Skip to main content

Security solutions #107

Page 1

A U S T R A L A S I A’ S L E A D I N G S E C U R I T Y R E S O U R C E F O R B U S I N E S S A N D G O V E R N M E N T

ISSUE #107 MAY/JUN 2017

ISSN 1833 0215

How Will The Australian Public Respond?

$9.95 inc GST / $10.95 NZ

When Terror Strikes:


NEED SERIOUS SECURITY? THE ANSWER IS EZI!

Ezi Security designs, manufactures and installs a premium range of electronic perimeter security products designed for both vehicle and pedestrian control. These consisting of a wide range of security products suitable for low to high-risk applications. Ezi Security Systems has been manufacturing quality security products for over twenty-one years with equipment is installed in some of the very harshest of environments the planet has to offer. And all with outstanding results. While Ezi has a commitment to innovative design and quality products we also fully understand the importance of easy and efficient after sales service. Ezi Security Systems services and maintain the products we sell to ensure that your critical infrastructure and personnel are protected at all times. “ALL EZI SECURITY SYSTEM PRODUCTS ARE BUILT TO LAST A RELIABLE THIRTY YEAR (PLUS) PRODUCT LIFE SPAN WHEN MAINTAINED”

Ezi Security Systems has the most extensive offering of Hostile vehicle barrier products (HVB’s) and has the expertise to design and secure any critical infrastructure or site of national importance. Ezi has an extensive range AVB and HVB Crash Certified products such as the world famous TruckStopper, the renowned K12 Wedge, crash boom beams and crash rated static and automatic bollards. Ezi Security Systems has all the realistic solutions to meet your high security requirements while maintaining an aesthetically pleasing solution for your site. All Ezi Security System AVB & HVB have been vigorously crash tested and certified to meet all ASTM, IWA and PAS 68 stipulations. Ezi Security and its partners continue to the push boundaries on all crash products with our in-house R&D security experts providing market leading products designs. This specialist ability also involves our renowned installation expertise and advice with the all important civil work design & engineering. Ezi Security believes in pushing design frontiers for its products to keep pace with marketplace and security priorities. This year alone Ezi and PPG have successfully worked with CTS and crash tested to Pas 68 in 2016 the following products:

•

M30 Bollard Performance rating V/7500[N2]/48/90:0.0/0.0

•

M50 Bollard Performance rating V/7200[N3C]/80/90:5.5

•

Wedge II Performance rating V/7500[N3]/80/90:0.0/20.7 (tested with 4 m blocking width)

With our highly chosen business partners being the best in their field and coupled with our own Ezi Security R&D in house design team Ezi Security continue to push boundaries on market leading and state of the art crash rated designed products. Our ability also involves installation expertise and advice with all important civil work design & engineering.


Ezi also takes pride to provide our clients with more than just perimeter security solutions. We also offer a quality range of internal pedestrian control products from Werra Entrance Control. The Werra Entrance Control range compliments perfectly the already strong offering of pedestrian security control that Ezi Security currently offers to the market. The range includes a wide variety of systems suitable for pedestrian access management that includes the ability to hold and isolate persons of interest and/or concern. Ezi Security again has a quality product for every threat and contingency for building personnel security. All products offer quick access for authorised persons and reliable protection against unauthorised access. With a flow rate of up to 35/min even large flows of people can be monitored and controlled effectively. Werra Entrance Control not only stands for innovative for the individual’s passage of person, but also is an extension for our philosophy of being a professional fullservice provider of all components within perimeter security and access control. Ezi Security Systems, and their business partners, are privileged to be protecting some of the most prestige and iconic man made marvels of the modern era from the Burj Khalifa Tower in Dubai to Australia’s very own Parliament House in Canberra.

IF SERIOUS SECURITY IS YOU REQUIREMENT, LOOK NO FURTHER THAN EZI! FIND OUT MORE ABOUT US!

AUSTRALIA NATIONAL

1300 558 304 11 Cooper Street Smithfield NSW 2164 www.ezisecurity.com.au sales@ezisecurity.com


CUSTOMISABLE ELECTRIC HEIGHT ADJUSTABLE SIT STAND CONSOLES

Does your control room meet

Australian Ergonomic Standards?

www.activconsole.com

Clayton VIC 3168


Safe Work Australia, Nov 2015

“...in 2012-13 the cost impact of work-related injuries and illnesses was estimated to be just over $61 billion...�

State-of-the-art ergonomic lifting technology Lifetime Australia phone support AS/NZS 4443:1997 & ISO 11064

+61 3 9574 8044

sales@activconsole.com


CONTENTS107

COVER STORY: AFTER THE ATROCITY: HOW WILL THE AUSTRALIAN PUBLIC RESPOND?

052 032

Over the past two years, Australia would have experienced 15 terror attacks, including public beheadings, if most plots had not been foiled in their advanced stages, according to police. Government agencies have done a great and cohesive job to stop attacks but we won’t always be so fortunate. Security expert Lyndall Milenkovic draws on over 24 years of experience in the risk arena, specifically in emergency management, including four Olympic Games, two Commonwealth Games and the World Expo in Shanghai, to examine how Australia might respond in the wake of a major terrorist incident.

HEALTH PREPAREDNESS AND AUSTRALIAN COUNTERTERRORISM STRATEGY Anthony Bergin, senior research fellow at Australian National University’s National Security College and a senior analyst with the Australian Strategic Policy Institute (ASPI), looks at the potential adverse health consequences which may follow a mass casualty attack in Australia. How bad would it be and what could and should we be doing to minimise the effects of such an incident?

060

GOVERNANCE OF EMERGENCY INCIDENT MANAGEMENT Neil James, Executive Director of the Australia Defence Association, examines the structure of ministerial governance of the agency or agencies concerned in dealing with major incidents and the legislation under which they operate. Are they actually fit for purpose and how can this fitness be best maintained?

070

HOUSTON: WE HAVE A PROBLEM! Jo Stewart-Rattray, Director of Information Security & IT Assurance, BRM Holdich and ISACA International Board Director looks at the issues around the lack of women in technology roles in the security industry and the technology sector in general.

084

SECURITY LEADERSHIP Former lawyer, NSW Legal Services Commissioner and current Registrar for the Australasian Register of Security Professionals, Steve Mark draws together ideas, comments and suggestions from a number of ‘experts’ and then presents a small case study from the author’s own experience around what it takes to be an effective security leader following a major incident.

088

WHEN RISK BECOMES REALITY Michael Dever offers insights into contemporary security risk management methodologies and the design and management of physical security systems. In this article, Michael focus on the process side of security risk assessments that are used to provide decision makers with appropriate advice about any protective security measures that may be required following a major incident.

004 SECURITY SOLUTIONS


We are a leading player in the biometric identification market by pioneering In Motion Identification (IMID) access, a multimodal verification for instant, seamless, and non-invasive verification. Ask us about advanced features such as multi-modality, speed of identification, our committed accuracy, anti-fraud algorithm, double factor availability, restricted people alerts, simultaneous identification.

The solution is designed for enterprise and can be easily integrated with existing infrastructure. It can be added to any existing door, turnstile or speed stile, and any access control solution. Ask us about high availability, scalability, cyber security and encryption, multi-site management, traceability and auditability, our APIs and ease of integration.

FST Biometrics is a leading identity management solutions provider. The company’s IMID™ product line offers access control through its proprietary In Motion Identification technology. This provides the ultimate security and convenience for users, who are accurately identified without having to stop or slow down. IMID™ solutions integrate a fusion of biometric and analytic technologies that include face recognition, body behavior analytics and voice verification. For more information, please visit http://www.fstbm.com.

With IMID Access, authorized users do not have to slow down, sign in or stop. Rather, they are identified in motion, and granted seamless access to buildings and facilities. Ask us about our rich out of the box functionality, such as visitor management, time attendance, notifications, digital doorman and mobile applications.

Add-On APAC Innovative Solutions offers converged physical, cyber and communication security solutions. Operating across the Asia Pacific region, we harness advanced products and ground-breaking technologies, helping our customers transform the way they protect people, information and assets. Learn more about us at http://www.addonapac.com. Add-On APAC Australia Pty Ltd info@addonapac.com, 03 9607 8465

IMID is the future of access control. Prefer to take your own conclusions?

Ask us for a product demonstration, and see it for yourself. SECURITY SOLUTIONS 005


CONTENTS107 010

040

LETTER FROM THE EDITOR

012 LEADERSHIP Jason Brown looks at leadership in the wake of a major

044 CCTV Leading CCTV expert Vlado Damjanovski looks at the

importance of designing CCTV systems to provide the necessary information to help deal with major incidents.

incident.

014

CYBER SECURITY How should companies respond to a data breach?

048 BUSINESS What are the four steps crucial to integrating risk management into strategic planning.

016 RESILIENCE What is the role of security professionals in mass gatherings?

018

058

HUMAN RESOURCES How should your organisation deal with disaster recovery and response from a human resources perspective.

020 RISK MANAGEMENT What does risk management look like after a major attack?

looks at Critical Incident Management and the importance of post incident actions within a system.

064

LOSS PREVENTION What are the keys to developing a plan for dealing

with busy retail periods?

072 AVIATION Aviation is always one of the hardest hit sectors in the

wake of a terrorist attack. How can the aviation industry better prepare, from a security point-of-view, for effectively responding to a major incident?

professional relationships ‘before’ a major incident occurs?

THINKING ABOUT SECURITY How can the security industry help shape Australia’s response to an attack?

028 EVENTS A look at upcoming industry events.

076 ACCESS CONTROL How do you protect sensitive sites in a constantly changing and evolving security landscape?

080 PROFESSIONAL DEVELOPMENT How can security managers more effectively shape the thinking of an organisation’s senior management team in preparation for dealing with major incidents?

036 ALARMS When everyone is clamouring for equipment following a major incident, how should suppliers interact with customers?

032

LEGAL Q&A Dr Tony Zalewski

024 COMMUNICATIONS Why is it so important to develop good 026

OPERATIONS Richard Kay examines the building blocks required in order to successfully prepare officers for dealing with dangerous events.

068

088

092

SECURITY STUFF

106

PRODUCT SHOWCASES

094

SPOTLIGHTS

110

SHOPTALK Company announcements from within the industry.

100

PROFILES

006 SECURITY SOLUTIONS


SECURITY SOLUTIONS 007


www.securitysolutionsmagazine.com

Editorial Editor: John Bigelow john@interactivemediasolutions.com.au Sub-Editing: Helen Sist, Ged McMahon Special Guest Editor: Don Williams Contributors: Anthony Bergin, Karissa Breen, Jason Brown, Greg Byrne, Rod Cowan, Vlado Damjanovski, Mike Dever, Kevin Foster, Neil James, James Jordan, Steve Lawson, Steve Mark, Lyndall Milenkovic, Laurie Mugridge, Rita Parker, Daniel Pinter, Jo Stewart-Rattray, Don Williams, Tony Zalewski.

Advertising keith@interactivemediasolutions.com.au Phone: 1300 300 552

Marketing & Subscriptions admin@interactivemediasolutions.com.au $62.00 AUD inside Aust. (6 Issues) $124.00 AUD outside Aust. (6 Issues)

Design & Production Graphic Design: Jamieson Gross graphics@interactivemediasolutions.com.au Phone: 1300 300 552

Accounts accounts@interactivemediasolutions.com.au Phone: 1300 300 552

Publisher

ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au Disclaimer The publisher takes due care in the preparation of this magazine and takes all reasonable precautions and makes all reasonable effort to ensure the accuracy of material contained in this publication, but is not liable for any mistake, misprint or omission. The publisher does not assume any responsibility or liability for any loss or damage which may result from any inaccuracy or omission in this publication, or from the use of information contained herein. The publisher makes no warranty, express or implied with respect to any of the material contained herein. The contents of this magazine may not be reproduced in ANY form in whole OR in part without WRITTEN permission from the publisher. Reproduction includes copying, photocopying, translation or reduced to any electronic medium or machine-readable form.

RS A DE VI

SSOCIATI

ON

ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au

O

SECURIT Y

PR

RALIA LTD UST FA

O

Written Correspondence to:

Or i g i n a l Si z e

O C I AT I

ON

Y P R OVI D

RIT

CU

D LT

SE

PR O

ASS

SPAAL

AU S T R A L I A

STRALIA LTD AU

SECURITY

RS

OF

E

Official partners with:

SSOCIAT IO N

OF

RS A DE VI

blue colour changed to this colour green.

COPY/ARTWORK/TYPESETTING APPROVAL Please proof read carefully ALL of this copy/artwork/typesetting material BEFORE signing your approval to print. Please pay special attention to spelling, punctuation, dates, times, telephone numbers, addresses etc, as well as layout.It is your responsibility to bring to our attention any corrections. Minuteman Press assumes no responsibility for errors after a proof has been authorised to print and print re-runs will be at your cost. Signed.................................................................. Date........................

008 SECURITY SOLUTIONS


Series 2005 is the leading brand of 19” rack mount enclosure for data and communications installations, with a huge range of sizes. MFB have the right cabinet for your needs.

When you choose Australian made, you’re choosing more than quality and reliability, you’re choosing peace of mind.

DESIGNERS & MANUFACTURERS OF 19” RACK SYSTEMS

MFB’s range of innovative racking solutions is proudly made onshore, to ensure quality and consistency above all others. Backed by constant development, unsurpassed customer support and expedited delivery. MFB proves a solid project partner whatever your requirements. Australian made, makes Australia. With a solid history of over 45 years of supplying innovative, off-the-shelf and custom built racking systems, you can rely on MFB to ensure when you buy Australian, you’re investing and supporting Australian industry.

AUSTRALIAN MADE MAKES AUSTRALIA

www.mfb.com.au

VIC NSW -

P (03) 9801 1044 P (02) 9749 1922

F (03) 9801 1176 F (02) 9749 1987

E sales@mfb.com.au E sydney@mfb.com.au

SECURITY SOLUTIONS 009


LETTER FROM THE EDITOR It is an honour to be invited to be guest editor of Security Solutions Magazine. I take this opportunity to thank John Bigelow for his ongoing commitment and hard work over more than 17 years in keeping us informed, educated and constantly challenging us to improve ourselves and the security industry. As the Irish Republican Army (IR A) said after the Brighton bombing failed to kill Margaret Thatcher, “You have to be lucky every time, we have to be lucky once.” Australia will suffer a major security incident resulting in multiple deaths, many casualties and a severe shock to our image as a safe society. The groups that want to kill really have not changed since the 1960s, although they take turns being most prominent: fringe right and left wing parties, animal rights activists and eco-terrorists, ethno-nationalists and separatists, and religious and social extremists. Through a combination of good policing, intelligence, community liaison, social cohesion and luck, we have avoided a major atrocity, so far. As security managers and practitioners, we concentrate on protective security – preventing the incident from occurring. While we recognise the importance of consequence management, it usually receives considerably less thought than the likelihood part of the risk equation. This issue of Security Solutions addresses the question of what happens when the risk is realised. It will be interesting to see how we, as a society, respond when we are finally attacked in a way that shakes our fundamental belief in who and what we are. Will we lose faith in our system and leaders because they failed to protect us, or will we bind together under adversity to become stronger and more unified? The contributors to this issue were asked to consider what happens “after the incident”. They all raise interesting questions and, in some cases, provide answers. The articles cover legal aspects, sector leadership, government response, resilience, cyber concerns, emergency management and legal issues. The cover story addresses how we as a nation, and as a society, will respond, as well as the role of the security professional, noting that we are also members of the community and, although we may have a better understanding of what happened and why, will still be affected along with the rest. In all cases, it is apparent that more work needs to be done and we who are responsible for preventing it cannot just wash our hands and say “well now it has happened it is not my problem, talk to business continuity planning”. We need to be involved in the post-atrocity planning and probably help lead the discussion. Securing of the business during and after the incident will be needed, as will working with others to secure the survivability of the organisation. It is not a matter of if but when and we should be ready; apparently, we are not.

Don Williams Special Guest Editor

010 SECURITY SOLUTIONS


REGULAR

LEADERSHIP Leadership and command is not exercised by retreat to so-called coordination or to broad oversight. Leadership and command is not exercised by being available if necessary at the end of a telephone.” So, what does this mean? In summary, to be a leader in the face of disaster, one needs the psychological traits and the leaderships skills to suit the situation. Leadership comes to the fore in times of crisis and disaster; it comes from the heart, not just the brain.

Post-Disaster Leadership By Jason Brown In my last column, I discussed situational leadership and now I will consider a particular situation for leaders – post-disaster or traumatic incidents. At a time of crisis and disaster, the managerial rule book fails, as it is the innate traits and the learned high-end competency for leading and supporting people in stress that becomes more relevant. Consider some innate traits: • Empathy – the experience of understanding another person’s condition from his/her perspective. You place yourself in his/her shoes and feel what that person is feeling. • Sympathy – (from the Greek words syn ‘together’ and pathos ‘feeling’ which means ‘fellow-feeling’) is the perception, understanding and reaction to the distress in others. • Selflessness – having, exhibiting or motivated by no concern for oneself; unselfish: a selfless act of charity. • Esprit de corps – a common spirit of comradeship, enthusiasm and devotion to a cause among the members of a group. • Compassion – a feeling of deep sympathy and sorrow for another who is stricken by misfortune, accompanied by a strong desire to alleviate the suffering. The Harvard Business Review suggests, “There is, however, something leaders can do in times of collective pain and confusion. By the very nature of your position, you can help individuals and companies begin to heal by taking actions that demonstrate your own compassion, thereby unleashing a compassionate response throughout the whole organization.” When compassion is derived from empathy and is converted into action, it can touch all concerned. In the boxed quote at the end of this article from

012 SECURITY SOLUTIONS

Harvard (https://hbr.org/2002/01/leading-in-timesof-trauma), we can see the personal actions by the leader making a difference. The full article also has a telling comparison example of a leader who did the reverse. But what about the practical competence? Leaders in a time of crisis need to demonstrate the following skills and knowledge: • Two-way communications – listen, hear and speak; the process by which information is exchanged between individuals. It requires a shared understanding of symbol systems, such as language and mathematics. Communication is much more than words going from one person’s mouth to another’s ear. In addition to the words, messages are transferred by the tone and quality of voice, eye contact, physical closeness, visual cues and overall body language. • Organisation – the ability to efficiently allocate time, energy and resources in order to achieve a goal. • Decisiveness – the ability to make decisions quickly and effectively. • Delegation – the capacity to allocate authority, responsibility and resources to achieve a task. • Command – to direct with specific authority or prerogative; order: and to deserve and receive (respect, sympathy, attention and so on): Jack Rush, QC, counsel assisting the Royal Commission into the Victorian fires said, “We submit that leadership cannot be divorced from command. Command does not necessarily involve the issuing of orders or directions, or swooping in to take over at an incident control centre. Command demands a presence: to inform, and if necessary, reassure and inspire. But also to oversight and monitor to ensure that key objectives are being met by subordinates.

Jason Brown is the National Security Director for Thales in Australia and New Zealand. He is responsible for security liaison with government, law enforcement and intelligence communities to develop cooperative arrangements to minimise risk to Thales and those in the community that it supports. He is also responsible for ensuring compliance with international and Commonwealth requirements for national security and relevant federal and state laws. He has served on a number of senior boards and committees, including Chair of the Security Professionals Australasia; Deputy Registrar Security Professionals Registry – Australasia (SPR-A); Chair of the Steering Committee for the International Day of Recognition of Security Officers; member of ASIS International Standards and Guidelines Commission; Chair of Australian Standards Committee for Security and resilience. TJX president and CEO Edmond English, who lost seven employees aboard one of the planes that hit the World Trade Center, gathered his staff together shortly after the attacks to confirm the names of the victims. He called in grief counsellors the very same day and chartered a plane to bring the victims’ relatives from Canada and Europe to the company’s headquarters in Framingham, Massachusetts. He personally greeted the families when they arrived in the parking lot at midnight on September 15. Although told by English that they could take some time off after the attacks, most employees opted to come in to work, as English himself had done, and support one another in the early days following the tragedy.


• INNOVATIVE PRODUCT DESIGN • BULLET RESISTANT CERTIFIED • BURGLARY RESISTANT CERTIFIED • UNIQUE HPJ CONCEPT

High Security Anti-Tailgating Portals

44

YEARS IN SECURITY

With over 40 portals in the range here is a closer look at two C3 Security Portal

HPJ140 Security Portal

The C3 Security Portal offers

The HPJ140 Security portal offers

•

Ultra Sonic Tailgate Detection

•

Unique Half Portal design to ‘cap’ an existing access controlled door

•

890mm entrance for DDA compliance

•

Ultra Sonic Tailgate Detection

•

Open design for maximum user comfort

•

900mm to 1200mm entrance for DDA compliance

•

P1A all the way up BR4 and WK4 glass construction

•

P1A all the way up BR4 and WK4 glass construction

www.pathminder.com.au

Phone: 1300 750 740 SECURITY SOLUTIONS 013


REGULAR

CYBER SECURITY Responding To A Data Breach

By Karissa Breen It is coming up to the weekend and everyone is starting to relax; the beer and champagne are coming out and everyone is now talking about their weekend plans. I see some senior leaders gathering and going in and out of meeting rooms. Uh oh, something is definitely going on. I hope it is not because my time sheet was late. The senior leaders are starting to look more worried and appear a bit lost. I have now been told my presence is required at a meeting. I am definitely feeling anxious; it is not about the time sheet, something worse. It is 4pm, I have had a long week and I just want to go home. I walk into the meeting room and a few faces look at me in shock. “We have been breached.” Well, that was that, we have been breached. We will need a team to work over the weekend to assist with this incident. We are going to need a plan, we are going to need to identify what went wrong, what data has been breached and what we are going to say to our clients. We are a newly formed company, this is not good for our reputation. This story sets the scene on what does happen within organisations and it sometimes does happen on Friday afternoons; unfortunately, that is just the nature of the business. Everyone is puzzled as to how this has happened, as it has never happened before. But how can they be so sure?

014 SECURITY SOLUTIONS

Data breaches hold a significant risk to organisations within Australia. These breaches represent companies which fail to protect confidential data, opening a gateway to fraud and data exfiltration. A data breach is an incident that involves sensitive information, which has been viewed or stolen by an unauthorised source. Companies and consumers are affected by their data being exposed. The internal dialogue starts going through everyone’s heads – what happens now, how does the organisation circumvent this? The answer is that Australia has now implemented laws that stipulate mandatory notification to the Australian Information Commissioner and communication must be made to members of the public when companies are aware they have been breached. They can no longer keep quiet or try to bypass a community announcement, as this is now incumbent of the law. These mandatory laws have now brought the Australian standard in alignment with other countries around the world, which have implemented the same requirements. Australian organisations want to engender trust in their clients. They want to demonstrate that they take their privacy and security seriously by implementing the appropriate

security controls. Addressing data breaches in the Australian market will generate awareness and assist in maturing the industry. In the event of a data breach, organisations will either have their own internal security team perform the investigation or an external consulting firm to determine what went wrong, what data was compromised and to generate a response strategy, as well as to provide a road map to uplift a company’s current security posture. Breaches are becoming more prominent as the world moves towards a digital economy. Regulations have been put in place to assist in mitigating the potential risk due to these attacks. It does not matter the size of the company, big or small. All companies are at risk of having a potential data breach; it is about how they respond to them and what they are doing on a day-to-day operational basis to ensure they are being smarter than the cybercriminals.

Karissa Breen is currently working as a BDM for Green Light who are an IT service provider and has a background in Cyber Security and has consulted to financial institutions. Karissa publishes her own IT blog.


S K Y H AW K FOR VIGILANT SURVEILL ANCE

L E A R N M O R E AT S E A G AT E . C O M / A U

SECURITY SOLUTIONS 015


REGULAR

RESILIENCE Mass Gatherings – The Role Of Security Professionals By Dr Rita Parker

Without doubt, concentrations of large numbers of people in accessible places are potential targets for terrorist and criminal attack and present a unique set of challenges to security professionals. Places of mass gathering include sporting venues, shopping complexes, open-air markets, business precincts, tourism and entertainment venues, cultural facilities, hotels and convention centres, public transport hubs and major planned – and unplanned – events. Mass gatherings, particularly in larger cities, provide opportunity for attack because of their accessibility and vulnerability. They potentially have high symbolic value and high impact imagery is generated by an attack. Above all, mass gatherings have potential consequences in terms of mass casualties, economic impact and generating fear in the broader community. The Melbourne Bourke Street attack in January this year, the truck attacks in Berlin and Nice last year, the attacks at the Bataclan Concert Hall and the Stade de France in Paris in 2015, and the 2013 Boston Marathon attack all highlight the vulnerability of planned and unplanned mass gatherings in their many forms. While event managers, and owners and operators of places of mass gathering, are responsible for taking reasonable steps to ensure the protection and safety of people, responsibilities are now more broadly shared. In 2009, the Australian National Counter Terrorism Committee noted that the protection of places of mass gathering is most effectively delivered through a business–government partnership, and it agreed to coordinate at a national level the work associated with protecting places of mass gathering.

016 SECURITY SOLUTIONS

This was a notable shift in public policy and a recognition of the role of the private sector. Prior to 2000, national security policy focused primarily on securing state assets against international terrorism and it was almost exclusively delivered by government security services. At that time, and in keeping with traditional views of security, security professionals in the private sector played little or no role. This has changed considerably today, where security professionals now play a valued role in securing and maintaining critical infrastructure and major events, as well as essential services and personnel. This change is evidenced by the number of public–private partnerships in which governments, national and state, have increasingly sought to cooperate with private corporations and businesses as well as with regional and local authorities. While the media often focus public attention on the tragedies of attacks on mass gatherings, many mass gatherings, including those of significant size such as the Rio Olympics and the 2017 Super Bowl can, and do, take place without incident. While the level of risk and vulnerability can never be completely mitigated for any mass gathering, contributing success factors reflect increased efforts to focus on preparedness and preventative aspects of the resilience cycle. This means moving beyond the ability to absorb shock, with the focus instead on the ability of businesses, governments and communities to take preventative action. This has been an important and significant step-change. To assist security professionals to meet the challenges of mass gatherings, there is a wealth of publicly available material and tools to increase their awareness and knowledge to build resilience, security and safety at mass gatherings. For further reading on this topic, I suggest three important and useful publications. First, the

National Guidelines for the Protection of Places of Mass Gathering from Terrorism (2011) which was supplemented in 2015 by the second publication, the Active Shooter Guidelines for Places of Mass Gathering. The third relevant publication is Improvised Explosive Device Guidelines for Places of Mass Gathering. These improvised explosive device (IED) guidelines, released in 2016, are designed to help governments and businesses protect Australians from the potential use of IEDs in places of mass gathering and to prevent, prepare for and respond to an attack. All three publications were developed by the Australia-New Zealand CounterTerrorism Committee (ANZCTC). Minimising and mitigating risks and threats at mass gatherings is a collective responsibility and all security professionals can contribute by building resilience to make future events safer and more secure. Dr Rita Parker is a consultant advisor to organisations seeking to increase their corporate and organisational resilience and crisis management ability. She is an adjunct lecturer at the University of New South Wales at the Australian Defence Force Academy campus where she lectures on resilience and nontraditional challenges to security from non-state actors and arising from non-human sources. Dr Parker is also a Distinguished Fellow at the Center for Infrastructure Protection at George Mason University Law School, Virginia, USA. She is a former senior advisor to Australian federal and state governments in the area of resilience and security. Dr Parker’s work and research has been published in peer reviewed journals and as chapters in books in Australia, Malaysia, the United States, Singapore and Germany, and presented at national and international conferences. Rita holds a PhD, MBA, Grad. Dip., BA, and a Security Risk Management Diploma.

C

M

Y

CM

MY

CY

CMY

K


Why force customers to collaborate when they are just happy to do it?

Open technologies for a safer world

Be STid, be free Open technologies for secure and smart access control Expert in contactless identification for security and industry for 20 years. First RFID manufacturer to have received the ANSSI French Government Security Certification.

SECURITY SOLUTIONS 017


REGULAR

HUMAN RESOURSES Disaster Response And Recovery From A Human Resource Perspective By Greg Byrne One of the most important responsibilities of human resources (HR) is to prepare for a disaster, including streamlining safety initiatives, communicating with employees and headlining crisis management efforts. Beyond this, organisations also have a duty to protect their workers’ safety while on the job. Work Health Safety legislation places onus on businesses to provide an environment free from hazards that can cause death or physical harm. As an involved member of a crisis management team, the HR manager/department responsibilities at the planning/preparation stage include: • assisting in the development of a crisis management team • development of a robust strategy that preserves HR records, such as personnel files, payroll, rosters, sales records and so on • development of a communication strategy that identifies the various means of communication with employees, customers and critical business partners • keeping a list of 24-hour emergency numbers for all employees (especially critical for casual staff who could easily seek employment with a competitor) and develop a call tree to keep employees informed • involvement in business risk management planning • assisting with risk assessments and strengths, weaknesses, opportunities and threats (SWOT) analysis

018 SECURITY SOLUTIONS

• development of a contingency recovery plan with the crisis management team – this is a current document outlining the organisation’s chain of command, worst-case scenarios and so on • ensuring there is a clear link between the plan and the organisation’s mission and core values • consideration on what to do if the ability to deploy and locate staff is lost or, if staff are unable to temporarily relocate (such as control room) or work remotely (e.g. locksmiths) • consideration of the ramifications for disruption to the supply chain and of engaging more than one supplier for staff uniform, equipment and storage of HR records. Planning considerations should address: • How will this event affect people? • Are there adequate workers compensation provisions? • Is the organisation able to stop or lessen the crisis in any way? • Does the organisation have the resources to react in a meaningful or effective way? • What happens if HR is not involved in planning and reacting? Once a plan has been developed and approved by the senior management team (or the board) it should be rolled out. Roll-out can include distribution to those who have a role to play in responding (some employees and most

supervisors). Roll out should also include training on how and when to activate the plan and who are the initial contacts and who should be informed of the crisis. On an ongoing basis, the plan should: • be updated and tested regularly; one of the roles of that person or department responsible for the plan is to ensure it is updated (phone numbers, new and leaving staff contact details) • be tested through regular crisis management team meetings and either field exercises (such as evaluations) or table-top exercises • update relationships with assistance providers such as the local fire and police departments, utility companies, community assistance organisations and government agencies. In the response phase, it is HR’s role to act as part of the crisis management team and ensure that the team and the organisation has the will and ability to implement the plan effectively. This should include: • assisting the senior management team to preserve the business or organisation’s reputation – this immediate and direct action can include management of stakeholders, continued deployment of guards and staff, and ensuring that customer appointments are being kept • ensuring staff and customers are evacuated to safe locations and their welfare and basic needs are being managed; further, that movement of


HUMAN RESOURSES staff is managed and that HR knows who is on duty, where they are and who has been sent home. • ensuring payroll records are maintained • ensuring all HR records are protected by being backed up, preferably in the cloud through a reputable service provider – most payroll software will automatically backup payroll and personnel data, such as annual leave balances and so on. As part of the recovery phase, HR should: • participate in recovery and focus on the safety, welfare and health of all employees and identify post-emergency assistance including, where

appropriate, employee psychological recovery and debriefing • assist the organisation to return to business as usual as quickly as possible • analyse current plans after disasters or emergencies to reveal possible emergency prevention opportunities. HR professionals, including those in the security industry, play an integral role in the survival of an organisation. They provide invaluable sustainability tools, can successfully protect employees and can ensure that business continuity occurs in a timely fashion.

Greg Byrne is the Managing Director of Multisec Consultancy Pty Ltd. He lectures part-time at the Western Sydney University for an undergraduate diploma in policing and is a sub-editor for and board member of the Australian Police Journal. His academic qualifications include Master of Management, Diploma of HR, Grad Cert in Leadership and a Diploma a Security Risk Management. Greg can be contacted via email greg@multisec.com.au

FAST. SILENT. STYLISH. Our award winning speedgates keep your building secure with style. Find out which speedgate is right for you.

1300 858 840 www.entrancecontrol.com.au SECURITY SOLUTIONS 019


REGULAR

RISK MANAGEMENT Risk Management After the Atrocity

By Dr Kevin J. Foster For this issue, I was asked to write about risk management as it would apply in the aftermath of a terrorist attack. It is an interesting subject because if risk management strategies had been effective then arguably, the atrocity would not have occurred. However, disturbing surprises and risk management failures do happen. I want to look at risk management from the point of view of both sides – those on the receiving end of a terrorist act, and those who form the organisation or group delivering politically motivated violence. Terrorist acts are usually a form of violent political protest against the established order. From the terrorist’s point of view, this violent action is a form of societal risk management, albeit an extreme type. For circumstances when conventional risk management by the establishment ceases to be effective, then resilience is required. This resilience may be in technical, organisational or societal dimensions. For example, some level of physical resilience to blasts might be achieved using standoff distances created with vehicle barriers; resilient structures such as blast walls; or perhaps special film on windows to minimise harm from fragments of glass which are imploding into a room full of people. Good crisis management, business continuity planning, simulation exercises to practise the response, and procedures to recover operations quickly, all help with resilience. Risk managers need to plan for surprising disasters by drafting crisis management frameworks that might be utilised by crisis

020 SECURITY SOLUTIONS

managers immediately after an atrocity. Planning for the aftermath of catastrophic events is a type of risk management but quite different to conventional notions. I refer to post-atrocity risk management as ‘Type 4’ Risk Management. The first three types include risk management aimed at achieving high reliability operations in a regulated environment (Type 1); risk management directed at maximising the payoff in a competitive business environment where accidents or errors are normal (Type 2); and risk management in a political environment directed at finding a compromise solution that is tolerable for the majority of stakeholders (Type 3). In a Type 4 situation, all stakeholders are equal in that all are exposed to extreme danger, and survival is the primary consideration. A crisis manager needs to determine the immediate response to the catastrophe. The risk manager needs to think about strategies to return the organisation back to a steady-state condition. This may involve transitioning through different states or types of risk management, determined mostly by the nature of the operational environment through time. The worst case for risk management is when the maximum environmental variety exists. This is referred to as a ‘turbulent field’ (Emery and Trist 1965). After an atrocity of catastrophic proportions, relatively insignificant events are seemingly amplified within the turbulent field and so the organisations and people within the disaster zone find it difficult to predict future safe states of this new environmental reality. Conventional risk

Risk managers need to plan for surprising disasters by drafting crisis management frameworks that might be utilised by crisis managers immediately after an atrocity.

management thinking and tactics may be difficult to implement. Where is safe? How can people in the disaster zone find a safe place? What will happen next and how can people in the disaster zone cope with the hazards? A turbulent field is an inherently unstable nonlinear environment. It is one the inhabitants might perceive as ephemeral (Thompson, Ellis and Wildavsky 1990) or chaotic (Christensen 1985). Survival is determined by the environment and not guaranteed by tactics, operations or strategies. Crises prevail. The number of choice opportunities are too numerous and too disorganised (Jarman 2001) to evaluate in a value free way. Any small movement in the wrong direction could be fatal. Therefore errors of judgment are not acceptable. Risk is everywhere but rejected and deflected. The environment is dualistic, being both the


TALL. FAST. STYLISH. Our award winning speedgates combine state-of-the-art optical technology with a high barrier height to protect your building.

EASYGATE SPT

• • • •

Barrier heights up to 1800mm Fast throughput (up to one person per second) Ideal for Disability Discrimination Act compliance Choose from a number of models, including the LX, SPT, SG, IM or LG • Custom pedestals with an array of attractive finishes EASYGATE LX

Find out which security gate is right for you.

1300 858 840

www.entrancecontrol.com.au

EASYGATE IM

FULL HEIGHT TURNSTILE

TRIPOD TURNSTILE

SWING GATE

SECURITY SOLUTIONS 021


REGULAR

COMMUNICATIONS RISK MANAGEMENT

controlled variable and the disturbance. Floods and fires are typical examples. Another is the sectarian terrorist on a murderous rampage of revolutionary change. Emergency services personnel train to work in a Type 4 environment. However, even their training may be inadequate for worst case scenarios, or those not previously considered in risk management planning. Contemporary terrorism itself exhibits some of the characteristics of a Type 4 Risk Management state. Not only do terrorists cause carnage but they themselves justify their acts because they believe they are in a dangerous and turbulent field of operations. Terrorist organisations may regard their operational environment as being in crisis, caused by the established order. An organisation in a Type 4 operational environment regards their crises as normal but unacceptable. This is a risk management system that focuses on urgently correcting current crises. The system attempts to manipulate its operating environment. However, it has no long-term goals other than to prevent other decision systems from disturbing their operational environment. The aim of the system is to restore the operating environment to its natural but delicate and unstable state. Internal ‘grouping’ seeking new values is the hallmark: in a word – ‘millenarianism’ (Schwarz and Thompson 1990). The inhabitants of this type of organisation display a critical ‘logicality’ based on fundamental cultural beliefs about the existence of crises caused by disturbances from conventional risk decision cultures. A Type 4 organisation does not trust the other types “to do the right thing” and will demonstrate their fundamental objections to unacceptable values and behaviour. This type of ultra-participative messianic organisation rejects and deflects risks which are seen as the causes of further crises and instability. The emphasis on this

022 SECURITY SOLUTIONS

system’s behaviour is not towards reliability but towards sustainability through fundamentalism. Rules and regulations are not as important as responding to the crisis (current or future) led by a new messianic leader. A Type 4 organisation, also called a ‘Murphy’s Law Organisation’ (MLO) has elements grouped in a shallow hierarchical structure, but a grided hierarchy as in Type 1 does not exist. There is a leader (perhaps charismatic); however there is no formalised hierarchy. This is typical of a Sect. The leadership is small but all-powerful. Risks will be rejected, deflected and punished severely if ‘anti-group’. The focus is on creating a new operational environment for the benefit of all – for example the creation of an ‘Islamic State’. While risks are anticipated, there is a greater concern about responding to a current crisis that is escalating into chaos. Neither trials nor errors are acceptable. The two primary dynamic risk management strategies aim to: 1. Create a new value system. 2. Share pain and scarce resources consistent with new leadership values. Positive feedback is important for maintaining ethical values, solidarity and the achievement of fundamentalist goals. System failure occurs due to an inability to generate greater power or strategic force (especially if no charismatic leader is present); redundancy is generally rejected and there is a reluctance to accept system resilience. The Type 4 organisation can only exist in the short term. If successful, these Type 4 organisations evolve to become the new Type 1 order. Established Type 1 organisations will do all they can to prevent the Type 4 organisation from becoming the new order. If both the established Type 1 and the new Type 4 organisations evolve to be competitors in a Type 2 environment, then full scale war might be the result.

References: Christensen, Karen S. 1985. Coping with Uncertainty in Planning. Australian Public Administration Journal. Winter, 63-73. Emery, F.E., and Trist, E.L. 1965. The Causal Texture of Organizational Environments. Human Relations. vol. 18, no. 1, 21-32. Foster, Kevin J. 2010. Unstable Risk Management Systems: The Evolution of an ‘Intelligent Building’ in Singapore. Saarbrucken: Lambert Academic Publishing. Jarman, Alan. 2001. ‘Reliability’ Reconsidered: A Critique of the Sagan-LaPorte Debate Concerning Vulnerable High-Technology Systems. Chisholm and Lerner Paper. Thompson, M., Ellis, R. and Wildavsky A. 1990. Cultural Theory. Boulder Colorado: Westview Press. Dr Kevin J. Foster is the managing director of Foster Risk Management Pty Ltd, an Australian company that provides independent research aimed at finding better ways to manage risk for security and public safety, and improving our understanding of emerging threats from ‘intelligent’ technologies.


MULTIPLE CAPABILITIES SUPERIOR SOLUTION

Volvo Group Governmental Sales Oceania

IN HOSTILE ENVIRONMENTS, IT’S IMPORTANT THE SYSTEMS THAT YOU DEPEND ON CAN

STAND THE TEST OF TIME.

At Volvo Group Governmental Sales Oceania, our core business is the manufacturing, delivery and the support of an unparalleled range of military and security vehicle platforms; a range of platforms that are backed by an experienced, reliable and global network with over one hundred years of experience

superior solutions, providing exceptional protected mobility SECURITY SOLUTIONS 023 www.governmentalsalesoceania.com


REGULAR

LEGAL

COMMUNICATIONS The Time To Build Relationships Is Before A Disaster By Rod Cowan A disproportionate interest in terrorism is resulting in the Government and policy makers failing in the fundamentals of national security, which must entail an all-hazards approach to security and risk mitigation. Having spent more than 14 years building relationships through the Trusted Information Sharing Network (TISN) and the Security in Government (SIG) annual conference, policy wonks scrapped the latter and allowed the former to become all but moribund. SIG, held each year, was routinely attended by over 500 delegates comprised of Government Agency Security Advisors and, increasingly, corporate security managers. An associated exhibition and sponsorship subsidised the event, which not only meant the conference was priced to suit security department budgets but also generated a profit of more than $70,000, which the Attorney-General’s department used to fund outreach projects. All this and at no real cost to the department, since organising the entire event was outsourced. Someone somewhere decided to scrap the event. No one understands why. The fact is, 90 percent of critical infrastructure in Australia is privately owned — and even more rely on private security for protection. To have an annual event that briefs, educates and informs is eminently desirable. To be able to do so at a profit seems eminently sensible. This lack of understanding of the relationships between all concerned with the protection of the nation has had a knock-on effect for the Trusted Information Sharing Network (TISN).

024 SECURITY SOLUTIONS

To be sure, the TISN has been successful in the area of the financial sector, which was allowed to run its own race and, indeed, funded a project officer to assist it. Other sectors, however, did not get to the same level of understanding and, thus, were unconvinced about funding further development. In the past four months, A-G’s has gone through at least three reshuffles and Mr Brandis’ position as Attorney-General is tenuous at best. And, no wonder, given the lack of leadership. The fact is the security profession has had no clear engagement since Mr Ruddock and, to an extent, Mr McClelland, both of whom would attend industry events and spend time with people at the sharp end of the stick. When I suggested to an AGD senior staffer that the current A-G would do well to follow suit, I was told: “Good luck with that, if you don’t have the CEOs there”. Mr Brandis did recently reach out to CEOs with an invite to a sit down with him on national security matters. The CEOs naturally checked with their security managers and advisors, most of whom, if not all, told them not to bother. Most declined, offering to send their senior security person. However Mr Brandis made it clear it was a “personal invitation” and there was no need to send anyone else; clearly talking to people knowledgeable about security was not the aim. Clearly, something needs to change and relying on the government simply will not do. The conversation, however, repeatedly returns to who should speak on behalf of the industry? Part of the problem is the nature of security.

A head of security for a major corporation, for example, could hardly speak out on security issues for fear of falling foul of their media/ communications/branding/marketing department (or communications prevention department, depending on your view). In other industries the role would fall to the likes of industry associations or institutes. The Australian Security Industry Association Limited (ASIAL) performs well in providing member services to primarily small to medium size security providers. ASIS — despite attempts at rebranding as an international organisation — remains resolutely US-centric in content, American in outlook, and swallows up fees without investing in local operations. The effectiveness of other institutes and associations wax and wane depending on individuals championing their cause. None could claim to be a political force. The solution would be a platform for meaningful dialogue with a view to communication and cooperation across a range of public and private organisations and issues. But the dialogue needs to take place between those who know about security and those with the power to do something about it in order to ensure that Australia is prepared to respond and recover from an incident, regardless of the cause. It is also a dialogue sadly silent today. Rod Cowan is Editor-at-Large for Security Solutions magazine and Director of SecurityisYourBusiness. com. He can be contacted on mail@rodcowan.net


When a high level of security is essential, dormakaba turnstiles and full-height gates provide the ideal solution. The robust turnstiles and full-height gates are especially suitable for securing the perimeter of buildings and property.

Secure your perimeters

Benefits include versatality in design, safe passage, minimal power consumption and lasting quality for any indoor or outdoor installation. For the complete range of smart and secure access solutions, contact dormakaba. 1800 675 411 www.dormakaba.com.au

SECURITY SOLUTIONS 025


REGULAR

THINKING ABOUT

SECURITY Post Incident By Don Williams So far, through good intelligence, police work, community liaison and luck, Australia has avoided a major security incident such as a massfatality attack. There have been some close calls on a number of occasions and there have been a number of incidents with a few fatalities. The vehicle attack in Melbourne in January, while not terrorist motivated, showed how a free and open society will always be vulnerable. Even that attack resulted in six fatalities (at the time of writing). The deliberate driving down of people in Melbourne also shows the limited memory of society, the media and individuals. This is neither the first nor the worst mass death event to happen in Melbourne within living memory: Hoddle St 1987 (seven dead and 19 injured), Queens St 1987 (nine dead and five injured) and the Russell St bombing 1986 (one dead and 21 injured). What is of interest is the modern outflowing of public grief and tributes. In Issue 30 (2002), I wrote an article titled As Close As It Gets about the Bali bombing, the thrust being that after the largest loss of Australian lives in a terrorist incident Australia, as a nation, reacted as if it had occurred on its shores. But, it had not happened here. There is little doubt that the Australian spirit of community support and generosity will surface and the help provided to the victims and affected region will be, as always, effusive and openhearted regardless of who was injured and by whom. What is also certain is that once the dust settles there will be a surge of ‘blamestorming’ and accusations, with lawyers looking for class

026 SECURITY SOLUTIONS

action targets. This second element will bring out the worst of society, as people and organisations seek to find someone to blame and to pay – whether the accusations are reasonable or not. A mass-casualty attack could come from ethno-nationalists, eco-terrorists, right or left wing extremists, or religious fanatics of any creed. It is understood that, at times, some groups are more visible and vocal in their calls for violence than others, but the rest are still there and bubbling away with their grievances and plans. How governments and responsible agencies respond will also shape how the general public react and recover. If the government accepts that the incident has occurred despite the combined efforts of the public and private sector and demonstrates effective and responsible leadership, then there will be a central pillar for Australia’s resilience. If, on the other hand, there is ducking and weaving, shifting of responsibilities, finger pointing and opportunistic political point scoring, the public will be left largely unled and divided. Security professionals will have a specific role to play, as detailed in this column a few issues ago. They will be called upon to explain to managers, staff and clients what happened and why and how it can be prevented from happening in Australia. The executive will be tempted to throw large amounts of money to protect the business. While taking advantage of this long overdue windfall, security managers should provide doses of common sense and balance to ensure the resources are spent wisely. They will

A mass-casualty attack could come from ethnonationalists, eco-terrorists, right or left wing extremists, or religious fanatics of any creed. also be called upon to counter the claims and statements of the ‘experts’ who will suddenly appear like locusts all over the media. When Australia does have a significant masscasualty event, and it will happen, a large part of the responsibility for providing a balanced, nuanced and realistic response will fall to the security profession. The article As Close As It Gets is available from Security Solutions and from www.dswconsulting. com.au/publications Don Williams CPP RSecP ASecM can be contacted via email: donwilliams@dswconsulting.com.au


SECURITY SOLUTIONS 027


REGULAR

EVENTS Safeguarding Australia 2017: Turning Points in Security 3–4 May 2017 QT Canberra, Canberra Competing priorities, growing threats and increasing complexity will continue to present fundamental challenges to Australia’s national security agenda in the coming years. Public and private security professionals – policy makers, practitioners and providers – will be forced to address a wide range of issues which have developed over recent decades and continue to grow, such as violent extremism, cyber threats (from lone and state actors), border control and legislation. In coming years, they will need to also contend with the security issues inherent in societal issues, adding known-unknown dimensions to an already complex national security agenda, most notably an ageing population, technology creeping into all facets of life and diversity in the workplace reflecting an increasingly cosmopolitan society. Safeguarding Australia 2017 will help face those challenges and shape the security agenda, by taking on its most demanding theme to date: Security at a Turning Point – Innovation, Leadership and Diversity. For over 14 years, the Research Network for a Secure Australia (RNSA), a not-for-profit network of security policy makers, professionals and academics, has gathered at the Safeguarding Australia annual national security summit to hear from high-level speakers representing both government and corporate viewpoints, exchange ideas, debate issues, and learn about techniques, cases studies and ground-breaking research, to meet the security challenges of today and the solutions for tomorrow. In addition to briefings on current policies, trends and activities, Safeguarding Australia

028 SECURITY SOLUTIONS

IFSEC International 20–22 June 2017 ExCeL London The global stage for security innovation and expertise 2017 will go further by drawing on local and international experts to examine three overarching themes affecting the way security and risk is managed to protect the nation, namely: 1. Innovation – exploring knowledge around technology, standards and research. 2. Leadership – focusing on the next generation, the greying population and education. 3. Diversity – in particular, the role of communications as a security tool addressing disparate ethnicities, genders and culture. In addition to a pre-conference workshop currently being designed, Safeguarding Australia 2017 will begin by outlining current challenges and activities and lead into defining future directions and solutions. Safeguarding Australia is the only high-level conference run by and for leading thinkers, policymakers and practitioners in the national security domain, working across wholeof-government at state and federal levels, including law enforcement and intelligence agencies, as well as engaging with corporate and private security practitioners and providers. Past attendees and current bookings include: • senior representatives from security, intelligence, military and law enforcement • risk and security managers and consultants • agency security advisors • critical infrastructure owners and operators • engineers, scientists, technologists, researchers and academics • corporate and business executives responsible for security and risk. Visit safeguardingaustraliasummit.org.au for more information.

IFSEC International is the biggest security exhibition in Europe taking place over three days between 20 to 22 June 2017 at London ExCeL. IFSEC welcomes over 27,000 global security professionals to experience the latest technological innovations and hear from industry leaders – all under one roof, over three days. The event caters to everyone within the security buying chain from manufacturers, distributors, installers, integrators and consultants to end users. With over 600 exhibitors showcasing over 10,000 products, you will be able to find the perfect security solution your business is looking for. There’s more to it than just security. IFSEC International is co-located with FIREX International, Facilities Show, Safety & Health Expo and Service Management Expo, catered for those working across many platforms in building management and protection of people and information. For more information or to register please visit www.ifsec.co.uk

Security Exhibition & Conference 2017 26–28 July 2017 International Convention Centre, Sydney In 2017 the Security Exhibition & Conference is heading back to Sydney to the brand new International Convention Centre. This stateof-the-art precinct over looks beautiful Darling Harbour and is a short walk away from Sydney’s vibrant city centre.


THE ALL-NEWTXF-125E BATTERY OPERATED QUAD BEAM Introducing the eagerly anticipated TXF-125E; a high performance Quad Beam sensor designed for battery operation - perfectly suited for rapid deployment in creating temporary or permanent secure perimeter intruder systems. With 4 selectable frequencies, multiple beam sets can be used without crosstalk, whilst adjustable detection distance allows a single beam set to be re-deployed in a variety of installations throughout its operational life. Two 3.6V (17Ah) batteries power each unit for up to 5 years of service.

NEW!

ACTIVE IR BEAMS The ultimate in trouble free perimeter detection for distances up to 200m outdoor / 400m indoor.

+61 (3) 9544 2477

email: oz_sales@takex.com

HIGH-MOUNT PIR Triple mirror optics for maximum detection performance at 2 to 6m.

BEAM TOWERS Rugged floor and wall mounted enclosures in 1/1.5/2/3m heights.

INDOOR PIR Spot, 360°, wide angle, and curtain detection from 2 to 4.9m height.

OUTDOOR PIR Hard-wired or battery operated outdoor PIR up to 180° x 12m .

1300 319 499 csd.com.au www.takex.com

TAKEX AMERICA SECURITY SOLUTIONS 029

VIC: Mulgrave, Tullamarine NSW: Northmead, Waterloo ACT: Fyshwick QLD: Loganholme SA: Marleston WA: Balcatta


REGULAR

EVENTS The new venue features a total of 35,000sqm of exhibition space presented in a smart, stacked layout to capitalise on the inner-city location and provide much improved loading facilities. Plus the halls feature customised registration and ticketing areas and dedicated meeting rooms. ICC Sydney will be Asia Pacific’s premier integrated convention, exhibition and entertainment precinct, underpinning Sydney’s position as one of the world’s most desirable meeting and event destinations. The entire team is looking forward to reuniting the industry once again in sunny Sydney where Security 2017 will connect more than 4,500 security professionals with over 150 leading suppliers. For over three decades the event has provided a showcase for new and innovative security technologies and solutions. Whether you are looking for a solution to protect your property, people or assets, the Security Exhibition & Conference provides the opportunity to discover the solution that is right for your organisation. Make sure you put July 26–28 in your diary; and we look forward to seeing you again in Sydney for the Security Exhibition & ASIAL Conference! To register now visit securityexpo.com.au

ASIS International Australia Conference Contemporary Security Leadership In Australia 19 October 2017 Melbourne The ASIS International Australia Conference 2017 is the premier gathering of security professionals. The conference provides an established platform for education and business exchange, addressing the key trends and issues facing security professionals locally and globally. Key topics: • Terrorism • Cyber-Security • Behavioural techniques • Security Management • Emergency Management. The conference is a great opportunity to: • engage with peers and colleagues from the public and private sectors • join industry leaders accelerating the future of the security profession. Who should attend the event: • Security professionals across the public and private sectors • Security Risk Management professionals • Security service providers • Security consultants • Government and law enforcement professionals. For more information contact events@asisvictoria.org.au or visit www.asisvictoria.org.au

030 SECURITY SOLUTIONS

The 2017 Australian OSPAs 19 October 2017 The River Room Crown Casino, Melbourne The Outstanding Security Performance Awards (OSPAs) are pleased to announce the date for the 2017 Australian awards. They will be working for the third year in a row with the prestigious, Australian Security Industry Association Limited (ASIAL). The Outstanding Security Performance Awards (OSPAs) recognise and reward companies and individuals across the security sector. The OSPAs are designed to be both independent and inclusive, providing an opportunity for outstanding performers, whether buyers or suppliers, to be recognised and their success to be celebrated. The criteria for these awards are based on extensive research on key factors that contribute to and characterise outstanding performance. Aspiring to Excellence, a Security Research Initiative report conducted by Perpetuity Research. The OSPAs are being setup in collaboration with security associations and groups across many countries. By researching and standardising the award categories and criteria, the OSPAs scheme provides an opportunity for countries to run their own evidence-based OSPAs schemes while maintaining an ability to compete on an international level in the future, ‘World OSPAs’. For more information or to make a nomination, simply visit au.theospas.com


Recognize and Analyze How often was he here this month?

Is he a known suspect?

How old is she?

Are they employees?

When, where did she enter?

Is this valued customer Mia Clark?

How many people are here? Is it too crowded in this area? New: Recorded media import and advanced investigation tools upload sets of videos recorded at a specific location and time to track possible participants in a crime find a person enrolled in an image database or search for an unknown person locate appearances in multiple videos make use of filters that specify timeframe, camera location, age range, gender and glasses

See it in action at Security Expo in Sydney, stand K26!


032


Health Preparedness and Australian Counterterrorism Strategy

033


By Anthony Bergin Killings carried out by terrorists are becoming worse and more gruesome to achieve the shock factor. While there is no suggestion of any new specific terrorist threat to Australia, the Australian Government is looking again at security for public events following last year’s Bastille Day attack to make sure that all necessary arrangements are in place. The Nice attack, where Mohamed Lahouaiej Bouhlel ploughed a truck through crowds of Bastille Day revellers on the Promenade des Anglais and killed at least 84 people and seriously injured more than 200, could easily happen here. There have been three terrorist attacks in Australia in the past 14 months, with nine disrupted plots foiled. Australia’s security agencies are investigating about 400 terrorism cases. The planned Christmas Day attack allegedly included multiple-venue and masscasualty attacks in public places in Melbourne’s CBD, including improvised explosive devices. Arrests made in Sydney and Melbourne last year included charges of conspiring to obtain illegal firearms and manufacture explosive devices. Terrorists in Australia intend to inflict mass-casualty fatal attacks. Violent extremists will draw inspiration from the Nice atrocity. No doubt, Australia’s homegrown Gen Y jihadists will look to emulate the Nice attack modus operandi. By the depraved standards of terrorism, the Nice attack was a great success. It made a huge impression right across the jihadist world: one does not need to use a plane as a weapon like 9/11; simply grabbing a lorry and ploughing into a crowd can mount an effective attack. On the protective security side at mass gatherings here, close attention will need to be paid to the feasibility of putting up barriers to keep out vehicles, especially trucks. (But even here there will be a requirement to allow in cleaners, rubbish collection, media and other vehicles.) However, it will be impossible to secure some open sites – think of events such as a marathon or an Anzac Day march. One of the lessons for Australia from the Nice attack is it must think about how to protect areas beyond capital cities. Just as the terror attack occurred in the south of France, Australia needs to consider security arrangements for regional centres. Local councils will need

034

to review security arrangements for public gatherings, particularly their plans with first aid responders, like the St John Ambulance. However, events should not be cancelled – that way, the jihadists win. But no matter how many bollards are erected, protection of soft targets against the sort of unsophisticated attack seen in Nice will not be possible. These attacks can only be stopped if there is intelligence prior to a potential attack. What needs to be done here is to focus more on the consequence management side. How would services practically cope with huge numbers of fatalities? In the Black Saturday bushfires, given the number of people who died in the fires, there was a need to rapidly assemble temporary refrigerated rooms as morgues. How would services cope with hundreds of seriously injured people, particularly in a regional centre? Across Australia, there is a lack of available air assets and retrieval teams that would be able to provide support and respond to masscasualty events. There are only two, sometimes three, medical helicopters covering greater Sydney. The nearest others are in Orange, Newcastle and Wollongong, any of which may be more than an hour’s flying time from Sydney if on a task. With minimal investment and a contractual agreement with Qantas and Virgin, up to four aircraft from their commercial fleets on the east and west coasts could be configured with the requisite kit for medivac use as required, as part of the commercial fleet on the east and west coasts. Suitable military transport aircraft might be available, but the Royal Australian Air Force (RAAF) must balance this role with military operations, training and maintenance. In any event, defence assets rely on doctors and nurses who often have to balance their civilian life with their part-time military service as specialist reservists. There is a lot that could be done to prevent the adverse health consequences that will flow from disasters, but Australia is not doing enough to prepare for a mass-casualty attack. Disaster response requires a wholeof-service response: hot zone and tactical emergency medical response, pre-hospital care, retrieval, emergency department and intensive care theatre. All elements should

One of the lessons for Australia from the Nice attack is it must think about how to protect areas beyond capital cities. Just as the terror attack occurred in the south of France, Australia needs to consider security arrangements for regional centres.


be drilled simultaneously and with simulated failings at each stage to prepare for the reality of a terrorist disaster. There has been no real action to address the findings several years ago of a major study in the Medical Journal of Australia of the surge capacity for people in emergencies in Australia’s hospitals. It predicted that hospitals would be quickly overwhelmed and that 60 to 80 percent of seriously injured patients would not have immediate access to operating theatres, and that there would be a similar lack of access to intensive care unit (ICU) beds for the critically injured and to X-ray facilities for the less critically injured patients. It would be useful for those responsible for counterterrorism to engage those in the health system who understand what is required to manage a mass-casualty event. The Improvised Explosive Device Guidelines For Places Of Mass Gathering guidelines were issued last year by the Australia-New Zealand Counter-Terrorism Committee. The guidelines rightly note: “Terrorist or insurgent attacks using explosives occur regularly around the world. Terrorists favour explosives because of their proven ability to inflict mass casualties, cause fear and disruption in the community and attract media interest. Explosives are also generally within the financial and technical capabilities of terrorists and IEDs can be assembled with relative ease and used remotely.” The guidelines provide general guidance to those operating places of mass gathering – such as shopping centres, sporting arenas, theatres and railway stations – in terms of emergency service requirements and security principles. The document provides useful guidance on detecting suspicious activity. But one of the weaknesses of the guidelines is its treatment of healthcare issues. There is no mention of post-blast planning and response, including the fact that the site of such an attack would be a crime scene, especially if injuries have occurred. In a post-blast incident, there would also be implications for immediate first aid and rescue before emergency medical services arrive. The guidelines refer to ‘injuries’ and ‘people hurt’, but not that multiple fatalities and a correspondingly larger number of casualties

Disaster response requires a wholeof-service response: hot zone and tactical emergency medical response, pre-hospital care, retrieval, emergency department and intensive care theatre.

in a terrorist bombing in one of Australia’s major cities are likely. There is no discussion in the document of longer term health issues; not all casualties will be immediately apparent and there will be a need to record those who felt the blast effects for medical observation and monitoring. There is no discussion in the guidelines either of on-the-scene triage or on how venue managers might work with emergency medical services to transfer the injured to definitive care. The truth is that Australia is unprepared to respond to a major disaster. Surge capacity – the ability of the medical system to care for a massive influx of patients – remains one of the most serious challenges for national emergency preparedness. No major metropolitan hospital in NSW, Victoria, Western Australia, Tasmania or Queensland met state emergency department benchmarks in the first six months of last year. In developing the health response to a disaster, there are some fundamental constraints: • Most ambulance and hospital services are overstretched on a daily basis. Pre-hospital and paramedic capacity, along with medical and nursing shortages, limit surge capacity for a large influx of critically injured patients. • Few of Australia’s hospital staff and paramedics have been involved in no-notice, large-scale disaster exercises, using the equipment with which they are supposed to be competent.

• Finding adequate numbers of ambulances will be a problem for most states in the event of a disaster. There are no formal protocols between the states for the deployment of paramedics and ambulances. Clearly, there is a problem. The first step in working out a response is to identify the shortfalls and set some performance goals. An audit of the national healthcare preparedness for large-scale disasters is needed on a regular basis, then the healthcare system would know what it is reasonably expected to be able to cope with and could plan appropriately, including the funding required. While it would not be that hard, it would require some goodwill and cooperation between the health departments of the Commonwealth and state governments and the involvement of local councils. It would be much better to deal with this proactively rather than in an after ‘lessons learned’ report.

Anthony Bergin is senior research fellow at Australian National University’s National Security College and senior analyst, Australian Strategic Policy Institute (ASPI). He is the author of Are we ready? Healthcare preparedness for catastrophic terrorism, published by ASPI.

SECURITY SOLUTIONS 035


ALARMS

036 SECURITY SOLUTIONS


By Steve Lawson

To state the obvious: by far the best response to an atrocity is to make sure that a proper defence is in place before the atrocity. After a security incident has happened, there is pressure to ‘do something’, especially from the media and government. The media tend to look at the spectacular and government looks at the politics. Security professionals should be prepared to weather pressure from both of those quarters. A common reaction to a security incident is to install new or additional security equipment. However, equipment is not cheap, it is not usually sitting on the shelf waiting for deployment and the equipment that is available will be snapped up quickly. It can, for example, take six months for X-ray equipment to be manufactured and deployed. There can be an issue with fitting large security equipment into existing infrastructure and the consequent impact on operations. So, the best thing to do before deploying equipment is some research. Which leads to: What can you expect from an equipment supplier? The first and probably most important thing is the supplier should be a source of advice. Giving advice sounds trite, but advice given freely and honestly is vital in responding to any tragedy. There have been many examples, especially after major incidents, where equipment was rushed into service that was not fit for the purpose, was improperly deployed or was operated by untrained or inadequately trained staff. People assume that terrorists are stupid; they are not. They research, conduct reconnaissance and attack where a target is most vulnerable. Poorly deployed equipment may not be a strength, but a vulnerability. What would be the first piece of advice security professionals should expect? They need to think very clearly about what they are trying to defend against. There is not

much use deploying equipment that can detect explosives when knives are being looked for. I have always relied on suppliers that provide me with honest advice and there have been times when it has saved millions of dollars. As an example, I was in Los Angles and there was a call to screen all freight from the airport. We were doing that using explosive trace detection (ETD), but were asked to look at our ability to screen freight for other operations. It was such an attractive proposition that would mean making a large amount of money. The first issue was how. I knew that there was an L-3 truck-mounted X-ray in Boston that was available and we spoke with them about redeploying it to Los Angeles. There were a number of meetings with L-3 and, in the end, on the honest and balanced advice provided, we decided it was not fit for purpose. To be blunt, conventional X-rays, especially ones that are designed to X-ray built-up freight, are problematic finding explosives. As stated earlier, there can be an urge to ‘just do something’ and throw equipment at a problem. That can be a mistake – the immediate and then long-term response needs to be considered. So, divide the response into three phases: • short-term • medium-term • long-term. The short-term response may include redeploying the existing equipment or even changing the way things are done. Invariably, it is to look at the resources, see where they are effective and whether they can be deployed or managed better. Believe it or not, an effective change may just mean changing the ‘look’ of the space to make it seem more focused. I recall a meeting about our first introduction of real air cargo security at Qantas Freight and that we wanted people

SECURITY SOLUTIONS 037


ALARMS

to ‘feel’ like they had been screened, so we changed security’s uniform from a nice corporate one to something that looked more like police. Nothing else had changed, but that simple change made people comment that security had increased and the security staff now felt that their primary function was about security and not customer service. We wanted to screen air cargo, but we did not know what the government was going to certify as suitable equipment nor what legislation they would introduce. Nor did we have much space to deploy equipment and we wanted to introduce measures quickly. We did know that we wanted to find explosives in air cargo – or rather, that there were no explosives in air cargo! So, our short/medium response was to deploy ETD. Not because it was intended as our long-term solution, but rather it was one of only two screening methods certified by the US to find explosives. The other was computed tomography (CT) X-ray, which in those days had a huge footprint, was inordinately expensive and took well over six months to deploy. Once ETD and some other changes were in place, I then went around the world to look at a longer term solution and looked at some quite amazing pieces of equipment. Deciding on a longer term solution relies on advice, but some suppliers still try the hard sell, so security professionals need to equip themselves with base criteria – the ‘what am I trying to achieve’ statement. For air cargo it was simple – I wanted to find explosives or incendiary devices. My issue was that everyone told me how easy it was for their equipment to find explosives, but they were looking for trucksized improvised explosive devices (IEDs) and I wanted to find IEDs the size of a coke can. I came to the conclusion that I needed a simple statement to measure equipment and quickly came up with this: “If it is stupid for passengers or their checked baggage, it is stupid for air cargo on the same aircraft.” Later, I made that into a more succinct and palatable policy, but that was my base rule and applying it cut out the more extreme ends of the spectrum.

038 SECURITY SOLUTIONS

If an emergency happens, consider what can be done with the current equipment, how it can be best deployed and if there are upgrades that can quickly be applied. Have things changed in the supplier space in the last 15 or so years? Absolutely. Not so much with the advice (the people who have been there for a long time are still dedicated, honest and professional), but definitely in pricing and computing power. For example, it is probable that the screening of people will change dramatically in the next few years. Conventional X-ray machines will give way more to CT machines, which have changed in price, footprint and speed. As they get faster, body scanners will displace walkthrough metal detectors and the networking of systems will introduce new capabilities. Systems will be networked so that both the CCTV systems and the airline’s passenger record can profile a person. So how does this help with security professionals once the security incident has happened? Recall the first line in this article: by far the best response to an atrocity is to make sure that a proper defence is in place before the atrocity. That also means that the current equipment list should be continually reviewed, equipment maintained properly and people appropriately trained in its use. Consider the likely life of the equipment. It is not much use buying something that will be in place for 10 years if it cannot be upgraded. If an emergency happens, consider what can be done with the current equipment, how it can be best deployed and if there

are upgrades that can quickly be applied. Keep abreast of current developments in security equipment. Talk to suppliers (not just current suppliers), maintain a network of suppliers and keep on good terms with all of them. Always make sure there are short-term, medium-term and long-term plans in place. Create a checklist for various scenarios – a really good checklist should answer the question: If xyz happens now, what can I do? Short – medium – long-term.

Steve Lawson has over 20 years’ experience in aviation security. As a Security Executive with Qantas Airways, Steve held a number of senior management roles covering all aspects of aviation security from policy development to airport operations. He was sent to New York immediately following the 9/11 attacks to manage the Qantas response and undertook a similar role following the 2002 Bali Bombings. On his return to Australia, he was appointed Security Manager Freight for the Qantas Group. Since 2007 he has been a Director of AvSec Consulting in partnership with Bill Dent, a fellow former Qantas Security Exec. Today Avsec Consulting provides consultants from the US, NZ, ME, Israel and Europe. Steve can be contacted on 0404685103 or slawson@avsecconsulting.com.


www.facebook.com/luminox

www.luminox.com

VIC 8th Avenue Watch Co., Emporium Melbourne, 03 9639 6175 | 8th Avenue Watch Co., Westfield Doncaster S/C, 03 9840 6304 8th Avenue Watch Co., Chadstone S/C, 9569 7652 | Temelli Jewellery, Highpoint S/C, 03 9317 3230 | Temelli Jewellery, Southland S/C, 03 9583 2633 | Temelli Jewellery, Westfield Knox City S/C, 03 9800 0799 NSW Lewis Watchmakers & Jewellers, Coffs Harbour, 02 6651 1612 | Melewah Jewellery, Haymarket, 02 9211 5896 | Vintage Watch Co., Sydney, 02 9221 3373 | Hennings Jewellers, Narellan, 02 4647 8555 WA The Watch Spot, Perth, 08 9421 1093 | Leon Baker Jewellers, Geraldton, 08 9921 5451 QLD 8th Avenue Watch Co., Pacific Fair S/C, 07 5575 4883 | Hatton Garden Jewellers, Beenleigh, 07 3287 1230 | Watch Tech, Brisbane, 07 3012 7023

SECURITY SOLUTIONS 039


040


Scenario Design Building Blocks Of Operational Success

041


By Richard Kay An instructor’s obligation is to prepare officers for that aspect of their job that has the potential to put them at risk. Preparing officers to survive confrontational situations has several factors: physical skills to control situations and ensure safety, knowledge to make decisions within lawful parameters and emotional resilience for post-incident management, expressed as safety, survivability and consequence. To prepare officers any less is to fail to prepare them at all. A critical aspect of fulfilling this obligation lies with assessing competence in all aspects required for effective operational duty. Effective reality-based training involves experiential training, where participants use core skills and knowledge to solve realistic workplace situations and learn from both success and failure; scenarios and participant behaviours are carefully planned and implemented to achieve these results. Experimental training does not have programmed outcomes, but uses a waitand-see approach, hoping that there will be interesting training points for discussion at the conclusion of the scenario. Scenario Design The scenario design process begins with research into problem areas that would benefit from reality-based training. Include as many sources of reference as possible at this stage to form a scenario development committee – instructors, subject-matter experts, legal advisory and command staff. The first question to ask is, “What recurring operational problems are happening? ” It might be that there have been incidents where officers and subjects were hurt due to physical confrontations. Studies may indicate that injuries for officers and subjects are reduced in instances where a chemical agent is used prior to physical skills, and a review of the tactical response model confirms that chemical agent is used before physical skills, with a sampling of officers illustrating this understanding. Next, develop low-level scenarios where correct participant responses to role player actions are simple 1-1 drills that teach specific responses to specific threats (experience fragments). After specific threat responses are practised, they are tested in context using highlevel scenarios. Scenario design begins with establishing

042

performance objectives, that starts by asking, “At the conclusion of this scenario, what will participants have demonstrated? ” It provides a concrete set of behaviours and skills to be tested and includes: • Conditions: describe the circumstances under which the behaviour is performed, such as scenarios using a live role player, or scenarios on a video simulator. • Behaviour: describes observable participant behaviours and indicates the behaviours that instructors will be looking for and the type of response expected. • Criteria: specify how well the student must perform the behaviour and set the policy standard by which performance is judged. An example of a completed performance objective might be: In a scenario using a live role player, the participant will demonstrate approved communication skills, deployment of chemical agent, and physical skills against a verbally resistive subject who becomes physically resistive after being sprayed, in order to gain physical control of the subject in a manner consistent with the approved tactical response model. To meet the performance objective, participants must demonstrate performance activities, the ‘must dos’ required to successfully complete the exercise. Any activity sufficiently important to be listed as an official performance activity must be completed, either during the first attempt at the scenario or during remediation that follows the debriefing. Subject-matter experts define the optimal participant responses. During the scenario, the participant is required to demonstrate those responses in accordance with the approved response model, and also to justify such actions during a debriefing. Complexity is the bane of reality-based training and is caused by two main factors: • Over-complicated scenarios have no defined end point. They are caused by lack of proper planning, preparation and execution, and are attributed to having too broad a performance objective or too many performance activities. The core of well-structured scenarios is simplicity, which requires thought, time, effort and revision. • Over-simplification of role player guidelines ensures that there is too much improvisation and role players will likely change the scenario every time they get bored. Properly structured

scenarios avoid the hazards associated with the unknown. Writing scenarios is an inclusive process. After the committee has accepted the array of officer responses, approval is obtained from legal and command staff to confirm that the responses comply with policies and procedures. Once approved, the committee can flesh out the rest of the scenario and develop a set of role player behaviours that predictably trigger the correct responses from participants. Completion of this process creates the scenario framework. A story line, ideally taken from actual events to make it valid, creates context for the proposed action and makes it experiential. This process puts the scenario design into a useable format. It is time consuming but, once completed, the scenario can be used repeatedly and the agency will benefit from training commonality. Scenario Development The scenario overview provides a template to develop a scenario and includes: • The performance objective is the scenario mission statement (a clear statement of what participants demonstrate) and gives a clear indication to when the scenario is complete. Scenarios continuing past completion of the performance objective not only waste training time, but are often when injuries occur. • The synopsis is a brief narrative description of what the scenario is about and what is supposed to happen. • The site description provides a statement on the requirement, type, quality, size, layout and so on of the training venue. The site should be chosen to best approximate the most realistic setting for the situation that will be depicted by the scenario so that the highest level of statedependent learning will be facilitated. • Notes are used for any additional notes that might be necessary in order to set up the scene. The scenario outline is a simple sketch of the scenario general idea. The scenario is written backwards from a natural conclusion to a logical beginning, which forces a progression of the scenario scripting actions and dialogue that move the scenario toward the desired conclusion. The scenario outline interacts directly with the role player guidelines, which helps organise specific


role player actions in response to possible participant actions. Prior to running scenarios, a test phase is recommended, which helps discover possible unanticipated participant responses. The test phase can debug many possibilities never anticipated when the scenario was written. Of course, there will always be situations where certain participants cause resistance to avoid facing what is waiting for them in the scenario. This is more a trust than a tactical issue, due to the belief the scenario is designed to make them lose or look foolish. The scenario evaluation is used to evaluate, debrief and remediate participants. It is critical to any reality-based training program to document participant performance, so instructors must complete this for every participant going through a scenario. During the scenario presentation, the evaluation should be with the instructor, who records performance activities as they occur, since these are the specific actions necessary to fulfil the performance objective. The evaluation components include: • The identification block gives the name of agency, participants and instructors, and the time and date of training; it begins the recording process necessary to support the training activity. • The equipment check ensures a safe training environment; safety officers ensure participants have all necessary equipment for the scenario, instructors confirm the equipment is present, in place, and participants are marked with safety indicators prior to scenario commencement. Conducting a scenario without the proper protective equipment is negligent. • The final preparation occurs prior to commencing a scenario; a briefing addresses any final safety concerns, answers questions participants might have and confirms with the training site that instructors are ready to receive participants and they know the scenario is going live. • The situation explanation sets the scene for the participants; it tells them what they already know, describes events that preceded their arrival in reality and gives them a logical start point. Without this, they might do things which might be correct in a real situation, but wastes time while they get to the point where the scenario actually begins. Communication with participants while

Paying attention to detail is the first step in developing training that makes a difference to officers specifically, agencies in general, and the community as a whole. in character should be done through the radio to force them to manage that equipment, except during an administrative pause or while in direct contact with other officers. If the participant is not being dispatched, verbally explain the situation to set up the scene. • Performance activities are clearly observable, objective actions; avoid using indistinct statements when writing a scenario by asking someone with an understanding of tactical responses if he can pick up the scenario evaluation and check off specific actions as observed. If he reasonably asks, ‘what specifically does that mean?’ about a performance activity, then it is too subjective or vague. Each performance activity is recorded as complete or incomplete by scenario end. Elective points are techniques helpful in solving scenario problems or make operational sense; they are not mandatory for participants to demonstrate that behaviour, but should be recorded on the evaluation to show superior procedure. • The signature authorises scenario completion as proof to document training; participants and instructors sign the evaluation, which is placed inside a participant’s training file. During the debrief, instructors use the evaluation to review scenario performance. The participant takes the instructor through the scenario as if describing events to an investigation team. When an incomplete performance activity is reached, ask the participant if he knows what he was supposed to have done. He may remember he neglected to do something, he may believe he did it when he did not, and he will not know what was missed because he was never taught a certain procedure. Either way, the participant must demonstrate incomplete performance activities during the remediation upon completion of the debriefing. If the participant does not know

what is required to solve the problem, he should receive supplementary training outside the scenario environment prior to repeating it. If failure resulted from forgetting or neglecting, and it is demonstrated during remediation, indicate that the participant performed correctly during remediation and completed all performance activities. A 100 percent compliance evaluation system is preferable to a score-based system, as it demonstrates complete participant compliance with policy and law. Legal authorities cannot review compliance evaluation and state that a participant was only performing at 80 percent capacity. If the evaluation system is compliance-based, participants with the necessary knowledge and skill to complete the performance objective pass; if they do not, they require additional training, after which they are re-tested. Using this system helps instructors determine participant deficiency so that substandard performance is corrected before it becomes a real-world issue. Reality-based training is complicated. Purchasing equipment and sketching out scenarios is how most agencies begin and why poor training occurs. Paying attention to detail is the first step in developing training that makes a difference to officers specifically, agencies in general, and the community as a whole. Build in safeguards that ensure effective training, with the focus always on operational safety. It takes time to get a comprehensive realitybased training program going. Instructors should secure time on a regular basis for scenario development. Set a goal to write three good scenarios each year. Research what three main problem areas are and write scenarios around them. Three good scenarios should take about three weeks to write, debug and get approved. Three scenarios per year equals 15 in five years. It might not seem like much, but the cumulative effects of small movements forward can be astounding.

Richard Kay is an internationally certified tactical instructor-trainer, Director and Senior Trainer of Modern Combatives, a provider of operational safety training for the public safety sector. For more information, please visit www.moderncombatives.com.au

SECURITY SOLUTIONS 043


CCTV

044 SECURITY SOLUTIONS


The Role of CCTV In Resolving Major Incidents

SECURITY SOLUTIONS 045


CCTV

By Vlado Damjanovski

I was asked to write an article on the CCTV aspects of a hypothetical incident and “what will/could/should/may happen after a security-related atrocity or major incident occurs”. A worrying thought indeed. A major incident could be, for example, a bomb in a public place which could affect almost everybody in this city. There are such public places in all major cities around Australia. So, to give a hypothetical scenario, assume a bomb has been planted at a major public venue in the biggest city in Australia and is detonated, killing innocent civilians and causing widespread disruption to the daily busy lives of thousands of people commuting in and out of the city. What will be the first thing to happen? It is not very difficult to guess. Firstly, there will be traffic chaos. Roads, particularly in Sydney, are not designed to cope with something as unpredictable as that. As police sirens ring out across the city and ambulances and rescue vehicles rush to the crime scene, traffic would come to a standstill. Secondly, and most important in determining who is responsible for such a heinous crime, would be the gathering of all the CCTV footage from the cameras positioned across the crime scene, if there are any. If there are no cameras covering the area, there would be a barrage of awkward questions aimed at the owner of that particular (public) space where the detonation occurred. Security personnel know that the decision of what needs to be covered with a surveillance system in public spaces is predominantly based on a consultant’s advice, which is usually based on a security manager’s experience with past incidents and ‘hot-spots’ that he or she is aware of. Clearly, it is possible that some proximities are not covered if there has been no history of a previous incident. As is common knowledge, cutting short on the number of cameras is usually the first step in ensuring that a CCTV system falls within the allocated budget. However, chances are that all public spaces, in Sydney at least, are covered by

046 SECURITY SOLUTIONS

a camera from one point or another. So, the issue is not whether an infrastructure is covered by CCTV, but how good the coverage of these cameras may be. A few questions need to be addressed. Is the video clarity sufficient for the police to be able to draw any conclusions of who planted the bomb? Is the video in such a format that the police can replay the footage on their system in the first place? Will the low-cost, low-quality Chinese camera imports suffice, given that not many people know about them (except the installer that was sold such a system); and can their exported footage even be played back? These are important questions, but with many variables, and obtaining a correct answer may not always be easy. Firstly, the camera resolution plays a big role, followed by the lens quality, the angle of coverage (focal length of the lens), the image quality (both in frames per second and compression), the camera low-light capability (typically most critical incidents occur in low light), and so forth. Similarly, the recording quality and recording duration are also important parameters. Luckily, most recorders these days offer at least a week or two of recording, if not more. When a major incident happens, chances are the police will only want the last 24 hours of footage. Therefore, the length of a recording of such a major incident would not be an issue (unless the recording is discovered three weeks later). Instead, it will be the quality of recording that is important, taking into account the parameters mentioned above. Today, most of the installed CCTV cameras are set to cover an area with as wide a view as possible with little regard to the quality of the recorded details. Quality in this instance does not necessarily mean sharp and focused images, with ‘good’ compression. It refers to the quality of the viewed scene where object details have predefined recorded pixel density, at the area of an expected incident. There are known pixel densities defined in various standards and, when applied properly during the design and installation stage, they will

So, the issue is not whether an infrastructure is covered by CCTV, but how good the coverage of these cameras may be.

guarantee capturing the required details as expected by law enforcement agencies. Very few consultants, and even fewer installers, will provide the requirement for the camera coverage at the expected incident distance. Very few of them will clearly request for image pixel density sufficient to recognise or identify a person. Rather, most of them will just make an effort to set a vari-focal lens to cover an area as wide as possible, without really being aware that at least 250 pix/m for face identification, or at least 125 pix/m for face recognition at a certain critical distance is required.


Cameras are not introduced to observe people’s private doings in public places. CCTV cameras are there to protect the community from the ‘baddies’.

Unfortunately, in the security industry today, anybody can import a ‘cheap’ product from the Asian market without taking into consideration whether a possible major incident could be covered by such products. In my role as a consultant, I have been called as an expert witness in a court matter, only to find out that the recorded footage used in the defence could not be replayed by anything. Both the camera and the recording system had no details of the manufacturer, its brand, the model or serial number. When I investigated the company to make contact, I discovered that it was no longer in business. So, as a consequence of a hypothetical incident occurring, it would be tragic to learn that, although the public area might be covered by CCTV cameras, it is highly probable that such cameras would not have captured sufficient details to identify the suspect. Even worse, it is highly probable that the recorded footage cannot be replayed properly. Blurry and unclear images will flood the news and people will be pointing the finger to the dated and poor-quality CCTV system. Not many will consider that, actually, it might be the consultant’s fault for not specifying camera views properly. Equally, the installer may have cut corners by supplying inferior equipment which promises the ‘world’ to the customer. Certainly, very few people will point the finger at the owner of the system, who has agreed to work with an ill-informed consultant and paid for an inferior system, thinking that having any camera, rather than none, is good enough. Having poor footage in TV news stories contributes to ill feelings by the public in reference to CCTV being used in public places. One of the criticisms of public CCTV is that it is inefficient and unclear in places where it is needed the most. The next thing to happen, in the case of the hypothetical public incident, will be a barrage of government promises ensuring that future surveillance systems will be better and will guarantee the apprehension of suspects and prevent future civil unrest and crime.

Tragically, only then will the real purpose and use of CCTV systems and cameras be made evident. Cameras are not introduced to observe people’s private doings in public places. CCTV cameras are there to protect the community from the ‘baddies’. In order for safe and sensible protection, cameras must be designed, manufactured, installed and set-up to comply with Australian and international standards. This is no different to the concept of paying a higher price for a safer car with better fuel efficiency, intelligent sensors and a good chassis construction, which will then further protect occupants in the event of a car accident. Such extra safety features may never be used, but it is comforting to know that sound engineering design features can be relied on when needed. A CCTV system should be installed with the utmost care and with the assumption that a major incident might be recorded by that exact camera. Hopefully this will never happen, but installers should act as if it might. The questions that every installer should ask themselves are: Is my system going to provide sufficient quality video footage to be able to help police apprehend the perpetrator? Does my system serve that purpose? If the answer is no, changes need to be made sooner rather than later, not after an incident has occurred. Those changes include a better understanding of every component in the camera’s system, its most optimal settings and the best angles of view to cover an area with sufficient details, while allowing for sufficient light for recording at night, best video quality encoding and ease of access by law enforcement agencies. If the above is adhered to, then CCTV cameras will be seen as protectors and welcomed by all and not, as they are commonly referred to, as intruders into people’s privacy. Vlado Damjanovski is an internationally renowned CCTV author, lecturer, innovator and consultant. He can be reached via his company website www.vidilabs.com

SECURITY SOLUTIONS 047


BUSINESS

4 Steps To Integrate Risk Management Into Strategic Planning

048 SECURITY SOLUTIONS


By Alex Sidorenko & Elena Demidenko Let me first start by saying integrating risk management into strategic planning is NOT doing a strategic risk assessment or even having a risk conversation at the strategy setting meeting, it is so much more. You will also find it difficult to relate if the objectives have not been defined or documented in your company or if the objectives are not measurable. Kevin W Knight, during his first visit to Russia a few years ago, said ‘risk management is a journey… not a destination’. Risk practitioners are free to start their integration journey at any process or point in time. However, I believe that evaluating strategic objectives at risk can be considered a good starting point. The reason why I think this is a good starting point is because it is relatively simple to implement, yet has an immediate and a significant impact on senior management decision making. STEP 1 – STRATEGIC OBJECTIVES DECOMPOSITION Any kind of risk analysis should start by taking a high-level objective and breaking it down into more tactical, operational key performance indicators (KPIs) and targets. When breaking down any objectives, it is important to follow the McKinsey MECE principle (ME – Mutually Exclusive, CE – Collectively Exhaustive) to avoid unnecessary duplication and overlapping. Most of the time, strategic objectives are already broken down into more tactical KPIs and targets by the strategy department or HR, so this saves the risk manager a lot of time. This is a critical step to make sure risk managers understand the business logic behind each objective and helps make risk analysis more focused. Important note: while it should be management’s responsibility to identify and assess risks, the business reality in your company may be that sometimes the risk manager should take the responsibility for performing risk assessment on strategic objectives and take the lead. EXAMPLE: RISK MANAGEMENT IMPLEMENTATION VMZ is an airline engine manufacturing business in Russia. Their product line consists of relatively old engines, the DV30, which are used for the medium-haul airplanes such as the Airliner 100. The production facility is in Samara, Russia. In 2012, a controlling stake (75%) was bought by investment company AVIARUS. During the last strategic board meeting, AVIARUS decided to maintain the production of the somewhat outdated DV30, although at a reduced volume due to plummeting sales and, more importantly, to launch a new engine, DV40, for its promising medium-haul aircraft, the Superliner 300. The Board signed off on a strategic objective to reach an EBT (earnings before tax) of 3000 milllion rubles (approximately 70.3 Million AUD) by the year 2018. STEP 2 – IDENTIFYING FACTORS, ASSOCIATED WITH UNCERTAINTY Once the strategic objectives have been broken down into more tactical, manageable pieces, risk managers need to use the strategy document, financial model, business plan or the budgeting model to determine key assumptions made by the management. Most assumptions are associated with some form of uncertainty and hence require risk analysis. Risk analysis helps to put unrealistic management assumptions under the spotlight. Common criteria for selecting management assumptions for further risk analysis include:

• The assumption is associated with high uncertainty. • The assumption impact is properly reflected in the financial model (for example, it makes no sense to assess foreign exchange risk if in the financial model all foreign currency costs are fixed in local currency and a change in currency insignificantly affects the calculation). • The organisation has reliable statistics or experts to determine the possible range of values and the possible distribution of values. • There are reliable external sources of information to determine the possible range of values and the possible distribution of values. For example, a large investment company may have the following risky assumptions: the expected rate of return for different types of investment, an asset sale timeframe, timing and the cost of external financing, rate of expected co-investment, exchange rates and so on. Concurrently, risk managers should perform a classic risk assessment to determine whether all significant risks were captured in the management assumptions analysis. The risk assessment should include a review of existing management and financial reports, industry research, auditors’ reports, insurance and third party inspections, as well as interviews with key employees. By the end of this step, risk managers should have a list of management assumptions. For every management assumption identified, risk managers should work with the process owners and internal auditors while utilising internal and external information sources to determine the ranges of possible values and their likely distribution shape. EXAMPLE: RISK MANAGEMENT IMPLEMENTATION (CONTINUED) Macroeconomic assumptions • Foreign exchange • Inflation • Interest rates (RUB) • Interest rates (USD) Materials • DV30 materials • DV40 materials Debt • Current debt • New debt

SECURITY SOLUTIONS 049


BUSINESS

Engines sales • New DV30 sales volume • New DV40 sales volume • DV30 repairs volume • DV40 repairs volume • DV30 price • DV40 price Other expenses • Current equipment and investments into new one • Operating personnel • General and administrative costs. Based on the management assumptions above, VMZ will significantly increase revenue and profitability by 2018. Expected EBT in 2018 is 3013 Million Rubles (approximately 70.6 Million AUD), which means the strategic objective will be achieved.

We will review what will happen to management projections after the risk analysis is performed in the next section. STEP 3 – PERFORMING RISK ANALYSIS The next step includes performing a scenario analysis or the Monte-Carlo simulation to assess the effect of uncertainty on the company’s strategic objectives. Risk modelling may be performed in a dedicated risk model or within the existing financial or budget model. There is a variety of different software options that can be used for risk modelling. All examples in this guide were performed using the Palisade @Risk software package, which extends the basic functionality of MS Excel or MS Project to perform powerful, visual, yet simple risk modelling. When modelling risks it is critical to consider the correlations between different assumptions. One of the useful tools for an in-depth risk analysis and identification of interdependencies is a bow-tie diagram. Bow-tie diagrams can be done manually or using the Palisade Big Picture software. Such analysis helps to determine the causes and consequences of each risk, improves the modelling of them as well as identifying the correlations between different management assumptions and events.

050 SECURITY SOLUTIONS

The outcome of risk analysis helps to determine the risk-adjusted probability of achieving strategic objectives and the key risks that may negatively or positively affect the achievement of these strategic objectives. The result is strategy@risk. EXAMPLE: RISK MANAGEMENT IMPLEMENTATION (CONTINUED)

The risk analysis shows that while the EBT in 2018 is likely to be positive, the probability of achieving or exceeding the strategic objective of 3000 mln. rub. is 4.6%. This analysis means: • The risks to achieving the strategy are significant and need to be managed • Strategic objectives may need to change unless most significant risks can be managed effectively. Further analysis shows that the volatility associated with the price of materials and the uncertainty surrounding the on-time delivery of new equipment have the most impact on the strategic objective.

Management should focus on mitigating these and other risks to improve the likelihood of the strategic objective being achieved. Tornado diagrams and result distributions will soon replace risk maps and risk profiles as they are much better at showing the impact risks have on objectives. This simple example shows how management decision making processes will change with the introduction of basic risk modelling.

STEP 4 – TURNING RISK ANALYSIS INTO ACTIONS Risk managers should discuss the outcomes of risk analysis with the executive team to see whether the results are reasonable, realistic and actionable. If indeed the results of risk analysis are significant, then management, with the help from the risk manager, may need to: • Revise the assumptions used in the strategy. • Consider sharing some of the risk with third parties by using hedging, outsourcing or insurance mechanisms. • Consider reducing risk by adopting alternative approaches for achieving the same objective or implementing appropriate risk control measures. • Accept risk and develop a business continuity / disaster recovery plan to minimise the impact of risks should they eventuate. • Or, perhaps, change the strategy altogether (the most likely option in our case). Based on the risk analysis outcomes it may be necessary for the management to review or update either the entire strategy, or just elements of it. This is one of the reasons why it is highly recommended to perform risk analysis before the strategy is finalised. At a later stage, the risk manager should work with the internal auditer to determine whether the risks identified during the risk analysis are in fact controlled and the agreed risk mitigations are implemented. Alex Sidorenko is an expert with over 13 years of strategic, innovation, risk and performance management experience across Australia, Russia, Poland and Kazakhstan. In 2014 Alex was named the Risk Manager of the Year by the Russian Risk Management Association. As a Board member of Institute for strategic risk analysis in decision making, Alex is responsible for G31000 risk management training and certification across Russia and CIS, running numerous risk management classroom and e-learning training programs. Alex represents Russian risk management community at the ISO Technical Committee 262 responsible for the update of ISO31000:20XX and Guide 73 since 2015. Alex is the co-author of the global PwC risk management methodology, the author of the risk management guidelines for SME (Russian standardization organization), risk management textbook (Russian Ministry of Finance), risk management guide (Australian Stock Exchange) and the award-winning training course on risk management (best risk education program 2013, 2014 and 2015).


SECURITY SOLUTIONS 051


COVER STORY

When Terror Strikes:

How Will The Australian Public Respond?

052 SECURITY SOLUTIONS


SECURITY SOLUTIONS 053


Turn static files into dynamic content formats.

Create a flipbook