Surveillance Strategies / Video Surveillance / Columns

Changing the Definition of Surveillance in the Age of Converged Risk

Surveillance deals with the act of carefully watching someone or something with the specific intent to prevent or detect a crime.

Surveillance deals with the act of carefully watching someone or something with the specific intent to prevent or detect a crime. A couple of decades ago that would have been a true definition as it related to protecting an enterprise against threats with limited capabilities and limited access to the enterprise. “Watching one thing” was sufficient. However, in our current technological state, that simple definition now involves more complexity and sophistication than ever before. The explosive growth of technological capabilities and people that can use them to probe, prepare and perpetrate an attack or criminal act against a geographically dispersed enterprise from thousands of miles away, undermines traditional surveillance strategies.  

The role of the CSO has significantly changed in the past 10 years and will change even more drastically over the next 10. For example, mention “convergence” and lines begin to blur – lines demarcating previously clear-cut, albeit traditional areas of management responsibility, budgets, reporting hierarchies, resourcing needs and geography. Indirectly, it challenges the more nuanced elements of competence, corporate politics, decision making and information sharing.  

Historically, the domains of physical/electronic security and information technology have been separated within the organization by mission, budget, hierarchy, culture and stakeholder bias. CSOs, CTOs, CISOs and the Chief Risk Management Officers can no longer perform their missions independently of one another. For an organization to survive, collaboration is required to effectively address the extraordinary challenges posed by the convergence of physical, cyber and insider threats.


On the Nature of Threat Convergence

It wasn’t that long ago when surveillance systems “watched” for traditional threats: the physical attack. Whether by air, land or sea, systems were developed, implemented and integrated so as to provide for the surveillance and alerting of identified external threats. But in today’s post-Web 2.0 world, the leading indicators of a physical attack may prove to be cyber-based.

Cyber-based threats defy the conventional perceptions of time, space, context and attribution, and thus challenge traditional approaches to surveillance. Unlike the physical threat charging the perimeter, a successful cyber attack can be accomplished without the victim’s knowledge of when, where, how or why the attack was carried out. Subsequent forensics may eventually determine when and how, but may leave unanswered the questions of who or why. More disturbing yet, while most public attention has been focused on the recent exploits of the BlackPOS malware that infiltrated Target’s systems, officials are concerned future malware attacks on Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) may be carried out in a similar fashion so as to trigger a broader, more damaging kinetic event, resulting in the loss of life and property.

While cyber threats continue to proliferate, evolve and grow ever more sophisticated and difficult to detect, one of the most insidious threats to an organization has been and remains the insider. As companies recognize more of their enterprise value in assets defined as intellectual property, the protection of such assets becomes ever more critical – and difficult to monitor.


The Nature of Security Convergence

While many large and mid-size companies typically have the resources and awareness to address converged risks, they are held back by many factors. We would consider such organizations immature in their approach to understanding and managing their converged risk profile. Often, little attention is paid to the concept of converged risk, let alone trying to implement a coordinated approach to converged security surveillance.

Organizations that demonstrate maturity in attempting to understand their enterprise risk profile typically seek to implement solutions, processes and methodologies that also cut across traditional stove-piped hierarchies. Whether they suffer a physical, cyber or insider attack, they may survive due to factors such as organizational resiliency, clear lines of communication among the organization’s risk advocates, protocols for identifying lessons learned, effective training concepts or leadership engagement. In these cases, converged security monitoring and surveillance activities are systemic in nature – they span technology, process and culture – and they thrive under the auspices of engaged leadership.

So how can an organization evolve from an immature converged risk management approach to a mature one?  The obvious answer is to take a converged approach. To accomplish this, long-held and sometimes cherished assumptions, opinions, traditions, methods and philosophies must be challenged. Prejudices, inefficiencies and deficiencies must be identified and unsentimentally dispensed with or mitigated, since converged threats will continue to evolve – ever seeking out and exploiting the vulnerabilities present within legacy surveillance systems, software applications and business practices.

In a world where converged and non-traditional risks combine and morph, we are obliged to dispense with the traditional approaches if we are to succeed in protecting our enterprises, no matter how big or how small. 


About the Author: Bob Liscouski is CEO and co-founder of Axio Global LLC, an innovative enterprise cyber risk management firm focused on protecting and preserving the value of companies that are essential to our global economy by providing complete cyber risk mitigation and transfer solutions. He is the former Assistant Secretary for Infrastructure Protection for DHS. Max Bobys, VP for Business Development at Axio Global LLC, also contributed to this article. 

Did you enjoy this article? Click here to subscribe to Security Magazine. 

Recent Articles by Robert Liscouski

You must login or register in order to post a comment.



Image Galleries

ASIS 2013 Product Preview

ASIS International 59th Annual Seminar and Exhibits, September 24-27 in Chicago, Illinois, will include an exhibit hall packed with innovative security solutions. Here are some of the products that will be shown at ASIS this year.


Virtualization and Data Center Security: What You Need to Know for 2014

Data centers are increasingly becoming the center of the enterprise, and data center and cyber security is following the same path for security departments. According to Justin Flynn, a consultant at the Burwood Group, the virtualization of data centers allows enterprises to scale more easily and faster, with a smaller footprint.

However, hosting enterprise data in the cloud can make intrusion detection more difficult – how can enterprise security leaders team up with other departments to keep aware of cyber risks and traffic, and physical and data compliance during the virtual transition? How can CISOs and CSOs discuss cyber threats with the C-Suite to get the resources they need? And how can the proper infrastructure test and verify possible malicious attacks? 

More Podcasts

Security Magazine

security 2015 january cover

2015 January

In the January 2015 issue of Security, learn how PTZ and fixed dome cameras do dual duty in video production and surveillance applications, improve security on college campuses, and how to better cope with harsh environments in surveillance. 

Table Of Contents Subscribe

Tougher Cybersecurity Legislation

On January 20, President Barack Obama called for tougher cybersecurity legislation in his 2015 State of the Union address. Which of the following points do you feel is most needed today?
View Results Poll Archive


CompTIA Security+ Certification Study Guide
CompTIA's Security+ certification is a globally-recognized, vendor neutral exam that has helped over 60,000 IT professionals reach further and higher in their careers. The current Security+ exam (SY0-201) focuses more on being able to deal with security issues rather than just identifying them.
More Products

Clear Seas Research

Clear Seas ResearchWith access to over one million professionals and more than 60 industry-specific publications,Clear Seas Research offers relevant insights from those who know your industry best. Let us customize a market research solution that exceeds your marketing goals.


Facebook 40px 2-12-13 Twitter logo 40px 2-12-13  YouTube  LinkedIn logo 40px 2-12-13Google+

Vertical Sector Focus: Critical Infrastructures

criticalhomepagethumbFrom terrorism to vandalism, it’s preparedness, response, training and partnerships. Learn about some of the critical security issues facing this sector.

Visit the Critical Infrastructure page to read more.