Do Security Assessments on Multiple Buildings Without Killing Yourself
Daniel Young
Prof Risk | Founder & Chief Innovation Officer @ Circadian Risk Inc. | Speaker | Security, Threat, Vulnerability, & Risk Expert and SaaS | ASIS Member, CSO Risk Council Member | LGBTQ+ Sponsor | Entrepreneur | Pet Lover
We often hear the same concern from clients: “I have 200 sites, but I only get to assess the risk at 24 every year.” Every organization would like to assess all 200 sites every year, but with paper-based threat and vulnerability assessments, it’s often not possible. Even if it were possible, no one would read through 200 reports.
Take the example of an international entertainment company. The company had just gone through a series of paper-based risk assessments for all of their buildings. In a moment of frustration, the head of security told me, “I have 600 facilities and 600?paper-based reports . What the heck am I going to do with 600 reports?” Assuming each report was 60-80 pages long, that’s as many as 48,000 pages to deal with. All the important information about risk was completely buried.
When an organization has multiple facilities, separate narrative reports for each site aren’t helpful — especially if they're paper. What you need is a digital solution capable of aggregating all your company’s risk and vulnerability data into one single dashboard.
Aggregate Data to Make Data Actionable
When a company receives paper-based reports for each building, there is no way to make sense of the data, much less take action on it. Instead, the building supervisor typically skims through a few executive summaries and shelves the reports. Nothing happens, no corrective action is taken, and the facility doesn’t reduce their physical security risks or vulnerabilities.
But many companies are discovering Circadian Risk. We have the only security assessment tool that can aggregate data from multiple buildings and present it in a single dashboard.
With Circadian Risk software, you can complete multiple assessments for any number of buildings. The software rolls up all your risks and vulnerabilities into one?corrective action plan ?for your entire organization. View the corrective action plan at an organization-wide level, by campus or by building. You can even drill down to the department level within a building. Filter the data based on priority, by assignee (tasks assigned to specific people) and element/category (for example, cameras, lights or smoke detectors). You can also review issues?visually on a floor plan ?of each facility.
Visibly see what’s going on with all your facilities in one screenshot. You’ll know what remediation activities are being done throughout the organization, and what their status is. Circadian Risk lets you see the status of every single item in any facility, in real time.
Understand Your Sites’ Inherent Risk
Inherent risk is risk that’s intrinsic to each site, and no two sites are the same. If Inherent risk is the intrinsic risk that exists because of several factors: its location, your mission, time of year or day, historic considerations, etc. A site that’s close to a body of water is at a greater risk of flooding than one far inland, and a site in an area with a high crime rate is at a greater risk for theft. Being able to compare risk for specific scenarios across your organization is an important function of an aggregated dashboard.
Use Risk Scores
Risk scores can be used to compare the risk of several different facilities relative to their own organization. If an organization has 100 facilities, a risk score is a simple and effective way to compare those sites against one another. Ideally a good risk score will let you see, at a glance, which sites carry a lot of risk, and which are more secure.
领英推荐
The best score, however, is a customized risk score. Circadian Risk’s risk enables you to use your own metrics, such as the value of your assets and your inherent risk, to generate a unique score for each of your facilities. This allows you to see, at a glance, the risk scores across all of your facilities.
Use Self Assessment and Incremental Assessment
It may be impractical to do full assessments of 200 sites annually, but that doesn’t mean you can’t do some assessments. Circadian Risk’s self-assessment function allows site managers to answer general questions before an assessment, and our incremental assessment feature enables you to build on previous assessment data by recording the progress you’ve made on remediations.
A digital platform provides a living document; as changes are made, they’re recorded in the software.
Business Benefits of Aggregated Data
Circadian Risk’s aggregate reports don’t just make it easier to improve your physical security—they make business sense, too.
Reduce Risk in Every Building
When my contact at the entertainment company heard about our aggregate reporting, he was impressed. He said, “To be honest with you, Dan, we were considering building our own tool, because we couldn’t find anything that meets our needs. But you guys are checking off a lot of boxes that no one else is.”
One of our customers is a railroad company doing aggregated assessments for several facilities. The aggregated reports have given the company more insight into their buildings in one dashboard. “If everybody did this, my job would be so much easier,” said one regulator when he saw the impact Circadian Risk’s solution was making.
That’s the kind of actionable difference Circadian Risk can make for your company.
Need a security assessment tool that can aggregate data from multiple buildings? See what our risk and vulnerability software can do for your company.?Schedule your personalized demo today .