Showing posts with label Preparedness. Show all posts
Showing posts with label Preparedness. Show all posts

Friday, August 28, 2026

9/11 Revisited: The Homeland Security Practitioner...

We are approaching the 9/11 anniversary and the images and memories will be revisited.


Many of us will shed a tear and millions will recall where they were and what they were doing, on that unforgettable Tuesday morning in September, 2001. 


The education of "Homeland Security" is taking place on a daily basis in the popular press and on the new social media platforms that have risen and now dominate the digital content since 9/11.


The academic and government institutions have strived for improving the standards, processes, rule sets and protocols for anti-terrorism policy. By education, we also need to explore what we are doing to collaborate at the academic institution level on a global basis, not just on a government basis. 


The "Homeland Security" curriculum at universities in the EU and the United States will soon be converging on several fronts and for good reason. The generation that will be starting their 1st year (freshmen) in college were not even born yet in 2001.


Their perception of what Homeland Security is today and the future for a life long career must be designed on a global basis, because this remains a global issue. 


The students who pursue an education in languages, political science, international affairs, history and science have just as much a stake in the future of Homeland Security as others. Those who are now getting a degree in emergency management, criminal justice or risk management, or information security are well on their way, yet still may lack the knowledge and tools their liberal arts colleagues have learned to be better analysts, intel targeters or linguists. 


A flash back to this article on "Homeland Security Intelligence" (HSI) , reminds us that regardless of the university education one receives, the future of effective strategies across the world will stem from intelligence: 


(27 February 2011 HSI: Homeland Security Intelligence…)

“What is the modern definition of U.S. Homeland Security Intelligence (HSI)? Many would differ on the jurisdiction, sources and nexus with specific intelligence that falls outside U.S. borders. The future of sharing relevant pieces of the vast mosaic of information may well lie with the definition and the interpretation of Homeland Security Intelligence.

One thing is certain about this topic of debate. If the information is being utilized to determine the nature of a threat within the confines of the U.S. Homeland, then that information will be treated according to the laws of the United States. This brings us to the next question. Are the current laws an impediment to more effective Homeland Security Intelligence (HSI) processes, methods and outcomes? The following areas must be addressed in order to get closer to the truth. 

  • Governance
  • Policies
  • Regulatory and Statutory Concerns
  • Civil rights and Liberties

Yet the question begs the discussion on the structure and the purpose of the Intelligence Community (IC) itself.”

Whether the homeland security incident is a natural catastrophe or a man-made threat, there are several components that all people pursuing a profession in the discipline should be developing with increased competency, including risk mitigation, legal framework, ethics, communication/collaboration, alternative analysis, supply chain, critical infrastructure, emergency/crisis management and terrorism. 


Those kids who were not even born yet on 9/11, may have a different perspective on what might be important these days in order to detect another attack of the same magnitude during these times of heightened digital and mobile awareness.


They grew up with the Internet and they don't need a class in Social Media 101 or how to use TikTok. They might however, also need some training in AI or the Deep Web, if they want to support the HSI infrastructure, or understand the adversaries modus operandi. 


The definitions of Homeland Security Intelligence (HSI) and what comprises the spectrum of relevant and legally obtained information may differ from country-to-country and state-to-state.


Is it legal to perform digital triage on an iPhone that has been part of a lawful search and seizure in the State of Ohio, USA? 


The education for Homeland Security professionals beginning with the university must take into consideration the requirements that exist for collecting, analyzing and sharing relevant and legally obtained information. The next step is to determine the correct skills that must be developed, before the newly minted student is filling out their first job applications or interviewing for their first internship. 


As we reflect on the 9/11 25 year milestone, we can all admit the journey has not been easy. It is still far from over.


Let the next decade produce our next generation of Homeland Security professionals who may decide that Social Media and Internet AI expertise is just as vital to the curriculum as Privacy and Civil Liberties.


Watch this area to converge dramatically over the course of the next few years and for the Supreme Court in the United States to make some landmark decisions…

Saturday, February 07, 2026

SMART Objectives: The Catalyst for Resilience...

Operational Risk Management (ORM) is evolving into a discipline with an over arching set of objectives. The organizations and entities that do not understand the purpose and the reason behind having SMART objectives, might need a refresher:
  • Simple
  • Measurable
  • Achievable
  • Realistic
  • Task-oriented
Without "SMART" objectives, any project will continue to strive for a purpose and a relevant set of outcomes. Constituents, stakeholders and various affected employees that intersect with an internal risk mitigation exercise, will continuously require coaching on how to base the project on "SMART" objectives.

Next, the stakeholders will require a path forward that includes a building block approach to gaining consensus, agreement and a set of written events that will either be simulated or real.

These events comprise a master scenario, that the organization will utilize to test a hypothesis or set of operational capabilities. The high reaching outcome, is to determine where there are gaps, vulnerabilities and opportunities to improve.

The building blocks approach may include:
  1. Seminars
  2. Workshops
  3. Table Top Exercises
  4. Games
These provide the stakeholders with the opportunity to converge on their respective areas of expertise and integrate them with the overall scenario being developed. However, these are still based upon first identifying the "SMART Objectives" and the application to your particular business, organization, city, state or country.

Taking the foundation of Operational Risk Management and applying a process for evaluation, requires a set of standards so all of the respective constituents, will be talking and practicing from the same exercise play book.

In the United States this standard is HSEEP or "Homeland Security Exercise and Evaluation Program":
The Homeland Security Exercise and Evaluation Program (HSEEP) is a capabilities and performance-based exercise program that provides a standardized methodology and terminology for exercise design, development, conduct, evaluation, and improvement planning.

The Homeland Security Exercise and Evaluation Program (HSEEP) constitutes a national standard for all exercises. Through exercises, the National Exercise Program supports organizations to achieve objective assessments of their capabilities so that strengths and areas for improvement are identified, corrected, and shared as appropriate prior to a real incident.
Whether your organization is new to doing functional or full-scale exercises doesn't matter. Having a process oriented model for program management and project management will provide you with the tools and the foundation to achieve new found learning on where and how to improve your enterprise resilience.

Operational Risk Management professionals are working with an organization or population that is constantly striving to be more resilient.

Without testing, without exercising and without the process framework in place to try and achieve measurable objectives, the organization will never gain the vital insight on where and how it can improve rapidly.

It will never fully understand where the enemy will try and exploit the weaknesses. The organization will never realize their resilience factor at this point in time.

When was the last time your organization really tested itself, to survive? How long has it been since you re-established the relationships and the trusted connections with your own supply chain? Why has it been that long?

There are some elite organizations in the world who understand readiness, that have learned along the way of their evolution why exercising and a trusted supply chain is critical to their own survival before the next incident occurs:
To become a SEAL in the Naval Special Warfare/Naval Special Operations (NSW/NSO) community, you must first go through what is widely considered to be the most physically and mentally demanding military training in existence. Then comes the tough part: the job of essentially taking on any situation or foe that the world has to offer.
Direct action warfare. Special reconnaissance. Counterterrorism. Foreign internal defense. When there’s nowhere else to turn, Navy SEALs are in their element. Achieving the impossible by way of conditioned response, sheer willpower and absolute dedication to their training, their missions and their fellow spec ops team members.
This analogy to the Navy SEALs demonstrates that preparedness long before you are asked to test your own resilience, will save lives. Yet there are so many other ways that our planet and the people on it, are being tested every day outside of the context of natural disasters, counterterrorism or national defense missions.

When you think about resilience in the context and relevance of the threats before us, we all have to realize that whether it is the National Level Exercise (NLE), or our US Navy SEALs, only SMART objectives will increase our ability to learn, to save lives and allow for the potential survivability of our organizations or impacted populations...

Saturday, January 24, 2026

Leadership in Crisis: Building Trust with Continuous Training...

How often have you ever heard the leadership management philosophy that you must "Train Like You Fight"?  Here is another way to look at it:

"The more you sweat in peace, the less you bleed in war." Norman Schwarzkopf

The theme is all too familiar with Operational Risk Management (ORM) teams that operate on the front lines of asymmetric threats, internal corruption, natural disasters and continuous adversaries in achieving a "Defensible Standard of Care."

As the senior leader in your unit, department or subsidiary the responsibility remains high for preparedness, readiness and contingency planning.  Your personnel and company assets are at stake and so what have you done this month or quarter to train, sweat and prepare?  How much of your annual budget do you devote to the improvement of key skills for your people in a moment of crisis or chaos?

What will the crisis environment look like?  Will it develop with clouds, water and wind or the significant shift in tectonic plates?  Will it begin with the insider employee copying the most sensitive merger and acquisition strategy to sell to the highest bidder?  Will it start with a single IT server displaying a warning to pay a ransom or lose all possibility of retrieving it's data and operational capacity to serve your business?  Will it end up being another example of domestic terrorism or workplace violence like San Bernadino, Paris or Ft. Hood?

Leaders across our globe understand the waves of risk and the possible issues that they may encounter each year.  Many travel to Davos to the World Economic Forum where the world tackles these disruptive events, with the best minds and exchange of information.  Why? They understand that vulnerability is what they fear the most.

Yet what can you do in your own community, at your own branch office to address the Operational Risks you face?  How can you wake up each day with the confidence as a leader, that you have trained and prepared for the future events that will surprise you?  It begins with leadership and a will to lead your team into the places no one really likes to talk about.  The scenarios that people fear to train for, because they think they will never happen.

Achieving any level of trust with your employees, your customers and your supply chain revolves around your leadership.  The discipline of "Operational Risk Management" is focused on looking at all of the interdependent pieces of your business mosaic.  The environment you operate in, even the building that houses your most precious assets.  All of these factors are considered in developing and executing your specific plan for training and readiness.

So what?  The question is

"Why Don't Employees Trust Their Bosses"?

Why this lack of trust?

As a leader your roles are multi-faceted and there is never enough time or money in the budget.  The leaders who excel in the next decade, will find a way.  They will invest in their teams training and the systems to increase trust, by addressing Operational Risk Management (ORM) as a key component of the interdependent enterprise.

The "TrustDecisions" you require and the understanding developed to insure effective "Trust Decisions" by all of your stakeholders will remain your most lofty goal as a leader.

How you train to fight and how you sweat now will make all the difference in your next war.  From the boardroom to the battlefield your leadership is all that is needed.  Your leadership will make a difference...

Monday, December 08, 2025

Linchpin: Trust in a Continuously Changing Environment...

In the early morning nautical twilight on a cold winter morning, thoughts about how the world is changing comes into clarity.  What do you believe in?

As the asymmetric threats seem to grow and our respective thoughts scan a vast Operational Risk landscape of people, processes, systems and external events; there is a mission worth pursuing.  It is a mission that is uncertain, full of unexpected change and potential catastrophes.

The outcomes that you seek will not always materialize as you wish, yet that is to be expected.  After all, what would an organization, state, region or country be like, without any substantial changes, unexpected events or new challenges?  You see, humans do not thrive in environments where behavior or events are 100% predictive.

We work best when there is a problem to solve, an environment or challenge that we can explore.  We can conquer or adapt to, in order to survive another day.  It is this ability to explore, to test, to solve problems that sets us apart from the current state of "Artificial Intelligence", for now.

Now, pivot your thoughts to the current ecosystem of people you encounter on a daily basis.  How does that environment change each day?  What mechanisms do you have in place to mitigate the risks that could create negative consequences and outcomes?  Think about all of the behaviors, tools and ways that you operate each day to deal with risks in your life.

The truth is, humans are curious and seek out risk.  Even if you get to a place where there is a perception that no risks are present, that no risks are over the horizon, we will look for new adventure, new learning and ways to adapt to a new environment.  So what really is the top priority for a parent, big brother/sister, manager, instructor, chief executive, commander or other organizational/constituent leader?

To create an environment of trust.  In a place where people have the ability to create the rules, teach the rules and operate within the rules.  Think about any environment where humans can't create the rules, or rely on the rules.  Where they are not effectively communicated or where people don't follow the rules.  Trust breaks down and uncertainty permeates our consciousness.  The decisions to trust become questionable.

Your goal, is to become a "Linchpin".  As Seth Godin has described in Linchpin:  Are you Indispensable?:
"Is there anyone in an organization who is absolutely irreplaceable?  Probably not.  But the most essential people are so difficult to replace, so risky to lose, and so valuable that they might as well be irreplaceable."
How many linchpins do you have on your team?  Guess what?  If everyone is so specialized, so vital and there is little or no backup and redundancy, you may have a single point of failure.  This is why as a linchpin, you need to be continuously training and teaching to be replaceable.  If you are not confident that you have done all you can do, to become replaced, then you as a linchpin have failed.  Your resilience factor is zero.

Your tasks will create more redundant linchpins and you shall create a consistent and highly trusted environment, physical or virtual.  A changing environment is inevitable.  Achieve a culture where trust is paramount and the team, class, cohort, company and community that creates the rules, communicates the rules, enforces the rules and follows the rules.

We as curious humans seek out unpredictable places, full of risk and simultaneously we wish the environment can be trusted?  Yes we do.

Onward!

Saturday, November 08, 2025

Strategic Organizational Resilience & Survivability...

According to the best practices from several sources, the Board of Directors is responsible for the "Strategic Resilience and Survivability" of an organization.


Let’s take a look at what the highly influential Basel Committee says about one principle as it pertains to Business Crisis and Continuity Management (BCCM):


Review and Testing of Business Continuity Plans – Basel Principle 13

“It is the responsibility of the organization's Internal Audit and Business Continuity functions to ensure that all of the organization's business continuity plans are tested and reviewed on a periodic basis to spot incorrect assumptions, oversights or changes to equipment, and employees and to identify any changes in business requirements not reflected in specific plans. Any undocumented requirements must immediately be documented. In addition, appropriate information owners and users must be informed of updates to plans.”

The Basel Accord for large global money center institutions says you have to test all of your suppliers and their plans so that you don’t have any service interruptions. The question is how often is enough? When is the last time you knocked on the door of your Power Company, Phone Company, and Water Company and said I’m here to audit your BCCM plans. And in every country you operate critical information processing and personnel centers.


Having survived several large quakes in Southern California in years past, you can be sure that all of the testing in the world can't prepare people for human behaviors that come from within.


People literally lose all sense of common sense when you are on the 42nd of the 50+ skyscraper and without any warning it physically sways a couple feet to the left and a few more feet to the right.


Believe it, the issue is not the testing itself, it’s how to create a real enough scenario that you get similar behaviors out of unsuspecting people.

Certainly the largest organizations realize that the threats are taking on different forms than the standard fire, flood, earthquake and twister scenarios.

These large catastrophic external loss events have been insured against and the premiums are substantial.


What it is less easy to analyze from a threat perspective are the constantly changing landscapes and continuity postures of the many facets of the organization having to do with people, processes and systems.


The many sources of significant loss events are changing as we speak. Here are a few that should not be overlooked:


· Public perception

· Unethical dealings

· Regulatory or civil action

· Failure to respond to market changes

· Failure to control industrial espionage

· Failure to take account of widespread disease or illness among the workforce

· Fraud

· Exploitation of the 3rd party suppliers

· Failure to establish a positive culture

· Failure in post employment process to quarantine information assets upon termination of employees


In summation, the following six factors are the critical aspects of effective and strategic organizational resilience and survivability:


1. Business continuity planning will be conducted on an enterprise-wide basis 24/7.

2. A thorough and continuous business impact analysis and risk assessment is the foundation of an effective BCCM.

3. Business continuity planning is more than the recovery of the technology; it is the recovery of the business.

4. The effectiveness of a BCCM can only be validated through continuous and thorough testing.

5. The BCCM and test results will be subjected to continuous independent audit.

6. A BCCM will be continuously updated to reflect and respond to changes in the organization.

Frankly, corporate directors have their hands full managing risk and continuity on behalf of the shareholders.

The risk management process will someday have as big an impact on the enterprise as other key functions because shareholders will be asking more questions about the changing landscape of managing risk for corporate governance…

Thursday, June 12, 2025

Black Swan: Strategy Execution for the "Outlier"...

The Black Swan is a surprise event and the idea that a catastrophe can strike without warning. A professional colleagues recent presentation was a timely reminder of its history and the origins.

What does your organization plan for within the Operational Risk Management (ORM) discipline? The Low Consequence “High Frequency Incident” or the High Consequence “Low Frequency Incident”?

The ratio can tell you what your "Resilience" factor is to Operational Risk loss events. Key Performance Indicators (KPI's) can give you some forward looking view into the risk portfolio, yet what about the resilience to the "Black Swan"?

The “Back Swan” is a highly improbable event with three principal characteristics:

It is unpredictable; it carries a massive impact; and, after the fact, we concoct an explanation that makes it appear less random, and more predictable, than it was.

"The astonishing success of Google was a Black Swan; so was 9/11.  For author Nassim Nicholas Taleb, black swans underlie almost everything about our world, from the rise of religions to events in our own personal lives."

"Why do we not acknowledge the phenomenon of black swans until after they occur? Part of the answer, according to Taleb, is that humans are hardwired to learn specifics when they should be focused on generalities. We concentrate on things we already know and time and time again fail to take into consideration what we don’t know. We are, therefore, unable to truly estimate opportunities, too vulnerable to the impulse to simplify, narrate, and categorize, and not open enough to rewarding those who can imagine the “impossible.”

Your organization is no doubt spending time on the Operational Risk Management (ORM) events, that consistently are in the high frequency "In Your Face" category.

In a highly regulated industry sector such as finance, health care or energy the oversight mechanisms require a continuous analysis of risk based upon the criticality of these sectors to the overall resilience of the economy.

"Yet it is the "Outlier" incident, that comes at the most unexpected time that is the real threat and the incident catalyst, that could be your "Black Swan”."

You never know when it is going to be coming, so you must plan, prepare and imagine that someday, it will happen.

Enabling Global Operational Risk Management (ORM) requires thinking beyond models and outside the box analysis of the "Resilience Factor," should an outlier impact the organization, the state or the country. The resources, personnel and systems focused on these areas of risk are small today. But not for long.

Just ask those people who had been working 24/7 since on any major incident.  It could have been the 9/11, "Fukushima"or "Lehman Brothers" crisis. Or more importantly, the plaintiff lawyers preparing their briefs for the inevitable aftermath of litigation over who knew what, when?

Another lesson learned from Supply Chain Risk.  Losing control of sensitive customer data is a fact of life for American companies. They’re collecting more of it, and they are often outgunned by nation state hackers, who are highly motivated to get at it.  Perhaps a vector through your most trusted supply chain vendors and partners.

One prediction into the future could be that litigation will follow all "Black Swan" incidents. If you are in a highly vulnerable industry sector, because it's part of the Critical Infrastructure of the global grid, then you already know you are in the middle of the target zone.

What is amazing to many in the after-action reporting is still how much we continue to under estimate the magnitude of a lack of planning and resources devoted, to these low frequency high consequence events…

Saturday, February 15, 2025

Infinistructure: Who Knew What When...

Who knew what when? This is the question of the last few months as we now embark on the path towards recovery.

The Operational Risks that have plagued our aging county, state and federal institutions are growing and the convergence factor has brought us even bigger systemic organizations "Too Big To Fail."

While many will be side tracked by the need to deal with the toxic assets still on the books or in sinking agencies the "Zero's and One's" don't lie.

The information, digital evidence and just pure data audit trails will remain for many to be caught, charged, indicted and then sent before a jury to decide their fate.

Managing risks in the enterprise today takes on many flavors and within several departmental or enterprise domains of expertise.

Whether it be the C-Suite, legal department, the IT department, Internal Audit, Security department or even the Operational Risk Management Committee the "Zero's and One's" don't lie.

Think about how much time the people behind organizational malfeasance spend on trying to cover their tracks, clean up the digital "Blood Trail" of their crimes and wrong doing all the while knowing that someday, a smart investigator or forensic examiner will connect the dots. Game over.

Regardless if you are two paid-off programmers who have been enforcing the "Business Rules" in their software by the boss or an internal threat actor does not matter.

Whether they are copying, stealing, altering or damaging the digital information within the organization does not matter; these Operational Risks still remain constant.

The resources and the money devoted to continuous due diligence, monitoring and preemptive strategy to Deter, Detect and Defend the digital assets of the enterprise need to grow dramatically to stay ahead of the curve.

The best way to figure out “What to do” and “How to do it” will require outside assistance. Moving your digital assets to be professionally managed makes sense for economic and other financially prudent reasons.

Yet this migration away from large numbers of people managing and maintaining your information technology infrastructure internally and on your payroll is just the standard "outsourcing" strategy right?

It has it's own set of 3rd party supply chain set of risks. After your next incident who will be asking: Who knew what when?

Many private sector and government enterprises who are augmenting their COOP and the economic strategy of "Cloud Computing" have realized the smart course of implementing and migrating to managed services and infrastructure suppliers.

"How can the utilization of an "Infinistructure" with the knowledge and application of a legal compliance ecosystem in your enterprise mitigate the risks associated with bad actors, unprepared personnel and the digital loss of key evidence?"

Stay tuned for more on this later. In the mean time remember this.

All of the newest technology, fastest AI computers and neural networks enabled with encryption and secured physical locations will not be enough to save your institution from Operational Risks.

It is just one more piece of the total risk management mosaic, that will still require the smartest people and the most robust policy and processes imaginable.

Who knew what when? This will continue to be the biggest question of the next decade.

Saturday, January 11, 2025

Maps: Finding Your Next Destination...

Where you decide to live your life and the geography that surrounds you, will shape who you become in your future.

When you were growing up, did you ever ask your Mom or Dad, why are we living here?

Did you ever have the pure curiosity to look on a map to discover where in your country your hometown was actually located? How far was it to your Nations Capital?

Your story as a young human being and where you started your early years going to a local school and taking a geography class was just your beginning.

What about the neighborhood you lived in and the friends and places around you that shaped many of your thoughts on life forever. That single map you were curious examining, was just a small world view of our entire globe and your opportunity.

In 2025, you now have the satellite imagery resolution and cloud-based services such as ESRI, Maxar or even just Google Maps to quickly explore your next destination.

Explore your next city, state and geography to live or work.

Your parents probably did not have those high tech tools when you were growing up across from the big lake, in just a small Mid-West community in our United States.

Now, how might you utilize a myriad of new technologies and online tools to research your next destination in life?

What questions might you ask yourself to begin to zero-in on a particular Zip Code or a proximity to the ocean, the mountains or the city with tall skyscrapers?

Would you begin with the weather site? Would you begin with ZipRecruiter dot com? Would you begin with Rent dot com? Would you begin with CrimeMapping dot com?

Yes, and unfortunately these days, people must consider all kinds of “Operational Risks” in their own particular community. Why?
We have all heard or experienced first hand the news reports from city names of where significant “Loss Events” have occurred across our America.

The spectrum of risks are wide and so unpredictable. Here are just a few such examples:

Where will you find your next place to work and/or raise a family, so that you may truly prosper and your family will be more safe and secure?

Where are the schools you will choose to associate with, that start the day with our “Pledge of Allegiance”? Where you will find “School Protective Resource Officers” are on premise and kindly greeting students as they arrive each day.

Why will you volunteer with your local Citizens Corps Community Emergency Response Team (CERT) and/or join your metro area InfraGard Members Alliance (IMA)?

Why will you learn CPR and how to use a tourniquet, organize a search and rescue team, learn self-defense and how to more effectively Understand, Decide and Act, with real-time digital active streams of relevant threat information?

Because of the geography where you grew up and it all began. Because of where you went to College and earned your degree(s). Because you learned and worked more than most in our International world of asymmetric warfare with continuous and invisible Operational Risks.

Because of your growing Christian faith. Because you have been Married once for 38+ years. Because together you and your wife raised a daughter and a son who were only 19 months apart working full-time.

Because your kids both graduated with Bachelor degrees from State Universities. Because they are now reflecting upon successful careers within a Dow Jones Industrial Fortune 500 and a few US Federal Government contractors.

Because you have your first Grandson. :-)

Because your own Mother and Father made the right decisions, on where to live and raise your family, as just another young kid on the YMCA Swim Team in that little Mid-West town.

In our wonderful and only, United States of America…USA.

Godspeed!