Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Enterprise Services

The 'Insecurity' Profession

By Phil Aronson
The 'Insecurity' Profession
September 1, 2016

Imagine a world of things that serve you. Sensors and machines that collect information about everything: your environment, your presence, your calendar and your diet. At the same time, it is impacting your business including your people and how they perform their roles within your processes. Every device, every sensor, can share information no matter who built it. Every one of those things will have a name (a uniquely identifiable identification), and anyone can find it anytime for any reason.

Believe it or not, this world is already here.

But there is a key foundational element that should be keeping all of us up at night but rarely does because we are too busy and the devices are too convenient: We need to understand fully what our risk is and the methods we use to mitigate or prevent risk. The threat is exacerbated by the temptation. Being first to market for a vendor is huge; this trumps security. Convenience, for a consumer or end user, trumps security.

So how does this apply to our industry (vendor/manufacturers, integrators, end users)? There is a problem. And we need to own it!

More and more companies are beginning to regularly audit their corporate IT infrastructure to determine their risk. And they are beginning to discover that the devices they have put on their corporate network have a few problems either with the way they were specified and purchased (their intended use), the way they were deployed, or the way they are persistently managed.

I’d like to tell you a story that underlines the challenge we have.

A company was going through their corporate IT audit performing internal checks and identifying potential risks. IT wanted to know why the IP address on the access control system’s controller had changed. There was no record of it anywhere.

This would be a challenging question for many Value Added Resellers of security devices. They need a policy for handling default passwords provided by the manufacturer. They need to train their people to change the password at deployment. They need to train their people how to protect their clients’ passwords. And they need to provide a regular service for checking the network protection of their installed security devices.

The end user would have to do the same. And ensure if they switch vendors that the password is changed.

Other “loop holes” can be found in deployment policy and practice as well. For example: Ports are being left open, password limitations of four characters are being found, devices offered by manufacturers are responding to common protocols, and audit scans can automatically change the password on a device.

Security Risk Management Services (SRMS) providers are now having to be proactive by addressing the concern up front in organizational risk assessments, asking questions about the company’s audit practices and whether they have included cyber testing as part of their technology assessments.

The SRMS providers need to look at contracts, proposals and their own IT infrastructure as well. Their clients may not have a language yet for describing what they want or need. But they need to ask the right questions of their practices, the technology vendor’s practice and their own practices.

This is not the Insecurity Profession. It is the risk, resilience and security profession. As an industry, we need to move quickly to secure the core before we rush to innovate with new devices and new solutions.

KEYWORDS: security management security risk management security systems security technology

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Aronson 2016 200px

Phil Aronson is the second generation owner of Aronson Security Group (ASG) a provider of risk, resilience and security solutions within the emerging Security Risk Management Services (SRMS) industry. Aronson is heavily invested in a legacy of value for the industry by hosting an executive leadership forum called The Great Conversation, by participating in the International Security Management Association (ISMA) and by leading his company to the next generation of security services.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Defining the Next Generation of Security Services in the C-Suite's Language; security technology, security services

    Defining the Next Generation of Security Services in the C-Suite's Language

    See More
  • The Mind of the CSO

    The Mind of the CSO

    See More
  • Mining the Security Value Within the Business Process

    Mining the Security Value Within the Business Process

    See More

Related Products

See More Products
  • The Database Hacker's Handboo

  • The Complete Guide to Physical Security

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing