Skip to main content

Cs june 2016

Page 1

MAKING THE MOST OF ANALYTICS TOOLS

KNOW WHAT TO EXPECT IN THE DARK WEB

A LAYERED APPROACH TO CYBER SECURITY

PAGE 16

PAGE 20

PAGE 24

Canadian

May/June 2016

THE PUBLICATION FOR PROFESSIONAL SECURITY MANAGEMENT

Front-line security personnel tell us the roles they play in the fight against Alberta wild fires

www.canadiansecuritymag.com

FIRE STORIES

PM# 40065710


BUILT IN SECURITY Protecting Canadians and their businesses comes naturally to us. Commissionaires offers more than just security. We provide a peace of mind that is backed up by experience, innovation and dedication.

To find a service that is right for you, visit: commissionaires.ca or call 1 877 322 6777


CONTENTS 3

Canadian THE PUBLICATION FOR PROFESSIONAL SECURITY MANAGEMENT

Columns

Volume 38 Number 3

Sharp focus

8 FOCUS ON CYBER SECURITY How to avoid cyber paralysis

The latest advancements in analytics can have a transformative effect on how security is conducted

10 RISK PERSPECTIVE Learning from new sources

By Linda Johnson

12 MUNICIPAL MATTERS Plan of action

16

14 CCTV & THE LAW The state of authentication

Departments 4 EDITOR’S NOTEBOOK Smarter policies for smart phones

Tangled in the web What security directors need to know about the Dark Web and how to keep their employees away from it

5 TRENDING 9 ASIS UPDATE Best Practices in session

By Sandy Bird

23 Q&A Bonnie Butlin, Security Partners’ Forum

20

25 BOOK REVIEW Separating risk from threat 26 PRODUCT FOCUS CCTV Cover image: A giant fireball is seen as a wild fire rips through the forest 16 km south of Fort McMurray, Alta., on highway 63, May 7, 2016. THE CANADIAN PRESS/ Jonathan Hayward

visit www.CanadianSecuritymag.com Security leaders will be dropping by our studio in 2016, so be sure to check out the video section of our website for new content.

SECURITY PAGES

Canada’s Only Security Industry Buyers Guide

Go Shopping at

SecurityPages.ca

canada’s Only Security industry Buyers guide

Security

Pages 2016

Brought to you by

Canadian The publicaTion for professional

securiTy managemenT

www.SecuritypageS .ca Security_pages 2016.indd

1 2015-11-16 10:31 AM

@SecurityEd • May/June 2016


Canadian

4 EDITOR’S NOTEBOOK By Neil Sutton

SMARTER POLICIES FOR SMART PHONES How Cisco ran with the idea of bring your own device

I

f you want a free phone, don’t work at Cisco. The networking and security giant has a company-wide BYOD policy, and with a few rare exceptions, its employees provide their own smart phones and mobile devices. This isn’t strictly a cost-cutting measure — though assuredly they have counted this cost — but a reflection of the times and general consumer behaviour. The simple fact is, most people own smart phones and increasingly it has become their primary means of communication, first choice for web surfing and reading, interface with social media, and in many cases digital wallet. People take them literally “Cisco doesn’t ask everywhere, including work. The BYOD phenomenon is not new but it employees to use a did cause some consternation a few years ago particular device but they when mobile devices began to proliferate. Firstly, you have to accept that mobile devices can be a distraction. Secondly, perhaps more troublingly, insist on ground rules.” you have to accept that people will connect these devices to your corporate network — regardless of whether you want them to or not. Cisco has recognized this and has determined the best course of action is to work with the tide rather than go against it. I know this because I recently met with Steve Martino, the company’s CISO. Cisco doesn’t ask employees to use a particular type or brand of device, but they do insist on some ground rules. There are nine stages of preparation required before a phone is given the OK. I didn’t ask Martino to name all of them, but the most important is that the devices be encrypted. Users also have to agree that Cisco has the right to wipe their device. At first, this sounded a little draconian to me. I asked Martino if he ever encounters resistance in taking such a major stake in the welfare of what is essentially a very personal device. The simple answer is yes. But that doesn’t mean the policy doesn’t work or isn’t effective. On the contrary, if an individual loses their phone, the idea that it can remotely be turned into a brick holds some appeal. The company no longer has to worry about corporate data going astray — which is encrypted anyway — and the user is no longer concerned about their personal information falling into nefarious hands. With a few keystrokes (or mouse clicks or whatever) the phone becomes an inoperable lump of plastic. When asked if he has any concern about people using their phones to take photos of intellectual property, whether by design or by accident, Martino stated, “You can’t stop people from taking photos with their phones so I don’t try.” Which isn’t to say he doesn’t care. There are guidelines on how people use their technology, just as there are guidelines that govern how people behave in the workplace (Cisco’s rules and those of common decency). Allowing people some agency in how they work and the tools they use is generally a good idea. But a remote wipe command is a great back-up plan.

@SecurityEd May/June 2016 • www.canadiansecuritymag.com

THE PUBLICATION FOR PROFESSIONAL SECURITY MANAGEMENT

Group Publisher Paul Grossinger pgrossinger@annexweb.com

Sales Manager Vince Naccarato vnaccarato@annexweb.com

Publisher Peter Young pyoung@annexweb.com

Art Director Graham Jeffrey gjeffrey@annexweb.com

Editor Neil Sutton nsutton@annexweb.com

Account Coordinator Trish Ramsay tramsay@annexweb.com

Online Editor Cindy Macdonald cmacdonald@annexweb.com

Director of Soul/COO Sue Fredericks

Editorial and Sales Office 222 Edward Street, Aurora, Ontario L4G 1W6 (905) 727-0077 • Fax (905) 727-0017 Web Site: www.canadiansecuritymag.com Canadian Security is the key publication for professional security management in Canada, providing balanced editorial on issues relevant to end users across all industry sectors. Editorial content may, at times, be viewed as controversial but at all times serves to inform and educate readers on topics relevant to their individual and collective growth and interests. Canadian Security is published six times per year by Annex Business Media. Publication Mail Agreement #40065710 Printed in Canada I.S.S.N. 0709-3403 Subscription Rates Canada: 1 Year $40.95 + HST; U.S.A. (payable in US dollars): 1 Year $70.00; International (payable in US dollars): 1 Year $80.00 Circulation Tel: (416) 510-5189 Fax: (416) 510-5170 asingh@annexbizmedia.com 80 Valleybrook Drive, Toronto, ON M3B 2S9 The contents of Canadian Security are copyright by ©2016 Annex Publishing & Printing Inc. and may not be reproduced in whole or part without written consent. Annex Business Media disclaims any warranty as to the accuracy, completeness or currency of the contents of this publication and disclaims all liability in respect of the results of any action taken or not taken in reliance upon information in this publication.

Editorial Advisory Board Jason Caissie Profile Group

Tracy Ann Kosa Microsoft

Carol Osler TD Bank

Ken Close Trillium Health Partners

Bill McQuade Final Image

Theresa Rowsell Kit and Ace

Ashley Cooper Paladin Security

Clark Northcott Hikvision

Tim Saunders G4S

David Hyde Hyde & Assoc.

Malcolm Smeaton Whitehorse Group


TRENDING 5

Security Canada West June 15, 2016 Richmond, B.C. www.securitycanadaexpo.com IFSEC International June 21-23, 2106 London, U.K. www.ifsec.co.uk Toronto Crime Stoppers Golf Tournament July 7, 2016 Richmond Hill, Ont. www.222tips.com

Alberta fires put security to the test In situations like the disasterous wild fire in Fort McMurray, Alta., private security companies play a unique role. Their first priority may be the safety of their own staff and the clients they serve, but they can still be part of the broader solution.

soon as the gates open, as it were. We’re prepared to go back in.” John Slater, CEO of Commissionaires Northern Alberta division, says part of his company’s role was to help re-open some of the camps north of Fort McMurray, which had been closed down or were

Greg Swecera, vice-president, Northern Alberta, for Paladin Security Group, says disasters truly demonstrate the importance of preparation. “There’s lessons learned,” he says. “When things settle down we’ll do a debrief. It’s amazing how important it is that you’ve done [business continuity] planning. I wouldn’t say it was plug and play ... but it was keeping it so we can continue business.” The company recently moved to a paperless HR system, which helped to keep track of staff in a more efficient manner, allowing them to quickly locate people who might be close to the fire. They were also able to set up a toll free number, manned 24x7 in their operations centre, so employees and clients could conveniently check in to let them know where they are. “I have some experience with that,” says Tom Manley, general manager for Calgary and southern Alberta for G4S Canada, of unpredictable natural disasters. Manley has a long police and military background, as well as first-hand experience of the Manitoba flooding of 1997. “From a personal planning perspective, as soon as the fire started, we started contingency planning,” he says. “‘Operation Extinguish’ is our operations plan name to deploy personnel, vehicles and equipment back into Fort Mac as

running on a skeleton staff when the Canadian oil industry began to experience its recent downturn. Those camps served as temporary housing for people who had fled in that direction from the fire. Many Commissionaires employees are veterans of Canadian military. That training serves them well during times of crisis like this, says Slater. Disasters also demonstrate the value of well-trained private security personnel, he adds. “I think it behoves emergency management organizations to know the quality of service that contract security can provide.” Swecera agrees that emergency situations can ultimately bring out the best in people. He says at one point the RCMP flagged down Paladin vehicles to lend a hand. The company’s trucks were able to help evacuate people who didn’t have access to their own vehicles or another means of transport. In some cases, staff were in the same situation as other residents and as much a victim of the fire. “It’s difficult to have managers and staff who have been displaced and they’re not sure what condition their homes and vehicles are in,” says Swecera. “To see them hard at work for their staff and clients is pretty amazing. The one thing I’ve seen in this whole thing is the human spirit is just amazing.” — Neil Sutton

THE CANADIAN PRESS/ Jonathan Hayward

CALENDAR

IAHSS Ontario Chapter Golf Challenge July 18, 2016 Richmond Hill, Ont. www.iahss.org ASIS International Canada Night September 11, 2016 Orlando, Fla. www.asisonline.org ASIS International Seminar & Exhibits September 12-15, 2016 Orlando, Fla. www.asisonline.org Security Canada Atlantic September 21, 2016 Moncton, N.B. www.securitycanadaexpo.com Anixter Showcase September 30, 2016 Montreal, Que. www.anixter.ca Focus On Government Security October 6, 2016 Ottawa, Ont. www.focusonseries.ca SecTor October 17-19, 2016 Toronto, Ont. www.sector.ca Security Canada Central October 19–20, 2016 Toronto, Ont. www.securitycanadaexpo.com Focus On Health Care Security December 7, 2016 Richmond Hill, Ont. www.focusonseries.ca

@SecurityEd • May/June 2016


PALADIN RECOGNIZES ITS EXTRAORDINARY PEOPLE MARK BAKOS | Contract Manager

Extraordinary Moment

E

dmonton City Centre attracts over 10 million shoppers annually and spans three city blocks; it is a busy hub within the downtown core of Edmonton, Alberta. Every day Mark Bakos makes it a priority to instill strength and integrity in the Security team he leads at the sprawling property. He also makes a point of maintaining strong ties with the Oxford Properties management team. On a recent afternoon patrol, Mark noticed a distressed woman had locked her keys in the trunk of her car. He quickly discovered the reason for her panic; her baby lay crying in the back of the locked vehicle. With the temperature rapidly rising, and the baby at risk, Mark jumped into action. He pried the window open with his bare hands, squeezing his arm through, trying to grasp the edge of the door handle. Eventually, Mark managed to grab and release the lock, the frantic mother was able to scoop up her crying baby, comforting her with a huge sigh of relief.

trained and passionate officers, our security programs designed for office and commercial high-rises improve tenant safety, security and reduce overall costs. Read More: paladinsecurity.com/extraordinary

What Our Client Said “We at Oxford Properties Group consider Mark our colleague. Whether he is assisting the disadvantaged, escorting someone who is lost, or supporting a CEO, Mark treats everyone with respect. Oxford’s motto is Managed with Pride; Mark does this everyday and we are extremely proud to have him as part of our team. Congrats Mark!” Oxford Management Team, Oxford Properties Edmonton, Alberta

Mark could have stopped and called car services, but he made the decision to keep going, crawling into the trunk through the back of the car to retrieve the mother’s keys. Mark’s consistency and extraordinary efforts were rewarded at BOMA Edmonton’s 2016 Awards Gala. Mark was awarded the BOMA Edmonton Pinnacle Award, for work Above and Beyond the Call of Duty. Paladin Security’s commitment to our clients is unmatched. By integrating state-of-the-art technologies with our highly

In photo (left to right): Pam Brown, Safety & Security Manager, Oxford Properties; Mark Bakos, Contract Manager, Paladin Security Edmonton; Katherine Bell, Director of Operations, Paladin Security Edmonton

Extraordinary People, Extraordinary Service. Since 1976. • SECURITY OFFICERS • MOBILE PATROLS & EMERGENCY RESPONSE • OPERATIONS CENTRES

• ALARM, FIRE & VIDEO MONITORING • ACCESS CONTROL SYSTEMS

• INVESTIGATIONS • SECURITY AUDITS & CONSULTATIONS • MANAGED SERVICES

• EMERGENCY MANAGEMENT & BUSINESS CONTINUITY PLANNING • CAMERAS & VIDEO MANAGEMENT SYSTEMS


Extraordinary happens everyday.

“His leadership and training shines through the good deeds he does everyday....” MARK BAKOS

Contract Manager, Paladin Security Edmonton Winner of the BOMA Edmonton Pinnacle Award, for work Above and Beyond the Call of Duty.

EXTRAORDINARY MOMENT Reuniting a mother and child

#extraordinary


8 FOCUS ON CYBER SECURITY

By Imran Ahmad

HOW TO AVOID CYBER PARALYSIS

I Canadian businesses are viewed as high valued targets, so be prepared

t seems that almost every week, a high profile cyber attack targeting businesses, governments and even law enforcement is reported in the media. Most experts will argue that there is no perfect solution that can fully immunize an organization from a cyber attack. It is anticipated that with organizations increasingly focused on digitizing all aspects of their business activities, rolling out bring your own device (BYOD) programs and accelerating the adoption of the industrial Internet of things (IIoT), the frequency, sophistication and scope of cyber attacks will increase in the years to come. In fact, Canadian organizations are viewed as high value targets for cyber criminals looking to steal critical intellectual property such as trade secrets, product designs, and customer lists. Given the fact that it’s a question of “when” and not “if” an organization will be the victim of a successful cyber attack, organizations should invest time and resources to implement protocols and strategies that allows them to mitigate the potential fallout of such an attack. In an effort to ensure they meet their legal obligations to protect the information entrusted to them, organizations can and should take concrete steps to improve their cyber defences. The following can be quickwins that any organization can implement: • Protect the “Crown Jewels.” Identify and properly secure all data that’s critical to the organization (such as trade secrets, intellectual property). This can be done in a variety of ways, including centralizing, tagging and encrypting data. Have backups to recover lost or damaged data. • Build a cyber monitoring team. It should consist of knowledgeable managers and professionals (internal and external) who will meet regularly to assess threat levels, discuss how to address gaps and make recommendations to management on how to protect digital assets. • Practice good cyber hygiene. Successful cyber attacks are often the result of insufficient employee awareness and training. For example, cyber criminals

May/June 2016 • www.canadiansecuritymag.com

can gain access to a network by sending an employee an e-mail that appears to be from a trusted source. It asks the employee to log onto a bogus page that requests a user name and password or click on a link that will download spyware or other malicious programming. Put practical and effective cyber policies in place and provide employees with regular training that helps them identify and correctly deal with potential threats. Organizations with high employee churn should conduct training more frequently. • Have insurance. It’s a key part of risk management and offers significant protection from unplanned events. Consider investing in insurance that covers network breaches, data loss and potential litigation costs. That said, cyber-risk insurance may only cover a fraction of the cost related to an attack. That’s why it’s important to have sufficient financial resources to weather a cyber attack and ensure business continuity. • Secure the supply chain. Organizations increasingly depend on their supply chains, but this comes with risk if vendors, service providers and other third parties are given physical and/or digital access to the organization’s network.Typical supply chain cyber security measures include: buying only from trusted vendors; disconnecting critical machines from outside networks; and educating users on threats and protective measures. Ensure service providers meet the security requirements (such as using “commercial grade” instead of free anti-malware software that’s less frequently updated with critical patches). Cyber criminals will seek out Canadian organizations as high value targets for the foreseeable future. Given that this is the new “norm,” organizations should speak with legal counsel to develop and test the robustness of their cyber defences. Imran Ahmad is a lawyer who specializes in cyber security. Ahmad was a featured speaker at Focus On Cyber Security, held in Toronto on March 30.


ASIS UPDATE 9

Best Practices in session

T

he Toronto chapter of ASIS International held its 23rd annual Best Practices Seminar in April covering everything from cheque fraud to public transit to the role of the Dark Web in harassment cases. The importance of communication was highlighted in each session — for investigative purposes, public trust and career-building.

Geoff Weinstein, author of Buried Alive, spoke about communicating clearly in a world increasingly dominated by social media.

Mark Cousins, Chief Special Constable at the Toronto Transit Commission, outlined some of the major security initiatives underway at the TTC and their positive impact.

Symcor’s Harold Wax says everything old is new again when it comes to cheque fraud.

Bill Bradshaw, SVRP, Group 6, Canada, (left) with ASIS International past-president Dave Tyson. Tyson flew into Toronto on short notice to address attendees.

Ryerson University’s Imre Juurlink (right) and Alasdair Goodwill delivered a presentation on how disruptive anonymous threats can be to campus life.

Our focus is to make darkness totally visible

Maximize performance in low light Wouldn’t it be helpful if you could rely on clear and relevant images regardless of the lighting conditions? With the DINION IP starlight 8000 MP camera, Bosch offers a new quality standard in round-the-clock video surveillance. Regardless of lighting conditions, time-of-day or object movement, the camera delivers relevant IP video 24/7. With its impressive technical specifications, this is the ultimate 24/7 camera. Learn more at www.boschsecurity.com/hdsecurity

@SecurityEd • May/June 2016 CS_Bosch_MayJune.indd 1

2016-05-16 10:51 AM


10 RISK PERSPECTIVE By Tim McCreight

LEARNING FROM NEW SOURCES

S Sometimes life experiences can provide deeper insight into security decisions

ecurity professionals managing risk gaps in controls — their approach looks programs can learn new approaches to at the health issues and how ardently the assessing risks from a variety of nonbody fights disease. We determine if the risk security environments. is high, medium or low. Doctors determine One recent personal experience serves as the survivability of disease, and how fit a an excellent example of how we can learn person is for travel. The more time I spent from new, and sometimes painful, situations. understanding their approach, the more A beloved family member was on foolish I felt for simply reacting emotionally vacation when they fell ill, instead of trying to and had to be admitted to appreciate their risk a foreign hospital. The care methodology. “The medical was exceptional, but our I learned some valuable family member’s condition lessons from this chapter profession has worsened very quickly. The in my life and career. While diagnosis was terminal, and we are learning to become continually applied the time he had left was a risk-based profession, we risk management.” short. have a long road ahead of The medical team us. Doctors and clinicians charged with their care have been collecting completed an assessment of meaningful statistics the family member’s condition quickly — our regarding the human body and its response version of a threat and risk assessment. The to disease for centuries. They have mapped medical team determined it was appropriate our genome, developed vaccines we could to airlift the family member back home. only have dreamed about decades ago, and At first, we were upset. How could this created protocols to cure some of our most team of apparently heartless doctors and damaging diseases. The medical profession nurses dare consider it was safe to fly our has continually applied risk management family member home? Why couldn’t they theories against their body of knowledge — simply let them be at peace where they were? comparing how well their risk remediation The flight was scheduled, and the family plans (treatments, vaccines, and cures) member flew home with their spouse. Shortly have fared against their recognized threats after they were settled into a local hospital, (measles, high cholesterol, and cancer). they passed away from their condition. We’re We need to keep focusing on a riskstill dealing with the loss, but the hidden based, business focused approach to security. lesson is something I am now starting to As professionals, we need to continually understand. review our body of knowledge and our past The clinicians at the foreign hospital had and current understandings of how we assess enough supporting evidence, from decades risks, and how well our remediation plans of previous clients, to realize that the costs of worked. managing our family member’s care would I’m not writing about the loss of a family exceed his insurance coverage, and that member to earn sympathy, or publicly deal (based on the risk assessment, or detailed with the loss. I have always been a strong physical examination) our family member believer in using real life examples to help would be more comfortable at home in our security profession grow into a risk Canada. profession. It struck me that these clinicians had This was the lesson I found once I got followed an approach we have used in the past the loss — he’d be proud I found it. security industry while conducting risk assessments. We consider the business context Tim McCreight is director, advisory services at Above of the risk, as did they. We look at the current Security (www.abovesecurity.com).

May/June 2016 • www.canadiansecuritymag.com


CANASA Presents

CANADA’S LARGEST SECURITY SHOWS

Security Canada

Security Canada

Security Canada

Richmond, British Columbia June 15, 2016

Moncton, New Brunswick September 21, 2016

Toronto, Ontario October 19 – 20, 2016

West

Atlantic

Central

Visit securitycanadaexpo.com and register for free.


12 MUNICIPAL MATTERS By Mel Gedruj

PLAN OF ACTION

T

How to build from strategic thinking to a working document

he last two columns painted the big Starting with the risk assessments: this picture, so to speak, and sketched is an area again that is not directly covered the framework. by domain-specific standards let alone the Once the strategic level has been agreed municipal world. So how do we go about upon and an overall direction is set, we have doing this work? Firstly we need a standard to get to work and develop the material that nomenclature. Site security audit? Building would allow us to manage (i.e plan, execute security condition audit? Threat risk / and learn) from our good and bad decisions. vulnerability assessment? And so on. We If we use the analogy have found a simple way to of a camera zoom, the address it is a site security highest level would be review (SSR). The layers “It is important in blurry but as we zoom in involved begin with the site closer, we see more details. perimeter, the building(s) a fiscally challenged A security management perimeter and interior areas plan would then be with possible critical assets environment to advise produced at the tactical depending on the type of decision-makers.” level. It would consist operation taking place. To of guidelines defining structure the future report what needs to be done. It resulting from the SSR, would also establish all there are two documents the required security policies necessary to that seem to help along the way: ASIS support a compliant security program. Guideline - GDL FPSM - 2009 Facilities The first level of compliance consists Physical Security Measures and NFPA of making sure that our policies do not Standard 730/31. These documents allow us contravene any of the current legislation to examine the areas of interest. in force, such as privacy legislation or We found that starting with CPTED health and safety regulations (e.g. Bill 168 (crime prevention through environmental in Ontario or Bill 151) when retaining design), then moving on to site security uniformed security firms or hiring in-house lighting and the rest as set in the ASIS guards. The second level of compliance has Guidelines provides a logical flow in to do with the given municipality itself. Prior capturing information. The next step would policies may be areas of concern. be to gauge current conditions against As an example, Let’s say that our energy benchmarks or against standards, thereby policy very strongly supports a LEED finding “gaps.” The third would be to (Leadership in Energy and Design) approach. propose ways and means to bridge those So if our planning includes enhancing our “gaps” with security countermeasures. lighting levels on the property perimeter we We should also define the timelines may have some challenges as LEED does needed to deploy the recommendations, not endorse “lighting pollution beyond the using criticality as a guide, and provide property line.” These are issues that should some budgetary outlines (capital and/or be flushed out at a lower level, not the higher operational). tactical and strategic levels. It is important in a fiscally challenged How do we then build our security environment to advise decision makers not plan, the cornerstone of any solid municipal only of the risks we may have uncovered but security program? There are two concurrent also what resources (money and time) are areas to be covered: on the one hand carry required. out security risk assessments covering a number of different properties, on the other Mel Gedruj, OAA, CSPM is an Ontario Licensed we would review all the procedural and Architect and Certified Security project manager administrative security processes. specializing in municipal security management planning.

May/June 2016 • www.canadiansecuritymag.com


14 CCTV & THE LAW

By Elliott Goldstein

THE STATE OF AUTHENTICATION

A

recent Alberta case has made new law in the area of authentication of videos.1 In R. v. Bulldog et al. the Alberta Court of Appeal considered whether there is an exclusive list of classes of witnesses who can authenticate a video, namely:

An Alberta decision is changing how video is viewed in court

The appellate Court noted that there were various features of the video recording that matched the testimony of certain witnesses in the Bulldog case, and there is nothing in the evidence of other witnesses that gave rise to a concern that the video recording was altered in a material way. “Now the evidence The appellate Court saw nothing 1. the camera operator; necessary to verify that unreasonable in the trial 2. an eye-witness present judge’s conclusion that it when the video is taken a video recording has was more likely than not who can testify that not been altered or that the video recording the video accurately tendered by the Crown represents what he or changed does not have was authentic, in the she saw; sense that it was a 3. a person qualified to come from one of four substantially accurate to state that the and fair depiction of representation is classes of authenticating what happened. accurate; or witnesses.” Now the evidence 4. an expert witness.2 necessary to verify that a video recording has not The Court of Appeal been altered or changed held that “… these does not have to come from one of four categories are not exhaustive in the sense classes of authenticating witnesses. that, if the Crown does not call one of these The Court clearly stated that four kinds of witnesses, the video recording “‘authentication’ simply requires that the is inadmissible. Rather, other kinds of party tendering evidence establish (to the evidence or different combinations of requisite standard of proof) the claim(s) witnesses may be employed to made about it. What authentication requires satisfy a court of the in any given instance therefore depends upon video recording’s the claim(s) which the tendering party is substantial accuracy making about the evidence. and fairness.” What the Court is saying is that the The Court degree of accuracy of the video recording’s made new law by representation is what matters, not whether concluding that “[A] it was altered. “So long as there is other trial judge is entitled evidence which satisfies the trier of fact of to authenticate a the requisite degree of accuracy, no evidence video recording by regarding the presence or absence of any using circumstantial change or alteration is necessary to sustain a evidence of one finding of authentication.” or more witnesses, provided such evidence establishes to the Elliott Goldstein, B.A., J.D., is a Thornhill, Ont.-based requisite standard of lawyer (elgold@rogers.com). proof that the video in 1. 2015 ABCA 251 (CanLII), 326 CCC (3d) 385 (2015-07-23). question is a substantially 2. The Court cited R. v. Doughty, 2009 ABPC 8 (CanLII) at para accurate and fair depiction of what 37 (citing Elliott Goldstein, Visual Evidence, A Practitioner’s it purports to depict.” Manual, Vol 1 (Thomson-Carswell, 2007) at 2-19 to 2-20).

May/June 2016 • www.canadiansecuritymag.com


Information Supplement

Securing the Bottom Line How Video Surveillance Technology is Helping Canadian Businesses

Canadian Security: For security management in Canada, how has the use of video surveillance changed over the past several years? Mike Reynolds: There is no arguing that IP-video products or network-based products have become the dominant factor in the surveillance world. This technology is so powerful that it offers businesses and corporations of all sizes more flexibility, more functionality, and more intelligence. At the end of the day, IP-based video solutions allow security end users to do so much more than what they used to be able to do with analogue technology. CS: What new video surveillance-related technology has made securing a business easier and more efficient? MR: If I were to name one, it would be compression technology. Simply put, advancement in compression technology has made it possible for security end users to send a lot of information, like video data, more efficiently and more cost-effectively from point A to point B. With today’s IP-video technology, data can be transmitted faster and over longer distances at a fraction of the cost of yesteryear. For businesses, this means they can better manage and use their network bandwidth, which ultimately benefits their IT infrastructure. CS: Besides security applications, how is video surveillance being used by companies to enhance their overall business operations? MR: Video surveillance is much more than a security tool — it is now a business tool, with bottom-line business advantages. In certain applications, like retail and education, it empowers a business to improve its operations, its customer service and its marketing. Video now has the capabilities of capturing extra data. It can think and it is smart. In the retail sector, for example, IP video can monitor heat mapping and crowd control; it can understand where people move in environments versus areas where they are not moving. It can count people coming in and going out of any location, which is vital for a company’s marketing strategies. Combine the intelligence behind the camera with the data and analytics video now provides, and what you have is an eye in the sky that every business can benefit from.

CS: What is the future of video surveillance as it relates to how Canadian businesses use it to protect their facilities, assets and staff? MR: Over the last few years, video surveillance has become smarter, faster, and more efficient. We are now focusing on the reliability of the product. Businesses need solutions that are reliable, help reduce the total cost of ownership and provide a return on their investment. With the continued evolution of IP video, security management personnel across Canada are bringing in new technologies that help with the overall financial well-being of the companies they are tasked to secure and protect. CS: What is unique about Panasonic’s video surveillance solutions? MR: Panasonic has one of the most reliable products in the market and this is what makes us stand out — we build reliability. We offer a free five-year warranty to all of our customers because we stand behind the reliability of our products. Panasonic offers more than just security solutions. Our complete suite of professional solutions address unified communications, mobile computing, retail point-ofsale, office productivity, visual communications (projectors, displays, digital signage), and HD video production. We deliver game-changing technology solutions for our customers and our customer’s customers. What truly sets us apart is we are able to utilize what we know about the marketplace and the customer’s requirements and pain points to be able to build solutions end to end, not just security. Mike Reynolds is the Security Products Marketing Manager, IT and Security Products Division for Panasonic Canada Inc.

For more information on how Panasonic’s video surveillance solutions can help protect and secure your business, visit: go.panasonic.ca/protect


16 BEST PRACTICES

Sharper focus How the professional security community is changing its view on smart security systems By Linda Johnson

A

fter a false start or two, video analytics are now taking off in a big way. While adoption so far has been more pronounced in some markets — such as retail, transportation, education and health care — they are finding their way into many different sectors. As they become a more mainstream part of the security market, end users are still discovering how to use them and how effective they are, and still trying to assess exactly what value they bring to their organization. A year and half ago, the City of Calgary, together with May/June 2016 • www.canadiansecuritymag.com

Calgary Transit, began testing two enterprise-level analytics systems. So far, security uses have included applications such as breached perimeters, direction of travel, basic motion, left objects and loitering. They’ve also used analytics for heat mapping to help monitor the number of people at public events. “An analytic that can see a crowd has grown will set off an alarm. All of a sudden, there are 200 people here; a lot of activity. Somebody needs to know about that,” says Sean Bolli, team lead, technical operations and support, corporate security at the City of Calgary. Bolli also believes the data from analytics can be used to deliver city services more effectively. For example, at Calgary Transit’s LRT platforms last year they tested an analytic designed


“These are systems that can train themselves, so you move to alarm when someone crossed the yellow line on the platform more towards the plug-and-play environment. The system learns when there was no train in the station, indicating the person may about the environment and determines over a period of time what have jumped onto the track. The analytic had to de-activate when is routine activity and what are the exceptions that you want to a train came into the station, when people must cross the line to trigger an alarm.” board the train. Another trend behind the adoption of analytics, he adds, is The business strategy group then asked if they could produce the movement of analytics-related storage into the Cloud. The data on when trains enter and leave stations, he says. “We were use of mega-pixel cameras and HD video, in particular, creates able to get a report by day, or by hour, showing all train times — enormous storage requirements. when they entered the station, when they left, Lastly, with the proliferation of cameras how long they stayed — that we could provide and the enormous amount of video that now to our business groups. It didn’t require us “All of a sudden, there exists, organizations face the issue of what giving them any video, so we weren’t breaking to do with it and how to automate video any privacy laws.” are 200 people here. processing. Bolli sees other opportunities for analytics, “In a control room, where an operator including traffic management (to adjust Somebody needs to is watching a series of monitors, there’s a traffic signals) and in city parks where a heat know about that.” problem of maintaining attention. You have mapping analytic can be used to determine to automate that vigilance so that you just attendance numbers. — Sean Bolli, City of respond to the anomalies and automate the However, they have found some Calgary routine monitoring of images,” Ingelbrecht difficulties. For one, analytics do not work says. well with PTZ cameras. Another concern “And of course, if you have thousands of is the false alarm rate. During phase one of cameras in an airport, thousands of people testing, they wanted to see how many false moving through, and you’re trying to identify individuals, you alarms the system produced. need the capability to manage the amount of data you’re getting “Analytics can introduce a whole new dynamic of false and to generate useful alerts.” alarms on top of what we already get for false alarms,” Bolli says. After the big rush to adopt analytics about six years ago “There’s a whole other level now. Where do you put them? What (which led to huge disappointment due to dashed expectations) cameras do you use? Are they up to date? Are they generating the market is moving into a “real-life version” of video analytics, good image quality? What are the lighting conditions like? says Erez Goldstein, senior product marketing manager Paramus, What are the activities being captured on that camera already N.J.-based Qognify. As the technology was taken up in areas such normally?” as customer service and retail, it created more confidence and led During testing of left-object capability, for example, when to the next generation of analytics. they would add an object to an area to see if the system captured As an example, Goldstein points to his company’s Suspect it, they found sometimes it did and sometimes it didn’t. When it Search, which allows a user to search recorded or live video for a didn’t, they would tweak the rules to try to improve the system’s specific person in an area. This next generation, he says, does not ability to capture the object. rely on binary, yes-or-no matches — did the object cross the line “And sometimes, when a person stood still for five seconds, or not? Is there a line longer than this number of people or not? the system thought, there’s an object left behind and set off an — and so provides more advanced insight. alarm. You can’t teach the system that kind of intelligence. You “In Suspect Search, it doesn’t matter whether it’s a crowded have to do that through the rules. There are many different place like an airport or city, the person’s image will be found factors to adjust.” based on sophisticated algorithms that compare the way they The current adoption of analytics is being driven by a number look and the way they are presented to the camera,” he says. of factors, says Nick Ingelbrecht, research director at Stamford “It represents the way the industry is going, towards more Conn.-based Gartner. One factor is technology and improved human-like needs. I need to find you, so I need an application that systems: better platforms and cameras, 3D systems, multiple finds you and not a random person with the same colour shirt.” sensors, displays, better algorithms — which have increased the Adam Curtis, senior director of corporate investigations at accuracy of systems and produce fewer false positives — along Milton, Ont.-based AFIMAC, says they often use video analytics with, of course, advances in the analytics capabilities themselves. for client companies that want to stop theft from construction “They’re all part of the system that delivers that capability. It’s sites. The covert cameras are equipped with motion detection. what the analytics actually does at the end of the day, and what When the system detects motion, it records it. it enables you to do in terms of such things as response, facial Another major use is for internal theft. Again, they set up recognition or managing environmental events,” he says. covert cameras in an office or retail store. “From the analytics Also key was the introduction of machine learning produced, we can hone in and target those specific areas we want capabilities into the lower-tier products, says Ingelbrecht. @SecurityEd • May/June 2016


18 BEST PRACTICES

INSIGHT  PRESTIGE CONSOLES IMPROVE YOUR VIEW Winsted provides ergonomic console solutions for your demanding control room operations. We offer stock, customised and bespoke console options with exible monitor mounting solutions to optimise sight lines and improve viewing angles. Our experts create inspiring, feature-rich consoles that work with your operators to enhance comfort, functionality and productivity.

Download your free copy of WELS4 at: winsted.com/wels

to look at.” Curtis says analytics, such as the facial recognition systems they are working with, are smart enough now to trust with critical decisions. Instead of key card access, for instance, which requires a person to swipe their card on a reader, the system recognizes a worker based on a photo. “As you’re walking up to the door, it recognizes your face, understands you are authorized to enter the facility and, then, automatically opens the door without your having to do anything.” The system also recognizes a face even when the person has changed their appearance; for example, hair style or colour, he adds. “It recognizes the changes of the individual, so it’s actually the computer program thinking.” Curtis says analytics do not completely replace people: you need people to analyze video and ascertain what information is being captured and whether it is relevant to an investigation. But, he adds, analytics do replace people in some situations. AFIMAC has guards at 21 cargo facilitates across Canada with extensive CCTV with analytics. “That is substantially reducing our physical feet on the ground because cameras can cover a lot more.” Bolli agrees that analytics do not not necessarily replace people. Rather, they help make staff more efficient and effective and able to respond to a wider variety of situations earlier, smarter and with more information. Goldstein also agrees, saying the next generation of analytics will take advantage of both the human and the algorithm. With Suspect Search, for example, the algorithm presents an operator with several potential suspects, all similar to the actual person. The operator then, using the human eye and brain, which are much better at distinguishing the suspect from similar people, eliminates some of the results and tells the algorithm to search again based on the most relevant images. “There is an iterative process of refining the search again and again based not just on the algorithm but on the human input,” he says. “This creates a strong and very accurate process that happens within seconds to find a person out of hundreds of hours of video. You have the strength of the algorithm finding a match and then the human refining the search and sending it to another iteration of researching.” Although Calgary is still testing different systems, Bolli says he is confident the analytics will make security more valuable to the city. In addition to using it to improve the ability of security staff to monitor and respond to situations earlier and better, they also plan to use it across all their business units. “That increases the value tenfold of the security program, security infrastructure and the expertise that security professionals have when it comes to CCTV, to now deliver business-enabled services,” he says. “What is basically a cost centre can add value to other areas that make it more valuable to incorporate into future planning.” Linda Johnson is a freelance writer based in Toronto.

May/June 2016 • www.canadiansecuritymag.com


SECURE ACCESS. NO CARD REQUIRED. Secure mobile access solutions by HID represent a revolutionary breakthrough in next gen technology by combining convenience, flexibility and the power of Seos. With a simple tap or use of our patented “Twist and Go” gesture technology, you’ll experience the most innovative way to make an entrance—no card required. And because it’s all powered by Seos, issuing, managing and revoking access couldn’t be easier—or more secure. You’ll call it the most advanced way to use your mobile device. We call it, “your security connected.” YOUR SECURITY. CONNECTED

|

Visit us at hidglobal.com/mobile

© 2016 HID Global Corporation/ASSA ABLOY AB. All rights reserved. HID, HID Global, the HID Blue Brick logo, and the Chain Design are trademarks or registered trademarks of HID Global or its licensor(s)/supplier(s) in the US and other countries and may not be used without permission.


20 TECHNOLOGY & POLICY

Tangled in the

What companies should know about the Dark Web and how they can guard against it

I

web

By Sandy Bird

For instance, anonymity can protect n many ways, the Dark Web can journalists, human right activists, be compared to the Earth’s deep whistleblowers and government oceans — the majority are left a intelligence. While nefarious individuals mystery and the more we explore, and stealthy hackers can use the the more we unravel their space to conduct illicit activities, complexities. such as selling malware, organizing a Think of all the sea creatures, cyberattack, and expanding their crime lurking beneath our sight, then think of rings. them as a parallel to One of IBM’s all the underground X-Force Threat cybercrime rings “The Dark Web is Intelligence reports operating in the last year verified the Dark Web, trading readily available to growing dangers pornography, the average user and of cyberattacks malware, weaponry originating from the and narcotics. is much easier to find Dark Web through the Rumours even use of the Tor browser. hold the network than one would The report found that accountable for until August 2015, plotting recent assume.” more than 600,000 terrorist attacks. malicious events Scary, isn’t it? originated from Tor So what is the around the world. The United States Dark Web? led with more than 150,000 malicious The Onion Router, otherwise events, while countries including known as Tor, is a downloaded network Romania, France and Luxembourg, that connects directly to the Dark Web, have each seen more than 50,000 and enables anonymous and encrypted malicious events originating from Tor. communications by letting users jump The growing use of Tor is a through relay nodes via multiple concern for all companies — no Internet Protocol (IP) addresses. matter what industry you operate in. For those not in IT: it’s essentially In fact, employees may be tempted to an anonymous and untraceable area fiddle with their browsers just to see of the Internet that can be facilitated what they can discover in the Dark for arguably the good and the bad.

May/June 2016 • www.canadiansecuritymag.com

Web — for non-malicious reasons too. However, if an employee activates a Tor browser within the company’s network, it can very easily put the business at risk for a malicious attack on proprietary data and in some instances, hold the organization legally liable for malicious content that comes through. In other cases, employees have been directed to use Tor if their corporate system was locked by a ransomware virus, as was such in the case of Locky Ransomware Virus victims in February and March this year. Victims of the cyberattack often had to use Tor to download the decryption program, due to spam emails and compromised websites. The point is, companies need to understand that the Dark Web is readily available to the average user and is much easier to find than one would assume. That’s why business leaders need to take the precautionary steps to help protect their company from potential threats and liability concerns. To do so, organizations should: 1. Clearly establish the acceptable use of networks such as Tor in its corporate policy If the company requires the use of Tor-like browsers, such as for journalists and law enforcement, ensure there is a strict and comprehensive corporate policy in place


Today’s G4S. More ways than ever to protect you.

Secure Integration

Corporate Risk Services

Security Personnel

To learn more about G4S, contact us today: www.g4s.ca • 1-888-717-4447 • solutions@ca.g4s.com

Follow us on Twitter @G4SCanada


22 TECHNOLOGY & POLICY 4. Update directories to identify Tor nodes and apply intrusion prevention systems Though the Tor network is large and cryptic, it is finite, and there are frequently updated directories to identify Tor nodes, enabling wholesale blocking at the firewall. Application gateways and intrusion prevention system (IPS) solutions can alarm attacks in real-time and block further entry from the source.

for the employees to abide by. Limited approvals for the use of Tor can also lower the risk of threats. 2. Deny access to anonymous agents or services such as Tor The reality is, very few industries actually require access to the Dark Web. Therefore, most companies should look to configure its corporate networks so that access to Tor is denied.

example of the urgency and necessity for Canadian businesses to protect themselves against predators lurking in the Dark Web. Other high-profile cases by association include, Silk Road and Silk Road 2.0 that operated an illegal drug marketplace in the Dark Web, the infamous WikiLeaks and the controversial exchange of bitcoins online. It’s a digitally-driven landscape out there and hackers are more sophisticated than ever, capitalizing on new communication channels and coordinating combined attacks. Business leaders need to recognize that enforcing these tips and applying collaborative tools and cognitive solutions are key to safeguard proprietary information and to avoid the costs and damages.

Malicious attacks originating from the Tor network, including ransomware and distributed denial-of-service (DDoS) attacks, have been on the rise since the beginning of 2015, according to the IBM report. Already this year in Canada, we’ve witnessed banks, businesses and hospitals, all fall victim to malicious cyberattacks. Notoriously splashed across the media last year was the Ashley Madison scandal, which remains as a perfect

3. Educate employees about the potential consequences of accessing prohibited websites Employees from every level need to understand how accessing a hidden network on a corporate device may be harmful to the company. By building a riskaware culture and explaining the dangers behind their actions, employees are more likely to follow the business conduct guidelines.

Sandy Bird was the co-founder and CTO of Q1 Labs, now part of IBM. Today, he’s the CTO for IBM Security (www.ibm.com/security).

MAKE IT 11

Help us select our 11th Security Director of the Year and nominate a colleague who’s working hard to make the industry a better place. CommuniCating in a Crisis n atm seCurity n Data Bunker

U OF T EMERGENCY RESPONSE • MAKING THE NEXT MOVE

Canadian

MANAGING FOR SUCCESS FRAUD PREVENTION INTEGRATION

Streamlined n What’S changedtipS Since Shand? Salary Survey reSultS Screening n top 10 camera placement n riSk management

Canadian

September 2007

Canadian

September 2008

UNIVERSITY GOES BEYOND CODE AUTOMATING ORDERS WORLD WATCH

Canadian

September 2009

THE PUBLICATION FOR PROFESSIONAL SECURITY MANAGEMENT

September 2006

THE TH HE PPUBLICATION UBLICATION FFOR OR PPROFESSIONAL ROFESSSIONAL SECURITY MANAGEMENT

focused

Keeping Toronto

on track Dwaine Nichol, the City of Toronto’s Manager of Security and Life Safety, is the 2008 Security Director of the Year.

Security Director of the Year

PM# 40063602.

PM# 40063602.

PM# 40063602.

PM# 40063602.

Ric Handren leads a worldclass organization — one that will be at Vancouver’s 2010 Olympics, running in their own event — securing RBC’s people and assets

A city-wide strike, the looming winter Olympics and a book on convergence …it’s not been an average year for the City of Vancouver’s CSO Dave Tyson. As the municipality prepares for it’s close up in 2010, Canadian Security’s 2007 Security Director of the Year readies the city for the world stage.

Gene McLean, Canadian Security 2006 Director of the Year

CS_Sept06.indd 1

Don MacAlister has been working for the last year to consolidate and streamline security over four health entities in the Lower Mainland area of British Columbia.

Security Director of the year

PM# 40065710

Tyson’s Wild West

November 2010

9/7/06 10:13:57 AM

CS_Sept09.indd 1

WEST COAST ASIS

SECURITY DIRECTOR OF THE YEAR

Canadian

CITY OF LONDON

CHECKING OUT JOB CANDIDATES

TAKING THE FIGHT TO MONEY LAUNDERERS

THE LATEST TRENDS IN RETAIL SECURITY

PAGE 13

PAGE 18

PAGE 24

###### ####### 1

Canadian

September 2011

THE PUBLICAT PUBLICATION TION FFOR OR PPROFESSIONAL ROFESSIONAL SE SECURITY MANAGEMENT

new challenges in loss prevention

guarding the greens at the canadian open

simulated attacks used as training tools

page 6

page 16

page 20

Canadian

September/October 2012

1

breaking new ground in data protection

online opportunities for skills development

Page 18

Page 22

Canadian

September/October 2013

The publicaTion for professional securiTy managemenT

THE PUBLICATION FO FOR OR PPROFESSIONAL ROFESS SSIONAAL SECURITY MANAGEMENT

9/9/09 12:35:41 PM

paving the way for more women in management Page 6

CS_Nov_10.indd 1

9/29/10 3:57:51 PM

APSA recognizeS guArdS MAking A difference

droneS And whAt to do About theM

Q&A with new SecuritAS cAnAdA PreSident

Page 6

Page 18

Page 22

Canadian

September/October 2014

The publicaTion for professional securiTy managemenT

September/October 2015

2016

The publicaTion for professional securiTy managemenT

2012

OF THE YEAR

Security Director of the Year is UNOPS’s Chief of Corporate Security. Thomas Gerstenecker shares his views on establishing global systems and processes within the emerging security landscape

SECURITY DIRECTOR OF THE YEAR

TD Bank’s Carol Osler takes top honours based on her 30 years of excellence and leadership in security

The

Community

www.canadiansecuritymag.com

man

Sean Sportun of Mac’s Convenience Stores is building more than just a solid security program

pm# 40065710

Builder

Standard Tom Rousseau’s Olympic efforts for Canadian Tire make him Security Director of the Year

Todd Milne’s commitment to transformative security projects at UHN make him Security Director of the Year

PM# 40065710

view

2013

career www.canadiansecuritymag.com

A

Sterling

PM# 40065710 Return Undeliverable Canadian Addresses To Circulation Department P.O. Box 530, Simcoe ON N3Y 4N5

PM# 40065710 Return Undeliverable Canadian Addresses To Circulation Department P.O. Box 530, Simcoe ON N3Y 4N5

SECURITY DIRECTOR

Security Director of the year

SECURITY DIRECTOR OF THE YEAR

www.canadiansecuritymag.com CS SEPT_OCT 2012.indd 1

12-09-07 12:21 PM

CS oct 2013.indd 1

2013-09-24 10:23 AM CS October 2015.indd 1

2015-09-21 10:36 AM

Submission deadline: July 22, 2016 Full details are available at www.canadiansecuritymag.com or contact Neil Sutton at nsutton@annexweb.com May/June 2016 • www.canadiansecuritymag.com

Canadian THE PUBLICATION FOR PROFESSIONAL SECURITY MANAGEMENT

Sponsored by:


23

QA &

with Bonnie Butlin, Executive Director, Security Partners’ Forum

N

ominally, Bonnie Butlin is the executive director of the Security Partners’ Forum, a self-described “agile network” that touches dozens of related security associations. But more than that, she has become a fixture on the security circuit — attending and speaking at events, consulting with security organizations, serving on boards and accepting several service awards from related magazines and associations. She is, to coin a phrase, in the thick of it. Canadian Security caught up with Butlin to get a better understanding of how she became integral to security associations operating in Canada and overseas.

in complex networks and global geopolitical context and analysis, and learning rapidly from the lessons learned and best practices hard-earned by the Canadian Forces and partners, including from the conflicts in Afghanistan and Iraq, I was able to assist in applying lessons learned and best practices to facilitate the development of a national, and now international, truly agile network of security associations and professionals, and build positive capacity within security for the benefit of Canadians, and our international partners, and the security profession. The Security Partners’ Forum (SPF) has been the result.

Canadian Security: How did you become engaged in the security field? Bonnie Butlin: I was raised in a family of British and Irish military tradition with an expectation that character would be demonstrated through military or law enforcement service. Pursuing a more academic route, I completed a Bachelor’s degree in Political Science and a Master’s Degree in International Affairs with concentrations in terrorism and counterterrorism, Cold War and Post-Soviet studies, nuclear containment theory, power politics, global and domestic complex threat networks, conflict and warfare, as well as economics, global strategic trends, and law. As the concept of security became broader over time, and as organizations and individuals became more aware of the effects and importance of security in their daily work and lives, I sought to learn more about and to reach out to the broader security community beyond my own understanding and national security communities. Drawing on my background

CS: You have received recognition and awards for your service to security. What accounts for your success and how does it feel to be acknowledged? BB: The proven track record of the SPF and our accomplishments, with tangible real-world results that are now being felt globally has resulted in the honour of me being honoured with some seven awards and recognitions over the past three years, first internationally, and now domestically. Not only do these awards and recognitions span a broad range of domains within security, but they also speak to the depth of impact that the SPF has had, and an expectation that it will have a robust and enduring effect, including internationally. CS: You have participated in several events that spotlight the role of women in security. Do you feel that headway is being made and women are better represented today in the profession? BB: Mentoring has been a critical and most valued part of my own professional development. I recently had the honour of being able to give back to other

women along their own professional development paths. I invited to speak at an official International Women’s Day event this year in Winnipeg, and was also invited to serve as a mentor at an ASIS Women in Security seminar in Toronto. The SPF has always been a strong supporter of mentoring. The SPF initiated the Women in Security series of dinner events held in Ottawa in 2012, 2013, and 2014. While some progress has been made for and by women in security, the progress has been mixed – for example, women’s participation in various fields, including cyber security, appears to have actually declined in recent years. Momentum is building for accelerated change and improvements for women in our society, including in security, and there is a need to continue to be creative and efficient in our approach toward progress. Such is the case with the Women in Security and Resilience Alliance (WISECRA) - an SPF construct - which has since March 2015 connected some 30-plus women in security and related groups internationally, and which has inspired the creation of new groups where none existed, such as in Australia and other partner states. CS: How important is networking, association development and engagement to professional security? BB: The increasing complexity of security as a profession, the increasing complexity of security challenges and threats that we face, and the growing number of partners within the security landscape have all made networking, associations development and engagement a necessity within the security field and for security professionals. Siloed and isolated approaches to security have left gaps and openings for threats, have limited our responses and prevented an effective proactive posture. We must now reach beyond our own individual networks, individual associations, and jurisdictional boundaries as none of these in isolation will be sufficient to manage the deep challenges ahead. @SecurityEd • May/June 2016


24 EXPERT ADVICE

THE VALUE OF A LAYERED DEFENCE Bill Sweeney is CTO and vice-president of BAE Systems financial services practice (www.baesystems.com).

R

ecent breaches have made it clear that organizations’ infrastructures are porous; employees are susceptible; and with this, come rising security costs. Cyber security is increasingly adopting behavioural analytics to counter the variety and volume of digital crime. As a result, enterprises are beginning to realize increased effectiveness, greater operational efficiencies, and are making better security investment decisions.

The practical need for a layered defence: A layered defence incorporates security at all levels of an infrastructure and is designed to quickly stop attacks and identify, via a “hunt,” assets that may have been compromised. This “hunt” component is required to look for those attacks that are not yet recognized or defensible. This requires a mechanism that identifies the anomalies caused by new attacks so that remedial action can be taken. Behavioural analytics does this by identifying both good behaviour and bad behaviour. Behaviour changes over time as attack vectors change: Over time, as new attacks are discovered, a new defence is needed to protect the health of the enterprise. Each new defence can lead to an immediate reduction in successful attacks as long as

that defensive layer is maintained. Feedback loops make captured data more valuable over time: Most managers value “continuous improvement” and/or a “learning enterprise” because mistakes often turn into learning opportunities that can enhance future performance. In today’s Big Data world, algorithms are used to aid people in decision making. Feedback loops provide the raw material for refreshing existing decision making algorithms and for creating new ones. In continuous improvement cultures, decisions are reviewed so that the individual can learn how/why they made a bad decision. The same lessons apply to our Big Data solutions. They need to learn how and why they went wrong and feedback is the best way to accomplish that.

WHY YOU SHOULD ATTEND: • Expert perspectives on the terror landscape in Canada • Advice on keeping privacy in focus in a Big Data world • CPTED in Government – promoting safety in public spaces

FOCUSON

Government Register online at focusonseries.ca Brought to you by

May/June 2016 • www.canadiansecuritymag.com

October 6, 2016 The Westin Ottawa Ottawa, Ont.


BOOK REVIEW 25

By Derek Knights

SEPARATING RISK FROM THREAT Threat Assessment and Risk Analysis: An Applied Approach By Gregory Allen & Rachel Derr Butterworth-Heinemann ISBN 9780128022245

E

arly twentieth-century U.S. Vice-President Thomas R. Marshall said, “What this country needs is a really good five-cent cigar.” I’ll paraphrase that into, “What this industry needs is a really good damn-the-cost book on threat and risk assessment!” In Gregory Allen and Rachel Derr’s book, I thought I had it. But ultimately, it’s still a four-cent cigar. The two authors are experienced and credible: Gregory Allen runs the Security Management Program at Nebraska’s Bellevue University, and Rachel Derr, a Bellevue Alumni, is a director of security and safety in retail. In general, they have a grasp of what they’re talking about. They each write a number of the book’s chapters, and you can soon tell them apart by style and context. But the problem with books that never get past the fourcent mark — and it’s both big and small at the same time — is the inability to discuss the concepts and nuances of threat and risk assessment processes and the varied methodology in a manner a neophyte can understand. If the book can’t do that, then its intended audience is someone already versed in TRAs, and this one struggles to punch its weight in that group. I have a favourite bugaboo in risk assessment books — I’ve read many and someday might write one — and it’s usually terminology. In my opinion, developed from training and experience, “threat” and “vulnerability” and “risk” are not interchangeable terms. But it always seems that they are mixed about in every book I’ve read so far and this one is no different. This can confuse the newbie audience and annoy the experienced one. To me, a “threat” is an actor or event that can exploit a weakness (“vulnerability”) which creates a “risk” of a negative outcome. You can’t change them around. For example, one sentence in Chapter 4 says, “The security threat assessment is a document that outlines the deficiencies in security procedures.” No, it’s not. That would be a vulnerability assessment. The “threat assessment” would discuss the capabilities of the bad guys — the ones who could get at your assets through those security deficiencies. There are other similar instances. And a bunch of typos. Having said that, this is not necessarily a book to pass by. It’s well-organized and contains a lot of information helpful in the risk assessment and analysis process. It relies heavily on the U.S. Homeland Security directives, which is a good

thing because it denotes some rigour, procedural maturity and standardization. The book contains many forms and checklists. While I dislike many of them, some are helpful and readers can modify them to suit their situation. They help start the thinking process. This is sort of what I mean when I speak about concepts and nuances in risk assessments. The book runs end-to-end from defining risk to emergency response and crisis plans (notwithstanding we should all be revisiting our plans after Paris and Brussels). It recognizes that threats can be deliberate and non-deliberate, and puts forth the “all-hazards” planning format. The writing style(s) is more or less plain language and easy to understand. You can read this book cover-to-cover in an afternoon or cherry-pick chapters for things you need at the time. This book has its faults but it’s not all that bad. After all, a four-cent cigar might still be a pretty good smoke. Derek Knights, CPP, CISSP, CFE CIPP/C, PCI, is the senior manager, strategic initiatives, global security and investigations, at the TD Bank Group (www. tdbank.com).

Lawyer,

Mediator

Author of Visual

Evidence

Elliott Goldstein, Cell: 416.315.0066

& B.A., J.D.

elgold@rogers.com

Mediation of Disputes - Commercial, Shareholder, Employment. Litigation to Collect Debts or Defend Customer Lawsuits. Alarm Installation & Monitoring Contracts, Employment Agreements. Minute Book Reviews and Updates, Incorporations. Wills, Powers of Attorney for Property and Personal Care. Video Surveillance Law Seminars, Forensic Video Analysis Law.

www.videoevidence.ca 45 Redondo Drive, Thornhill (Vaughan), ON, Canada L4J 7S7

Fax: 905.597.6226 @SecurityEd • May/June 2016


26 PRODUCT FOCUS CCTV Mini-dome cameras

Edge camera

Illustra Illustra Pro 2 megapixel mini-dome cameras feature new UltraVision low light technology to capture high quality colour video in the most extreme low light conditions. The new Illustra UltraVision technology allows the camera to effectively maintain colour video well below 1 lux. Illustra UltraVision is suited for applications such as parking lots, alleyways, warehouses and other lowlight settings where maintaining colour and video quality is critical to the surveillance operation. Illustra Pro 2MP mini-domes also feature advanced onboard analytics, including motion detection, face detection, blur detection and tampering. To minimize bandwidth use, storage requirements and to optimize performance and video quality, users can program up to five individual regions of interest. www.illustracameras.com

Avigilon The H4 Edge Solution Camera line combines high-definition imaging, selflearning video analytics, network video recorder functionality, and embedded Avigilon Control Center video management software for an all-in-one intelligent surveillance solution. The H4 Edge Solution Camera records video directly to an onboard solid-state drive, eliminates the need for a separate network video recorder, and reduces installation and system costs. The H4 Edge Solution Camera line offers deployment options ranging from standalone installation, multi-camera solutions, to integration into a conventional network video surveillance system. www.avigilon.com

Network cameras

Sony The new SNC-VB770 camera achieves high resolution and sensitivity, in addition to low noise due to its image processing and full-frame 35mm Exmor sensor. The SNC-VB770’s E-mount lens series accommodates a variety of lens options from wide angle to telephoto, allowing easy integration into a range of video capture applications such as city, transportation, ports or critical infrastructure, nature studies or scientific applications. The camera’s Intelligent Cropping feature lets users capture a full view while cropping images in its native 4K resolution from multiple images at the same time, with either three or five simultaneous video streams. www.sonybiz.ca

Canon Canada Five new network cameras share several core technologies and features including a Genuine Canon Lens, a 2.1 Megapixel (1920 x 1080) resolution high sensitivity CMOS sensor, and Canon’s DIGIC DV III Image Processor. Models include: the VB-R12VE (outdoor) and VB-R13 (indoor) vandal resistant indoor fixed dome network cameras (also available, the TVB-R13VE with audio and external I/O support); the VB-H651V vandal resistant indoor fixed dome network camera; and the VB-H652LVE infrared vandal resistant outdoor fixed dome network camera. www.canon.ca

HD-TVI 1080p cameras Speco Technologies Intensifier and IR camera models are now available in full HD-TVI. Cameras that feature heater circuitry and anti-moisture glass to reduce fog and condensation, as well as wide dynamic range, are now available in full HD 1080p resolution over coax. Previously only available in 960H, the new HD-TVI HT7246T and HT5940T provide detailed images day or night. The HT7246T utilizes Intensifier technology, allowing users to see HD colour video in low light without IR LEDs by amplifying existing light with no distance limitations. Objects appear in 1080p clarity with low illumination. For low light situations, the HT5940T with Intense IR function can be utilized to adapt to the darkness and provide a 1080p image. www.specotech.com

4K network camera

NVR with facial biometrics American Dynamics Facial biometrics can be added to a VideoEdge network video recorder (NVR). Users can conduct a SmartSearch within VideoEdge to automatically find a matching face and view the associated corresponding video. This allows security operators to identify criminals, terminated employees, VIPs and other persons of interest. Users can save up to 1,000 faces per NVR enrollment database. Additionally, VideoEdge users can utilize the facial verification feature with victor Unified and Software House C•CURE 9000 security and event management platform. www.americandynamics.net

AD INDEX Anixter 27 www.anixter.com Bosch 9 www.boschsecurity.com/hdsecurity CANASA 11 www.securitycanadaexpo.com Commissionaires 2 www.commissionaires.ca 13 xtl.dymo.com Dymo Elliott Goldstein 25 www.videoevidence.ca Focus On 24 www.focusonseries.ca May/June 2016 • www.canadiansecuritymag.com

G4S HID Paladin Panasonic Kaba SDOTY Winsted

21 www.g4s.ca 19 www.hidglobal.com 6, 7 www.paladinsecurity.com 15 go.panasonic.ca/protect 28 www.kaba-adsamericas.com 22 www.canadiansecuritymag.com 18 www.winsted.com


Powered by partnerships with industry-leading manufacturers, Anixter takes innovative approaches to help you build, connect, power and protect valuable assets and critical infrastructures. Our Showcase events highlight the latest products while providing you with direct access to the experts and engineers that drive the latest technologies and standards. Attend this event and discover what Anixter and our partners can accomplish for you. Who Should Attend: • CSOs • CFOs • CIOs • Engineering managers • Electrical contractors and engineers • EPCs • Industrial automation managers • IT managers • Systems integrators • Engineers

1.800.ANIXTER | anixter.com

• • • • • • • • • •

Networking managers Contractors Data communications managers Purchasers Project managers CLECs Telecom managers Security integrators OEM specialists Facility managers

Your Chance to Win

a $5,000 trip voucher for 2

Attendees of the 2016 Showcase will be entered into a draw to win a $5,000 trip voucher for 2 *** Winner must be present in order to claim prize***

*Due to applicable laws and Anixter’s policy, no government personnel such as Federal, Provincial or Municipal, will be eligible for prizes or food and/ or beverages, if provided. If government personnel do register to participate in a prize draw and any of their names is randomly selected, that draw will be disregarded and another name will be drawn.

Legal Statement: anixter.com/legalstatement | 16E6045 © 2016 Anixter Inc. • 04/16

Products. Technology. Services. Delivered Globally.


Keyscan access control and integration solutions that fit. The updated version of Aurora Access Control Management software is set to integrate with Kaba E-Plex® wireless locks and Saflok hotel locks to provide a single software platform solution. Advanced security functions include managing, auditing and controlling access for any number of users, using the same credential at every door throughout a facility.

The new K-PROX3 proximity reader increases system performance. Its ultra-modern design features dedicated functions for Aurora’s updated software.

The soon-to-be-released K-PROX3 proximity reader features added technologies and dedicated functions designed for Keyscan systems. Its anti-tamper “heartbeat” intelligence triggers alarm conditions when the signal is interrupted. Plus, auxiliary LED indicators provide visual confirmation of our exclusive Present3, facility lockdown mode. For Keyscan, technology is the pulse of access control solutions that fit.

Kaba Access & Data Systems Americas 1.888.539.7226 kaba-adsamericas.com


Turn static files into dynamic content formats.

Create a flipbook
Cs june 2016 by Annex Business Media - Issuu