Business Security: What Risk Management?

Security, complementing safety, aims to protect businesses from malicious acts (attacks, cyberattacks). It is a major concern and is governed by the Labor and Penal Codes, with specific provisions for Seveso sites.

Marie Faucon
Consultante HSE
Publication : 
04.12.2020
Table of Contents
Request a demo

Please note: This article concerns French legislation. The requirements described may not apply in other countries.

The attack on the Saint-Quentin-Fallavier site (Isère) on June 26, 2015, and the two criminal explosions at the Berre-l’Étang petrochemical site (Bouches-du-Rhône) on July 14, 2015, are regrettable incidents that should raise awareness of the central role of preventing corporate security risks. Where to begin? What do regulations say on the matter? Here's a brief overview...

Security or Safety?

SAFETY involves implementing measures to prevent human and technical failures (sprinklers, traffic plans, evacuation drills, etc.). SECURITY, on the other hand, aims to prevent deliberate malicious acts (attacks, intrusions, occupation of premises, industrial espionage, cyberattacks, theft of property, kidnappings, vandalism, verbal and physical assaults, etc.).

Any business, regardless of its activity or size, is potentially a target for malicious acts.

The corporate security which aims to ensure its sustainability and the protection of its employees, is a major concern for business leaders. It is indeed essential to implement a security risk management system aimed at reducing threats and malicious acts.

Corporate security risk management systems

Thus, just like safety risk assessment, it is the role of each company to identify security needs and to assess internal and external threats, developing policies, plans, procedures, and protective measures to control these threats.

What are the benefits of such a corporate security policy?

1- Protecting their employees;
2- Protecting their data and brand image;
3- Protecting the environment (air, water pollution, etc.).

What are the essential points for implementing a risk management system?

1- Conduct a risk assessment: what are my company's targets? what are the potential malicious scenarios?...
2- Deploy protective measures: human resources (e.g., security guards), technical (e.g., video surveillance), procedures, staff information and training, lockdown drills, …
3- Ensure continuous security monitoring and regularly check the protective measures in place.

What are the security figures?

According to the CNPP's "Practical Treatise on Security Against Malicious Acts" (2018):

77% of incidents related to malicious acts involve fire;

7,816 metal thefts were recorded in France in 2015;

67% of companies in 2018 were affected by a "cyber event"

Business Security: What Do Regulations Say?

The Standard

Unlike safety, business security is not yet standardized… but this is expected to change very soon with the ISO 22342 management standard project on security planning.

The Labor Code

This code outlines the measures companies must implement as part of their obligation for employee safety and security (Article L. 4121-1 of the Labor Code).

The Penal Code

If an employer fails to uphold their duty of protection by not complying with the security and safety rules under the Labor Code, and this failure causes harm, they may face criminal penalties (fines and prison sentences).

For Seveso sites

Regulations concerning the protection of Seveso classified sites are more specific, particularly with the agreement of July 18, 2016, relating to health, the improvement of working conditions, safety, and security, which addresses the concept of a "security file" that all external service providers for Seveso classified sites must provide.

For cyberattacks

To address this, regulations have established an organization that brings together vital operators (OIVs), whether private or public.

These are operators whose activities, in the event of a cyberattack, would endanger residents or paralyze France (examples: sectors such as health, water, electricity and gas, food, hydrocarbons, transport, telecommunications, industry, finance, nuclear, etc.).

If a company is part of the OIVs, it is informed by the National Agency for Information System Security (ANSSI) and must therefore meet obligations regarding IT security.

Furthermore, Article 22 of the Military Programming Law (Law No. 2013-1168 of December 18, 2013) requires OIVs to strengthen the security of the critical information systems they operate: vital information systems (VIS).

Given the multiple threats of malicious acts that companies face, it therefore becomes important to anticipate and manage these malicious risks to limit their consequences. Just like safety, companies must implement an organization to prevent security risks within the company.