THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Jason Blumenauer, Vice President of Security, First StudentWith the landscape of the world today, a strong security program is more important than ever for an organization. Employees,’ customers, partners, and investors all want to feel safe and secure, and if that feeling of security is lost, it can be devastating to a company. Lack of strong security culture and practices hurts organizational health, affects the opportunity to gain and/or retain employees, and weakens a company’s ability to effectively manage a crisis as well as manage an effective business continuity program.
Security should be a fundamental expression of any proactive business philosophy. This means more than simply dealing with security incidents when they happen. There needs to be a commitment to protect and develop an organization and to help achieve a business's objectives. If an organization is prepared to manage through a crisis or incident, a normal day will come much easier, and operational excellence will follow.
In any industry, security begins with identifying all business resources: people, property, assets, services, and information. Only after identifying these resources – and the risks associated with them – can the designing and implementation of an effective security program that safeguards the investments begin.
A strong security program is only part of a successful equation. The meat of any program lies in the ability to lead and influence a security culture that has a focus on minimizing risk. There are many methods to complete this task, and where I have found the most success is when I follow these five basic but important guidelines.
1. Build the foundation of a security program by creating and maintaining a robust yet nimble security manual, emergency response program, business continuity program, and many supporting documents through policies, SOPs, and quick reference guides.
2. Build and maintain a security team that is not only knowledgeable in security but understands business and how to align the two.
"Success is found through the foundation of collaboration, thinking outside of the box, and constantly progressing"
3. Provide and maintain vendors that can support your security strategy and provide a best-in-class service that matches the essence of your security program.
4. Manage and maintain strong metrics that diverse audiences can understand and, if done correctly, can create strong engagement from outside the security department. For many years, security was a shared service that was pushed out and mandated. The right program with the right information can change that pushed shared service into one that is pulled into the day-to-day operations.
5. Create, manage, and maintain a strong marketing strategy to influence the business to inject the security program into their day-to-day operational flow. Showing ROI through operational efficiencies, risk mitigation, and organizational health improvement.
Through all five guidelines, there is a common theme. No matter the process you take to build a program, it is especially important to maintain it. The business landscape is always changing, and if you do not constantly assess your program to ensure you are providing the best service and aligning with your company strategy, you become ineffective.
With the base of the above five guidelines, it should never be forgotten that the key fundamentals of any security program should still always be planning proactively and understanding the temperature of risk for your organization, your industry, and the national and international landscape. Constantly track and monitor, and always be prepared to respond, knowing that there is always an opportunity to learn and grow. Remember, future successes are disguised as past failures or gaps.
Every leader has a unique idea of what success is. Success is defined as the accomplishment of an aim or purpose. From a security standpoint, I believe being able to identify a need and to mobilize a plan to fill that need and then deliver a solution while understanding the strategic importance of continuous improvement creates a successful mindset. Success is found through the foundation of collaboration, thinking outside of the box, and constantly progressing. Success is never stagnant; it is an ongoing activity, and it is important to own the change. If your security program follows this type of approach, I find it hard not to be a vital asset to any organization.