The Information Accessibility Gap in Incident Response
When the pressure is on, people do not rise to the level of their plan. They fall to the speed of their clarity. That’s why safety information should be easily accessible when people need it most.
Joe Heinzen is the CEO of WorldSafe, an organization that helps leaders make safety and resilience guidance more understandable, actionable, and usable before something goes wrong.
In this episode, Joe challenges the idea that documentation equals readiness. He explains why plans buried in binders and disconnected systems often fail during high-stress moments.
What you’ll hear from Joe:
- Why safety guidance should feel as accessible as a basic human need
- How cognitive overload turns complex plans into operational failure
- What the first few minutes of an incident reveal about an organization’s readiness
- Why every organization needs backup decision-makers
Transcript
(Automatically transcribed)Peter Steinfeld: Hello and welcome to The Employee Safety Podcast from AlertMedia, where you’ll hear advice from industry leaders on how to protect your people and business. I’m Peter Steinfeld.
Many organizations have emergency preparedness and incident response plans. But when a crisis is unfolding, the real test is whether people can actually use those plans, make quick decisions, and act calmly under pressure.
Joe Heinzen is the CEO of WorldSafe, an organization that helps leaders proactively manage risk, improve crisis response, and protect people and assets. Joe joins us to explain why incident response plans only work when the right people can find, understand, and act on the right information quickly.
Here’s our conversation.
Hey, Joe, thanks so much for being here.
Joe Heinzen: Thanks for having me, Peter. It’s great to be here.
Peter Steinfeld: What exactly does WorldSafe do and what problem is it trying to solve?
Joe Heinzen: World Safe helps organizations make safety and resilience understandable, actionable, and usable before something goes wrong. A lot of organizations have pieces to the puzzle. Policies, emergency plans, different technologies or training platforms.
But the information can often be fragmented or hard to operationalize under pressure. We believe safety information should be accessible to everyone in the same basic way that needs are accessible.
So food, water and shelter, we believe that those belong in that same category.
Peter Steinfeld: So it seems like there’s a lot to it. Which begs the question, why can safety, security and resilience guidance feel so hard to access for most people?
Joe Heinzen: I think unintentionally, the industry sort of speaks in layers of complexity. It can be overwhelming, it can be daunting.
You can go out with the best of intentions to figure out what best practice standards or an industry standard is to protect your people, your property or interests.
And a lot of that guidance that you would go in search of that exists, it can be buried in PDFs, compliance language, disconnected systems, or consultant terminology that doesn’t really translate operationally. So that person that’s responsible for making those decisions can often feel overwhelmed.
And often that person handed safety responsibility isn’t a full time security professional. They might be in HR or operations or facilities or on the legal team.
And we’re even seeing a dotted line from who’s responsible to technology teams like the ciso. So now you have somebody that’s trying to protect people while navigating fragmented information and sort of conflicted priorities.
That creates hesitation. And hesitation during a crisis can be catastrophic to your people, to your property, and your interests.
In addition to all that, it can also be pretty darn expensive.
Peter Steinfeld: That sounds daunting for someone who doesn’t do safety like 100% for their job. So what happens when safety responsibility lands with someone who just doesn’t know where to start?
Joe Heinzen: Well, I think that what we observe within market is that there’s really three distinct Personas. The first is someone that has a lot of experience. There might be a lot of financial commitment to that individual or that team.
They realize that in many cases that they’ve lost objectivity within that environment. They will understand fundamentally that they need to bring in another set of eyes or other people into assess what they’re doing.
But they have money, they have resources, they have people. The second is sort of a moderate range of that.
Someone with maybe lesser experience, maybe just a team of one, or they have other resources that are tied in are associated with them. And the third is what we consider to be the accidental safety owner.
It’s someone in HR or operations or facilities who might have inherited the responsibility because no one else owned it and it needed to go somewhere.
It’s someone that just really has safety, security, and resiliency just nestled under them, and they don’t know what to do, where to start, or how to get there.
One story that really stuck out with me was a leader within DRU community organization who was trying to think through school safety, community protection, communications, like public visibility, all at once. And she wasn’t lacking commitment in any way. She was overwhelmed by the weight and responsibility and ultimately unsure where to begin.
And if you’re not familiar, statistically, the Jewish community represents 2% of the total population in the U.S. but over 60% of the hate crime. And as we sat there and talked about preparedness, best practices and standards, she sort of began to rustle around below her desk and in a cabinet.
And my inner narrative as she was doing this was sort of like, my gosh, what is she doing? Like, it looked like she was picking up for something really heavy. I was like, is she picking up a dumbbell?
It looks like she’s about to, like, work, work out or something. And she. She brought up from beneath her desk this massive binder.
And as she studied it down on the desk, what this represented was all of the threats and issues that she was dealing with. And she began to cry. Wow. And we sat there and we had a conversation about the best ways to protect her community.
She had a lot that she had in front of her as a result of, you know, statistically what I just shared with you. And as we talked through the ways that she could best prepare and insulate her people, her property and her interests.
And again, part of those people were Students I began to realize that this was a really common issue. It’s more common than people might realize.
One of the biggest misconceptions in corporate security is that most organizations have someone focused on safety and resilience and they don’t. A lot of what is represented is sort of what I just shared with you.
Among the Fortune 1000 and very large enterprises, dedicated security functions are relatively common. You would expect that, right? Financial services, healthcare technology, manufacturing, critical infrastructure.
Most of them have titles that kind of usual suspects, right? Chief security Officer, VP of Security, Corporate Security Director, Global security teams, Executive protection functions.
My estimate based upon surveys from like ASIS and Gartner and stuff like that, and they’re just experience over the years, within the Fortune 100, 95% have those titles. Fortune 500 that number goes down to 85%. The Fortune 1000 probably hovering around 70%. They have that dedicated physical security function. Even here.
However, teams are often understaffed and focused on investigations, travel, security or access control rather than cultural enterprise resilience. And there’s no such thing as safe, but there is such thing as having cultural resiliency, being able to minimize a crisis and recover from it faster.
As we go into mid market, that is where the problem really becomes glaring. And that’s probably that spot between a hundred to five thousand employees.
Most mid market companies have no security leader, no dedicated physical security team, no threat assessment process or no business continuity ownership and certainly no crisis management program.
And many of these organizations security responsibilities are simply assigned to what we discussed previously Peter, which are facilities, HR ops or legal.
And you know, there’s a ASA survey that found that 40% of these companies don’t have a comprehensive active assailant program, workplace violence or just general preparedness plan within those disciplines and within those segmentations available.
So my estimate with having dedicated physical security within mid market is somewhere probably between 25 to 40%, 100 to 500 employees, probably closer to 10 to 20% smaller company, small business, under 100, less than 5%. Wow.
Peter Steinfeld: So I think what that really lends itself to is this idea that security is incredibly complex and there are a trillion shades of gray. And that’s why you can’t just put a small group of people in place that produce a widget for security. Like it doesn’t work that way.
And that’s why it has to be this cultural institutional thing that everybody takes responsibility for security in order for it to be effective. Is that a fair statement?
Joe Heinzen: I think there’s a lot of accuracy to that. And there’s also this notion that if it hasn’t happened to us, it’s not going to happen.
And you know, I think that the general principle that leaders need to understand is that there’s obviously legal liability, negligence and other things that you’re focused on. But that’s not preparedness. Preparedness isn’t just simply checking a box. It’s not creating a document that lives in a binder on a shelf.
Defining cultural resiliency is addressing it within not only your executive team, making a commitment to it, but also encouraging your middle management to cover topics of relevance in their meetings with their staff so that everyone is on the same page, marching to the same beat and hitting that drumbeat together.
Most organizations are really too large to ignore security and resilience, but too small in this mid market to justify hiring a full time security executive. And that’s the gap here. And the majority of these organizations aren’t really being negligent.
They simply don’t have the expertise or resources internally. And again, I believe that this is a basic human right.
I believe being able to keep your people, your property and your interests safe and insulated is basic. And we’ve normalized Peter, the idea that every company needs an HR leader, a finance leader or an IT leader.
Yet many of these organizations with thousands of employees have nobody responsible for physical security, crisis management or resilience.
So I believe the biggest risk facing most organizations is that they don’t have bad people managing security, is that they have nobody managing it at all. And ultimately what this comes down to is that emergencies don’t care about your org chart.
When something happens, whether it’s workplace violence, severe weather, maybe a cyber incident or an active threat, someone has to make decisions and they have to make them quickly. If nobody owns preparedness beforehand, everyone owns that crisis in that moment. And that’s what we’re ultimately trying to avoid.
Peter Steinfeld: And it seems like a lot of organizations, especially the medium sized and smaller ones, tend to say, look, I don’t have the expertise, so let’s create a binder, like you said, a checklist and stick it on the shelf. But why does that not always translate into readiness?
Joe Heinzen: Documentation and readiness are not the same thing. A plan can exist but still fail operationally, you know, if people can’t quickly understand it, access it, or really execute under stress.
There’s a study that was done and they found that during a crisis you lose a third of your higher processing ability. So readiness is ultimately about behavior. It’s about whether people know it’s whether it’s cultural for you as an organization? What’s happening?
Who’s owning the decisions? What actions come first? And can people disseminate? What are the top one, two or three things that we need to do immediately for crisis A, B or C?
And we have a saying actually preparing for everything means that you’re ready for nothing.
So understanding fundamentally what is relevant to you, what’s relevant based upon your geography, your people, what work you do organizationally, if that would make you a target in some way. So most plans are written for review and very few are written for use during cognitive overload.
Peter Steinfeld: Mm, that’s a really good way to put it. And that’s a great reminder.
When I got into this industry back in 2001, someone came up to the booth of the company I was working at and said, all right, show me what you got. But everyone’s IQ drops 20 points during an emergency, so it’s gotta be dead simple or I’m gonna walk away.
Joe Heinzen: Right.
Peter Steinfeld: And that really stuck with me over the years. It’s really true. You don’t just suddenly get dumb, you just are deer in the headlights. You’re like, I’m not sure what to do.
And you just kind of fall back to your level of training.
Joe Heinzen: Yeah, you’re right. And it’s that flight or flight mentality. You’re in survival mode.
And there’s technologies out there that can help and assist in those moments, things that cue you in that moment that identify role, responsibility and action. And that’s really what it’s about, is taking action in that moment to reduce the severity of that crisis.
Peter Steinfeld: Let’s dig in on that a bit more. So what does separate a plan that looks just awesome on paper from one that people can actually use?
Joe Heinzen: Well, I think the best plans, as we just discussed, are, you know, executable under pressure. It means that they’re simple enough to navigate during a high stress moment, clearly define ownership and prioritize action over documentation.
And I think that’s no fault to any organization. I think that they’re navigating for compliance. You get lost in the day to day blocking and tackling of service delivery.
Whatever your product or service is, that’s natural. But making the commitment to understanding that good plans really reduce thinking during the event because the thinking already happened beforehand.
So committing to a desktop exercise or a technology that will prompt and cue in that moment.
One thing I always tell leaders is, you know, if your plan requires someone to stop and interpret during a crisis, it’s probably too complicated and you’ve already.
Peter Steinfeld: Lost and that all talks back to the stress that people are under. And you don’t want them thinking too much. So how does stress really change the way people respond during a crisis?
Joe Heinzen: Stress ultimately compresses cognition. During high stress incidents, people can lose significant portion of their higher processing abilities.
They revert towards instinct, familiarity, and simplicity.
And if you haven’t defined what that instinct should be, what that familiarity should be, and what that simplicity is, they’re going to struggle in that moment. And that’s why organizations sometimes experience failures that seem irrational afterward. And it’s kind of like, gosh, what were they thinking?
And it’s not necessarily because people lacked intelligence or intent. It’s because stress changes how the brain processes information. So these plans often fail cognitively before they fail operationally.
And they might look good on paper, but if people are overwhelmed and something’s unclear or searching for information in that moment. And that’s another part of this is accessibility. Those first moments of an incident, the organization is already behind.
Peter Steinfeld: And it seems like familiarity really aids in recall.
Are you a fan of things like micro trainings where you just kind of walk around and just look to two people and some cubes in an office and say, hey, someone’s like, this is a test, but someone’s having a heart attack over there. What do you do? And just like within two or three minutes see what their response is and do they know what to do?
Is that powerful to kind of build that memory?
Joe Heinzen: So, yes, we are in favor of micro training sessions. It really depends fundamentally on what the user group looks like or the use cases.
When you’re protecting learning environments, work environments, or public environments, it’s a little bit different for each one.
So public environment might represent a concert arena or venue, or a sports arena, you know, football team or a basketball team, something along those lines. I think for each one, it’s a little different. We are actually in favor in the regular cadence of something we refer to as tune up Tuesdays.
They’re micro training sessions that are in the style of a TED talk. And it’s a 15 minute micro training session where you bring in your team to discuss a particular subject matter that might be relevant to them.
Something that happened recently geographically in close proximity to your office, something along those lines.
You’ve even had some clients really key in on the tune up portion to it and use a particular song to start out the meeting, to create engagement, to bring in that audience and getting them paying attention. Because there really is a need to be artful about communicating in this messaging.
A Lot of times it can be stagnant, it can be a little drab, and there’s a better way. And I think you’ve keyed in on that, Peter. I think that there is a great use case for inserting micro training sessions into the organization.
Peter Steinfeld: It kind of snaps people out of their paperwork mindset of, oh, it’s on paper and I’ve read it, and logically I know what to do. But when you put someone in the heat of the moment and they have to think on their feet, it’s totally different. And it goes back to what you said.
You’ve got to focus more on emotion, not logic, because emotion is really what drives people to A, buy in, but also B, be able to react when something happens. Logic, like, you’re not thinking of logical checklists when a disaster is occurring because you’re just like freaked out in the moment.
So, you know, with that in mind, what does happen in the first 15 minutes of an incident that can shape the rest of the process?
Joe Heinzen: Well, I think that there’s a segmentation that we should probably approach that first 15 minutes with Fortune 100, Fortune 1500.
I think that there’s going to be one response that takes place there mid market, which we talked about, where there can be an accessibility issue with people having access to the best standards for preparedness, for response, and for your emotions during that crisis. The first 15 minutes often determines whether an organization stabilizes or spirals.
So each one of those can look a little bit different within that profile. That early window is usually where confusion either gets contained or sort of amplified.
And it’s also where negligence and liability issues can often reside.
If you don’t communicate, for instance, that there is a crisis or an issue going on within a certain set time, and it’s a bit different based upon a variety of factors, the set time is generally around six minutes. That can create a financial liability for you as an organization. What tends to go wrong is surprisingly consistent, though.
Unclear ownership, delayed escalation, conflicting information, uncertainty around authority, or people waiting for someone else to act. Like, what the heck are we going to do right now? What is the action plan?
And once confusion sort of compounds, regaining control becomes much, much harder. And a lot of organizations think response begins when leadership convenes.
And in reality, response begins the second uncertainty enters the environment.
Peter Steinfeld: And would you say that there’s something psychological with humans where when something bad happens, we tend to want to ignore it and say it’s not happening? And that has an impact on how people respond?
Joe Heinzen: Oh, absolutely. If you’re familiar with bystander syndrome. It’s a perfect example of that. Bystander syndrome essentially will result in behavior in reflection.
That just doesn’t make sense when there’s, you know, an act that’s taking place and you really just kind of freeze and don’t know what to do. Bystander syndrome is often associated with that.
Peter Steinfeld: So with that in mind, that speaks to ownership. So what should clear ownership look like during incident response?
Joe Heinzen: I think ownership, it may seem like it goes without saying, but let’s say it anyways. Ownership needs to be explicit, distributed and resilient.
It needs to withstand not only the regular cadence of communicating it, but the regular focus of addressing it. You know, as a person or a company, an organization or a team.
I really personally believe that you should always be going through a process of perfection and refinement. What can I improve? How can I change this? How can I adapt?
One of the things that we do as an organization is when there’s an event that takes place, we debrief and we talk about what went wrong, what we have done differently. And I think every organization should be doing that. And there’s very commonly these CNN or these Fox moments in the news. And those are opportunities.
We never want those things to happen. Right, you never want them to happen.
But when they do, take a real good self assessment of where you are individually, within yourself, your team, your organization, whatever you have an area to influence or impact and ask what you might have done different. Most organizations define a primary decision maker in those moments who are which is important.
But they don’t always define what happens if that person is unavailable, overwhelmed, traveling, or directly impacted by the incident themselves. What’s the failover plan?
We have failover plans for disaster recovery from a technology standpoint, hey, if that data center goes down, you know, what’s our failover plan? Is our IP address going to failover? If there’s a hurricane in Florida, what’s our failover plan?
But I sometimes compare exactly the that moment to something similar within that technology umbrella.
The data center goes down, another system is going to take over automatically, organizationally, if that person is gone or not there or out sick that day, we need to look at that similarly. And there needs to be continuity from leadership in the understanding that someone else needs to assume that role and that responsibility.
So who owns communications, who owns accountability for people, who makes operational decisions and who comes becomes the backup in that moment. And if those answers are unclear beforehand, they’re going to be unclear in that moment. So we really need to make that a focus.
Peter Steinfeld: Yeah, that is super critical and a bit of a nuance on that. I think a mistake a lot of organizations often make is tying ownership to title.
It’s like, oh, disaster happens, CEO, and that’s not always the best thing to do. What do you think about that?
Joe Heinzen: I think that the answer is a bit nuanced, as you said. The question is it really depends on the organization. Some organizations have a reality that is much different than another organization might have.
Finding answers can be somewhat convoluted or feel convoluted.
And so one of the things that we’re doing as an organization is we’ve created a chat instance that’s steeped in the best academic research, best practices and standards.
Our team is comprised of retired Navy SEALs and things of that nature that have done like pattern of life assessments for prime ministers and public safety data scientists. And so we’ve taken all of this knowledge and we’ve inserted it into a chat instance where anyone can go from an accessibility standpoint.
Because again, tying this back into accessibility, we believe the best information, the best preparedness information should be accessible to all.
So there’s a safe environment for you to go in, ask questions, determine what might be best for you, and get some answers that will be released soon at WorldSafe Life.
Peter Steinfeld: Oh, that sounds fantastic. I really look forward to seeing that tool. I think it’s going to be super helpful to our listeners and just the general safety folks out there.
Joe Heinzen: Thank you. We’re looking forward to it as well.
Peter Steinfeld: Now, speaking of tools in general, I. How can organizations decide what they actually need before investing in safety solutions?
Joe Heinzen: Well, I think that that becomes an academic sort of. There’s a prerequisite to that, if you will.
The preface to that is that organizations should start with understanding risk with their specific risk, instead of starting with products or services or things like that.
And one of the simplest frameworks that you can do to determine this, you know, the definition of risk is threat times vulnerability times consequence equals risk.
So it’s sort of this question and this exercise you go through where, you know, a threat by itself is not enough, a vulnerability by itself is not enough. But the real question ultimately becomes is what could happen?
What’s potentially possible to happen specific to us, how exposed are we and what would the impact actually be? So it’s kind of like what’s behind that door?
And if someone got into that, how would that impact our business or our ability to deliver our product or service?
Now, if you’re a higher ed institution, someone Gets behind that door, and that’s the server room where admissions or registration for classes happens. That would be devastating to that university. So I think assessments are evolving now beyond compliance exercises.
And the better ones evaluate operational reality, human behavior, cultural resilience and communications flow, even environmental design and continuity all together. And when you define what those vulnerabilities are, you can have an honest discussion with yourself among your team.
What are the ways we’re going to mitigate this? Otherwise, you have the flip side of this where you have organizations that just end up buying technology endlessly.
You it might not even be adopted before understanding what the actual problem is that they’re trying to solve.
Peter Steinfeld: Yeah, it’s like begin with the end in mind, as Stephen Covey always said.
And I like that idea of focusing on consequence because that really transfers it from being a security focus thing to an organizational and an executive thing. If you can speak in terms of consequences, then executives say, oh, now I see how that relates to our business. Yeah, go ahead and buy that tool.
Make that investment. Hire that extra person.
Joe Heinzen: I think where organizations struggle fundamentally is why is this a business decision for us?
And if you can integrate into that vulnerability plan why you’re recommending subsequent mitigations, and you can say, here’s the cost per incident, and then this is the cost to mitigate, it becomes much easier, without a doubt.
Peter Steinfeld: Well, before we sign off, how do leaders ensure that the right safety information reaches the right people before an incident occurs?
Joe Heinzen: I think the theme of this conversation that we’ve had, Peter, has been around accessibility. I think that that is the missing link.
Organizations spend enormous time building plans, but not enough time asking whether the right people can actually access that plan or operationalize it. The information then becomes even more difficult to navigate when stress is high. Right. That’s been our theme here.
The goal should be clarity before urgency, because during a crisis, people don’t rise to the level of the plan. They fall to the speed of their clarity.
The organizations that respond well are usually the ones that have removed that friction right before the incident ever occurred. It’s not easy, but we can do this. It just has to be together. It means leveraging the resources that are available to you.
Listening to podcasts like this, talking with your peers, hey, I’m experiencing this problem. How have you dealt with that before? We really need to be a community in all of the best ways. That’s one of the biggest ways that we can solve.
A lot of the issues that you and I have discussed today is accessibility. What do you have access to how are you going to access it?
How are you going to leverage it to make it more powerful and use it as a springboard to protect your people, your property, and your interests?
Peter Steinfeld: I think that’s fantastic. Accessibility and then what you said, clarity.
The more people are clear on what they’re supposed to do and what could happen and how to do things, the more likely they’ll just jump into action and take care of business when something bad happens.
Joe Heinzen: That’s exactly right.
Peter Steinfeld: Joe, thank you so much for being on the show. A lot of tremendously helpful advice.
Joe Heinzen: Yeah, I appreciate you having me, Peter.
This was a great conversation and you know, like ultimately just to bookend things and like in closing plans don’t save people, accessibility to information does.
In a crisis, the right information has to get to the right people at the right time in a way that they can actually find, understand, and ultimately act on. Preparedness is really about making good decisions easier when it matters most.
So I thank you for having me today and I appreciate being a part and a participant in this conversation because as I said, I think it really has to be a group effort.
Peter Steinfeld: To learn more about Joe and his work with WorldSafe, click the links in the episode description. You can also watch the video Highlights on AlertMedia’s YouTube channel. Don’t forget to subscribe, rate and review the show wherever you get your podcasts. Stay safe out there.
Outro: Thank you for listening to the The Employee Safety Podcast from AlertMedia, the world’s leading provider of risk intelligence and response solutions. To learn more about how to protect your people in business during critical incidents, visit alertmedia.com.
CEO of WorldSafe

More Episodes You May Be Interested In
-
Inside Uber’s Incident Response PlanWellness checks and surveys are essential to any crisis communication plan, but what happens when an employee responds that they need assistance? In this episode, Ashley Guest, Head of Strategic and Operational Solutions for Trust and Security at Uber, explains how the company built a global support model to ensure that impacted employees receive the…
-
The Strategy Behind High-Performing Safety CulturesToo often, organizations measure safety by what went wrong instead of what must go right. Shawn Galloway, Best-Selling Author and CEO of ProAct Safety, explains how leaders can focus on the behaviors, decisions, and systems that create stronger safety performance. Shawn challenges leaders to look beyond injury rates and “let’s fail less” thinking to focus…
-
How to Build a Proactive Protective Intelligence ProgramCorporate security is at a turning point. With rising acts of violence and grievance-driven threats, protective intelligence is no longer confined to executive protection. Melissa Newberg, Global Head of Intelligence at Seerist, explains why it’s becoming the standard operating model for modern security teams. Drawing on her experience building a protective intelligence program at Meta,…




