Elevating Enterprise Security- The Power of Competency-Based Training
govciooutlook

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Gov CIO Outlook Advisory Board.

City of Reno

Elevating Enterprise Security- The Power of Competency-Based Training

Christopher Harper

Mr. Christopher S. Harper is the Security Manager for the City of Reno, Nevada, where he leads the City Security Department, overseeing the City Security Operations Center and all security systems for the City’s critical infrastructure. Previously, he served as Security Director for Kaiser Permanente, University of San Francisco Benioff Children’s Hospital and Texas Children’s Hospital. Before entering healthcare security, he was a sworn California police officer serving on the specialized Street Enforcement Team in West Fresno Country.

Mr. Harper holds CHPA - Certified Healthcare Protection Administrator certification from the International Association of Healthcare Safety & Security and CCIPS - Certified Critical Infrastructure Protection Specialist certification from the Department of Homeland Security. He is also certified in Emergency Program Management, Continuity of Operations Management, Incident Command System Management for Healthcare & Hospitals and Multi-Hazard Emergency Planning for Educational Institutions. He holds a Bachelor of Science Degree in Business Management from the University of Phoenix. He is a senior member of ASIS and vice chair of its Northern Nevada chapter, a senior member of the International Association of Healthcare Safety & Security, a member of the Association of Threat Assessment Professionals and a life member of the Law Enforcement Alliance of America.

As security leaders, we face a constant, compounding challenge. The threat landscape is evolving faster than corporate infrastructure, expanding from physical asset protection to complex, blended threats that include cybersecurity, workplace violence, and crisis management. Yet, despite the sophistication of these risks, many enterprise security departments remain tethered to an outdated operational model: the reliance on presence over proficiency. The standard of “any uniform is better than no uniform.”

For decades, the standard metric for a successful security training program was if the officer completed their mandatory annual regulatory training, the box was checked and the company felt secure. But were they really? Having a poorly trained person filling a uniform doesn’t reduce risk or threats, in fact it provides a perfect opportunity for exploitation by bad actors.

The standard regulatory training in most states for security officers represents a baseline, the absolute minimum required by law. It does not measure capability, adaptability, or performance under pressure. To truly elevate an enterprise security department from a cost center to a critical business enabler, leadership must shift from a time-based familiarization training model to a comprehensive, competency-based training framework.

The Flaw of Time-Based Training

Traditional security training measures inputs: How many hours did the officer sit in a classroom? This approach assumes that exposure to information automatically translates to operational capability, but we all know it does not.

“Elevating a security department is not an administrative exercise; it is a cultural and operational transformation.”

In a high-stakes scenario, such as an active threat in your building, a severe medical emergency, or a hostile termination in HR, it does not matter if an officer attended an eight-hour seminar last June. What matters is their verified capability to execute specific, high-stress tasks flawlessly.

Time-based training creates an illusion of readiness. It satisfies legal minimums but leaves the organization exposed to significant operational and vicarious liability. The defense of "they completed their annual hours" rarely protects an organization’s reputation or bottom line.

Defining the Competency-Based Model

Competency-based training reverses the equation by focusing strictly on outputs: What can the security officer do, and to what standard?

In this framework, progression is tied to the mastery of specific knowledge, skills, and abilities, regardless of how long it takes to acquire them. Competency is a measurable, observable pattern of skills that leads to successful performance.

For an enterprise security department, competencies are structured into three distinct tiers:

1. Core Competencies: Foundational skills required including de-escalation tactics, emergency medical response (CPR/AED/First Aid), etc.

2. Specialized Competencies: Role-specific capabilities, such as console operations within a Global Security Operations Center (GSOC), or advanced surveillance detection.

3. Leadership Competencies: Skills required for leaders, including crisis command structure, operational budgeting, and threat assessment team integration.

Implementing the Framework

Transitioning your department to a competency-based model requires a deliberate, structured approach.

Before you can train for competency, you must define it. Analyze every role within your department to identify the critical tasks required for successful execution. Each of those tasks then becomes a competency with documented actions that must be performed or known, to demonstrate that the officer can perform that task/duty.

Every competency must have an objective, binary evaluation metric (Pass/Fail). Replace subjective instructor feedback with clear, performance-based rubrics. For example, instead of evaluating a de-escalation module with a written multiple-choice test, utilize role-play scenarios where officers must successfully de-escalate a simulated situation using approved verbal techniques within a set timeframe. Reserve valuable in-person training hours exclusively for practical, hands-on application, scenario-based drills and rigorous tactical simulations.

Continuous Verification

Many skills an officer must possess are perishable. A competency-based program requires a structured cadence of re-verification annually. In addition, institute a monthly or quarterly sustainment program on key topics that are critical skills/knowledge for officers, but because they aren’t used often, they atrophy from non-use. 

The Return on Investment

Implementing a competency-based training program is a significant operational undertaking, but the strategic return for security leadership is profound.

By maintaining objective, documented proof of individual and departmental capability, you establish an ironclad defense against claims of negligent training and decrease your organization’s liability. Competency training allows a department to stop wasting budget re-teaching skills that officers have already mastered, allowing it to redirect training funds toward critical capability gaps. Competency training improves morale, lowers turnover, and attracts top-tier talent. It is why law enforcement focuses on this type of training through a police officers’ tenure.

One of the most profound benefits is elevating the organizational trust in the security department. When executives see that the security department operates on a framework of verified metrics and proven capability, security transitions from an administrative necessity to a trusted strategic partner.

Elevating a security department is not an administrative exercise. It is a cultural and operational transformation. By dismantling the outdated reliance on compliance hours and instituting a competency-based framework, you do more than just train your team. You validate your department's value, safeguard your organization's assets, and ensure that when the crisis comes, your team is truly ready.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief