Field Notes
Your Security Plan is Not Your Security Culture
BAILEY COLAHAN
We’re all familiar with examples of workplace jargon gone viral: circle back, close the loop, stack hands, think outside the box, win-win…the eye roll inducing list goes on. After another busy spring/summer conference season, I’ve noticed another one emerging within the behavioral threat assessment and management (BTAM) community: “culture of security.”
How many times have you been told to create a “culture of security” or to foster “security culture” at your organization? (If you try to tell me it’s fewer than 20 times, I won’t believe you.) How many times have you heard it defined? When we use viral terms like these, it’s easy to assume everyone means the same thing. However, widespread use doesn’t necessarily mean shared understanding. In our field, unclear language can undermine safety. We have a responsibility to be clear about what we mean when we throw around important concepts like “security culture,” and so far, we haven’t done a very good job of it.
Defining and Developing Security Culture
If we aren't clear about what creating a culture of security entails, we risk undermining our goals before we even get started. To one listener, the phrase might refer to developing a robust physical security ecosystem. With that understanding, physical security measures like video cameras, magnetometers, security guards, and badging technology might seem like the primary means of creating that culture. Appropriate physical security measures are an essential part of a holistic security plan, but implementing them is not the same as building a security culture.
So, what does it mean when we talk about creating a culture of security? It means cultivating a system of behaviors, norms, and habits within a group or organization that promotes shared responsibility, information sharing, and decision-making aligned with clear security objectives. Building that culture means creating the conditions in which people see security as something they participate in and contribute to, trust those responsible for managing concerns, know how to share information, and feel confident doing so.
Modeling shared responsibility starts at the top. Leadership plays an essential role in shaping an organization’s culture. How leaders talk about expectations, procedures, and goals gives employees cues about how to behave. One effective way to communicate that security is a shared responsibility is to use “we” statements. For example, “Here at Widgets-R-US, we do the right thing. We look out for one another here. If something doesn’t seem right, we want you to say something.” Simple statements like these reinforce the idea that everyone has a role to play and encourage employees to speak up when something is wrong.
Build trust by making security personnel approachable. Information sharing depends in part on trust, and trust is easier to establish when security personnel are seen as accessible colleagues rather than anonymous authority figures. Even small changes can go a long way toward establishing trust through interpersonal connection. In a formal setting, seasonally appropriate lapel pins, decorative flower arrangements, or lobby music could help cultivate a sense of approachability. In informal settings, even more can be done. Encourage security employees to show some of their personality: allow visible tattoos while in uniform, or encourage employees to wear a favorite baseball team’s cap on opening day. Bring security employees out from behind fortress-like security desks during high traffic times. These small points of connection can lower the interpersonal barriers that might otherwise make someone hesitate to approach security with a concern.
Design the security environment to reinforce your cultural goals. Physical security measures communicate something about an organization's relationship with its members. Consider how the appearance, sound, and placement of security infrastructure shape employees’ experience of it, and design your environment to reinforce rather than contradict the culture you are trying to create. If possible, choose wood accents and neutral earth tones instead of sterile white or steel gray. Program gates and access control systems to chime with pleasant tones rather than alarming buzzers. Incorporate cameras and metal detectors into architectural panels or structures when appropriate. Finally, use clear, polite signage: instead of “STOP! Unauthorized entry prohibited,” try “Please check in here.” The goal is to make physical security feel like an integrated part of the organization’s shared commitment to safety rather than an obtrusive or adversarial presence.
Make reporting easy and accessible. Timely access to information is essential, therefore reporting procedures should be straightforward and readily available to employees. Employees should have multiple ways to report concerns, including online forms, text/app-based submissions, telephone reporting, and in-person reporting, with an option to report anonymously when appropriate. These options should be routinely advertised to the employee population and clearly identified in internal communications and resources. Just as importantly, employees should have confidence that their concerns will be received seriously and respectfully. While confidentiality or other considerations may limit what can be shared about the outcome of a report, acknowledging concerns and providing appropriate follow-up can reinforce that speaking up is worthwhile. It should be every security director’s nightmare for an employee to want to make a report and be unsure where or how to do so, or to believe that doing so won’t matter.
Build relationships before you need them. It’s much easier to work with key partners during a crisis if you’ve established relationships ahead of time. If you haven't connected with colleagues in areas such as human resources, legal counsel, employee assistance, or communications, consider it a pressing task. Learn about their goals, responsibilities, and constraints, and make sure your expectations of one another are clear. Remember that partnership goes both ways; security practices should account for your partners’ needs and draw on their expertise. Periodically check in to make sure these relationships are working. These conversations can uncover issues that might otherwise go unnoticed, like too many security requests falling to a single employee, and give you a chance to address them before they strain the relationship.
Make every interaction reinforce the culture you want to build. Security programs, and BTAM programs in particular, depend on people throughout an organization being willing to share information and collaborate. Whether you are speaking with an employee who has reported concerning behavior, or working with human resources on an area of joint concern, how you show up matters. Be approachable, prepared, and respectful. Stand-offish, annoyed, or overly aggressive security personnel don’t often get very far with people; so don’t get in your own way. Treat every report seriously and every reporter with respect and receptivity. Each interaction can either reinforce someone’s willingness to engage with your program or make them think twice the next time.
If “security culture” becomes just another buzzword, we risk losing sight of what we’re actually trying to build. Start by asking those in your organization if they feel security belongs to them too. Work until you consistently hear yes. The goal is for people to see security as a shared responsibility and to make it as easy as possible for them to participate when it matters. A security plan provides the tools and procedures that help keep an organization safe. A security culture builds the trust, habits, and shared responsibility that make them work.