Brian Sims
Editor
Brian Sims
Editor
IN THE second instalment of an exclusive four-part series for the readers of Security Matters, Paul Lotter outlines precisely what underpins every good security solution and, in doing so, continues the theme of building security models for today’s practising security and risk managers.
In the first article of this new series, we set out an integrated security model built on five steps: Assess, Understand, Deter, Identify and Treat (AUDIT). This time around, it’s about focusing on Assess and Understand: the steps that lay the foundations for the rest of the security model.
Assess is about measuring where an organisation stands, while Understand is concentrated on interpreting what it’s up against – ie Deter, Identify and Treat, which we’ll cover next time – with a keen focus on risk prevention, the detection of threats and the escalation and management of incidents.
Making sure the first steps are right then enables the whole security approach to become that much more targeted.
Assess: looking within your organisation
Start with Assess on the basis that you cannot sensibly choose a security solution before you understand what you’re protecting and from what. In truth, this is the stage too many organisations skip, yet it’s the foundation the rest of the model is built upon. If it’s wrong, everything that follows inherits the flaw. Assess is the measurement stage comprising an honest audit of your vulnerabilities and risks.
In practice, that means cataloguing the critical assets that matter most, examining the protection already in place and pinpointing where an organisation is most exposed. Carried out properly through risk assessments, consultations and a close review of sites, systems and procedures, it produces an accurate and evidence-based picture of exactly where you stand. Just as importantly, it sets the baseline against which every later decision is judged.
Without that baseline, there’s no way of knowing whether a control is working or whether budget is being directed to where it’s genuinely needed. It can often surface quick wins as well, such as identifying gaps in your back-up and recovery procedures, which then allows you to close them efficiently before any major protective investment is on the table.
Understand: reading the environment around you
Where Assess looks inward, Understand looks out. It interprets the world beyond an organisation’s own four walls: the specific threats, vulnerabilities, location and operating environment that shape its risk.
A site’s geography, its sector, its neighbours and the people who might target it all change the picture. It could involve reviewing protest activity surrounding a client’s headquarters, even if it’s not the main target. A threat that can be severe for one organisation may well be irrelevant for another only a mile distant. Defining that context is what separates a proportionate response from either complacency or overspend.
Interpreting that context well is rarely something an organisation can do alone, which is why these stages often draw on external intelligence and consultancy. For example, Corps Intel’s in-house bulletins and regular intelligence reporting help organisations to base decisions on evidence rather than assumption.
Understanding what needs protection – and from whom – turns a sense of unease into a clear view of the measures actually required. Good intelligence goes further than listing threats. It weighs up which truly apply, as well as how likely and how damaging each would be. It’s this inside-out holistic view that matters most.
Only once that understanding is established can you scope the right solution. In many cases, it will be a blend of people and technology, but the method should follow the thinking, not lead it.
A generic ‘one-size-fits-all’ package is never going to be the answer. Two organisations on the same street can face very different risks. As such, their security regime should reflect that fact.
Biggest misconception
Assess and Understand are also never a one-off exercise. The biggest misconception in our industry is that you appoint a solution and you’re done. You’re not. The threat landscape moves continuously and so should the model.
Depending on the environment involved, revisiting both the assessment and the wider external threat picture at least every six months is what keeps a security solution fit for purpose. Indeed, the process often reveals where a solution can be tightened or reshaped.
At its heart, every security solution depends on people. Technology and intelligence can sharpen the picture, but it takes human judgement to interpret what they show and to decide what truly matters.
If Assess and Understand are right, many potential security issues can be addressed before they snowball into incidents. Where that’s not possible, there’s a stronger foundation to build on for the three steps that follow: Deter (suitable prevention), Identify (early detection) and Treat (a joined-up response).
In the next part of this exclusive series for the readers of Security Matters, we will explore the Deter, Identify and Treat elements of the integrated security method before examining going on to examine precisely why the model works and who it’s aimed at.
Paul Lotter is Chief Operating Officer of Corps Security (www.corpssecurity.co.uk)
Western Business Media Limited
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM