Stop Asking Executives to Care About Security
Updated: Sep 2
Show them how security and preparedness affect the outcomes for which they are responsible.

You have identified a legitimate risk. You have the incident reports, staffing data, professional guidance, and operational experience to support your concern. You have explained what is needed—perhaps additional officers, new cameras, stronger access controls, more training, an updated emergency plan, or a more comprehensive workplace violence prevention program.
Leadership says it will consider the request.
Nothing happens.
It is easy to conclude that executives do not understand security, emergency management, or workplace violence prevention—or simply do not care enough about them.
Sometimes that conclusion may be partly correct. More often, however, the problem is not a lack of concern. It is that a valid technical need was never translated into an organizational decision.
If leaders repeatedly fail to understand the importance of your recommendation, the problem may not be their lack of concern. It may be how you are communicating the need.
Executives are not expected to care about security technology, response tactics, emergency management terminology, or professional standards at the same depth as the subject-matter expert. They are expected to make decisions about patient care, workforce stability, operations, finances, compliance, organizational risk, and reputation.
Our responsibility is to connect what we know to the outcomes they are responsible for protecting.
Technical expertise does not automatically create influence
Security and emergency management professionals often earn credibility by knowing the details. We understand response times, deployment models, camera coverage, alarm functions, incident command, hazard vulnerability analysis, continuity requirements, workplace violence trends, and training standards.
That knowledge is essential. But it can also become a communication trap.
We may lead with the details most important to us:
1. The number of officers we need
2. The camera or access-control system we want
3. The equipment that is outdated
4. The training standard we recommend
5. The incidents that occurred
6. What another hospital is doing
7. What a professional association recommends
8. Why something is considered a best practice
All may be relevant, but none automatically tells an executive why a decision is needed, why it is needed now, or why this request should compete successfully against other legitimate priorities.
“Our radios are outdated” describes equipment. “Communication failures are delaying assistance to clinical staff in high-risk areas, and the current system cannot provide reliable coverage during an emergency” describes organizational exposure.
The first statement invites a purchasing discussion. The second invites a risk decision.
The goal is not to remove technical detail. It is to place that detail behind a clear explanation of the organizational problem.
Start with the outcome, not the purchase
Many unsuccessful proposals begin with the preferred solution: more officers, more cameras, another software platform, a training contract, or a facility modification.
That sequence asks leadership to accept the practitioner's diagnosis before the organizational problem has been established.
Begin instead with what is happening and why it matters.
If you need four additional officers, explain which locations, shifts, or responsibilities are not being covered; what service demand shows; how response time, injuries, overtime, missed activity, or staff concerns are affected; and what the current staffing model cannot reliably accomplish.
If you need more cameras, identify the risk and the coverage or investigative limitation. Explain whether the cameras will be monitored, what response the system supports, who will maintain it, and what improvement should result. “More coverage” is not an outcome.
If the access-control system is obsolete, connect the request to recurring failures, unauthorized access, maintenance costs, cyber exposure, business continuity, workflow, and the potential effect on patient care.
If employees need training, identify the performance gap. Explain which employees are affected, what incidents or observations reveal, what they must do differently, and how the organization will determine whether the training changed performance.
If you need a stronger workplace violence program, connect it to employee injuries, absenteeism, turnover, reporting confidence, staffing stability, patient care, regulatory expectations, and post-incident support.
If continuity planning is incomplete, do not simply say the plan is required. Explain which clinical and support services may fail, how long essential care can be sustained, which resources are shared, what capacity or revenue is at risk, and which decisions executives must make before a disruption.
Translation does not weaken the security or preparedness message. It reveals why the message matters. Explaining the expected return on investment helps leaders understand why action is needed, what organizational outcomes the recommendation is intended to improve, and how success will be measured.
“Best practice” is not a business case
Professional guidance, regulatory requirements, accreditation standards, and industry practices can strengthen a recommendation. They rarely make the entire case.
Saying that another hospital has implemented a technology may create interest, but it does not establish that the same investment addresses your organization's risk. Saying that something is a best practice may sound authoritative, but leaders still need to understand its relevance, feasibility, cost, and expected effect.
A stronger explanation is:
This practice addresses a recurring exposure we have identified in these locations. We considered several options. This recommendation provides the most reasonable balance of risk reduction, operational effect, and total cost. Here is what it will require, the exposure that will remain, and how we will evaluate whether it works.
That is not simply an appeal to authority. It demonstrates analysis and judgment.
There is no single executive language
Executives share responsibility for the organization, but they view a recommendation through different accountabilities. The facts should remain consistent. The emphasis should help each leader understand how those facts connect to their responsibilities.
CEO—mission, strategy, trust, and governance: Could this issue affect the organization's ability to provide care, execute its strategy, protect public trust, or defend leadership and governing-body decisions?
COO—capacity, reliability, and implementation: How does the issue affect workflow, service interruption, response, productivity, and the organization's ability to operate consistently? Can the proposed solution work within actual operations?
CFO—total cost, competing priorities, and measurable value: What is the full lifecycle cost? What costs are occurring elsewhere today? What exposure remains if action is deferred, and what evidence will show that the investment produced value? If you can add What costs can be reduced by this implementation? Even better!
CNO—workforce safety and patient care: How does the issue affect nurses and other clinical staff, injuries, staffing, response support, confidence, retention, and the ability to deliver care?
CMO—clinical practice and physician confidence: Does the recommendation support clinical decision-making, physician and advanced-practice-provider safety, behavioral emergency response, patient rights, and care-team coordination?
CHRO—people, trust, and workforce stability: How does the issue affect recruitment, retention, absenteeism, employee confidence, training expectations, reporting, and support after an event?
Legal or General Counsel—foreseeability and defensibility: What did the organization know, what options were considered, what was decided, and can the rationale and execution be demonstrated?
Risk Management—frequency, severity, and control effectiveness: Where is the exposure concentrated? What are the consequences, which controls are failing, and will the recommendation reduce the likelihood or severity of loss?
Quality—systems and sustained improvement: What process conditions contribute to events, and how will corrective action be measured to confirm that improvement occurred and lasted?
Technology leadership—integration, resilience, and lifecycle support: Will the proposed technology integrate with existing systems, protect data, remain supportable, withstand disruption, and receive appropriate maintenance and replacement?
This is not telling different executives different stories. It is explaining the same problem in ways that allow each leader to evaluate the consequences within their area of accountability.
Correlation is not the same as causation
A pattern does not automatically prove its cause. An increase in workplace violence reports following a staffing reduction does not, by itself, establish that fewer staff caused the increase. The change may also reflect higher patient volume, different patient acuity, improved reporting, longer wait times, environmental conditions, or several factors acting together.
However, the absence of proven causation does not mean the relationship should be ignored.
A credible professional distinguishes what the evidence demonstrates from what it merely suggests, examines reasonable alternative explanations, and identifies what additional information is needed.
Executives do not require false certainty; they need an honest assessment of the relationship, the potential consequences, and whether the available evidence is strong enough to justify further analysis, interim controls, or action.
Overstating causation can damage credibility, but dismissing a meaningful correlation can allow an emerging risk to continue unexamined.
Do not confuse fear with persuasion
Practitioners sometimes believe that making the risk sound more frightening will make the request more persuasive. It may attract attention, but it can also damage credibility.
Worst-case scenarios have a place in risk analysis. They should not be used as a substitute for evidence. If every vulnerability is described as catastrophic, urgent, or unacceptable, leaders eventually stop hearing the distinction between an immediate danger and a condition that should be managed over time.
Executive communication is not about creating fear. It is about reducing uncertainty enough for leaders to make an informed decision.
Be direct about the potential consequences, including severe ones, but distinguish what is possible from what is probable. Explain the evidence, assumptions, limitations, and remaining uncertainty. A credible adviser does not promise that a recommendation will eliminate all risk. A credible adviser explains how it will change the risk and what exposure will remain.
Leaders are more likely to trust someone who can say, “This is not the highest risk we face today, but it is recurring, the consequences are increasing, and a phased solution is reasonable,” than someone who describes every request as an emergency.
Bring a decision, not just a problem
A technical expert may identify the best technical solution. An organizational adviser also recognizes that the recommendation competes with clinical staffing, facility repairs, technology, equipment, and other priorities.
Do not bring leaders only a problem and a preferred purchase. Bring realistic choices.
For example:
Maintain the current approach. Describe the cost, limitations, and remaining risk leadership would be accepting.
Make targeted improvements. Identify focused process, staffing, training, or technology changes that address the most significant exposure.
Implement the full recommendation. Explain the expected benefit, operational requirements, total cost, and implementation timeline.
Phase the solution. Prioritize the highest-risk locations or capabilities across multiple budget cycles, with clear interim controls.
Not every proposal needs four options. Each option must be genuine, not a deliberately poor alternative designed to make the preferred choice look better.
Providing choices demonstrates business judgment. It allows leaders to compare cost, risk reduction, implementation demands, and residual exposure. It also makes clear that choosing not to act is still a decision—one that should include an informed understanding of the risk being accepted.
Answer the questions leaders will ask before they ask them
A credible recommendation should make eight points clear:
What is happening? Define the condition without exaggeration or unnecessary technical language.
Why does it matter here? Connect the issue to this organization's patients, workforce, operations, finances, obligations, or reputation.
What evidence supports the concern? Use incident trends, response data, work orders, injuries, survey findings, employee concerns, exercise findings, audit results, or other relevant information.
What are the realistic options? Include alternatives, not only the preferred purchase.
What will each option cost? Include implementation, staffing, training, maintenance, licensing, workflow, and replacement—not merely acquisition.
What risk remains? Explain what each option will and will not accomplish.
What do you recommend, and why? Make the decision easier by providing a clear professional judgment.
How will we know whether it worked? Identify outcomes, performance measures, review dates, and ownership.
If these questions cannot be answered, the proposal may not be ready for executive consideration. More slides will not correct incomplete analysis.
Measure outcomes, not activity alone
Security and preparedness programs often report activity because activity is easy to count: calls for service, patrols, training completions, drills, badge transactions, cameras installed, or policies revised.
Those measures may show effort. They do not necessarily show effectiveness.
Leaders also need to know whether response times improved, repeat incidents declined, known vulnerabilities were corrected, employees demonstrated the required behavior, downtime procedures worked, reporting confidence increased, injuries or operational disruption decreased, and corrective actions remained effective.
The measurement should match the promise. If the proposal claims that a change will reduce response delays, report response performance. If training is intended to improve early intervention, examine behavior and event reviews—not only attendance. If cameras are intended to improve investigations, measure usable evidence, coverage reliability, and whether the system supported a timely response.
Do not claim more than the data can prove. Show leaders what changed, what did not, and what must be adjusted. That is how one successful recommendation creates credibility for the next.
Become an organizational adviser
The most effective security, emergency management, and workplace violence professionals do more than explain their disciplines. They help leaders make responsible organizational decisions.
That requires technical competence, but it also requires curiosity about operations, clinical care, finance, workforce concerns, technology, quality, compliance, legal exposure, and organizational strategy. It requires listening before presenting and understanding what other leaders are trying to protect.
It also requires accepting that the technically strongest solution may not always be the most practical one. A phased improvement that can be implemented, sustained, and measured may reduce more risk than an ideal solution the organization cannot fund or operate.
Subject-matter expertise earns you a place in the conversation. The ability to connect that expertise to patient care, workforce stability, operations, finances, compliance, and organizational risk helps your recommendation survive the conversation.
Leaders do not need you to think exactly as they do. They need you to explain what you know in a way that helps them make a responsible decision.




Comments