Security and Freedom

A heavily protected perimeter separates an external world of threats from a calm, open and harmonious workplace inside.

1. Security, the Perennial Spoilsport

In a company, an embassy, a school or a hotel, security rarely gets to play the popular role. It asks people to wear a badge, close a door, justify their presence, follow a prescribed route or wait a few moments before entering. Where operations seek fluidity and where people quite legitimately expect greater autonomy, security is easily seen as the function that slows things down, says no or makes life more complicated.

That perception is not entirely unreasonable. By definition, every security rule limits a possibility. Yet the problem is not the existence of the rule itself, but the way it is designed, explained and applied. A restriction that is understood and proportionate is generally accepted. One that appears arbitrary, excessive or disconnected from day-to-day work eventually feels intrusive.

Yet when you leave your home or your vehicle, do you not lock the door, knowing that you will have to unlock it again to get back in? You therefore accept a restriction on your freedom quite naturally, simply because you understand why it is necessary.

This is where the professional challenge begins. Security does not protect an empty site, but a living place occupied by people who need to work, receive visitors, move around, create, teach or simply carry out their duties. Treating every one of them as a permanent suspect would not only be unbearable, but probably counterproductive. If security tries to control every movement, it risks becoming an internal obstacle rather than a form of collective protection.

The first balance, therefore, is to recognise two equally legitimate needs: that of the organisation, which must protect its people, assets, information and continuity of operations; and that of individuals, who need enough freedom to function normally. Security starts to become truly effective when these two requirements stop fighting each other and begin to work together.

2. The Stricter the Rule, the More People Look for Room to Manoeuvre

The difference often comes down to one word: understanding. We readily accept locking our own door because we know the risk that the restriction is meant to address. The same mechanism applies within an organisation. When a rule is explained, understood and connected to an identifiable reality, it stops being merely a prohibition: it becomes a shared protective measure, almost common sense.

Conversely, a rule imposed without explanation wears thin over time. An employee tries to save a few minutes, regain some comfort or simply do the job more easily. The intention is not necessarily to weaken security; it is to find a solution to what feels like an unnecessary difficulty. That is ordinary human adaptation. The more repetitive, burdensome or poorly understood a restriction becomes, the stronger the temptation to work around it. The attraction of what is forbidden is part of human nature: exploring, trying, discovering, testing…

Security therefore also has a role in raising awareness. Why must this door remain closed? Why is this badge essential? Why is this check carried out here rather than somewhere else? Security can remain firm without becoming mute. A rule does not have to be renegotiated every morning, but people should understand the reason behind it. An unexplained “no” easily produces resistance; an understood “no” establishes a limit; better still, it spreads, because once the rule makes sense, it becomes accepted.

Explanation must not, however, be confused with weakness. Some rules are, and must remain, non-negotiable. But firmness and dialogue are not opposites. The difficulty lies in setting limits strict enough to protect, clear enough to be understood and practical enough to be respected. When a rule unnecessarily prevents people from working, or ignores predictable human behaviour, it can end up creating the very vulnerability it was designed to prevent. Two real situations illustrate this.

3. When Security Creates the Vulnerability Itself

At one embassy, a smoking area had been provided for security officers. Its location created no particular security difficulty, but the smoke and smell caused annoyance. Gradually, pressure increased until the arrangement disappeared altogether: guards were no longer allowed to smoke on site, and they were not allowed to leave the site either. On paper, the problem appeared to be solved.

In reality, it was anything but. Nicotine dependence does not disappear because of a rule, and some officers simply started looking for places where they would not be seen: corners, technical areas, even locations close to fuel tanks or flammable materials. A controlled nuisance had become a potential fire risk. Fortunately, no incident occurred. The situation was eventually reconsidered and a new smoking area was created in a more suitable location.

The prohibition had not removed the behaviour. It had made it invisible and uncontrollable. By trying to solve a comfort issue with an absolute rule, the organisation had shifted the problem onto genuinely security-related ground. The answer was neither to let everyone smoke wherever they wished nor to deny the behaviour existed; it was to manage it intelligently.

Another case, in a company with a particularly sensitive research and development department, illustrates the same mechanism in a different way. Access was tightly controlled by badges with limited validity periods. Security communicated little with employees and the system was perceived as rigid. One day, a permanent employee’s badge expired, effectively preventing access to the employee’s own office. To carry on working, the employee asked a colleague from the R&D department, who had broader access rights, to open the doors.

Then the colleague was absent. The improvised solution became very simple: the colleague lent the badge. The employee could now enter, but under someone else’s electronic identity and with access rights that were broader than their own. When the badge owner returned and retrieved it from the offices, the anomaly suddenly became obvious. A system designed to guarantee identification, access rights and traceability had led ordinary employees to exchange their digital identities simply in order to work.

In both cases, nobody was trying to attack the site. The guards wanted to smoke; the employee wanted to reach the office. Yet rules that were too rigid, poorly explained or badly adapted to the way the site actually functioned — or, worse still, security perceived as an oppressor — led to behaviours that created vulnerabilities greater than the original problem.

The lesson is essential: a security measure should never be assessed only by what it prohibits. It must also be assessed by the behaviours it is likely to trigger. Security is not about organising the world as we would like it to be, but about protecting the world in which people actually live.

An employee follows a one-way route into a dead end where every direction is forbidden, illustrating security rules that become absurd and counterproductive.

4. Security Should Be Hard to Breach, Not Hard to Live With

The first challenge of any site lies in its perimeter in general and its access points in particular. While a person remains outside, we do not yet know whether they are legitimate, expected, authorised or even whether they represent a risk. This is therefore the boundary at which security should be most rigorous: observe, identify, check, verify and decide. Once that step has been properly completed, the logic should change.

Inside, an authorised person should be able to work, move around and carry out their duties as freely as possible. Of course, some sensitive areas will require additional controls; they then become a new perimeter, almost a state within a state, with their own rules linked to that new access point and to a genuine need: confidentiality, hazard level, value of assets or nature of the activity. Applying the same intensity of control everywhere often amounts to compensating for poor organisation by multiplying restrictions.

The stronger the first filter, the more it becomes possible to lighten what follows. A well-designed entry process avoids turning every internal movement into a fresh source of suspicion. The site becomes easier to understand: the rule is strong where it needs to be, and far more discreet where it no longer adds value.

The logic can be summarised simply: before access, vigilance; at the point of access, rigour; after access, fluidity. Security should be hard to breach, not hard to live with. That distinction helps maintain a calm atmosphere, preserve individual freedom and, paradoxically, achieve better security through awareness that encourages acceptance and, better still, collective buy-in.

5. An Employee Is Not an Enemy

An organisation is not hostile territory. A person who works there is not, by definition, a threat to be watched constantly. When a security system blurs that distinction, it gradually creates distance between security officers and everyone else. The guard becomes the person people avoid, the person they stop talking to, the person whose decisions they try to work around rather than someone they ask for help.

Yet security needs everyone else. A door that does not close properly, an unfamiliar visitor, unusual behaviour, a vehicle in the wrong place or a lost badge will often be noticed first by the people who live and work on the site every day. But they still need to want to report it. A security team that is approachable, known and integrated naturally receives these weak signals which, taken separately, may seem insignificant but can become essential.

Trust does not, of course, replace control. But control without trust eventually becomes blind. A person who feels respected and involved is more likely to accept a rule, ask questions, report an anomaly and contribute — sometimes without even realising it — to collective protection. Conversely, someone who feels constantly suspected begins by protecting themselves from security itself.

The guard’s role is therefore not limited to filtering, prohibiting or watching. A guard must also observe, listen, explain, advise and know how to receive information. Effective human security does not symbolically place a police officer behind every employee; it creates enough proximity for everyone to become a relay point for vigilance. At that stage, security is no longer merely imposed: it starts to be shared.

As we often repeat, security is first and foremost a matter of information. Without information, we anticipate nothing: we merely react. The more accepted and appreciated we are, the more naturally information flows back to us. That information allows us to anticipate, to act before we have to react, and also to understand better the needs of those we are supposed to protect. At that point, the employee is no longer merely protected: the employee becomes an actor in security.

6. Buy-In Rather Than Surveillance

The objective is not to turn every employee into a security officer, nor to ask people to watch their colleagues. It is to enable them to buy into the system: to understand what is normal, what is not, why certain rules exist and, above all, who should receive the information. We are not asking everyone to “do security”; we are helping each person understand that, at their own level, they are already part of it — because ultimately they are among those who may be affected if the system fails.

That buy-in begins with awareness. Explaining why a door must remain closed, why a badge must not be lent, why a visitor must be accompanied or why an anomaly deserves to be reported is often enough to turn a restriction into a reflex. A rule that is understood is no longer merely followed: it becomes internalised. And when it is seen as legitimate, it may even end up being defended by the very people to whom it applies.

This is where people skills matter. A security team that is close to the workforce and able to communicate without losing its sense of direction creates an environment in which information flows naturally. That proximity must never become complacency; on the contrary, it allows the rule to remain in place while removing fear of the person who enforces it. The guard remains the guardian of the framework, but also becomes a recognised point of contact. We often talk about SOPs — Standard Operating Procedures: in a sense, the guard is the stage director who brings them to life.

When people genuinely buy into a system structured in this way, the organisation gradually stops depending on constant surveillance. People self-correct, report faster, understand restrictions better and help maintain the level of security without feeling permanently controlled. Security then becomes a shared culture rather than a succession of prohibitions.

But buy-in cannot be decreed. It is built, sometimes slowly, according to the history of the site, its habits and people’s ability to understand and then accept the rules. The professional may therefore need to begin with what is immediately acceptable, reduce the most significant vulnerabilities first, demonstrate the value of the measures and then adjust the dial progressively. This is how security can move from the “least bad” towards something better — not by piling on restrictions, but because the people it protects are now ready to support it.

7. Freedom and Security: Harmony Between Two Opposing but Necessary Requirements

Freedom and security are often presented as though one must inevitably retreat for the other to advance. That is too simplistic. Within an organisation, both are indispensable. Freedom allows people to work, create, move, decide and live normally; security provides the framework that allows that freedom to endure without leaving it exposed.

The objective is therefore not to choose one over the other, nor even to seek a permanent compromise in which each gives up part of itself. The aim is to build harmony: place restrictions where they are genuinely necessary, preserve freedom wherever possible, and make sure people understand the system well enough that they no longer experience it simply as something imposed on them.

In its most mature form, a secure organisation may not be the one with the largest number of guards. It is the one in which everyone knows the basic principles, recognises an anomaly, knows how to report it, applies the right reflexes and understands what to do if a threat materialises. Everyone then becomes, at their own level, a sensor, a relay and a participant in security, without becoming a security professional.

This becomes particularly important when a serious incident occurs. A security team cannot be everywhere, see everything, hear everything or, above all, be numerous enough to deal alone with every consequence of a crisis. If the rest of the organisation remains a spectator, security becomes isolated at precisely the moment when it most needs a collective response. Conversely, when people have been made aware and genuinely buy into the principles, everyone knows how to contribute within their role: raise the alarm, pass on information, apply a reflex action, protect, evacuate, facilitate the response or simply avoid making the situation worse.

The ideal model therefore no longer sets “security” against “everyone else”. Security professionals retain the skills, responsibilities and coordination that belong to them; everyone else becomes a complementary force because they understand, buy in and know how to act at their own level. Security then stops being a department sitting alongside the organisation: it becomes a function integrated into the organisation itself.

Perhaps that is where the desired harmony between freedom and security lies: an organisation in which controls exist where they are necessary, while the rest relies largely on understood principles, acquired reflexes and collective buy-in. The paradox is that this harmony is often easier to build after an incident, when everyone suddenly understands why it is necessary. The professional’s challenge is precisely to try to build it beforehand.

After all, what would become of your freedom if you destroyed the security that protects it?

8. Awareness Often Comes After the Event

Before an incident, security seems excessive. After an incident, it seems insufficient. It is almost a truism.

The professional’s role, therefore, is to create that awareness before the incident does it for us.