Houston
Houston Digital Forensics
Address:
9750 Tanner Rd. Houston, Texas 77041Latest Blog in The eDiscovery Zone
From Response to Prevention: Security Program to Intelligence Program – Part 4
Traditional security programs generally protect facilities, control access, safeguard assets, and respond when an incident occurs. A risk intelligence program has a broader mission: identify emerging concerns, evaluate information, support leadership decisions, and coordinate preventive action before threatening behavior escalates into violence or operational disruption.
During my public-sector service, I was part of a team that helped transform a statewide security operation from a largely reactive support function into a multidisciplinary risk-intelligence program.
Historically, security was commonly viewed as a building-support service. Its responsibilities included unlocking doors, managing visitors, conducting routine patrols, assisting employees, and responding to incidents. Although these functions were necessary, security was not consistently recognized as a professional investigative, intelligence, or risk-management capability.
That model also meant security was frequently brought into a situation too late. Employees reported concerns to supervisors, who elevated them through multiple levels of management. Individuals without investigative or behavioral-threat-assessment training were effectively deciding whether a concern warranted professional review. Serious warning behaviors could be minimized, while routine workplace conflicts might be escalated based on fear or perception rather than an objective risk assessment.
The transition to risk intelligence changed both the purpose of the security program and how information moved through the organization.
From Response to Prevention: Seeing the Whole Picture – Part 3
Turning Reports into Actionable Intelligence
When I worked for the State of Vermont, our team did not treat an SSIR submission as simply a complaint to be documented. It initiated a structured, multidisciplinary assessment. Each team member was assigned a specific role so that the available information could be collected quickly, independently verified, and evaluated within the larger context.
Depending on the circumstances and available legal authority, that work could include:
From Response to Prevention: How Modern Organizations Build Anticipatory Security – Part 2
Targeted violence rarely begins when someone produces a weapon. It is often the end of a developing process involving grievance, ideation, planning, preparation, and movement toward a target. The challenge is recognizing meaningful escalation without treating every angry comment, personal crisis, or unpopular belief as a threat.
There is no single profile of a violent actor. Behavioral threat assessment, therefore, focuses on what a person is doing—not on appearance, identity, diagnosis, political views, or personal associations. Relevant indicators may include increasing fixation, repeated boundary violations, threatening communications, target research, weapons acquisition, surveillance, sudden desperation, or statements portraying violence as necessary or inevitable. No single indicator proves intent; the concern comes from context, combinations of behavior, and escalation over time.




