Wednesday, March 13, 2019

Everyone is a Manager Today - No Joke

Everyone manages something today.

People, and even kids, today are all engaged in managing... something. Whether it is the operation and projects of their own life, someone they take care of routinely, or even, and here' the kicker, their gaming existence. But first, consider what I mean, at the base of the argument, that everyone is a manager today.

Thursday, January 10, 2019

The Property Line Is No Longer be the Perimeter

I do not expect this post to be of any great insight to many, but it might be for a few. That is, the notion that the property line has little to do with asset protection, security, or even safety for that matter. Property lines have a role in taxation, owner responsibility, taxation, and the like. Sometime it denotes the limit of the organization’s immediate “touch.” But it really has little to do with the process and efforts of securing and protecting the enterprise. Here’s why...

Wednesday, January 9, 2019

The Anecdote of Success - a Simple Tool

When beginning an initiative, project, or releasing an RFP how can you convey the vision of success to the audience? In some instances, a request-for-proposal has a sterile feel and fails to clearly convey the nuances of what, precisely, is desired from the provided system or service. The same can be said when an organizational leader presents a new initiative, or charters a project. The author, or presenter, of these desires are already intimately familiar with what they seek but those around them, whether vendor or peer, may not be visualizing the same solutions. How can they create a common vision?

I like to overcome this unnecessary problem of perception with a short narrative describing a successful utilization of the system. And, it can also be applied to expectations for security posts and proposed procedures. Writing an “Anecdote of Success” helps to solidify what you, the creator, customer, solution seeker, truly want and expect.

Wednesday, October 31, 2018

When Halloween Costumes Cause Problems... After Halloween

Halloween is here and some may choose questionable costume ideas. What happens to their costumes and accessories after Halloween? Well sometimes they end up getting donated - fully intact - cause some serious problems.

Tuesday, October 30, 2018

If You're Not Getting Your Hands Dirty When It Matters, Why Not?

Many years ago, a store manager offered me some of his "books" about management. They were little four-inch by three-inch staple-bound pamphlets. There were called something like Horse Sense or some such, but there were pretty cool to read back then - and the big boss was offering wisdom. Short anecdotes, long before our attention spans had dropped as far as today, made for quick learning. He also seemed to have left random paperclips in some of the books. And, that is where I started with a story about General Washington, a corporal, and a cart. I'll never forget it.

Friday, October 26, 2018

The Bathroom is Ticking... You Can't Make This Up

Early in my tenure in one position, my boss walked into his office for our scheduled meeting. He had a serious look on his face when he said, "There is a ticking sound in the men's room." I smiled and said I'd take care of it. So I walked across the hall to the men's room and... yep!


Friday, September 21, 2018

To Manage Predatory Dumping Use Your Words

When the adversarial environment is blatant... While speaking to the "eight-hundred pound gorilla" internal customer, I was told, "You want me to listen to you? I have a half a million dollar problem with dumping. You find a solution to that and then I’ll listen to you."

The proverbial gauntlet hit the floor in that pause. That was it, in no uncertain terms. First, though, predatory dumping is when folks come to your property late at night and dump their trash. Such a thing is not too much of a problem for the average business, but one that accepts donations as a part of their business model tends to attract this behavior. This leader thought he was stumping me, but he unwittingly set me free at what I do best.. find solutions when no one believed any existed.

Thursday, September 13, 2018

A Little Trust, a Little Agile, and Getting Things Done

If you hire Firebreathers, self-starters, or self-motivated problem solvers sometimes all you need to do is set them free.  Patton is quoted as saying: "Don’t tell people how to do things, tell them what to do and let them surprise you with their results." With the right people this can't be more true.

In a more modern context, one of the Agile Principles states: "Build projects around motivated individual. Give them the environment and support they need, and trust them to get the job done."

Wednesday, September 12, 2018

Getting a Clock into Your Interview Recordings


Is there a clock in your recorded interviews? Here's one solution that worked wonders.

If you know a better one? Share it in the comments!

Friday, September 7, 2018

Still Thinking "It Can't Be Done" - It Can. Try This.

We've all heard the refrain, and maybe sometimes recited it too.
It's not in the budget; We don't have enough... [money, time, staff]; It just doesn't work that way.

Try flipping that script to "How can we get it done?"

Thursday, August 30, 2018

Hotline Accessibility Testing - Who is Answering Yours?

Are you using an anonymous hotline service? Do you administer this service in-house? How do you know if the provider, be it contract service or employees, are meeting your expectations?  Are they competent in the necessary language, cultures, and can they assist someone with a disability? Is the most important information accurately conveyed to your responsible parties? Let me share the solution I put in place.

Monday, August 27, 2018

Committing to Robbery Investigations Pays Off

Aggressively committing internal investigation resources to robberies pays off, especially when law enforcement has limited resources to commit. Take a look at the effectiveness such a robbery response protocol can have.

Sunday, August 26, 2018

Getting back at it... It's been too long

Hey folks,
The times have changed, passing by in my silence here. We clearly have some ground to cover to get back on track. In one of my recent roles I built an enterprise security program that took a day or two - geologically speaking. At the same time, technology has advanced in some interesting ways. We have drones, artificial intelligence engines, video simulators of amazing quality, and virtual reality. Which means, so do our adversaries. If you're new to security things are getting interesting in new ways very quickly, and if you've been around for awhile then hang on because it's going to be one heck of a ride.

I look forward to getting back to discussing what I consider to be the most interesting industry. I have a few posts lined up to share fairly quickly. One is a short case study on a robbery protocol success story, and another has to do with different tools when soliciting assistance from vendors.

So here goes, and I hope to keep coming back to check on these posts... I'll try to keep it interesting and if you bump into something I ought to discuss, please let me know.

Rob
/

Thursday, May 12, 2016

Why "security" fails (and how to prevent it, maybe)

It is not uncommon that serious organizational interest in improving security occurs after "security" fails. Sure, there are exceptions; however it is not an uncommon phenomena.

Why then does security fail?

If we never changed the oil in our car we would not wonder why it stopped working.

If we were to over draw our bank account, having never put money into it, we would not wonder why there was no more money.

So why then consider organizational security any differently?

Wednesday, July 24, 2013

While We're on Burglary Prevention - Window Shopping

Many burglary prevention materials out there contain language about not putting valuables by windows. They speak of electronics, jewelry, money and other items that can be pulled through a window quickly. Let's take a moment and consider another type of valuable that is rarely mentioned.

INFORMATION. Your information is valuable to someone at some point for some purpose. The intruder is looking to make their efforts easier.  So what can be seen from your windows?

Can an intruder see a calendar? Does that calendar contain vacation dates, children's appointment schedules, your doctor appointments, or other similar data? What else is left by windows, on tables, and car seats-dashboards-floors?

Take a moment and walk around the house to look into the windows. What do you see? What will a bad guy see?

On a related note, what is in the pictures you and your family are posting on the internet? Are there pictures of that calendar? Valuables?

Monday, July 22, 2013

A Worthwhile Resource on Violence at Churches

I stumbled on this recently and thought it worth sharing. Awareness and vigilance are foundational to any protection program.

http://www.sheepdogseminarsforchurches.com/index.html

Besides that, I can't think of anything produced by Lieutenant Colonel David Grossman so far that not be worth reviewing.

The Card Trick - Burglar Style

Everyone seems to know one card trick or another. This one can be done with almost anything. The reason cards are often used is their inconspicuous nature and low cost. Consider this, whenever you or one of your neighbors go on vacation does anyone look out for the property? Collect newspapers, mail and clean up anything on the property that you might clean up anyways? This ties back into the concept of "covert channel" communications. The lack of presence at a property could be discerned by the lack of routine activity. Throughout our lives we set patterns and our individual patterns blend with the various groups around us. Someone paying attention to these patterns can easily see a change. A car left parked outside all day and never moved. This might be the second family car and the lack of movement could tip off a bad guy that the family has not been home. A dog that is normally outside in a fenced yard that is conspicuously missing during otherwise fair weather. Any of these could be a tip to the bad guy casing the neighborhood. And by casing, or observing, they could be exposing themselves to undue scrutiny by others in the neighborhood. To avoid this scrutiny the simple card-trick method is used. In addition to avoiding undue scrutiny it also permits the screening of a large number of target residences in one day - without the activity attracting too much attention by itself.

How many times have you come home to find a business card or flyer at your front door? Did you follow up with the business to purchase services? Probably not. Now if a bad guy, or team, were to blanket a neighborhood, or several neighborhoods, with these solicitations it might take a couple of hours. Say half a day tops. The next day, or maybe two days later, they might drive through the same areas and identify those houses that still have these items on the door. Would your neighbor know to check your front door and collect these items as well as mail and trash? In this way the bad guy can identify a number of targets with little effort. No doubt, at least one home owner might catch them at the door depositing the card and make an inquiry. The screening bad guy need only say he/she was just paid to deliver the cards and thereby avoid further inquiry. Or a more elaborate script may be followed whatever works best for them.

That's the card trick. Some sort of debris is left at a residence to identify a lack of attendance to its care. It is fairly easy to defeat this approach through diligence and neighborliness.

Sunday, July 21, 2013

Remote alarm system control

Remotely arming/disarming and alarm system management are popular features no doubt. Are they worth it? What is the best service for remotely managing your alarms?

What exactly do this offer? Remotely managed and controlled alarm systems are a relatively new consumer feature, although it has been around for about a decade. Service providers typically offer web access to your alarm system so you, the user, can make adjustments, set up reports, and sometimes even arm/disarm the system remotely.

This, of course, means your alarm system is accessible via the world wide web - the internet - and anyone with that access (like billions) may also potentially have access as well. Sounds daunting and maybe even discouraging. Is it a risk? Yes. Is it a manageable risk? Yes. Most of these systems offer a feature that allows a message to be sent (email or sms) whenever the account is logged into, so the user can quickly know that someone has attempted or gained access.

So what are the advantages of such a service? The obvious ones are being able to arm the system while you are outside the building. It allows you to disarm the system remotely so a friend can get in, a landlord, the fire department, et al. That's just the beginning. You can add/delete users on the fly or change user codes. Some providers allow sensors to remain actively monitored even when the alarm system is disarmed. Whenever a sensor's status changes the event is logged, and the user can create alerts (emails/sms) to identify whenever this event occurs. So a parent can see when a child arrives home, or opens the liquor cabinet, goes into space where a firearm is maintained, and so on.  


It also becomes possible to create a system with no "quiet zone" around the access door.  This last point is unique. Instead of providing greater convenience and control it opens possibilities for identifying intrusions. Without the "quiet zone" around the keypad the alarm system activates immediately upon entry. This is true both for the intruder and the legitimate user. The legitimate user should, of course, disarm the system prior to entering. There may not even be a keypad by a door to facilitate system operations. Or a dummy keypad can be placed by a door to allow the less intelligent intruder to "try" to disarm the system - slowing them down for both an apprehension by law enforcement and limiting their ability to collect items to steal. Most importantly, the detection time is shortened.

So, is this feature worth it? I wouldn't want a system without it. Is it possible for an accomplished hacker to bypass this aspect of the system? Yes, no, maybe, what of it. For now this is a more powerful tool for the threat it is designed - the burglar. The super-hacker is not who is likely to target your home, unless you in a position of power, prestige or fame in which case you should hire a professional to guide and assist you with a more integrated all-risk approach. For the rest of us the street criminal that is likely to target our homes can be better managed as you take greater control of your systems.

Friday, October 28, 2011

What is the best way to arrange alarm sensors?

It's the way that detects the intrusion the quickest and most accurately. And, that is done how?

Keep these in mind:
• What are you protecting and where is it? [the asset]
• What are you protecting it from and how will it get there? [the threat]
• What accommodations are needed to function with and within the protected area? [your activities]

The Assumptions:
The goal of the alarm system is to deter a criminal with a siren once an intrusion is detected and to summon a law enforcement (or private security) response. It is also going to provide some insight into the intruders path and possibly their intentions during the attack.

The asset is inside your home or business. There is most likely more than one asset and they are not necessarily grouped together. This makes for multiple areas to specifically protect.

The threat is coming from outside. This may not be true in reality; however it is an assumption for this exercise. It will need to pass through a door, window, wall, floor or ceiling to gain access.

You, your family, or your business associates might want to conduct some limited activity inside sometimes when the alarm is armed. Most of the time the location will be vacated when it is alarmed.

The Basics:
1. All exterior doors should certainly have a magnetic contact or other point sensor installed.
2. Exterior windows should also have magnetic contact or point sensor installed.
3. The areas directly inside the exterior doors and windows should have at least one volumetric sensor.
4. Large areas of glass, or glass that may be targeted by street punks, should have a glass break sensor.
5. Some individual assets may warrant specific protection such as sensors inside safes, or liquor cabinets (for teenagers).
6. The alarm control panel should be in a well protected location (rapid access to this will disrupt the alarm communication and response)
6a. If the communications module for the panel are located away from the panel it too should be well protected.

The Next Step (for the Unoccupied State):
The most likely path(s) that an intruder might use should be monitored by sensors. This offers insight to their activity during the intrusion. The degree of insight comes from the nature of the sensors that are focused on that asset.

The Next Step (for the Occupied State):
Think about where you wish to move while the alarm is armed. Plot this area on a set of floor plans if necessary. Now is it still possible to effectively detect an intrusion with these areas not monitored? In a perfect environment you and your family will be able to use the restroom and walk to each other without activating the alarm. This may not be ultimately possible; although it is with some creative planning. Keep in mind that some burglars have been known to move around the bedrooms of their victims while they were sleeping in the room.


With the sensors planned - we'll jump beyond the whole installation part - there is at least one more step. And it is quite possibly the most important one....

Sunday, October 23, 2011

Cyber Security Awareness Month - what's the hype about

"Every American has a stake in securing our networks and personal information" All the daunting and cool hacker stories today may leave the everyday citizen feeling... well a little uninvolved. NOT SO! Consider for a moment how this directly affects you....

You are a but a cog in the machine is the global information systems. You could be an important cog and never know it. First it's important to realize that most "hacking" is similar to the average burglary. Really it is. Remember the average burglary gains entry through an open or unlocked door or window, right? Well the average malware (malicious software - the projection of the hacker) gains access to your computer by getting past poorly maintained firewalls, anti-virus software that is not updated, and through unpatched/updated software applications. And what does this malware do you ask? What does a burglar do? The malware may roam your machine and look for interesting data, it may lay in wait for you to enter interesting information and it carries it away to for someone else to use. A burglar takes you TV and fences it. A hacker using malware may steal your credit card, social security number, phone numbers, addresses and what not, and then fence them on a website. Or they may just use them for their ends.

What is the most significant difference between a burglar and a network hacker? Threat Population! At any given time there are only so many people within travel distance of your home or office with the tools, expertise and desire to break into your home or office. Let's just make it easy and say the population of the metro area where you live and work. Now the available population for attacking your online presence is everyone connected to the Internet who can download a free software to seek out vulnerable machines and exploit them (so nearly everyone connected). The population difference for the threat is several orders of magnitude larger. Imagine a burglar that was able to cast out their thoughts (fanciful I know but bear with me) and in the telepathic scan can know who did not lock a door or window to their home or office without ever leaving the comfort of their warm soft couch and the other amenities that bring any lazy minimalist pleasure. That is what a hacker may do when they scan the portion of the Internet where your machines are connected. The easiest targets become apparent - the low hanging fruit of cyber theft.

Now an updated firewall, anti-virus software, and application software will not protect you from everything - not even close. Though it will cover the laziest of online miscreants. If you apply the Pareto Principle to this it means that 20% of your effort will be sufficient for 80% of the problems. Updating software also helps to keep it operating smoothly and efficiently.

Why mess with it if it works. I like to install it and leave it alone you say? Consider this analogy for unmaintained firewall. A firewall is a device or software used to separate networks. It's the difference between an open door and a door with an armed receptionist to manage authorized traffic. So you have a security officer come to your home every night to check and make sure everything is locked up and no one can get it. Now everything requires maintenance, even the officer. After a time the vision in his right eye begins to fade but he keeps reporting to you that everything is locked up tight. Then one day you hire a new officer because you had too and suddenly he reports that the last guy didn't see that one of the windows had been unlocked - the one on the right. Who knows how long that window has been open and your resources have been leaving through it.

When you get infected with malware you may be sending to your friends, and their friends, and their acquaintances. Just like a nasty STD. You send an email or message that the malware has attached itself to without your knowledge. Your friend trusts you and opens the email and maybe even an attachment. They're infected now too. The malware that your half-blind security let it might be sending these emails without your knowledge as well. So, please keep your software, firewall, anti-virus, and applications up-to-date. It's a start.