Physical security · The built environment

Where does security truly exist within an organisation?

Security is often viewed as a function, a department, or a specialist discipline. But what if it is something more?

Security is a thread, not just a discipline.

Organisations are strengthened not by isolated controls, but by the connections between the disciplines that shape them. Like the strands of a web, every decision influences the whole. When security is woven through those disciplines, it becomes part of how an organisation thinks, decides and succeeds.

This website explores what happens when organisations stop treating security as a function and start weaving it through every discipline. If these ideas resonate, then welcome to the conversation.

A point of view

Better decisions begin with better ways of seeing.

Security exists wherever organisational decisions are made. It runs through strategy, governance, operations, procurement, facilities, resilience and countless everyday choices. It influences them all, yet belongs exclusively to none of them.

Most of the writing shared here sits one layer beneath hardware, standards and compliance. It explores the thinking behind security: how decisions are made, the assumptions that shape them, and whether those decisions remain sound when tested over time.

Because security is rarely won or lost at the moment of an incident. More often, it is shaped long before, by the quality of the decisions that came before it.

The Thread Model

One question, explored through every lens.

The lenses above are not a collection of interests. They are one evolving philosophy: security as a thread woven through the decisions an organisation makes. The Thread Model is where that thinking lives, grows, and invites challenge.

Take something with you
You can't count the attacks that never happened. Success often looks like nothing at all. But failure is visible, costly, and judged in hindsight.
From Beyond the Checkbox
Where the writing comes from

The executive years

I spent years as a security executive across Africa, one of the hardest schools in the profession. There were decisions made less than 60 kilometres from a war zone, kidnappings, internal fraud, civil unrest, and the challenge of rebuilding programmes from whatever could be saved after failure. Those experiences shaped my judgement, but they are not what I value most.

I value the opportunity to have built high-performing teams, developed future leaders, worked in organisations recognised for their culture, and solved problems for which there were no established answers. Looking back, those years taught me that security is ultimately about people. Technology changes, threats evolve, but good judgement, trust and leadership endure.

The consulting years

Consulting broadened my perspective in ways I had not anticipated. Today my work spans giga projects in the Middle East, major developments in England, and clients across Europe and North America. The projects are remarkable, but it has been the clients and the people I work alongside who have had the greatest influence on my thinking.

As a security executive, experience was often enough to guide difficult decisions. Consulting demanded something more. Experience still matters, but it must be supported by evidence, aligned with recognised standards and tested against the thinking of other experienced practitioners. Working alongside colleagues who help shape global practice has challenged my assumptions as much as it has confirmed them. They continue to sharpen my technical understanding, strengthen the way I justify my recommendations, and remind me that expertise is never finished.

The projects themselves are confidential, so I rarely write about them directly. Instead, I write about the principles that emerge across projects, organisations and countries. They are the ideas that continue to shape my thinking and the reason this website exists.

The person behind the thinking

Practitioner first, strategist second. The long version is on the about page.

Writing

Lenses, not lectures.

Each piece here tries to leave you with a different way of seeing a familiar problem, not just another answer. The current series looks at how decisions in physical security are actually made.

Everything here is the working out of one evolving philosophy, the Thread Model of Security: one question, explored through six lenses.

The Thread Model
The decision-making series
Resources

Free tools, drawn from the writing.

One Companion per lens as the series grows, with one-page field tools alongside them. Creative Commons, made to be used.

Blog

The person, not just the practice.

Shorter, more personal, and not always about security. The thinking that does not fit the technical writing, but shapes it anyway.

The Uniform Is Not the Person

For recruiters and leaders: understanding the person behind the experience, not just the label they carry.

Read

More to come

This is where the personal writing will build over time, alongside the technical series.

Soon
← Back to the blog

The Uniform Is Not the Person

Blog · First published July 2026
A split portrait: one half a corporate face, the other camouflage face paint beneath it, a hand lifting the corporate half away like a mask.

For recruiters and leaders: understanding the person behind the experience, not just the label they carry.

My commanding officer once wrote in a performance review that I was not really a soldier, but an adventurer. At the time, I took it as criticism.

I had not simply coped in the military, I had excelled. Physically, mentally and intellectually, I had proven myself capable of performing at a high level. I could operate under pressure in combat environments, make sound decisions with incomplete information, and set the standard for others when conditions were at their worst. I was well placed for the next stage of a military career.

So why would someone who knew me well say something that sounded like a dismissal of the thing I had worked hardest to earn? For a long time I thought he was questioning my commitment. Looking back, I think he recognised something before I did. I was not building a career around being a soldier. I was using the military to discover who I was.

Those are very different things.

I joined at an age when I was trying to understand myself. Like most young people, I had spent years moving through systems that told me who I should be. Parents, teachers, society, all handing you labels long before you have had a chance to decide whether they fit. The military offered me something different. Not freedom. Challenge.

I have always performed best when things become difficult. I do not seek difficulty for its own sake, but I have learned that challenge reveals something. When the world becomes uncertain, I become clearer. When the pressure rises, the distractions fall away, and the person I am trying to be moves closer to the person I actually am.

So the military was the obvious test. Give me the hardest thing you have, and I will throw everything I have at it to succeed. At that age I did not understand what I was really doing. I was not looking for a career. I was looking for a measure of myself. The challenge was never the destination. It was the environment where I would find parts of myself I could not see anywhere else.

The strange thing is that the parts I expected to define me were not the parts that stayed. I assumed it would be the training, the physical demands, the responsibility, the moments where you are pushed past what you believed you could carry. All of that mattered, and yes it shaped and it tested me. But it is not what stayed with me. What shaped me most was the people.

I saw more combat than most people do. Different roles, different environments, situations many will thankfully never experience. And still, when I look back, it is not the combat I return to. It is the relationships.

There is something about working in an environment where the consequences of a decision arrive immediately. Where success and failure are not abstract. Where people depend on each other, not because a policy says so, but because it matters. Trust becomes tangible. Leadership becomes something you experience rather than something you describe. Character becomes visible.

You learn quickly that people are not defined by what they say about themselves. They are defined by what they do when circumstances turn. The military manufactures those circumstances. It puts people in situations where physical, mental and emotional limits are tested at the same moment, body and mind and spirit all engaged at once. The point is not hardship for its own sake. The point is to create the conditions where a person finds out what they are capable of.

The military did not create me. It revealed me. It showed me things that were already there, before I had the words for them. Perhaps that is why conversations about military service are so often strange. For people who have never been near it, the military is difficult to read. They see the visible things: the uniform, the rank, the medals, the book, the films, the stories. And naturally they try to make sense of them. We all do this, we use what we can see to understand what we cannot.

The trouble is that the visible part is rarely the whole story. Military service is not one experience. It is thousands of different experiences gathered under a single organisation. A person who spent a career leading soldiers in contact has lived a very different life from someone who spent it maintaining aircraft, analysing intelligence, running logistics, providing medical support or managing administration. Same uniform, same commitment, completely different environments, responsibilities and lessons.

The uniform creates a category. The individual experience creates the person. This matters because we all reach for shortcuts. We sort people into groups because it helps us handle a complicated world. Soldier. Veteran. Officer. Engineer. Doctor. Executive. The label gives us somewhere to start. But when we mistake the label for the person, we stop being curious, and curiosity is where understanding begins.

When the uniform becomes a measure of manhood

To understand why military service can grip an identity so tightly, it helps to understand the world some people experienced it in. I grew up in South Africa in the 1980s, in a society where service was universal among all men. Veterans were everywhere. Your teachers, your doctor, your minister, your uncles, your grandfather. Everyone you looked up to had served, and many had seen combat. Service was not something separate from society. It was the society.

That carried into ordinary life in ways people rarely said out loud. A teacher who had held a higher rank than the headmaster might command a different kind of respect. Rank and service and experience meant something well beyond the organisation that issued them.

For a young man in that environment, the message was not subtle. The military was not a job. It was the very thing that set one apart from others. Combat was the ultimate test, the place where courage and character were measured against something real.

I can see now how powerful that idea was, and how basic. The desire to prove yourself is not a military invention. It is deeply human. Young men in particular go looking for something hard enough to tell them who they are. The military offered exactly that. A mountain to climb, a standard to meet, a place to find out what you could do. But the test does not define the person. It only reveals something about them.

Over the years I have noticed what happens when people learn about my background. The conversation shifts. Sometimes it is curiosity, sometimes admiration, sometimes discomfort. The questions are almost always well meant. People are trying to reach an experience that sits outside their own.

One question has followed a lot of veterans.

“So, how many people have you killed?”

It is an uncomfortable question, but it often reveals more about the person asking than the person being asked. In my experience, it usually comes from one of two places. Some ask with a kind of excitement, wondering whether they themselves would be capable of violence in combat. Others ask from fear, trying to work out whether they should be afraid of you.

Both are understandable responses, but neither begins with an understanding of combat or of the person standing in front of them. The question is shaped by the asker’s own assumptions, fears and curiosity. It reduces a human being to a single imagined moment—and misses everything that came before and after it.

The same thing happens across an interview table. A veteran and a recruiter can share a language and still miss each other entirely.

The veteran tends to describe experience through responsibility: the people they led, the decisions they made, the uncertainty they worked inside, the problems they solved. The interviewer tends to listen for familiarity, for something that maps onto their own organisation. And military experience is usually described in a language that does not exist in civilian workplaces.

A veteran may talk about the size of the team they were accountable for, the complexity of the environment, the decisions they made without enough information, and what it would have cost to get those decisions wrong. To someone who knows that world, those details communicate judgement and leadership immediately. To someone who does not, they sound like unfamiliar terminology. The value is there. The translation is missing.

So interviews with veterans often become conversations about the wrong thing. The interviewer works on the experience. The veteran is trying to describe the person who came out of it. Those are not the same.

A rank does not tell you how someone leads. A deployment does not tell you how someone handles pressure. A combat role does not tell you how someone works with other people. Those things give you context. They do not give you conclusions.

I have found that the most revealing questions are never about what someone achieved. A person can tell you they led a team; the better question is what they learned about leading people. A person can tell you they worked in difficult conditions; the better question is how those conditions changed the way they decide. A person can tell you they faced adversity; the better question is what they found out about themselves when it arrived. The experience matters. The meaning behind it matters more.

None of this is unique to veterans. Everyone arrives carrying a history that shaped them. The teacher, the doctor, the entrepreneur, the athlete, the parent. Our mistake is assuming that the most interesting thing about a person is the thing that is easiest to identify. It rarely is.

With veterans this cuts both ways, which is worth saying plainly. Some interviewers see only the good: discipline, leadership, resilience, a willingness to carry responsibility. Others focus on the unknown, wondering whether someone has been changed by what they saw, whether they will fit a different culture. Both reactions come from trying to understand. Both become limitations the moment they replace curiosity.

Because the danger of a stereotype is not that it is negative. Assume every veteran is a natural leader and you will miss the individual just as completely as if you had assumed the worst.

The best interviewers I have met were not the ones who understood the military. They were the ones comfortable admitting they did not, and willing to say: help me understand what that meant. Behind every unfamiliar term is a human experience. A decision. A responsibility. A moment where someone had to adapt. That is where the value sits.

People often describe veterans as direct. Abrupt. Too honest. Occasionally difficult. I think that reading misses something.

In most military environments, clarity is not rudeness. It is respect. When misunderstanding carries a real cost, communication becomes deliberate. You learn to say what you mean, to strip out ambiguity, and to accept that dodging a hard conversation almost never makes the problem smaller. Honesty has value because it lets other people decide well. It is not bluntness for its own sake. It is valuing someone enough to give them what they actually need.

That travels badly. Many civilian organisations run with more layers: diplomacy, consensus, the careful management of relationships. Those things have real worth. But they change what people expect from the way a message is delivered. A veteran may believe they are showing respect by being clear. The person receiving it may hear something else entirely. Neither is wrong. They are working from different assumptions.

The same behaviour reads differently depending on the room. Confidence can look like arrogance. Directness can look like aggression. Certainty can look like inflexibility. Often what you are seeing is simply a person applying lessons that worked somewhere else.

So the useful question is not why does this person communicate like this. It is: what experience taught them that this was the right way to communicate? Behind most behaviour there is a reason, and finding it is where leadership starts.

The mask we all wear

In 2003 I started journaling. The first words I wrote were: Who am I?

That question has followed me through every stage of my life since, and the more I have experienced, the more I have come to think identity is not something fixed. It is something we keep building.

We all wear masks. Not out of dishonesty, but because we are social. We present different parts of ourselves depending on where we are standing. At work, the professional version. In relationships, something else. Inside a team, we adapt to the people around us.

The military is no different. A soldier wears a uniform, but the uniform is not the person. It is a role, a responsibility, a way of operating in a particular environment. The danger comes when we confuse the role with the individual, and assume the person we can see is the whole person.

I struggled with that distinction myself for years. The military was the apex of my life. The intensity, the responsibility, the relationships, the certainty that decisions mattered. Experiences like that leave a mark, and for a long time I kept defining myself through that chapter. It was a significant chapter. It was formative. It was still a chapter, not the book.

The irony is that even inside the military I was wearing a mask. To operate there you have to believe in yourself. You have to trust your ability, stand in uncertainty and decide anyway, and project confidence while knowing exactly how difficult the thing in front of you is. That ability is necessary. It is also a role. The person others saw in those moments was the person the moment required.

Which is worth holding onto if you ever interview someone who has served. You are not meeting the soldier. You are meeting someone who once played that role, learned from it, was shaped by it, and has kept growing since.

Leaving is where this becomes obvious. We describe it as a career transition, a change of employer. For many people it is a change of identity. In the military there is almost no separation between the person and the profession. The person leading the patrol is the same person sharing the trench, eating, sleeping, suffering and celebrating with the same people. The relationships do not stop at the end of the working day. The responsibility does not either.

That is what makes leaving difficult. You are not simply leaving an organisation; you are leaving an environment in which nearly every part of you was engaged.

I have done that more than once. When I left South Africa, I did not just leave a job. I left a country, and a version of myself that country had shaped. The military brought a different culture, a different organisation, and a different understanding of service. Later came other chapters. Each identity was real, but none of them was the whole picture.

Circumstances changed, and the labels changed with them. I no longer live on a farm or spend my weekends kayak fishing on the open ocean. But the person beneath those roles has remained.

We look for simple explanations of people: a label, a category, something that lets us decide quickly who they are. But people are not static, we are always growing. The veteran sitting across the table is not the person who first put on the uniform, nor the person who took it off.

When I made the image that goes with this piece, I was trying to catch something I think is widely misread. It shows me pulling away a corporate face to reveal camouflage underneath. At first glance it suggests the soldier is the real person and the corporate identity is the mask.

The longer I look at it, the more I think the opposite is true. Neither one is the whole person. The corporate face is a role. The camouflage is a role. Both are environments, responsibilities, versions of a self. The person exists beneath them both.

The military shaped me. It challenged me. It revealed parts of myself I might never have found anywhere else. It does not define me. And the same is true of everyone who has ever sat across an interview table with a history behind them.

I am still asking the question I wrote in that journal. Who am I? I no longer treat it as something needing a final answer. It is not a problem to solve. Every challenge, every relationship, every difficult moment adds another layer.

For me the military gave some of the clearest lenses I have. After moments where life and death were not abstract, priorities rearrange themselves. After being responsible for other people, relationships mean something different. After watching people perform under extreme pressure, your understanding of courage and character changes shape. Those lessons stayed with me, but not because they are military lessons. They stayed because they are human ones.

So to anyone interviewing someone who has served: do not hire the uniform, and do not reject it. Do not be distracted by the story they can tell you. Be curious about the person who lived it. Ask about the decisions. Ask what they learned. Ask who they became.

Before you ask them anything at all, ask yourself one question.

Am I interviewing their experience, or am I trying to understand the person who lived it?

Because somewhere beneath every uniform, every title and every achievement is a person still working on the same question I wrote down in 2003. And perhaps the most useful thing we can do for each other is stop assuming we already know the answer.

About

Who am I?

I wrote that question in a journal in 2003. I still cannot fully answer it.

Perhaps that is because we spend our lives becoming. You can leave home, spend decades crossing continents, and return bearing the same name, yet be an entirely different person.

Adriaan Bosch

I have travelled to 72 countries and worked across Africa, Europe, North America and Asia. Along the way I have been a student, a farmer, a soldier, a storyteller, a photographer, a guard, a guide, a loner and a father. I have known the despair of war and the privilege of protecting endangered wildlife.

Yet none of those things is who I am.

The road taught me something simpler: each of us is utterly unique, yet we hope, fear and dream in much the same way. That understanding has become the foundation of both my life and my work.

I try to leave the world a little better than I received it.

The work

There is rarely a day I do not learn something new.

I am fortunate to work in an industry that allows me to live my passions. It challenges me with some of the world’s most complex projects and takes me to places I never imagined I would see.

What I learn, I share. I have no intention of taking it to my grave. That is why this site exists.

I am equally fortunate as a leader. I have the privilege of helping young graduates grow, working alongside exceptional people, and continuing to learn from mentors who have shaped my own journey.

The record

I am a physical security strategist in the built environment. I spent years as a security executive across Africa and now advise on some of the world’s most ambitious giga projects.

IFSEC recognised me as one of the world’s most influential security executives. The full record lives on LinkedIn. This page is the person.

Everything I have experienced has led me to one conviction.

The security industry does not have a technology problem. It has a decision-making problem.

That is what I write about. The more personal side of that thinking, less technical, lives on the blog.

The operating principle

Security is a thread, not simply a discipline. It does not exist as a department that stands apart from the organisation. It runs through governance, strategy, operations, procurement and facilities because it is inseparable from the decisions people make and the way they behave. It belongs to all of them, even though it owns none of them.

Security owns its advice: the analysis, the design and the recommendations that follow. It never owns the risk.

The risk owner decides what is acceptable, weighs the cost and accepts what remains. Removing a security requirement is not a quiet cost saving. It is a conscious decision to accept additional risk, and it should be treated as such.

An evolving philosophy

The Thread Model of Security

Where does security truly exist within an organisation?

Security exists wherever organisational decisions are made.

Everything else flows from that. Decision-making is the mechanism by which the thread is woven.

The philosophy

Security is a thread, not just a discipline.

Security should not be viewed solely as a department, function or specialist capability. It is a management philosophy that recognises security as a continuous thread woven through every organisational discipline: governance, strategy, operations, procurement, human resources, facilities, continuity and compliance. It influences them all, yet belongs exclusively to none of them.

Notice what that definition leaves out: guards, cameras, access control, standards. They remain important, but they are expressions of the thread, not the thread itself. Security is not something organisations possess. It is something they embed.

Five principles
Three proofs

Everything the model claims was once done, and it worked.

These are from my executive years. They are not arguments, they are what happened when security thinking left the department. Each one proves a different part of the model.

Proves: security connects

The camera was never the deterrent

A camera on its own deters nothing if all it is intended to do is record images. In my younger years one of my mentors, Dr Craig Donald, said something I have never forgotten. Roughly: "The adversary always has a strategy that is in response to yours. They might not always know it, but it exists nonetheless." The adversary strategises around visible hardware faster than we can install it. Having a security system is not a deterrent. Having a process supported by a system to create a consequence is.

Deterrence does not sit in the hardware. It exists in the certainty of consequence: the chain that runs from the offence to a courtroom. Placement, angle, lighting, connectivity, power, maintenance, monitoring, response, evidence capturing, prosecution. Every link belongs to a different team, with security a single ingredient in the recipe.

This was one of the best lessons I learned in my retail years. We were an early adopter of two-way audio integrated into our video surveillance systems: a control room operator in a remote location could use live audio to interact with an adversary miles away. Few things are as powerful as picking an individual out of a crowd and saying "You there, in the blue shirt. I see what you just did. Someone is coming for you." The certainty of detection, every time, had the adversary on the run. But it did something more than deter. It made the customers feel safe. Ultimately security is not something that we are, but something we perceive to be.

Effective security is not based on the cost of the system but on its ability to shape human behaviour. To do that you need solutions that work together to achieve a specific desired behaviour. It matters more that every element is present than that one ingredient is left out to afford the shiniest product on the market.

Leave one element out of the recipe and the deterrent is gone, regardless of what was spent on the hardware. That is the main reason security cannot be owned by one department. The deterrent is something everyone owns a component of, and everyone is the beneficiary of.

Proves: the decision and intelligence pillar

It is a business, not just the burglar

When dealing with loss events in larger organisations, incidents of burglary and robbery are not isolated. They are often carried out by the same individuals. For these individuals it is not simply about a robbery or a single burglary. It is what they do. It is their profession.

It is not something an individual organisation can solve. When dealing with organised crime it takes a combination of entities working towards a common goal: security, investigators and prosecutors, all working together to deliver a consequence.

With this approach we started to look at securing evidence, not just monitoring space. It changed the angle of the camera, the lighting, the height of the camera. Instead of looking at scenes we were looking for evidence. Where did people touch? Did they leave something behind? What physical evidence was there to find? We started keeping track of stock numbers and IMEI numbers, and embossing our stock, all in an effort to create evidence. Evidence that could be traced to a source and linked to an individual.

That individual could then be linked to other incidents. The evidence is what leads up the chain, to the buyer and the recruiter organising it.

Where are they working from? Why are they targeting us? Those are the questions that ultimately lead to the solutions. We appointed analysts and an investigator to capture the information, create the links, and turn data into intelligence. In other words, to build a whole picture instead of a lone incident on a map.

Assisting the police in capturing the burglars, they were able to identify the buyers. Once they identified the buyers, the market disappeared. Once the market was removed, the incidents stopped.

Over two years, recorded incidents fell by over sixty percent. That number is the organisation's own, in its annual reports. There was no second programme to credit it to. This was the strategy: take down the organised criminals. Over the same period, other organisations were reporting rising losses.

What strikes me now is where the thread had to run to get there. Through psychology, changing control room operations, training new skills, intelligence work, and building relationships with agencies to understand how we could make their work easier. Then out past the edge of the organisation altogether, into the adversary's own supply chain. Not one metre of that ground belonged to the security department.

Proves: security enables

Delivering stock at night

When stock deliveries were moved to night, the security team had to step in.

Trucks doing deliveries at night met no traffic. Road time fell by about forty percent. Fewer hours on the road meant fewer accidents, less fuel, fewer trucks and fewer drivers, and runs that were once impossible became possible. But this could only happen in a secure environment: providing access to a store remotely and safely, tracking the truck, preventing syndicates infiltrating the drivers, and moving the opening and closing of the trailers to a remote control room.

This then enabled us to remove the bolt seals. We replaced them with locks released remotely from the control room, because a seal has to be cut and the offcuts were discarded on the ground, leading to tyres being shredded on a regular basis. Ending the flat tyres alone paid for the whole system inside a year. The security case supported by the financial one.

None of that changed the intent of the security strategy. All of it benefited from a security decision.

That is the part the department framing cannot hold. We were not there to reduce road time or to replace bolt seals. We were there to stop stock walking out. But a decision made in one discipline lands in every discipline it touches, and the ledger it lands on is rarely ours.

The custodian

Nobody owns security. Somebody must keep the thread.

This is where the idea has led me, although experience continues to test it.

For a long time I thought the role of the security professional was to own security. I don't think that's true anymore. Security lives in too many places, and depends on too many people, for anyone to own it.

What we can do is keep the thread intact.

That means noticing where it begins to fray. It means connecting people who would not otherwise speak to one another. It means making sure an observation reaches the person who can turn it into a decision, and that the intent behind the decision is not lost along the way.

It is quieter work than ownership. Most of it happens between disciplines rather than within them. When it is done well, it is almost invisible. When it is neglected, organisations slowly stop feeling what is happening around them.

There is one place where this idea could easily be misunderstood.

None of it replaces specialist security work. Detection, response and investigation remain expert disciplines. A connected organisation still needs people who know how to investigate, respond and make difficult judgements under pressure. An organisation that concludes security is now everybody's responsibility and quietly removes its specialists has not strengthened the thread.

It has broken it.

The thread carries the signal.

People still have to decide what to do with it.

Security is not something organisations possess. It is something they embed.
The Thread Model
How woven is your organisation?

Five levels, each with an observable test. The test is always what people actually did in real recent decisions, never what the organisation says about itself.

An honest test

What would count against it

A philosophy that cannot lose is a slogan. The Thread Model would be weakened by evidence that isolated security departments consistently match woven organisations on comparable outcomes, or by the maturity levels failing to distinguish organisations that behave differently in practice. The model invites that test.

One more honest note for readers in the built environment: the thread here is not the Building Safety Act's golden thread, which is a record of building-safety information. The two share a metaphor because the metaphor is good. They do not share a subject.

The Thread Model of Security is an evolving enterprise security philosophy. It reflects an ongoing exploration of how security is integrated into organisations through leadership, governance and decision-making. Like the organisations it seeks to explain, the model will continue to develop as new ideas, experiences and perspectives emerge.

Contact

If something here made you pause, I'd like to hear about it.

For conversations about security, decisions, or the writing.

Prefer another route? Message me on LinkedIn or browse my security links.

← Back to writing

Beyond Risk: the Role of Strategy in Security Decision-Making

Part two of the decision-making series · First published April 2025

Introduction: Security Decisions Are More Than Risk

Security as a discipline has long relied on risk assessment as the primary basis for decision-making. From threat modelling to vulnerability management, security frameworks consistently position risk as the foundational logic behind why actions are taken. However, while this focus on risk provides necessary structure, it is insufficient for making comprehensive or strategically aligned decisions, especially within complex business environments.

No widely recognised security standard explicitly mandates a multi-principle approach to security decision-making. Most frameworks centre exclusively on risk without incorporating additional influences such as financial constraints, compliance obligations, legal oversight, operational disruption, or business resilience. This leads to a disconnect, while security professionals build cases around risk reduction, business leaders make decisions based on a broader set of strategic drivers.

In practice, security decisions are shaped by a mix of external and internal forces, from finance teams demanding cost justification to legal departments enforcing compliance to operational leaders wary of friction or downtime. These influences are real and powerful, yet rarely formalised within traditional risk management models.

Business leaders, by contrast, operate from an integrated decision-making model. Their choices reflect trade-offs between multiple business goals, guided by key questions:

  1. Strategic Alignment – Does this support long-term business objectives?
  2. Financial Viability – Is there a return on investment or demonstrable value?
  3. Regulatory & Legal Compliance – Are we required to act?
  4. Operational Impact – Will it hinder efficiency or service delivery?
  5. Reputation & Stakeholder Perception – How will it be received publicly or internally?
  6. Risk Tolerance – How much risk is acceptable within our context?

This divergence in approach creates a communication and influence gap: security talks risk, while the business thinks strategy. To bridge this gap, security professionals must evolve their approach, not by abandoning risk, but by elevating strategy as a co-equal lens for making decisions.

In this article, we focus specifically on the role of strategy in security decision-making. We explore how strategic thinking complements risk analysis, enables better trade-offs, and aligns security decisions with broader business intent. The goal is to reframe how security contributes to decision-making, not as a barrier to risk, but as a driver of long-term business resilience and adaptability.

"Tactics without strategy is the noise before defeat." - Sun Tzu

What Strategy Adds That Risk Alone Cannot

While risk assessment helps identify and quantify potential threats, it lacks the capacity to prioritise across broader organisational objectives. Risk, by its nature, is reactive, it identifies what could go wrong and assigns weight to it. Strategy, in contrast, is proactive. It defines where an organisation wants to go, how it plans to get there, and what trade-offs it is willing to make along the way.

Long-Term Vision and Prioritisation

One of the key contributions of strategy is its ability to operate with a long-term orientation. Risk assessments are typically bounded by current-state analysis: they evaluate today's threats to today's assets in today's environment. Strategy looks ahead. It asks what the business will need tomorrow, what future risks will emerge, and how current actions support, or hinder, those future positions.

This long-term view enables prioritisation in ways that risk scoring alone cannot. For example, two risks may be rated similarly in impact and likelihood, but strategy helps determine which one matters more based on future growth, market entry plans, digital transformation initiatives, or stakeholder expectations. Strategy ensures that the organisation is not just doing what is "least risky," but what is most valuable over time.

Managing Operational Trade-Offs

Security decisions often involve trade-offs, between safety and speed, control and convenience, protection and productivity. Risk models can highlight vulnerabilities and recommend mitigations, but they typically do not account for the operational friction those mitigations might cause.

Strategy provides the framework for balancing these competing priorities. It helps decision-makers evaluate the consequences of control implementation, not just in terms of reducing risk, but in how they affect business performance. For instance, a high-security measure that slows down critical workflows may reduce the likelihood of theft, but if it also impairs the business's ability to deliver services or meet SLAs, the cost may outweigh the benefit.

Without strategy, there is a tendency to default to maximum security, without fully understanding or communicating the downstream effects. Strategy ensures that security solutions are operationally sustainable, not just technically sound.

Strategic Alignment with Business Goals

Perhaps most importantly, strategy ensures that security decisions are aligned with dynamic business goals. Unlike risk assessments, which often emphasise universal principles of exposure and mitigation, strategy is contextual, it recognises that what is appropriate for one asset, system, or organisation may not suit another.

Strategically, the asset type is a primary influence on the chosen approach. Two environments may face similar risk profiles, say, unauthorised access or data leakage, but the strategy to address them will differ depending on the value, function, and criticality of the asset involved. A guest services kiosk in an entertainment venue and a secure payment gateway may both be exposed to threat actors, but they demand distinct strategic treatments because their roles, operational dependencies, and business impacts vary.

This logic scales upward. The same principle applies at the organisational level. A security strategy that proved effective in a manufacturing environment may not translate well to a fast-paced, customer-facing entertainment operation, context matters. The right strategy is not just about the nature of the risk, it's about how that risk intersects with organisational structure, culture, and priorities.

Relying on historical precedent or industry norms without regard for business context can lead to strategic misalignment. Strategy enables organisations to resist the temptation of one-size-fits-all solutions and instead build decision-making frameworks that reflect where they are, what they do, and where they're headed.

"Strategy is not about avoiding risk. It's about knowing which risks to take, when, and why." - Adapted from military doctrine

Understanding the Trade-Offs

In physical security, every decision involves a trade-off. It's rarely a question of whether a site is secure or insecure, but rather, whether the measures in place are sufficient and proportionate for the context in which they operate, particularly where life safety is concerned. Security must be understood as a spectrum that balances protection, accessibility, and continuity of operations.

Security as a Spectrum, Not a Binary State

The simplistic framing of security as "secure" versus "not secure" fails to account for the nuances of real-world environments, especially those that are publicly accessible, complex, or multifunctional. In venues such as entertainment districts, stadiums, or urban public spaces, absolute security is neither practical nor desirable. Instead, the goal is to achieve an acceptable level of security based on clearly defined threats, potential consequences, and the environment's operational requirements.

In this sense, physical security is not just about stopping an event from occurring. It's about ensuring that if something does occur, systems and personnel are in place to protect life first, then assets, reputation, and operations.

Evaluating Cost, Usability, Resilience, and Business Impact

Strategic physical security must evaluate trade-offs across multiple domains:

  • Life safety: What measures are in place to protect people in the event of an incident?
  • Operational continuity: How do security interventions affect day-to-day functioning?
  • Public usability: Do security controls unnecessarily restrict movement or create public discomfort?
  • Cost and maintenance: Are the solutions financially sustainable over time?
  • Resilience: Can the environment recover quickly after a disruption?

These trade-offs must be explicitly considered, not just assumed. For instance, implementing hardened access control at a publicly accessible plaza might reduce intrusion risk but increase egress times in emergencies, raising life safety concerns. Likewise, deploying intrusive surveillance may improve situational awareness but impact public trust or community perception.

Rethinking "Reasonableness" in a Hindsight-Driven Culture

Physical security decision-making is also influenced by a wider legal and regulatory landscape, where enforcement and liability are often judged retrospectively. In practice, what is considered "proportionate" or "reasonable" is often not defined until after an incident has occurred. The absence of an attack rarely validates a strategy, but the presence of one is often seen as a definitive failure, regardless of preparation or limitations.

This reality complicates the application of principles like ALARP ("As Low As Reasonably Practicable"), particularly when it's difficult to clearly determine what would have been practicable under the circumstances.

In the context of physical security, especially where life safety is at stake, there is a need for a more grounded and transparent decision-making model. This includes:

  • Strategic intent: Was the decision informed by a clear understanding of asset type, threat profile, and stakeholder obligation?
  • Scenario foresight: Were potential threats considered not just in terms of likelihood, but consequence, especially for people?
  • Documented rationale: Can the choices made be traced to a structured, explainable process?
  • Preparedness posture: Were resources, personnel, and systems reasonably in place to respond?

By embracing this structured framing, physical security decisions can be better defended and more effectively implemented. It shifts the focus from theoretical proportionality to practical defensibility, ensuring that decisions reflect not just risk, but duty of care, public expectation, and operational feasibility.

"You can't predict the future, but you can prepare for the possible." - Anonymous

Dynamic Context Requires Strategic Framing

Physical security does not operate in a vacuum. It is embedded within constantly shifting environments, urban layouts evolve, crowd behaviours shift, threat actors adapt, and organisations change focus. A strategy that was effective last year, or in another part of the business, may no longer be fit for purpose today. To remain effective, security must be framed strategically, with an understanding that the only constant is change.

The Myth of Prediction

One of the most enduring misunderstandings in security planning is the belief in prediction, the idea that we can foresee what will happen and prepare accordingly. But prediction is a false promise. In physical security, there are no certainties, only possibilities. The goal is not to predict specific events but to maintain awareness of what could happen and to prepare systems, staff, and procedures to respond when those possibilities materialise.

Strategic framing accepts this uncertainty. It emphasises flexibility over certainty, preparedness over prediction, and responsiveness over rigidity. This approach ensures that security decisions are made not just for the most likely scenarios but for the plausible and impactful ones as well.

Context Is Not Static: It's a Moving Target

Security strategies that fail to evolve with their context become liabilities. A strategy suited for managing foot traffic at a sports venue may not translate to a festival site with open boundaries and fluid crowd dynamics. Similarly, an approach developed for managing third-party vendors in one region may not align with regulatory or cultural norms elsewhere.

Strategic framing must begin with context: What is the nature of the environment? Who are the users, stakeholders, or potential adversaries? What external factors (political, social, economic) shape how risk is perceived or managed?

This is where governance plays a pivotal role. Governance frameworks define the boundaries in which strategy operates: they clarify roles, set priorities, and articulate acceptable thresholds. Without these framing mechanisms, security strategies risk becoming disconnected from the very realities they are meant to address.

Framing for Scale, Change, and Accountability

As organisations grow or diversify, adding new venues, launching events, or expanding into unfamiliar geographies, the challenge isn't just scaling security operations; it's scaling the thinking behind them. Strategy must adjust not only to asset type but to organisational maturity, resource availability, and stakeholder expectations.

Framing allows security leaders to step back from reactive, incident-driven models and build strategies that:

  • Acknowledge and prepare for context-specific complexity,
  • Reflect the lived experience of users and frontline operators,
  • and are defendable under scrutiny, even when the unexpected happens.

This is especially critical in environments where public safety is paramount. Strategic framing makes space for nuance, for understanding not only the nature of the threat, but the consequence of inaction, the perception of preparedness, and the expectations placed on the organisation.

"True intelligence lies not in knowing more, but in understanding the weight of outcomes." - Inspired by Bentham's Felicific Calculus

Context, Data, and Intelligence: A Strategic Foundation

A robust security strategy is not just about having the right data or systems in place, it's about framing decisions through the lens of context. This is where strategy becomes more than planning, it becomes a mechanism for synthesising process, content, and context into coherent, defensible decisions.

Strategy = Process + Content + Context

At its core, strategy in physical security involves three interdependent components:

  1. Process – the structured methods by which decisions are made (e.g., assessments, stakeholder reviews, design principles).
  2. Content – the specific details of the environment, such as asset types, threat categories, and stakeholder responsibilities.
  3. Context – the surrounding conditions that shape how content is interpreted and how processes are applied.

Context is often the most overlooked of the three, but it is also the most influential. A solid process applied to the wrong context leads to poor outcomes. Similarly, content without context can be misunderstood, under-prioritised, or poorly defended.

Intelligence Is Context, Not Just Data

Too often, intelligence is mistaken for raw data. In reality, intelligence is data interpreted through context, it's what transforms observations into insight. Without the ability to situate data within a relevant, real-world frame, the outcome is often noise: overwhelming streams of information with limited strategic value.

In physical security, intelligence without context can lead to poor assumptions about intent, impact, or vulnerability. For example, knowing that a crowd is forming near a venue is data. Understanding whether that crowd is celebratory, confrontational, or unrelated to your site is intelligence. Only context can give meaning to the observation, and only contextual intelligence can inform action.

Contextual Intelligence and Strategic Decision Optimisation

This is where contextual intelligence, as defined by psychologist Robert Sternberg in 1984, becomes essential. Contextual intelligence refers to the ability to adapt one's thinking and behaviour based on environmental cues. Sternberg outlines three strategic modes of decision-making, highly applicable to physical security strategy:

  1. Adapting to the environment – aligning with current constraints (e.g., working within crowd density or infrastructure limits).
  2. Shaping the environment – modifying the context to meet objectives (e.g., redesigning flow paths, introducing early interventions).
  3. Selecting to withdraw or redesign – recognising when a strategy is untenable and rethinking the approach (e.g., cancelling or relocating events).

These approaches mirror real-life strategic dilemmas in physical security, where leaders must continuously choose whether to accept, mitigate, or avoid a given exposure. Each choice is only valid if it is rooted in a clear understanding of context, legal, cultural, spatial, and operational.

Perception of Consequence and Adversary Intent in Strategic Design

No security strategy can be complete without considering the adversary's perspective. In physical environments, deterrence is often achieved not just through visible barriers or patrols, but by shaping the perceived consequence of hostile action.

Three dimensions influence adversarial calculation:

  • Surety: How likely is the adversary to be caught?
  • Severity: How serious are the consequences if they are?
  • Swiftness: How quickly will those consequences follow?

This triad informs not only tactical deterrents but the strategic credibility of the entire security posture. A visible presence with no follow-through, or harsh penalties with inconsistent application, undermines deterrence. Strategy must anticipate and influence how consequences are perceived, not just how they are structured.

In short, a physical security strategy must account for intent as much as exposure. The most well-secured asset may still be targeted if the attacker believes the consequences are manageable, or worth the risk. Contextual intelligence helps design systems where intent is discouraged before it even materialises.

"Strategy is about making choices, trade-offs; it's about deliberately choosing to be different." - Michael Porter

Integrating Strategy into Security Planning

If risk assessment identifies what could go wrong, and technical controls define how we respond, strategy is what determines whether the response makes sense in the first place. To be effective, security strategy must be fully integrated, not just as an add-on to governance, but as a distinct strategic framework that informs decisions, guides investment, and aligns with the organisation's broader mission.

Strategic Framing as a Layer Above Risk and Technical Controls

Security is often reduced to a collection of risk registers, compliance checklists, and technology solutions. While these are essential components, they are not strategy. Strategy provides the why behind each decision: why this control, at this time, for this environment, and at this level of investment.

Strategic framing sits above risk and control, it connects purpose to action. It ensures that decisions about access control, surveillance, response protocols, or architectural design are not made in isolation but within a shared understanding of business priorities, public interface, and operational constraints.

Without strategic framing, physical security plans risk becoming either overbuilt and cost-prohibitive, or underdeveloped and ineffective. Strategy balances this by asking: What are we trying to protect, in what context, and to what end?

Building a Strategic Framework: More Than Governance

Governance structures define accountability, but they don't necessarily define direction. To achieve coherence across sites, departments, and projects, organisations must develop a strategic security framework that:

  • Articulates overarching principles and posture (e.g., deterrence-first, resilience-focused, people-centric)
  • Connects security goals to business objectives
  • Informs capital and operational planning
  • Aligns with other internal frameworks (e.g., crisis management, safety, risk, compliance)

Such a framework not only streamlines decision-making but also drives cost efficiency. By removing ambiguity and inconsistency, organisations reduce the risk of overengineering solutions in one area while underprotecting another. Over time, this leads to smarter capital allocation and leaner operational expenditure without compromising performance.

Planning Techniques: Scenarios, Modelling, and Trade-Off Analysis

Strategic security planning is not just a boardroom exercise, it involves applied methods that can test ideas, stress assumptions, and forecast outcomes. Among the most effective techniques:

  • Scenario planning: Developing and stress-testing responses to a range of credible events
  • Trade-off analysis: Weighing the implications of security measures against operational, financial, and reputational costs
  • Security modelling: Mapping physical, human, and procedural systems to understand vulnerabilities, interdependencies, and response capacity

These tools support evidence-informed decision-making, enabling leadership to balance control and flexibility, certainty and adaptability, risk and resilience.

Positioning Security as a Business Enabler

The end goal of strategic integration is not just better security, it's better business. When strategy is embedded in planning, security shifts from being a reactive cost centre to a proactive enabler of operations and reputation. A secure environment is not only safer, it's more trusted, more resilient, and more adaptable to change.

In environments where people gather, interact, or seek experience, such as entertainment venues, public spaces, or vendor-managed zones, strategy is what ensures security enables flow, not friction; confidence, not control for control's sake.

Integrating strategy into physical security planning ensures that protection is not an obstacle to business, but a structured contributor to its continuity, adaptability, and growth.

Closing Statement

When security decisions feel stalled, contested, or disconnected from business objectives, the root cause is often not the absence of risk data or technical options but a gap in strategic framing. Decision fatigue, inconsistent implementation, and resistance from leadership or stakeholders are frequently symptoms of this underlying misalignment.

Reframing security through a strategic lens, grounded in context, shaped by operational realities, and driven by intent, offers a clearer path forward. It enables security leaders to move beyond reactive controls and build systems that are not only defensible but sustainable, credible, and aligned with how the organisation actually functions.

This article is not a conclusion, it's an invitation. If your physical security decisions are being challenged or your frameworks are no longer fit for purpose, now is the time to realign through context, not just controls. Let's keep the conversation going because strategy doesn't end with a plan; it begins with a shared understanding of what matters most.

← Back to writing

The Flawed Singularity of Risk Determination in Security Decision-Making

Part one of the decision-making series · First published February 2025
"A problem clearly stated is a problem half solved." - Dorothea Brande

Security decision-making is often predicated on the singular objective of determining risk. However, this approach is inherently flawed as it relies heavily on intangible elements that do not align with broader business decision-making frameworks. While other corporate functions integrate multiple variables such as financial data, operational efficiency, and strategic goals, security frequently isolates itself within a narrow scope of risk assessment, leading to decisions that lack coherence with the organisation's overall objectives.

The problem of intangibility in security risk assessment

Security risk assessments frequently rely on qualitative factors, expert judgement, and hypothetical threat scenarios. Unlike financial risk assessments as an example that are data-driven and quantifiable, security risks often involve ambiguous or unpredictable threats. This reliance on intangibility creates a perception gap between security management and business leadership, reducing the perceived credibility of security-based decisions.

Furthermore, the subjectivity of security risk assessment means that different assessors may arrive at vastly different conclusions when evaluating the same scenario. This inconsistency further alienates security decision-making from standardised business practices, where consistency and data-backed reasoning are paramount.

The challenge of security leadership and governance

The governance structures of an organisation play a crucial role in framing security parameters. Proper governance ensures that security is not seen as an isolated function but as a key element of corporate resilience. By correctly framing security requirements within governance frameworks, organisations can establish clear parameters for security decision-making. It is not just simply stating the requirement of alignment with the ALARP (As Low As Reasonably Practicable) principle. What is Practicable should be defined by the organisation and not left as an undetermined value with unlimited outcomes. It should ensure that security measures are both proportionate and justifiable within the broader business context, not just the risk landscape.

While representation in executive decision-making is important, security is ultimately a support function within the business. It should be able to operate effectively without requiring direct board-level representation. Instead of solely relying on hierarchical authority for decision-making influence, security management must employ multiple mechanisms to justify and implement its strategies.

The ability to utilise diverse mechanisms ensures that security decisions align with business priorities and remain adaptable to changing contexts. A rigid reliance on singular risk assessments limits security's ability to function as a strategic enabler, reinforcing the need for a multifaceted decision-making approach.

The importance of framing elements in security strategy

Within the overall security framework, the framing of elements is fundamentally important in the development of the security strategy. Risk plays a critical role within this framework, but it is not the sole foundational element to consider. The decision-making parameter is essential as it enables organisations to define the processes and content of strategies in a constantly changing context.

This is particularly important in security, as security operates within a highly variable context. It is not solely dependent on a fluctuating asset base but must also contend with a dynamic risk landscape. Security strategies must be capable of functioning within this dynamic environment, adapting to evolving threats, operational shifts, and external influences. Proper framing within the security strategy ensures that decision-making remains agile, relevant, and effective, allowing security teams to proactively address risks while aligning with broader business objectives.

If you find it difficult to gain buy-in for your security solutions, it may be time to examine how you arrive at your conclusions. Decision-making cannot be based solely on singular risk assessments; it must integrate multiple mechanisms that account for operational realities, business priorities, and governance frameworks to provide a comprehensive and credible argument for security investments.

← Back to writing

Heuristics in Strategic Security Decisions: The Problem Isn't Starting There, It's Stopping There

Part three of the decision-making series · First published May 2025

In security strategy, we all start from what we know. A leader with a background in manned guarding is likely to lean toward personnel-based solutions. Someone from a technical systems background might default to surveillance and intruder detection systems. These approaches aren't wrong, in fact, they often reflect real-world experience and delivery confidence. The problem isn't starting there. It's stopping there.

I often find, working with a wide variety of clients and diverse projects, that there is no single approach that is universally applicable. Although many fall into the trap of duplicating a process that has worked for them in the past, context always matters. What worked in one environment may fail in another. This is especially true in physical security, where each location, threat profile, and stakeholder landscape brings its own complexities. Strategic decisions made by default, rather than by design, often result in solutions that are well-executed but misaligned.

As consultants or in-house strategists, we are often brought in to close a gap the stakeholders know exists but can't always define. Working in a consultancy role, the challenge is that clients will often try to shape our contribution around what they already understand. In doing so, they risk reconstructing the same problem, just with new packaging. Our job isn't just to deliver a solution; it's to help reframe the problem. That's why building mutual awareness into the process is so critical.

To approach this problem, start with the following steps:

  • Name the dynamic early: "Here's what I bring. Here's what I might miss."
  • Use structured inquiry: stakeholder mapping, threat framing, and non-technical scenario walkthroughs.
  • Encourage the client to reflect on their own defaults, and be open about your own.

The solution isn't to abandon heuristics, it's to formalise them, challenge them, and situate them in context. Strategic thinking starts with self-awareness: knowing your default approach, and then asking if that's what the problem really needs. It means creating the space to test ideas beyond habit and anchoring decisions in relevance, not routine.

To formalise and elevate strategic thinking, security leaders should incorporate a decision framework that includes heuristic awareness checkpoints. These checkpoints help ensure that decisions are driven by fit-for-purpose logic, not just familiarity. Here's how that can be structured:

Problem framing

  • What is the core challenge we are solving?
  • Are we addressing a symptom or the root cause of a broader issue?
  • Is this a tactical problem or a strategic one?

Contextual analysis

  • What makes this environment, threat, or population unique?
  • How do variables like life safety, business continuity, and public perception influence the stakes?
  • What constraints (legal, spatial, social) shape the feasible options?

Option diversification

  • What solutions exist outside my personal or organisational default toolbox?
  • Who from other disciplines (technical, behavioural, architectural, environmental) should inform the strategy?
  • Are we considering layered, integrated approaches rather than single-point fixes?

Bias audit

  • Why am I drawn to this solution? Is it because it worked before, or because it fits this context?
  • What alternatives did I dismiss too early, and why?
  • Have we challenged our initial assumptions through inquiry or feedback?

Decision rationale

  • Can I clearly articulate why this option is the right fit for this specific challenge?
  • Can others evaluate, understand, and defend this decision under scrutiny?
  • Are we documenting our rationale to support institutional learning?

Lastly, it's vital to recognise that no single consultant or strategist can embody every skill, perspective, or lived experience. The goal is not to create a "super consultant" but to build strategic teams with diverse skill sets, viewpoints, and even neurodiverse cognitive approaches. Diversity in thinking helps mitigate blind spots, challenge echo chambers, and introduce alternative problem-solving models that wouldn't arise from one mind alone.

The most resilient strategies are rarely the product of a single genius, they emerge from well-framed decisions made by collective intelligence that respects complexity, interrogates assumptions, and balances intuition with structure.

In practice this is what it might look like:

  • Framing problems in capability-neutral terms ("We need awareness of X" instead of "We need CCTV on X").
  • Asking, "What would this look like if we couldn't use our usual approach?"
  • Bringing in parallel disciplines to pressure-test your logic.

Heuristics are not the enemy. In fact, they often contain the seeds of good decisions. But without reflection, they can just as easily become shortcuts to stagnation. Strategic leadership in security doesn't require knowing every answer. It requires having a process that keeps us from stopping too soon, and helping others do the same.

← Back to writing

Beyond the Checkbox: Strategic Thinking in Compliance-Driven Security Decisions

Part four of the decision-making series · First published July 2025

Compliance is often seen as black and white, but in practice, it's anything but.

Compliance-driven decision-making is often misunderstood as being simple or binary, "comply or don't." In reality, compliance is layered, jurisdictional, and deeply context-sensitive. In physical security, where decisions must stand up not only to operational tests but also board-level scrutiny or legal review, relying purely on checklists or minimum standards is rarely sufficient.

From government mandates and national security regulations, to sector-specific practices, and even internal corporate protocols, compliance influences every layer of security strategy. But where do you start? What do you need to comply with? And more importantly, how do you ensure your decisions are justifiable, transparent, and strategically sound?

This article shares insights from working across complex physical security environments to explore a more strategic view of compliance. Rather than seeing it as a constraint, we explore how compliance can function as a foundation for clearer, more defensible decision-making, when it's framed correctly.

1. Understanding the compliance landscape

There's no single source of truth when it comes to compliance in security. You're usually navigating a mix of laws, internal policies, and sector guidance, all with a different intent and often pulling in different directions. To make good decisions, it's critical to understand these layers and how they interact. Here are the big categories you're likely to encounter:

Legal or regulatory obligations. These come from national authorities or local jurisdictions and must be met for a facility to operate legally. They may include technical specifications, procedural requirements, or approvals from relevant ministries or government bodies. These are non-negotiable, and failure to comply can carry legal or financial consequences.

Industry-recognised standards. These are often developed by professional bodies or international organisations and define good practice within specific sectors. While not always legally binding, they are widely accepted as the benchmark for safe and effective design.

Internal organisational standards. These reflect a company's own policies and are sometimes more demanding than external requirements. They may include global security frameworks, internal performance thresholds, or design expectations shaped by corporate values such as sustainability, resilience, or stakeholder accountability.

Voluntary best-practice frameworks. These are often maintained by independent third parties and offer certifications, accreditations, or design principles. While optional, they can bring reputational benefits, support insurance or investor requirements, and serve as useful tools when navigating complex or contested design environments.

Understanding compliance, then, is not about simply checking off boxes. It's about recognising that different standards apply in different ways, and the real challenge is knowing how to balance, prioritise, and defend your choices within this layered environment. The point here isn't to memorise every standard. It's to recognise that compliance sits within a system, and that system needs to be navigated, not blindly implemented.

2. A strategic approach to compliance

Being compliant doesn't mean you're secure.

In my experience, one of the biggest challenges in physical security consulting is assisting decision-makers in understanding that it's not just about being compliant, but understanding how compliance supports the organisation's goals. When approached strategically, compliance becomes a tool to clarify priorities, protect resources, and demonstrate accountability.

This is especially true in physical security, where compliance does not automatically equate to effective protection. For example, a standard focused on delay resistance may pass a technical test, but that same barrier may be ineffective against an adversary using coercion or social engineering as a tactic. Compliance alone won't create a holistic solution. You still need to understand your threat and apply the correct mix of systems, processes and procedures that mitigate it.

Strategic compliance also means recognising that misalignment has consequences:

  • Overemphasising technical compliance can undermine public usability or safety. (There is always a tradeoff.)
  • Ignoring local mandates in favour of corporate preferences can result in legal exposure.
  • Blindly following outdated internal policies can fail to address new risks altogether.

When facing a compliance requirement, whether internal or external, it's not enough to ask "Are we compliant?" The real question is: "Does compliance support our objective, and is it sufficient?"

To move from checkbox thinking to strategic clarity, consider these questions as part of a layered framework:

1. Clarify the requirement. Is this requirement mandatory (legal, regulatory, or internal)? What is its core intent, and does it match our actual risk context? Does it apply fully to this site, asset, or operation, or only in part?

2. Assess coverage and gaps. What risks or operational factors are not addressed by this requirement? Are there known threat types or business sensitivities it overlooks? Does it conflict with any other obligations (e.g., life safety, public access)?

3. Select supporting frameworks (if needed). Is there a voluntary standard that meaningfully fills those gaps? Why are we choosing this specific framework, reputation, technical merit, stakeholder expectation? Are we adopting it in full or only in part, and what's our rationale either way?

4. Conduct a cost-benefit review. Does this approach justify the investment in terms of security, safety, or business value? What impact will it have on usability, operations, or public perception? Is there a simpler or more adaptable way to achieve the same outcome?

5. Document and defend. Can we clearly explain why we chose this path, in this context, at this time? Have we captured gaps, trade-offs, and the reasoning behind voluntary standards used? Have we set a review trigger to revisit this as the context changes?

This framework doesn't slow down decision-making, it supports it. It ensures that compliance isn't just followed, but understood, applied with intent, and used to strengthen strategic outcomes. Used this way compliance becomes a reference point, not a finish line. It can help prioritise investment, align teams, and provide justification. But only if you stay curious about what's behind it, and how it fits your specific risk picture.

3. Simplifying complexity with a decision framework

Compliance is a snapshot in time.

What passes today might fall short tomorrow. Threats shift. Laws change. New priorities emerge.

One thing I've seen time and again: the decisions that get questioned later are usually the ones that weren't clearly recorded at the time. It's not that the wrong choice was made, it's that no one can explain why it made sense then.

That's why I often encourage teams to treat compliance decisions not just as technical tasks, but as strategic steps worth documenting. It doesn't need to be complicated, but it does need to be deliberate. Here's a simple framework I use to help structure and record decisions. It's not rigid, it's a tool to support better thinking and clearer conversations.

1. Map the compliance landscape. What rules apply here? Start by listing the relevant laws, regulations, internal standards, and voluntary guidelines. Be honest about which are mandatory and where there's room for interpretation. Record a short summary of each requirement, its source, and how you're applying it.

2. Understand the context and the threat. What makes this situation unique? Asset type, public use, known risks, these shape how compliance should be applied. Record the site context, user dynamics, threat profile, and key assumptions.

3. Define the strategic intent. What are we actually trying to achieve? Is the goal deterrence, life safety, business continuity? Get clarity first. Write a one-line statement of intent. It keeps everything grounded.

4. Evaluate the trade-offs. Where are the tensions? Sometimes compliance clashes with safety, usability, or operations. Make that tension visible. Record what options were considered, and why you chose the path you did.

5. Justify and capture the decision. Why did this make sense at the time? You're not just protecting a site, you're protecting your reasoning. Use a format that includes: Context, Objective, Options, Rationale, Review date.

And keep in mind: this isn't a one-time exercise, build in review cycles. Make documentation part of your process. That's how you keep decisions defensible, not just compliant.

4. The role of internal standards and governance

Governance doesn't exist to slow things down. It exists to make decisions deliberate, explainable, and repeatable.

Too often, internal standards are either outdated, overly rigid, or forgotten. But when they're done right, they become one of the most useful tools for making consistent, confident decisions, especially when you're navigating multiple influences like compliance, risk, and operations.

What makes internal standards valuable isn't how detailed they are. It's that they reflect your organisation's intent. They define what "good" looks like for you, and help people make better calls when things aren't black and white.

When structured and maintained well, they deliver clarity (define what "good" looks like for your organisation), consistency (reduce project-by-project variation), speed (avoid rethinking basic elements each time), and accountability (support defensible, traceable decision-making). But they have to be alive, not static. Assign ownership. Update them when the landscape shifts. And always make sure they support decision-making, not just control it.

So how do you influence governance without authority? Internal governance is often shaped at a level where security may not have a formal seat. In many organisations, strategic decisions are driven by finance, operations, or legal, while security remains a support function. Yet even without direct authority, security professionals can shape governance. Influence isn't just about position, it's about framing, timing, and contribution. Here's what I've seen work in practice:

1. Align with existing business priorities. Position security standards as enablers, not barriers. Frame them around business outcomes, reduced liability, operational continuity, or protecting reputational assets. The more clearly security supports their goals, the more welcome your input will be.

2. Offer decision-ready inputs. Don't wait for an invitation to contribute, bring something to the table. Draft templates, propose baseline measures, or structure guidance that others can easily adopt or adapt. It's easier to influence governance when you provide something useful, not just raise concerns.

3. Collaborate across functions. Build informal alliances with facilities, safety, compliance, and risk. Governance often evolves through consensus and shared needs. The more cross-functional the support, the more staying power your contributions will have.

4. Promote review cycles. Internal standards shouldn't be static. Recommend clear ownership, scheduled reviews, and practical update triggers (e.g., after incidents or regulatory changes). This keeps standards relevant, and reinforces your role as a forward-thinking contributor.

5. Build for real use. Avoid complexity for complexity's sake. Good standards should guide, not constrain. Use plain language. Focus on actions and principles. And make sure what you're proposing is usable by the people who have to apply it.

Internal governance isn't just about control, it's about creating a shared language for better decisions. And while you may not always have a seat at the top table, you can still shape the conversation. Often, the most effective influence comes not from authority, but from clarity, initiative, and relevance.

5. Closing reflections

This is the fourth piece in a bigger conversation about how decisions in physical security are made. We've looked at risk (and its limits), strategy (and its importance), heuristics (and their influence), and now compliance (and how to use it wisely).

Each one plays a role. But none of them are enough on their own. Compliance gives you legitimacy, but not always security. Strategy gives you alignment, but needs realism. Heuristics give you speed, but risk bias. And risk gives you focus, but can't predict the future.

Pull them together with the right frameworks, and you create something better: defensible decisions that make sense at the time, hold up under scrutiny, and serve the people they're meant to protect.

You can't count the attacks that never happened, the lives quietly protected, or the costs quietly avoided. Success often looks like nothing at all. But failure? That's visible, costly, and judged in hindsight.

That's why security decision-making isn't about getting it perfect, it's about making it justifiable, proportional, and context-aware, for the environment, for the moment, and for the duty we carry.

← Back to writing

The Hidden Fifth D

Part five of the decision-making series · First published August 2025

Physical security is usually explained through the four Ds: deter, detect, delay, and deny. They describe the actions and controls that shape defences, but they leave out something vital: how leaders decide which actions to take, when, and why. At the centre of it all lies Decision, strategic choices guided by intelligence and vision.

Think of it like baking. The four Ds are the ingredients: essential, but not enough on their own. Without a recipe to guide how they're combined, in what order, and for what purpose, the result won't hold together. Decision is that recipe, the framework that binds the ingredients into something coherent and effective.

The penny dropped for me while reading Decision Advantage by Jennifer E. Sims, a leading scholar and former senior U.S. intelligence official. In her work, Sims defines decision advantage as the use of intelligence to create a competitive edge in diplomacy and conflict. Applied to physical security, this means converting intelligence into strategic choices that shape the environment before threats materialise.

Great strategists like Sun Tzu remind us that victory is shaped long before the first move is made. In the same way, this article argues that decision must be recognised as the hidden fifth D, the element that gives meaning and direction to the others. As Jennifer Sims points out, intelligence isn't just about collecting information; it's about shaping choices in ways that create real advantage.

Seen through this lens, decision is the recipe that binds the four Ds (deter, detect, delay, and deny) into a coherent, forward-looking posture. The four Ds remain vital, but they are tactical by nature, focused on execution rather than intent. What they miss is the pivotal moment of choice. Every deterrent we design, every detection system we deploy, every barrier we build, every denial measure we enforce, all of them flow from earlier decisions.

If those decisions aren't grounded in sound intelligence and foresight, the four Ds risk becoming fragmented, reactive, or misaligned with broader goals. But when decision is placed at the centre, the four Ds stop being isolated controls and start working together as a strategy.

In previous articles, I have examined the foundations of decision-making. Here, I want to build on that work by exploring the idea of decision advantage, transforming intelligence from a support function into a strategic lever that unifies the four D's into a resilient, forward-looking security capability.

"Strategy without tactics is the slowest route to victory. Tactics without strategy is the noise before defeat." - Sun Tzu

Why decision must be explicit

Intelligence on its own doesn't change anything if it just sits there. It only becomes powerful when leaders turn it into action through clear decisions: setting priorities, directing resources, and creating real effects. As Jennifer Sims puts it, intelligence is information for competition, its purpose is to shape outcomes and help us navigate uncertainty.

That means intelligence can't just be a passive input or another report on the desk. It has to be an active lever, guiding which risks to accept, which to eliminate, and which to shape before they ever materialise. When intelligence is tied directly to decision, it stops being background noise and becomes strategy.

Strategy always comes before tactics. As Sun Tzu reminds us, the real victory is secured long before the first move is made. In practice, this means that the choices leaders make (what to deter, what to detect, where delay will matter, and what must be denied) set the stage for everything that follows.

The world we operate in is full of uncertainty. Threats shift, evolve, and often appear where we least expect them. That's why decision advantage matters: it allows organisations to learn faster, adapt their posture, and stay one step ahead while adversaries are still catching up. In this sense, intelligence isn't just a rear-view mirror telling us what has already happened, it's a forward-looking guide to what should happen next.

When intelligence is tied directly to decision, it becomes a living cycle: decisions drive outcomes, outcomes generate data, and that data sharpens the next decision. This feedback loop turns security from a static checklist into a dynamic system of learning, foresight, and adaptation.

← Back to writing

Where Security Actually Lives

Introducing the Thread Model · First published July 2026

There is a camera above the loading bay. Clear view, good lighting, records everything. In four years it has never stopped a single thing.

I have stood under a lot of those cameras. Early in my career I would have called one a deterrent. I don't anymore. A camera is a witness: one with a perfect memory and no authority. It can tell you exactly what happened, but it cannot influence what happens next.

That left me with a question I couldn't answer for a long time. If the camera wasn't the deterrent, what was? I kept looking at the technology when I should have been looking at everything connected to it.

The chain nobody owned

What stops someone is the certainty of consequence, not the chance of being seen. The camera only provides the chance of being seen. Whether that sight becomes consequence depends on everything that follows.

The more I thought about it, the more deterrence began to look like a chain. Placement. Angle. Lighting. Connectivity. Power. Maintenance. Monitoring. Response. Evidence. Prosecution. Every link has a purpose. Break one and the whole thing weakens. The camera still records, but the certainty disappears. What remains looks like security, but behaves more like theatre.

The uncomfortable part was realising how little of that chain belonged to security. Lighting belonged to the electrical engineer. Power and connectivity belonged to facilities and IT. Maintenance belonged to the service provider. Response belonged to operations. Evidence and prosecution belonged to people outside the organisation altogether.

The security department owned only one link, yet we had convinced ourselves that buying and managing that link was the same as providing security.

The man in the blue shirt

I saw the difference during my retail years, when we were early adopters of two-way audio integrated into our surveillance system. An operator sitting a hundred miles away could speak directly into a car park.

One afternoon he picked a man out of a crowd.

You there, in the blue shirt. I see what you just did. Someone is coming for you.

The man stopped, looked around, and walked away.

It wasn't the camera that changed his behaviour. It was the certainty that the observation had become action. In that moment the technology disappeared. What mattered was that the man understood someone knew, someone cared and someone was already responding.

Something else happened that I hadn't expected. Customers felt safer. The equipment hadn't changed, but the organisation had become visible through it. People weren't responding to the presence of cameras. They were responding to the presence of attention.

That was the point I started to realise security is as much about confidence as control. People judge it less by the technology they can see than by the intent they believe sits behind it.

What the thread carries

For years I struggled to explain why all of this felt connected until I found myself thinking about a spider's web.

We usually think of a web as a trap. It isn't. The spider catches the fly. The web is something else entirely. It is a network of threads connecting the spider to its environment. Every strand exists to carry information. When something touches one corner of the web, the vibration travels to the only place that matters: the point where a decision can be made.

That is much closer to the way I now think about security.

The camera sees. The guard observes. Procurement notices an unusual supplier. A controller questions a journey that makes no sense. Facilities notices a door that no longer closes properly. None of those observations achieves anything on its own. They matter because they are connected to a process, driven by an intent and capable of producing an action. The thread is what gives each observation meaning.

Looking back, I realised the chain I had been describing was really just another way of seeing the same thing. Each link existed to preserve the thread from observation to consequence. Break the thread and every component still performs its individual task. The camera records. The guard watches. Procurement raises a concern. But the observation never reaches the place where it can change an outcome.

The thread is not simply communication. It is the path that carries intent through an organisation until observation becomes consequence.

Security is a thread, not just a discipline

This is the conclusion I have arrived at, although experience continues to test it.

Security does not live in a department. It lives wherever decisions are made. It lives in procurement decisions, maintenance schedules, facilities management, IT architecture, operational routines and a thousand small choices that nobody experiences as security decisions at all. It runs through every discipline while belonging exclusively to none of them.

That changes what I think the role of the security professional really is. We often behave as though we own security, when perhaps we are only its custodians. The work is not to own the thread but to keep it intact: to connect disciplines, preserve intent, ensure observations travel to the people who can act and notice when part of the thread begins to fray.

Security is less a function than a property of a connected organisation.

Where I could be wrong

Every model deserves a boundary, otherwise it becomes ideology.

Here is mine. Nothing I have described reduces the need for people who are very good at the sharp end. Someone still has to run the investigation, make the call at two in the morning, and keep their judgement together when it counts. That work does not get easier because more people are paying attention.

The failure this invites is a quiet one. A leadership team hears that security belongs to everyone and reads it as permission to thin out the people who do it. That is not a woven organisation. It is one that has mistaken awareness for capability.

The thread carries the signal.

People still have to decide what to do with it.

An invitation, not a doctrine

I am not offering a framework or a methodology. This is simply one practitioner's attempt to describe what experience has slowly taught him. It explains more of what I have seen than the models I used to rely on, but that does not make it complete.

If it is wrong, I would rather discover that than defend it. If it proves useful, then take it, challenge it and improve it.

The camera above the loading bay is still there. It still records everything that passes beneath it. What changed was never the camera. What changed was my understanding of where security lived.

It was never in the lens.

It was always in the thread that connected the lens to people, process and purpose.

Break that thread and the camera becomes exactly what it has always been: a witness with a perfect memory and no authority.