Skip to content

Illustration by iStock; Security Management

Why Corporate Security Influence Expands in Crisis and Contracts in Routine Operations

Corporate security leaders often recognize a recurring organizational rhythm. When the organization faces a serious incident, an escalating threat environment, or intense regulatory attention, security becomes central to how decisions are made. Senior leaders want briefings, resources are made available quickly, and security advice shapes priorities across functions.

However, as conditions stabilize, that influence frequently diminishes. Security remains busy and visible, yet its input becomes easier to defer, negotiate, or compartmentalize as operational demands regain dominance. Many practitioners describe this as being listened to in crisis while being treated as optional in routine conditions.

That pattern is commonly explained through leadership personalities, organizational politics, or assumptions that executives do not understand security. Those factors matter, yet they do not explain why the same pattern appears across sectors and organizational types, including organizations with mature governance frameworks and well-resourced security functions.

This article summarizes insights from a completed multiphase, qualitative doctoral study, An Investigation into the Mechanisms, Barriers, Degree and Sphere of Risk Influence in Corporate Security. It examined corporate security influence through three lenses: how corporate security is described and constructed in the literature, how influence failed to translate into action across major organizational failure events, and how senior practitioners described influence dynamics in their own organizations.

The overarching finding is that corporate security influence is conditional. It expands and contracts in response to organizational context, risk salience, and legitimacy rather than being secured by role titles, reporting lines, or technical competence alone.

Engagement or Influence

A practical starting point is to separate two ideas that organizations frequently blur. Corporate security commonly has a wide sphere of engagement. It interacts with operational managers, facilities and asset teams, compliance and audit functions, risk management units, legal counsel, human resources, business continuity and emergency management teams, and selected executive stakeholders.

Externally, security often interfaces with regulators, law enforcement, emergency services, private security providers, insurers, auditors, and intelligence partners. This breadth can create a reasonable assumption that security’s organizational influence is similarly wide.

The study shows that this assumption routinely fails, and it fails at a definite point: conflating influence with engagement.

Engagement describes where security is present, consulted, or required to contribute. Influence is visible only when security input changes decisions, priorities, resourcing, or organizational behavior. Many organizations engage security extensively while still confining its practical impact to specific operational and compliance environments.

This clarifies a frustration that is otherwise easy to personalize. Security leaders can be technically capable, operationally respected, and embedded in governance processes while still being unable to mobilize sustained action outside a bounded arena.

In practice, security recommendations compete within a broader interpretive field. They are not evaluated solely on technical merit; they are weighed against other success criteria that dominate the decision setting. Operational leaders privilege throughput, reliability, and labor availability. Finance privileges cost, return, and capital discipline. Legal and compliance privilege defensibility and adherence. Strategy privileges growth, optionality, and competitive positioning. Safety privileges prevention and harm minimization.

These competing evaluative frames shape what risks are elevated, what controls are judged “reasonable,” and what gets funded or deferred. From a practitioner standpoint, this helps explain why technically strong recommendations can be acknowledged and documented yet still lose priority in routine trade-offs.


Corporate security influence is conditional. It expands and contracts in response to organizational context, risk salience, and legitimacy.


Structural location reinforces this dynamic. Corporate security commonly sits within the organizational technostructure or adjacent support functions. Its influence is typically exercised indirectly through standards, policies, procedures, audits, investigations, assurance regimes, and performance frameworks. These tools provide reach across the organization, yet their effectiveness depends on uptake by the managers responsible for operational delivery, as well as sponsorship from senior leaders who control budgets and operational cadence. This is a central reason that security can be visible without being decisive.

In many organizations, security is positioned to advise, standardize, and assure, while operational and commercial leaders retain discretion over adoption and timing. Security influence becomes less a function of technical confidence and more a function of access to the forums where priorities and trade-offs are set.

When practitioners describe the experience of being brought in after decisions are already made, they are usually describing the effect of decision arenas. Organizations do not make decisions in the abstract. They make decisions through budgeting cycles, capital approvals, procurement gates, project governance, risk committees, operational performance routines, and incident escalation pathways. Each forum privileges particular forms of evidence and particular kinds of justification. Security may be present in governance architecture but still be peripheral to the moments when investment choices are finalized and delivery constraints are negotiated. The effect is formal inclusion without consistent decision impact. Practitioners experience this as security being consulted, yet options remain constrained by prior commitments, cost ceilings, and delivery timelines.

Legitimacy further shapes whether security input is treated as non-negotiable or discretionary. Specialist advice carries weight when it is perceived as appropriate, credible, and aligned with organizational values and priorities.

Where security is culturally framed as a cost center, a policing function, or an operational constraint, security recommendations tend to be treated as negotiable under delivery pressure. Where security is framed as value preservation, operational enablement, and protection of core activity, the same advice is more likely to be treated as strategic and action worthy. Practitioners recognize this distinction immediately in the language that circulates in their organizations. The former frame reduces security to a barrier to speed. The latter frame treats security as protection of continuity, reputation, and license to operate.

How Operational Conditions Affect Influence

The above organizational factors explain why crises temporarily change the rules. During crisis or high-salience risk conditions, threat visibility increases, accountability intensifies, and attention narrows toward protection and control. Decision-making often centralizes, and senior leaders become more directly engaged. In this context, security advice aligns more closely with executive priorities, access improves, and barriers are temporarily bypassed.

This doctoral study into security risk influence found that this expansion is common across different types of incidents and different organizational contexts. It is also temporary. As threat salience reduces and operational routines reassert, organizations revert toward efficiency oriented trade-offs and dispersed decision rights. Security influence contracts accordingly. Practitioners experience this as a sharp contrast between crisis conditions, where speed of mobilization is high, and routine conditions, where security competes with production and cost constraints.

Across the study, four recurring configurations or conditions, of influence were observed: routine, in which influence stays concentrated in operational and compliance environments; compliance-driven, in which influence expands procedurally but recedes once the obligation is met; crisis, in which influence expands rapidly across senior decision forums before receding as conditions stabilize; and institutionally enabled, in which influence extends consistently across governance environments.

Routine operating conditions. Engagement is frequent, technically grounded, and often respected locally, particularly in facilities management, investigations, guard operations, access control, and regulatory compliance. Influence remains situational. Security is able to shape local decisions about controls and responses, while having limited traction in strategic planning, capital allocation, or enterprise-level prioritization.

Compliance-driven conditions. Here, influence expands procedurally. Security input is incorporated because it is required for audits, legislative obligations, or corporate policy demands. This can create a temporary uplift in attention, yet it remains bounded to the compliance task. Once the obligation is satisfied, security’s influence contracts and the organization returns to its normal prioritization logic.

Crisis conditions. A distinct configuration emerges under crisis or high-salience risk conditions. Security gains rapid access to senior decision makers. Engagement, persuasion, and mobilization occur at speed. Practitioners recognize this as the moment when security is treated as immediately decision relevant, often because organizational exposure becomes visible and accountability pressures sharpen. The study also shows that this uplift tends to recede when conditions stabilize. Strategic access becomes less frequent, security returns to an operational rhythm, and discretionary adoption of security recommendations becomes more likely.

Institutionally enabled conditions. This less frequently observed configuration involves conditions where influence extended more consistently across governance environments. In these cases, security mechanisms are institutionally enabled through clear role definition, cultural legitimacy, and formal access to decision forums. Security participates meaningfully in strategic risk discussions and influences priorities beyond immediate operational concerns. The study found that such conditions are possible but uncommon. Where they occur, they depend on mature enterprise risk management frameworks and elevated reporting lines that give security formal standing in strategic risk governance, rather than on functional maturity alone.


Specialist advice carries weight when it is perceived as appropriate, credible, and aligned with organizational values and priorities.


For practitioners, the value of this model of conditions lies in how it clarifies what drives influence when it does occur. Four categories of enabling mechanisms consistently shaped influence outcomes: technical and specialist expertise, interpersonal leadership and general managerial capability, organizational culture, and positional authority. The first two are capabilities the function can build. The second two are conditions the organization confers, and they govern whether the first two can be enacted.

Technical and specialist expertise. These provided a base level of credibility in the study. Included were threat and vulnerability assessment, protective design, operational control implementation, investigations, and emergency response capability. However, technical competence rarely produced wider influence by itself.

Leadership capabilities. Interpersonal leadership and general managerial capability served as the bridge between expertise and organizational action. Practitioners who could frame risk in business terms, coordinate across functions, and advocate effectively for investment and prioritization were more likely to secure traction beyond operational domains. This was not about selling security. It was about translating security exposure into the categories that decision makers use: productivity preservation, regulatory exposure, capital discipline, reputational downside, and continuity of core activity.

Organizational culture. Cultural framing influenced whether security was viewed as a strategic contributor or a discretionary cost.

Positional authority. This authority determined security leaders’ access to decision arenas: committee participation, executive sponsorship, and involvement in capital and project governance.

The study observed that these latter two factors function as preconditions. When cultural legitimacy and structural access were weak, technical competence and managerial capability often remained advisory. When cultural legitimacy and access were strong, security influence expanded and mobilization became easier. This is an important correction to the common assumption that better technical work alone will produce better organizational outcomes. The findings suggest that influence is produced through the interaction of capability, legitimacy, and access.

The concept of degree of influence adds another layer of practical clarity. Security leaders often track influence through meeting attendance, consultation requests, and governance visibility. These indicators measure engagement rather than influence. Degree of influence focuses on observable organizational impact: changes in priorities, allocation of resources, implementation of controls, and sustained shifts in behavior or routines.

The study found degrees of influence to be highly variable across contexts. They tended to be strongest during crisis and compliance-driven periods and weaker during routine operations. This variability reflects organizational systems oriented toward stability, efficiency, and production continuity. Practitioners benefit from recognizing that influence is often risk calibrated and forum specific, with different degrees of impact available in differ rent decision settings.

This recognition leads to a practical reframing of a persistent question in the field. Many discussions ask why corporate security lacks consistent strategic influence. The study suggests a more useful question concerns when influence is organizationally appropriate and what conditions enable it to persist where risk relevance justifies it. In many organizations, bounded influence reflects deliberate design. Security is positioned as a specialist function with broad engagement and targeted authority, brought forward decisively when risk salience rises. That pattern can be sensible within an enterprise where many risk domains compete for attention and resources. The issue for practitioners is less about pursuing universal influence and more about deploying influence effectively when conditions make it available, while building the foundations that allow influence to travel further when required.

Periods of heightened influence also offer a strategic opportunity. Crisis moments can generate executive attention and rapid mobilization, yet the window closes quickly. Practitioners who treat a crisis as a gateway to institutionalization tend to secure more durable outcomes. This involves embedding security into the governance routines that drive resources and priorities, including capital planning, procurement gates, project assurance, and risk committee cycles. It also involves strengthening translation capability so that security risk is consistently framed in decision-relevant terms rather than presented as a standalone technical domain. Over time, these actions support a shift in cultural legitimacy, where security becomes associated with value preservation and operational enablement rather than disruption.

For security practitioners, the practical message is both challenging and constructive. Influence is rarely a permanent entitlement. It is situational, relational, and shaped by organizational context. Security leaders improve their effectiveness when they differentiate engagement from influence, recognize the constraints created by structural location and competing decision logics, and concentrate on mechanisms that convert expertise into organizational traction.

When influence expands during crisis, the priority becomes converting temporary visibility into durable governance integration. When influence contracts under routine conditions, the priority becomes sustaining legitimacy, strengthening translation, and targeting the forums where degree of influence is realistically available.

Corporate security’s organizational role continues to broaden, and expectations of enterprise contribution continue to rise. The study’s evidence suggests that influence will remain conditional even as functions mature. Practitioners who understand this conditionality are better positioned to operate with realism, deploy their influence where it matters most, and build the organizational foundations that allow security to shape risk outcomes when risk significance warrants strategic attention.

 

Nicola Lockhart, PhD, is course coordinator and lecturer in counterterrorism, intelligence, and security science at Edith Cowan University, where her work sits at the intersection of security practice, governance, and law. Drawing on operational experience of over a decade, she completed her PhD in security risk in 2025, with doctoral research examining how corporate security functions shape organizational decision-making, exploring the mechanisms, barriers, and degree of influence through which security risk drives outcomes at the enterprise level.

Michael Coole, PhD, is the associate dean of teaching and learning in the School of Science at Edith Cowan University. Drawing on over a decade in the Australian Defence Force and more than 20 years in the Western Australian justice system, his teaching and consultancy span physical security, access control, and CCTV systems, as well as facility management and security risk management. 

Warren Doudle, PhD, is the director of Sec Risk, a risk management consultancy based in Perth, Western Australia, and a senior lecturer in security science at Edith Cowan University, where he leads the Security and Intelligence Research Group. With nearly three decades of experience spanning defense, critical infrastructure, resource sector operations, and academia, Doudle brings a broad and dynamic perspective to strategic security and risk leadership.

 

arrow_upward