enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Jason Blumenauer Vice President Head of Security at First Student & First Transit

Significance of an Enterprise Security Risk Program

Jason Blumenauer Vice President Head of Security at First Student & First Transit

There is a new norm in business today, and that is to be prepared for the unexpected and associates, customers, and clients expect a service that can sustain and manage through a crisis. This is a new way of thinking for many businesses, and if an incident or crisis is not managed correctly, it can have lasting adverse effects. Having an emergency management program and a business continuity plan in place is nothing out of the norm, but the real question is, do you have a strong security culture that supports these programs? That will make the difference between reacting to an incident or responding to an incident.

Reacting is when you have the basics of a security program and must scramble to provide what is needed to confront a problem at hand. You usually see many e-mail communications and meetings with many people from different departments asking questions and not necessarily engaging thoughts towards a solution. This practice uses valuable time and is not very efficient or effective. The other issue commonly seen is no accountability, no defined leadership, and destructive silos.

Responding provides a whole different flow to how you combat a situation. By responding, you have immediate engagement from like-minded individuals who take a holistic approach to manage a problem. Prioritization is almost instantaneous, and sharing information allows for synergies to align with a focus on protecting people, property, operations, and brand. Doing it the right way makes a difference and minimizes the repercussion of claims currently and in the future; this is very important to the bottom line. We can try as hard as possible, but we will never be able to stop all crises from happening, but we can make sure we are prepared to manage appropriately. This is what allows you to be risk-averse.

It is important to remember that today's risk landscape is full of fast-moving, sometimes containing multiple threats ranging from civil unrest, workplace violence, terrorism, natural disasters, health crisis, civil unrest, internal and external criminal activity, and beyond. With a world of connected technology and instant linking to the masses, an organizational incident can escalate quickly and, in record time, can bring reputational and financial devastations. Having the right leaders and culture to respond is more important than ever.

The opportunity to minimize risk starts with a strong strategy around managing day-to-day security issues and concerns. Taking a proactive approach with a consistent program helps an organization reduce risk, builds organizational health, and maintains a risk-averse culture, which has also shown to help with retention problems, and with today's labor shortage, this is very important.

Workplace security issues are at a record high, and claims that need to be managed take a significant toll on your brand reputation internally and externally. But there is also a significant negative revenue implication. Imbedding a solid security culture with the right tools and resources can only strengthen an organization and minimize those losses. Allowing for a more proactive versus reactive approach to an incident saves time and money and provides more opportunities to invest in the organization's growth instead of constantly defending to sustain the operation.

At the core of best-in-class risk mitigation, a security program is a team that can champion the security resources and influence and engages the functions to navigate through concerns that may come their way. A business partner security strategy will need the following to show an ROI to the organization.

• Building the right brand that resonates with both internal and external customer

• Establishing security influence at every level

• Defining a best-in-class program that has a consistent flow and aligns with the overall business strategy

• Build a strong security story through metrics

• Maintain and grow consistent process controls

• Maintain constant communication across all pieces of the company

The approach is to focus on security from a holistic standpoint, considering the day-to-day reality of an organization and assessing the required security measures in this context. Proper Risk Management practices can significantly reduce the potential for loss. It is imperative to note that not every program will look the same. Each program must identify the business footprint and create a package that can overlay around the business initiatives and once embedded, can influence future business decisions. The goal is to create something sustainable, flexible to change with the business landscape, and ready to support growth.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.