There are various forms of strategic plans depending on the needs of each organisation.
According to Louw and Venter (2009), “each organisation’s strategic approach consists partly of custom-designed actions to fit its own circumstances and industry environment, there are countless variations in the competitive strategies that organisations employ”.
These plans normally cover a long period spanning more than one year. The strategic plan provides direction to the organisation at all levels. Business and functional strategies are then derived from the main strategy and are aligned to it.
One such functional plan, which forms the basis of this article, is the security-loss control strategy. This plan is part of the board’s risk management responsibilities and in the absence of a board, top management or the entrepreneur.
The security-loss control strategy can be called by any other term but its prime purpose is to contain comprehensive plans to deal with security and loss control issues within the organisation. Security and loss control provides protection and loss prevention to the organisation’s assets. These assets are normally in the form of people, infrastructure, working capital, materials, processes, products, vehicles, revenue, profits, reputation and so on.
Some organisations may deal with the issue of security-loss control management by rule of thumb, gut feel, off the cuff and general prevailing security practices. However, security matters need not be handled in an ad hoc manner, by luck or beliefs. There is need for practicality, compliance and consistency.
Just like in any strategic management process, formulating a security-loss control strategy requires a thorough appraisal and analysis of the internal and external security environments particularly the operating environment. The security-loss control operating environment is interconnected with other functions of the organisation where assets, threats and vulnerabilities reside. It is actually a support function which cannot exist on its own in the absence of the other main business model functions, unlike in a security organisation where it is the core business.
The security-loss control strategy contains a number of elements which may include mission, pen picture, subordinate goals, objectives, core areas of protection, functional tactics, security budget priorities and performance matrix.
This plan is anchored on a thorough and detailed security risk and loss control assessment and from it follows security policies and procedures, functional security tactical requirements and security instructions.
The shortcomings for organisations that operate without a security-loss control strategy or policies and procedures are costly to contemplate. Some of them include an inaccurate security environment assessment, lack of integration and compatibility between security and other functions, absence of or an ambiguous security risk assessment process. This drives the security management function and failure to recognise or appreciate security costs during the planning process leads to ad hoc and costly security approaches.
Strategic security plans should be written in detailed security terminology, with a hybrid of alignment, compatibility, compliance, education and enforcement outlining specific roles, responsibilities and outcomes. Organisations should guard against voluminous strategy and policy documents that gather dust without being operationalised. Much of security work is mainly existential and not abstract. A security-loss control strategy and its consequent policies, procedures and security instructions must be workable and with very little room for exceptions and should be visible in the organisation’s operations.
The security plan should be outlined in both descriptive and quantitative terms aided by applicable organograms, Gantt charts, frameworks or templates. There should be a regular performance measurement and review system with appropriate criteria which acts as dipstick for security efforts and costs.
It is important however for all managers to embrace security and loss control within their interdependent functions or business units even though they may not be specialists in this field. Specialist professional security competence can be called upon at the critical stages of security strategy development, risk assessment, policies and procedures, functional tactics, security instructions, loss prevention checks and internal investigations.
Failure to appreciate and plan for the organisation’s security and loss control requirements can result in pilferage, thefts, robberies, fraud, asset- abuse and corruption some of which may never be detected through accounting and audit systems.
A security-loss control strategy therefore acts as a monitoring mechanism providing checks and balances during the course of the organisation’s operations.
The direct beneficiaries of a comprehensive and effective security-loss control plan are the shareholders, directors, management, employees, customers and other members of the supply chain. It is just part of management best practice.
- Dimax Musonza is the Managing Consultant of Checkmate Security Risk Management Consultancy.
E-mail: [email protected]



