Nate’s Notes
Sorry for the missing newsletter last week! I was on vacation and apparently my fat finger hit the 3 instead of the 2 when I scheduled it before I left.
I’m pleased to announce that you will not have to wait until August 25, 2036 to read it.
Sigh… It’s gonna be a long week.
Most security dashboards can only report the past
IAHSS Guideline 01.05.03 is called Security Metrics, and it is the closest thing healthcare security has to a field standard for what a program ought to be counting. It was revised this year. Response time is still in it, and so are incident volume, loss figures, and the rest of the familiar set.
None of those numbers is wrong. The problem is that every one of them describes something that has already finished happening, and a dashboard built entirely out of them can only ever report the past. That's why the executive conversation goes badly. It's a timing problem, not a vocabulary one.
Direct, indirect, lagging
Take the dashboard you actually brief from and put each number into one of three buckets.
Direct. What is true right now. Current staffing posture, open incident count, queue depth, systems up or down.
Indirect. What is going to happen, showing up hours or days before it lands. Overtime trend, how often the shift runs at minimum staffing, drill readiness, how long since a post was rotated.
Lagging. What already finished. Average response time, incidents per quarter, downtime totals, dollars lost.
Most security dashboards are almost entirely lagging, with a couple of direct numbers borrowed off a monitoring screen and nothing at all in the middle. That gap describes what the program can do, not what it prefers to report. Measure only finished events and you can explain them without ever getting ahead of them. The middle column is the only one that looks forward.
The three categories sort by who is looking, too. The GSOC runs on direct. The question at the console is what to do in the next few minutes, so a screen showing last month's totals is no help to anybody working a shift. What helps is sortable and readable at a glance. Operations leaders run on indirect, in days and weeks, watching for what is about to break. Lagging is what gets carried to senior leaders, because they answer for what already happened and what it cost.
That is what an empty middle column actually costs. Operations leaders end up working off the same finished numbers as the board, and nothing but the past ever reaches the top.
Who reads it | Horizon | The question | |
|---|---|---|---|
Direct | GSOC console | Right now | What do I do in the next few minutes |
Indirect | Operations leaders | Days to weeks | What is about to break |
Lagging | Senior leaders | Last quarter and back | What did it cost |
The quarterly review
A security director walks into a quarterly review with response times and incident counts. Somebody asks what the operational risk posture looks like right now, or what is likely to break before the next review. Nobody has an answer, and it isn't for lack of data. Overtime sits in the payroll system, minimum-staffing shifts in the schedule, rotation slippage in the post logs. None of it was ever pulled into the dashboard, because the dashboard was built to report performance rather than to predict it.
The executive isn't asking a security question. It's the same one they put to finance and operations, which is what's coming and what can be done about it now. Every other function in the building answers that with leading indicators. Security shows up with a scorecard.
Start with task saturation
The best indirect metric a security operation has is how loaded its people are, and it's the one the field is least comfortable measuring.
An ASIS Human Threat Management Community webinar made the case this spring. Cognitive overload is predictable and preventable, and task-saturated workers are dangerous to the operation. Dr. Jill Frack, presenting on that program, put it in four words. Burnout is a systems problem. The term task saturation comes out of aviation and military human factors, where the logic is the same.
Saturation shows up before the error it produces, which is what makes it a leading indicator. You can see it in overtime hours, consecutive shifts, how many alarms one operator is holding, how far into a shift the errors start. All of that is recorded somewhere in the building already, and almost none of it reaches the dashboard.
The culture makes it worse. A program that treats voluntary overwork as dedication is reading its clearest leading indicator as good news.
What you actually say
Sorted by timing, each category answers a different question. The direct numbers say what is happening right now, how many incidents are open and what each one costs an hour to run. The indirect ones say what is coming, which shows up as an overtime trend and as errors clustering at a predictable point in a twelve-hour shift. Lagging says what it cost, recovery time on the last disruption against the same event a year earlier.
Same program, same data, three different conversations.
What 01.05.03 leaves out
A dashboard is built out of whatever generates it, and every system in the building reports its own narrow slice. Somebody has to decide which of those numbers matters, to which executive, and where it falls on the timing scale. That happens before any of it reaches a screen.
IAHSS 01.05.03 tells a healthcare security program that it should have metrics. It does not tell anybody how to convert them into a sentence a CFO can act on. That gap is where the field currently is.
Touring
Keep your own fix-it list
A burned out light in the far corner of the lot gets flagged to facilities in the ticketing system, and then it isn't security's problem anymore. That's how it's supposed to work.
Then somebody goes down out there, and the only defense security has is that we told facilities about it a month ago. That invites the next question. Did anybody follow up?
A fix-it list is the department's own copy of what it already knows is wrong. Each line says what the condition is, when it was first seen, who it went to, and where it stands now. It doesn't replace the ticketing system and there's no reason to stop using that. It just means security isn't relying on somebody else's queue to show it was paying attention.
The whole cost is a spreadsheet and a habit at shift change.
The number worth watching is how many items are older than 90 days. When those pile up it's usually a ticket that got opened and then nothing. Lines that name a person instead of a department hold up better too, because somebody can be asked what they did about it.
SigInt - Monthly feature
Three August numbers that count something else
The NRF and the LPRC reported that shoplifting fell 12.4% last year. The same report says 63% of retailers send fewer than half their incidents to police. Both numbers are in there. One of them got quoted everywhere.
That's the August pattern, and it showed up three times in three different corners of the industry.
Retail
The 12.4% counts police reports. The 63% says most incidents never become one. A drop in reports fits a drop in theft, and it fits retailers giving up on reporting, and the survey can't separate them. Cite the decline as a crime trend and what you're citing is a reporting trend.
Integration
SDM's 2026 Top Systems Integrators report put North American integration revenue at $9.72 billion for 2025, up 15%, on 263,333 new systems started against 300,667 the year before. More revenue on fewer starts. The easy read is that jobs got bigger, which fits the four integrator acquisitions that closed in five days at the start of the month.
SDM defines the revenue line carefully and never defines a new system started. A national account rolling out forty sites under one contract can book as one. If that's happening more often, the ratio is measuring consolidation as much as job size, and there's no way to tell from the report. Headcount and business locations dropped too, though the list itself moved, with two large integrators sitting the survey out and eighteen new or returning firms coming in.
Kidnapping
Control Risks counted 154% more mass kidnappings in 2025 than in 2020, and 60% more kidnapping events overall. They say in their own material that kidnapping is underreported.
So the figure counts recorded events. Recorded events move with reporting and collection as much as with activity, which means the number goes up when things get worse and also when somebody starts counting more carefully. The coverage runs percentages without base counts, and mass kidnapping is small enough that 154% could be thirty more incidents or three thousand.
What they have in common
All three published a number their data can't carry. Retail crime figures are counting reporting decisions, the revenue-per-system ratio is counting a unit nobody defined, and the kidnapping numbers are counting what reached a private firm.
They aren't one phenomenon, and it would be tidier if they were. A retailer who doesn't call the police made a decision, usually about time and whether anything would come of it. SDM has a definitional hole in a voluntary trade survey. Kidnapping is underreported everywhere no matter who is doing the counting.
What they share is smaller than that. In each case the number that circulates is a stand-in for something harder to collect, and by the time it gets quoted nobody says so. None of the three reports hid any of it. The 63% is printed right alongside the 12.4%, SDM publishes its methodology, and Control Risks says outright that kidnapping is underreported.
None of that happens in the report. It happens in the citing.
Passdown
dictated by Ricky Portezzo, Senior Security Supervisor in Center City, Philadelphia
Slow night. Wrote up the ice machine again, that's four times now.
Mikey wants a running list of everything we already know is broke, separate from incident reports. I told him we write things up. He said write them down anyway, which is the kind of sentence that ends a conversation.
So now there's a form on the tablet that dumps into a spreadsheet, and it emails you if something sits open too long. Mikey says it took him a couple days to build and he'd do it again. First thing on it was the loading dock light, out since June, told Donna on the 14th.
Then a driver went down on the ramp last week and his company came at us about the lighting. Corporate wanted to know what we knew and when.
Donna, June 14. Took four seconds to find and nobody asked me anything else. Would have gone different if all I had was me being pretty sure I told somebody.
List is up to 31 now, which I don't love, and 9 of them are older than 90 days, which I love a lot less. Half this building is running on a work order nobody ever closed.
Ice machine is number 32.
A ticket is not a follow up. Keep your own list with SCC Spectrum Security Almanacs.
SCC Spectrum Security Almanacs. www.gsoc911.com/products