Protective Security Training for Security Managers
.
A security problem develops and people look to the security manager for answers. What is happening? What is the risk? What matters most? What should we do?
This is where professional capability becomes visible. Security knowledge, qualifications and policies all have value, but when an organisation needs an answer, knowledge has to become judgement, decisions and action.
Effective protective security training should develop the judgement to assess problems, make sound decisions and turn those decisions into action.
.
What Does a Protective Security Manager Need to Be Capable of Doing?
Protective security is ultimately about making sound decisions concerning people, assets, operations and risk. A capable security manager needs to understand the operating environment, identify what actually needs protecting, recognise credible threats, find vulnerabilities and assess the risk they create.
The difficult part is what should be done about it. Not every vulnerability requires another security measure, and not every threat justifies significant expenditure. Resources are finite, while organisations also have operational, financial and commercial priorities.
The security manager therefore needs the judgement to determine what is reasonable, practicable and proportionate to the risk. Poor decisions can leave vulnerabilities unmanaged, waste resources, disrupt operations or create security measures that provide reassurance without delivering effective protection.
.
Why Security Knowledge Alone Is Not Enough
Consider a busy commercial premises where management becomes concerned about a potential security threat and asks the security manager for advice.
It would be easy to immediately start discussing CCTV, access control, guarding, hostile vehicle mitigation or additional procedures. But that starts with solutions before the problem has been properly understood.
The first task is to establish what needs protecting and why, identify the credible threats, understand existing vulnerabilities and protective measures, and determine the potential consequences. Only then can the risk be assessed and appropriate measures considered.
Protective security training should develop this thinking process rather than simply provide more information to remember.
.
Protective Security Risk Assessment and Decision Making
Risk assessment sits at the heart of protective security decision making. Its purpose is not simply to complete a template or produce a numerical score. It is to understand the problem well enough to make a credible and defensible decision.
That requires the practitioner to consider:
• what the organisation needs to protect
• threats relevant to the operating environment
• vulnerabilities and potential adversary opportunities
• existing protective measures
• potential consequences
• organisational risk tolerance
• reasonable and practicable options for reducing risk
The value comes from the judgement applied to that information. A security manager should be able to explain what is recommended, why it is necessary and how it will reduce the identified risk.
.
Turning Risk Assessment Into Protective Measures
A risk assessment only creates value when its findings lead to proportionate measures that can be implemented, maintained and used in practice.
Protective measures should therefore be considered as a system. People, procedures, physical security, technology, communications and operational requirements need to support each other rather than operate independently.
The human element is particularly important. A procedure may appear effective on paper but fail because people do not understand it. Technology may be capable but poorly monitored. Security officers may be well trained but positioned where they cannot identify a developing problem.
This is particularly relevant to Martyn’s Law, where organisations need people who understand their roles and can implement public protection procedures effectively. For security managers, this reinforces an important principle: having a procedure is not the same as having the capability to deliver it.
The objective is not simply to add more security. It is to create protection appropriate to the risk that works within the organisation and performs as intended when it is needed.
.
Communicating Security Risk to Decision Makers
Security managers rarely make significant organisational decisions alone. Senior management, operations, finance, facilities, HR, legal teams, contractors and external stakeholders may all influence what happens next.
Technical security knowledge therefore needs to be translated into clear business language. Decision makers need to understand the problem, potential consequences, level of risk, available options, recommended action and implications of doing nothing.
A capable practitioner should be able to explain these issues without unnecessarily complicating them. This is often the difference between producing a sound security recommendation and getting that recommendation understood, supported and implemented.
.
Developing Practical Protective Security Capability
Professional development should leave a security manager more capable of identifying and prioritising problems, assessing risk, challenging assumptions, developing proportionate solutions and communicating recommendations with confidence.
Real security problems rarely arrive with complete information or an obvious answer. Practitioners have to find the relevant information, distinguish evidence from assumption, determine what matters and make defensible decisions.
This requires more than knowing what security measures exist. It requires understanding why they may be needed, where they should be applied and how they contribute to the wider protective system.
.
Protective Security and Counter Terrorism Practitioner Development
Mildot Group develops practical protective security and counter terrorism capability for security practitioners, managers and organisations operating in the private sector.
Our Private Sector Counter Terrorism Practitioner Programme provides 30 hours of accredited professional development built around the judgement and practical skills required to turn knowledge into action.
The programme develops capability across protective security risk assessment, threat and vulnerability analysis, protection in depth, counter terrorism, the human element, crisis management and business continuity, interoperability, commissioning security measures, adversary thinking and stakeholder decision making.
Developed from operational and corporate security experience, the programme is designed for practitioners who need to understand not only what protective security measures are, but why they are required and how they are developed into practical capability.
Individual enrolment and Corporate and Group Accounts are available.
.
Build the Judgement Others Depend On
The value of protective security training becomes visible when a real problem develops and people look to you for an answer.
Can you identify what matters, assess the risk, explain your reasoning and recommend something that will actually work?
That is the capability organisations depend on.
.
.
Useful Links:
.
