Most organizations hire security leadership after something happens. A workplace violence incident, a lawsuit, a break-in that the cameras recorded and nobody watched, an insurer or a major customer asking questions the organization cannot answer. The hire gets made in a hurry, under pressure, with the incident still in the room. It works out sometimes. It would have worked out better a year earlier.

This article is about recognizing the moment before the incident. The signs are usually visible for a long time. The problem is that they are spread across departments, and nobody is standing where all of them can be seen at once.

Nobody Can Answer the Ownership Question

Ask your leadership team who is responsible for security across the organization and listen to the pause. If the answer is a list of names, each responsible for a piece, you do not have security leadership. You have security tasks distributed among people who were hired for other jobs. Facilities has the locks. IT has the badge server. HR has the threats. The guard company has the lobby. Each of them will tell you honestly that they are handling their part, and none of them can tell you whether the parts fit together. That pause is the first and most reliable sign.

Spending Is Reactive

Look at how the last three security purchases were decided. If each one followed a complaint, an incident, or a vendor presentation, spending is being driven by whoever got leadership’s attention most recently rather than by any assessment of where the risk actually sits. Organizations in this state tend to own a great deal of technology that does not talk to itself, a guard contract that was never renegotiated, and a set of policies written by whoever was available at the time. None of it is wrong exactly. None of it was chosen on purpose.

The Program Has Never Been Tested

If nobody can tell you the last time someone verified that the alarm signal reaches a person who will respond, that the access list matches the people who should be on it, or that the incident plan works when the people named in it actually try to run it, then your security is assumed rather than known. Assumption is comfortable right up until the moment it is tested by someone other than you. I have spent much of my career looking at the aftermath of that moment, and the recurring finding is that the failure was visible in advance to anyone who had gone looking.

Someone Outside Is Asking

A growing number of organizations reach for security leadership because an outside party required it. The insurance renewal comes with a questionnaire nobody can complete. A large customer’s vendor security review asks for the name of your security director and the date of your last assessment. A regulator or accrediting body wants documentation. A board member with a background in risk asks a question at a meeting and the room goes quiet. These are not embarrassments so much as gifts, because they give leadership a concrete reason to fund the role before an incident supplies a worse one.

Growth Has Outrun the Arrangement

The security arrangements that worked at one site and eighty employees do not scale to four sites and five hundred. A second location, an acquisition, a move into a new building, a shift to a public-facing operation, or a change in what the organization handles, whether that is patients, data, cash, or hazardous materials, each changes the risk profile in ways the old arrangement cannot see. If the organization has grown meaningfully and security has not been rethought since, the gap is already open.

Why Fractional Rather Than Full-Time

At the moment these signs appear, most organizations cannot justify a full-time director and should not try to. The volume of director-level work is real but not yet continuous, the program does not yet exist for a full-time hire to run, and the budget conversation will stall on the number. A fractional security director fits that moment precisely. The organization gets an experienced leader who owns the program, builds the foundation, and demonstrates the value, on a retainer the budget can absorb. If the organization later grows into a full-time seat, the fractional director has usually written the job description and built the program the new hire inherits.

The Cost of Waiting

Waiting feels free because the cost has not arrived yet. It arrives as a guard contract that has quietly overcharged for years, as a settlement in a negligent security claim, as a workplace violence incident that a threat assessment process would have caught, as a customer lost to a security review that could not be passed, or as an insurance premium that reflects an unmanaged risk. Any one of those typically costs more than several years of a fractional retainer. The organizations that come out well are the ones that hired the leader while the signs were still just signs.

Go Deeper

If several of these signs describe your organization, start with What Is a Fractional Security Director? The Complete Guide. My book Fractional Security Director walks executives and boards through recognizing the gap, choosing the right model, and building a program that can be tested rather than assumed.

Commissioner William Epps is an author and security leadership consultant. His books are published through E.P.P.S. Method Publishing Co.

Leave a comment

Get the Book

The ultimate guide for creators: strategies, stories, and tools to help you grow your craft.

Be Part of the Movement

Every week, Jordan shares new tools, fresh perspectives, and creator spotlights—straight to your inbox.

← Back

Thank you for your response. ✨

Creator Rising: A Playbook for a Meaningful Creative Life is your guide to building
not only income, but a creative life
worth living.

Inside you’ll find systems for sharing your work, habits that fuel inspiration, and ways to grow without losing
the spark that makes you create in the first place.