WE HAVE MOVED - CHECK OUT OUR NEW HOME!
Monday, 6 September 2010
Personnel Security is a must for any organisation.
Wednesday, 2 June 2010
How to Provide Security Assurance in 9 Easy Steps!
In conjunction with management you should produce and deliver an Annual Programme (1) of risk based audits aimed at ensuring security risks are identified and effectively managed. It is more than useful to obtain senior executive level approval that is communicated throughout your organisation and that clearly sets out the objectives, authority and responsibilities of the Department conducting these security audits.
Once high level approval is obtained you need to develop a structure as to how these security audits should be done and who needs to be involved. Below is an idea for a structure that could be adopted once the business area or security risk owner (also known as an auditee) has been identified.
Tuesday, 1 June 2010
Personnel Security - Something we should all be paying a lot of attention to!
In these modern times not only are organisations at risk from external threats but we also have a very significant threat from the insider. An insider is classed by the CPNI (part of the security services) as 'someone who exploits or has the intention to exploit their access to an organisations assets'. So this could result in a number of different scenarios including fraud or an employee who sells your company data to a competitor or an employee who is feeding information to a terrorist organisation.
Personnel security is an area that many 'security professionals' think they understand, but in my experience actually don't. There are elements of personnel security which are managed by non security departments for instance pre employment screening by HR or it may even be outsourced to a 3rd party provider. If this is the case I recommended carrying out some of your checks to see if they are doing what you think and expect they should be doing.
I am lucky enough to receive training from some world class experts in this area, but the level of understanding is very different from organisation to organisation. The strategic objectives for personnel security are the same for everyone but in a private sector environment I believe it is a little more difficult, for example government departments have a security policy framework(SPF) which includes 70 mandatory controls (supported by various baseline standards) which must be adhered to (along with a annual declaration of adherence). The private sector has not got this level of hierarchy governance but of course there is no reason why at a local level you can’t have a similar assurance process. I would recommend any security professional obtaining a copy of the SPF which is publicly available here It is useful and a document which I refer to regularly.
1. Assess Personnel Security Risks and include these on your risk registers
2. Have a helpline in place for employees to confidentially report concerns
3. Know the source of employment references
4. Confirm employee has the Right to Work in the UK (a legal requirement)
5. Carryout qualification checks and check physical certificates where possible
6. Where possible complete the 'pre-employment screening' process prior to start date
7. Promote a positive security culture
8. Advise potential employees of the level of checks you use, this may deter potential insiders
9. Transparency - have clear polices and procedures in place
10. Audit - to provide assurance that the systems are effective
In future blogs I intend providing some more details on each of the individual personnel security subjects which will hopefully help you going forward.
Cultural sites 'vulnerable to criminals' during 2012 Olympics
Charles Hill said security around the games was focusing on Olympic sites, while many so-called "soft targets" – including museums, galleries, churches and cathedrals – are being overlooked.
Hill pointed to evidence of "high and holy day trophy art crime" being carried out when police resources are especially stretched.
During the 1994 winter Olympics in Norway, thieves stole Edvard Munch's painting The Scream from the Oslo National Art Museum and left a note that said: "Thanks for the poor security."
On New Year's Eve 1999 robbers broke into the Ashmolean Museum in Oxford and took its only Cézanne, while Rembrandts and a Vermeer were stolen from a museum in Boston – still the art world's biggest unsolved theft – on St Patrick's Day 1990.
Hill has investigated some of the most high-profile art thefts and headed undercover operations to recover works. Today, he said soft targets inside and outside the capital would be vulnerable during the Olympics, which could also be a target for terrorist attacks.
His comments came after the sports minister, Hugh Robertson, announced last week that the security minister, Pauline Neville-Jones, is carrying out a review of security for the 2012 games.
However, it has not been confirmed whether the review will include soft targets, with the Department for Culture, Media and Sport saying security was a matter for the Home Office.
Hill's concerns were echoed by Peter Osborne, a former national security adviser for the nation's museums, who said: "It is imperative that the security of [cultural] sites is not overlooked." But the directors of the Museum of London and the National Portrait Gallery said today that their security was being reviewed through the National Museum Directors' Conference, which represents the UK's national collections.
Jack Lohman, the Museum of London director, said: "We're hot on security …liaising with police. All national museums have plans, co-ordinated by the NMDC." However, Dr Michael Dixon, the chairman of the NMDC, said: "There is no specific project that NMDC is working on to consolidate security issues for the Olympic year.
"It's up to individual museums, and there are good relations with the security services."
A spokesman for the Association of Chief Police Officers said: "Museums, galleries and cultural sites typically put in place their own security measures where necessary."
Friday, 28 May 2010
Saturday, 22 May 2010
£430m loss, let's blame the Security Guards!

A number of news headlines highlighted the that the guard/s (some reports state that 3 were on duty) were sleeping and the Evening Standards headline said 'Guards dozed as thief stole Paris paintings'! Why is it that the security guards sleeping hits the headlines and not the other catalogue of errors and issues that took place at the Museum :
- CCTV cameras pointing only at the roof
- Managements decision to switch off the alarm system because it kept going wrong (parts were on order).
- The paintings may not have been insured
- £15 million was spent upgrading security during a two-year refit which ended in 2006.
- Theft not discovered for up to 3 hours
- The intruder slipped into the Museum after simply removing a window.
- Insiders working for low pay in galleries are often suspected of helping criminals.
I think this really goes to prove a point that I made in this blog after my recent visit to IFSEC. You can spend an awful lot of money on technology (£15m in this case) but you still have the human element 'who leave cameras pointing at the ceiling' or the senior member of management that 'turns of the alarm systems due to false activations' or the member of staff who 'leaves the door unlocked in return for €50's'.
There is and always will be a requirement to have a robust security management regime (including Physical Security and Personnel Security) in place along with regular security audits to provide assurance that these measures are proportionate and effective. Although the night guard failing asleep is a serious issue (and one which is a common in the industry) it hardly deserves to be the headline for what is a heist of the century and a £430m loss of some of the rarest art pieces in the World.

One of the pieces stolen a £15m: Fernand Leger's 'Still Life with a Chandelier'
SOME OF THE BIGGEST ART THEFTS IN HISTORY
- May 2010: A lone thief stole five paintings possibly worth hundreds of millions of euros, including works by Picasso and Matisse, in a brazen overnight heist at a Paris modern art museum.
- February 2008: Armed robbers stole four paintings by Cezanne, Degas, van Gogh and Monet worth $163.2 million from the E.G. Buehrle Collection, a private museum in Zurich, Switzerland. The van Gogh and Monet paintings were recovered.
- December 2007: A painting by Pablo Picasso valued at about $50 million, along with one by Brazilian artist Candido Portinari valued at $5 million to $6 million, were stolen from the Sao Paulo Museum of Art in Brazil, by three burglars using a crowbar and a car jack. The paintings were later found.
- February 2007: Two Picasso paintings, worth nearly $66 million, and a drawing were stolen from the Paris, France home of the artist's granddaughter in an overnight robbery. Police later recovered the art when the thieves tried to sell it.
- February 2006: Around 300 museum-grade artifacts worth an estimated $142 million, including paintings, clocks and silver, were stolen from a 17th-century manor house at Ramsbury in southern England, the largest property theft in British history, according to reports.
- February 2006: Four works of art and other objects, including paintings by Matisse, Picasso, Monet and Salvador Dali, were stolen from the Museu Chacara do Ceu, Rio de Janeiro, Brazil, by four armed men during a Carnival parade. Local media estimated the paintings' worth at around $50 million.
- August 2004: Two paintings by Edvard Munch, The Scream and Madonna, insured for $141 million, were stolen from the Munch Museum in Oslo, Norway by three men in a daylight raid. The paintings were recovered nearly two years later.
- August 2003: A $65 million Leonardo da Vinci painting was stolen from Drumlanrig Castle in southern Scotland after two men joined a public tour and overpowered a guide. It was recovered four years later.
- May 2003: A 16th-century gold-plated Saliera, or salt cellar, by Florentine master Benvenuto Cellini, valued at $69.3 million, was stolen from Vienna's Art History Museum by a single thief when guards discounted a burglar alarm. The figurine was later recovered.
- December 2002: Two thieves broke in through the roof of the Vincent Van Gogh Museum in Amsterdam and stole two paintings by Van Gogh valued at $30 million. Dutch police convicted two men in December 2003, but did not recover the paintings.
- December 2000: Hooded thieves stole a self-portrait by Rembrandt and two Renoir paintings worth an estimated $36 million from Stockholm's waterfront National Museum, using a motorboat in their escape. All paintings were recovered.
- October 1994: Seven Picasso paintings worth an estimated $44 million were stolen from a gallery in Zurich, Switzerland. They were recovered in 2000.
- April 1991: Two masked armed men took 20 paintings - worth at least $10 million each at the time - from Amsterdam's Van Gogh Museum. The paintings were found in the getaway car less than an hour later.
- March 1990: In the biggest art theft in U.S. history, $300 million in art, including works by Vermeer, Rembrandt and Manet, was stolen from the Isabella Stewart Gardner Museum in Boston, Massachusetts, by two men in police uniforms.
- December 1988: Thieves stole three paintings by van Gogh, with an estimated value of $72 million to $90 million, from the Kroeller-Mueller Museum in a remote section of the Netherlands. Police later recovered all three paintings.
- May 1986: A Vermeer painting, Lady Writing a Letter with her Maid, is among 18 paintings worth $40 million stolen from Russborough House in Blessington, Ireland. Some of the paintings are later recovered.
- August 1911: Perhaps the most famous case of art theft occurred when the Leonardo Da Vinci's Mona Lisa was stolen from the Louvre by employee Vinczo Peruggia, who was caught two years later.
Wednesday, 19 May 2010
Security is simple......
I suppose the purpose of writing this blog and sharing my experiences, questions and concerns is a way of me trying find out more and attempt to understand what it is about security that makes everyone an expert. I understand that the physical or technical security application to a site, risk or areas is important, but will always strongly maintain that without the right people, processes and procedures it doesn’t matter about the Rolls Royce kit if it’s not being utilised properly.
I was fortunate to present at the recent Counter Terror Expo 2010 on providing assurance to senior management of security risks. Whilst preparing I found myself getting angry at the lack of people in the security world actually talking about this subject and noted that there are lots of ideas, discussions, plans and strategies about what the government do and how parts of the Critical National Infrastructure (CNI) are assisted by that, but the gulf between public and private I think is just too great. What happens to the private company, limited company or the small business that would not have exposure to or have the staff to understand the CONTEST strategy or the HMG Security Policy Framework (which I believe is being widely touted and over used as the way forward) what does it mean to any of them? The same could be said for most other areas of the (and for now I use the words loosely) ‘security world’ as what do they do about countering fraud, personnel security and screening arrangements for the insider threat.
Following my presentation I received feedback from a couple of visitors who said it was interesting and that they hadn’t really given providing assurance much thought, "my Finance Director could understand some of our security risks that way, thanks". Now I am not suggesting it was a pinnacle of my career but I took this feedback as a compliment (don’t get many so I’ll take it) but thought maybe I should open this discussion up to others, maybe I could post some of the questions that I don’t think I could answer without comparing it to religion, football or politics. So here goes…..it’s a simple one really….. Ready….....
What is Security?
I really hope anyone visiting this blog can help me, I am guessing there's no absolute right or wrong answer but any comment will assist in my quest, thanks for reading.
Tuesday, 18 May 2010
National Trust Defends Security After Theft
Thursday, 13 May 2010
Another year another visit to IFSEC
I have been lucky enough to attend a number of events this year including Infosec (too many IT geeks there for my liking), the Counter Terror Expo (which was good and Richard was a speaker at the conference), HOSBD (which was very good, but with too much testosterone on show for my liking). I have learnt a number of important lessons whilst walking around 1) don't look anyone in the eyes you are not interested in talking to, 2) don't walk onto any stands you are well 'not interested in talking too' and 3) don't let anyone scan your badge otherwise you will be bombarded with spam (these are very important points to remember). Yes I know I sound miserable but with over 600 exhibitors (plus the Facilities and S&H expo's), frankly I do not have the time or dare I say the interest in some of the products, services or even the companies (maybe that's another blog idea).
The plan was to meet up with a number of contacts, look at some security 'porn' and to spend some time in the SMT Select Lounge networking, all of which I happily achieved and gained some valuable contacts from. IFSEC serves a purpose for me which is that it maintains my knowledge and awareness of the latest technology available in the industry (although IFSEC is a little 'death by CCTV'). I don't spec for systems but I do need to know if there is a more effective solution available. But it is much like attending the British Motorshow I wouldn't buy a car just because I saw it (or sat in it) at the show. IFSEC is without question a one stop shop for all the latest technologies available to security professionals.
Whilst having a cup of coffee I did overhear a conversation between two fellow visitors and one said to the other 'it is good but how many bloody CCTV cameras can you look it'! A fair point I thought.
I would be interested in knowing from any exhibitors what their conversion rates are. The stands are getting bigger, brighter and clearly more expensive (some even had cars on display) I guess it must be worthwhile attending IFSEC or is it purely making sure that your are seen......keeping up with the Jones?
A couple of areas I feel IFSEC is missing is around the areas of Risk Management and Security Audit/Assurance (both are very important factors in an organisation where Security is embedded). Technology is important but how do organisations provide the ongoing assurance to the rel event boards or committees that they have the appropriate measures in place to manage security and mitigate against risks? Also what about Personnel Security we all know how important this area is (and its an ever increasing list of companies that have now made security departments responsible for pre-employment screening) but I didn't see any stands showcasing this? If the organisers truly want to provide a world-class show these are areas which must be represented, after all we are in a very cost conscious climate and technology solutions are expensive and are not always an option!
I think it should be compulsory that all senior management (with responsibility for security) or at the least budget holders to attend this show. In terms of security it is glitzy and actually demonstrates that security is much more then a uniformed guard stood on a door. Dare I say the show was almost sexy! Just look at these.........
and these............. Also for anybody out there who is interested yes I did attend the Facilities Show and yes I also attended the Safety and Health show (or Health and Safety as its known to most). How did they compare to IFSEC? Well it just wouldn't be a fair comparison.....IFSEC had an Audi R8 on display, but they were blowing stuff up in the S&H show!
So will I attend next year, yes why not, hopefully some of the more cost effective solutions might be on display and by then maybe automated security guard robots will be released upon the world.....although some say we already have these!
