Security at a large multinational business

Paint splatters - security at a multinational

Share this content

Facebook
Twitter
LinkedIn

Erik Antons, Chief Security Officer at PPG discusses the significance of governance and standards for a global business.

Can you just tell me about your journey in security and your current role?

It’s been a long, strange trip to get to where I am now! I graduated with a degree in Journalism & PR but never went into the profession.

Instead, I was self-employed and worked for small businesses for about 12 years.

Following the terrorist attacks on 9/11 though, something shifted and I had a complete change of heart.

I went into the public sector and joined the US Department of State. In 2014, an opportunity came up with a company called Sempra Energy in Southern California.

I moved over to Sempra and was hired into a new position as the Manager of International Security & Executive Services.

After about three years, I wanted to run my own department, but that opportunity wasn’t available at Sempra. I started to look around and was hired as Vice President, Chief Security Officer at HYATT Hotels.

When the COVID-19 pandemic hit, our entire department was laid off.

I found myself looking around again, and fortunately, Whirlpool Corporation was looking for a new head of Global Security and that’s how I ended up there in October 2020.

In the spring of 2024, Whirlpool announced a massive reorganization and eliminated all global roles, including the Chief Security Officer, so I chose to start the job search again.

Fortunately, about three and a half months later, I ended up with PPG, where I am today, and it’s now been seven months.

We produce paint, coatings and specialty products – think rust treatment for vehicles, primer and topcoats, the architectural finishes for homes, and things you may not think about, like the layer underneath the display of an iPhone or the lining for paper coffee cups.

What’s it like coordinating security for teams across the globe?

It’s challenging, but I’m a firm believer in standards. It’s essential to provide global governance, which is followed by the entire department.

It’s very rare to have departmental standards in what we do.

While developing standards might not come very easily to security professionals, if they’re put in place early on, then it allows you to govern at scale.

In my opinion, it comes down to three basic aspects, regardless of department size. The first is the “why”.

Why do we even need a security department at [this organization]?

To answer that question, it’s critical to think about who you are as a department, what you do, what your promise to the organization is, how you are organized and how you will measure success and organize these into a manifesto of sorts.

Some might call this a department charter, but it’s much more than that – it’s actually a department standard.

Once your standards are established, you can start looking at operational procedures.

That’s the next big action item: to develop step-by-step guidance after identifying the most common tasks that people have to conduct in the field.

I have generally found that across all industries, there are about 50 common tasks.

The challenge here is to provide guidance to the field that is specific enough to be meaningful, yet broad enough to apply globally.

Once complete, this provides a blueprint for regions or sites to build more prescriptive guidance aligned with culture, risk and law in those areas.

The last aspect is technical standards. When I talk about technology, I’m not just talking about the complex technologies like access control, video management or intrusion detection.

This also includes the less complex technologies, like guards, gates, barriers, signage, lighting and so on.

One of the first things we did within PPG was to audit our sites to determine how many different manufacturers of cameras were represented at our facilities around the globe.

I couldn’t believe how many different makes we had, but it wasn’t surprising because each site had responsibility for their individual equipment.

They had limited guidance, and many decisions were made based almost exclusively on cost.  

Instead of having so many different types of camera equipment, what if we could reduce that to three or four camera manufacturers?

Not only would it help us standardize our procedures, but could also open up the opportunity for most cost-effective solutions.

Then, rather than trying to be all things to all people, we can now truly become experts with our vetted technologies.

What are some of the challenges that you face working for a multinational to secure supply chains?

While supply chain security responsibility doesn’t lie within our organization, cargo security does.

Typically, PPG products are applied to end products within the same region they were produced.

However, cargo security can still be very challenging, particularly in Latin America, where risk cargo theft is highest.

We have a very efficient team in Latin America where a key part of their success has been built on our governance standards.

By looking at their end goal, considering what success means, taking steps to ensure cargo integrity and evaluating the best tools to use, they have become a very effective team.

We have a regional operations center that’s excellent at following cargo in real time and coordinating response in the event of an incident.

As a result, most of our cargo theft cases are resolved very quickly.

Usually by the time the driver is asked to step out of the vehicle by the would-be thieves, law enforcement has been notified, product is rarely lost or damaged and our drivers are rarely harmed.

The key to all this is about having those pieces in place and governance procedures set up in advance, while also learning from any mistakes that were made.

An after-action review process is vital to any security department.

How do you go about that learning process – how might it be implemented?

My advice to anyone in the security industry is not to overcomplicate.

By building out governance from the beginning, it will always be clear who is responsible for every process.

Is something the responsibility of only security? Is it the responsibility of a multidisciplinary team?

While this should provide a clear structure of how to handle events when something occurs, it also allows you to make a judgement after the fact of whether the process is the right course of action.

What happens all too often is that people are so eager to have these events behind them, and they simply move on.

Sometimes there’s another incident just around the corner. It’s incredibly important to set time aside and actually learn from the initial event.

Everything that the security function for an organization does, I’ve found, falls into one of four categories: preparation, prevention, response and recovery.

That recovery piece is too often forgotten, but it is one of the most important ones.

What advice would you share with other security leaders?

I find myself talking about the need for governance more than any other topic.

I’ve been in the manufacturing sector a while, where I’ve seen first-hand the benefits of having standards in place ahead of time.

I’m always astounded by how little governance people in my role actually have in place within their departments when it makes everybody’s lives so much easier.

For example, take a minimum wage guard working midnight with limited supervision.

When facing a challenging situation, would they know what to do if they cannot wait until morning to make the phone call or send an email?

Do we provide enough guidance to somebody like that to have a pretty good idea of what to do?

There are also the financial implications of standards.

The Department of Defense, for example, has fairly strict security requirements as a condition of doing business.

So you need to have this in place or sometimes you cannot even bid on these contracts, meaning you lose out.

At the end of the day, governance rules out ambiguity and provides a metric for success.

If we don’t have a clear idea of where we’re trying to go, we may never get there.

What security trends do you predict we’ll be seeing in the near future?

Geopolitically, the US is pulling away from being the global policeman, which means cargo security is going to be an increasing issue.

We’re seeing it already in attacks on cargo ships moving through the Suez Canal and in other areas.

With the turmoil in Europe and the Middle East, it means we need to continue to be on our toes and monitor what’s going on.

This is part of the intelligence piece of our jobs to anticipate events before they manifest.

In terms of technology, we’re seeing some of the greatest advances in video management right now.

Twenty years ago, we heard all about edge analytics, but we’re only just now starting to see the impact of these analytics that we were promised then.

Now though, we are truly seeing more advances. Video is moving toward the cloud, and we’re getting more plug-and-play systems that are very secure.

Site personnel can install these without waiting for integrators to come onsite.

Additionally, we only need one camera system.

Where we might have needed two before – one for manufacturing and one for security – we can now train one system with specific analytics that look for anomalies or unsafe practices as well as checking quality.

This article was originally published in the May edition of Security Journal Americas. To read your FREE digital edition, click here.