Showing posts with label Crisis Management. Show all posts
Showing posts with label Crisis Management. Show all posts

28 August 2026

9/11 Revisited: The Future Homeland Security Practitioner...

We are approaching the 9/11 anniversary and the images and memories will be revisited.


Many of us will shed a tear and millions will recall where they were and what they were doing, on that unforgettable Tuesday morning in September, 2001. 


The education of "Homeland Security" is taking place on a daily basis in the popular press and on the new social media platforms that have risen and now dominate the digital content since 9/11.


The academic and government institutions have strived for improving the standards, processes, rule sets and protocols for anti-terrorism policy. By education, we also need to explore what we are doing to collaborate at the academic institution level on a global basis, not just on a government basis. 


The "Homeland Security" curriculum at universities in the EU and the United States will soon be converging on several fronts and for good reason. The generation that will be starting their 1st year (freshmen) in college were not even born yet in 2001.


Their perception of what Homeland Security is today and the future for a life long career must be designed on a global basis, because this remains a global issue. 


The students who pursue an education in languages, political science, international affairs, history and science have just as much a stake in the future of Homeland Security as others. Those who are now getting a degree in emergency management, criminal justice or risk management, or information security are well on their way, yet still may lack the knowledge and tools their liberal arts colleagues have learned to be better analysts, intel targeters or linguists. 


A flash back to this article on "Homeland Security Intelligence" (HSI) , reminds us that regardless of the university education one receives, the future of effective strategies across the world will stem from intelligence: 


(27 February 2011 HSI: Homeland Security Intelligence…)

“What is the modern definition of U.S. Homeland Security Intelligence (HSI)? Many would differ on the jurisdiction, sources and nexus with specific intelligence that falls outside U.S. borders. The future of sharing relevant pieces of the vast mosaic of information may well lie with the definition and the interpretation of Homeland Security Intelligence.

One thing is certain about this topic of debate. If the information is being utilized to determine the nature of a threat within the confines of the U.S. Homeland, then that information will be treated according to the laws of the United States. This brings us to the next question. Are the current laws an impediment to more effective Homeland Security Intelligence (HSI) processes, methods and outcomes? The following areas must be addressed in order to get closer to the truth. 

  • Governance
  • Policies
  • Regulatory and Statutory Concerns
  • Civil rights and Liberties

Yet the question begs the discussion on the structure and the purpose of the Intelligence Community (IC) itself.”

Whether the homeland security incident is a natural catastrophe or a man-made threat, there are several components that all people pursuing a profession in the discipline should be developing with increased competency, including risk mitigation, legal framework, ethics, communication/collaboration, alternative analysis, supply chain, critical infrastructure, emergency/crisis management and terrorism. 


Those kids who were not even born yet on 9/11, may have a different perspective on what might be important these days in order to detect another attack of the same magnitude during these times of heightened digital and mobile awareness.


They grew up with the Internet and they don't need a class in Social Media 101 or how to use TikTok. They might however, also need some training in AI or the Deep Web, if they want to support the HSI infrastructure, or understand the adversaries modus operandi. 


The definitions of Homeland Security Intelligence (HSI) and what comprises the spectrum of relevant and legally obtained information may differ from country-to-country and state-to-state.


Is it legal to perform digital triage on an iPhone that has been part of a lawful search and seizure in the State of Ohio, USA? 


The education for Homeland Security professionals beginning with the university must take into consideration the requirements that exist for collecting, analyzing and sharing relevant and legally obtained information. The next step is to determine the correct skills that must be developed, before the newly minted student is filling out their first job applications or interviewing for their first internship. 


As we reflect on the 9/11 25 year milestone, we can all admit the journey has not been easy. It is still far from over.


Let the next decade produce our next generation of Homeland Security professionals who may decide that Social Media and Internet AI expertise is just as vital to the curriculum as Privacy and Civil Liberties.


Watch this area to converge dramatically over the course of the next few years and for the Supreme Court in the United States to make some landmark decisions…

09 May 2026

Business Resilience: Beyond Readiness…

The Continuity-of-Operations-Plan (COOP) for your Communications operations is an operational risk that in many cases is underestimated until a significant business disruption occurs.


When Comms are down, this means a combination of voice and data services that serve your business enterprise may not be available.


The resilience of both the voice and data communications is the holy grail of continuity of operations and disaster recovery professionals on a global basis.


Business Resilience and the ability to effectively anticipate or absorb the impact of an incident, whether man made or as a result of a natural phenomenon differentiates your suppliers.


When is the last time you tested your Tier I service supplier for a mission critical business process to determine the ability to keep their voice and data services running during a time of crisis?


And maybe more important, is your own enterprise “Incident Command” system survivable so that you can provide voice leadership to your "Incident Commanders" where ever they may be located on the globe.


When it comes to planning for the next Hurricane Katrina or the "Tip of the Spear" overseas operations readiness, resilient business organizations need to implement robust planning, immersive exercises and systems to be able to overcome the asymmetric “Operational Risks” that are now before them.


Power blackouts are the catalyst for many risks to the “Critical Infrastructure” including Transportation, Internet, Voice communications and even those services that you take for granted, like pumping gas at the local petrol station or emergency services at the local hospital.


Cyberspace as we know it is so deeply embedded into most of the mission essential aspects of business today that our readiness factor needs to go well beyond redundant power supplies and battery back ups just for power.


Cyber-Readiness is a key component of any organizations plan to stay resilient in the face of a Distributed Denial of Service Attack (DDOS) and other cyberspace exploits that may disrupt our operations.


Do you think you're spending too much time with your team planning and training?


You haven’t.

The organizations whose teams have planned for every possible scenario and trained together in live immersive simulations will become the most successful in their strategy execution.

Their missions will be accomplished on time and within budget.


Incidents of different severity and frequency are happening all around you and your organization every day.


Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?


Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things will go wrong…

28 March 2026

CRMS: Mechanisms for Continuous Risk Monitoring...

Stryker, Lloyds Bank, European Commission, Fortinet and others have yet to announce their settlement with recent hacker and/or data breach law suits.


One of the systemic resilience problems at large institutions including large and global organizations like Stryker is keeping your finger on the pulse of "Risk Indicators”.


Unfortunately for SVP's and other CxO executives in the corporate hierarchy, your middle managers are creating the layer that impedes the best Early Warning System you have at your disposal.


When problems surface on the front line or in the "Cube City" down in Information Systems, the normal agenda is for the employee to go to their direct supervisor to raise the "Red Flag" or disclose the incident.


And the first behavioral response by the Middle Manager is to keep it quiet. Fix it before anyone else finds out. Keep it under wraps until damage control can be implemented.


When you are the head of Enterprise Risk Management, you need mechanisms to bypass and eradicate the barrier holding your intelligence, incidents and overall hunches for ransom.


There is no magic system or process that will solve it all. The only way to attempt at breaking through this layer of social and organizational dysfunction is to circumvent it.


A continuous risk monitoring system has to be implemented and operating anonymously 24/7 if the upper echelons of executive management are ever going to "Feel the Pulse" of true risk hotspots in the company.


These hotspots translate into human "Risk Indicators" from the sources themselves, people who know what's going wrong and know the truth.


A Continuous Risk Monitoring System (CRMS) is an automated human feedback and problem identification mechanism for detecting risks. It allows leaders of large organizations to quickly identify problems and incidents of all kinds in their company.


Call it a sophisticated whistle-blower system or suggestion box but that is exactly what it is, on steroids.


The ideal system would emulate communication patterns in small groups which is often a major ingredient in successful teams. It would also run on the existing computers and networks of the organization or from home by logging in via a trusted VPN.


The soldiers on the front line know what is going on far sooner than the commanders in the “Joint Operations Center” just as the employee or 3rd party supplier does and they need a way to communicate the issue, concern or threat in a rapid and efficient manner.


The system provides the executives with instant or trend based Intel that is actionable. It provides the "Insight" as well as the pertinent facts that you need to make quick effective decisions.


Think about how long it takes for data and relevant information to percolate and bubble up from the places in your organization that are considered "Current Risk Hot Spots”.


The point is that for far too long we have been playing the old telephone game. You know, the one that you played as a kid sitting around the kitchen table or on the floor in a circle.


One person starts and whispers into the ear of the person to their right. Just a sentence or two. By the time the message gets around to the 3rd or 4th person, now the data is dramatically different than the original. It's been interpreted, edited and sanitized.


Walk down the hall or pick up the phone and contact the person in person who is in charge of the corporate “Emergency Operations Plan (EOP)”, electronic suggestion box or corporate whistle-blower program at your institution.


Ask them for the most recent activity log.  Ask yourself how you could get this mechanism to perform better and then work with your front line to develop something that middle management can't filter, change or delete.


That is when you will be on your way to getting the real story, in more recent real time…


07 February 2026

SMART Objectives: The Catalyst for Resilience...

Operational Risk Management (ORM) is evolving into a discipline with an over arching set of objectives. The organizations and entities that do not understand the purpose and the reason behind having SMART objectives, might need a refresher:
  • Simple
  • Measurable
  • Achievable
  • Realistic
  • Task-oriented
Without "SMART" objectives, any project will continue to strive for a purpose and a relevant set of outcomes. Constituents, stakeholders and various affected employees that intersect with an internal risk mitigation exercise, will continuously require coaching on how to base the project on "SMART" objectives.

Next, the stakeholders will require a path forward that includes a building block approach to gaining consensus, agreement and a set of written events that will either be simulated or real.

These events comprise a master scenario, that the organization will utilize to test a hypothesis or set of operational capabilities. The high reaching outcome, is to determine where there are gaps, vulnerabilities and opportunities to improve.

The building blocks approach may include:
  1. Seminars
  2. Workshops
  3. Table Top Exercises
  4. Games
These provide the stakeholders with the opportunity to converge on their respective areas of expertise and integrate them with the overall scenario being developed. However, these are still based upon first identifying the "SMART Objectives" and the application to your particular business, organization, city, state or country.

Taking the foundation of Operational Risk Management and applying a process for evaluation, requires a set of standards so all of the respective constituents, will be talking and practicing from the same exercise play book.

In the United States this standard is HSEEP or "Homeland Security Exercise and Evaluation Program":
The Homeland Security Exercise and Evaluation Program (HSEEP) is a capabilities and performance-based exercise program that provides a standardized methodology and terminology for exercise design, development, conduct, evaluation, and improvement planning.

The Homeland Security Exercise and Evaluation Program (HSEEP) constitutes a national standard for all exercises. Through exercises, the National Exercise Program supports organizations to achieve objective assessments of their capabilities so that strengths and areas for improvement are identified, corrected, and shared as appropriate prior to a real incident.
Whether your organization is new to doing functional or full-scale exercises doesn't matter. Having a process oriented model for program management and project management will provide you with the tools and the foundation to achieve new found learning on where and how to improve your enterprise resilience.

Operational Risk Management professionals are working with an organization or population that is constantly striving to be more resilient.

Without testing, without exercising and without the process framework in place to try and achieve measurable objectives, the organization will never gain the vital insight on where and how it can improve rapidly.

It will never fully understand where the enemy will try and exploit the weaknesses. The organization will never realize their resilience factor at this point in time.

When was the last time your organization really tested itself, to survive? How long has it been since you re-established the relationships and the trusted connections with your own supply chain? Why has it been that long?

There are some elite organizations in the world who understand readiness, that have learned along the way of their evolution why exercising and a trusted supply chain is critical to their own survival before the next incident occurs:
To become a SEAL in the Naval Special Warfare/Naval Special Operations (NSW/NSO) community, you must first go through what is widely considered to be the most physically and mentally demanding military training in existence. Then comes the tough part: the job of essentially taking on any situation or foe that the world has to offer.
Direct action warfare. Special reconnaissance. Counterterrorism. Foreign internal defense. When there’s nowhere else to turn, Navy SEALs are in their element. Achieving the impossible by way of conditioned response, sheer willpower and absolute dedication to their training, their missions and their fellow spec ops team members.
This analogy to the Navy SEALs demonstrates that preparedness long before you are asked to test your own resilience, will save lives. Yet there are so many other ways that our planet and the people on it, are being tested every day outside of the context of counterterrorism or national defense missions.

When you think about resilience in the context and relevance of the threats before us, we all have to realize that whether it is the National Level Exercise (NLE), or our US Navy SEALs, only SMART objectives will increase our ability to learn, to save lives and allow for the potential survivability of our organizations or impacted populations.

24 January 2026

Leadership in Crisis: Building Trust with Continuous Training...

How often have you ever heard the leadership management philosophy that you must "Train Like You Fight"?  Here is another way to look at it:

"The more you sweat in peace, the less you bleed in war." Norman Schwarzkopf

The theme is all too familiar with Operational Risk Management (ORM) teams that operate on the front lines of asymmetric threats, internal corruption, natural disasters and continuous adversaries in achieving a "Defensible Standard of Care."

As the senior leader in your unit, department or subsidiary the responsibility remains high for preparedness, readiness and contingency planning.  Your personnel and company assets are at stake and so what have you done this month or quarter to train, sweat and prepare?  How much of your annual budget do you devote to the improvement of key skills for your people in a moment of crisis or chaos?

What will the crisis environment look like?  Will it develop with clouds, water and wind or the significant shift in tectonic plates?  Will it begin with the insider employee copying the most sensitive merger and acquisition strategy to sell to the highest bidder?  Will it start with a single IT server displaying a warning to pay a ransom or lose all possibility of retrieving it's data and operational capacity to serve your business?  Will it end up being another example of domestic terrorism or workplace violence like San Bernadino, Paris or Ft. Hood?

Leaders across our globe understand the waves of risk and the possible issues that they may encounter each year.  Many travel to Davos to the World Economic Forum where the world tackles these disruptive events, with the best minds and exchange of information.  Why? They understand that vulnerability is what they fear the most.

Yet what can you do in your own community, at your own branch office to address the Operational Risks you face?  How can you wake up each day with the confidence as a leader, that you have trained and prepared for the future events that will surprise you?  It begins with leadership and a will to lead your team into the places no one really likes to talk about.  The scenarios that people fear to train for, because they think they will never happen.

Achieving any level of trust with your employees, your customers and your supply chain revolves around your leadership.  The discipline of "Operational Risk Management" is focused on looking at all of the interdependent pieces of your business mosaic.  The environment you operate in, even the building that houses your most precious assets.  All of these factors are considered in developing and executing your specific plan for training and readiness.

So what?  The question is

"Why Don't Employees Trust Their Bosses"?

Why this lack of trust?

As a leader your roles are multi-faceted and there is never enough time or money in the budget.  The leaders who excel in the next decade, will find a way.  They will invest in their teams training and the systems to increase trust, by addressing Operational Risk Management (ORM) as a key component of the interdependent enterprise.

The "TrustDecisions" you require and the understanding developed to insure effective "Trust Decisions" by all of your stakeholders will remain your most lofty goal as a leader.

How you train to fight and how you sweat now will make all the difference in your next war.  From the boardroom to the battlefield your leadership is all that is needed.  Your leadership will make a difference...

09 August 2025

Facilities Safety: +Beyond Travel Risk Management...

Have you ever wondered where high value assets are located in your facility or on your campus? Especially those that are mobile assets. Have you ever wondered who and where visitors to your offices or campus facilities are located at any given time?

Ekahau is making the answers to these and other questions much easier and at a more rapid response. Safety, production costs, and time-to-market are vital points of consideration for industries, education and campus organizations.

"By being able to easily track people, vehicles, and assets, these factors can be made substantially more safe and efficient."

Founded in 2000, Ekahau is the recognized leader in location-enabling enterprise Wi-Fi networks. Ekahau's mission is to provide the easiest, most cost effective and accurate positioning solutions for locating people, assets, inventory and other objects using wireless enterprise networks. The Ekahau solution tracks wireless laptops, PDAs, VOIP phones, Wi-Fi tags and other 802.11 enabled devices.

Ekahau’s solution allows businesses to keep track of valuable assets and equipment, improve the overall workflow, and improve the levels of corporate security and customer service. With Ekahau, the critical corporate resources, people and assets, will be always available at the right place and at the right time.

As Ekahau's location tracking solution does not require installation of proprietary wireless infrastructure, but can be done individually over the private Wi-Fi network, the deployment cost is kept in minimum, and the overall system payback time is the fastest possible.

Safety and security applications are numerous especially in Healthcare:

• Emergency management - more efficient and faster emergency response

• Patient monitoring - better patient safety and increased throughput

• Workflow management - better staff utilization and increased patient throughput

• Equipment management - reduced need for inventory

• Information delivery - improved workflow, reduced errors

• Billing support & verification - improved revenue capture

Can you think of other Homeland Security and first responder applications using the Ekahau capabilities especially in post event incident management and key personnel tracking inside a closed perimeter? As WiMax and other 802.11 networks are deployed in major metro locations, the applications become wide spread.

People: Beyond Travel Risk Management...

When was the last time your corporate travel department gave you some timely INTEL?

Maybe you got a report on the current level of risk in the foreign region, city or country you are now scheduled to visit in the next few days. What are you going to do if everything “Goes South” in a matter of seconds or minutes?

The Mission

In situations that require instinctive response, you have to go beyond the traditional travel management report on what to do and who to call. You have to be proactive and make decisions on your own.

In order to survive, one must be trained on the authoritative, detailed description of the methods by which terrorist organizations, hostile intelligence services, and criminal groups select and target specific individuals.

Individuals and a team must learn how they can detect and counter potential threats against them, and their sponsoring organizations to better manage these pervasive operational risks.

These threats could include recruitment by a hostile service, kidnapping or assassination by terrorist and criminal elements or espionage by business competitors.

Combined with real-time INTEL, you must receive intense, real-time instruction in surveillance detection and counter-surveillance so that you can take appropriate actions.

Combining real-time intelligence with a focused surveillance and threat detection-training program is exactly what savvy corporate executives and Chief Security Officers are looking for from a single source.

Personnel threat management is a prudent risk mitigation solution. This combination is one key strategy to mitigate the operational risks associated with key personnel in your organization.

Individuals whose occupations place them at risk may include people with access to valuable proprietary information or holders of high level security clearances, the wealthy and those responsible for their safety.

The Take Away

Combine two parts Threat Detection & Management Training with one part INTEL and you have the perfect combination to ensure the successful completion of corporate or organizational missions across the globe…