Rethinking commercial operational security risk

eventuality occurring and its resultant consequences on our expectations, in the event that it does occur.
In situations with cost or loss implications, the benefits of engaging in a commercial activity may not materialise.

Risk is normally associated with loss of monetary value, loss of life, injury to people or damage to property.
Risk is a term which can be described in various forms.
The Bank of International Settlements Basel Committee in 1999 defined operational risk as, “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events”.

In business management in general, there are several forms of risk and one such area, which merits attention, is “security risk”.
The predominant mindset or preferred perspective in security risk management is premised on physical protection to prevent theft.
Common aspects of physical security include access control, buildings, perimeter fences, walls, gates, doors, electronic security gadgets, safes and some such other visible and tangible security features.

Physical security is an unavoidable essential security risk control requirement in both residential and commercial setups.
Commercial operations are based on a business model which follow an inputprocessing – output architecture.
A commercial enterprise is characterised by movement of materials, semi-finished goods, finished products, people and revenue.

Business functions, activities and transactions are driven and co-ordinated by information, which can be either verbal, manual or electronic.
The prime purpose is to achieve the mission and objectives of the organisation.
This explanation is important in order to understand the place and value of security risk in commercial operations.

It is understandable that security risks do reside in operating system structures.
These security risks mainly include loss due to criminal conduct such as theft, fraud and corruption just to mention the main ones among a host of unlawful acts meant to derive gain or benefit.
However, in some situations mere negligence may constitute a commercial security risk which may result in loss or damage to goods.
An example would be a driver of a vehicle who overturns with a consignment of goods due to his negligence, injuring or causing death to people as well as damage to the goods in transit.

Numerous cases of security breaches, which cause leakages in commercial operations, are brought out in the media and several forums.
The contemporary business environment is characterised by rapid, revolutionary, discontinuous changes and intense competition associated with changes in information systems and technology, transportation, work methods and human behaviour.
These variables are indicative of the fact that security risk management should also be dynamic if control measures are to be effective.

This demands the integration and synergistic alignment of security risk management within the functions of the business’s value and supply chain.
Integrated operational security risk management is knowledge based and it encompasses work processes, information systems and physical protection.
There is need to differentiate security management from the provision of security services.

Not many organisations have a formal component of security management though, of course, they have security functions or activities as support to operations, for protection purposes.
It may, of course, not be necessary to have a formal security management function. However, in some
medium and large corporate enterprises where there is voluminous movement and consequent exposure, the practice of security risk management is a necessity to safeguard operations.

Security management actually entails the decisions to ensure the provision of security services and procedures or the transfer of risk through insurance arrangements.
Formal security risk management requires a systematic process which involves a critical, rigorous, ruthless, detailed analysis and evaluation of interconnected variables as well examination and recognition of constraining factors.

The main activities in the process are asset or process identification, threat, vulnerability and impact assessment which is then followed by solutions to deal with the exposure and probability levels.
In a security risk design model, it is important to pay particular attention to costs and practicality.

Recommended solutions should be feasible, desirable and appropriate to reduce or eliminate the identified risks.
In commercial operations the threats are mostly in the form of theft, fraud and corruption but for them to be realised certain vulnerabilities have to be exploited within the input processing output functionality.

There are different operating system structures in commercial operations. The form and scope of the operating system structure determines the breadth and depth of the security set up.
Threats may easily be profiled but vulnerabilities and the requisite solutions can be challenging and daunting hence the need for practical defence in-depth knowledge and experience in security risk modelling.

A few examples of vulnerabilities which may fall outside the scope of physical security include but not limited to, absence of written or unwritten operating procedures, ineffective off the shelf logistic or transaction processing IT system, intermittent IT system offline with porous manual procedures and absence of data recovery system or business resumption. Others include the absence of or lax management decision structures, incompetent or poorly trained staff, inconsistent human resource system procedures, dishonesty or high propensity to steal among employees, connivance among

staff, security, customers and other members along the supply chain.

Operations susceptible to leakages related to security risk and with considerable frequency include manufacturing, processing and storage plants, mining, agriculture, procurement, transport, warehouses, retail outlets, point of sale and cash handling systems.
Security risk management in commercial entities encompasses and superintends the design, development and provision of security services and equipment including IT security systems.

Some of its critical tasks include security risk assessment, security strategy development, security supplier selection and evaluation, strategic security cost management, training and measuring the performance of security efforts.

In conclusion, integrated, compatibly aligned and dynamic security risk systems are embedded in commercial operating system structures and they provide prevention, detection and recovery.
Such system solutions operate at all levels of the organisation, are periodically reviewed and enable the organisation’s mission and objectives to be achieved.

But, of course, there is always residual risk which should be tolerated, the levels of which should be clearly identified.

  • Dimax Musonza is a commercial security risk consultant and has written this article in his personal capacity. Email [email protected]

Related Posts

Economy: Growth signs visible

Martin Kadzere Senior Business Reporter ZIMBABWE has made significant progress towards achieving upper-middle-income status, with the country’s Gross National Income per capita growing by 84 percent since 2021, Finance, Economic…

Gold to shield Zim from Middle East conflict fallout: AfDB

Africa Moyo Deputy National Editor ZIMBABWE’S strong gold sector and broad resource base are expected to cushion the economy against the economic fallout from the escalating conflict in the Middle…

Leave a Reply

Your email address will not be published. Required fields are marked *

×