Can security managers also be risk managers?

August 2015 Editor's Choice, Security Services & Risk Management

In the business world, security is a necessity, the infamous grudge purchase. However, as more company leaders realise the importance of protecting their businesses effectively, they realise they need more than a security manager. Today’s corporation needs a risk manager with a portfolio of responsibilities that stretch further than that of the traditional security manager.

Nico Snyman, CEO of Crest Advisory Africa explains that the job descriptions of risk and security managers clearly show there are two separate fields requiring different skills and knowledge. As South Africa (and the world in general) comes to terms with risk management in documents such as the King III report and legislation such as the Companies Act, it becomes clear that risk management is a field on its own with its own set of demands, priorities and responsibilities.

For example, the traditional security manager is responsible for three basic objectives: physical security of the premises, asset security and the protection of resources – to simplify the job. A corporate risk manager, on the other hand, needs to understand the standards governing risk that all the departments within the company must comply with.

Local and international standards

Locally, the King III report is held by all to be the leading corporate guide to good corporate governance, including risk management (chapter 4), and this is further supported by international standards, ISO 73: 2009 (Risk Management terminology & vocabulary), ISO 31000:2009 (Risk Management Guidelines and Principles) and ISO 31010:2009 (Risk Management Analysis Techniques) and most recently, ISO 9001: 2015, with an added focus area of risk management (see related article in this issue).

There are other standards too, depending on the area of business the company operates in. TAPA, for example, has a set of standards that applies to the logistics industry. The reality is risk managers need to understand these standards and apply and tailor them to their organisations.

Snyman notes this means creating the appropriate risk management frameworks, policies and measurement criteria, and then implementing policies and processes to ensure the company is compliant. The risk manager must be able to conduct risk assessments in all areas of the business, from IT to HR, and develop processes to handle the risks that occur. This requires a budget and, possibly more importantly, the authority to implement and enforce these processes in the organisation.

The different responsibilities that the security manager and the risk manager are measured on therefore means that one person can’t realistically do both jobs. That’s not to say a security manager can’t be a good risk manager, but the individual concerned needs to understand what is expected of a risk manager as well as the relevant standards without losing track of his security responsibilities.

They must also be able to effectively divide their time between the two tasks. The question is: what time is devoted to each and will the company respect that division? Will a dual-responsibility job allow the individual to pay the required attention to the 50 risk definitions in ISO 9001, or the frameworks in ISO 31000? Will he have the time to implement all these changes, down to developing and maintaining a risk register for the company?

Two in one?

Given the severity and the recent increases in crime in South Africa, the answer will most likely be no. Your security manager works a full time job and companies can’t allow them to divert their attention away from their goals. And when you consider that risk management today incorporates all aspects of the organisation, including cyber risks, your traditional security manager is unlikely to have the required skills.

In addition, the ISO standards are changing from being compliance driven to being objective driven. This will place additional responsibilities on the risk manager and require a keen understanding of the risks a company faces, as well as the development of a well-defined strategy to address them. Snyman says this will require the corporate position of a Chief Risk Officer (CRO), or someone on the board that has the authority to make and enforce decisions, something not usually associated with the security manager.

Snyman again notes that this does not exclude security managers from becoming risk managers, but he stresses that the two jobs are different, with different priorities and standards to maintain. Mixing the two distracts the responsible individual from fulfilling the demands of both and leaves the company in a vulnerable position that can potentially cost far more than the salaries of the two positions.

Nico Snyman is the Chief Executive Officer (CEO) of Crest Advisory Africa, specialising in risk management, corporate governance and advanced technologies. For more information, contact +27 (0)76 403 4307, nico@crestadvisoryafrica.com, www.crestadvisoryafrica.com





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Beyond the checkpoint
Veracitech Editor's Choice
For decades, mining corporations have treated employee screening as a necessary friction point, an operational cost to be managed rather than a strategic capability to be optimised. A new generation of full-body X-ray technology, purpose-built for the realities of high-throughput precious-metals environments, is beginning to change that calculus.

Read more...
Persistent surveillance with rapid deployment
Editor's Choice
Sky Robots has introduced an aerial drone system designed to operate as a consistent layer within security environments, addressing long-standing challenges around visibility and response across large or complex sites.

Read more...
The control room problem that nobody wants to talk about
Technews Publishing Editor's Choice
WhatsApp has become the unofficial backbone of security communications across the mining and industrial sectors, but it was never designed to be a security tool.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
The post-Q1 security checklist
Asset Management Security Services & Risk Management
By this time of year, employees have changed jobs or roles, suppliers may have changed, and devices have moved between offices, homes, and sites. This is the right time for businesses to run a practical post-Q1 security check.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Your company is already breached, you just do not know it yet
Information Security Security Services & Risk Management
Attackers are no longer relying on sophisticated exploits to break-in. Instead, they are systematically targeting weak credentials, misconfigured systems, and exposed devices stemming from preventable gaps such as identity weaknesses and poor visibility across digital environments.

Read more...
Excellerate Services sets a new standard
News & Events Security Services & Risk Management
Excellerate Services relies on specialist expertise and the sophistication of its operations deployment and management. Central to this is an investment in smarter, data-driven operations through the Velocity and Performance Centre platforms.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.