.totalfacilities.com.au

Visit www.asiseurope.org for full details on the packages available and applicable fees.

ASIS Europe 2017 From Risk To Resilience 29–31 March 2017 Mico, Milan, Italy

ISC West 5–7 April 2017 Sands Expo Centre, Las Vegas

At a time when the Internet of Things is making established lines of responsibility obsolete and the risk of terrorism and political turmoil mean physical threats remain all too real, ASIS Europe 2017 tackles the most challenging issues. Cyber-physical threats in hyper-complex, connected environments are the core themes of the event. ASIS, as a global community of security practitioners tasked with the protection of assets – people, property and information – is uniquely positioned to deal with enterprisewide risks. If you are responsible for keeping organisations secure, sustainable and resilient, join ASIS in Milan in March 2017.

ISC WEST is the largest security industry trade show in the US. At ISC West you will have the chance to meet with technical reps from 1,000+ exhibitors and brands in the security industry and network with over 28,000 security professionals. Find out about new and future products and stay ahead of the competition. Encompassing everything from access control to Facial Recognition software, you are sure to find products and services that will benefit your company and clients. This year don’t miss our new IT Pavilion featuring the latest cyber security solutions.

028 SECURITY SOLUTIONS

Working with SIA, ISC also features world class education to learn about every facet of the security industry. For more info on SIA Education@ISC visit: www.iscwest.com

Safeguarding Australia 2017: Turning Points in Security 3–4 May 2017 QT Canberra, Canberra Competing priorities, growing threats and increasing complexity will continue to present fundamental challenges to Australia’s national security agenda in the coming years. Public and private security professionals – policy makers, practitioners and providers – will be forced to address a wide range of issues which have developed over recent decades and continue to grow, such as violent extremism, cyber threats (from lone and state actors), border control and legislation. In coming years, they will need to also contend with the security issues inherent in societal issues, adding known-unknown dimensions to an already complex national security agenda, most notably an ageing population, technology creeping into all facets of life and diversity in the workplace reflecting an increasingly cosmopolitan society. Safeguarding Australia 2017 will help face those challenges and shape the security agenda, by taking on its most demanding theme to date: Security at a Turning Point – Innovation, Leadership and Diversity. For over 14 years, the Research Network for a Secure Australia (RNSA), a not-for-profit network of security policy makers, professionals and academics, has gathered at the Safeguarding Australia annual national security summit to hear from high-level speakers representing both government and corporate


Recognize and Analyze How often was he here this month?

Is he a known suspect?

How old is she?

Are they employees?

When, where did she enter?

Is this valued customer Mia Clark?

How many people are here? Is it too crowded in this area? New: Recorded media import and advanced investigation tools upload sets of videos recorded at a specific location and time to track possible participants in a crime find a person enrolled in an image database or search for an unknown person locate appearances in multiple videos make use of filters that specify age ranges, gender, ethnicity and glasses

FaceVACS-VideoScan uses premier face recognition technology to detect and identify persons of interest while computing demographic and behavioral data, supporting security staff, marketing teams and operations management.

SECURITY SOLUTIONS 029


REGULAR

EVENTS viewpoints, exchange ideas, debate issues, and learn about techniques, cases studies and ground-breaking research, to meet the security challenges of today and the solutions for tomorrow. In addition to briefings on current policies, trends and activities, Safeguarding Australia 2017 will go further by drawing on local and international experts to examine three overarching themes affecting the way security and risk is managed to protect the nation, namely: 1. Innovation – exploring knowledge around technology, standards and research. 2. Leadership – focusing on the next generation, the greying population and education. 3. Diversity – in particular, the role of communications as a security tool addressing disparate ethnicities, genders and culture. In addition to a pre-conference workshop currently being designed, Safeguarding Australia 2017 will begin by outlining current challenges and activities and lead into defining future directions and solutions. Safeguarding Australia is the only high-level conference run by and for leading thinkers, policymakers and practitioners in the national security domain, working across wholeof-government at state and federal levels, including law enforcement and intelligence agencies, as well as engaging with corporate and private security practitioners and providers. Past attendees and current bookings include: • senior representatives from security, intelligence, military and law enforcement • risk and security managers and consultants • agency security advisors • critical infrastructure owners and operators • engineers, scientists, technologists, researchers and academics

030 SECURITY SOLUTIONS

• corporate and business executives responsible for security and risk. Visit safeguardingaustraliasummit.org.au for more information.

IFSEC International 20–22 June 2017 ExCeL London The global stage for security innovation and expertise IFSEC International is the biggest security exhibition in Europe taking place over three days between 20 to 22 June 2017 at London ExCeL. IFSEC welcomes over 27,000 global security professionals to experience the latest technological innovations and hear from industry leaders – all under one roof, over three days. The event caters to everyone within the security buying chain from manufacturers, distributors, installers, integrators and consultants to end users. With over 600 exhibitors showcasing over 10,000 products, you will be able to find the perfect security solution your business is looking for. There’s more to it than just security. IFSEC International is co-located with FIREX International, Facilities Show, Safety & Health Expo and Service Management Expo, catered for those working across many platforms in building management and protection of people and information. For more information or to register please visit www.ifsec.co.uk

Security Exhibition & Conference 2017 26–28 July 2017 International Convention Centre, Sydney In 2017 the Security Exhibition & Conference is heading back to Sydney to the brand new International Convention Centre. This stateof-the-art precinct over looks beautiful Darling Harbour and is a short walk away from Sydney’s vibrant city centre. The new venue features a total of 35,000sqm of exhibition space presented in a smart, stacked layout to capitalise on the inner-city location and provide much improved loading facilities. Plus the halls feature customised registration and ticketing areas and dedicated meeting rooms. ICC Sydney will be Asia Pacific’s premier integrated convention, exhibition and entertainment precinct, underpinning Sydney’s position as one of the world’s most desirable meeting and event destinations. The entire team is looking forward to reuniting the industry once again in sunny Sydney where Security 2017 will connect more than 4,500 security professionals with over 150 leading suppliers. For over three decades the event has provided a showcase for new and innovative security technologies and solutions. Whether you are looking for a solution to protect your property, people or assets, the Security Exhibition & Conference provides the opportunity to discover the solution that is right for your organisation. Make sure you put July 26–28 in your diary; and we look forward to seeing you again in Sydney for the Security Exhibition & ASIAL Conference! To register now visit securityexpo.com.au


TALL. FAST. STYLISH. Our award winning speedgates combine state-of-the-art optical technology with a high barrier height to protect your building.

EASYGATE SPT

• • • •

Barrier heights up to 1800mm Fast throughput (up to one person per second) Ideal for Disability Discrimination Act compliance Choose from a number of models, including the LX, SPT, SG, IM or LG • Custom pedestals with an array of attractive finishes EASYGATE LX

Find out which security gate is right for you.

1300 858 840

www.entrancecontrol.com.au

EASYGATE IM

FULL HEIGHT TURNSTILE

TRIPOD TURNSTILE

SWING GATE


032


The Growing Threat Of Terrorism In Australia

033


By Dr David Wright-Neville The recent release of the respected 2016 Global Terrorism Index carries some worrying implications for Western nations such as Australia. Of particular concern is the increasingly migratory nature of the kind of fury that inspires terrorism in other parts of the world. The report drives home the point that, in the 21st century, anger does not need a passport. It travels quickly and efficiently so that resentments fuelled by events in, for example, the Middle East, increasingly merge with local frustrations to form a highly combustible rage that has erupted in the streets of Paris, Nice, an Orlando nightclub and other spaces once considered safe. Although much of this increase in terrorist violence in the West has been inspired by Islamic State – 18 deaths caused by ISaffiliated attacks in the Organisation for Economic Co-operation and Development (OECD) countries in 2014 rose to 313 deaths in 2015 – it would be incorrect to credit the group as the only reason for the growing incidence of terrorism in the West. Terrorism has been trending upwards globally for over a decade, a development from which Western countries have not been immune, as witnessed by tragedies such as the attacks on the public transport systems in Madrid (2004) and London (2005) – killing 192 and 56 people respectively – the killing of 77 people in Oslo by the right wing extremist Anders Breivik (2011) and, among others, the Boston marathon bombing (2013). Over this period, there have also been a series of near misses with a combination of good luck and good police and intelligence work avoiding mass casualty attacks in places ranging from Copenhagen to Times Square. And, of course, Australia has not been immune from this trend, with a series of smallscale terrorist attacks and a few larger scale strikes interrupted by police and security services before being carried out, suggesting that like comparable Western nations, terrorists reside among Australians and public spaces no longer offer protection. Just a small sample of these incidents occurred in September 2014, when the 18-year-old Numan Haider was shot and killed by police after stabbing two officers outside a Melbourne police station. Several months later in December, a refugee from Iran, Man

034

Haron Monis, took 17 people hostage in the Lindt café in inner Sydney, resulting in three deaths (including Monis). Then in February 2015, two men from Sydney (a 24-year-old and a 25-year-old) were arrested and charged with preparing to commit an act of terrorism. A homemade Islamic State flag was discovered in their possession. In May 2015, a 17-yearold boy from the outer Melbourne suburb of Greenvale was arrested after being discovered in possession of homemade bombs. This was followed in October 2015 when a 15-yearold Iranian-born Kurdish refugee shot dead 58-year-old accountant Curtis Cheng outside the Paramatta police station in Sydney. More recently, in September 2016, a 22-year-old student was arrested after allegedly stabbing a pedestrian in a park in the Sydney suburb of Minto – a copy of the Islamic State’s online magazine Dabiq was reportedly found on his computer. Although not on the same scale as attacks in Western Europe and the United States, the attacks in Australia have nevertheless impacted significantly on the national psyche and rendered the threat of terrorism as an organising principle for many aspects of public policy. In many respects, Australia’s reaction to the threat of terrorism can be explained by the nation’s comparable lack of experience with terrorism. Until the events of 9/11 – when 11 Australians were among the 2,996 people killed – the nation had been relatively immune from the threat. Small, isolated acts in the name of Irish nationalism during the late 1800s; an attack on a picnic train by two Turkish nationalists near Broken Hill on new year’s day 1915; a series of bombings and shootings targeting Turkish, Yugoslavian and Jewish interests in Sydney and Melbourne in the 1970s and 1980s; the 1978 bombing of the Sydney Hilton during the Commonwealth Heads of Government Meeting (CHOGM), and a series of small-scale arson attacks by white supremacist groups in the 1990s meant that acts of terrorism were small and rare compared to equivalent Western societies in Europe and North America. But since 9/11, Australians have changed the way they think about their safety, about the right of government to pry into their private affairs in the name of security, and in the

way they treat people of different faiths and backgrounds. Terrorism, or fear of terrorism, is now firmly embedded within the Australian consciousness and is a fixed part of the political landscape. It now informs Australia’s foreign policy, its willingness as a society to trade away key rights for the dubious promise of ‘safety’, its approach to refugees and asylum seekers, and even local planning laws (witness the long debate over the construction of a mosque and Islamic cultural centre in the small Victorian rural town of Bendigo). In the wake of these episodes, it is now understood that a terrorist might be the young person at the tram stop, a neighbour’s teenage son, a nephew or niece, or sadly for a growing number of parents, even their own children. Yet despite this, many Australians continue to labour under a troika of misperceptions about the nature of the terrorist threat confronting the country. Grounded in hysteria and a seemingly irresistible urge to reduce the complex phenomenon of terrorism to glib clichés and headlines, an informal alliance of politicians and media seem to have become addicted to peddling these non-sequiturs. In short, what is needed is a calmer approach to discussing the nature of the threat faced by Australia, beginning with the dispelling of three enduring myths. Myth 1: Terrorists hate Australia for its way of life In the aftermath of any significant terrorist attack it is common to hear politicians attribute the actions to the terrorists’ ‘hatred’ of Australia’s way of life. People are told that terrorists, particularly those linked to Al Qaeda or Islamic State, hate freedom and democracy and are hell bent on its destruction. This reduction of terrorist motivations to a single obsession glosses over some important nuances and diverts attention from a more detailed and sophisticated understanding of what drives terrorists to kill. Stripping away the surface-level rhetoric of terrorists and examining the life histories of those who commit such acts reveals that the violence is very rarely motivated by any existential contempt for the accoutrements of modern liberal democratic lifestyles. Although they might not agree with the universal


franchise, the consumption of alcohol, licentious behaviour or the wearing of revealing clothing, this disagreement is not enough to trigger the urge to kill. Rather, violent rage is more often based on the belief that the dominance of these lifestyles leaves little room for alternatives. In the case of groups such as Al Qaeda and Islamic State, anger with the West is given added momentum by foreign policy where support for repressive regimes in the Middle East is conflated with a general hostility towards Islam and a desire to prevent Muslims from pursuing the kinds of social choices that are taken for granted in the West. This view was articulated clearly by Osama bin Laden himself after the 9/11 attacks when he rejected the view that the attacks were motivated by a hatred of freedom per se but were the result of opposition to American foreign policy. “I say to you that security is an indispensable pillar of human life and that free men do not forfeit their security, contrary to Bush’s claim that we hate freedom. If so, then let him explain to us why we don’t strike, for example, Sweden?” he said. The same is true of Islamic State and its recent attacks by its supporters’ targets in the West. It is important to note that until the commencement of the Western-led bombing campaign in August 2014, the group’s message focused on trying to attract Western recruits to assist in consolidating the so-called caliphate declared by its leader Abu Bakr al-Baghdadi. This only changed with the commencement of Western-led airstrikes and overt Western actions designed to roll back Islamic State’s successes. Of course, this is not to argue that the international community, particularly the West, should not have involved itself in the struggle to defeat Islamic State, whose grotesque use of violence posed both a moral and political challenge to the entire international community. But it is wrong to argue that Islamic State’s actions against the West are motivated by an existential hatred of Western society and a desire to obliterate democratic freedoms in the West. Myth 2: Terrorists are insane Another myth about terrorism is that those who perpetrate the violence must be insane

or in some way mentally impaired, with the most common diagnoses suggesting either psychosis or paranoid or narcissistic personality disorders. Until very recently, there was no evidence to support this view. In fact, most research suggested that the vast majority of terrorists were as ‘sane’ as ordinary members of the public. Some research even suggested that the rate of psychopathological illnesses within terrorist communities is slightly lower than their incidence among the general population. This research makes sense when the difficult circumstances under which terrorist groups exist are considered – the need to remain alert to police and intelligence operations militates against the presence of mercurial personalities within terrorist networks, particularly those prone to erratic or unpredictable behaviour likely to attract the attention of the authorities. It is true that some research suggests this might be changing with the growing phenomenon of lone wolfs and solo actors. The development of digital communication technologies and the associated emergence of virtual terrorist communities has certainly opened a space for personality types which in previous times would not have struggled to find a place within terrorist groups. However, research in this area is still in its infancy and a clearer picture is still some time away. Myth 3: Religion causes terrorism As demonstrated by the research of Peter Neumann and others, a large number of those fighting for Islamic State have been attracted to the organisation, not because of its religiosity – for they themselves are often religiosity illiterate – but because membership addresses deeper feelings of inadequacy and social impotence. Whereas once they felt powerless and weak, as part of Islamic State they feel empowered and important, imbued with a social significance and authority they could never have dreamed of in their previous mundane lives. In other words, it is not religion per se that fuels their violence; it is a complex set of grievances and psychological dispositions that are given a veneer of religiosity through their attachment to a highly selective use of Islamic thought. In the same vein, it would be wrong to blame Christianity as a whole for the actions

of Eric Rudolph, the man convicted of the Atlanta Olympics bombing and a series of attacks against abortion clinics and a lesbian bar, despite his affiliation with the shadowy Army of God. Rather, Rudolph – a loner with long-standing grievances against women and homosexuals – was angry and primed for violence before gravitating towards a terrorist network whose warped interpretation of Christian scripture provided a pseudo-religious justification for Rudolph to act out his preexisting anger under the guise of religiosity. Reducing terrorism to these myths partly explains why after over 10 years of the incremental erosion of human rights and civil liberties in the name of security – the so-called freedom-security trade off – the nation is no safer. Indeed, the data released by the Institute for Economics and Peace suggest the nation is at greater risk than ever before. There is no denying that Australia’s police and intelligence services do an outstanding job in anticipating and eliminating threats as they emerge. But it is also true that they remain hamstrung by a lack of political and social leadership and are more often than not reactive rather than proactive when dealing with the terrorist threat. This lack of leadership is epitomised by the ease with which political leaders and journalists retreat into the easy stereotypes discussed above. Holding to these myths not only obviates the need for deeper reflection and more honest explanations about the complexity of the threat, but also feeds a public expectation that defeating terrorism is simply a matter of killing, capturing or incarcerating irrational fanatics who hate Australians for their way of life. But this is precisely what Australia has been trying to do for more than a decade and, despite its efforts, the threat continues to grow. Surely it is time for a more honest public discussion about the complexities of the challenge that confronts Australia.

Dr David Wright-Neville is a Senior Political Risk Analyst at Globe Communications. He can be contacted via email: davidwn@globecommunications.com.au

SECURITY SOLUTIONS 035


ALARMS

CPTED: The Glue That Holds Security Programs Together And Provides A Unified Sense Of Purpose

036 SECURITY SOLUTIONS


By William Nesbitt

Crime Prevention Through Environmental Design (CPTED) as a security strategy has been steadily on the rise for the last 30 years or so. CPTED affects human behaviour by affecting perceptions. The goal is to discourage negative behaviour, while encouraging positive behaviour. This notion is very much in line with the behaviour modification theories of B.F. Skinner (the father of behavioural psychology). By design, CPTED is intended to evoke behaviour modification. CPTED methodologies are applicable to both internal and external environments. The threat of internal criminality has long been the downfall of a variety of business enterprises. External criminality can affect public perceptions, which may also result in business failures and losses affecting reputation, including premises liability lawsuits. CPTED has the capacity to have a positive impact and discourage negative behaviour. This is the psychology of CPTED – the reinforcement of positive and desirable behaviour.

The application of CPTED principals, like most security strategies, is to ensure that the result produces the outcome that the whole is greater than the sum of the parts. This means that CPTED should become the linchpin forming the basis for a holistic and synergistic security program; it should be an integral component of every security program. Crime prevention programs are effective only when they are perceived as legitimate. Video surveillance that is not monitored in real time will quickly lose utility and legitimate deterrent to criminal behaviour. Security technology lacking

a CPTED environment will quickly be rendered impotent. For those who doubt this assertion, just try watching the sixo’clock news some night. CPTED is applicable to many verticals, such as schools/universities and houses of worship. It is applicable to high-rise buildings, sports and entertainment venues and residential communities; to manufacturing enterprises, the biotech industry and healthcare facilities, along with shopping malls and office parks. The bottom line is that CPTED is a strategic adjunct to any security program and is a reasonable methodology to deter both the internal and external threat of criminality. To put it another way, the lack of CPTED may render otherwise effective security programs impotent, especially those enterprises that afford public access. CPTED is also applicable to internal environments such as supply chain facilities, hospitals, hotels and shopping malls. Storerooms and warehouses that appear to be in disarray and exude a perception of poor housekeeping and maintenance send a message of permissiveness and wanton disregard. The great thing about CPTED is that once one understands the fundamental components of the discipline, the situational application of these principals is only limited by one’s imagination. For anyone considering the inculcation of CPTED strategies, the best place to start is at the property line. When employees understand the application of CPTED values, they can actively become part of the solution. A few months ago, we had the opportunity to work with a large hospital group. One of the thematic architectural design features of most of these hospitals was the prodigious use of glass. This design feature produced 360 degrees of natural surveillance. I subsequently suggested that employees be encouraged to observe the surrounding

SECURITY SOLUTIONS 037


ALARMS

environs by looking for suspicious persons. Anytime such persons were observed, we encouraged them to contact the security team to check out those identified individuals. Obviously, 95 percent of those identified were legitimate visitors to the campus. Most times, the security officers simply offered good customer service. However, the implicit message to potential perpetrators was, “We are paying attention”. Natural surveillance became a proactive tool. The components of effective CPTED design include: • good lighting (preferably LED) • landscape maintenance (minimising areas of concealment) • unobstructed fields of view • wayfinding by design (external and internal) including the identification of restricted areas • establishment of recognisable boundaries and property lines • redundancy (circles of protection) for high-value/restricted areas.

The Security Solution Hierarchy, depicted here, represents a hierarchical approach to the development of a practice and effective security program. The hierarchy presents a progression of security strategies, moving from the least costly to the costliest (security personnel). Depending on the ambient threat environment, all levels may not be required. Please note that CPTED is the first level of the hierarchy. It is also the least costly over time. In some cases, CPTED may suffice. The great thing about CPTED is that, once it is understood, its dimensions are boundless, limited only by the inability of creative thinking.

038 SECURITY SOLUTIONS

CPTED has the capacity to have a positive impact and discourage negative behaviour. This is the psychology of CPTED – the reinforcement of positive and desirable behaviour.

Finally, the essence of almost any successful security program is proactive employee participation. Employee participation does not occur in a vacuum. The values and participative aspects of successful security and loss prevention programs require training and ongoing reinforcement. If employees are asked to be aware of suspicious people they must be given the skill sets to do so. If CPTED programs are to attain maximum effectiveness, the role of each employee must be defined. Consider this scenario: Assume there are two strip malls across the street from one another. Mall One is unkempt and looks neglected – there is trash blowing about the car park, the landscaping is overgrown and not maintained, some of the overgrown vegetation conceals a homeless encampment, some of the lights are not working and there are cracked windows here and there. Across the street, Mall Two is pristeen, well maintained and well lit. There are no signs of graffiti or broken windows and the perimeter of the mall is well defined by a well-trimmed border

hedge. Shop owners are provided with basic crime prevention training. Which of the two has more criminality, all other things considered equal? Finally, CPTED is very cost effective because it will negate the need for more costly traditional security modalities, and ensure that those more traditional modalities are more effective. Inversely, a well-designed security program will likely be marginalised if it is lacking CPTED. With just a little imagination, CPTED can be a positive adjunct to almost every aspect of any security program, including access management, perimeter control, asset and inventory protection, and it can even provide a positive contribution to workplace violence mitigation. CPTED design will also help to mitigate premises liability claims. Among the plethora of security measures, CPTED is likely the most cost effective. William H. Nesbitt, CPP is a certified CPTED practitioner and is president of Security Management Service International, Inc. (www.smsiinc.com). He can be contacted via email bill@smsiinc.com


ZKTeco Biometric technology, the next generation of access control is at your finger tips. Make your life sparkle with biometric innovations

EDUCATION | HEALTH | GOVERNMENT | FINANCE | HOSPITALITY | OFFICE SUPPLY | CHAIN RETAIL RESIDENTIAL | CONSTRUCTION | PROPERTY MANAGEMENT | REAL- ESTATE | PUBLIC FACILITIES Standalone Bio Finger RFID Backlit Keypad Face Recognition Finger and Vein

IP based Door Access Control Management C3 – 100/200/400 TCP/IP and RS-485 communication Built -in auxiliary inputs and outputs Advance access control functions 1 door, 2 door, 4 door models Lift controls and Expansion boards

www.mainline.com.au VICTORIA 221 Nepean Hwy Gardenvale, VIC 3185 +61 3 9596 6688

QUEENSLAND 54 Caswell St. East Brisbane, QLD 4164 +61 7 3891 2222

www.zktecoaustralia.com.au WESTERN AUSTRALIA Unit 8/14 Halley Rd Balcatta, WA +61 8 9344 2555

SECURITY SOLUTIONS 039


Post-Trauma Stress: Officer Wellbeing Post Confrontation [ Part 2 ]

040


041


By Richard Kay Part one of this two-part article introduced readers to the diagnostic criteria of posttraumatic stress disorder (PSTD) and the range of emotional reactions officers may experience after a traumatic event. As discussed, while officers may have little control over when confrontations occur, they do have control over how they respond to these events before, during and after. This article concludes the discussion by considering the debriefing process and protocols to follow post-incident. Debriefing A debriefing is any post-event discussion that assists officers to come to terms with and learn from it. Hopefully, it helps to gain closure so the event will not continue to cause emotional distress. An informal debriefing can be a discussion that arises spontaneously post event, while a formal debriefing is organised and facilitated to ensure it helps everyone. There are two primary functions of a critical incident debriefing: 1. It is needed to reconstruct the event from the beginning to the end, to learn what was done rightly/wrongly and to help develop operational lessons. 2. It is a time to put everyone back together. There might be memory loss, memory distortion, irrational guilt and a host of other factors that cloud the ability of the officers to deal with everything that happened. Debriefing is a tool to sort out these matters, and to restore morale and unit integrity. It can make lives healthier and sometimes it even saves them. The first objective is to capture and preserve the event in the minds of the participants, so the information can be dissected and everyone can learn from what happened. The first step in maximising memory retention is to have everyone involved make a report immediately after the occurrence. To get detailed information, participants need to be kept calm and collected. From the very beginning, the goal is to delink the memory from the emotions. Initially, participants should be removed from where the stressful event took place, as there are many associations there that can act as powerful stressors. Sometimes, for legal purposes, investigators are

042

concerned about ‘contaminating’ the memory process. In those situations, encourage everyone involved not to rehash the event with others, but rather go home and get a good night’s sleep to help recover additional memory. Sleep helps them achieve a calmer mental state, which in turn helps them consolidate information into their long-term memories. The next day, a second interview can be conducted, and then they can conduct their own informal debriefings with each other. To prevent their memories from being contaminated, instruct the participants not to read the paper or watch the news. After the first night’s sleep, an interview can be conducted at the location, but it may be necessary to help the participants separate their emotions from their memories. Anticipate that the interview might have to be stopped to help an especially emotional person through the tactical breathing process, because by returning to the scene, the participants are exposed to memory cues that facilitate their recall of how the event unfolded. Objects that seem to be inconsequential to people who were not involved just might provide the missing link that brings all the information together. The day after the incident, agencies should conduct a group ‘critical incident debriefing’. Everyone involved in the incident should attend. The idea of a group critical incident debriefing is to ‘get back on the train’ and derive specific memory cues from each other. All this is not without its flaws. A process called ‘memory reconstruction’ is unavoidable in a group debriefing. What happens is that some participants reconstruct, or fill in their missing pieces of memory with information learned from other participants. The mind hates a vacuum, so they might fill in the gaps and ‘remember’ it as if it had actually happened to them. Some degree of memory reconstruction is inevitable, but the group debriefing is still the best possible tool for giving participants accurate information to help them remember, for helping them learn from mistakes, and for helping them on the path to returning to normal after a horrific incident. Consider conducting a second debriefing 24–48 hours later. This allows participants to get another night or two of sleep, which often provides for further memory consolidation.

An informal debriefing can be a discussion that arises spontaneously post event, while a formal debriefing is organised and facilitated to ensure it helps everyone.


The first thing officers must understand is their obligation to participate in a critical incident debriefing. Unmanaged stress is a major factor that can destroy officers and devastate their families. PTSD is ‘the gift that keeps on giving’. When officers are impacted by stress symptoms, their families are also impacted and if it is left unchecked, they will continue to be affected in the years to come. One key tool to prevent PTSD is the critical incident debriefing. There are always those people who say something like ‘Debriefing? I do not need a debriefing!’ But the debriefing is not necessarily for them; it is for their colleague, partner, spouse and their children. It is important to let participants know that any thoughts or reactions they experienced during a critical incident debriefing are okay. Once they realise that the physical and emotional responses they experienced are normal, then they are more likely to relax and open up, and these reactions no longer have the power to hurt officers. The most important objective of a debriefing is to separate the memory from the emotions, delinking the memory of the event from the sympathetic nervous system arousal. Officers need to make peace with that memory, so that it does not haunt them. As the debriefing unfolds and they work their way through the memory of the event, know that anything and everything is permitted, except anxiety. Post-Incident Protocol After surviving a force response encounter, many officers are further traumatised in word and deed. Because of the treatment they receive, they feel betrayed and abandoned by their own people, and the psychological injuries they experience can hurt more than their physical injuries. Often, fellow officers unwittingly inflict trauma because they do not know how to appropriately relate to a colleague who has been involved in a critical incident. Here is a post-event protocol that will heal rather than harm: First words: The initial response by peers and command staff should be, ‘I am glad you are safe’. This suggests concern, care and support and very effectively eases the immediate emotional trauma that the involved officer may be experiencing.

Make contact: Avoiding an officer after an incident may make him feel he has done something wrong. Sometimes peers are ordered not to contact the officer so as not to damage an investigation, but this leaves the officer feeling alone and anxious. At a minimum, if the incident cannot be discussed or others do not know what to say, they should give the officer a handshake, a hug, or an understanding nod. These nonverbal gestures can be a powerful indication of support. Avoid second guessing: No one was in the officer’s shoes during the incident; no one saw it evolve from his perspective. Others may think they would have acted differently, but no one knows for sure how they will act in a violent encounter until they are actually in one. Do not second guess another officer’s actions, and discourage him from second guessing himself. He likely had only milliseconds to make his decisions, and usually on only partial information. Second guessing could lead to dangerous hesitation the next time around. Share experience: Those who have been in a similar critical incident should lend an empathetic ear and share their experience. They can help normalise how the officer is thinking, feeling and acting. If the officer is having some adverse reactions, it is particularly important to emphasise that he is not crazy but is responding normally to an abnormal and crazy event. Officers that have had counselling after an event can ease another officer’s concerns about ‘seeing a shrink’. Watch humour: Black humour is traditionally used as an effective coping mechanism in everyday life. But after a critical incident, be sensitive to the effect of humour on an involved officer. Use restraint: Do not lionise the officer – he may not feel heroic, especially if he had to take a life. At the same time, do not dehumanise the subject who forced the officer into responding – especially if the officer had eye contact with the subject as he was injured or dying, the officer may see the subject in very human terms and resent denigrating comments. Encourage talking: Do not allow the officer to withdraw from the world. When that happens, intrusive thoughts about the incident tend to become overwhelming. For legal reasons, it may be best to avoid discussing details of an incident,

The first thing officers must understand is their obligation to participate in a critical incident debriefing. Unmanaged stress is a major factor that can destroy officers and devastate their families. but without pressuring him, be ready to actively listen and not judge while the officer unloads about his emotions. A subject can potentially leave psychological skeletons in an officer’s emotional closet. Helping the officer unload emotional garbage by encouraging him to talk can be very beneficial. Talk over coffee, though, not over alcohol. Show respect: An officer surviving a threat to his life deserves to be honoured with dignity and respect, not in the manner of bitterness and resentment. He has followed his training and survived the most extreme of threats to carry out the duty bestowed on him to ensure public safety. These are important and require an openness and sensitivity that many officers find challenging if not downright intimidating. There is no hesitation is responding to an officerneeds-assistance call on the street. Officers will risk injury and even death to save another person’s life. But when a response is needed to an officer-needs-emotional-assistance call, it is often a different matter. That is something to think about, because responding appropriately to that kind of call is sometimes exactly what is needed. Richard Kay is an internationally certified tactical instructor-trainer, Director and Senior Trainer of Modern Combatives, a provider of operational safety training for the public safety sector. For more information, please visit www.moderncombatives.com.au

SECURITY SOLUTIONS 043


CCTV

044 SECURITY SOLUTIONS


Presenting CCTV Evidence In Court: A Case Study

SECURITY SOLUTIONS 045


CCTV

By Gary Palmer

With Internet Protocol (IP) and highdefinition (HD) CCTV now a part of everyday life for residential, retail and corporate business, it is more important than ever that the fundamentals of basic operation and system objectives are met. If not, the likely outcome will be a very expensive set of electronics that now provides little or no useful information to prosecute an offender. As an example, and to highlight the issues related to providing useful CCTV, the following scenario will be of benefit when designing, installing and maintaining a surveillance system. A few years ago at a licensed premises, which included a gaming facility, there was a confrontation between two individuals resulting in the death of one. Almost all of the activity was captured successfully on an analogue digital video recorder (DVR). The DVR was recovered and removed from site by police and a technician. To fully secure the evidence, the unit was stored in a secure vault within the court complex. At the time, we suggested to police that a backup be made of all video data for the full 24-hour period surrounding the incident from all 16 cameras on-site in case of a hard disk failure while the unit was in storage. Following consideration by police and the court, a copy of the video data was transferred onto a new hard disk drive supplied by police. During the process of backing up video data, the supervising officer (also the officer that attended the venue on the night of the incident) asked how best to ensure that the DVR would be fine and ready for use in court when the need occurred. This posed a number of issues. The question was raised regarding how long might it take before the evidence on the original DVR could be presented. The answer was understandably vague, as the processes involved in preparing the case, which involved both police and the court, were very detailed and would take considerable time to complete. The main issues surrounding the preservation of the DVR were as follows: • that the unit not undergo any significant

046 SECURITY SOLUTIONS

or unnecessary movement • under no circumstance could the unit be dropped during relocation • the unit should not be opened or manipulated unnecessarily in any way. The last point triggered a bigger issue that had not been considered previously. All of the people involved in the handling and storage of the DVR to this point were supremely confident that the data stored on the original unit was intact and that it was encrypted and watermarked in such a manner that would be acceptable for use in a court environment. They could also be reasonably confident that the unit would not need to be moved or relocated and certainly not dropped. The unit was tagged appropriately and boxed with its polystyrene packaging and carton and stored securely, so “all should be well when we get to court” we all said with a sigh of relief. We shall return to this particular incident in a moment. After a couple of weeks had passed, a shoplifting incident occurred at an unrelated site and video data was backed up from the ageing DVR and provided to police. It was noted during the process of completing the on-site backup that, although the incident had occurred during daylight savings time, the DVR had not automatically updated its time correctly as the time server IP address in the DVR was no longer valid. Upon further investigation, it was found that the CMOS battery on the motherboard was dead, resulting in the time and date on the unit being reset to the unit’s default, most likely following a complete power re-boot. This initially triggered some concern about the ability to retain secure video data on older models of DVRs. However, further thought led us to explore the necessity of ensuring that systems are maintained in a manner that would reduce the risk of unreliable video evidence. This incident immediately prompted concern regarding the previously discussed DVR, which was being held for evidentiary purposes by the court, with my immediate thought being ‘what if’. A concern which would very soon become pertinent.

Contact was made with police to point out that if the DVR in question was going to be held in a secure evidence store for an extended period of time, the CMOS battery might fail, which would not corrupt any of the existing video data on the drives, but could and probably would reset the system time to the default 01-01-2000. Furthermore, on power up, the unit would begin recording from that date. Therefore, surely when the unit was used in court to provide evidence, the recorded video history would clearly show that the most recent video data recorded appears to be up to eight years older than the video being presented for evidence. Did this render the video evidence of the incident unusable or unreliable? It was decided that during the lead up to trial, the DVR would be periodically brought out of the evidence store and run up in a secure environment within the court facility with a police and court witness present at all times. This would ensure and confirm that the DVR would be functional and ready to present the video data recorded at the time of the event from its original source, not a backup. It was also decided that during the trial, I should be available to present factual evidence with regards to the construction of the DVR, the software used to create the recordings and original installation, maintenance, recovery and continued care of the unit. The positioning of cameras on-site was considered at the time of installation and, of course, had evolved during the life of the CCTV system to reflect the growing needs of the venue. We had discussed during the installation that the balance between the length of recorded history and the number of frames each camera would capture each second was a critical decision, but could be easily adjusted over the initial month to get the best possible outcome. The eventual frame rate agreed upon was seven frames per second. It was felt that this would provide around 60–70 days of recorded history and all at a very good motion detect sensitivity. The cameras utilised were of relatively


good quality, with some even being reused when the system was upgraded. The cameras were at least 500TVL day/night, so good images were produced, regardless of the local lighting and weather conditions. A number of the cameras were inside the building and a couple were on the external facade to cover car parks and entry points. The Trial The trial ran over a number of days, with my attendance being required for the duration of the hearing. Although I had attended many court cases to provide support to police or the court, this was the first that involved the death of a person clearly recorded on CCTV. Coincidentally, the camera that captured the final event was not an expensive 600TVL day/night camera with sens-up or clever backlight compensation (BLC) adjustments; it was an older, full-bodied camera in a dome housing that had been installed some years before. My initial court attendance involved being required to re-install the DVR into the actual courtroom where the trial would commence later that day and then training prosecution and defence barristers on the use of the unit’s playback characteristics. I was present when the incident was shown to the court and was then questioned at length on the construction, programming and security of the recorded video data. I was also asked about my personal experience and longevity in the security industry, including my historic knowledge of this particular DVR and software. All of the aforementioned questions were answered with little need for further questioning. However, it should be remembered that when giving such evidence, one must only state the facts and no assumptions may be made regarding any part of the evidence provided and to remain calm and confident in your answers. I would like to say at this point that the idea of having to provide evidence in court is an easy thing to do, but it is not. It is stressful and sometimes disconcerting. The most difficult points to relay to the court were the understanding of video compression (why

does it need to be compressed), frame rate (explaining what might have been missed in the other little bits of that one-second period recorded), motion detection (what bits do not get recorded) and the watermarking of video (security), all of which would have a direct bearing on the final outcome of the trial. To make these points clearly and concisely in a manner that the court could understand, a large whiteboard came in very handy. The outcome of the trial was never going to be positive for the individuals involved, but it proved that the best possible CCTV evidence is a critical component for police and the court to come to a definitive decision. As a result of my involvement with this and other court cases, I have been able to develop a number of key points which need to be taken into account when considering the implementation and maintenance of any CCTV system. They are: • Regularly maintain the system, including camera mounting, cleanliness, focusing and alignment to the subject.

• Check the system time against a known correct source frequently and correct accordingly. • Retain records of system maintenance. • Only use recording equipment that records watermarked images and therefore cannot be manipulated, altered or changed in any way. • Restrict the number of employees that have access to the CCTV equipment. • Provide training to key staff on the use of the system, ensuring they can backup video for police on request. • Remember that the person that provides the video data to police will become a witness; they should have a good understanding of the CCTV system and be able to give evidence of the steps they took to make a backup copy of the video data supplied to police. Some guidance on camera location, purpose and objective is provided below, in accordance with South Australian Police requirements for closed circuit television.

Location

Camera Purpose

Objective

Entrance and exit

Identify

Identify all persons entering and leaving the premises

Service counters

Identify

Identify and clearly record actions of customers and staff

High-value merchandise

Recognise

Clearly record actions of customers and staff

Pay points (customer side)

Recognise

Clearly record actions of customers at the payment point

Pay points (business side)

Recognise

Clearly record actions of staff at the payment point

Vehicle gates/driveways

Recognise

Clearly record entry and departure of all vehicles

Shop floors/display areas

Detect

Identify customers and staff and establish their movements

Car parks

Observe

Determine the date and time of persons and vehicles in the area

Fuel station forecourts

Recognise

Record images of vehicles and persons re-fuelling vehicles

Fuel station forecourts

Identify

Identify all vehicle number plates

Hazardous materials

Recognise

Clearly record actions of customers and staff at the counter

Gary Palmer is the general manager/director of AlarmLogic Electronic Security and passes his 40th year in the security industry this year. Gary has spent six years as president of The Security Institute of South Australia (formerly The National Security Association of Australia - SA) and, following many appearances in court to assist in technical-related issues, was appointed as an industry assessor by the Attorney General in the state of South Australia. As such, he is considered by the South Australian courts to be an expert court witness in matters related to CCTV. Gary can be contacted via email admin@alarmlogic.com.au or call 08 82857455.

SECURITY SOLUTIONS 047


BUSINESS

048 SECURITY SOLUTIONS


Building Risk Culture Is Easier Than Making Hot Dogs By Alexei Sidorenko Yes, building risk culture is that easy! Before I explain, let me first clear some misconceptions about risk culture that have been floating around in the nonfinancial companies.

1

Making decisions under uncertainty is not natural for humans Back in the 1970s, scientists had a breakthrough in understanding how the human brain works, what influences people’s decisions, how cognitive biases impact on their perception of the world and so on. Daniel Kahneman and Vernon Smith received a Nobel prize in Economic Sciences back in 2002 “for having integrated insights from psychological research into economic science, especially concerning human judgment and decision-making under uncertainty�. It is amazing how many risk managers and consultants continue to simply ignore this research. Identifying, analysing and dealing with risks is against human nature. They need to stop kidding themselves. The sooner the professional community accepts this, the easier it will be to integrate risk management into decision making.

SECURITY SOLUTIONS 049


BUSINESS

2

Managers do not take risks into account by default One of the biggest deceptions floated around is that most business processes already take into account risks and decisions that are made by management after careful consideration of risks. Not so. Naturally, managers do consider some of the more obvious risks and there are exceptional cases where risk analysis is already integrated into the decision making. For the other 95 percent of companies, existing processes and management tools barely account for inflation and ignore or purposefully hide significant risks. If risk managers, instead of running useless risk workshops, had a deep hard look, they would soon discover that budgets are overly optimistic, project plans are unrealistic and some corporate objectives are borderline naïve. But then again, maybe not, because the rest of the company is fine with how things are and will do everything to stop risk managers from getting involved.

3

Making risk management everyone’s responsibility is just wishful thinking There seems to be an idea that strong, robust, risk-aware culture is the ultimate objective. It is the end result. While it sounds great, it is physically impossible. This is why so many risk managers have failed and so many more are struggling to make an impact. They are trying to move the rock that is not meant to be moved. This is probably the most important point of this article: The only person in the company who thinks strong risk culture is a positive thing is the risk manager. The rest of the organisation sees risk management as a direct threat to their personal interests, their income and their position in the corporate world. Most managers ignore risks and take uncalculated risks for a reason. Most, but not all managers, and not all the time. That is where the risk manager comes in, trying to change the culture of certain individuals some of the time.

4

Risk management culture is not about hearts and minds Hopefully by now, readers realise that management does not care about risk culture. They will still say the right words when the risk manager is present but, deep down, nobody will care. The only chance for risk culture to stick is if it makes business sense for the individuals. This does not mean soft things

050 SECURITY SOLUTIONS

like transparency, corporate governance and other nonsense; it means the direct impact on the bottom line or the personal security of an individual. The best examples of managers suddenly becoming very risk aware are when they can be shown that, by better managing risks, individuals could protect their role, avoid prosecution, have better business case for investors, save on insurance, save on financing costs or to get higher bonuses.

The only chance for risk culture to stick is if it makes business sense for the individuals. So… Takeaway Instead of Hot Dogs? Despite everything above, building risk culture is a piece of cake. Risk managers just have to realise that they will not be able to convert everyone and some people are beyond help. There is also no single solution that will do the job. It is all about finding what makes each individual tick. It is time consuming yes, but not difficult at all. Hence, it can be equally applied by large corporations and smalland medium-sized businesses. Here are some practical ideas to get started: • Develop high-level risk management policy. It is generally considered a good idea to document an organisation’s attitude and commitment to risk management in a high-level document, for example, in a risk management policy. The policy should describe the general attitude of the company towards risks, risk management principles, roles and responsibilities and risk management infrastructure, as well as resources and processes dedicated to risk management. Section 4.3.2 of ISO31000:2009 also provides guidance on risk management policy. • Integrate risk appetites for different risk types into existing board-level documents; do not create separate risk appetite statements. • Regularly include risk items on the board’s agenda. • Consider establishing a separate risk management committee at the executive level or

extend the mandate of the existing management committee. • Reinforce the ‘no blame’ culture by finding a number of arguments for different situations and different people on why it makes more business sense to disclose and account for risks. • Include risk management roles and responsibilities into existing job descriptions, policies and procedures and committee charters, not into a risk management framework document. • Update existing policies and procedures to include aspects of risk management. • Review and update remuneration policies. • Provide risk awareness training regularly. • Use risk management games. • Most importantly, get personally involved in business activities. More ideas about integrating risk management into day-to-day operations and building risk culture can be found in the book that will be available to download next month for free at http://www.riskacademy.ru/en/download/risk-management-book

Alexei Sidorenko is an expert with over 13 years of strategic, innovation, risk and performance management experience across Australia, Russia, Poland and Kazakhstan. In 2014 Alex was named the Risk Manager of the Year by the Russian Risk Management Association. As a Board member of Institute for strategic risk analysis in decision making, Alex is responsible for G31000 risk management training and certification across Russia and CIS, running numerous risk management classroom and e-learning training programs. Alex represents Russian risk management community at the ISO Technical Committee 262 responsible for the update of ISO31000:20XX and Guide 73 since 2015. Alex is the co-author of the global PwC risk management methodology, the author of the risk management guidelines for SME (Russian standardization organization), risk management textbook (Russian Ministry of Finance), risk management guide (Australian Stock Exchange) and the award-winning training course on risk management (best risk education program 2013, 2014 and 2015).


www.facebook.com/luminox

www.luminox.com

VIC 8th Avenue Watch Co., Emporium Melbourne, 03 9639 6175 | 8th Avenue Watch Co., Westfield Doncaster S/C, 03 9840 6304 8th Avenue Watch Co., Chadstone S/C, 9569 7652 | Temelli Jewellery, Highpoint S/C, 03 9317 3230 | Temelli Jewellery, Southland S/C, 03 9583 2633 | Temelli Jewellery, Westfield Knox City S/C, 03 9800 0799 NSW Lewis Watchmakers & Jewellers, Coffs Harbour, 02 6651 1612 | Melewah Jewellery, Haymarket, 02 9211 5896 | Vintage Watch Co., Sydney, 02 9221 3373 | Hennings Jewellers, Narellan, 02 4647 8555 WA The Watch Spot, Perth, 08 9421 1093 | Leon Baker Jewellers, Geraldton, 08 9921 5451 QLD 8th Avenue Watch Co., Pacific Fair S/C, 07 5575 4883 | Hatton Garden Jewellers, Beenleigh, 07 3287 1230 | Watch Tech, Brisbane, 07 3012 7023

SECURITY SOLUTIONS 051


COVER STORY

052 SECURITY SOLUTIONS


THE SHAPE OF THINGS TO COME Mapping the future Of Security Technology

SECURITY SOLUTIONS 053


Turn static files into dynamic content formats.

Create a flipbook
Security solutions #106 by Security Solutions - Issuu