Proficient operational security management

September 2019 Security Services & Risk Management

The quest to establish an organised and integrated security operations programme based on a Plan-Do-Check-Act (PDCA) cycle for continuous improvement is paramount for a successful security operation. A PDCA framework establishes efficiency, implementation, monitoring, reviewing and improvement and is critical, whether you are in the security service sector, an in-house practitioner or need comfort that your service partner is performing to agreed standards.

The security operations programme is an ongoing governance process, supported by top management and resourced to ensure the necessary steps are taken for a successful security programme. To this end, security managers should analyse critically what the key contributory factors are to the core business which they protect. This will clarify their role to ensure that the business objectives are achieved.

Once this process is complete, the first critical success area (CSA), namely ‘leadership’, can be established. This CSA will define the security strategy, policy, code of conduct and mission.

The second CSA is ‘people’. The security function can never be successful without competent and willing teams. The direction of the team is entrenched through clearly defined objectives. At this point of designing the programme, the notion and structure of your human resources must follow strategy to provide a clear picture of how the team should be comprised. A host of subset elements provide further criteria for this CSA.

The third CSA is ‘operations’. This is the heartbeat of the integrated programme. Every sub-category is actively involved with the proactive approach to risk mitigation, prevention of crime and ultimately the protection of assets.

‘Assurance’ and ‘quality’ make up the fourth leg in this process. Too often, good procedures, processes and other control parameters are implemented; however, the wheel of surety is not complete unless the processes have been subjected to oversight inspections and audits to establish the real value addition to the organisation, and consequently the success of the programme as a whole.

The fifth CSA is ‘technology’ in various forms and is in demand in modern security. This is crucial, especially if the planned programme demands proactive measures for crime prevention. However, the primary measurements from such systems must not only satisfy proactive measures, but also demonstrate the ability to report leading indicators rather than lagging these indicators.

In the world of the security owner, manager or advisor, the ability to provide security services not exceeding budgeted costs is key for success. The sixth CSA therefore addresses ‘costs’. Regular Lean Six Sigma approaches to all security processes identify the main elements of waste. This is coupled with key expenditure to ensure ALARP (as low as reasonably practicable) spend is achieved.

Finally, the seventh and equally crucial CSA is ‘investigation’ and ‘surveillance’. This area in the programme provides constant information for key decision makers to decide the proactive direction of the programme. This includes control room management as well as the direction and command of frontline offices.

Each CSA should be equipped with a primary metric for performance management; each metric is then measured and performance compliance discussed.

An integrated security management programme should be seen as a process of continuous improvement. The owners, management and leaders should constantly review the efficiency of the programme and make adjustments suitable to their business objectives and needs.

For more information contact Kevin van Zyl, Horizon Risk Solutions, +27 76 801 5639, kevin@horizonrisk.co.za

Kevin van Zyl.
Kevin van Zyl.

Kevin van Zyl is the managing director of Horizon Risk Solutions. He has been successful in the implementation of a programme based on the above principles since 2013. The programme has made positive change to management teams as well as the greater security operation, ultimately contributing to the success of the core business.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
The post-Q1 security checklist
Asset Management Security Services & Risk Management
By this time of year, employees have changed jobs or roles, suppliers may have changed, and devices have moved between offices, homes, and sites. This is the right time for businesses to run a practical post-Q1 security check.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Your company is already breached, you just do not know it yet
Information Security Security Services & Risk Management
Attackers are no longer relying on sophisticated exploits to break-in. Instead, they are systematically targeting weak credentials, misconfigured systems, and exposed devices stemming from preventable gaps such as identity weaknesses and poor visibility across digital environments.

Read more...
Excellerate Services sets a new standard
News & Events Security Services & Risk Management
Excellerate Services relies on specialist expertise and the sophistication of its operations deployment and management. Central to this is an investment in smarter, data-driven operations through the Velocity and Performance Centre platforms.

Read more...
957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...
The security debt hidden in residential estates
Security Services & Risk Management Integrated Solutions Residential Estate (Industry)
Many residential estates undermine their own security not through a lack of technology, but through hidden weaknesses in gate design, fragmented systems, recurring software dependence, weak operational ownership, and insufficient estate management input.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.