From Response to Prevention: Security Program to Intelligence Program – Part 4

Aug 20, 2026 | Risk Management

From Response to Prevention - Part 4

From Security Program to Risk Intelligence Program

Contributed by Jim Brigham, LCG VP of Risk Management, Former Operations Chief, State of Vermont, Office of Safety and Security

Traditional security programs generally protect facilities, control access, safeguard assets, and respond when an incident occurs. A risk intelligence program has a broader mission: identify emerging concerns, evaluate information, support leadership decisions, and coordinate preventive action before threatening behavior escalates into violence or operational disruption.

During my public-sector service, I was part of a team that helped transform a statewide security operation from a largely reactive support function into a multidisciplinary risk-intelligence program.

Historically, security was commonly viewed as a building-support service. Its responsibilities included unlocking doors, managing visitors, conducting routine patrols, assisting employees, and responding to incidents. Although these functions were necessary, security was not consistently recognized as a professional investigative, intelligence, or risk-management capability.

That model also meant security was frequently brought into a situation too late. Employees reported concerns to supervisors, who elevated them through multiple levels of management. Individuals without investigative or behavioral-threat-assessment training were effectively deciding whether a concern warranted professional review. Serious warning behaviors could be minimized, while routine workplace conflicts might be escalated based on fear or perception rather than an objective risk assessment.

The transition to risk intelligence changed both the purpose of the security program and how information moved through the organization.

Removing Barriers to Reporting

A centralized safety and security reporting system allowed employees to report concerns directly without first obtaining supervisory approval. Leadership could be notified for awareness, but management could not prevent, delay, or unnecessarily filter a report before it reached trained personnel.

Direct reporting was critical because the employee with firsthand knowledge generally possesses the most accurate information. When reports pass through several people, details may be unintentionally shortened, softened, exaggerated, or interpreted. In threat assessment, even small changes can affect how people understand intent, context, credibility, and urgency.

Employees were also encouraged to report circumstances outside the workplace when those circumstances could potentially affect workplace safety. Domestic conflict, stalking, threatening communications, financial stress, or other personal matters do not always remain outside the office. Providing a trusted reporting channel allowed the organization to identify those risks and support affected employees earlier.

Turning Information into Intelligence

The organization did not treat a report merely as a complaint to be documented. It initiated a structured review conducted by trained personnel and supported by multidisciplinary resources.

Depending on the circumstances, the assessment could involve security, Human Resources, legal counsel, information technology, physical security professionals, emergency planners, law enforcement, behavioral health professionals, corrections personnel, or social service providers. Relevant information could also be shared with authorized law-enforcement intelligence partners when legally permissible and operationally necessary.

This produced an important two-way exchange. Our team could provide information about behaviors or individuals that came to the organization’s attention. At the same time, outside partners could contact us when they believed we might have relevant information about a developing concern. Each organization often held only one part of the picture. Connecting those pieces created context that no single department could develop independently.

The assessment examined the totality of the circumstances, including the person’s grievance, communications, behavior, planning, relationships, stressors, access to potential targets or weapons, and available protective factors.

The objective was not to predict violence with certainty. No responsible professional can guarantee what another person will do. The purpose was to determine whether someone appeared to be moving toward violence, identify what might accelerate or interrupt that movement, and provide leadership with a defensible course of action.

Not every threatening situation was primarily a criminal-justice problem. Housing insecurity, financial instability, family conflict, untreated behavioral-health concerns, substance use, employment disputes, or other unmet needs could contribute to a person’s desperation or grievance. Effective intervention sometimes required law enforcement, but in other cases, behavioral-health treatment, social services, legal guidance, or another form of support offered a better opportunity to reduce the risk.

Intelligence-Based Decision Support

Risk intelligence must lead to decisions. When credible information indicated an elevated concern, leadership could temporarily restrict access to a facility, enhance visitor screening, authorize remote work, coordinate with law enforcement, or implement other proportionate protective measures.

During an emerging event, decision-makers received concise briefings addressing:

  • What had been reported and independently confirmed.
  • What remained unknown or unverified.
  • The nature and immediacy of the concern.
  • Protective measures already implemented.
  • The recommended operational posture.
  • The information still being sought.

Every briefing carried an essential qualification: The assessment is based on what is known at this time.

Threat information is rarely complete at the beginning of an event. Leadership may understandably want certainty, but waiting for absolute certainty can surrender the opportunity to prevent harm. A better approach is to make a proportionate decision based on available intelligence, continue gathering information, and adjust the response as circumstances change.

Protective measures were not intended to remain in place indefinitely. The team continually reassessed the situation based on new information from appropriate authorities and partners. The team documented decisions to increase, maintain, or reduce protective measures, including the information available, its source, the professional recommendation, and the authority responsible for the final decision.

From Assessment to Prevention

The program produced far more than written reports. Threat assessments frequently exposed physical and operational vulnerabilities that might otherwise have gone unrecognized.

Findings supported improvements to access control, visitor management, surveillance coverage, emergency communications, incident command, employee notification, and facility design. In some locations, video-intercom technology allowed employees to see and communicate with visitors without leaving a protected position. Other changes reduced the unnecessary public identification of senior officials, their vehicles, and their routine locations.

Protective planning also extended beyond government facilities. Employees experiencing serious threats could receive personal safety planning, temporary workplace accommodations, and coordination with the law-enforcement agency serving their home community. When appropriate, employees also received help understanding available legal protections and support services.

In other cases, cooperation among multiple jurisdictions allowed authorities to intervene before a person of concern could reach an intended location or target. These outcomes demonstrated the value of established relationships and information-sharing before a crisis occurs.

The Cultural Transformation

The most significant result was cultural, not technological.

Employees became more willing to report concerns. Leadership involved trained personnel earlier. Security became recognized as a professional advisory and risk-management capability. Decisions increasingly relied on evaluated information rather than instinct, organizational politics, or a desire to return to normal as quickly as possible.

Training was essential to achieving that change. Employees and leaders received instruction in incident reporting, active-threat response, de-escalation, emergency medical intervention, and personal safety. Reporting data also helped justify staffing, funding, training, and facility improvements by demonstrating where risks were occurring and where resources were most needed.

As confidence in the process increased, the number of reports grew substantially. That did not necessarily mean the workplace had become more dangerous. It meant employees trusted the system and concerns that had previously remained hidden were finally becoming visible.

The fundamental transition was clear:

Traditional security protects assets and responds to incidents. Risk intelligence identifies emerging threats, connects information across organizational boundaries, supports leadership decisions, and coordinates preventive action.

Security was no longer simply the group called after something happened. It had become a professional, intelligence-led capability that helped leadership understand what might happen next and how to prevent it.

Contact LCG Discovery

Your Trusted Digital Forensics Firm

For dependable and swift digital forensics solutions, rely on LCG Discovery, the experts in the field. Contact our digital forensics firm today to discover how we can support your specific needs.