SNOWDEN ON CANADIAN ANTI-TERROR LAWS
SECURITY DIRECTOR OF THE YEAR GALA HIGHLIGHTS
WHY SOCIAL MEDIA IS YOUR WEAK LINK
PAGE 5
PAGE 6
PAGE 18
Canadian
November/December 2016
THE PUBLICATION FOR PROFESSIONAL SECURITY MANAGEMENT
SALARY SURVEY 2016:
www.canadiansecuritymag.com
TIME FOR SOMETHING NEW
1 in 5 survey respondents say the security job they are doing now is completely different from the one they were originally hired to do, but what’s really changing?
PM# 40065710
WE stop What caN haPPEN •
Security Guards
At Commissionaires, security is more than guarding.
•
Mobile Patrol
•
Non-core Police Services
•
Process Serving
•
Parking and Bylaw Enforcement
From risk assessment to non-core policing, Commissionaires offers a comprehensive range of security services. We are 21,000 strong with a high proportion of ex-military and RCMP in our ranks. The competition can’t match our training, discipline, sense of duty and front-line experience.
WhEN SEcurit y iS a Priorit y ca ll c o M M i S S i o N a i r E S | 877 322 6777 commissionaires.ca/cdnsecurity
CONTENTS 3
Canadian THE PUBLICATION FOR PROFESSIONAL SECURITY MANAGEMENT
Columns
Volume 38 Number 6
Is this what I signed up for?
8 FOCUS ON GOVERNMENT SECURITY The new face of government
Canadian Security’s annual salary survey results indicate job change is normal and in most cases good, but are the mechanisms in place for a smooth transition?
9 MUNICIPAL MATTERS The back-up plan 11 RISK PERSPECTIVE Network management
14
By Neil Sutton
Departments 4 EDITOR’S NOTEBOOK 5 TRENDING
Exploiting the social Employees over-sharing online can lead to some obvious holes in security, but it doesn’t take much to make a company vulnerable
6 ASIS UPDATE Police, security acknowledged by Toronto chapter
By Bruce Cowper
21 BOOK REVIEW Words to live by 22 PRODUCT FOCUS Video Surveillance
18
IN SUPPORT OF
LACE ‘EM UP FOR CHARITY FEBRUARY 16, 2017 CANLAN ICE SPORTS YORK UNIVERSITY
| TORONTO
REGISTER TODAY • www.mission500hockeyclassic.com @SecurityEd • November/December 2016
Canadian
4 EDITOR’S NOTEBOOK By Neil Sutton
ROLE CALL Salary survey results point to a broader skillset for security professionals
T
here’s an often-used expression in the media industry that states: content is king. That phrase has been interpreted over the years by various publishers, writers and editors (yes, they are all different roles, but not mutually exclusive), but it essentially boils down to one thing: good information matters to readers. How that information is delivered has become more and more fluid over time, owing to the increasing number of outlets and technologies that make its delivery possible. Printed media was once the undisputed king of content (TV and radio notwithstanding), but it didn’t take long for digital media to rise to prominence, thanks to its immediacy and almost “The fundamentals universal availability. Within that there are numerous are still there but the subsets and possibilities: blogs, videos, webinars, microsites (shorthand for small, dedicated websites that serve an ancillary purpose). I’m not going to even get way they are applied into social media and its impact on all of the above. is quite different.” Today’s journalists need to at least be aware of all of these content platforms. If they stay out of the loop, they do so at their peril. As I see it, security is much the same. The fundamentals are still there (“security best practices are king,” if you like), but the way they are interpreted, taught and applied are all quite different, depending on their circumstances. I try to look at our annual security salary survey, sponsored by Commissionaires, through this lens, identifying change, highlighting opportunities and trying to understand what’s making the industry tick. I don’t assume that our survey results will provide perfect clarity, but I do feel the survey serves an important purpose in that it provides an avenue for discussion and an opportunity to explore the relevant issues more deeply. A focal point of this year’s survey was examining role changes for security professionals. The most obvious of these, and one that was highlighted in the article on p.14 is the impact of technology, whether that’s the automation of certain security tasks, the increasing role of drones or the ubiquitous impact of cyber-security. On top of that, we have to consider the professionalization of security roles, security’s relationship with the broader business goals of an organization, and the ability of a security department to assume more responsibility and shoulder more of the workload (sometimes indelicately referred to as “scope creep”). It can seem quite overwhelming but in a sense I’ve seen it before. Content was, and is, king in the journalism world. When I started in media — and I’m trying not to date myself too much here — the printed word was supreme and the Web was only really starting to emerge as a viable news outlet. Over the years, of course, everything has changed and those of us who have stuck with it have acquired new skills and learned to manage our time more effectively. I don’t think it’s a huge leap to say security is much the same. No one is saying that everyone has to become an expert in everything, but it behoves us all to take a look at the big picture and at least have a good sense of all the colours that make up the landscape.
@SecurityEd November/December 2016 • www.canadiansecuritymag.com
THE PUBLICATION FOR PROFESSIONAL SECURITY MANAGEMENT
Group Publisher Paul Grossinger pgrossinger@annexweb.com
National Account Manager Jennifer Dyer jdyer@annexweb.com
Publisher Peter Young pyoung@annexweb.com
Art Director Graham Jeffrey gjeffrey@annexweb.com
Editor Neil Sutton nsutton@annexweb.com
Account Coordinator Trish Ramsay tramsay@annexweb.com
Online Editor Cindy Macdonald cmacdonald@annexweb.com
Director of Soul/COO Sue Fredericks
Editorial and Sales Office 222 Edward Street, Aurora, Ontario L4G 1W6 (905) 727-0077 • Fax (905) 727-0017 Web Site: www.canadiansecuritymag.com Canadian Security is the key publication for professional security management in Canada, providing balanced editorial on issues relevant to end users across all industry sectors. Editorial content may, at times, be viewed as controversial but at all times serves to inform and educate readers on topics relevant to their individual and collective growth and interests. Canadian Security is published six times per year by Annex Business Media. Publication Mail Agreement #40065710 Printed in Canada I.S.S.N. 0709-3403 Subscription Rates Canada: 1 Year $40.95 + HST; U.S.A. (payable in US dollars): 1 Year $70.00; International (payable in US dollars): 1 Year $80.00 Circulation Tel: (416) 510-5189 Fax: (416) 510-5170 asingh@annexbizmedia.com 80 Valleybrook Drive, Toronto, ON M3B 2S9 The contents of Canadian Security are copyright by ©2016 Annex Publishing & Printing Inc. and may not be reproduced in whole or part without written consent. Annex Business Media disclaims any warranty as to the accuracy, completeness or currency of the contents of this publication and disclaims all liability in respect of the results of any action taken or not taken in reliance upon information in this publication.
Editorial Advisory Board Jason Caissie Profile Group
Tracy Ann Kosa Microsoft
Carol Osler TD Bank
Ken Close Trillium Health Partners
Bill McQuade Final Image
Theresa Rowsell Kit and Ace
Ashley Cooper Paladin Security
Clark Northcott Hikvision
Tim Saunders G4S
David Hyde Hyde & Assoc.
Malcolm Smeaton Whitehorse Group
TRENDING 5 CALENDAR February 27-28, 2017 TechSec Solutions Delray Beach, Fla. www.techsecsolutions.com March 8, 2017 Security Career Expo Toronto, Ont. www.securitycareerexpo.ca April 5-7, 2017 ISC West Las Vegas, Nev. www.iscwest.com April 12,2017 Focus On Cyber Security Toronto, Ont. www.focusonseries.ca April 23-25, 2017 IAHSS Annual Conference & Exhibition Vancouver, B.C. www.iahss.org April 26, 2017 Security Canada East Laval, Que. www.securitycanadaexpo.com May 10, 2017 Security Canada Alberta Edmonton, Alta. www.securitycanadaexpo.com May 31, 2017 Security Canada Ottawa Ottawa, Ont. www.securitycanadaexpo.com June 23-27, 2017 IACLEA Annual Conference & Exposition Milwaukee, Wis. www.iaclea.org September 25-28, 2017 ASIS International Seminar and Exhibits Dallas, Tex. www.asisonline.org October 4, 2017 Focus On Drones Toronto, Ont. www.focusonseries.ca October 18-19, 2017 Security Canada Central Toronto, Ont. www.securitycanadaexpo.com
Snowden takes aim at Canadian anti-terror laws
N
to review, on a case by case basis, every SA whistleblower Edward Snowden use of the power provided by C-51 to spoke via video link to a packed ensure it is carried out in accordance with crowd at the SecTor cyber-security the law. Second, he said, there should be conference in Toronto in October about no mass sharing of intelligence through some of the recent fundamental changes international channels without in surveillance systems and adequate reason to do so. “People practices. are not Pokémon,” he said. “We Regarded as a pariah by shouldn’t be traded like this.” some and a patriot by others for Finally, Snowden took C-51 his actions, Snowden came to to task for perceived vagueness international attention in 2013 of the term terrorism. “There is as the government contractor no commonly agreed upon legal who outted the National Security definition here,” he said, arguing Agency for its surveillance Edward Snowden that some who are branded practices. During his opening addresses Toronto terrorists, largely by media, address at the SecTor conference, crowd at SecTor “are really common criminals” which celebrated its 10th conference who do not ultimately present a anniversary thus year, Snowden “super-criminal threat that is represented argued that the balance of power has by our terrorism legislation.” shifted in large part due to the current The Government of Canada opened technology that enables surveillance. the anti-terror legislation and the nation’s “A generation ago, surveillance was security policies for public consultation expensive. Governments had to spend beginning Sept. 8 to “ensure they reflect huge sums to track lone individuals,” said the rights, values and freedoms of Snowden. “Now, one guy sitting in front Canadians,” according to a message from of a monitor can track with precision Public Safety Canada. The consultation an unimaginably large and increasing period is set to end on Dec. 15. number of individuals. Instead of teams Snowden also weighed in on the tracking individuals, you now have recent Apple vs. FBI situation when individuals tracking teams.” the latter tried to compel the former Snowden argued that the balance to provide access to the locked iPhone should be reverted in order to prevent that was recovered from one of the San ongoing, widespread intelligenceBernardino shooters. gathering of entire populations. Snowden argued that technology “That may sound radical if you’re providers should not as a matter of thinking about the law enforcement course build back doors into their devices context, but for an American, it is to allow government or law enforcement actually a fairly fundamental idea,” said immediate access since that would Snowden, invoking the U.S.’s own Bill of introduce a weak point that may be Rights as one reason for resisting mass exploited by others. Companies should surveillance. be accountable to their customers first, he Regarding Canada’s Bill C-51, said, not the government. anti-terror legislation brought in under He also commented on the growing the previous Conservative government, belief that young people are less guarded Snowden echoed the sentiments of some about their privacy than previous of its critics, saying it falls short on three generations. “They get angry when people major fronts. Primarily, he said, it lacks say they don’t care,” he said. meaningful oversight. Snowden suggested there should be a judicial body in place — Neil Sutton @SecurityEd • November/December 2016
6 ASIS UPDATE
By Neil Sutton
Police, security acknowledged by Toronto chapter
T
he Toronto Chapter of ASIS International announced the recipients of its law enforcement and security awards during a lunch ceremony held Oct. 20. Jason Ball, Purolator’s manager of security technology solutions, was named security professional of the year for his guidance of a major security install. In the police category, the recipient was D/ Cst. Scott Airey of Durham Regional Police. Two security guards were recognized for their actions last December, when they were able to successfully disarm a man wielding a weapon on a busy street intersection in downtown Toronto. Paragon Security guards Nathaniel McNeil and Phillip Bonaparte received national attention last year when video emerged of them tackling then
Bill Anderson, ASIS Toronto; Phillip Bonaparte, Paragon; Michael Brzozowski, ASIS Toronto; and Nathaniel McNeil, Paragon
handcuffing a suspect who was seen brandishing a machete in an apparent attack on another individual. The suspect was later identified by police and charged with attempted murder. “It was not a regular day for us,” said McNeil of the incident. McNeil had been forewarned that an armed and dangerous person was in the vicinity of the area where he works, Toronto’s Atrium at Bay
and Dundas, but said he knew something was immediately very wrong when he saw the reactions on the faces of the patrons at a nearby restaurant. McNeil said he was able to restraint the suspect and bring him to the ground while Bonaparte secured the weapon and applied hand restraints. The suspect was then turned over to the police. McNeil added he was not aware of the attention his actions garnered until he began receiving requests for media interviews later that day. At the October award presentation, the ASIS Toronto chapter also recognized Sheridan College student Yagana Samim, who received a bursary and scholarship. Samim delivered summaries of her research and essays on terrorism terminology and perceptions, and the role of aggression in perpetuating racial and sexual prejudices.
Security Director of the Year 2016 AWARD GALA C
anadian Security celebrated the achievements of Patricia Patton, director of security and operations at the University of Regina, with a gala event, dinner and award ceremony sponsored by Anixter Canada on Oct. 19 in Toronto.
From left: G4S Canada’s J.D. Killeen and Floria Chiu with HR REIT’s Mike Soberal
Pat Patton receives her award from Canadian Security publisher Peter Young (left) and Gary Mistak, Anixter Canada
Baycrest Health Sciences’ Martin Green (left) and Brine Hamilton
Patton thanked colleagues, friends and family for their support
Rick Snook, Axis Communications Manulife’s Mike Allen (left) with ASIS (left) with Minaz Jivraj, Dufferin-Peel Toronto Chapter Chair Jason Caissie Catholic District School Board
November/December 2016 • www.canadiansecuritymag.com
Ronald Gibbon, security coordinator at the Regional Municipality of Niagara (left) with Canadian Security columnist Mel Gedruj
Don’t give risk the slightest opportunity.
Corporate Risk Services
Systems Integration
Software & Technology
Security Personnel
AMAG Technology Symmetry GUEST Security Products Magazine New Product of the Year 2016 Visitor Management
When you prepare, you prevent. At G4S, we integrate our resources and expertise to help businesses mitigate risk and protect assets all around the globe. G4S can help you stay ready – with everything from security officers and investigators to managed services and technology – to help shut out risk wherever it could appear. To stay prepared, please visit g4s.ca or call 888-717-4447.
8 FOCUS ON GOVERNMENT SECURITY By Allan McDougall
THE NEW FACE OF GOVERNMENT
T Federal structures have had to rethink security and embrace modern approaches
he federal government has certainly baseline but not the advanced understanding not been immune to the economic needed to take on Agency requirements. As a pressures facing other security result, the Agency developed a progressively organizations within Canada. tiered system that used the CSPS baseline, Consequently, security organizations have then built upon it using a structure that had to evolve administratively, technically and integrated many outside practices: operationally. • The establishment of a management The primary step involved reinforcing the structure for training based on ISO 17024 concept that the federal (Requirements for bodies security program consisted operating the Certification of two main activities. of Persons) intended to keep “The security officer no The first and most visible training relevant to Agency activity involved the needs; longer worked within a provision of security • The formation of a government bubble.” services such as guard training continuum from the services, security patrols, entry level to management sweeps and combination to give a clear sense of changes. The change in this step involved knowledge expectations; understanding that the security advisor roles, • The creation and ongoing delivery of 63 essentially functional roles, were much more webinars intended to provide detailed in line with the professional, scientific and training on technical aspects of the technical services defined in NIACS 2017. program; and The second step involved understanding • A formalized coaching and mentoring that the federal physical security officer no program to help personnel integrate their longer worked within a government bubble. learning. When the Government of Canada owned These four elements culminated in its own infrastructure (and it still does in individuals being encouraged to seek some rare cases), government policies could certification to industry standards so as to be considered authoritative and final in be working at parity with the consulting and their own right. As a result, the physical senior security officer positions representing security officer simply needed to impose the the private sector at the table. requirements of policies and standards. With This training has allowed the Agency divestiture and the rise of the public-private to take on innovative projects that focus on partnership, this landscape has changed. The improving service delivery. federal security officer now operates in a These improvements were possible span of influence where his or her decisions because the internal capacity moved from a must be scrutinized by those who look to passive compliance mode (waiting for lead save each and every dollar but who also look agencies to provide guidance) to an active at the issue through a private sector lens. In innovative mode (focusing on problem solving short, the new relationship is one where the in support of operations). The key to this federal physical security officer needs to be shift, however, resided in modernizing our able to perform his or her function based on concepts of professionalism and then building reasoning that can influence a performance our capacity to best meet that standard of and efficiency driven group. performance. To accomplish this, physical security within the CBSA identified that training was Allan McDougall is Manager, Physical Security, (by a margin) the single greatest gap. With Comptrollership Branch, Canada Border Services Agency most physical security officers having access and was a presenter at the Focus On Government Security to only three courses through the Canadian conference hosted by Canadian Security magazine in School of Public Service, that provided a October in Ottawa.
November/December 2016 • www.canadiansecuritymag.com
By Mel Gedruj
MUNICIPAL MATTERS 9
THE BACK-UP PLAN
C Critical infrastructure requires an approach that considers contingencies and promotes resilience
ritical Infrastructure as defined ASIS SPC.1.2009 (SPC stands for Security by Public Safety Canada “refers Preparedness and Continuity). to processes, systems, facilities, A good practitioner’s reference technologies, networks, assets and services would be James LeFlar and Marc Siegel’s essential to the health, safety, security or “Organizational Resilience: Managing the economic well-being of Canadians and the Risks of Disruptive events” (Taylor & Francis effective functioning of government.” Group, 2013). The US Department of Homeland Security In it, they qualify the approach with an (DHS) defines it as “the interesting outlook on these backbone of our nation’s two standards: “It is like an economy, security, and Italian recipe; it tells you “What should be health.” ‘what’ you need to do but Ten sectors are listed let’s you determine the ‘how’ avoided is a single as CI in Canada while 16 to fit your taste.” point of failure.” have been identified by Once the strategic level the DHS in the U.S. For has been planned using the the purposes of municipal above noted methodologies, management, two to three are to be covered: we need to deal with more practical issues of Public Transit (PT), Water/Wastewater (W3) what to do in infrastructure and operational and the third could be Energy/Utilities. security management. Whether we are dealing with bus, rail or The American Water Wastewater water systems, the important concept that Association publishes guidelines for physical dominates current thinking is “resilience.” security while the Canadian Water Waste This goes beyond mere security concepts Association has been promoting Cybersecurity to the management of the organization‘s in collaboration with Public Safety Canada. multiple risks be they financial, affecting As for Hydro distribution security, the CEA optimal service delivery or safety and security. issues guidelines to its members. Another conceptual model to retain is Transit was the subject of an extensive that these systems are designed in a very security enhancement from 2006 to 2009 similar way to IT networks. Therefore when through Transport Canada’s sponsored establishing the required range of criticality, Transit Secure program delivered in rounds it is paramount to evaluate the consequential going from a large metropolitan system down loss of each of the components. Resilience to small ones. The take away from all the is also to be assessed. For instance, when available knowledge shared via a number reviewing water reservoirs or pumping of them such as Canadian Cybersecurity stations, it would be advisable to check the Response Centre, the Infrastructure Security areas served and when assuming a total loss Partnership, WaterISAC or others, is that of service, verify that another water asset facility and cyber security are intertwined, in maybe able to pick up the slack. Also, within essence two faces of the same coin. the pumping station itself, the question would The reason being that Internet based be, do we have enough redundancy in spare communications have increased the pumping capacity? As with any networks, vulnerability of our industrial controls what should be avoided is a single point of systems ( SCADA). However, it should be failure, which makes resilience a challenging noted that both wired and wireless systems goal to achieve. need to be housed somewhere and CI assets What are the guidelines and standards are physical infrastructures on land or we could rely on to assist us in our underground. security management planning work? For Organizational resilience ISO 31000 Mel Gedruj, OAA, CSPM is the president of V2PM Inc., Risk Management standard and ANSI/ specialized in municipal security management planning. @SecurityEd • November/December 2016
By Tim McCreight
RISK PERSPECTIVE 11
NETWORK MANAGEMENT
T
Whether you’re dealing with IT infrastructure or a system of partners, consider the risk they introduce
he recent attacks on the Domain realization goes beyond the cyber domain, and Name Service (DNS) hosted by reaches into the physical world as well. Dynamic Network Services Inc. As security professionals, we must start (Dyn) demonstrates a principle of risk looking at how our organization uses other management that we sometimes neglect to services like the Internet, or the rail system, factor during our internal risk assessments or national trucking companies, to provide — the impacts we may face from business our services. Assessing risks must take into partners or technology account myriad new providers that cannot tangents, ranging from the service our needs. impacts we could suffer “Assessing risks must By now, we have read if our Internet Service how the attack against the take into account myriad Provider was unable to Dyn DNS was launched manage a concerted attack, new tangents.” from, among other vectors, to the impacts our company Internet connected devices would face if the rail that had poor or negligible system were unavailable or security, and how the impact was felt by some impacted by a labour action. very high profile organizations like Netflix, Many of us plan for these events as LinkedIn and Tripadvisor. The service outages part of our Disaster Recovery Program, or faced by customers of these organizations Incident Response Plan. I believe we need have been reported in the media, and to bring these components closer to our concerns range from why this attack affected operational models, and begin assessing these their service, to preventing this type of risks alongside our current methodology. incident occurring in the future. Over the past few years, we’ve seen the I had a chance to review many of the interdependency of internal systems to the reports on the event, and understand the Internet, and our reliance on vendors and concerns many have regarding the issues their ability to deliver products, increase to arising from the “Internet of Things”, and the point where failures from external entities the potential threats these devices pose to has an immediate impact. Companies like Internet connected services. Looking past Netflix felt the recent attack immediately, the technical components of these events, I when clients attempting to legitimately access began to realize some of the lessons we can the service were rejected because the Netflix all take from these incidents. environment was bombarded by automated Over my career, I conducted a number of requests from compromised devices. threat and risk assessments against physical What also struck me was our acceptance and logical assets. I’ve highlighted how of other companies and their security posture. some of these assessments were conducted Our organizations rely on other organizations in previous columns, and focused on the more now than any point in history. In many benefits of including business leaders and key cases we simply accept that these supporting stakeholders, to develop a more holistic view players have their risks under control, and of risks facing an organization. Many of these will continue to be a critical component to assessments focused solely on the organization, our success. The lessons we’ve learned from and how it can react to events by developing this recent event should force us as security internal controls to mitigate risks. professionals to recalibrate our risk assessment Recent events, however, highlight the need process, and begin some potentially difficult to extend our assessment beyond our own discussions between our organizations, and organization, and truly begin to understand those we rely upon for success. the complexities of how our organization interacts with other organizations to provide a Tim McCreight is director, advisory services at Above service, sell a product, or address a need. This Security (www.abovesecurity.com). @SecurityEd • November/December 2016
PALADIN RECOGNIZES ITS EXTRAORDINARY PEOPLE KRISTA BRODIE | Security Officer
Extraordinary Moment
T
he Charles V. Keating Emergency and Trauma Centre at the QEII’s Halifax Infirmary is the largest in Atlantic Canada. Through an annual awards program, the staff of the QEII ER acknowledge their team members’ dedication and hard work. Paladin Security Officer Krista Brodie was awarded Best Support Worker in 2016 for her consistent service excellence. In the years that the awards have been given, Krista was the first Security Officer to stand amongst the winners. Home to leading care, research and teaching in all medical and surgical fields, the QEII is a unique setting. With a substantial team of committed professionals who strive to provide excellent emergency care, consistent security support is needed. Krista’s service and training aided the medical staff in countless incidents. Her consistency with people made a real impact on patients and with fellow healthcare professionals alike.
ship exceeding clients’ expectations, and that comes through in the attitude, character, and efforts of team members like Krista.
Read More: paladinsecurity.com/extraordinary
What the Client Said Krista Brodie was our first ever Security Officer Recipient of Best Support Worker of 2016 at our annual awards banquet. Krista has provided our department with great presence and tremendous customer service skills that help assist people on the path of wellness. She was recognized by staff for her caring and thoughtful attitude towards not only the patients and their families, but our staff as well. This is a well-deserved recognition of an outstanding team player. – Robert MacKinley, Health Services Manager, Department of Emergency Medicine, QEII Health Sciences Centre.
Pj Spencer, Client Service Manager at Paladin Security, said, “When Krista won the award, I was so proud. She has excelled within the healthcare field and her strong sense of empathy compliments the patient-centric approach that Paladin strives for. She has built amazing relationships with the QEII team.” Krista shared, “It is a true honour to be selected as Best Support Worker at the Halifax Infirmary. I am so grateful for the acknowledgment. This award shows how good customer service and security presence truly impacts our clients.” Customer service is at the core of Paladin’s security programs. In every interaction – the single purpose is to forge a relation-
In photo (left to right): Health Services Manager, Department of Emergency Medicine QEII Health Sciences Centre, Robert MacKinley. Security Officer, Krista Brodie.
Extraordinary People, Extraordinary Service. Since 1976. • SECURITY OFFICERS • MOBILE PATROLS & EMERGENCY RESPONSE • OPERATIONS CENTRES
• ALARM, FIRE & VIDEO MONITORING • ACCESS CONTROL SYSTEMS
• INVESTIGATIONS • SECURITY AUDITS & CONSULTATIONS • MANAGED SERVICES
• EMERGENCY MANAGEMENT & BUSINESS CONTINUITY PLANNING • CAMERAS & VIDEO MANAGEMENT SYSTEMS
Extraordinary happens everyday.
“Krista has provided our department with great presence and tremendous customer service. This is the well-deserved recognition of an outstanding team player...” – Robert MacKinley, Health Services Manager, Department of Emergency Medicine, QEII Health Sciences Centre.
KRISTA BRODIE
Security Officer, Paladin Security Halifax, N.S.
EXTRAORDINARY MOMENT First Security Officer awarded Best Support Worker of the Year, QEII Health Sciences Centre
#extraordinary
14 SALARY SURVEY
IS THIS WHAT I
SIGNED UP FOR? This year’s salary survey results indicate security is still in a rapid state of evolution, but what that looks like to the individual depends very much on their appetite for change, organizational pressures, and other factors like the growing influence of cyber-security By Neil Sutton
C
hange is a significant part of almost any career and security is no different in that regard. The extent of change in a job role or function is dependent on a variety of factors. Some of that change comes about naturally as promotions are attained and job roles expand. In other cases, security professionals may find themselves taking on additional responsibilities that fall outside their job description or even outside their security skillset or the work itself may have changed drastically in response to technology advancements. According to Canadian Security’s annual salary survey, almost one in five respondents say they are now doing jobs that are completely different from the ones they were hired to do. This is a concept that will be more fully explored and explained as we examine the survey results in greater detail and ask experts to help us interpret those findings. In 2016, the salary survey, sponsored by Commissionaires, was completed by 208 respondents in September and October. Of those respondents, the most common titles reported were: Security director (13.46%), security manager (24.04%), security guard (13.46%) and site supervisor (10.58%). Others included: senior vice-president, president, IT security
November/December 2016 • www.canadiansecuritymag.com
professional and consultant. The majority of respondents said they work in Ontario (57.84%) followed by Alberta (12.75%) and British Columbia (9.31%). More than a dozen vertical markets were reported as major employment sectors. The most common were: Commercial (7.34%), Education (9.04%), Health Care (10.73%), Public Sector (16.38%), Retail (10.73%), Finance/Banking (7.91%), and Manufacturing (8.47%). When asked, “How has your job/employment changed in recent years?” 41.62% of respondents said “New skills required due to increased job scope/responsibilities,” and 19.65% said
GENDER
Female
16% Female
84%
15 “My job is completely different than the HOW LONG HAVE YOU BEEN WITH YOUR CURRENT EMPLOYER? one I was first hired to do.” In response to the same question, 22.54% said they have Less than expanded their professional scope in the 6 months hopes of achieving career advancement, 6-12 months but otherwise their job roles remained the same. Just over 16% said they saw “no 1-5 years appreciable change” in their jobs. Written responses to the question 6-10 years indicated a variety of reasons for these shifts in roles and responsibilities. “[My] 10-15 years employer keeps adding tasks to my plate and it is overflowing already. I need two 15-20 years more plates to accommodate the multiple tasks,” responded one survey taker. Others 20+ years said they started in entry-level positions (guarding, for example) and were able to advance in their careers, taking on planning are quite common today. more and more responsibilities through “Typically those functions have a little promotions and new job opportunities. bit of touch on security,” he says. “It’s Additional work load, broader scope of somewhat dependent on the industry responsibility and knowledge and the sector, segment or channel, but we do Greg Hurd, a security professional with increasing role of technology (such as see some of that for sure.” more than two decades of experience (and learning new software) were also cited as Regarding some of the technical a policing background before that) shares contributing to major job changes over changes and challenges in security, his advice on how to get started in security time. “The burgeoning survey respondents and what it takes to succeed. of electronics/cyber has were also asked, “How • Identify early on what motivates “It may be the security changed the package has technology changed you towards the security space and completely,” wrote one your job function?” look at opportunities to capitalize on guy and IT getting respondent. In total, 44.51% of that, either through exposure to the “I think there’s respondents said that industry or academic programs or together for coffee two drivers there: a “greater number of training opportunities. one is the change in IT/computer skills are • Look at your education and experience and saying, ‘Here’s the both the technical and required.” More than a like a toolbox. Try to figure out how direction we’re going in.’” quarter (27.75%) said, professional aspects of many tools you have in that box right the profession,” explains “IT knowledge/skillset now and figure out what else you — Greg Hurd, ASIS International Greg Hurd, president of is now an essential part need to put in to be successful. the ASIS International of my job function.” • Assess the security landscape when certification board and Of those that indicated looking at career options: It depends a senior security director in the energy little to no change, 19.08% said they on an organization’s appetite for risk sector. “Second, it’s the organization had experienced “some changes but no and the threats they may face as to change that the organizations are more than most jobs,” like an increasing how much time and effort they may undergoing.” use of smartphones, and only 8.67% be willing to put into security. CyberAt some of the most senior levels, indicated no change at all. security skills, including the prevention security managers have seen non-core For security guards and supervisors, and detection of social engineering, duties being added to their workload, technology has become an integral part will likely be attractive to a wide adds Hurd, noting that parking and travel of work, says Bruce Belliveau, CEO, variety of organizations.
3.5% 5%
29% 23.5% 16% 8%
15%
So you want to be successful in security?
AGE
20-30
30-40
6.28% 19.81
40-50
37.20
50-60
22.71
60-plus
14.01
@SecurityEd • November/December 2016
16 SALARY SURVEY WHAT IS YOUR ANNUAL SALARY? 0.50%
3.98%
13.93%
16.92%
16.42%
17.91%
15.42%
7.46%
3.98%
3.48%
Under $10,000
$10,000 $20,000
$20,000 $40,000
$40,000 $60,000
$60,000 $80,000
$80,000 $100,000
$100,000 to $120,000
$120,000 to $150,000
$150,000 to $200,000
More than $200,000
Commissionaires Nova Scotia. Rather than simply checking ID cards as employees walk through the door, today’s security staff may have considerable responsibility in terms of running and managing more complex access control software. More than that, they may be required to handle surveillance systems or even pilot drones — a technology that Commissionaires is exploring for some of its patrols. “There’s a significant technical aspect to security guarding that’s coming to the fore,” says Belliveau, as well as more stringent training requirements. Without that training, “the chances of [career] progression are slim to nil.” The degree to which IT and cyber security has changed more traditional physical roles varies greatly. According to one survey respondent, “Having a basic understanding of IT security functions is necessary as more and more technology is intertwined with physical and IT aspects.” For Ed Dubrovsky, head of security for OnX Enterprise Solutions, physical and logical security operate on the same continuum. “It’s really been there all along. I just think we haven’t been paying too much attention to it. Folks who are coming into the industry really need to understand both aspects,” says Dubrovsky. A recent example of that, he says, is the major DDoS attack reported on Oct. 21 in which numerous popular websites such as Twitter and Spotify were affected with downtime, as well as entertainment services like Netflix. In some cases, IoT devices, webcams and security cameras were identified as possible network weak points that were exploited by hackers. “If you use the connected camera example, in this latest attack, a lot of these cameras installed around the world have been installed with default passwords. That enabled the malicious actors to gain control over these cameras, exploit a particular vulnerability within them and make them attack other websites and behave in a manner that wasn’t by design.” In those cases, says Dubrovsky, the onus may be on the manufacturers, developers and integrators to ensure that they are manufacturing and installing technology that meets much more stringent criteria in terms of network integrity. However, he says, security professionals from almost all walks of life November/December 2016 • www.canadiansecuritymag.com
should at least attain a proficient level of technical knowledge. “From a skills perspective, I feel that security folks today need to understand the physical, they need to understand the digital, but they also need to understand that they’re almost like a soldier within an army — they need to understand some of the bigger strategic issues affecting the industry overall. It’s a very interesting combination of skills,” says Dubrovsky, who recently helped York University implement the CISSP designation for its cyber security program. Hurd adds that while there is definitely a strong correlation between IT and physical security skills, there can often be some “ebb and flow” in terms how that convergence model is realized within organizations. There are few people who are equally adept at both, but may need to confer regularly with their counterpart in order to maintain the appropriate security posture. In many cases, he explains, it may be “the security guy and IT getting together for coffee and saying, ‘Here’s the direction we’re going in. Are there any impacts either of us needs to know about?’” In terms of how survey respondents view their profession overall, many still point out some of its seemingly perennial deficiencies, particularly at entry-level guard positions: low pay, dull or repetitive work and poor public image. That said, overall 81% of respondents said they would recommend security as a career to a friend, a slight increase over previous years when that same question was posed. And despite some of the industry’s shortcomings, many respondents were generally upbeat in their responses to the question, “what are the advantages of a career in security and what are the drawbacks?” “It is a very interesting career with many different challenges, but this job does change your personal outlook on people,” wrote one respondent. Another said there is “diversity in the job. You learn and gain further insight into the operation of your company quicker than most employees.” One respondent said that security professionals “touch everything in the organization” which is “an advantage and disadvantage. We grow our sphere of control but the resources required to perform this added diligence are not necessarily keeping pace.”
SWIPE TAP TWIST POINT TOUCH OR PUSH WITH CONFIDENCE. Technology is evolving and words like “interoperability” are taking on entirely new meaning. HID Global is leading the industry by developing the world’s broadest portfolio of truly scalable, fully interoperable secure identity solutions. We are connecting people to places with physical, mobile and virtual access solutions like never before—and we’re doing it with the most advanced layers of security anywhere on the planet. You’ll call it seamless end-to-end solutions. We call it, “your security connected.” YOUR SECURITY. CONNECTED
|
Visit us at hidglobal.com
© 2016 HID Global Corporation/ASSA ABLOY AB. All rights reserved. HID, HID Global, the HID Blue Brick logo, and the Chain Design are trademarks or registered trademarks of HID Global or its licensor(s)/supplier(s) in the US and other countries and may not be used without permission.
18 TECHNOLOGY AND POLICY
EXPLOITING THE
SOCIAL
How unguarded use of social media can make your company a more attractive target to criminals By Bruce Cowper
O
data, and use it against you. The security consequences can be calamitous.
pen Source intelligence (OSINT) used to be something that only Mining professional social networks journalists and spies did. Even those employees who use social media A rarified practice, it responsibly can make it easier for attackers “Consumer social involved mining publicly to find attack points in your company. In networks are an available information professional social networks, the relationship sources to find out everything you could metadata alone makes it easier for an attacker emotional playground about a target. to reconnoiter your company and find soft Operatives would scour newspapers, then and people often switch targets. TV and radio broadcasts, and then digital Attackers like to profile more than just data sets that were hard to find. It took talent your company’s technical infrastructure off their internal filters and hard work. because open network ports are not the when posting.” Then, social media happened. Now, only attack points. People are soft targets, anyone can be an OSINT operative — and social graphs provide a clear picture including your next online attacker. They of your company’s personnel. It’s like an may already be mining your employees’ organizational chart in a box. social media accounts for useful information, and when they Not all social networks list a person’s relationships for find it, they’ll put it together with other publicly available everyone to see. LinkedIn only makes a person’s relationships
November/December 2016 • www.canadiansecuritymag.com
TECHNOLOGY AND POLICY 19 visible to their direct contacts. Nevertheless, fake accounts (known as “sock puppets”) can be a great tool for attackers wanting to probe this information. Attack groups have used LinkedIn sock puppets with surprising success. F-Secure highlighted one such incident in 2015, where attackers used fake LinkedIn profiles to target infosecurity professionals. The fake account, Jennifer White, worked for a bogus company, and all her connections were other fake employees, so this was pretty easy to see through. A more sophisticated LinkedIn OSINT operation came from “TG-2889,” a group identified by SecureWorks as an Iran-based operation that regularly uses LinkedIn for reconnaissance. Its sock puppetry was more convincing, with two layers. The first layer consisted of “persona” accounts, with extensive histories, claiming employment at known companies in the security sector such as Northrop Grumman. These were backed by a larger number of less fully-developed secondary accounts that were used to bolster the persona accounts with endorsements. TG-2889 would regularly change the names and photos on its persona accounts, presumably in preparation to hit new targets. These accounts were used to target infosecurity professionals, some of whom ended up connecting with the fake accounts. If it works on these supposedly hardened individuals, the chances are it will work on your employees, too.
Combining social media information with publicly available data Consumer social networks are even worse than professional networks in many ways, because they’re an emotional playground and people often switch off their internal filters when posting. People put all kinds of personal information on Facebook that they wouldn’t dream of putting on LinkedIn. That makes them vulnerable, which can make their employers vulnerable. Social media information doesn’t have to be embarrassing or incriminating to be useful, though, especially when combined with broader OSINT techniques. The hallmark of a good OSINT attack is to find seemingly innocuous information and use it in innovative ways to achieve greater goals. Data becomes information when it has context. Information becomes intelligence when it turns into something you can use. It all starts with simple data points that can be mined from social media. Recently, U.K.-based fraud prevention non-profit CIFAS staged a stunt in a coffee shop. Customers were offered free coffee to like the shop’s Facebook page. When they ordered their coffee, the barista asked for their first name. In the time the coffee was made, staff in a van nearby looked up their full name from the Facebook page, and swept online sources for more information. By the time the customer got their coffee, the barista had written their details all over it: addresses, ages, job titles, and more. All from a single Facebook like. Attackers can begin building a profile of a person from
these small data nuggets in a relatively short time period. Cross-referencing to other social media sites can be relatively straightforward using many sites like Pipl, or (for U.S. users) Spokeo. Searching posts in industry forums can turn up nicknames. If an attacker sees them using a handle on an industry discussion or support forum, he can search for it on Checkusernames to cross-reference other social media sites they may be using. Because all of this information is available online, searches are disturbingly easy to automate. Chris Maddalena, a security consultant who spoke at SecTor 2016 in Toronto earlier this year, frequently runs sanctioned OSINT operations on his clients to test their security. He even created his own tool to automate OSINT searches. Automated OSINT can be devastating, especially for targets in countries where more public data is available. If you live in the U.S., then I can find out not only your address, but the tax information on your property. Some states and countries make electoral lists public, which provides yet another reference point for attackers looking to leverage social media data. Others, like Mexico, just accidentally publish them online.
Thinking outside the box The available information isn’t just textual. One of the attractions of social media is its ability to relay rich information. Shared images and video are the language of social media, and they can often reveal more than you’d expect to a trained eye. Sites like Instagram enable their users to flag accounts or images as private, but many don’t know or care. Searching employee accounts, or searching by company name or location may yield data from public accounts that can reveal useful things. One security consultant known to SecTor uses Iconosquare to search for images across social media accounts including Instagram, using hashtags like #myjob. Match this with location and keyword searching, and some workplace shots may pop up. That goofy office pic may show a password written on the wall, or something on a screen. Or maybe just finding out that they all use Macs in that office is enough. The greater an employee’s attack surface, the more likely an attacker is to find out useful pieces of information that can then be parlayed into intelligence. So, social media can be used as a starting point for further OSINT investigations, but don’t assume that all the information will be accurate. A successful attacker will cross-reference information from multiple sites to sanity-check what they’re finding and weed out extraneous information that a site may have gathered from another account.
Attacks Tools are making it easier to gather this information than ever before, but it still takes effort. What would someone use it for? Successful reconnaissance can fuel a range of attacks on a target. @SecurityEd • November/December 2016
20 TECHNOLOGY AND POLICY Social engineering is the most obvious attack. It can be difficult to persuade someone who doesn’t know you to open an infected file, but it gets far easier if you know a few things about them. Slipping a few things into a conversation while posing as a customer or someone from tech support can be fruitful. Have they been on holiday recently? Do you know who their immediate boss is, or an ex-lover or old school friend? All of these things can be used in a well-crafted email message. Impersonation is an oft-overlooked attack. Registering an account with the target’s handle on a social network that they don’t use enables the attacker to impersonate them to others. That could be particularly useful when trying to discredit the target or take advantage of the trust that other individuals have in them. Perhaps an attacker might send an infected link to the target’s work colleague from that account to try and gain a foothold on the corporate network. Sometimes, all an attacker needs are a few pieces of information — just enough to answer the personal security questions on their target’s account. The answer to Sarah Palin’s Yahoo security question was found from information from a simple Google search, and the answers to celebs’ security questions were equally easy to find for those hacking nude photos from their Apple accounts. A target’s social media account will often get an attacker what they need to reset an account.
How to protect yourself Companies that can be targeted via their employees have a duty to protect themselves by policing social media use and having a policy about what corporate information can and can’t be posted. Not posting corporate information is a no-brainer, but ultimately these accounts are the property of the individual, and the attack points are beyond the company’s control. The bottom line is this: Social media is a demilitarized zone. You can’t control what explicit or implicit information is gleaned from it. But you can act to protect yourself against the attacks that this intelligence is used for through a mixture of technical protection and employee education. As part of your social engineering and security awareness training (you are doing that, aren’t you?) include a section on social media. A lot of the steps are common sense, but it takes mindfulness to avoid slipups. In a social world, vigilance is key. Bruce Cowper is a founding member of the Security Education Conference Toronto (SecTor), the Toronto Area Security Klatch (TASK), the Ottawa Area Security Klatch (OASK) and an active member of numerous organizations across North America. In his day job, Bruce works for Microsoft helping to deliver cloud security and compliance.
FOCUSED. EDUCATIONAL. INTERACTIVE Where the Security Industry Talks Solutions
Three events in 2017 that meet the needs of today’s security professionals with targeted content, expert speakers and valuable networking time
Register online at focusonseries.ca Brought to you by
Cyber Security April 12
Drones October 4
November/December 2016 • www.canadiansecuritymag.com
Health Care Security December 8
For more information and sponsorship opportunities, contact Peter Young at pyoung@annexweb.com, 905-713-4344 or Jennifer Dyer at jdyer@annexweb.com, 416-450-5848.
By Derek Knights
BOOK REVIEW 21
WORDS TO LIVE BY A
s our world and our businesses grow more complex, our writing must reflect this and help make them more understandable. Good writing still needs to come from good writers. Earlier this year, I wrote mini-reviews of four books on business and report writing and I’ve made it my mission to keep doing this. This is my tale: I thought I was a great report-writer because I’d being doing it so long. But at age 40 and writing reports for more than 20 years, I found myself with a tutor to teach me business writing. You see, my boss (and her bosses) weren’t as impressed with my writing as I was. Developing good writers on your staff is important, but it might be more difficult than you think. Two psychologists studied what they call the Dunning-Kruger Effect, which demonstrates that about half of any group will overestimate their abilities in various tasks, sometimes significantly. They think they write well, because they can’t recognize what they’re doing wrong, and you will be hard-pressed to convince them otherwise. Studies in the U.S. and Canada show roughly 40 per cent of the population score less than 3 (out of 5) on literacy skills, including 20 per cent of university graduates. So, probably half your employees think they write better than they do, and almost half have unsatisfactory literacy skills. Look carefully at your employees (and yourself), then look at this book: “Writing Without Bullsh*t: Boost Your Career by Saying What You Mean,” by Josh Bernoff, HarperBusiness, 2016, ISBN: 978-0062477156. Bernoff cuts through the bull early in this terrific new book, and boils writing down to the basics. He introduces the term Iron Imperative: you must treat the reader’s time as more valuable than your own. Three early chapters in his book are about change: Change Your Perspective, Change What You Write, and Change How You Write. Those three chapters should be required reading for every security manager.
Most large organizations will have a “style guide” so, in theory, people writing on its behalf are consistent. If you have one, use it. If you don’t have one, make one. Bill Walsh is the copy editor for the Washington Post, so it’s his job to enforce consistency and he has written three books you will find helpful. And they’re funny. Mr. Walsh writes concisely, though not necessarily in his titles: • Lapsing Into a Comma: A Curmudgeon’s Guide to the Many Things That Can Go Wrong in Print — and How to Avoid Them, McGraw Hill, 2000, ISBN:978-0809225354 • The Elephants of Style: A Trunkload of Tips on the Big Issues and Gray Areas of Contemporary American English, McGraw Hill, 2004, ISBN:978-0071422680 • Yes, I Could Care Less: How To Be A Language Snob Without Being A Jerk, St. Martin’s Griffin, 2014, ISBN:9781250006639 A copy editor’s responsibility starts with ensuring that if it’s “online” the first time you write it, it doesn’t become “on line” or “on-line” later in the article, newspaper or book. And that’s just where it starts. If the copy editor is the publishing world’s traffic cop, then the “style guide” is its list of laws and regulations. Readers notice things; if your spelling and word use indicates you wrote haphazardly, then your reader will read it that way. If you don’t care, why should they? Most people know that spell-check (spellcheck?) has limitations; so do all the other technology-based solutions. For reports or proposals, nothing beats a literate employee who knows how to write and cares about it — and they are made, not born. Derek Knights, CPP, CISSP, CFE CIPP/C, PCI, is the senior manager, strategic initiatives, global security and investigations, at the TD Bank Group (www.tdbank.com). @SecurityEd • November/December 2016
22 PRODUCT FOCUS VIDEO SURVEILLANCE Network camera series
Fisheye camera
Axis Communications The new AXIS M20 Series features built-in infrared (IR) illumination for video surveillance even in the dark. The cameras offer complete coverage with a wide field of view and high levels of detail with resolutions up to 4 MP. The new small bullet-style cameras are lightweight, yet durable. They can be installed in both hot and cold weather and feature an integrated sunshield for protection against sun and rain. With an integrated back box, the bullet-style cameras are easy to handle and install. The cameras provide highly detailed images and complete coverage of retail stores, offices, lobbies, libraries and hallways with a wide field of view and high resolution. www.axis.com
Avigilon The H4 Fisheye camera line is designed to provide a complete high resolution 360-degree panoramic view, eliminating blind spots. The H4 Fisheye is available in 6 and 12 megapixel camera resolutions, providing frame rates of up to 30 and 20 frames per second respectively. Available for order now, the H4 Fisheye is video analytics-ready and, in conjunction with future software upgrades, will provide immediate access to a strong video analytics patent portfolio. www.avigilon.com
Server grade NVR Milestone Systems The Milestone Husky M550A server-grade NVR delivers a guaranteed recording performance of 1400 Mb/s and unlimited external storage thanks to the use of features normally only seen in enterprise servers.The M550A NVR hardware platform with scalable VMS is scheduled for release in Q4 2016. The new model features a dual power supply for added resiliency and the use of Intel’s X550 converged network adapter. This adapter allows native 10 GbE connections to enterprise class storage from EMC, Dell and HP, as well as using iSCSI and FCoE (Fiber Channel over Ethernet). www.milestonesys.com
Enterprise solution IPVideo Corp Mosaic Enterprise caters to large-scale, single-site, multi-building applications. It supports 4K cameras, streamlines workflows and operator efficiency, and provides advanced investigative tools and sophisticated export tools to consolidate relevant video evidence. Operators’ situational awareness is enhanced through features including interactive, multi-layered maps with integrated alarm management, a camera navigator function that tracks moving objects as they move between camera views, the ability to push video from smart phones directly to the VMS interface, and “ONVIF Bridge” – a feature that allows video streams from Mosaic to be shared with 3rd party VMS systems. www.ipvideocorp.com/mosaic
Event analytics Arteco This Event Analytics platform combines the power of analytics software with intuitive video security monitoring, singling out the most relevant information in the face of a security breach. Arteco VEMS integrates and converges third-party sensors into one common platform, allowing for an interoperable system that is easy to use and provide training for operators. Event Analytics is separate tool that can be used to analyze events that are managed inside the VEMS and provide greater situational awareness to security teams. Event Analytics can also be used inside the VEMS tool itself or through any browser or mobile device. www.arteco-global.com
NVR storage servers Promise Technology Two new network video recorder (NVR) storage servers, the Vess A2330 and A3340, are now available in North America. Promise’s Vess A2330 is a 2U 6-bay NVR that offers low latency recording for entry-level deployments of up to 35 cameras per system. The Vess A3340 is a 2U 8-bay NVR designed for mid-sized surveillance deployments of up to 80 IP cameras. Promise’s line of Vess NVR appliances are purpose-built for video surveillance environments and feature a range of proprietary technologies that enable the systems to handle a high number of IP cameras. Vess NVR appliances reduce support and equipment costs as there is no separate RAID storage unit to manage. This eliminates the need for a server, controller cards, external cables, and a separate storage enclosure. www.promise.com
AD INDEX Anixter 23 www.anixter.com CANASA 10 www.securitycanadaexpo.com Commissionaires 2 www.commissionaires.ca Focus On 20 www.focusonseries.ca G4S 7 www.g4s.ca November/December 2016 • www.canadiansecuritymag.com
HID Mission 500 Paladin Salto Systems
17 www.hidglobal.com 3 www.mission500.org 12,13 www.paladinsecurity.com 24 www.saltosystems.ca
Build Electronic Access Control Solutions ASSA ABLOY and ANIXTER Provide COMPLETE Security Solutions
ENTRY CONTROL Electronic Access Control Systems, Panels, Controllers, Software
Credentials, Readers, Keypads
ACCESSORIES Switches, Brackets, Remote Switches
PATH
EXIT
Low Voltage Wire & Cable, Network Cable & Patch Cables, Wire Transfer Hinges, Door Loops
Touch Bars, Electrified Panic Devices, Request to Exit Sensors, Electrification Kits
POWER
LOCK
Plug in Transformers, Boxed & Regulated Power Suppliers, Back Up Batteries
Mag Locks, Strikes, Electrified Locks
Experience the Future of Security Distribution. Call Toll-FREE:
1-800-268-2357 www.anixter.ca
THE KEYLESS SOLUTION TO MECHANICAL KEY CONTROL Innovative technology in wire-free access control for virtually any type of door.
BATTERY OPERATED ELECTRONIC WIRE-FREE LOCKS
FLEXIBLE AND EASY TO ADAPT TO VIRTUALLY ANY TYPE OF DOORS JustIN MOBILE APP BY SALTO
Innovation keeps you one jump ahead ELECTRONIC LOCKS
AUTOMATIC DOORS
ELECTRONIC CYLINDERS
GATES
PANIC DEVICES
SALTO Systems Inc. 950 rue Valois, suite 104 Vaudreuil-Dorion, QC, Canada, J7V 8P2 Tel. 514.616.2586 Info.canada@saltosystems.com