Applicable PSeMS components
- Senior management endorse security policy
- Security management plans implemented and maintained
Challenges
- It was recognised that there were opportunities for security to become more systemised with a requirement for better standardisation in security management approaches throughout the organisation.
- The organisation wanted to develop a flexible approach to achieving security assurance based on the organisation’s overall objectives, with measures being developed centrally and empowerment for delivery firmly embedded locally and with those responsible.
- The organisation had many of the PSeMS components in place, but certain processes such as risk management, security resilience, and security performance management needed developing and optimising.
- Safety had traditionally had a far greater focus than security and held greater attention at senior management level.
What was done
- Some elements are still work in progress, but the organisation has achieved the following in relation to the above challenges:
- A change in senior leadership within the organisation resulted in a new vision, purpose, and supporting pillars for the business. For the first time security was included as one of the supporting pillars (Safety and Security, Assurance and Compliance).
- The alignment of security within safety was key, and the organisation’s established Steering Groups were now used to deal with the respective security focus areas: workplace violence and suicides (Health and Wellbeing) and terrorism and trespass (Customer Safety).
- The organisation changed its perception and emphasis of security recognising that robust risk controls often come from other areas of the business e.g. safety, customer services.
Benefits
- The alignment of security with safety has helped to improve the status of security, as safety had always enjoyed a greater focus within
the!organisation.
Applicable PSeMS components
- Regular security risk and threat assessment
Challenges
- Senior management level support is good but the organisation needs to also focus on longer-term risks rather than immediate challenges.
- The security team had finite resources.
What was done
- The PSeMS approach adopted by the organisation encouraged a collaborative approach with key stakeholders to inform intelligence gathering and security risk assessment. The organisation is policed by the British Transport Police (BTP) and strong, collaborative relationships exist between the two organisations. A Performance and Stakeholder Engagement Plan is in place between the two entities and good levels of collaboration are also maintained with the Department for Transport (DfT). These relationships are based on mutual trust, confidence and a shared understanding that the organisations are seeking to achieve the same objectives.
Benefits
- Improved collaboration with external stakeholders has helped ensure the security risk assessment process is well informed while leveraging external resources.
Applicable PSeMS components
- Performance data is traceable, retrievable, and accessible
Challenges
- The organisation did not have the capability to view the network-wide compliance picture and were examining security performance data site by site. This tended to create a risk-averse approach where one relatively small problem identified could result in a wrong assumption that the issue was more widespread.
What was done
- Covert tests are now being performed in conjunction with the regulator. Local management!teams have been empowered to conduct their own tests. Work is underway within the Light Railway to develop their systems to achieve a more complete view of performance data.
Benefits
- More informed assurance picture and credibility with regulator.
- The focus on PSeMS/security assurance has helped to move the organisation from a reactive stance to one that is pro-active and risk-based.