A U S T R A L A S I A’ S L E A D I N G S E C U R I T Y R E S O U R C E F O R B U S I N E S S A N D G O V E R N M E N T
ISSUE #108 JUL/AUG 2017
HOW YOU’RE FUNDING TERRORISM
CUSTOMISABLE ELECTRIC HEIGHT ADJUSTABLE SIT STAND CONSOLES
Does your control room meet
Australian Ergonomic Standards?
www.activconsole.com
IFC-001_SSM108.indd 2
Clayton VIC 3168
20/06/2017 2:28 pm
Safe Work Australia, Nov 2015
“...in 2012-13 the cost impact of work-related injuries and illnesses was estimated to be just over $61 billion...�
State-of-the-art ergonomic lifting technology Lifetime Australia phone support AS/NZS 4443:1997 & ISO 11064
+61 3 9574 8044
IFC-001_SSM108.indd 1
sales@activconsole.com
20/06/2017 2:28 pm
SECURITY EXCELLENCE CALL FOR NOMINATIONS #SecurityAwards 2017 g By
Natalie Shymko, Marketing and Communications Manager, Australian Security Industry Association Limited (ASIAL)
T
he vital role performed by Australia’s private security industry will be recognised later this year at a special awards ceremony in Melbourne organised by ASIAL. The 2017 Australian Security Industry Awards for Excellence and Outstanding Security Performance Awards will recognise excellence in the security industry. Nominations are open to all and provide an opportunity to recognise individuals, including frontline security personnel who have gone beyond what could reasonably be expected of them in providing a level of service that exceeds client’s expectations. Likewise, organisations and teams who have demonstrated leadership and innovation will also be recognised. Judging of the awards will be undertaken by an independent panel of judges, that includes Kate Hughes, Chief Risk Officer, Telstra; Damian McMeekin, Head of Group Security, Australia & New Zealand Banking Group Ltd (ANZ); John Yates, QPM, Director of Security,
002-003 Advertising SSM108.indd 2
Scentre Group; Chris Beatson, Director, PoliceLink Command, New South Wales Police Force; John Adams, Editor, Security Electronics and Networks Magazine; John Curtis, Director, IPP Consulting Pty Ltd and Vlado Damjanovski, CCTV Specialist and MD, ViDi Labs. Nominations are now open and close on 1 September 2017. Winners will be presented at a special awards ceremony to be held at Crown Melbourne on 19 October 2017.
2017
Award categories include: • Individual Achievement – General • Individual Achievement – Technical • Gender Diversity • Indigenous Employment • Special Security Event or Project • Integrated Security Solution • Product of the Year (Alarm,
Access Control, CCTV – Camera, CCTV-IP System/Solution, Communication/Transmission System, Physical Security (bollard, gate, barrier)
Award categories include: • Outstanding In-house Security Manager • Outstanding In-house Security Team • Outstanding Security Training Initiative • Outstanding Security Partnership • Outstanding Security Officer • Outstanding Guarding Company • Outstanding Security Consultant • Outstanding Security Installer • Outstanding Information Security Companybarrier) For more detailed information on the award nomination criteria and process visit www.asial.com.au/ securityawards2017
20/06/2017 2:28 pm
RECOGNISING EXCELLENCE
Australian Security Industry Awards Nominations close 1 September www.asial.com.au
2017 EVENT Winners announced - 19 October 2017 The River Room, Crown Melbourne. The Australian Security Awards Ceremony & Dinner The night is an opportunity to celebrate excellence and innovation in the security industry, and network with likeminded security professionals.
Organised by
Lead dinner sponsor
Entertainment and centrepiece sponsor
2017
#securityawards 002-003 Advertising SSM108.indd 3
20/06/2017 2:28 pm
CONTENTS108
W i I a s
A m o a r i
T a e t s
COVER STORY: INSIDE THE SHADOW ECONOMY: ARE YOU FUNDING TERRORISM?
052 032
It costs money to commit acts of terrorism and field armies to fight the battles of jihad. The cost to pay for fighters, food, equipment, lodging, training, deployment and medical services for the jihadist by the controlling organisation or group is not cheap. When operating beyond the borders of the sponsor of terror, the costs can be five times as much as it would cost to conduct a local operation. How do terrorist groups fund their activities and how are thousands of Australians unwittingly contributing?
A c m o
INTO THE WILD BLUE YONDER Australian public and private organisations across a myriad of sectors are currently investigating and embracing the technological and competitive benefits of using remotely piloted aircraft called unmanned aerial vehicles (UAVs), or drones. But is drone technology right for your business? Garry Barnes looks at the factors every organisation should consider before flying into the great unknown.
060
PREPARING FOR THE NEXT WAVE OF RANSOMWARE ATTACKS – HOW TO DEFEND YOUR BUSINESS There’s no doubt about it, ransomware is both destructive and costly to businesses. However, in terms of an attack methodology it’s nothing new. What has elevated ransomware is the sheer magnitude and the evolving nature of the attacks. What steps can you take to protect your business from ransomware attacks?
068
THE NEW MASS GATHERING SECURITY REALITY Can security ever really counter the terrorist threat at places of mass gatherings?
084
SECURITY AND COUNTER TERROR IN LONDON
W n R a b
9,850 security professionals from over 114 countries travelled to London in May for the latest instalment of Security & Counter Terror Expo (SCTX). The show once again incorporated leading forensics show Forensics Europe Expo and Ambition – the event for the emergency preparedness, resilience and response (EPRR) community. We bring you a complete round up of this year’s event.
090
SECURITY 2017 Find out everything you need to know to plan and get the most out of your visit to this year’s security exhibition and conference. From exhibitor listings to the conference program and everything in between.
A fu t d
004 SECURITY SOLUTIONS 004-007_SSM108 Contents.indd 4
21/06/2017 12:34 pm
We are a leading player in the biometric identification market by pioneering In Motion Identification (IMID) access, a multimodal verification for instant, seamless, and non-invasive verification. Ask us about advanced features such as multi-modality, speed of identification, our committed accuracy, anti-fraud algorithm, double factor availability, restricted people alerts, simultaneous identification.
The solution is designed for enterprise and can be easily integrated with existing infrastructure. It can be added to any existing door, turnstile or speed stile, and any access control solution. Ask us about high availability, scalability, cyber security and encryption, multi-site management, traceability and auditability, our APIs and ease of integration.
FST Biometrics is a leading identity management solutions provider. The company’s IMID™ product line offers access control through its proprietary In Motion Identification technology. This provides the ultimate security and convenience for users, who are accurately identified without having to stop or slow down. IMID™ solutions integrate a fusion of biometric and analytic technologies that include face recognition, body behavior analytics and voice verification. For more information, please visit http://www.fstbm.com.
With IMID Access, authorized users do not have to slow down, sign in or stop. Rather, they are identified in motion, and granted seamless access to buildings and facilities. Ask us about our rich out of the box functionality, such as visitor management, time attendance, notifications, digital doorman and mobile applications.
004-007_SSM108 Contents.indd 5
Add-On APAC Innovative Solutions offers converged physical, cyber and communication security solutions. Operating across the Asia Pacific region, we harness advanced products and ground-breaking technologies, helping our customers transform the way they protect people, information and assets. Learn more about us at http://www.addonapac.com. Add-On APAC Australia Pty Ltd info@addonapac.com, 03 9607 8465
IMID is the future of access control. Prefer to take your own conclusions?
Ask us for a product demonstration, and see it for yourself.
21/06/2017 12:34 pm
CONTENTS108 010
LETTER FROM THE EDITOR
044 CCTV Leading CCTV expert Vlado Damjanovski looks at the
importance of designing CCTV systems to provide the necessary information to help deal with major incidents.
012 LEADERSHIP Jason Brown looks at the concept of leading from below.
014 CYBER SECURITY What are staff members really doing with company data?
016 RESILIENCE How has cyber resilience evolved a decade after the
048 BUSINESS Is risk policy the new risk paradigm? 058
LEGAL Q&A We answer your legal questions.
064 LOSS PREVENTION We present the first of our two-part special on
the role of loss prevention across the retail supply chain security program.
first large scale cyber attack?
018 HUMAN RESOURCES Greg Byrne presents the second part of his special on conducting workplace investigations.
072 AVIATION What does the immediate future hold for passenger screening?
020 RISK MANAGEMENT From a risk management perspective, is it legal to design security systems without a license?
076 ACCESS CONTROL What are the technology advancement that are currently reshaping the security landscape?
024
LEGAL Beware Google.
080 PROFESSIONAL DEVELOPMENT What is Risk Intelligence?
026 THINKING ABOUT SECURITY What is the value of Pro Bono work for
088
SECURITY STUFF
028 EVENTS A look at upcoming industry events.
090
SPOTLIGHTS
036 ALARMS Why do we need standards for electronic security
096
PROFILES
106
PRODUCT SHOWCASES
110
SHOPTALK Company announcements from within the industry.
security professionals?
systems?
040 OPERATIONS Richard Kay examines why brains are more important than brawn in public safety environments.
040
032
048
072
084
006 SECURITY SOLUTIONS 004-007_SSM108 Contents.indd 6
21/06/2017 12:34 pm
TR
OR
004-007_SSM108 Contents.indd 7
HÉE D’ OP
21/06/2017 12:34 pm
www.securitysolutionsmagazine.com
Editorial Editor: John Bigelow john@interactivemediasolutions.com.au Sub-Editing: Helen Sist, Ged McMahon Special Guest Editor: Don Williams Contributors: Garry Barnes, Karissa Breen, Jason Brown, Greg Byrne, Per Bjรถrkdahl, Vlado Damjanovski, Kevin Foster, Steve Lawson, Justin Lawrence, Rita Parker, Don Williams, Richard Kay, Tony Charge, David Lake, Kevin Cunningham, Jac Brittain, Craig Harwood, Rob Spinetti, Dr Gav Schneider, Dr Paul Johnston, Kate Down.
Advertising keith@interactivemediasolutions.com.au Phone: 1300 300 552
Marketing & Subscriptions admin@interactivemediasolutions.com.au $62.00 AUD inside Aust. (6 Issues) $124.00 AUD outside Aust. (6 Issues)
Design & Production graphics@interactivemediasolutions.com.au Phone: 1300 300 552
Accounts accounts@interactivemediasolutions.com.au Phone: 1300 300 552
Publisher
ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au Disclaimer The publisher takes due care in the preparation of this magazine and takes all reasonable precautions and makes all reasonable effort to ensure the accuracy of material contained in this publication, but is not liable for any mistake, misprint or omission. The publisher does not assume any responsibility or liability for any loss or damage which may result from any inaccuracy or omission in this publication, or from the use of information contained herein. The publisher makes no warranty, express or implied with respect to any of the material contained herein. The contents of this magazine may not be reproduced in ANY form in whole OR in part without WRITTEN permission from the publisher. Reproduction includes copying, photocopying, translation or reduced to any electronic medium or machine-readable form.
RS A DE VI
SSOCIATI
ON
ABN 56 606 919 463 Level 1, 34 Joseph St, Blackburn, Victoria 3130 Phone: 1300 300 552 Email: enquiries@interactivemediasolutions.com.au
O
RALIA LTD
SECURIT Y
PR
UST FA
O
Written Correspondence to:
Or i g i n a l Si z e
O C I AT I
ON
Y P R OVI D
RIT
CU
D LT
SE
PR O
ASS
SPAAL
AU S T R A L I A
STRALIA LTD AU
SECURITY
RS
OF
E
Official partners with:
SSOCIAT IO N
OF
RS A DE VI
blue colour changed to this colour green.
COPY/ARTWORK/TYPESETTING APPROVAL Please proof read carefully ALL of this copy/artwork/typesetting material BEFORE signing your approval to print. Please pay special attention to spelling, punctuation, dates, times, telephone numbers, addresses etc, as well as layout.It is your responsibility to bring to our attention any corrections. Minuteman Press assumes no responsibility for errors after a proof has been authorised to print and print re-runs will be at your cost. Signed.................................................................. Date........................
008 SECURITY SOLUTIONS 008-011_SSM108 Editors Letter.indd 8
21/06/2017 12:23 pm
Series 2005 is the leading brand of 19” rack mount enclosure for data and communications installations, with a huge range of sizes. MFB have the right cabinet for your needs.
When you choose Australian made, you’re choosing more than quality and reliability, you’re choosing peace of mind.
DESIGNERS & MANUFACTURERS OF 19” RACK SYSTEMS
MFB’s range of innovative racking solutions is proudly made onshore, to ensure quality and consistency above all others. Backed by constant development, unsurpassed customer support and expedited delivery. MFB proves a solid project partner whatever your requirements. Australian made, makes Australia. With a solid history of over 45 years of supplying innovative, off-the-shelf and custom built racking systems, you can rely on MFB to ensure when you buy Australian, you’re investing and supporting Australian industry.
AUSTRALIAN MADE MAKES AUSTRALIA
www.mfb.com.au
VIC NSW -
P (03) 9801 1044 P (02) 9749 1922
F (03) 9801 1176 F (02) 9749 1987
E sales@mfb.com.au E sydney@mfb.com.au
SECURITY SOLUTIONS 009 008-011_SSM108 Editors Letter.indd 9
21/06/2017 12:23 pm
LETTER FROM THE EDITOR While it is difficult to quantify to what degree terrorist activity has increased across the globe since 2001, there can be little doubt that the world has experienced a significant increase in terrorist attacks. Esri, a global leader in mapping and spatial analytics, recently published a map showing the locations and details of terrorist incidents across the globe for the year 2017 up to early June*. The map is a collaboration between the Esri Story Maps team and PeaceTech Lab and uses crowd-sourced data from Wikipedia to present a chronology of terrorist attacks around the globe. According to Esri, Wikipedia moderators include experts in the field of global conflict and terrorism, and the pages driving this story map have been revised thousands of times since the beginning of 2017. As a result, the quality of the data on this map is constantly improving. According to the map, there have been 571 attacks across the world resulting in 3,924 fatalities since the 1st of January 2017, including two attacks in Australia – the most recent being the siege involving Yacqub Khayre in Melbourne (who was reported as being inspired by ISIS), and an incident which occurred in Queanbeyan, NSW, in April involving two young boys (again reportedly inspired by ISIS) who attacked a service station and killed the 29-year-old service station attendant before stabbing another person. The unquestionable rise in terrorist activity over the last decade raises significant questions around not only how best to tackle terrorism but, equally importantly, how is it that these terrorist groups are able to fund and support their actions. In this Issue’s cover story, David Lake, a serving law enforcement officer and expert in the area of organised crime, shines a light on the shadow economy and examines issues around the types of illegal activities carried out by terrorist groups in order to fund their activities. In preparing this story, I was horrified not only by the scale and monetary value of these activities but, perhaps more importantly, the lack of action being taken by governments to stem the tide of funding and the degree to which many Australians (and citizens of other countries) have become unwitting financial supporters of terrorist activities. I would strongly urge every reader to take a look at this article and then think long and hard about how, in your role as both security professionals and everyday members of the public, you might best be positioned to help address and eradicate this problem and potential source of terrorist funding. Share the article far and wide. Debate it, discuss it, think about it but, most importantly, where possible, act upon it. If anyone is in a position to do something about this problem, it is the readers of this publication. * storymaps.esri.com/stories/terrorist-attacks/?year=2017
John Bigelow Editor
010 SECURITY SOLUTIONS 008-011_SSM108 Editors Letter.indd 10
21/06/2017 12:23 pm
R
EasyIP 3.0 H.265+ EasyIP 3.0 H.265+
EasyIP 3.0 SERIES
Simple and Powerful The Easier Journey toEasyIP Better 3.0Security SERIES Simple and Powerful The Easier Journey to Better Security
The all-new Easy IP product range is simple to install and use, and is available at a budget-friendly price. Rarely does an affordable system come with such powerful functionality: 4K ultra HD with true WDR, H.265+ Smart Codec compression technology. New cameras in the range also provide greater analytic functions, featuring on-board Video Content Analysis options. Its power, combined with its easy installation and user-friendliness, means the Easy IP 3.0 solution requires significantly less operator input to deliver a significantly more efficient and effective security solution. - 4K Ultra HD with WDRrange is simple to install and use, and is available at a budget-friendly price. The all-new Easy IP true product Rarely does an affordable system come with such powerful functionality: 4K ultra HD with true WDR, H.265+ - H.265+/H.265 Compression technology Smart Codec compression technology. New cameras in the range also provide greater analytic functions, featuring on-board Video Content Analysis options. Its power, combined with its easy installation and Hikvision Oceania user-friendliness, means the Easy IP 3.0 solution requires significantly less operator input to deliver a significantly more efficient effective security solution. Unite 14a Eden Park Dr, Macquarie Parkand NSW 2113 Tel: +61 2 8599 4233 - 4K HD557 with true WDR Toll Ultra Free:1300 450( Australia only) Email:salesau@hikvision.com www.hikvision.com - H.265+/H.265 Compression technology 008-011_SSM108 Editors Letter.indd 11
Hikvision Oceania
21/06/2017 12:23 pm
REGULAR
LEADERSHIP Leading From Below By Jason Brown
In the world of security, hierarchies are common and leadership tends to be associated with position or rank, but this need not always be the case. If you have the desire, competence and willingness to communicate your ideas you can lead from below (LfB). I would argue that in any well-run organisation, those who demonstrate a capacity to lead from below usually end up with a formal leadership position. In this article, I have gathered thoughts from a number of leadership writers on the topic of LfB. First of all, you have to wish to lead and be willing take the risks that putting yourself forward entails. This means being able to influence decisions and directions, not through position power, but through sharing good ideas and information and demonstrating a willingness to help others achieve their professional goals. You need to understand your organisation, particularly its goals, structures and processes. This knowledge of how everything works lets you input your ideas at the right time with the right people who will recognise your contribution and willingness to help. Consider the issues impacting on your overall organisation, not just those in your specific duties, and take them into account when making suggestions. You are more likely to be heard and understood by those more senior. In the Wall Street Journal report ‘Leading From Below’, James Kelly and Scott Nadler suggest that organisational change and development can only occur when there is leadership at all levels. They made a number of suggestions: Make a decision to be a leader, do not wait to be told: • become less essential to the doing of routine work, free up time and energy for leadership, unlock staff potential • become aware of signals from outside your organisational unit and your organisation.
Focus on influence, not control – enlist your staff in a common cause: • adopt the perspective of the people you are trying to influence • do not hoard information, share it • aim to influence existing work processes, do not build new ones • do not worry about being proved right • keep things clear and simple • keep a sharp focus. Make your mental organisational chart horizontal rather than vertical – connect with peers, make them your focus group Work on your trusted advisor skills: • turn conversations into meaningful discussions that make people seek you out • listen more than you talk • ask questions that broaden people’s perspective • share what others have seen and done in similar circumstances. Do not wait for the perfect time, just find a good time: • do not wait for an invitation • look for situations where complacency has been disturbed. Taking responsibility is a key attribute. Accept your successes and recognise and admit any failures. Keeping a win-win approach to the fore is an important way of engaging and leading others, particularly when you can share opportunities with others and align their goals to yours. You need to be open and generous with both time and information and accept and act on feedback. This is generally reciprocated and you will have the input to enrich your competence and influence.
This is demonstrated by the behaviours listed above. Herminia Ibarra, Professor of Leadership and Learning at INSEAD, summed it up in an interview in Global Network Perspectives: I define leadership behaviorally. A leader is somebody who is able to set direction for a group, and then mobilize them toward that goal. I don’t get into personality characteristics because it can vary a lot. The common factors really are big-picture strategic thinking and the capacity to influence people. In terms of vision, it’s being able to sense what’s going on in the world, see the unexploited opportunities and lurking dangers, and use that to figure out what to focus on and what not to focus on. With influencing others, it’s how you get people to see your view, how you get them to see it as their issue, not just your issue, and how you communicate in a way that makes them feel motivated, inspired, involved, and a part of things. Lastly, I would suggest that you need to be authentic in your actions and words. This builds trust and influence. But do not forget to add a bit of humour; at the right time it will build camaraderie and reduce negative tension. Good luck leading from below. It is worth the effort. Jason Brown is the National Security Director for Thales in Australia and New Zealand. He is responsible for security liaison with government, law enforcement and intelligence communities to develop cooperative arrangements to minimise risk to Thales and those in the community that it supports. He is also responsible for ensuring compliance with international and commonwealth requirements for national security and relevant federal and state laws. He has served on a number of senior boards and committees, including Chair of the Security Professionals Australasia, member of ASIS International Standards and Guidelines Commission and Chair of Australian Standards Committee for Security and resilience. As of February 2017, Jason has been appointed Chair of the International Standards Committee for Risk Management.
012 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 12
21/06/2017 10:55 am
STOP TAILGATING AND OTHER UNAUTHORISED ENTRY ATTEMPTS
NOW AS EASY AS 1,2,... 1
2
1
Take 1 standard access controlled door with tailgating problems.
Tailgating is the art of unauthorised people following authorised people through an access controlled door.
www.pathminder.com.au
012-031 SSM108 Regulars.indd 13
2
Add a PathMinder HPJ half portal.
The PathMinder HPJ half portal can ‘cap’ any access controlled door to turn it into a secure interlock, the highly sophisticated ultra sonic tailgate detection technology makes sure access is limited to one person at a time.
3
Sit back and relax, job done.
With over 40 portals in the range, PathMinder has a high security solution to controlling access at any entry point. Our portals include vandal, attack and bullet resistant certified designs, DDA compliant solutions and full customisable models to match your security needs.
Phone: 1300 750 740
21/06/2017 10:55 am
REGULAR
CYBER SECURITY What Are Employees Actually Doing? By Karissa Breen
C
M
The news or the media are always reporting that outsider threats are the main source of cyberattacks, but who is actually looking at the employees on the inside? What are all these people doing? Is anyone monitoring what the system administrators are doing and ensuring they are not downloading every episode of “House of Cards” under the sun because they can and because they have ‘privileged account management’? Organisations are so quick to point the finger a ‘outsiders’ who are always generating bad media affairs because they are on point for performing sophisticated cybercrime. But what interests me the most about insider threat is the psychology behind why employees do what they do. Perhaps they believe having privileged access to sensitive information could advance their career, perhaps not. Who actually knows? But there are mechanisms to identify user activity. There are a few potential reasons why insider threats are going next level nowadays. Sometimes it is not always an intentional ‘crack’ at the organisation. It can sometimes be by accident or lack of security awareness and failure to undertake correct security procedures. For example, an employee could be sitting down in a coffee shop utilising the public free Wi-Fi (most people generally opt for this option anyway). The employee could have no intention of performing any malicious intent to the business.
However, anyone with malicious intent within range could piggyback on the employee’s signature to gain access to confidential information. In thi example, this employee probably did not set out with the wrong intention of jeopardising the company’s confidential information However, another example could be that when the cyber forensics team investigate the logs and see that the same type of behaviour was a frequent occurrence and data leakage was taking place through various mechanisms, it is probably safe to say that this was an intentional offence. Userbased activity can always be traced and, therefore, assumptions can be made on individuals. Once the unethical behaviour has been detected, organisations should undertake the correct protocol to ensure that this behaviour is stamped out immediately. Organisations engender trust with their clients; they should also be engendering trust with their insiders. Organisations need to understand human behaviours and be across potential defects that insiders make and intrinsically understand why this is happening. Information security teams need to have a comprehensive understanding of privileged account management and monitor these individuals through appropriate controls to ensure they maintain strong integrity. Senior management should be taking it upon themselves to ensure they are responding
appropriately and looking for trends in behaviour; organisations are now gathering this through artificial intelligence So, do not always point the finger straight awa and play the blame game, but instead understand what employee activity is going on. Privileged account management users need to have appropriate controls in place to monitor their level of access. Organisations should be aware of these types of insider behaviours and ensure the correct security policies and procedures are embedded to protect the organisation’s integrity and reputation. When data leakage occurs, it is not always for a bad intent, but if organisations are not aware of what their employees are doing it is quite easy to blame them and then in turn organisations lose their employees’ trust. Organisations should be advanced enough to identify a misdemeanour and distinguish that from an accident. Do not be so quick to judge, but ensure the business is performing the correct procedures to eradicate this type of unethical behaviour.
Y
CM
MY
CY
CMY
K
Karissa Breen is currently working as an account executive for Green Light, a provider of IT services to systems integrators, telcos, consultancies and defence organisations in the global market. Karissa has a background in cyber security, financial services and consulting an publishes her own IT blog.
014 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 14
21/06/2017 10:55 am
NEW INT-QUADIP For PB- Series Quad Beams
C
M
Y
CM
MY
CY
CMY
K
IP INTERFACE MODULE
LAN/WAN
With the new IP interface module, our intelligent PB- series Quad Beams are as easy as IP cameras to install and integrate with leading VMS solutions.
VMS
Most intruder detection systems rely on legacy technologies which require a number of third-party products and man-hours to install. The INT-QUADIP module utilises infrastructures already in place with CCTV, Access Control, and other security systems; dramatically reducing installation costs whilst providing a fully integrated security system which can be easily expanded and configured as desired.
KEY SPECIFICATIONS ● ● ● ●
PoE Class 3 IEEE 802.3af VMS Compatible Direct control for cameras including: - Axis - Bosch - Hikvision - Sony
● Plug & play web browser interface ● No software installation required ● One cable installation
PB-IN-HF/HFA The ultimate in trouble free perimeter detection for distances up to 200m.
1300 366 851 www.seadan.com.au 012-031 SSM108 Regulars.indd 15
PB-F/FA Single channel quad beams ideal for simple perimeter systems.
PB-IN-100AT Anti-crawl beam for high security perimeters up to 100m.
PB-KH TAKEX quad beam performance for use in beam towers.
(02) 9427 2677 www.sprintintercom.au
21/06/2017 10:55 am
REGULAR
RESILIENCE Cyber Resilience – A Decade After The First Large-Scale Attack By Dr Rita Parker The fragility of cyber defences worldwide was exposed when malicious software (ransomware) created havoc around the globe in May this year, affecting businesses, individuals and critical infrastructure. The global reach was unprecedented. The first wave of cyberattack hit 200,000 targets in at least 150 countries, according to a statement by the head of the European Union’s police agency Europol Director, Rob Wainwright. Malicious software or ransomware is a program that enters your computer either by clicking or downloading malicious files. I then holds your data as ransom. The global attack in May this year was attributed to a form of ransomware known as WannaCry that targets Microsoft’s widely used Windows operating system to locks up files on your compute , encrypts them so they cannot be accessed, and demands payment to regain access. But there is no guarantee that access will be granted after payment. The question that needs to be asked is: have we developed our cyber resilience since the firs deliberate large scale cyberattack a decade ago, in May 2007? At the time, it was a coordinated approach that had never been seen before. The massive cyberattack occurred following the Estonian Government’s decision to move a bronze statue that the Soviets had built in 1947 to commemorate their war dead after driving the Nazis out of the region at the end of World War II. But having rid the country of German occupation, the Russians then occupied Estonia. For many citizens, the statue was a symbol of an oppressive occupation. Sixty years later in April 2007, the now independent Estonian state decided to move the monument from the centre of the city to a military cemetery on Tallinn’s outskirts. For Estonia’s ethnic Russians, who make up a quarter of the nation’s population, it was an emotionally
charged time and, following the statue’s removal, there were several days of civil unrest and violent confrontation resulting in hundreds of arrests, many injuries and, tragically, one death. But the situation did not end there. What followed was unprecedented – for almost three weeks, a series of massive cyber operations targeted Estonia and disrupted and closed banks, government networks and emergency services, the media and police operations. It was as close to chaos as was imaginable. Estonian border guards had reported no incursions and the country’s airspace had not been violated. The attacker was invisible, yet the attacks were virtual, psychological and real. Never before had an entire country been targeted simultaneously on almost every digital front. It was a wakeup call, not just for the Estonian Government, but around the globe about the extent of cyber vulnerability and of the need to become resilient. Ten years later, in May 2017, there was a feeling of déjà vu as malicious software attacked targets around the globe. Part of adopting a cyber resilience approach to business is to take anticipatory and preventive measures. One of the most basic preventative measures is to avoid clicking on links or opening attachments or emails from people you do not know or companies you do not do business with. To enhance cyber resilience, other basic steps are necessary, such as regularly backing-up your important files. Installing and using up-to-dat antivirus solutions, and ensuring your software is up-to-date also helps. In addition to seeking expert advice, it is important to have your systems and procedures tested. Thought also needs to be given to building in redundancies in the event of a complete or partial shutdown of your computer system. These preventive measures to safeguard business operations contribute to building cyber resilience, and they are just as important for small
businesses as well as large corporations. It is a mistake to think that as a small business you may not be a target for a cyberattack because this type of assumption can result in huge losses. In Australia, we realise that our geographic sovereign border is vulnerable with 35,876 km of coastline, with an additional 23,859 km when taking into account island coastlines. Yet another border, the Internet and the World Wide Web, potentially makes the nation even more vulnerable to real threats and risks to our economic, trade and social wellbeing and security. Every person who owns or operates a computer linked to the outside world has a responsibility to ensure they have in place relevant strategies and processes to prevent or mitigate an attack and, importantly, strategies to ensure they are resilient in the event of an attack. Dr Rita Parker is a member of the International Council of Security & Resilience Professionals, and Centre Manager of the Australian Centre for Armed Conflict and Society at the Universit of New South Wales, Canberra. Rita is also a former Distinguished Fellow at the Center for Infrastructure Protection at George Mason University (GMU) Law School, Virginia, USA, and she was a Founding Board Member of the Australasian Security Professionals Registry. Dr Parker provides advice to organisations seeking to increase their corporate and organisational resilience and crisis management ability. In additional to being a regular columnist for Security Solutions Magazine her work has been published in Australia, Germany US, Singapore and Malaysia. Her co-edited book, Global Insecurity, published by Palgrave McMillan will be available in 2017, includes aspects of her recent research about urgent global security policy issues. She can be contacted at ritap2020@gmail.com
016 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 16
21/06/2017 10:55 am
EC - S
TALL. FAST. STYLISH. Our award winning speedgates combine state-of-the-art optical technology with a high barrier height to protect your building.
EASYGATE SPT
• • • •
Barrier heights up to 1800mm Fast throughput (up to one person per second) Ideal for Disability Discrimination Act compliance Choose from a number of models, including the LX, SPT, SG, IM or LG • Custom pedestals with an array of attractive finishes EASYGATE LX
Find out which security gate is right for you.
1300 858 840
www.entrancecontrol.com.au
EASYGATE IM
FULL HEIGHT TURNSTILE
EC - Security Solutions Ad.indd 1 17 012-031 SSM108 Regulars.indd
TRIPOD TURNSTILE
SWING GATE
6/02/2017 10:37:16 AMam 21/06/2017 10:55
REGULAR
M S
HUMAN RESOURCES Conducting Workplace Investigations – Part 2 By Greg Byrne
In this edition of the Security Solutions Magazine, I will conclude the two-part article on conducting an internal investigation. In the previous article (in Security Solutions Magazine Issue 106), I discussed that conducting an internal investigation involved a four-step process of: 1. Preparation and information collection 2. Interviewing the relevant parties 3. Making a finding and report 4. Resolution activities. In that article, I outlined the fi st two steps of preparation and information collection and interviewing the relevant parties and any witnesses. I discussed that the process of collecting information involved first establishing that there was a need to conduct an investigation in the fi st place, that it was vital that an independent and competent investigator be appointed, and that a proper interview process and plan was prepared and followed. The second step in the process was then to conduct the interviews, which involved identification of appropriate locations, correct and accurate record keeping, and maintaining the confidentiality of the process, including securing records of the interview and any evidence gathered. This article will outline the last two steps for investigators in conducting an internal investigation. The fi st is making a finding and the second resolving the complaint. When arriving at a finding, it is vitally important to objectively assess all evidence that
has been gathered. The information gathered should be consistent, reliable and credible and, if discrepancies exist, they should have been addressed. In weighing the evidence and arriving at a logical outcome, ensure that the reasonable person test has been applied, and consider that the more serious the implication of a finding the stronger the balance of probabilities test needs to be. Consider the fallout from the complaint and subsequent investigation and make sure that the welfare of all involved has been addressed, including the offending employee (if it is established there is one). Also consider what the complainant intended when making the complaint and that his wishes have been considered when arriving at a finding. Make sure the employer’s wishes have also been considered, since they are the people paying wages and are also responsible for ensuring a safe (free of bullying or harassment) workplace. Internal policies (such as meal room etiquette, movement around worksites and wearing of uniform) and external policies and legislation (such as work, health and safety [WHS], state crimes acts and other relevant acts) must also be considered. Police should be informed if criminal behaviour was either initially complained of or is detected during the investigation. Be aware that once the police have become involved, they must be informed of the existence of any information that could form part of a police brief of evidence.
When compiling information, consider summarising it using an evidence matrix. Then make findings on each of the matters complained of in the fi st instance, or anything arising. List elements of each complaint and make a finding on the facts: • behaviour found to have occurred • behaviour found NOT to have occurred • inconclusive. Then categorise as: • potentially unlawful • breach of policy/code • unreasonable • unprofessional • reasonable in all the circumstances. Decision Making Once all relevant persons have been interviewed, the welfare of all concerned (including any offending employees) and the wishes of the employee and the employer have been considered, and the information has been categorised, it is now time to make a decision. Firstly, do not leave any material matters unaddressed. A finding might be that there is insufficient evidence to support a finding of inappropriate behaviour or that the case against the respondent has not been established on the balance of probabilities. It is not fair to the respondent(s) to leave a matter unresolved. Take one last look at the various elements of the complaint in totality and see if there is a
018 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 18
21/06/2017 10:55 am
MULTIPLE CAPABILITIES SUPERIOR SOLUTION
Volvo Group Governmental Sales Oceania
IN HOSTILE ENVIRONMENTS, IT’S IMPORTANT THE SYSTEMS THAT YOU DEPEND ON CAN
STAND THE TEST OF TIME.
At Volvo Group Governmental Sales Oceania, our core business is the manufacturing, delivery and the support of an unparalleled range of military and security vehicle platforms; a range of platforms that are backed by an experienced, reliable and global network with over one hundred years of experience
superior solutions, providing exceptional protected mobility www.governmentalsalesoceania.com 012-031 SSM108 Regulars.indd 19
21/06/2017 10:55 am
REGULAR
HUMAN RESOURCES public interest where appropriate. Some outcomes may include: • conciliation/mediation • counselling • formal apology • training • communication of policies to the workforce • re-crediting any leave taken as a result of the discrimination or harassment • disciplinary action – for example, warning, dismissal, transfer, demotion • dismissal of the complaint if it is found to have no substance • increased supervision/monitoring • reimbursing costs (for example, medical, counselling) • disciplinary action against the complainant if the complaint was vexatious or malicious • applying an appeals process if parties are not satisfied with the investigation result.
pattern of behaviour. Ensure that a connection between the evidence and findings and any subsequent conclusions has been established so that the rationale is evident. Findings should be presented in a workplace investigation report that outlines the evidence uncovered or discovered and details how the organisation could deal with the complaint if it is submitted in subsequent legal proceedings. For example, if a complaint is lodged with the Human Rights and Equal Opportunity Commission or another anti-discrimination agency, records of internal action will be useful in establishing whether ‘reasonable steps’ were taken to deal with the discrimination/ harassment and may assist in discharging the organisation’s liability. In the process of compiling an investigation report and making findings (and making recommendations, if requested), consider that: • all the issues have been covered • everyone who should have been interviewed has been • all respondents against whom an adverse
finding might be made have been advised of the relevant allegation and have been given a chance to respond to the allegation. Also ensure that all witnesses have had the opportunity to review and make any necessary corrections to their statements and that statements have been signed. Ensure that the decision-making process applied the balance of probability test and established that it was more probable than not that it occurred (an evidence matrix form as discussed above is a useful tool to assist investigators in this regard). Once the report has been compiled and the employer, aggrieved parties and offending parties have all been informed of the outcomes, consider resolving the complaint in a lawful and efficient manner. Every situation is different and the suitability of resolution activities varies accordingly. The decision-making process must consider all the evidence at hand and must consider the interests of all concerned, including the
Communication Keep in mind that while an investigation may be carried out that meets all process requirements, it is the perceptions of the individuals involved that will influence their ability to accept the outcome. With this in mind, consider creating and following a communication plan. That then is the brief outline on how an internal investigation should be planned for, conducted and finalised. I intended writing two articles on this, but I ran out of room to also cover some important information. I think some of the issues that I have not covered yet are important and, as a result, I will include them in a third article on conducting workplace investigations. Greg Byrne is CEO and director of MultiSec Consultancy Pty Ltd, a multi-faceted consultancy advising CEOs and boards of security organisations in Australia on best approaches to manage business risk, particularly operations, disaster recovery, business continuity and human resources. Greg can be contacted via email greg@ multisec.com.au or on 0402 295 124.
020 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 20
21/06/2017 10:55 am
dorma
Co m
es Sec at ee th urit st e yE xpo and H futur e , fo 2 r yo 2, ur cha nce
WI aG
oP
ro V
ide
N
to
oC am
era
The c-lever range -The perfect symbiosis of technology and design. Since the launch of the smartphone, it’s been clear that intelligent secure technology and design are not mutually exclusive.
Come see the future
Our designers have taken inspiration from such developments and created shapes that stylishly combine aesthetic and functional secure requirements. Come visit stand H22 at the Security Exhibition & Conference to learn more about our c-lever range and our security solutions to meet your business requirements.
1800 675 411 www.dormakaba.com.au
dormakaba_c-lever x 275mm_SS#107_108_240517.indd 2 012-031 SSM108 air_210mm Regulars.indd 21
6/2/2017 9:21:54 AMam 21/06/2017 10:55
REGULAR
Co Fo
COMMUNICATIONS RISK MANAGEMENT Is It ‘Legal’ To Design Security Systems Without A Licence? A Risk Management Perspective By Dr Kevin J. Foster Recently, I heard an argument from a licensed security consultant that, in a legal sense, an engineer in Victoria cannot design electronic security systems for a project in Western Australia (WA) unless he or she is licensed in WA. I have heard similar arguments previously; for example, that someone in Canberra cannot work on a security project in Queensland unless they are licensed in Queensland and so on. The security industry legislation in WA clearly states that a security consultant (Class 4) licence is required if there is a transaction involving the provision of security advice to a paying customer and this transaction occurs in WA. The legislation has no specific requirements about who can or cannot draft technical specifications and drawings for the consultant’s consideration. The only requirement is that security advice must be provided to a paying customer under the authority of a security consultant’s licence and the licensed security consultant must be employed under the authority of a security agent’s licence. In this context, it is the advisory transaction that is being regulated, not the location of the pre-transaction design work, and not who was involved in the drafting of specifications and drawings. All that seems to matter is whose licence is used to provide authorised advice to a paying customer and in what state the transaction occurred. For example, if an electrical or electronics engineer (who we will call John) in Melbourne sends his security systems design to his colleague (Bill) in the same fi m in Perth, then
under WA security industry legislation, a licence is not required for that transfer of information from one office to another (for example, security systems diagrams and specifications). However, if Bill then presents the security design in the form of security advice to a paying customer in Perth, then Bill will need to be a licensed security consultant as defined under the Security and Related Activities (Control) Act 1996 (WA) Part 3 Division 1 s. 13. When an engineering team contributes to the design of a major building or civil infrastructure, a number of disciplines are involved. An electrical engineer (for example, John) might design electronic building services including intrusion alarms, CCTV and access control systems. If John has had no training in security risk management, it is possible he may not have a clear understanding of how any of these systems might reduce security risk, nor would he necessarily understand the intent of criminals or terrorists who might present a threat. However, if John is a chartered professional engineer and registered on the National Engineers Register, it might be a poor argument to suggest he does not have the expertise to design the technical elements of an electronic security system to a brief written by someone who is aware of the security risk issues. However, there is a valid argument that John should not be advising paying customers about the impact of his designs on the customer’s security risk. This is where the security consultant has an important role. The security consultant (Bill) should be the interface
between the customer and the design engineer (John). The security consultant should be the person responsible for presenting security advice to the customer, especially if there is an expectation that the security system’s design will alter the security risk in some way. Similarly, structural and civil engineers might design security structures and barriers to stop a vehicle or to provide resilience to a blast pressure wave. This type of work is security related. However, interestingly, I do not hear arguments that civil and structural engineers need to be licensed security consultants. If their designs are entirely technical then perhaps they do not need to be. The test for who needs to be licensed or registered needs to be consistent. I think the legislation in each state is clear, but perhaps the arguments from security consultants are not always so consistent or logical. Most states have legislation that regulates the provision of security advice to paying customers through provisions for licensing or registration of security advisers. I am not aware of any legislation that specifies a “licensed security systems designer”! This article should not be construed as legal advice. It represents the personal opinion of the author who is a commentator on security risk management issues. Dr Kevin J. Foster is the managing director of Foster Risk Management Pty Ltd, an Australian company that provides independent research aimed at finding better ways to manage risk for security and public safety, and improving our understanding of emerging threats from ‘intelligent’ technologies.
022 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 22
21/06/2017 10:55 am
Contact us on 1300 364 864 Follow us on
Delivering Proven Solutions for Security & Safety We Protect People & Assets www.magneticautomation.com.au 012-031 SSM108 Regulars.indd 23
21/06/2017 10:55 am
REGULAR
LEGAL Beware The Power Of The Google Search By Justin Lawrence Google has become an incredibly effective research tool for business. It allows businesses to uncover information about current or prospective employees, suppliers and contractors that would have simply been unavailable several years ago. As employers are routinely using Google to do instantaneous background searches of prospective (and current) employees, the tide is also turning in the other direction. The reputations of businesses, business owners and high level management are increasingly being subjected to online attacks. It is estimated by some studies that up to 20 per cent of employees regularly submit comments on posts to blogs, forums and chat rooms. In the ‘old days’ reputations took many, many years of diligence, hard work and good service to establish. If a client had a bad experience, his ability to tell others about it was limited to those within ear shot. Now, one person with access to a computer can scuttle the hard-won reputation of a business by posting an account of his experience online, which can then be read by anybody at any location around the world. This, in itself, is a problem for business. As more and more people rely on Google as a source of information, the word of the nameless, faceless blogger is apparently given as much credence as any other source of ‘legitimate’ information. Some online publications are strictly controlled and legitimate. For example, after legal proceedings are issued, most courts
place details of those proceedings on their website portals for public access. Whilst specific details of each case are usually not published online, the name of the parties and the official steps that have been taken in the proceedings are published. This means that any court proceeding in which a party was involved is almost certain to appear in a Google search of that person’s name. Thus, an employer concerned about the character of a potential employee might be tempted to do a Google search to find out whether he/she has ever been involved in court action. Even then, there is no guarantee that full details of the allegations made by a party to that court proceeding will actually be available for public consumption. Sometimes judges make orders restricting the general public dissemination of information raised in court documents and in court hearings for protective reasons. Therefore, whilst a Google search might reveal the existence of a particular court case, it will often be that only a summary of the case is revealed. Without further detail, an employer might be unable to make an informed decision about the nature of the allegations in the case – was this person the victim of unacceptable workplace behaviour or are they simply a trouble maker searching for their next target? Of course the court file can be searched in an attempt to gain that information, but are most employers likely to go to that extent?
Much like many other sources of online information, court case details can often be found on the internet many months after the proceedings conclude. Any information found in a Google search should be checked against other reliable sources of information. If, through a Google search, an employer found out that a prospective employee had been involved in a court case against a former employer for unfair dismissal, that might be grounds for caution. At that point, the employer would be wise to undertake further enquiries, including old fashioned reference checks, to ascertain the overall suitability of the employee. While online information might be interesting – and to some extent useful – employers are well advised to proceed with caution. Ideally it should be used to complement existing sources of information, rather than being used as a substitute for it. Justin Lawrence is a partner with Henderson & Ball Solicitors, 17 Cotham Road, Kew, Victoria, and practises in the areas of Commercial Litigation, Criminal, Family and Property Law. Henderson & Ball has Law Institute of Victoria accredited specialists in the areas of Business Law, Property Law and Commercial Litigation. Justin Lawrence and Henderson & Ball can be contacted on 03 9261 8000. Whilst every effort has been taken to ensure its accuracy, the information contained in this article is intended to be used as a general guide only and should not be interpreted or taken as being specific advice, legal or otherwise The reader should seek professional advice of a suitably qualified practitioner before relyin upon any of the information contained herein. This article and the opinions contained in it represent the opinions of the author and do not necessarily represent the views or opinions of Interactive Media Solutions or any advertiser or other contributor to Security Solutions Magazine.
024 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 24
21/06/2017 10:55 am
Recognize and Analyze How often was he here this month?
Is he a known suspect?
How old is she?
Are they employees?
When, where did she enter?
Is this valued customer Mia Clark?
How many people are here? Is it too crowded in this area? New: Recorded media import and advanced investigation tools upload sets of videos recorded at a specific location and time to track possible participants in a crime find a person enrolled in an image database or search for an unknown person locate appearances in multiple videos make use of filters that specify timeframe, camera location, age range, gender and glasses
See it in action at Security Expo in Sydney, stand K26! 012-031 SSM108 Regulars.indd 25
21/06/2017 10:55 am
REGULAR
THINKING ABOUT
SECURITY Pro Bono U2 By Don Williams Pro Bono does not mean being a fan of the group U2. Rather, it is pro bono publico – for the public good – basically Latin for you are not getting paid. Why would people do unpaid work? There are a number of reasons – the main one being that without volunteers little would actually happen, particularly in the security field. All of the security industry and professional associations are run by volunteers. There may be the occasional paid administrative positions, but they are the exception. The work to raise the image of the security industry, set standards, increase professionalism, have recognised certifications and registrations, recognise the efforts and gallantry of security employees and to represent security to government is driven by volunteers. There are benefits to volunteering to be on a committee, but there are also significant responsibilities. The benefits include making things happen and being part of the forces for change. There is a profile that comes with being on the committee of an organisation; it looks good on a CV. In some cases, it adds to the continuous professional development requirements for certifications such as CPP. It provides the opportunity to meet and work with others, sometimes quite influential people on the committees and in the government, industry and corporate sectors. The responsibilities include having to do something. Far too many people join a
committee, discuss the issues, debate the options and consider the next step. Far fewer actually make things happen. And it can be hard work. Someone (a volunteer) has to arrange the meetings with government and external agencies, draft the newsletters, organise the seminars, take and publish the newsletters and seek the views of members and others. If lucky, people have to help draft policy and even legislation. Not only are volunteers not paid, there are real time and financial costs. Few organisations pay people to attend meetings, so travel and accommodation, if needed, come out of the volunteer’s pocket. Only the most enlightened of employers sees the benefit of having their staff working on committees of professional and industry organisations. For those that are self-employed, the time spent in improving the world through volunteering takes away from business time. It can be seen as soft marketing; it provides exposure to other views and people, some of whom are good business contacts and it puts volunteers in the centre of decision making and developing change. Unfortunately, it has been a truism for more than 2500 years that “when all is said and done – a lot more is said than done” (Aesop). The main problem is those who ‘say’ but do not ‘do’. Committees need people who will put into action the decisions made, often after much long-winded discussion. A technique that assists is to do the volunteer work fi st; the paid work will happen, but the
For those that are self-employed, the time spent in improving the world through volunteering takes away from business time. committee work will continue to drop to the bottom of the priority list. Get it out of the way and off the desk quickly. Is it worth being on a committee? Certainly. There is a huge sense of achievement when change is achieved and the society made a little safer or peers are a bit better provided for or respected because a group have achieved what was needed. You can make a difference but if you do offer to help, make sure that what you promise to do happens. If you will excuse the pun – volunteering to improve the security sector should be for U2. Don Williams CPP RSecP has provided managerial advice on security and strategic security analysis for 30 years. Don can be contacted via email donwilliams@ dswconsulting.com.au
026 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 26
21/06/2017 10:55 am
www.facebook.com/luminox
www.luminox.com
VIC 8th Avenue Watch Co., Emporium Melbourne, 03 9639 6175 | 8th Avenue Watch Co., Westfield Doncaster S/C, 03 9840 6304 8th Avenue Watch Co., Chadstone S/C, 9569 7652 | Temelli Jewellery, Highpoint S/C, 03 9317 3230 | Temelli Jewellery, Southland S/C, 03 9583 2633 | Temelli Jewellery, Westfield Knox City S/C, 03 9800 0799 NSW Lewis Watchmakers & Jewellers, Coffs Harbour, 02 6651 1612 | Melewah Jewellery, Haymarket, 02 9211 5896 | Vintage Watch Co., Sydney, 02 9221 3373 | Hennings Jewellers, Narellan, 02 4647 8555 WA The Watch Spot, Perth, 08 9421 1093 | Leon Baker Jewellers, Geraldton, 08 9921 5451 QLD 8th Avenue Watch Co., Pacific Fair S/C, 07 5575 4883 | Hatton Garden Jewellers, Beenleigh, 07 3287 1230 | Watch Tech, Brisbane, 07 3012 7023
012-031 SSM108 Regulars.indd 27
21/06/2017 10:55 am
REGULAR
EVENTS IFSEC International 20–22 June 2017 ExCeL London IFSEC International is the biggest security exhibition in Europe taking place over three days between 20 to 22 June 2017 at London ExCeL. IFSEC welcomes over 27,000 global security professionals to experience the latest technological innovations and hear from industry leaders – all under one roof, over three days. The event caters to everyone within the security buying chain from manufacturers, distributors, installers, integrators and consultants to end users. With over 600 exhibitors showcasing over 10,000 products, you will be able to find the perfect security solution your business is looking for. There’s more to it than just security. IFSEC International is co-located with FIREX International, Facilities Show, Safety & Health Expo and Service Management Expo, catered for those working across many platforms in building management and protection of people and information.
The new venue features a total of 35,000sqm of exhibition space presented in a smart, stacked layout to capitalise on the inner-city location and provide much improved loading facilities. Plus the halls feature customised registration and ticketing areas and dedicated meeting rooms. ICC Sydney will be Asia Pacific’s premier integrated convention, exhibition and entertainment precinct, underpinning Sydney’s position as one of the world’s most desirable meeting and event destinations. The entire team is looking forward to reuniting the industry once again in sunny Sydney where Security 2017 will connect more than 4,500 security professionals with over 150 leading suppliers. For over three decades the event has provided a showcase for new and innovative security technologies and solutions. Whether you are looking for a solution to protect your property, people or assets, the Security Exhibition & Conference provides the opportunity to discover the solution that is right for your organisation. Make sure you put 26–28 July in your diary; and we look forward to seeing you again in Sydney for the Security Exhibition & ASIAL Conference!
opportunity to discuss cyberthreat analysis, operations, research, and law enforcement to coordinate various efforts to create a more secure world. The ICCS 2017 serves as a platform for researchers and practitioners from academia, industry, and government to present, discuss, and exchange ideas that address real-world problems with CYBER SECURITY. The conference program will include special sessions, presentations delivered by researchers from the international community, including presentations from keynote speakers and stateof-the-art lectures and keynote speeches. Post Conference, all accepted papers will be reviewed for possible publication in the THOMSON REUTERS (eSCI) and/or SCOPUS indexed Journals with H index or impact factor.
j
v
`j
For more information visit www.iccs2017.iaasse.org
jv
`v
`jv
CIO Leaders Summit Australia 2017 6 September 2017 Sydney
h
Security Exhibition & Conference 2017 26–28 July 2017 International Convention Centre, Sydney
To register now visit securityexpo.com.au
In 2017 the Security Exhibition & Conference is heading back to Sydney to the brand new International Convention Centre. This stateof-the-art precinct overlooks beautiful Darling Harbour and is a short walk away from Sydney’s vibrant city centre.
3rd International Conference on Cyber Security 12 August 2017 Kota, India
The CIO Leaders Summit Australia is invitation only and intended for Australia’s most senior IT leaders to gather for a strategic event in order to exchange knowledge and interact as one over a range of important issues facing the industry. The one-to-one meetings with leading supplier companies will also provide a wealth of knowledge and offer opportunities for all attending delegates, while the informal networking sessions promise to create a unique interactive forum.
The International Conference on Cyber Security (ICCS) 2017 is an unparalleled
For more information visit cioleadersaustralia.com
For more information or to register please visit www.ifsec.co.uk
`
028 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 28
21/06/2017 10:55 am
`
j
v
`j
jv
`v
`jv
h
THE ALL-NEW TXF-125E BATTERY OPERA TED QUAD BEAM Introducing the eagerly anticipated TXF-125E; a high performance Quad Beam sensor designed for battery operation - perfectly suited for rapid deployment in creating temporary or permanent secure perimeter intruder systems. With 4 selectable frequencies, multiple beam sets can be used without crosstalk, whilst adjustable detection distance allows a single beam set to be re-deployed in a variety of installations throughout its operational life. Two 3.6V (17Ah) batteries power each unit for up to 5 years of service.
NE W!
AC TIVE IR BEAM S The ultimate in trouble free perimeter detection for distances up to 200m outdoor / 400m indoor.
+61 (3) 9544 2477
email: oz_sales@takex.com
HIGH -MO UNT PI R Triple mirror optics for maximum detection performance at 2 to 6m.
BEAM TOWE RS Rugged floor and wall mounted enclosures in 1/1.5/2/3m heights.
IND OOR PIR Spot, 360°, wide angle, and curtain detection from 2 to 4.9m height.
OU TD OOR PIR Hard-wired or battery operated outdoor PIR up to 180° x 12m .
1300 319 499 csd.com.au www.takex.com
TAKEX AMERICA
VIC: Mulgrave, Tullamarine NSW: Northmead, Waterloo ACT: Fyshwick QLD: Loganholme SA: Marleston WA: Balcatta 012-031 SSM108 Regulars.indd 29
21/06/2017 10:55 am
REGULAR
EVENTS CISO Leaders Australia Summit 7 September 2017 Sydney The CISO Leaders Summit Australia will highlight the emerging technologies that are leading the way and will examine current challenges that CISOs are faced with throughout 2017 and beyond. This conference will provide CISO professionals with a unique opportunity to learn and interact with their peers through a series of professionally led sessions hosted by both international and local experts, allowing all attendees the opportunity to be informed by front line executives while also having the opportunity to engage with a unique group of key suppliers through targeted prearranged meeting sessions. For more information visit cisoleaders.com.au
ASIS International Australia Conference Contemporary Security Leadership In Australia 19 October 2017 Melbourne The ASIS International Australia Conference 2017 is the premier gathering of security professionals. The conference provides an established platform for education and
business exchange, addressing the key trends and issues facing security professionals locally and globally. Key topics: • Terrorism • Cyber-Security • Behavioural techniques • Security Management • Emergency Management. The conference is a great opportunity to: • engage with peers and colleagues from the public and private sectors • join industry leaders accelerating the future of the security profession. Who should attend the event: • Security professionals across the public and private sectors • Security Risk Management professionals • Security service providers • Security consultants • Government and law enforcement professionals. For more information contact events@asisvictoria.org.au or visit www.asisvictoria.org.au
The 2017 Australian OSPAs 19 October 2017 The River Room Crown Casino, Melbourne The Outstanding Security Performance Awards (OSPAs) are pleased to announce the date for the 2017 Australian awards. They will be working for the third year in a row with the prestigious, Australian Security Industry Association Limited (ASIAL). The Outstanding Security Performance Awards (OSPAs) recognise and reward companies and individuals across the security sector. The OSPAs are designed to be both independent and inclusive, providing an opportunity for outstanding performers, whether buyers or suppliers, to be recognised and their success to be celebrated. The criteria for these awards are based on extensive research on key factors that contribute to and characterise outstanding performance. Aspiring to Excellence, a Security Research Initiative report conducted by Perpetuity Research. The OSPAs are being setup in collaboration with security associations and groups across many countries. By researching and standardising the award categories and criteria, the OSPAs scheme provides an opportunity for countries to run their own evidence-based OSPAs schemes while maintaining an ability to compete on an international level in the future, ‘World OSPAs’. For more information or to make a nomination, simply visit au.theospas.com
030 SECURITY SOLUTIONS 012-031 SSM108 Regulars.indd 30
21/06/2017 10:56 am
26-28JULY JULY2O17 2O17 26-28 ICCSYDNEY SYDNEY ICC DARLING HARBOUR DARLING HARBOUR
THE INTELLIGENCE OF SECURITY The Security Exhibition & Conference returns to Sydney this July to reunite the industry for three days of business networking and intelligence sharing. Offering inspiration and innovation to tackle your security challenges, you can compare solutions from leading suppliers whilst learning from the experts and connecting with your industry peers.
REGISTER FREE ONLINE AND ENTER PROMO CODE: SEC1 SECURITYEXPO.COM.AU
PRINCIPAL SPONSOR
012-031 SSM108 Regulars.indd 31
LEAD INDUSTRY PARTNER
ORGANISED BY
21/06/2017 10:56 am
INTO THE
WILD BLUE YONDER 032 032-035 SSM108 Article 1.indd 32
20/06/2017 5:23 pm
By Garry Barnes
Is drone technology right for your business? Factors every organisation should consider before flying into the great unknown.
Australian public and private organisations across a myriad of sectors are currently investigating and embracing the technological and competitive benefits of using remotely piloted aircraft called unmanned aerial vehicles (UAVs), or drones. Goldman Sachs (Drones: Reporting for Work) predicts that Australia’s drone spending will be an estimated US$3.1 billion between 2017 and 2021. And Australia’s Civil Aviation Safety Authority (CASA) estimates there are currently over 1,000 registered commercial operators.
033 032-035 SSM108 Article 1.indd 33
20/06/2017 5:23 pm
While the US and Europe currently lead enterprise use of UAVs, Australian businesses have been quick to capitalise on the benefits of the technology. Some examples of how organisations are implementing drones as strategic tools include: • pipeline security, management, maintenance, survey • land survey, mine exploration • real estate sales • package delivery • livestock/range management • film making • environmental management, such as surfing conditions, bushfi e management and wildlife conservation • underground sewer, power and utility maintenance and safety inspection • general security surveillance (private residences, corporate offices, public spaces). Along with the numerous benefits comes the need for organisations to review legal and regulatory issues around airspace, privacy, security and safety in order to protect the business and individuals. In 2013, a drone flew
into a car on the Sydney Harbour Bridge. In 2014, an athlete competing in a West Australian triathlon event was injured by a drone being used to film the event. The Australian Transport Safety Bureau noted that accidents involving drones grew from 14 incidents over eight years from 2006–2013 to 37 in just one year from 2014–2015 (West Australian News, Jan 2017). There are also implications that UAVs could be used for terrorist activities. In September 2016, CASA implemented new regulations for both personal and commercial use of drones. CASA now categorises commercial use, or using the drone for hire or reward, in two categories: a) small drones (under 2kg) – operators can now work without an operator’s certificate but still require a once-off registration b) large drones (over 2kg) – operators must be registered and apply for the Unmanned Aircraft Operators Certificate, which can cost between $5,000 and $10,000. These regulatory changes have largely been viewed as a relaxing of the rules, but whether operating small or large drones, organisations still need to be aware of and act in accordance
with CASA’s legal requirements and consider the business implications (regulatory, financial and safety) before deploying drone technology. Specifically, is the organisation ready to operate an aviation department? In March, ISACA issued a white paper entitled Rise of the Drones: Is Your Enterprise Prepared? which presents detailed questions and scenarios that management should answer when contemplating whether drone technology is right for their organisation. Key questions include: 1. Is running an aviation operation in line with the organisation’s mission? Core business? Capabilities? 2. Are uses of the enterprise’s UAVs consistent with the company’s ethics policy? 3. Is the business prepared to operate and manage an internal aviation department? Is the organisation ready to assume the responsibilities of flight operations? Has the organisation identified all the complexities and challenges of operating an internal certified flight operations function? 4. What added risk and liabilities will the organisation encounter once it establishes an aviation function/department and who
034 032-035 SSM108 Article 1.indd 34
20/06/2017 5:23 pm
6. How is UAV technology classified within the enterprise? Is it IT? Is it operations? 7. What procedures exist to attest that any organisational use of UAV technology: (a) is legal; (b) is authorised and approved by executive management; (c) is conducted according to established operational protocols; and (d) meets or exceeds legal compliance requirements? 8. Will the company be able to immediately comply with any legislation and regulations for the safe and proper operation of its UAV fleet? 9. Does the organisation maintain a policy for acceptable use of UAV technology? If not, does the absence of such a policy represent a potential liability to the organisation? 10. Does the organisation maintain appropriate levels of insurance, covering the operation, maintenance, storage and security of the UAV and its related technologies?
Privacy and Security
is responsible for all of the compliance requirements associated with this function? How is this risk expected to be mitigated? 5. Who is responsible for assessing and authorising applications of the drone technology to specific business usages/purposes?
In addition to preparing the business case and organisational risk analysis for using drone technology, organisations should also consider the potential privacy and security issues. CASA stipulates personal privacy should be respected, and outlines height and proximity rules. However, there is currently very little legal recourse. Government agencies, such as the Commonwealth House of Representatives and Senate Standing Committee on Rural and Regional Affairs and Transport, have called for more legislative regulation, ranging from updating
the Privacy Act, to requiring manufacturers to provide educational brochures regarding individuals’ privacy rights. The Australian Law Reform Commission recently called for a “tort of privacy” to be written to guard against intrusions and allow individuals to sue for damages. Australian courts have currently rejected the recommendation, although this may change as more drones are purchased for recreational and commercial use. Other countries have already incorporated remotely piloted aircraft into their privacy laws. Organisations also need to ensure their security measures adequately protect data gathered from the drone, and guard against unauthorised access of the on-board technology, programming and recording equipment. Processes and procedures also need to be drafted and adhered to for decommissioning drones, including purging sensitive data.
“In September 2016, CASA implemented new regulations for both personal and commercial use of drones.” In conclusion, an organisation’s decision to incorporate drone technology into the business means establishing and operating an aviation department within its business operations. Outsourcing this activity to a third party does not necessarily discharge the organisation from the responsibility to ensure that compliance is maintained and appropriate controls are in place to mitigate the risk. Poised to enable a tremendous leap forward in information collection and knowledge transfer, UAVs can bring enormous competitive, safety, financial and research benefits to enterprise. However, if not properly controlled, monitored and implemented, they can also lead to significant and potentially disastrou unintended outcomes. Garry Barnes is practice lead, Governance Advisory at Vital Interacts (Australia). He has more than 20 years of experience in information and IT security, IT audit and risk management and governance, having worked in a number of New South Wales public sector agencies and in banking and consulting.
SECURITY SOLUTIONS 035 032-035 SSM108 Article 1.indd 35
20/06/2017 5:23 pm
ALARMS
ONVIF:
The Evolution of A Standard
036 SECURITY SOLUTIONS 036-039 SSM108 Alarms.indd 36
20/06/2017 5:33 pm
has become a nearly 500-member strong organisation with more than 7,500 ONVIFconformant products in the market today. With members on six continents, ONVIF’s specifications for video and access contro have also been adopted by the International Electrical Commission (IEC), one of the world’s most influential standards organisations Not bad in eight years. Like many other standards, ONVIF has evolved incrementally and its development, use and acceptance have as well. The journey ONVIF is on is quite typical for a standards organisation. Other standards such as IEC, the Institute of Electrical and Electronics Engineers (IEEE), HDMI and Bluetooth have experienced similar ebbs and flows, hurdles, successes and acceptance in many of the same ways that ONVIF has. Over time, these organisations have expanded the scope of their standards, changed their approaches to standardisation when needed and have dealt with issues of false conformance, just as ONVIF has.
Building a Foundation
By Per Björkdahl ONVIF has achieved a lot since its founding in 2008. The member consortium began as a small group of manufacturers that wanted to collaborate to accelerate the acceptance of systems based on network surveillance cameras. While ONVIF’s mission has not changed significantly since then, its applicatio and influence has; it is now an industry allianc for the physical security industry. ONVIF
Standards organisations are often founded to create, at least initially, one specific kin of benchmark within an industry. ONVIF was founded by Axis, Sony and Bosch to create a global standard for the interface of network cameras and video management systems to be an alternative to the very much standardised analogue CCTV industry. The organisation sought to provide greater freedom of choice so installers and end-users can select interoperable products from a variety of different vendors. By establishing a basic standard for video in its early days, the founders also hoped to simplify product development for manufacturers. The philosophy was that establishing a basic integration standard within the industry would allow developers to spend more time on creating innovative features and designs and less effort on creating multiple application programming interfaces (APIs) for simple integrations between products. Even in its early days, ONVIF made some significant achievements, most notably by creatin and releasing its first specification soon aft its founding. When the first specification w deployed for real-world use, ONVIF realised it had to make some adjustments to its approach to creating a standard. Although members had agreed on how to specify APIs for video, the way the manufacturers actually deployed these in their products varied. All were following the
specification, but there was no agreement o which features to support. For example, a camera manufacturer may have only implemented specific video functions to interact with anothe manufacturer’s video management software (VMS) using ONVIF, but that particular VMS supports many additional functions of that camera. So, when users of the VMS expected to be able to utilise a specific function in th camera, it was not supported through ONVIF; all of which gave room for some doubts regarding the usability of the standard.
Why ONVIF Standards Matter to Integrators A common interface allows integrators to use technologies from different manufacturers together. This concept of designing devices to work with other brands or technologies is often referred to as interoperability. Interoperability typically equals a reduction in the time spent on the design and installation process, both in current and future installations or upgrades. From the end-user side, the benefit is freedo of choice. Using ONVIF-conformant products prevents end-users from being locked into using solutions from a single manufacturer and being tied to that manufacturer for years to come.
A Broadening Vision Less than a year after ONVIF was founded, members began to develop the profile concep to address the variance in supported features between manufacturers. The advantage of the profile approach was that a number of feature and implementation specifics could be defin under one umbrella and with greater specificit . The idea was that if manufacturers developed products in accordance with the profile, thei products would work together regardless of the manufacturer of the VMS or camera. ONVIF’s first profile, Profile S, was relea in 2011 following two years in development. If a product is Profile S conformant, i will always be conformant, regardless of when it is manufactured. Bluetooth experienced a similar chain of events when it introduced an updated version of its specification for headsets in 2005. Bluetooth s new version of the specification for headset did not initially support an older version of the specification and, as a result, conforman devices could not always communicate. Because of this, Bluetooth introduced Headset Profil (HSP), designed to work regardless of when the device was manufactured. Once HSP was
SECURITY SOLUTIONS 037 036-039 SSM108 Alarms.indd 37
20/06/2017 5:33 pm
ALARMS security industry. In addition to Profiles S and Q ONVIF has continued to use the profile concep to develop and release four additional profiles Profile G for video storage, Profiles C and A f access control, with Profile T to follo .
Collaboration Between Standards Standards bodies and the standards they create cannot operate independently – today’s world demands cooperation and collaboration. As the demand for interoperability between all devices increases and the concept of the Internet of Things becomes a reality, standards groups must work together on standards themselves. ONVIF and the IEC are working together in this collaborative way. The ONVIF specification ha been included in the international IEC 62676 standard, the first international standard fo video surveillance systems. defined, it was not to be changed. A new profi with a new name was created when future changes were needed, which is the same profil approach that ONVIF employs. Changing the specifications of a product can b a long process, but development of a new profil can happen rather quickly and lets ONVIF and other standards adapt as market and member demands change. Adaptability is paramount to maintaining real-world, usable standards and is an integral part of maintaining relevant standards across industries. An example of this can be illustrated with ONVIF’s Profile S and an ONVIF profile that currently in development. Profile S was released i 2012 to include support for pan, tilt, zoom (PTZ), audio and metadata streaming, and relay outputs on devices; it also encompassed configuration requests and control of streaming video data over an Internet Protocol (IP) network by a client. Profile S bridged the gap between conforman clients and devices on a basic level. In the four years since the release of Profil S, video technology has changed. To address new developments in video technology, ONVIF will introduce Release Candidate Profile , which employs a new media service that enables the support of H.265 video compression. Once the new video profile is released, Profile S will mo likely lose significance over time – both profil will be in circulation, as not all products in use will necessarily employ H.265 compression standards. Profile S conformant devices and clients therefore, will always be Profile S conformant independent of the new video profile. Th
Release Candidate Profile T will be circulated t stakeholders for at least six months before being released in its final form
Profile Profile Q, one of ONVIF s newest profiles, i especially relevant to system integrators. The two main features of Profile Q are easy set-u and advanced security features. Profile makes configuration and the use of advance security features easier. With an easy set-up mechanism and basic device level configuration, Profile manufacturers have ONVIF automatically enabled for products that are Profile Q conformant. Fo the integrator, that means time saved, because the installer does not need to activate ONVIF or search for instructions on how to do so. Profile conformant devices are also easily discovered and feature factory reset functionality. Profile Q supports ransport Layer Security (TLS), the widely used cryptographic protocol that is designed to provide communication security. TLS uses certificates and asymmetri cryptography to authenticate the data transferred between parties. TLS protocol allows Profil Q to manage certificates and keys on ONVI devices themselves. Once set up, Profile devices and clients can communicate across a shared network without being vulnerable to tampering and eavesdropping. Profile Q is just one example of how th framework established on ONVIF’s formation has enabled the group’s scope for standards to include any discipline within the physical
Members Matter ONVIF and other standards groups are member-driven organisations that operate on the basis of consensus. The next ONVIF profile will be developed based on feedbac from ONVIF members and the physical security industry at large. It is important to note that ONVIF is not only for manufacturers. ONVIF values input from all stakeholders, which is why it has developed four different membership levels that are geared to manufacturers, consultants, integrators, specifiers, end-users, installers, member of the media and those outside the physical security industry. Input from across the industry and beyond is needed to continue to produce meaningful and effective standards.
The Future By examining the evolution of other standards, it is obvious how vital they are to industries, often beginning with a relatively small focus on one specific market and expanding to includ others as acceptance and use grows. It is hard to predict if ONVIF will follow a trajectory similar to other standards like IEC. It is safe to say, though, that wherever ONVIF goes in the future, its path will be determined by its members and the physical security community, who ultimately are together at the helm, driving ONVIF forward as new technology develops and evolves. Per Björkdahl is the chairman of the Steering Committee for ONVIF.
038 SECURITY SOLUTIONS 036-039 SSM108 Alarms.indd 38
20/06/2017 5:33 pm
TR
OR
036-039 SSM108 Alarms.indd 39
HÉE D’ OP
20/06/2017 5:33 pm
INTELLIGENT PUBLIC SAFETY Brains Over Brawn
040 040-043 SSM108 Operations.indd 40
20/06/2017 2:20 pm
By Richard Kay The operational environment can be a dangerous place, with interpersonal conflict and violence being very real potential risks to officers as well as the public. Officers require practical solutions to resolve situations and confrontations, and that requires the ability to act from the basis of a planned approach involving strategic thinking. To teach officers how to act, it is important to teach them how to think and, to do that, instructors must develop officers’ problem-solving skills early in the training process. Nowhere is this more relevant than in operational safety training. Common issues experienced by new officers often include aspects like a failure to perceive danger, failure to make decisions and the inability to problem solve, which may be a result of technique-based training. Solution-based operational safety training is less concerned with an exact technique and places more emphasis on pattern recognition, decision making and problem-solving tactics. This is similar to contemporary fi earms instruction which is more concerned with accurate fi e than with any particular posture officers may take. To accelerate officer skill development, once they understand the fundamental concepts of a tactic, technique or procedure, they quickly depart the sterile training room and move to more realistic environments to practise. This training approach is reinforced via results from an agency research project. Due to an overly large group size, operational safety training was split into two separate days. One group of officers performed numerous blocked and constant practice repetitions of techniques strictly in a gym environment. The second group had far fewer repetitions of the same techniques, but they occurred in a random and variable manner while interspersed with combative skills in operational environments. The second group spent considerable time practising their skills in scenario-based experiences. Whilst the split-approach training was not a scientifically controlled experiment, the outcome was interesting and showed results that would not surprise cognitive and sports psychologists. During skills testing in the mid and final assessment periods, both groups performed similarly. However, during scenario testing where officers were required to perform in a situational environment with role players under
041 040-043 SSM108 Operations.indd 41
20/06/2017 2:20 pm
in detail how an instructor performs improves an officer’s ability to reproduce those skills. The power of excellence modelling has been understood for several decades, provided officers are paying attention and are interested in what is being demonstrated. Instructors need to get the officers’ attention by making them understand the life-saving value of the skills they will be learning. Then, their interest must be maintained by providing scientifically validated and challenging training. To develop long-term memory, motor programs and problem-solution schematics, the science of cognition and motor skill development should be incorporated into training. The learning experience should be structured in accordance with contemporary principles of motor learning and performance. Skills can be practised in blocked, variable, constant or random patterns, or some combination thereof. Studies have demonstrated that for both cognitive and motor skill training, a schedule of variable and random practice proves more effective for longterm skill retention.
Training Methodology circumstances that were tense, uncertain and rapidly evolving, officers that had been exposed to less rigid, open-skill, novel and solutionoriented training generally fared better.
Operational Relevance Officers want to know the why of what they are being taught and how that applies to what they will be doing with that information on the job. They bring mature reasoning skills to the learning environment, so instructors must stimulate officers to use those reasoning skills as soon as possible in training. Telling an officer how to perform a task without establishing the relevancy of the task to job application is indoctrination without context. Relevancy means understanding context. Content still needs to be taught – how to perform a search, how to apply a pair of handcuffs and so on – but there are numerous ways to accomplish this and instructors should avoid being overly rigid about technique. If officers modify a technique and get the job done in a safe and effective manner, then they have succeeded in that task. One method to demonstrate relevancy is to incorporate problem-based learning exercises when possible. For instance, direct
them to perform a task without instruction (for example, handcuffing or searching) and ask them to develop a solution. This accomplishes a couple of things. First, officers are required to actively problem solve and think of possible solutions. Next, the motivation factor is included as officers quickly realise that even simple tasks often are not. Once they see that applying handcuffs is not an effortless task, or finding a hidden weapon on subjects can be quite difficult, they will understand the personal relevance. Simultaneous to developing their attention, interest and motivation, instruct officers in the strategies, concepts and tactics that are universal to subject control and officer safety. A training cycle familiar to many is the emphasis on demonstration, explanation, repetition and simulation. Mirror neurons will influence how officers perform a skill. Their mirror neurons are activated when they observe a physical skill or problem-solving strategy being demonstrated. The study of mirror neurons suggests profound implications about how officers need to be trained. Modelling ideal behaviour in the demonstration phase is an important component of teaching. Through the impact of activated mirror neurons on the brain, watching
Blocked practice is a sequence in which officers work on a single skill for multiple repetitions before moving on to the next. In random training, officers minimise consecutive repetitions of a task and intersperse it with the practice of multiple tasks during the same practice period; skills are practised in no particular order. While it may seem intuitive to master a skill before moving to another, experiments have established that practising in a random manner more effectively develops long-term retention of the material. Officers learning new skills most likely need some blocked practice before moving to random practice. The extent to which officers remain in the blocked schedule depends upon innate individual traits, prior knowledge, motivation, attention and, most importantly, the simplicity or difficulty of the task. Instructors can influence most of these variables by structuring training in an efficient and effective manner, utilising motivating coaching skills and minimising the cognitive load of the material by simplifying the tactics, techniques and procedures taught to officers. As soon as officers have a fundamental understanding of how to perform a technique, random practice should be incorporated.
042 040-043 SSM108 Operations.indd 42
20/06/2017 2:20 pm
Officers may feel more comfortable practising a single skill for multiple repetitions believing that they are beginning to get it, and may become frustrated when just at that point instructors move on to another task. Since officers have a need to understand why they are doing what they are doing, instructors should explain the science of motor skill development to mitigate that frustration. To improve officers’ problem-solving and adaptability skills, tasks should be practised in a variable manner. Variability refers to practice sequences that introduce a number of variations of a particular skill during a training session. Variation refers to both surface features (context) as well as structural features (content) of tasks. Since the ultimate goal of instruction is the transfer of skills from the learning environment to the real world, content and context of a task should be practised in reality-based surroundings. An example is teaching handcuffing. In a constant practice regimen, officers perform their instructed handcuffing technique in isolation. They learn a single method for applying handcuffs with no problem-solving or environmental challenges. In fact, they may be required only to apply the handcuffs from a single approach angle. Sterile practice in a gym environment is not realistic training. Problem-solving scenarios in real-world environments (specificity of learning principle) must be incorporated into practice sessions in order to prepare officers for the real world. Instructors can promote this realistic training by varying task requirements. First, ensure that officers are forced to practise their handcuffing technique from various approach angles and know how to apply the technique to either hand. This would be an example of context variability, since the underlying procedures to accomplish the task remain the same. Then vary the content by changing the environmental considerations. Using 3-dimensional training environments such as hallways and Sim-houses, officers discover that techniques they learned in a sterile gym area do not translate to confined spaces, operating from behind cover, or in cluttered rooms where backup officers cannot attain a perfect cover position. Incorporating a problembased learning precept, officers are encouraged to develop options to adapt their initial training to solve the current problem in the more realistic environment.
Some officers can discover practical answers to handcuffing in a more realistic environment. Instructors should be looking for solutions that are reasonable and satisfactory, not operationally perfect. Other officers discover that the cognitive load of developing problem solutions is too great and interferes with learning. At any stall point in learning and problem solving, instructors should use one of several coaching strategies to further the instruction, such as worked examples, part problem solving, prompts, hints, inquiries or direct instruction.
Skill Development Public safety work involves open skills, or skills that are performed in an environment that is unpredictable or in motion and that requires officers to adapt their actions in response to dynamic properties of the environment. Many instructors train officers in a manner that is consistent with closed skills, or skills performed in predictable and stationary environments that allow officers to plan their actions in advance, and far from the real-world environment of operations. A by-product of a random and variable training model in an open-skill environment is a level of stress adaptation. The impact of closed-skill training has been measured by asking officers to self-report on their experiences. Officers assigned to closed-skill, constant and blocked training methodology state that they felt less prepared and more stressed about scenario testing during academy training, became bored and did not feel challenged during training due to the monotony of the more-reps instructional strategy, had difficulty transferring their gymbased theoretical knowledge into the practical knowledge needed for scenarios, and felt less confident in their ability to improvise and adapt to operational situations that they expect to encounter on the job. Blocked and constant training works best for short-term memory retention. If the desired outcome is to teach officers a skill one day that will be tested on the next, then have officers perform mass repetitions of the skill. If the goal is to develop a skill to be retained for many years, such as operational safety, then apply variety and randomness to the training cycle. New material is quickly forgotten if not reinforced, so review time should be strategically incorporated in practice schedules. High-risk and high-frequency skills needed by officers
are more readily retained with frequent and short practice sessions distributed throughout training. Start training sessions with a review of the tasks most frequently performed by officers. After breaks, review new material that was presented in the previous instructional block. Performance rapidly improves with this strategy, as does officer interest, confidence and motivation. With appropriate skill modelling and application of the scientific principles of adult learning and motor skill development, instructors can demonstrate relevancy, motivate officers to take responsibility for learning and develop their ability to transfer skills to different situations. By developing and applying simulations to the learning cycles, officers develop a problemsolving attitude and have an opportunity to adapt to the stressors presented in the event.
“Officers want to know the why of what they are being taught and how that applies to what they will be doing with that information on the job.” To develop the problem-solving operational safety skills of officers, agencies should deliver content while remembering that it is equally important to set context. Transition training from the gym to hallways, stairs and vehicles, set up scenarios that challenge officer skills early, and make the scenarios realistic and solvable. Instructors should guide officers to an acceptable resolution, not demand a preprogrammed solution – they are not going to be there on the job to assist them. Agencies should teach officers how to problem solve – how to think – and be confident that they have given their officers the best training upfront to prepare them properly for operational reality. Richard Kay is an internationally certified tactical instructor-trainer, director and senior trainer of Modern Combatives, a provider of operational safety training for the public safety sector. Visit www.moderncombatives.com.au for more information.
043 040-043 SSM108 Operations.indd 43
20/06/2017 2:20 pm
CCTV
ABOUT PIXEL
DENSITIES AND WHAT THEY MEAN
044 SECURITY SOLUTIONS 044-047_SSM108 CCTV.indd 44
20/06/2017 2:22 pm
By Vlado Damjanovski An Internet Protocol (IP) surveillance system is most often used to observe and protect people, objects and people’s activity inside and outside the objects, traffic and vehicles, money handling in banks, or games in a casino environment. All of these objects of interest may have different clarity when displayed on a workstation screen. The image clarity depends primarily on the camera used, the imaging sensor, its lens and the distance from the object. In a typical installation, once all cables are run, IP addresses allocated to the cameras and recorders, and the system is running, installers would then position the cameras and set the lenses for focused and sharp images. Most often, the choice is the widest possible angle of view (shortest focal length of the lens) and then the installer would focus the image, whether that be manually or automatically, set the optimum recording parameters and complete the installation. There is nothing wrong with this approach if the images are sharp and clear and the customer is happy with it. Very little attention is given to the clarity of the key objects for the given field of view, where clarity refers to the object size and the ability to recognise a person, a number plate or money, for example. Clearly, the closer the objects are to the camera, the easier it would be to identify an intruder and vice versa.
However, there is a better and more scientific approach. There is one parameter in IP CCTV that expresses the image clarity in a simple way – pixel density. The pixel density is usually expressed in pixels per metre (pix/m), at the object plane, although it can be expressed in pixels per foot. Pixel density in an IP CCTV sense should not be confused with the display pixel density quoted by various LCD display manufacturers, which defines the screen density in pixels per inch (PPI). The advantage of expressing object clarity with its pixel density is that it combines the sensor size, pixel count, focal length and distance to the object in just one parameter. When using pixel density metrics, all variables are included and the details on an operator’s workstation screen will be universally understandable. When designing a system, or a tender for a system, one can request pixel density for a particular image quality. So, instead of asking for a 6mm lens for a camera in a particular location for example (which means nothing without knowing the camera sensor it is used on), it would be much more useful if a particular pixel density is defined for the view. This will then be used to calculate the required lens for the camera used and the distance from the object. This will guarantee the clarity of the
SECURITY SOLUTIONS 045 044-047_SSM108 CCTV.indd 45
20/06/2017 2:22 pm
CCTV
“The advantage of expressing object clarity with its pixel density is that it combines the sensor size, pixel count, focal length and distance to the object in just one parameter.” image (assuming the lens is focused optimally and there is sufficient light, of course). Pixel Densities for Different Objects Pixel density can be used for any object that an IP CCTV user might be interested in: face, licence plate, playing card, money and similar. One of the most commonly referred pixel densities is for face identification. Face identification in CCTV means sufficient clarity of the image so that one can positively identify who the person on the screen is. According
to Australian Standard AS 4806.2, for face identification in analogue CCTV, 100 percent of a person’s height is required to fit on the monitor screen display. This has been tested many times and has been verified to be sufficient for identification. A PAL signal is composed of 576 active TV lines so, according to AS 4806.2, a person’s height would occupy all of the active lines to make it 100 percent. The head occupies around 15 percent of a person’s height, which is equivalent to around 86 lines (576 x 0.15 = 86.4), which is the same when converted to
046 SECURITY SOLUTIONS 044-047_SSM108 CCTV.indd 46
20/06/2017 2:22 pm
pixels (assuming recording is made in full TV frame mode, which is equal to two TV fields). Assuming that an average person’s height is 170cm, the head would occupy around 25cm of that. The pixel density at the object, which is required to make a positive face identification according to AS 4806.2, can be calculated to be 86 pixels at 25cm of head height. Since there are four times 25cm in 1m of height, this becomes 4 x 86 = 344pix/m. So, one can say that with a pixel density of 344pix/m at the object’s plane, it should be possible to positively identify a face, according to AS 4806.2. Some other standards may require different values, and one such (newer) standard is the IEC 62676-4, which defines 250pix/m to be sufficient (that is, it suggests that identification of a person is possible with a slightly lesser pixel density than the AS standards). Clearly, this number is not fixed in concrete and it will depend on the observing ability of the operator, as well as other parameters (lens quality, illumination, compression artefacts and so on), but the key is to understand that such a pixel density can be calculated for any type of camera, irrespective if that is SD, HD, 4k or any other format. The next image quality down, as defined by the standards, is for face recognition. The details of a face recognition image should be sufficient to recognise the gender of a person, what he/she is wearing and possibly make an assertion of who that person might be, if picked from a group of people that have already been identified somewhere else (for example, from a passport or drivers licence photo). This is basically an image with half the pixel density of the face identification, which according to AS 4806.2 should be around 172pix/m, while IEC 62676-4 suggests 125pix/m. Similarly, pixel density can be defined for visual recognition of vehicle licence plates (not software automatic licence plate recognition). In AS 4806.2, this is defined as five percent of the character’s height on a display screen, which is around 30 TV lines (pixels; to be very
accurate, 576 x 0.05 = 28.8). Assuming that a typical Australian number plate has characters of around 90mm in height, then this equates to 11 x 30 pixels = 330pix/m. The number 11 is obtained from dividing 1000mm (1m) with 90mm. Visual licence plate recognition requires a similar pixel density as for face identification. When money and playing cards are observed in banks or casinos, many practical tests have shown that at least 50 pixels are required across the longer side of the notes or cards in order to positively identify the values. According to ISO216 standard, the dimensions of standard playing cards are B8, which is 62mm x 88mm. So, the 88mm card length needs to be covered with at least 50 pixels for proper identification. This means around 550pix/m (1000mm/88 mm = 11 => 50 pix x 11 = 550pix/m) should be sufficient for playing cards. A slightly better pixel density may be required for identifying money, since the size of notes is typically larger than playing cards, so using the face inspection pixel density of 1000pix/m should attain good
identification, although as it can be seen from the real-life example in Figure 5, even 770pix/m might be sufficient. As it can be concluded from the above examples, the pixel density can be defined for any object and any camera, large or small. The beauty of the pixel density parameter is, as said at the very beginning, that it includes all parameters influencing the clarity of the observed objects. For this reason, ViDi Labs has developed the ViDiLabs iOS calc (search ViDiLabs calc in the iTunes App Store), a unique tool for the surveillance industry, which can also be used in cinematography, photography and any other imaging application dealing with object details. The table below can be used as a rough guide for various pixel densities: Vlado Damjanovski is an internationally renowned CCTV author, lecturer, innovator and consultant. He can be reached via his company website www.vidilabs.com
OBJECT
MINIMUM REQUIRED PIXEL DENSITY (PIX/M)
Inspect (IEC-62676-4)
1000
Face identification (AS 4806.2)
350
Face identification (IEC 62676-4)
250
Face recognition (AS 4806.2)
175
Face recognition (IEC 62676-4)
125
Observe (IEC 62676-4)
60
Intrusion detection (AS 4806.2)
35
Detect (IEC 62676-4)
30
Licence plate visual identification (AS 4806.2)
300
Playing cards
500
Casino chips (39mm)
1200
Money (notes)
800
Money (coins)
1500
SECURITY SOLUTIONS 047 044-047_SSM108 CCTV.indd 47
20/06/2017 2:22 pm
BUSINESS
RISK IS THE NEW RISK PARADIGM
048 SECURITY SOLUTIONS 048-051_SSM108 Business.indd 48
20/06/2017 2:22 pm
By Tony Charge
In Issue 102 of Security Solutions, (June 2016) an article was published around Risk Management which related to work the Australian Risk Policy Institute (ARPI) is doing in the complementary but separate space of Risk Policy. In response, I would like to take this opportunity to elborate on the subject and inform readers about the difference and benefits of Risk Policy, not only to the security profession, but generally to leadership as well as other business professions. APRI was founded in response to a call by the World Economic Forum, to revise and enhance risk management to provide greater benefits in decision-making at higher organisational levels and earlier in decision making process. More often than not, risk management advice is reactive, later than optimal and sometimes does not get to key decision-makers either at all or unfiltered. The Global Financial Crisis was just one example of this type of situation. ARPI is an independent and not-for-profit organisation aimed at senior professionals, with the specific aim of developing and publishing material around the need for paradigm change in leadership and risk. More specifically, our focus is on the need for strategic action earlier, and at executive/decision-making levels, addressing ‘vulnerabilities’ or potential risks. In the case of Risk Policy, the focus is on the response required to protect against vulnerabilities while often also generating
SECURITY SOLUTIONS 049 048-051_SSM108 Business.indd 49
20/06/2017 2:22 pm
BUSINESS • Ensuring that risk is now a trilogy of operations – risk policy, risk management and risk governance – the three arms being inter-dependent.
Risk Policy is thus designed to operate before risk management is involved, and is intended to actually inform and authorise the process of risk management
strategic opportunities, rather than in the case of risk management where the focus is often around waiting to identify and manage actual risks. Risk Policy is thus designed to operate before risk management is involved, and is intended to actually inform and authorise the process of risk management, and head a new ‘risk trilogy’ comprising risk policy, risk management and risk governance. ARPI enjoys engagement with all sectors of society, including an academic partnership with the Australian National University as well as a range of partnerships and relationships with peak professional bodies and in the public, corporate and community sectors. Word has spread globally and the creation of affiliated Risk Policy Institutes has begun with the European Risk Policy Institute (ERPI) in full stride across Europe. The ERPI will convene the fi st Global Risk Policy Conference in September 2017. A call for special purpose Risk Policy Networks resulted in the creation and successful operation of networks at a senior level in the areas of security, cyber security, complex project management, fraud, counterfeiting and anti-money laundering. Leading security identity, Jason Brown, National Security Director of Thales Australia, is the inaugural convenor of the Global Security Risk Policy Network. ARPI’s Risk Policy Model 2016 is freely accessible at www.arpi.org.au – not to be confused with a further publication titled Strategic Risk Policy (to which your previous article refers) which supplements the Risk Policy Model
especially to help risk management practitioners develop a better understanding of Risk Policy. The essence of Risk Policy, promoting paradigm change by leaders, is as follows (full details are contained in the Risk Policy Model): • Viewing the environment in ‘whole systems’ comprising (horizontal) networks and no longer living in (vertical) silos – nations, governments and organisations; • Paradigm change to a network-centric approach rather than the former organisation-centric approach; • Appreciating that in today’s interconnected world (like never before), information resides in networks; • Mapping stakeholder networks has become a critical exercise and source of information to identify strategic vulnerabilities (i.e. potential risks) plus consequential opportunities; • Obtaining the right information at the right time on the right matter from those networks – possibly through formal protocols where required e.g. confidentiality, privacy, etc; • Protecting against vulnerabilities will result in fewer and lesser risks to manage; • Recognising and engaging both internal and external networks; • Changing leadership paradigm so that Risk Policy authorises and informs risk management; • Articulating a Risk Policy Statement – e.g. defining and measuring risk appetite and tolerance; and
Two critical areas where ARPI considers improvement in risk management is needed are: 1. Recognition, identification and different treatment of ‘Systemic’ risks having multiple legal ownerships requiring plural, formal management and not just liaison to achieve results. Failure to so recognise and manage issues can lead to Wicked Problems: that is, Systemic risks are the precursor to Wicked Problems (e.g. the GFC); and 2. Revision of the traditional risk equation because today some consequences are so unthinkable that consequence must dominate the equation, particularly when faced with financial pressure to rely on likelihood. Consequence is the conjunction of vulnerability and threat. In response to growing interest, ARPI can announce it is developing an educational suite comprising vocational and tertiary courses – from a Certificate in Risk Policy through to a Masters’ Degree in Risk Policy. In addition, ARPI is currently providing Master Classes and strategic consulting arrangements at critical levels across all societal sectors. ARPI recognises the importance of security to society, hence the strong Risk Policy interest in this field and invites continuing contact and interaction with security professionals. Tony Charge JQ FARPI FAIM is President of the Australian Risk Policy Institute. For more information or comment, please email inquiry@arpi.org.au
050 SECURITY SOLUTIONS 048-051_SSM108 Business.indd 50
20/06/2017 2:22 pm
048-051_SSM108 Business.indd 51
20/06/2017 2:22 pm
COVER STORY
By David Lake
It costs money to commit acts of terrorism and field armies to fight the battles of jihad. The cost to pay for fighters, food, equipment, lodging, training, deployment and medical services for the jihadist by the controlling organisation or group is not cheap. When operating beyond the borders of the sponsor of terror, the costs can be five times as much as it would cost to conduct a local operation. For clarity, jihad will be separated into three tactics. First is the ‘inspired’ lone wolf attacks, then the planned and directed operations of terror groups, and finally the mobilisation of terror armies on the battlefield.
The overhead of a lone wolf attack is low for the instigator, but there are costs associated with creating, producing and broadcasting the instigating message through a variety of channels. How much does it cost to publish Inspire, the online magazine owned by Al Qaeda in the Arabian Peninsula? While the group behind the publication may not have to pay traditional publishing costs, such as print and distribution since it is an online publication, they still have to pay someone to do the production and work on the material – or that person will have to get a real job to eat, support loved ones and so on. It is possible
in this scenario that the lone wolf begins to receive some funding for training, existing and equipment once his operational commitment is confirmed and financial support is justified. The overhead of a planned terror event by a terror cell is much higher. If the cell is ‘radicalised in place’ members will already have established lives, which often include a job and a place to live. They may require extra funding for training, travel and equipment. If the cell is ‘inserted’, the costs grow considerably to establish housing, transportation, food and so on. Often, inserted cells have no legal means of employment in the host country. Cell members
052 SECURITY SOLUTIONS 052-057_SSM108 Cover Story-v2.indd 52
21/06/2017 12:39 pm
SECURITY SOLUTIONS 053 052-057_SSM108 Cover Story-v2.indd 53
21/06/2017 12:39 pm