Don't Ask, Don't Tell

At a session on risk assessment at the ASIS International Seminar and Exhibits in September, a security professional spoke of his company’s reluctance to perform a top-to-bottom risk assessment out of fear of discovering and documenting a problem that might lead to liability if that problem were to lead to a serious accident, breach, or loss of life or limb, before it could be fixed. From the handful of grunts and “mmm-hmms” that followed the comment, it was clear the experience was not isolated.

It is a telling comment on our litigious society: Corporate management would rather not know about a potential security problem rather than face the legal consequences that might arise from it coming to light in the first place. It’s a form of risk assessment in its own way: Wagering that willful ignorance could prove less costly than pro-active security policies.

It’s not unreasonable, just to be devil’s advocate for a minute. Legally, knowing about a problem and failing to take action about it, constitutes negligence. And courts can be widely interpretive about what constitutes failure to take action. For example, if a company discovers a potential security hazard in 10 plants, and undertakes an expensive two-year program to systemically fix it, say through integration of physical security assets into an IP network, is it still liable, if 20 months into the project, a breach occurs at the one remaining facility not upgraded? Legal consul would tell you the outcome would be unpredictable.

Still, this is no reason for burying one’s head in the sand of “Don’t Ask, Don’t Tell.” Compliance ultimately requires companies to take a hard look at security policies. What we need, however, are realistic safeguards to protect enterprises that do the right thing.

First off, good faith efforts at legal compliance should not be allowed to become an e-discovery gold mine for tort attorneys seeking to bring large class action liability cases. Enterprises face a new breed of physical and IT security threats. They need the freedom to assess and address those threats without fear their audits will be used against them. Sarbanes-Oxley, FISMA and HIPAA rules are revised in each session. Congress should amend the rules to close loopholes that might allow legal exploitation of information gathered for the purposes of upgrading and improving corporate security.

That is, as long as the enterprise has a documented audit and assessment program in place for the expressed purpose of identifying and addressing security and other compliance gaps, it should be protected from civil suits that may stem from what it documents for the first time in the course of that process. At the very least, there should be a high bar for demonstrating negligence in these cases. If a case for negligence did not exist prior to an audit, facts discovered during an audit, absent of a pre-existing investigation, should not be sole grounds for legal action. Such rules may indeed skirt due process in that it could be seen as forcing company executives to testify against themselves.

In the dangerous times in which we live, risk assessment will be a vital element of any enterprise strategy going forward. Our companies need the freedom to do their due diligence without looking over their shoulder. Corporate policies and documents relating to video surveillance, perimeter defense and building access are in place to protect employees and customers, not provide a handy library for ambulance-chasers.

About the Author

Steven Titch is editor of Network-Centric Security magazine.

Featured

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.