
A school may employ guards and still have no security. Two incidents reveal what happens when authority, procedures and decision-making are never formally established.
The First Warning
At an international school, a man once entered the premises carrying a large bag. It appears that he simply came in alongside a pupil, without anyone checking precisely who he was or what he was carrying.
A few minutes later, he was found in the courtyard, among the children.
He was selling chicken wings.
The story may raise a smile. Yet when staff realised that the man was neither a parent, an employee nor an authorised contractor, the question immediately became less amusing: how had a stranger carrying a large bag been able to enter a school so easily and move freely among its pupils?
That day, the bag contained chicken. But what else might it have contained?
The man was escorted out and the incident was considered closed. Once again, the school was asked to make badges compulsory, establish genuine access control and formally define everyone’s responsibilities. Naturally, these requests were made verbally, leaving no written record and prompting no meaningful discussion.
These recommendations had been known for a long time. They were heard, discussed and then gradually diluted by daily routine—or by the habitual abandonment of any security decision as soon as it was perceived as a restriction of personal freedom.
After all, nothing particularly dramatic had happened.
The Second Warning
A few months later, a particularly aggressive man appeared outside the school. He seemed to be under the influence of alcohol or another substance. He made vague threats and claimed to be armed. His jacket appeared sufficiently heavy for that claim not to be dismissed as mere provocation.
The security manager attempted to calm him while observing his behaviour. The situation was deteriorating and the uncertainty was becoming serious: did the man genuinely possess a weapon? Was he going to attempt to enter the school?
Faced with that uncertainty, the security manager made a perfectly rational decision: activate the intrusion alarm and temporarily lock down the pupils and staff.
Had the threat proved unfounded, the school would merely have lost twenty minutes of class time. Had it been real, the lockdown might have saved lives.
On his instruction, a guard went to activate the alarm. Before he could do so, however, a member of the administration intercepted him. That person had neither operational responsibility for security nor any genuine decision-making authority in relation to this type of threat.
Nevertheless, they decided that the situation was not sufficiently serious.
The alarm was not activated.
By chance, a police officer passing nearby noticed the individual, quickly understood that something was wrong and managed to calm him down. The man eventually left without producing a weapon or attempting to enter the school.
Once again, nothing had happened.
That, at least, was the most comfortable conclusion.
In reality, a great deal had happened. A potentially armed individual had threatened a school. The security manager had assessed the danger and ordered a protective measure. A member of staff with no appropriate operational function had overridden that decision. Finally, only the fortuitous intervention of a police officer had brought an end to a situation whose outcome no one could genuinely have predicted.
This Was Not Crisis Management. It Was a Gamble.
The problem lay neither in the absence of guards nor in their inability to react. It lay in the absence of rules clearly defining who could decide, under what circumstances and according to which criteria.
A Standard Operating Procedure—or SOP—is not a document intended merely to fill a binder. It establishes alert thresholds, assigns responsibilities and creates a chain of command. Above all, it prevents a critical security decision from being overturned, disputed or even debated by someone who possesses neither the necessary competence nor the proper authority.
Would the lockdown have been disproportionate? Perhaps.
But when there is a reasonable possibility that an individual may be armed, the acceptable error is to interrupt lessons temporarily. The unacceptable error is to expose children because absolute certainty of the danger has not yet been obtained.
In security, that certainty always arrives too late. It is then measured by the number of victims.
When Vulnerability Becomes Reputation
There is one further consequence, less visible but no less serious. The weaknesses of an organisation eventually become known. Employees talk, families observe, contractors circulate and incidents are recounted. Little by little, a site may acquire a reputation for being easily accessible, poorly controlled or incapable of making a coherent decision.
Vulnerability then becomes reputation.
Not everyone who hears about it will, of course, have malicious intentions. Yet it takes only one person to decide, one day, to exploit it.
Security Requires More Than Guards
A school is not secure merely because guards stand at its gate. It is secure when those guards have precise instructions, recognised authority and the right to act before uncertainty becomes tragedy.
That day, the bag contained chicken.
The next time, perhaps the man had no weapon.
A responsible organisation cannot base its security policy on the hope that a third incident will end just as harmlessly.
In security, chance must never become the deciding factor.
