
How Fractured Approaches to Corporate Security Create Major Vulnerabilities: A Managed Security Program Case Study
See how Insite built a Managed Security Program after a former employee accessed an executive floor, exposing major gaps in ownership, access control, offboarding, and incident response.
Building a Managed Security Program After an Executive-Floor Intrusion
Industry:
Asset Management
Primary Service:
Managed Security Program
An unchallenged intrusion onto the executive floor by a disgruntled former employee exposed the absence of any real security program. Insite responded by building one from the ground up.
The Challenge
Ask “who owns security” at a mid-size firm, and the answer is rarely simple. At this asset management firm's New York headquarters, responsibility had been unintentionally split across Facilities, IT, and Human Resources.
Facilities managed the badge system and the front desk, IT controlled the access platform behind it, and HR handled the employee lifecycle that was supposed to keep the two in sync. No single leader was positioned to see the full picture, and each function quietly assumed the others had it covered.
That assumption was put to the test when a former employee, terminated weeks earlier after a contentious departure, walked back through the front doors. His badge, still active, waved him past reception and into the executive offices without a second look.
By the time anyone registered that he no longer belonged there, he was standing outside the CEO's office. Employees on the floor froze, caught between conflicting instincts of intervening, calling building security, or calling the police. The seconds that should have triggered immediate action instead stretched into several unanswered minutes.
No one was harmed, but the firm's leadership understood that the outcome had hinged entirely on the intruder's intentions, not on any safeguard the firm had built. A repeat incident ran the risk of a direct threat to employees’ life safety.
Insite was brought in to find out exactly how far that vulnerability extended, beginning with a Corporate Security Program (CSP) Gap Analysis targeted at the specific failure points the incident had exposed.
Our team assessed:
No formal offboarding checklist connecting HR's termination process to IT and security
No process for monitoring former employees that were terminated under contentious terms
No tiered access separating the executive floor from the rest of the office
No visitor management protocol requiring identification or an escort
No process to monitor to threats by individuals towards the firm and it's leadership
No documented plan defining who was responsible for security incidents affecting the firm
Insite built the firm a fully Managed Security Program, anchored by a dedicated Security Director, to close the gap across every discipline of physical security:
Risk Assessments
Evaluated the office’s approach to all aspects of security including visitor management, video surveillance, access control, emergency preparedness, life safety equipment, and emergency response procedures
Protective Intelligence & Investigations
Built risk profiles and conducted continuous monitoring for the CEO and other senior executives
Ran a focused investigation into the former employee to assess his ongoing risk level
Executive Protection
Informed by our intelligence and investigative findings, Insite stationed guards at key office access points and provided secure transportation to and from the office for the targeted CEO
Access & Technology
Tied badge deactivation directly to the HR termination workflow so access is revoked the same day
Placed the executive floor behind a distinct access tier with a mandatory visitor escort
Upgraded the access control platform and expanded camera coverage across entry points
Training
Delivered scenario-based training on workplace violence, insider threat, and lockdown response
The Insite Approach
The Results
Ensured that future incidents are completely mitigated through removing the gaps in access control that enabled the intruder to enter the building after being terminated
Leadership received clear documentation on how future intrusions were mitigated and how the program works within their existing corporate structure to holistically manage risk
Executives were provided with ongoing visibility into their risk profiles and threats that may arise internally or online
Employees were empowered as security resources after receiving training from subject matter experts
The firm gained a single accountable partner to lead security decision-making
Legal and HR leadership now have a recountable record demonstrating duty of care
A Managed Security Program closes gaps before an incident occurs, replacing informal assumptions with defined ownership, tested protocols, and one team accountable for every layer of protection. No matter the organization, the Insite team builds programs designed to address your organization’s specific risk profile.
