Get a demo

Security Program Management Does Not Scale by Hiring

Ask a security leader at a growing company what they need and the answer is usually people. That is the honest answer. It is also the one thing the company is least likely to supply at the rate the problem arrives.

Security program management has an arithmetic problem that rarely gets said out loud. Revenue can double. Site count can double. The function adds one person, maybe two, and only after a budget cycle that runs on its own schedule. This is not a failure of persuasion by the security leader. It is what happens when one side of the equation grows with the business and the other grows by approval.

 

The Arithmetic Nobody States Plainly

A company going from twelve sites to thirty has not made its security team two and a half times busier in any linear way.

Each new site brings more than itself. It brings a landlord, a local vendor, an access system that may not match the others, a regulator with its own view, and a set of risk decisions somebody made locally before anyone at headquarters heard about them. The work does not add up site by site. It compounds through the relationships each site drags in behind it.

The function, meanwhile, goes from three people to four. One of whom is new.

A head of security at a high growth company put the position plainly: the hard part is not the money, it is getting leadership to see the risk, while the company grows faster than the team can scale.

The starting position is often worse than that. A head of physical security at a global law firm described walking into a brand-new security function with nothing but cameras and badges, and running it now across every office at a fraction of the cost of a full-time team. That is the common shape of it. One person owns security, sometimes in their first week, with no program to build on, and effort goes to what is visible rather than to what matters.

 

Why the Usual Fix Runs the Treadmill Faster

The standard response to a bigger footprint is more assessment. Bring in a partner provider, survey the new sites, produce the reports, add them to the shelf.

That approach scales in a straight line with site count. Twice the sites means twice the assessment spend, twice the documents, and the same people reading them. Nothing about it lets a fixed team cover a growing footprint.

It also produces something less useful than it looks. Each assessment arrives on its own scale, in its own format, at its own moment. Ten reports on ten sites is not a picture of a network. It is ten pictures, taken at ten different times, that cannot be laid over one another. Somebody still has to hold the whole thing in their head and work out what it adds up to. That somebody is the security leader, whose time was the scarce thing to begin with.

There is a timing problem underneath. Standing up a security program the conventional way takes twelve to eighteen months. A company opening sites every quarter has changed shape before the program is finished describing what it looked like at the start.

The Team Is Short of Hours, Not Headcount

Look at where senior security time actually goes in a growing company.

Chasing vendors for a current equipment list. Rebuilding a baseline that existed last year but is now wrong. Reformatting findings so they can sit next to each other. Assembling a board deck from six sources. Confirming whether the thing that was approved in March was ever installed.

None of that is judgment. All of it is mechanical, and it expands with the footprint whether or not anyone is hired.

Which is why headcount is the wrong frame for the problem. A larger team does more of the mechanical work. It does not produce more judgment.

The scarce thing at a growing company is not people who can gather information. It is the small number of hours belonging to the people who know what the information means. 

A larger team does more of the mechanical work. It does not produce more judgment.

 

Making One Team's Judgment Cover More Ground

If the mechanical layer is handled somewhere else, the same three people can cover thirty sites, because what they are being asked for is the part only they can do.

That takes three things:  

  • Every site has to enter a common standard rather than starting its own conversation;  

  • The current state has to update as things change rather than being rebuilt from scratch each cycle, and;

  • Everything has to be comparable in a common unit, which in practice means dollars, because that is a unit the CFO and the board already read.

Get those in place and adding a site becomes an entry rather than a project. The team does not grow. The ground it covers does. That is also much of what keeping program management in step with scale turns out to require in practice, and it is the reason a lean team can run a real program without waiting for a headcount cycle that may never come.

Holtium is the risk operating system for corporate security. It absorbs the mechanical layer, keeps every location on one dollar scale as the footprint changes, and turns the result into the reporting leadership already reads, so security program management stops being limited by how many people you were allowed to hire this year.

 

Back to All Holtium Insights