Can security managers also be risk managers?

August 2015 Editor's Choice, Security Services & Risk Management

In the business world, security is a necessity, the infamous grudge purchase. However, as more company leaders realise the importance of protecting their businesses effectively, they realise they need more than a security manager. Today’s corporation needs a risk manager with a portfolio of responsibilities that stretch further than that of the traditional security manager.

Nico Snyman, CEO of Crest Advisory Africa explains that the job descriptions of risk and security managers clearly show there are two separate fields requiring different skills and knowledge. As South Africa (and the world in general) comes to terms with risk management in documents such as the King III report and legislation such as the Companies Act, it becomes clear that risk management is a field on its own with its own set of demands, priorities and responsibilities.

For example, the traditional security manager is responsible for three basic objectives: physical security of the premises, asset security and the protection of resources – to simplify the job. A corporate risk manager, on the other hand, needs to understand the standards governing risk that all the departments within the company must comply with.

Local and international standards

Locally, the King III report is held by all to be the leading corporate guide to good corporate governance, including risk management (chapter 4), and this is further supported by international standards, ISO 73: 2009 (Risk Management terminology & vocabulary), ISO 31000:2009 (Risk Management Guidelines and Principles) and ISO 31010:2009 (Risk Management Analysis Techniques) and most recently, ISO 9001: 2015, with an added focus area of risk management (see related article in this issue).

There are other standards too, depending on the area of business the company operates in. TAPA, for example, has a set of standards that applies to the logistics industry. The reality is risk managers need to understand these standards and apply and tailor them to their organisations.

Snyman notes this means creating the appropriate risk management frameworks, policies and measurement criteria, and then implementing policies and processes to ensure the company is compliant. The risk manager must be able to conduct risk assessments in all areas of the business, from IT to HR, and develop processes to handle the risks that occur. This requires a budget and, possibly more importantly, the authority to implement and enforce these processes in the organisation.

The different responsibilities that the security manager and the risk manager are measured on therefore means that one person can’t realistically do both jobs. That’s not to say a security manager can’t be a good risk manager, but the individual concerned needs to understand what is expected of a risk manager as well as the relevant standards without losing track of his security responsibilities.

They must also be able to effectively divide their time between the two tasks. The question is: what time is devoted to each and will the company respect that division? Will a dual-responsibility job allow the individual to pay the required attention to the 50 risk definitions in ISO 9001, or the frameworks in ISO 31000? Will he have the time to implement all these changes, down to developing and maintaining a risk register for the company?

Two in one?

Given the severity and the recent increases in crime in South Africa, the answer will most likely be no. Your security manager works a full time job and companies can’t allow them to divert their attention away from their goals. And when you consider that risk management today incorporates all aspects of the organisation, including cyber risks, your traditional security manager is unlikely to have the required skills.

In addition, the ISO standards are changing from being compliance driven to being objective driven. This will place additional responsibilities on the risk manager and require a keen understanding of the risks a company faces, as well as the development of a well-defined strategy to address them. Snyman says this will require the corporate position of a Chief Risk Officer (CRO), or someone on the board that has the authority to make and enforce decisions, something not usually associated with the security manager.

Snyman again notes that this does not exclude security managers from becoming risk managers, but he stresses that the two jobs are different, with different priorities and standards to maintain. Mixing the two distracts the responsible individual from fulfilling the demands of both and leaves the company in a vulnerable position that can potentially cost far more than the salaries of the two positions.

Nico Snyman is the Chief Executive Officer (CEO) of Crest Advisory Africa, specialising in risk management, corporate governance and advanced technologies. For more information, contact +27 (0)76 403 4307,,

Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Social media and intelligence-led surveillance
July 2019, Leaderware , Editor's Choice, Integrated Solutions, Security Services & Risk Management
Social media has become a major feature of most people’s lives in the last few years and they can be invaluable as a source of information for companies and security organisations.

The 4th Industrial Revolution
July 2019, Wolfpack Information Risk , Editor's Choice, Cyber Security, Security Services & Risk Management, Industrial (Industry)
Most major industries have turned to and are reliant on technology to run their operations. This is a time of great promise, but also one of frightening peril.

Data protection more challenging
July 2019 , Editor's Choice, IT infrastructure
The number of businesses unable to recover data after an incident nearly doubled from 2016, according to the Global Data Protection Index surveying 2 200 IT decision makers from 18 countries.

Cyber-attacks target operational technology
July 2019 , Editor's Choice, Cyber Security, Industrial (Industry)
Focus on operational technology security increasing as around 74% of OT organisations come under attack in the past year, finds a new Fortinet report.

Fear of the unknown
July 2019, Kaspersky Lab , Cyber Security, Security Services & Risk Management
Fear of the unknown: while there’s still interest in cryptocurrencies, just 19% locally understand how they work.

Ingo Mutinelli moves to IDEMIA
July 2019, Technews Publishing, IDEMIA , Editor's Choice, News
IDEMIA, the security and identity management company has announced that Ingo Mutinelli will be taking on the post of regional sales director for the southern Africa region.

Residential Estate Security Conference 2019: Integrating man and machine for effective security and operations
July 2019, Technews Publishing , Editor's Choice, News, Residential Estate (Industry), Conferences & Events
The Residential Estate Security Conference 2019 will delve into how estates and their service providers can better integrate man and machine for more effective security and operations.

Milestone appoints new VP for research and development
July 2019, Milestone Systems , Editor's Choice, CCTV, Surveillance & Remote Monitoring, News
Milestone Systems has appointed Tom Bjerre as its new VP for research and development. He will oversee planning, development, testing and release of Milestone Systems’ video management software.

Johnson Controls launches Technology Contracting in Africa
July 2019, Johnson Controls , Editor's Choice, News, Security Services & Risk Management
To address the growing challenge of planning, integrating and maintaining a multitude of different, highly connected systems, Johnson Controls is launching Technology Contracting in Africa.

A new method for data destruction
July 2019 , News, Security Services & Risk Management
Xperien is now able to professionally erase data on retired IT assets in compliance with the Protection of Personal Information Act (PoPIA).