Applicable PSeMS components
- Senior management endorse security policy
- Security management plans implemented and maintained
Challenges
- The security department lacked the ability to describe why particular security processes are necessary.
- Security policies were either incomplete, difficult to implement, or absent. The policies often did not have a sound operational rationale for their implementation.
- Security processes were perceived as a barrier to achieving business goals and the importance of security procedures was not appreciated by senior management. It was therefore a priority to show how security could be an enabler and be of benefit to all staff and all business areas.
What was done
- Recognising the importance of senior level engagement the security management team took advantage of the requirement to conduct home security visits with members of the leadership team (due to prior intelligence that they could be potential ‘targets’ of external threat actors). This made security personal to these individuals and brought home the importance of the security function within the organisation.
- The security team helped to positively change the attitude of the leadership team to security within the context of the wider organisation.
- Presenting security risk analysis and recommendations in a format similar to financial analysis (which the Board is used to working with) is helping to demonstrate security benefits.
Benefits
- By targeting the senior leadership team via one to one engagement, created high-level advocacy and corrected entrenched misperceptions of security.
- Increased ability to demonstrate organisational security benefits.
Applicable PSeMS components
- Senior management approve resources
- Regular workforce engagement
Challenges
- Minimal resources were available to enable the organisation to focus properly on threat, policy, training, and risk management. However, there were adequate resources devoted to aspects of physical security.
- The organisation lacked the resources to assess security intelligence and emerging risks to help inform decision-making and policy across the organisation.
What was done
- New security roles were established with the express purpose of providing an integrated focus on threat, policy, training, and risk management. The organisation formalised the role of Chief Security Officer with clearly defined roles and responsibilities. A Senior Security Risk Manager was appointed with qualifications in threat intelligence analysis, policy development, and security training and education.
- A conscious effort was made to use consistent language to describe security risk and avoid using jargon. A common taxonomy for risk was established so that all departments see the measurement of risk in the same way.
- A deliberate effort was made to recognise and celebrate good security practices and behaviours across the organisation. This helped to associate good security with a positive experience. This was done through media campaigns and emails of thanks to staff who showed the right approach (with details copied to their line management).
Benefits
- Senior management approval of increased resources has enabled the organisation to take a more structured and risk proportionate approach to security that helps in inform threat intelligence analysis, policy development, security training and education.
- Increased recognition of the security team’s role and capabilities has helped to influence and build trust across the organisation. Therefore, success stories related to security are more visible across the organisation and with greater traction with senior management. The security team expect the value of this type of benefit to increase as PSeMS develops and matures within the organisation.
- Personalising security delivery has helped with engagement at the leadership level and has created a positive impression that ‘security is looking out for me, and my family’.
Applicable PSeMS components
- Informed decisions at senior level
- Improvement: Security policy updated with lessons learned
Challenges
- The organisation lacked an understanding of how to improve the existing physical security systems despite extensive experience in maintaining standards of security.
What was done
- More focus and structure was obtained to risk and threat intelligence as a result of implementing a formal PSeMS process supported by appointment of a Senior Security Risk Manager.
Benefits
- The intelligence/threat picture the organisation is now able to present to stakeholders creates business opportunities and drives a more pro-active response with informed security decisions being made at a senior level.
- An unexpected benefit for the organisation was that a security risk assessment conducted on invited participants prior to a high profile communications event revealed factors about individuals that whilst not security related, enabled the speakers to target their presentations and prepare for likely challenges and questions. This target audience analysis was a real non-security benefit from a security activity. This clearly demonstrated that security can not only add value but can, if done correctly, be an investment and not a cost.