In the modern federal landscape, the mandate of government agencies is clear: serve the public, protect the mission, and maintain transparency. However, for organizations like the National Labor Relations Board (NLRB), which manages over 50 public-facing offices across the United States, the execution of this mandate is fraught with complex security challenges. Balancing the need for an open, accessible government environment with the imperative of protecting personnel and sensitive data requires a delicate, highly calibrated approach to risk management.
Recently, I sat down with Raymond Hankins, the Chief Security Officer for the Security Branch at the NLRB, to explore the intricacies of federal facility management. Our conversation delved into how the agency navigates the evolving threat landscape, the necessity of inter-agency cooperation, and the increasingly critical need to bridge the operational divide between physical and cybersecurity teams.
The Mandate of Openness: Security in the Public Sphere
For many security leaders, the term "open facility" is often synonymous with "vulnerability." Yet, for federal agencies, the mission is fundamentally linked to public access. The NLRB’s operational model is predicated on the idea that justice and labor relations services must be approachable.
Adhering to the ISC Framework
According to Hankins, the NLRB’s strategy for balancing accessibility with security is rooted in the rigorous standards established by the Department of Homeland Security’s Interagency Security Committee (ISC). These guidelines are not merely checklists; they are a framework for balancing the protection of human capital and government resources with the constitutional and administrative requirements of public service.
"These standards are intended to achieve an appropriate level of protection while ensuring that members of the public are treated with respect and dignity," Hankins explains. The goal is to create facilities that are resilient and fortified against threats without transforming the workspace into an environment that feels hostile or exclusionary to the taxpayers it serves.
The Role of Facility Security Committees (FSCs)
The cornerstone of this operational success lies in the Facility Security Committees (FSCs). These groups—composed of building tenants, federal security professionals, and designated building officials—act as the primary governing body for site-specific risk assessments.
By decentralizing the decision-making process through these committees, the NLRB ensures that security measures are tailored to the unique vulnerabilities of each specific office location. This collaborative approach allows for the implementation of measures that are not just effective, but also contextually appropriate. As Hankins notes, this makes federal facilities "less attractive as targets" because they are hardened in a manner that is proportionate to the actual risk, rather than employing a one-size-fits-all deterrent that might alienate the public.
Chronology of Evolution: From Static Protection to Adaptive Resilience
The security environment for federal agencies has shifted dramatically over the past two decades. Historically, security was a static, perimeter-focused discipline. Today, it is an adaptive, intelligence-driven operation.
The Rise of New Threats
The timeline of federal security has evolved from protecting against unauthorized entry to managing complex, multi-vector threats. The emergence of Unmanned Aircraft Systems (UAS), commonly known as drones, represents the latest frontier. These devices challenge the traditional concept of a "secure perimeter," which once focused almost exclusively on ground-level access.
Hankins highlights that the NLRB is constantly evaluating its stance against these emerging technologies. The process involves a continuous cycle: identifying the threat, assessing the vulnerability of current infrastructure, and updating policies to mitigate risk. This evolution is supported by annual compliance reporting across the federal community, which serves as a vital feedback loop. These reports act as a "community pulse," allowing agencies to share best practices and benchmark their progress against their peers.

Bridging the Operational Divide: The Physical-Cyber Convergence
Perhaps the most significant portion of our discussion centered on the internal friction between physical security professionals and their counterparts in the cybersecurity department. As building management systems (BMS), surveillance networks, and access control systems become increasingly digitized, the historical separation between these two disciplines has become a liability.
Differing Perspectives on Risk
Hankins identifies a fundamental difference in how these two disciplines view the clock. "One of the biggest challenges is that physical security and cybersecurity professionals often approach risk from different operational perspectives," he observes.
- The Physical Mindset: This is a culture of immediate response. When a door is breached or a physical threat enters a lobby, seconds matter. Security personnel are trained for instantaneous threat assessment and rapid, life-safety-focused decision-making. Their primary objective is the preservation of human life in a high-stakes, real-time environment.
- The Cyber Mindset: Conversely, the cybersecurity discipline is inherently analytical and methodical. A cyber-incident response requires the preservation of digital evidence, the careful identification of the scope of a breach, and a surgical approach to mitigation. Moving too quickly—or "ripping and replacing" compromised systems—can inadvertently destroy the evidence needed to understand the root cause of an attack or result in unintended system downtime.
The Path to Integration
The challenge, according to Hankins, is fostering mutual respect for these differing methodologies. If a physical security officer ignores the cyber risks inherent in a networked door lock, the agency is compromised. If a cybersecurity officer ignores the urgency of a physical threat, the agency is vulnerable to physical harm.
Successful integration requires more than just sharing office space; it requires:
- Common Language: Developing a shared risk lexicon that both disciplines understand.
- Joint Planning: Conducting table-top exercises that simulate dual-vector attacks (e.g., a physical breach occurring simultaneously with a network outage).
- Unified Objectives: Reframing the mission statement so that both teams realize they are ultimately protecting the same assets: people, information, and critical infrastructure.
Implications for Future Security Leadership
The insights provided by Raymond Hankins underscore a shift in what is required of future security leaders. The "siloed" expert is becoming an artifact of the past. Today’s Chief Security Officer must be a translator, capable of navigating the high-speed demands of physical safety and the high-complexity world of digital defense.
The Strategic Value of Resilience
As the NLRB and other federal entities move forward, the emphasis on "resilience" will continue to outweigh the emphasis on "fortification." A resilient facility is one that can withstand an attack, recover rapidly, and continue its mission of service to the public. This is achieved not just through cameras and guards, but through a robust culture of cross-disciplinary communication.
Building a Common Understanding
For the federal sector, the integration of these teams is no longer optional. With the convergence of physical and cyber systems, the security posture of an agency is only as strong as its weakest link. Whether it is an unsecured server room or an improperly monitored badge reader, the physical and the digital have become inextricably linked.
As we look toward the future, the lessons from the NLRB demonstrate that security leadership is fundamentally a people-centric endeavor. It is about aligning personnel, creating forums for communication, and ensuring that every stakeholder understands that, despite the differences in their tools and tactics, the ultimate goal remains the same: the protection of the agency’s mission, its people, and its information.
In conclusion, the work being done at the National Labor Relations Board serves as a blueprint for other government agencies. By embracing the complexity of modern threats and intentionally breaking down the walls between physical and cyber teams, security leaders can create a safer, more transparent, and more resilient future for the federal government and the public it serves.
