Search This Blog

Wednesday, May 19, 2010

Terrorist threats and computer intrusions lead to onsite intrusions

Worst Case Scenario Thinking

I've been reading books and articles by Bruce Schneier since 2002, when I purchased Applied Cryptography. I have a 50/50 opinion of him, on some days or on some of his opinions I think he's right, and other times I disagree heartily. His recent write up Worst-case thinking makes us nuts, not safe -CNN.com is one of his best critiques of security thinking. He basically says worst case thinking makes us ineffective by encouraging and substantiating any wild claim of likely future events. His quote and critique of Rumsfield is especially entertaining.

I do think Schneier's prohibition on thinking about and preparing for the worst is a little too extreme. For instance I think all high profile government offices should anticipate an Oklahoma City bombing as at least higher than 0 probability, but of course lower than a 1.

Still, it is useful to consider an over-emphasis on the unlikely, bizarre and anomalous as unproductive preparation. In this frame of critique I'd like to suggest what is productive preparation:

  1. Incorporate every anticipation into your site plans.

  2. Make every task in your site plan truly doable by the employees you have. This implies officers performing with competence and honesty, but the greatest onus of responsibility is on security management to establish reasonable and doable tasks. Assigning the undoable is worse than no assignment at all, because it creates a norm to ignore orders. Of course discipline or terminate employees who do not perform reasonable orders they have had adequate training for.

  3. Daily (or hourly) routines are the antithesis of worst-case thinking, they are the blah kind subject matter as opposed to imagining a nuclear bomb in a white van. Daily routines, such as patrols, are the holy grail. Security is only as good as these routines provide. The "worst case" is going to be stopped by these, not by an expensive consultant visiting your company and telling his battle stories.

  4. Of course it is entirely reasonable to factor in flamboyant threat-thought such as IED's and other terrorist tactics. Security officers should have access to a compact document describing materials and behaviors to watch for.

Computer Network Security

The site I work at is government. They have chosen to use especially vulnerable software, in some cases simply not updated, and in other cases a more vulnerable software when a cheaper remedy is well known and available. My security company, and myself, lack the authority or leverage to change their computer software to something more secure. We are moving further into a century in which every aspect of business activity is controllable via computer network. Physical intrusion into the sites we are assigned to protect will happen because the computer network was hacked. I anticipate years of tension and vulnerability for traditional
security companies and their clients, as the computer network becomes more and more the entryway onto the physical site. Read: http://www.networkworld.com/community/blog/black-duck-eggs-and-other-secrets-chinese-hac

Wednesday, May 12, 2010

Industry Medicine

The math works something like this: if Obamacare materializes, and it appears that it will, most households making under $30k per year will be entitled to free health care. Hospitals and clinics will have a vastly increased need for security, because a lot of households don't make $30k and don't have health care. As people start to see health care as right instead of a privilege, I suspect the average patient's behavior at the doctor's office isn't going to improve either. I suspect that these factors will grow demand and wages in security generally, promoting professionalism in the industry.

Here's the low-down in the Health Care Security-specific certification. The organization is called the IAHSS (International Association for Healthcare Security & Safety.) Their top level certification is called the CHPA (Certified Healthcare Protection Administrator.) They have 3 lesser certifications for Basic, Advanced, and Supervisor levels, which sound ideal for someone trying to get into the Health Care segment of the security industry.

Wednesday, April 14, 2010

Licensed investigative company offers cellphone location service

For $95 you can the exact location of someone's cellphone. Another service they offer is a Telephone Card Spy, you give someone this calling card and tell them its free and encourage its use. You then can get info on every call made on it. Welcome to the 21st century.

http://www.best411.com/

Thursday, April 8, 2010

Union Advantages?

Private security's roots have a controversial anti-union history that we pride ourselves in. It's easy to see the conflicts-of-interest that the usually-mixed unions courting the security industry create. Even for a cutting-edge lefty-progressive like myself, unions put employees at odds with security business ownership, a problem because I want to see more worker-cooperatives in the security industry.

However, I have noticed that the top performing security companies in the Seattle area in 2010 have strong relationships with unions. This has forced me to look beyond my ideology and ask "is there a serious advantage to a security company being unionized?" I have come up with 4 points so far that are not dependent on each other, so any one of them stands as an advantage without any of the others:

1) I have heard "a good HR person can get around 80% of the union grievances that can come up, seriously deflating the power of the union: unions tend not to have the mental and monetary resources they need to do provide effective services." The problem with this claim is that it outlines an important specific advantage for a security officer to be in a union: a good 20% of the time, the union will be able to keep him from getting fired when things get ugly.

2) Another claim is "all unions do is protect bad employees." In the security industry, "training = good employees." Unions often pressure employers to make training options more available to their employees. Unions also raise what employees can make at a job, increasing the odds of employees staying instead of moving to another job, thus increasing the amount of experience on the security team.

3) The companies that try to find loopholes out of contractual obligations to have their security officers unionized are not fairing well right now. Though politics is a major factor, keep in mind there are politics going on for the individual security officer as well. If the security officer is not unionized and has to keep employees from stealing who are unionized, that security officer has a huge disadvantage in "my word against yours" situations. You can bet that many clients (or the people they answer to) understand this about security-services quality, in spite of whatever political pressures they are under.

4) Saying "unionization requirements for security accounts is only about politics" is taking a very narrow view, and ignores the academic management studies on this topic. People feel like they need to protect their jobs, and often keep feedback from their superiors. Because of this, HR often prides themselves in "telling people what they need to hear, even if it is not what they want to hear." Where Unions come into play is when HR or upper management needs to hear something that they don't want to hear. The union can give realistic information about employee needs and the health of the account that upper management can't get anywhere else.

Again, I sympathize with those that are concerned that unions harm the security industry. We need solid chains-of-command so we can act fast in emergencies. This does not invite employee feedback, and until recently we have thrived as we have rejected unions. However, we are in the middle of major paradigm shifts in the security industry right now. In nature, the more adaptable a creature is, the more likely it is to survive. The security companies that can't learn to live with unions will also fail to learn to live without them.

Monday, March 15, 2010

Surveillance Camera Debate

Bruce Schneier CNN.com essay:
http://www.schneier.com/essay-309.html
The surveillance camera industry rebuttal:
http://www.securityinfowatch.com/surveillance-industry-responds-bruce-schneier


I disagree with Schneier if he is advocating exclusively more manpower and little or no cameras. One of the retorts to Schneier refers to video footage as a superior forensic tool. Another retort mentions live cameras as a way for first responders to go straight to where the action is, especially in the case of the Virginia Tech shooter incident.


I'd like to dwell on video footage as a forensic tool, and make the extreme claim that video footage is always superior to someone's recollection and verbal account. The less forensic investigation relies on data stored in human brain cells, the better. Video or audio media is not inclined to subjective filtering, cultural preferences, or dishonesty. Humans are. Long live machines, our more honest and reliable resource.

Wednesday, February 10, 2010

Teen is beaten in bus tunnel; Metro to review security guard policies



Teen is beaten in bus tunnel; Metro to review policies -Seattle Times


QUOTING FROM THE SEATTLE TIMES ARTICLE:

The guards, who work for Olympic Security Services, provide security throughout the transit system.

According to the contract with Metro, guards with Olympic Security Services are instructed not to intervene when witnessing suspicious behavior or criminal activity, but to "observe and report" and radio the Metro Transit Control Center, which relays requests for assistance to the appropriate law-enforcement agencies.

According to the Sheriff's Office, the guards called the tunnel communication center after the Jan. 28 assault.

In light of the assault, Metro is reviewing the restriction on physically intervening in fights or other criminal activity, Desmond said.

Asked if he thought the guards acted appropriately in light of the policy, Desmond said, "The whole thing, in terms of what happened with or without a sensational video, is very concerning and very disturbing to us. On the face of it, the security guards were following the letter of the policy. I certainly wish they had done something different. ...

"We're talking with Olympic and we're going to change that policy," he said.

Thursday, February 4, 2010

(cdc.gov) NIOSH: Workplace violence resources

http://www.cdc.gov/niosh/docs/2006-144/

I just went through my WA state unarmed security guard license preparation class and test. I found the Workplace Violence info interesting and am looking into it further with online government/academic resources, cases and studies. This NIOSH site replicates things taught in the OSSI training session, and of course goes further.

I will add to this blog entry as I come across especially useful information.

Thursday, January 28, 2010

In Person Meeting

I would like to set up meeting to talk about Security Information (Training, Equipment and Etc.) from time to time as people want or have time to. please let me know if anyone else has time to or wants to?

Networking

I was hoping to use this blog to networking all levels of security professional. As there are no email address of any member in the profiles. So I hope that all members will change that in their profiles. So there is easier ways for there to networking tools for all members.

Wednesday, January 27, 2010

Smart Phones

I can see many ways to use smart phones within the security industry. The idea are long and many so I will add to this posting soon. If anyone has any thoughts on this please post them.

Security Unions?

Any Thoughts?

Flex Work?

What is anyone thoughts on flex work? Why would anyone work that kind of shifts?

Tuesday, January 26, 2010

Job Openings

If anyone see Security based Job opportunities please post them to the blog so if any of our members are looking for work may see them and so we all can get a idea about whats out there and what we can do to improve the way the security industry work all who want to work in it.


Sorry life been crazy

Sorry to all members for not doing any up keep on my blog. I hope now be able to work more on the blog by working on networking with all of you and making this blog a useful tool for security professionals and anyone who want to learn about what security does and where t is going

thanks

Tuesday, October 13, 2009

Watch surveillance feeds on iPhone




Reference document: HERE.

This technology is changing how security professionals can view security cam video feeds. Instead of being limited to a dispatcher or security-booth for viewing, every guard onsite could have access to live security cam feeds. Via iPhones.

I think having all guards with iPhones equipped to view all local building security cam feeds would be great for enhancing the security team's intelligence gathering and ability to respond to dynamic situations. Still, someone needs to be designated "watcher", sitting at a booth and watching traditional monitors.

File this under security team agility.

Monday, October 12, 2009

crime-reconnaissance.appspot.com

I write web applications computer programs sometimes as a job and most of the time for fun. The following is a crime fighting tool I wrote a few months ago.
-> http://crime-reconnaissance.appspot.com/

The idea is simple: a "user" knows of some crime or suspicious behavior. Let's say they have surveillance footage related to the incident, and have uploaded the video to Youtube. Also, they know the address of the incident.
They would go to crime-reconnaissance.appspot.com, login in with their Google username, and post 1) address 2) link to Youtube video 3) a description and info of the incident.

Crime-reconnaissance.appspot.com has nothing useful on it as of now. That's because I wrote the cool software, but don't have any crime incidents to report. The material currently up there are mere examples to show the software in action. What's needed are real users with real incidents to post on the site. Hopefully someone reading this gets an interest and posts something. Web 2.0 tools such as this are only powerful once a critical mass of users use it.

If you look at crime-reconnaissance.appspot.com and say "wow, thats an ugly interface, it could be designed so much better", then I am prepared to accept your criticism. I wrote the core software, which works well enough, but waiting on users to show up to give me feedback and to test the software under a heavier load.

IFPO Articles and Reports

International Foundation of Protection Officers website has a library of articles at http://www.ifpo.org/articles/index.html. I've read maybe 25 percent of them, and the depth of the material varies. Some are barely a nugget of information, others are an actual help and illuminate a topic.

To help get started on the more useful content, below are articles I found informative:


More info: Sarbanes-Oxley Act

Tuesday, May 5, 2009

Wireless Mesh Video Surveillance by Seattle Police Dept

Wireless mesh networks are the latest and most sophisticated use of wireless WLANs. I was surprised to see this article with the SPD using a mesh to see video surveillance in Pioneer Square for Mardi Gras.



http://www.governmentvideo.com/articlenews/81082