Preparing today's security leaders for the threats of tomorrow
Earlier this month at the Great Conversation conference in Seattle, SIW had an opportunity to sit down with Francis DâAddario, the former vice president of partner and asset protection for Starbucks and an emeritus faculty member for the Security Executive Council (SEC). DâAddario leads the SECâs Next Generation Security Leader program, which is designed to provide security executives with the business skills necessary to survive in todayâs corporate landscape. For years, many businesses have seen the security department as a cost center rather than a contributor to the organizationâs bottom line, so it is crucial for todayâs security leaders to show how theyâre delivering value to the business.
What really brought this to the forefront, according to DâAddario, were the years following the 9/11 terror attacks when organizations put a lot of money and effort into security only to see no tangible return on their investment. Â Â Â
âTen years ago, I would say that we were, ultimately, misaligned in terms of our assignment of being the all-hazard risk detectors and mitigators for major enterprises, corporations, NGOs and agencies,â explained DâAddario. âDonât forget, after 9/11 we were on the job of being ever-vigilant, theoretically, and we spent trillions of dollars on security that did not have any viable payback in the decade that ran from 2001 through the (economic) downturn that weâre just coming out of. What happened was there was a loss of credibility and a loss of confidence (in security).â
However, DâAddario said that in recent years, security practitioners have once again started focusing on enterprise risk management strategies that will pay dividends down the road and show the value proposition of security to the C-suite. Â Â Â
âI would say that in the last few years, weâve put our eye on the horizon again. We are engaged in longer planning and that includes facilitation of a more effective supply chain for better risk mitigation outcomes for organizations, institutions and economies,â said DâAddario. âNow we are assessing what the imperatives of management are and what the strategic goals of our organizations are. Our ability to measure our success is imperative. We canât have anymore failures of confidence. We have to measure confidence and security and all of the risk mitigation processes that we bring to bear and we have to do that in a way thatâs viable for our stakeholders and our stakeholdersâ stakeholders.â
While it may seem like a simple exercise for security executives to learn to speak the language of business, DâAddario said that oftentimes one of the biggest hurdles for CSOs is just learning to stop and listen.
âWhen you listen, youâre going to find the leadership imperatives of your organization very well enunciated,â said DâAddario. âFor our senses, particularly in the communications realm, we have people that are going to be audio learners, weâre going to have people that are going to be visual learners that have to see the charts and graphs, and we have people that have to read it. I think we have to take a multimedia effort in not only listening, but anticipating that when weâre reviewing the text or weâre reviewing the symbolic iconography of whatever the value system or strategic objectives are of the organization, that weâre not only in full alignment with all of it but weâre enabling it, weâre having a discussion around what are the risk implications to those lofty imperatives and goals and weâre mitigating against those all of the time.â Â Â Â Â Â Â Â Â Â
DâAddario believes that one of the biggest challenges facing todayâs security executives is the shear velocity of change in global connectivity.
âWe talk about how technology brings the deck of distance, it really also compacts your ability to analyze and use intelligence in a way thatâs beneficial,â added DâAddario. âWe now, through the World Economic Forum and others, have a really good understanding of what risks are and what the economic consequences of risk are. We understand that a food crisis in another part of the world can affect the general stability of governments; we understand that the fiscal crisis of collapse can crack the economics of nation states and regions; and, we understand that socio-political changes up to and including war, revolution and terrorism are things that we have to deal with and have very real world consequences for the supply chain and confidence on the movement of goods and information.â
Additionally, DâAddario believes that security practitioners need to be good students of the successes and failures of their colleagues in these aforementioned threat environments.
âHow are other people dealing with it? What is the consequence of their intervention, their timing, their people, processes and technology applications?â he asked. âAt the end of the day, whatâs the bottom line for the organization? Is it confidence? Is it financial gain? Is it the capability of stewarding finite resources in an NGO and being able to inoculate everybody in the world?â
While the capabilities of security technology such as video surveillance and access control have grown by leaps and bounds and everyone recognizes the benefits of a truly integrated system, DâAddario said that security leaders sometimes have a tendency to take their ârisk hatâ off when theyâre looking for the perfect solution to address their needs and forget about the potential liabilities.
âWeâre not asking ourselves, âwhat are the risks to my network of this particular peripheral?â In the old days, the chief information security officers and chief technology officers would say everything is buttoned down, but nothing was integrated so it was a hassle for the consumer to use,â DâAddario said. âAs youâre developing integration, youâve got these sorts of opportunities to be able to disadvantage the network, be able to pick up protected data off of those networks, etc. Having smart devices that really give us the analytic capability of true access control, just-in-time needed analytics and management information to run and enable a business, we have to make sure that those features are not opportunistically available to people that would wish to harm us or rip us off.â
The recent data breach at retail giant Target has also raised awareness among CSOs about the need to balance protecting traditional physical assets with securing information that organizations now collect in cyberspace. According to DâAddario, the key to striking the right balance is ânarrowing to the critical few.â
âIf you know you have supply chain in 31 countries, but the supply chain is disparately under five percent in 30 of those counties and 17 percent from one country, spend your time on your biggest supply chain arena,â he said.Â
About the Author
Joel Griffin
Editor-in-Chief, SecurityInfoWatch.com
Joel Griffin is the Editor-in-Chief of SecurityInfoWatch.com, a business-to-business news website published by Endeavor Business Media that covers all aspects of the physical security industry. Joel has covered the security industry since May 2008 when he first joined the site as assistant editor. Prior to SecurityInfoWatch, Joel worked as a staff reporter for two years at the Newton Citizen, a daily newspaper located in the suburban Atlanta city of Covington, Ga.Â

