Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Leadership and Management

How Incident Reporting Can Mitigate Threats

What reporting strategies should your enterprise adopt?

By J. Kelly Stewart
Managing Mitigation
April 1, 2014

When there is a fire, it must be extinguished. Anyone who has ever been in a fire wants to prevent it next time. It is the same with security incidents. Some time may pass without an incident – but they happen and will happen. Trend reports show that incidents are not becoming fewer. On the contrary – they are becoming more advanced and targeted. Although some targets will be more popular than others, there are no safe hide-outs. For instance, even smaller schools in countries with languages spoken by small populations are being targeted these days. Banks, big networks, government and military entities are ‘popular’ targets.”

– European Networt and Information Security Agency

 

“Risks to reputation are not anymore part of the emerging risks; in fact, they have been on the risk management radar for over a decade now. However, the last year of this first decade of the 21st century seems to have seen a burst of incidents all over the economic spectrum that tainted the reputation of even well established companies. BP suffered their third blow of the decade with the oil spill in the Gulf of Mexico, Toyota product recall was a warning to the automobile giant that blog can be damaging, not to speak of the SEC suit against Goldman Sachs. If these may be PR disasters to some extent, it would be very casual to not investigate all those event in depths as the root causes are probably not in faulty communication, but rather in faulty operations, faulty governance, etc.”

- Jean-Paul Louisot, Jenny Rayner, Managing Risks to Reputation: From Theory to Practice

What is poignantly clear is that incidents can be defined in many different ways to many different departments and organizations. However, it is the managing of those incidents that outline the strength and longevity of a business. If their processes were in sync, then the return on investment for that key process would have been a worthwhile expenditure. When considering incidents within a particular organization, we must properly explain how incidents are defined by not only each of the varying departments and their particular processes, but also have an understanding of the overall definition the organization gives.

Equally critical is the reporting process. Reporting and managing incidents allows processes to be changed to stop incidents recurring and prevent potential harm turning into actual harm. Thereby, enabling a business to add value to the safety and security of all employees and clients, create potentially more profitability for the company, help reduce incidents and losses and more importantly, provide a built-in defense against accusations of negligence or inadequate security. However, an understanding of an incident must be clearly determined.

As a matter of course, our security industry defines incidents in many different ways by many different departments both in Information Security and Physical Security.  Hence, a broad definition must be sought so that it encompasses the vast range of incidents that may occur. Why is this so important? Having a narrow or more specific definition of what an incident may endanger the organization or specific department from fully realizing the extent of the incident, making the reporting of that incident incomplete.  Therefore, rendering the organization at a disadvantage from realizing the full extent of the risks involved. 

For this article we will define security incidents as those natural or man-made events or hazards that adversely affect the organization, but must be examined and reported to potentially mitigate a reoccurrence. We are essentially gathering facts and conducting an investigation – gathering of evidence and related data to an occurrence, or incident with the goal of arriving at a logical conclusion based on the evidence. 

That evidence and the assessment conducted during the investigation must be accurately recorded. In today’s environment with everything being digital and “Big Data” taking a grip on the size and complexity of the information being obtained, designers and management are obligated to ensure that solid and coherent strategies are developed to provide consensus within the management team. Lack of a strategy will dismantle the effectiveness of the information obtained and diminish the ability to properly mitigate a reoccurrence. While many security incident reporting strategies depend on the organization, there are a few baseline security incident-reporting strategies that should be utilized when developing this type of program.

 

Planning & Preparation

First of these strategies is planning and preparation. Each department within the organization to uncover perceived and known threats and vulnerabilities must conduct a thorough Business Impact Analysis. Many of today’s incidents are so complex and time-consuming that preparation cannot be dismissed. Therefore, by examining each department a baseline of security in systems, network devices and overall physical security can be established so that incidents are not likely to become routine. Some basic aspects behind planning and preparation are:

 

• Setting up a reasonable set of defenses/controls based on the threat that presents itself.

• Creating a set of policies and procedures to deal with incidents as efficiently as possible.  Within these procedures and policies it must be clear that:

   - All incidents, accidents, or occurrences that cause or could cause harm must be reported.

   - A blame-free environment needs to be promoted because by getting to the root cause of an error, you can fix the underlying system or process issues that allowed the event to happen.

• Obtaining the resources and personnel necessary to deal with the problem.

 

Engage Cooperation

In order to gain cooperation for this program/system, organizers need to gain the trust and confidence with future security incident reporters by making use of the already existing arrangements and resources within each department; raise awareness of the hazards and threats; most importantly, build trust. Building trust is paramount to success considering crucial and difficult a task it is. Developers should leverage already existing relationships to assist in building that trust. 

 

Develop a Technological Infrastructure

Companies such as PPM2000, iView Systems and D3 Security systems offer organizations the ability to create customized security incident reporting solutions and systems through their incident management software. This permits an organization’s workforce to easily report incidents online, and also creates more security awareness while simultaneously advancing the organization’s ability to master analytical competencies. 

Indicative of this transformation is the pursuit to integrate and converge disparate systems within the organization that have long been in departmental silos. The security incident management system should be interdisciplinary and organizationally flexible to meet the needs of incidents of any kind or size. 

 

Manage Security Incident Reporting

Once the infrastructure of the security incident reporting system is in place, a close watch and review of the system and its process must be maintained. This can be achieved by analyzing as well as following-up on individual incidents, conducting statistical analysis on a number of incidents and examining feedback to improve and evolve the process.

 

Conclusion

Droughts and wildfires in the West, record snowfalls on the East Coast, Typhoon Haiyan in the Far East, gun violence erupting in America’s schools and colleges at a rate of more than three incidents a month with 13 school shootings recorded in the first six weeks of 2014, as well as the recent rash of cyber attacks on Target, Neiman Marcus, Michaels and more recently Apple, exemplify the necessity for accurate incident reporting to improve safety and security; maintain corporate reputational integrity; increase shareholder value; and ensure maximum return on investment.

An incident reporting system in today’s world involves an organizational mindset that emphasizes complete and thorough corporate involvement. This would improve personal and organizational safety that would allow front-end practitioners to have easy access for reporting an incident with an understanding that their report will be handled in a non-punitive manner, and the notion that it will lead to enhanced learning regarding the causation of the incident and systemic changes which may prevent it from recurring.

 

About the Author: J. Kelly Stewart, MBA, CHS-IV, CAS is the Managing Principal and CSO for Newcastle Consulting, LLC - an Enterprise Risk and Strategic Security Design Management Consultancy. 

KEYWORDS: access management tools security education security incident reporting security leadership security risk mitigation

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Top Cybersecurity Leaders
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Cybersecurity
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

Shopping mall

Victoria’s Secret Security Incident Shuts Down Website

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

July 17, 2025

Tech in the Jungle: Leveraging Surveillance, Access Control, and Technology in Unique Environments

From animal habitats to bustling crowds of visitors, a zoo is a one-of-a-kind environment for deploying modern security technologies.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • cyber 3 responsive default

    Taking a Closer Look at Remote Workplace Fraud Vulnerabilities: How to Mitigate Escalating Threats

    See More
  • healthcare-cybersecurity-freepik1170x658.jpg

    How to proactively mitigate healthcare threats with wave 2 video analytics

    See More
  • researcher uses IoT medical device

    Top 5 healthcare cybersecurity threats — and how to mitigate them

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk-Analysis.gif

    Risk Analysis and the Security Survey, 4th Edition

  • contemporary.jpg

    Contemporary Security Management, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!