Skip to content

Illustration by iStock; Security Management

How to Move Your Organization Out of the Wait-and-Document Trap

A manager comes to you with a concern about an employee. Something feels off. The employee has become withdrawn, made a few comments that did not sit right, and seems to be escalating in ways that are hard to articulate. The manager cannot point to a policy violation. There is nothing concrete. Nothing actionable.

You do what you have been trained to do. You tell the manager to document it. Keep an eye on it. Come back if something else happens.

Something else happens. By then the window has closed.

Every security professional knows this pattern. Most have lived it. And the instinct that produced it—wait for more information before acting—is not negligence. It is exactly what our training, our legal counsel, and our institutional culture have taught us to do. That instinct is the problem.

Why We Wait

The wait-and-document reflex feels responsible because it is defensible. Acting on incomplete information carries risk. If you intervene and you are wrong, there are consequences. If you wait until a threshold is crossed, your action is justified by clear evidence. The organization rewards the leader who acts on certainty and penalizes the one who acts on instinct and gets it wrong. So, we wait, we document, we build the file, and we tell ourselves we are being prudent.

The research on targeted violence tells a different story. The U.S. Secret Service National Threat Assessment Center has consistently found that in most incidents of targeted violence, people around the attacker observed concerning behavior beforehand. The signals existed. The information was available. The FBI describes the pathway to violence as a process, not an event. It unfolds over time, and it is observable.

The problem is not that we fail to see the signs. The problem is that our entire operational posture is built to wait until those signs become undeniable. And by the time they are undeniable, prevention is no longer possible. What remains is response.

Here is the uncomfortable truth for the security profession. We have built sophisticated response capability and called it preparedness. Response matters. It will always matter. But response begins at the moment prevention ends, and most organizations have invested almost nothing in the window before that moment. Moving out of the wait-and-document trap is not about better documentation. It is about three operational shifts that any organization can begin making immediately.


Response begins at the moment prevention ends, and most organizations have invested almost nothing in the window before that moment.


Shift One: Give Prevention an Owner

In most organizations, response has a clear owner. Someone is accountable for the emergency plan, the drills, the incident command structure. Prevention has no owner. It is assumed to be everyone's job, which means it is no one's job.

The first operational move is to assign ownership of prevention to a single executive. Not the security director alone, not HR alone, not legal—it must be a C-level leader with cross-functional authority who can make decisions that cross departmental boundaries, because prevention information does not respect organizational charts. A signal might surface in HR, connect to something facilities noticed, and require action that involves legal and security simultaneously.

The executive who is the prevention owner is accountable for the conditions that determine whether early signals are noticed, reported, and acted upon. The prevention owner is not responsible for the response to incidents but for the window before them. Without a named owner, prevention remains a value everyone endorses and no one is responsible for.

Shift Two: Change the Language

The language we use when a concern is raised determines whether people keep bringing concerns forward. Most organizations have trained their people, often unintentionally, to expect a demand for proof.

When someone raises an ambiguous concern, the reflexive response is some version of: Do you have documentation? Can you be more specific? We need more information before we can act. Each of those responses, however reasonable they sound, teaches employees that their observation is not credible until it meets a standard they are not equipped to meet. They learn to stay quiet until they are certain. And certainty, in the context of prevention, usually arrives too late.

The shift is from demanding proof to seeking understanding. The responses change: Tell me more. What else have you noticed? Who else may have seen or heard something?

These questions accomplish something that the demand for proof does not. They keep the person talking. They signal that incomplete information is welcome. They open the door to the additional detail that often makes the difference between a vague worry and an actionable picture. And they communicate that the organization values early observation rather than punishing it.

This is not a script; it is a posture. It has to be modeled by leadership consistently until it becomes the organizational default. When the person who raises an ambiguous concern is met with genuine curiosity rather than a request for evidence, they come back the next time they have a security concern. When they are met with a demand for proof, they do not.


Without a named owner, prevention remains a value everyone endorses and no one is responsible for.


Shift Three: Have the Liability Conversation Before You Need It

Most security professionals operate under an assumption about liability that has never been tested against current case law. This assumption is that acting on incomplete information creates exposure, so waiting is the safer legal position. That assumption is increasingly wrong.

Negligent security law, a well-established branch of premises liability, holds that when an organization knew or should have known about a foreseeable risk and failed to take reasonable steps to address it, it can be held liable for the harm that follows. Courts increasingly examine what an organization did before an incident, not only how it responded during one. Recent verdicts in these cases have reached into the tens of millions of dollars.

An organization that can demonstrate a functioning prevention posture, a named owner, a culture of early reporting, and documented early engagement is in a materially different legal position than one that can demonstrate only that it waited for certainty.

The operational move is to sit down with your legal team before an incident, not after, and ask three questions.

  • What is our liability exposure if a preventable incident occurs and it can be shown that signals existed and were not acted upon?

  • What is our exposure if we have a documented prevention framework demonstrating reasonable care?

  • What recent case law is relevant to our duty to act on knowable risk?

This conversation reframes prevention from a soft value into a risk management imperative. It also gives the security professional the institutional backing to act earlier, because legal has now articulated the cost of waiting—rather than only the cost of acting.

The Cultural Shift Underneath All Three

These three shifts hold only if the culture underneath them changes. Most reporting cultures are built on fear. People report because they are worried about what happens if they do not. Fear-based reporting is reluctant, inconsistent, and easily discouraged.

The organizations that work the space before crisis successfully build reporting cultures based on care. People bring concerns forward because they care about the person they are worried about and the people around them. Care-based reporting is persistent and specific because the motivation is relational, not self-protective. Building it requires leadership to consistently demonstrate that a concern raised in good faith is met with care, followed through on, and never punished, whether it turns out to be something or nothing.

What Monday Looks Like

You will not rebuild your organization’s prevention posture in a week. But you can begin immediately. Name the executive who owns prevention. Change the first question you ask when someone raises a concern. Schedule the conversation with legal that you have been assuming you understood.

None of these measures requires a new budget line, a technology purchase, or a consultant. They require a decision to stop waiting for certainty that arrives too late: to start building the conditions where action is possible while it still matters.

The signs are almost always there. Someone almost always notices. The question for our profession is whether we have built organizations where noticing leads to action, or organizations where it leads to a file that gets opened after the worst has already happened.

 

Daniel Schneider, CPP, is the founder of Strategic Security Advisors LLC, a prevention-focused security consulting firm based in Wickenburg, Arizona. He is an InfraGard member, FBI Citizens Academy alumnus, co-chair of the ASIS International Phoenix Chapter Houses of Worship Committee, and the author of The Space Before Crisis. He also co-hosts The Security Shift, a podcast on security leadership and industry practice. He can be reached at [email protected] or azssa.com.

© 2026, Daniel Schneider, CPP, Strategic Security Advisors, LLC

arrow_upward