One in four companies expects some form of terrorism, says RAND research

April 23, 2003—FMs considering or already managing a business continuity plan may be interested in a new survey revealing the attitudes of security and risk managers at 50 major corporations. According to research just released by think-tank RAND Europe and The Risk Advisory Group, a European corporate investigations and intelligence consultancy:

  • One in four companies (26 per cent) expect to experience some form of terrorist attack over the next two years;
  • One in ten businesses (10 per cent) believe it is “extremely likely” they will face at least one instance of terrorism;
  • Sixty-three per cent of respondents believe terrorism is now a “significant threat” to their organizations, with three out of four (74 per cent) believing that this threat will increase over the next 24 months.
  • Twenty-four per cent believe it is likely their organizations will be deliberately targeted by terrorists – and half of companies believe terrorism is now a more serious threat than crime or fraud.
  • Almost four in ten (38 per cent) think conventional weapons are the most likely tactic to be used by terrorists, but cyber-terrorism (32 per cent), chemical or biological attacks (18 per cent), and radiological or nuclear terrorism (12 per cent) are also seen as likely tactics.

Yet the research revealed that many businesses still have gaps in their security management processes:

  • One in seven (14 per cent) give no security awareness training to their staff; one in six (16 per cent) have no travel security programs or systems in place; and almost one in five (18 per cent) do not screen their employees before hiring.
  • Senior executives seem to be a particular target, with only 54 per cent of companies having some form of close protection in place for their senior managers.
  • And one in seven companies (14 per cent) have not undertaken any form of security surveys, audits, or penetration testing to check systems.

The research results were released to delegates at “Behind the lines: terrorism risk and the private sector,” a TRAG-sponsored conference held recently in London. David Claridge, head of TRAG’s security risk management arm, noted that as governments have been responding more effectively to the threat of terrorism, terrorists have begun to focus on “softer” targets, particularly economic ones, including businesses, banks and financial institutions, multinational “icon” brands, and the travel industry.

TRAG also announced a new “Red Team” threat assessment and security testing service at the conference. Under Red Team testing, a team of expert security and terrorism experts takes on the role of a hostile “enemy” to test a corporation’s security measures. The team conducts threat modeling, hostile surveys of the company’s physical environments, and penetration testing exercises—getting “hostiles” into positions in which, if they were real terrorists or criminals, they could cause significant damage to the organization.

David Claridge reported, “In the last year, we have conducted 18 ‘hostile’ penetration tests against major corporations. In every single case, we have succeeded in getting team members into positions in which they could have caused severe criminal or terrorist damage to the company concerned—whether it be ‘secure’ data centers, bank vaults, or manufacturing facilities.”

Topics

Share this article

LinkedIn
Instagram Threads
FM Link logo