Operational Readiness for Physical Security
Q: What does “operational readiness” mean for a security program?
A: Operational readiness means having the people, processes, technology, and resources in place—as proven through training, exercises, and testing—to respond effectively to emergency situations while sustaining all essential security functions.
Why This Matters
When an emergency occurs, the organization's security focus doesn't narrow; it widens. Security personnel must respond to the immediate situation while continuing to protect the people, assets, and operations that remain vulnerable. Responding to one event should not create new opportunities for theft, sabotage, workplace violence, or other security incidents elsewhere.
This requires more than documented emergency response procedures. Personnel at every level must understand their roles and responsibilities, communicate effectively, coordinate resources, and adapt to changing conditions. Security leaders must maintain situational awareness beyond the immediate incident, recognizing how the emergency affects the organization's overall security posture. That level of readiness cannot be assumed. It must be planned, developed, exercised, and demonstrated.
Think Capabilities, Not Plans
Most organizations have emergency response plans. Fewer have demonstrated the capabilities needed to execute those plans effectively under real-world operating conditions.
Operational readiness begins with capability-oriented questions rather than document-oriented ones. Are roles and responsibilities clearly defined? Have personnel been trained and exercised in those responsibilities? Can security resources be reallocated without creating unacceptable vulnerabilities elsewhere? Are communications, decision-making authorities, and supporting technologies prepared to function under the pressures of an emergency?
Thinking in terms of capabilities naturally broadens the discussion beyond the Security department. Effective emergency response often depends upon coordinated support from Facilities, EHS, Human Resources, Information Technology, business leadership, and public safety agencies. Operational readiness therefore becomes an organizational capability, with Security serving as both a leader and a key participant.
The Hospital Incident Command System (HICS), hosted by the California Hospital Association, offers a strong example of capability-oriented emergency preparedness. It provides a well-developed framework, along with practical forms, Job Action Sheets, and related guidance, to help organizations define roles, organize resources, and support coordinated incident response. Just as important, HICS recognizes that these structures and tools should be adapted to the organization rather than adopted wholesale. They can and should be scaled to align with the organization’s specific hazards, operational realities, and security objectives. This is consistent with the central point here: effective readiness depends on developing organizational capabilities that can be applied under real conditions, not merely on maintaining written plans.
Building Operational Readiness
Fortunately, most organizations do not need to create an entirely new program to improve operational readiness. The necessary elements often already exist within the security program and related organizational functions; the opportunity is to strengthen them, integrate them more effectively, and ensure they work together when needed.
Planning establishes expectations. Training develops competency. Exercises validate individual and organizational performance. Testing confirms that people, processes, technology, and supporting resources perform together as intended. After‑action reviews identify opportunities for improvement. Together, these activities create a continual cycle of learning and improvement that steadily increases operational readiness.
Rather than asking, “Do we have an emergency response plan?” organizations should ask, “Have we demonstrated that we can execute our responsibilities successfully under emergency conditions while continuing to sustain essential security functions?”
World Trade Center: A Readiness Case Study
On September 11, 2001, early television news reports estimated that, out of the roughly 50,000 people who worked in the Twin Towers on a typical day, as many as 20,000 lives might have been lost. As survivor counts improved, those projections dropped to about 5,000. In the end, approximately 2,045 building occupants and visitors in the Twin Towers lost their lives—still a catastrophic outcome, but far below the initial estimates that assumed far less effective evacuation.
Operational readiness at the World Trade Center was the result of a deliberate security and life‑safety program developed and run by the Port Authority of New York and New Jersey’s security organization, supported by its police department and major tenants. The program included designated Floor Captains to manage evacuations, a detailed evacuation plan, and regular full‑building evacuation drills. Those drills, which moved tens of thousands of people out of the towers, lasted hours and represented millions of dollars in lost work time across more than 400 companies, yet they produced a population that knew the routes, understood the procedures, and could respond quickly and in an orderly fashion under extreme stress.
Taken together, the Port Authority’s building‑wide operational readiness and the firm‑level programs it enabled demonstrate the real value of investing in practiced capability, not just written plans. Without that level of operational readiness, plans translated into practiced behavior, clearly defined roles, and a culture that took drills seriously—the loss of life could reasonably have been ten times higher.
Security leaders should insist on building‑wide drills and measurable readiness standards appropriate for the nature and occupancy of their company’s facilities.
Conclusion
Operational readiness should be treated as a core business capability, not an optional enhancement to the security program. When security leaders define and measure readiness in terms of demonstrated capabilities—supported by regular drills, well‑defined cross‑functional coordination, and clear standards tailored to each facility—emergency response becomes a predictable and verifiable organizational strength rather than a hopeful assumption.
About the Author

Ray Bernard, PSP, CHS-III
Ray Bernard, PSP, CHS-III, is the principal consultant for Ray Bernard Consulting Services (RBCS), a firm that provides security consulting services for public and private facilities (www.go-rbcs.com). In 2018 IFSEC Global listed Ray as #12 in the world’s top 30 Security Thought Leaders. He is the author of the Elsevier book Security Technology Convergence Insights available on Amazon. Ray has recently released an insightful downloadable eBook titled, Future-Ready Network Design for Physical Security Systems, available in English and Spanish.
Follow him on LinkedIn: www.linkedin.com/in/raybernard.
Follow him on Twitter: @RayBernardRBCS.
