THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



Organizations that separate security from workplace strategy often create unintended costs: slower decision-making, employee frustration, project delays, increased compliance risk, and diminished trust. Yet for decades, organizations have treated security and employee experience as competing priorities, assuming stronger security requires more friction.
I believe the opposite is true.
The most effective security programs do more than reduce risk. They help organizations move faster, make better decisions, and create environments where employees can perform at their best. They are the ones thoughtfully designed to enable the business while protecting people, assets, and operations. When security leaders understand business objectives and partner closely with stakeholders, security becomes a strategic enabler rather than a perceived obstacle.
Over the course of my career leading physical security, investigations, workplace experience, facilities, and employee safety programs, I've observed a common challenge: security is often invited into conversations after decisions have already been made. By that point, timelines have been established, investments have been made, and operational decisions are already moving forward. Security is forced into a reactive role, often introducing controls that feel disruptive because they were not considered during the design phase.
Organizations then spend time revisiting decisions, redesigning processes, and managing avoidable friction that could have been addressed earlier.
When security is brought in early, however, the outcome is dramatically different. Instead of blocking an initiative, security can help design solutions that achieve business goals while appropriately managing risk.
This requires a shift in mindset.
"When security becomes a business enabler rather than simply a business function, organizations become both safer and stronger."
Security professionals have traditionally been viewed as the people who say "no." But modern organizations need security leaders who can present options, assess tradeoffs, and help stakeholders make informed decisions.
Effective organizations understand that risk cannot be eliminated, only managed. The objective is to make informed decisions that align with organizational priorities and risk tolerance.
I often think about this through four simple principles.
First, Start with the Business Objective
Before discussing controls or policies, understand what the organization is trying to accomplish. Whether the goal is creating productive workplaces that inspire collaboration and creativity, hosting large-scale events, supporting workplace flexibility, or expanding into new markets, security should align its solutions to the desired outcome.
During the pandemic, our organization needed a way to safely reopen offices while maintaining employee confidence and meeting public health requirements.
We partnered across functions to develop a solution integrated with our access control program that supported a safe return to the workplace while maintaining business continuity. When security starts with the business objective, the conversation shifts from control to enablement. The question becomes not "How do we secure this?" but rather "How do we help make this successful while appropriately managing risk?"
Second, Reduce Friction Wherever Possible and Truly Understand the “Why”
While supporting Uber's autonomous vehicle program, we worked closely with business teams to understand where intellectual property and operational risks truly existed. Together, we implemented a tiered approach that focused on stronger protections where consequences were greatest while minimizing friction elsewhere.
The result was not only stronger security but stronger adoption because the controls were designed around the realities of the business rather than disconnected from them.
Designing controls that people willingly adopt creates something even more valuable than compliance: trust. And trust is often the difference between security being consulted early and security being brought in after the fact.
Third, Build Trust through Partnership
Security is ultimately a relationship business.
The strongest security programs are built on trust, not simply policies or technology. Employees are more likely to embrace controls when they understand the purpose behind them and see security as a partner invested in their success.
This requires security leaders to move beyond a mindset of approval or denial. Modern security leadership is about presenting options, communicating the “whys” and tradeoffs if alternative choices are made, and helping stakeholders make informed decisions.
It also requires intentional partnership across functions. By understanding the priorities and pressures of key stakeholders, security leaders can align solutions to business needs rather than operating independently from them.
When trust exists, employees raise concerns sooner, business leaders seek guidance earlier, business leaders understand the capabilities you bring to the table, and security becomes organically becomes integrated into decision-making rather than added after the fact.
Fourth, Turn Risk into Actionable Intelligence
Historically, security teams measured success by what they prevented. While that remains important, modern organizations increasingly need security leaders to help interpret risk before disruption occurs. Security is uniquely positioned to connect information from multiple sources and translate it into a meaningful business context.
Today's organizations face an expanding set of risks that extend beyond traditional security concerns. Environmental events, workplace disruptions, violent activism, geopolitical developments, and operational dependencies can all affect the employee experience and business continuity.
Security teams often sit at the intersection of these information streams and are uniquely positioned to translate complex and fragmented data into actionable intelligence.
Today, advances in automation and intelligence allow security organizations to surface meaningful information that enables leaders across the business. At my organization, we developed a security intelligence agent designed to monitor and consolidate safety, security, environmental, and business continuity risks affecting our footprint. Rather than requiring executives and operational leaders to sift through dozens of information sources, the program provides leaders with a clear and actionable view of emerging risks, enabling faster and more informed decision-making.
Security as a Resilience Partner
The future of corporate security will not be defined by the number of incidents avoided, the strength of a policy manual, or the sophistication of a control.
It will be defined by our ability to help organizations move confidently through uncertainty. Security and employee experience are not competing priorities. When designed together, they become powerful drivers of organizational resilience, trust, and performance.
Ultimately, organizations are not simply building security programs. They are building resilience: the ability to adapt, respond, and continue operating effectively through disruption. When security becomes a business enabler rather than simply a business function, organizations become both safer and stronger.