The concept of using so-called “red teams” to test the effectiveness of security personnel and equipment is typically thought of as a practice that only the military or the federal government uses. Security professionals who have not worked in those environments may not be as familiar or as comfortable with these approaches. The use of undercover operators and unplanned security tests can point out what needs to be fixed.
Chameleon Associates (chameleonassociates.com), a Los Angeles-based security consulting firm, discusses how they use red team exercises with their clients:
“A key element of security training is testing. And the best testing is in the form of red teaming or simulated adversarial tests. You may already be familiar with the kind of red teaming that the TSA does, where for example, their agents try to infiltrate a weapon onto a flight. There is much more to it than that. We use role players to test the security systems of our clients. The role player mimics the behavior and actions of a would-be criminal or terrorist who could be trying to get a weapon through or, just casing the joint. Maybe they are conducting surveillance or researching potential targets. The operational possibilities are endless and always reflect the methods of operation the adversary would use against the protected target. Red teaming and role players support our quality assurance services.
“In fact, we often turn to our clients’ security officers to act as the role players for the test exercises. A security officer from perhaps another property or who is normally on a different shift—steps in. A method of operation (MO) is decided upon. Perhaps the MO is purse-snatching. The officer starts acting like a purse-snatching thief, following potential targets and mimicking that behavior. Hopefully, the security officer on duty notices. If he does, he passed the red team [test]. If he does not, it is a fail and a learning experience. There are multiple benefits to this technique:
- The role-playing officer gets a chance to walk in the adversary’s shoes. Seeing the security situation from the other side can be a real eye-opener. The adversary is no longer theoretical. Having to act the part, the officer is closer to being ‘in the head’ of the bad guy. That’s a good place to be if you are trying to prevent threats from becoming events.
- The officers have an added sense of responsibility. There is a tendency for officers to feel isolated and in fact often they are alone on post, that’s the nature of the job. However, after a red teaming experience, they often realize that they are a part of a bigger picture.
- Rather than hear descriptions of the MOs and the suspicion indicators, the officer experiences them. They also gain a better understanding of suspicion indicators because they are obliged to act them out.
- Officers get a better perspective on what good performance looks like versus under-performance. The difference between getting it right, or not, becomes crystal clear in a red team situation.
- The red team testing is a great training tool, both for the role player and the security officer. The approach should never be one where the role player is trying ‘to get’ the officer. A red team fail is not a win for the role player. It’s just a chance to bolster a weak skill or to fill in missing knowledge about the MOs and associated suspicion indicators for a given protected environment. Everyone responsible for security there stands to benefit from the lessons learned.”