How to Build Your Security Team’s Internal Brand
Robby Dunn-Bernstein, Head of Global Safety, Security, and Intelligence at a major technology company, believes a strong internal brand can help security teams earn greater influence and become more valuable partners to the business.
Robby shares how his team built that brand around being innovative, trusted, and reliable.
To strengthen security’s brand across the business, Robby recommends:
- Creating safety resources employees want to engage with
- Making security communications timely and relevant
- Building partnerships that bring security into conversations earlier
- Empowering team members to take ownership and innovate
Transcript
(Automatically transcribed)Peter Steinfeld: As head of global safety, security and intelligence at a prominent technology company, Robby Dunn-Bernstein is responsible for protecting employees and supporting business operations across 56 countries. He’s helped build and evolve security programs at organizations like Nike, Hulu, Warner Brothers Discovery, and the World Bank.
Today, Robby talks about creating a security function that people trust, value and support. Hey, Robby, thanks for being here.
Robby Dunn-Bernstein: Hi, Peter. Thank you for having me.
Peter Steinfeld: Now, a lot of organizations these days have a tremendous number of risks that are competing for their attention. So how do you decide where to focus?
Robby Dunn-Bernstein: I think it starts with understanding the business itself and what the most likely and impactful things are that could impact the business reputation, operations or workforce. From there, we may not have a solution for everything.
However, what I have done is built a framework that is not rigid, but is fluid and flexible that brings in the largest coalition of individuals possible to the table. Selected, of course, so that when we are ready or need to make a decision, we have the right people at the right time at the right table.
This allows us then to address any sort of issue or incident that may arise without being siloed or stuck to old SOPs and things that may be outdated or no longer as relevant as they used to be.
Peter Steinfeld: And do you evaluate that on a quarterly basis? Twice a year, annually.
What’s the frequency that you review that to make sure that you’re still on target for the things that need the most attention?
Robby Dunn-Bernstein: I think that we evaluate as needed. Things emerge throughout the day, the week, the month, the year that will take priority or precedent over other risks or threats or issues and incidents that could be impactful to the org.
Part of that means that I need to remain open and communicative with my partners and stakeholders to understand how this may impact them.
One of the things I appreciate about my role is that while I have a perception of what a risk or a threat may be, by incorporating the ideas of others, other teams, other departments, they can also then inform me what risk looks like from their end. And that gives me more information, more credibility, and more resources ultimately to help make decisions.
Peter Steinfeld: How often do you find there’s surprise on either side that you take an idea to the executive team and they’re like, nah, that’s not a risk, it’s not an issue for us. And you thought it would be, or vice versa. They bring something to you and then you say, oh, well, here’s why that’s not a big issue.
Does that happen frequently?
Robby Dunn-Bernstein: I won’t use the word frequently, but to both of those questions, taking priority risks that we have identified to C-suite or higher levels.
Throughout my career, yeah, I have seen times where somebody has said, I don’t see the risk the same way as you, or they’ve said, I do understand what you’re saying, I’m willing to take the risk because there is an appetite for that given the reward.
On the other side of that coin, we get brought things constantly where we have to either hold our tongue or say, I see that you understand this as a huge priority and a risk. However, we don’t assess it the same way.
What I’ve learned from that is that we’re service oriented, which means we still need to take into account those concerns, the considerations, the feelings that others may have and bring to us. We never want to turn somebody away.
Ultimately we want people to come to us with those sorts of issues, incidents, concerns, situations that may be to that individual, you know, a four-alarm fire.
But to us we may see it as, you know, just a little smoke, and what I perceive to be a risk, others may not, and vice versa, but to them that risk is real. So we don’t want to dampen their reality or tell them that they’re wrong, but we want to point to evidence, data, facts and help guide them.
We want to do it in a way that is supportive, constructive and consistent with a brand and reputation that we’ve created.
Peter Steinfeld: So knowing that it’s really a partnership between the security team and the people they’re protecting, what does it take for security to become a team that people want involved in the conversation?
Robby Dunn-Bernstein: This is a great question because it’s something that’s really near and dear to me about building momentum, building a strategy and a brand that’s identifiable within an organization. I think that like anything with momentum, when you’re being talked about, especially in a positive way, people want to be a part of it.
They want to collaborate, they want to find ways to partner.
And even better is if you’re not talking about yourself sharing your wins and your successes in partnerships, but when others can do it for you, I think that is going to give you the momentum you need to be looped into those conversations actively.
Peter Steinfeld: How can security teams actually build an identity that employees recognize and trust? Do you have a good story you can tell there? I do.
Robby Dunn-Bernstein: It’s a little bit of a two parter. So what it starts with is understanding that we as security are often misperceived. And so what we’ve wanted to do is build our own brand.
Good brands are recognizable, they’re trusted, they’re dependable, people know what they’re getting with it. So there is that consistency feeling.
So one of the things I did with my team when I first took over as leader of the organization is I got my leads together and we decided we’re going to have an honest, open conversation that we’re going to be calling the good, the bad and the honest. And we decided to discuss what are the things that people know about us that are positive as GSSI, global safety, security and intelligence?
What are the bad things or the not so good things that we know that we have a stigma about, or people have labeled us, but we need to change? And what’s the honest conversation here?
Do they know about the services, the capabilities, the things that we do behind the scenes that often is not talked about or seen. So through that, we also then came away with three aspirational words that we wanted our brand to be known for.
For us, it was innovative, trusted and reliable. I think these are three things that every security team, if not any brand in the world, would want to be known for.
But then what I did was I challenged my team. I said, what are you doing or what will you do to help bring about this culture and brand that we want for our team?
So moving forward, what are some of the ideas that we can actually implement or enact in order to get us there, to be talked about in a way where we seem innovative and trustworthy and reliable? A really cool product came from that. It’s something similar to one that I’ve created and brought to other companies I’ve worked for.
In this case, we called it the Incident Response Guide, the IRG.
And what’s nice about this is that it’s a QR code based website that lists out, in this PDF, a really easy to read on your phone format of all the ways to respond to incidents. Key things like earthquakes, power outages, maybe a cyber incident, active shooter, an intruder in the building, those sorts of things.
But it lays out the three to five key steps of what to do in the event of these sorts of incidents. It also provides the information for our GSOC critical contacts and local emergency. As we are a global company.
In each one of these incident response guides, we worked with branding, marketing and comms to make sure that it was extremely aesthetically pleasing, fit the culture and would be something that people wanted to see, open and talk about. Getting people to talk about this product is absolutely key.
So one of the things I’ve done every time I’ve created a similar product is built in an Easter egg so that people know that they can bring something to the table to talk about or to share it with others and go, did you see this?
So at the end of it, rather than saying there’s a power outage or something that may be related to the workplace environment, it says zombie apocalypse. Or it might say, AI has become sentient and taken over the singularity of it. It’s really kind of a fun thing to get people talking and sharing.
And when they see you in that sort of light as security, they start to think about you in a different way. It’s actually putting a more personable touch on something where security is so often seen as guards, gates, guns, you know, the authority figure, almost the corporate police in the room.
And so what we wanted to do was kind of break that spell a little bit and make it much more inviting and something that people wanted to share and talk about while still learning about the ways you respond to incidents and the resources that we can bring should there be an event that requires us in our involvement.
Peter Steinfeld: Yeah, that’s a great story. And there’s so many nuances to getting people to really buy into things.
There’s things like simplicity, like you mentioned, clarity, which is important, but also that fun aspect that you have to bring along, and that’s something that’s hard to balance. And every culture is a little bit different.
Robby Dunn-Bernstein: Fun is a good word for it. Fun and security typically don’t go together.
So we’re really trying to find ways not to just make it fun and inviting, but we want to make it part of the culture. So you really have to understand what your corporate culture is like and where you fit in.
And similarly, the messaging campaigns that you have, they should be aligned with a broader strategy across the organization, or at least timed in a way where they make sense to those that are receiving it.
So, as an example, this past summer, we wanted to coincide our messaging campaign about our services and capabilities around travel, safety, security and awareness, which included some of our trainings and resources that were available to all employees, whether it’s work, travel, or personal. This coincided with cybersecurity and infosec teams also messaging about things to keep in mind as they travel, whether it be for work or personal.
I think it was great timing on behalf of the company because everyone was focused on their upcoming travels over the summer and what they would be doing. But they got to keep in mind that safety, security, infosec and cybersecurity were all kind of there to support them as needed.
Peter Steinfeld: Yeah, that really is a good story because people were primed to receive that information, whereas if you may have shared it at a different time, they would not have been primed to receive that. So that really begs the question, like, how do you go about balancing security requirements with helping the business move forward?
Because sometimes it can feel oppressive to people.
Robby Dunn-Bernstein: This question can be answered through the lens of what is the strategy of the business organization? Working with people like comms to understand the direction that things are going really helps you hone in on your message.
And while you may not be targeting a specific audience, you are tailoring it for what the other messaging or strategy of the company may be. Back to a previous point about creating products around incidents and the potential impact that they may have. We have three products that we create.
One is for informationals, which can be something like an FYI. We are just sharing this information for your awareness. There is no impact, no perceived impact, or we are unaware of any potential impact.
A next product could be something like an alert, where we are sharing that there is in fact an impact or there is a likely impact to the business, the organization, to the workforce, or the brand reputation. A third product is called a situation.
A situation report over time will continue to expand upon the impact that is known and what it may be continuing to bring in a situation, such as a power outage or a blackout that may impact our offices or data centers, a hurricane, an earthquake where you know that might mean displaced people or that there’s an impact to the greater business. With those three, they all coincide with each other in a way where an FYI can become an alert can become a situation.
A good example of this, as we saw several years ago, was an FYI around a police involvement where a suspect had died on scene and there was a local protest that was forming shortly after. We had an alert come out at a previous company where we said there were nationwide demonstrations in response to this incident.
The situation report, which evolved and continued for many months, was then ongoing protests nationwide and even internationally that later became George Floyd’s protests and movement.
So you can see how an FYI can become an alert, can become a sit rep. And if we’re there at the start, we build this communications plan of being the central hub of information sharing that then people become invested in, that we become the reliable provider of information, of resources and capabilities, and people stop searching for it on their own and start trusting us and the reliability that we can bring in presenting information clearly and how it impacts the organization.
Peter Steinfeld: So it sounds like communication really is a vital part of what your team does on a daily basis?
Robby Dunn-Bernstein: Absolutely.
And part of that communication means that we might not understand everything and all of the needs of the organization where our stakeholders and partners are concerned, but we leave it to them to understand for their own selves what the information means to them and then share it back with us what’s important. So that flow of communication goes both ways. We have to know that it’s worth sharing where it might potentially be worth sharing.
And they have to know to pick up that rope and say, yes, this is something to tug on further. We want to know more.
Peter Steinfeld: What have you learned over the years about building strong teams and helping people grow?
Robby Dunn-Bernstein: This is one of my favorite questions because it comes back to my philosophy with my team of empowerment, not permission. I think that, like any good team, you’re playing with folks who have strengths and areas that need improvement.
And your job as a leader, as a coach, is to help not just offset those areas that may need support, but help individuals grow and develop and ultimately feel like the best possible team and combination of resources that you can bring to bear.
So what I like about this idea is that it requires me and my team to understand each other, our roles, responsibilities, but not in a siloed way where they’re categorized as yours and mine, but where we understand where we may need support, where others may not have the resources necessary to fully fulfill their mission and their roadmaps. So I like to challenge my team. I like to bring in other resources and capabilities that may not be something that typically they would use.
I like to challenge them to build relationships and partnerships so that they can leverage other resources and capabilities and services from across the organization. And I really like to watch them develop. So something that we’ve done is we’ve paid for MasterClass subscriptions for every one of the team members.
Not only do we then assign key areas where people may need a little bit of help or some extra push to get them on track with something that they may need support with, like a key skill or a learning area or opportunity, but then we also challenge them to offer it to each other. What have you learned?
What did you take away from a training or a learning or a MasterClass? Who else would benefit from this?
So it goes back to that transparency conversation that we were having, where my team is radically transparent with each other. And if somebody sees an area of growth opportunity, we share it, we lean in. And as I tell my team, these are your skills to keep.
I don’t benefit from them personally, but we as a collective mind do, so we want you to go out and take those trainings. We want you to lean in, to grow your own role, to own the role. That doesn’t mean that you’re alone or that it’s only siloed into your category.
What it means is that by owning your role, you have buy-in, you become more consistent, you become more creative within your space. And ultimately that means that you should be shaping your own roadmap and telling me what happens and comes next.
We want them as teammates to tell us this is where we should be headed. So once they see a grander strategy or vision for the team, it’s that ownership component that allows them to take it where they want to go.
And we, as supportive leaders, should be guiding them, not letting them run completely free, but being a good sounding board. We should not always be the director. We should know the direction we’re going, but the map is not the terrain.
And as the director or the leader or the CSO, you’re not always going to understand the lay of the land the same way that people will who are boots on the ground or closer to the subject.
Peter Steinfeld: So basically give people a North Star and then push them out of their comfort zone a little bit to challenge them. What’s the feedback you get from your team members that live this life with you?
Robby Dunn-Bernstein: It’s been great so far, actually. I think that more than anything, they feel there’s an authenticity about it. They get to be themselves, they get to experiment.
They also understand, which is critical, that I have their back. They’re allowed to take risks, and that’s important if you want to be innovative, as the team does.
And as stated in the branding conversations that we’ve had, you need to take some level of risk. I’m also there to help guide them along that journey of what level of risk is acceptable and be a little bit of that sounding board to say to them.
Have you considered this? Do you think that this is the most likely outcome? What happens if… So it’s really part of that guiding.
It’s not full ownership, but at the end of the day, I want them to feel empowered. I want them to own it, and I want them to create what happens next.
Peter Steinfeld: Robby, thank you so much for being on the show. I really enjoyed your insights. The good, the bad and the honest. I’m going to start saying that now instead of the ugly. I love that.
Robby Dunn-Bernstein: Appreciate it. Thank you very much for having me, Peter.
Peter Steinfeld: To learn more about Robby, click the links in the episode description. You can also watch the video highlights on AlertMedia’s YouTube channel. Don’t forget to subscribe, rate and review the show.
Wherever you get your podcasts, stay safe out there.
Outro: Thank you for listening to The Employee Safety Podcast from AlertMedia, the world’s leading provider of risk intelligence and response solutions. To learn more about how to protect your people in business during critical incidents, visit alertmedia.com.
Head of Global Safety, Security, and Intelligence in the Technology Industry

More Episodes You May Be Interested In
-
The Information Accessibility Gap in Incident ResponseWhen the pressure is on, people do not rise to the level of their plan. They fall to the speed of their clarity. That’s why safety information should be easily accessible when people need it most. Joe Heinzen is the CEO of WorldSafe, an organization that helps leaders make safety and resilience guidance more understandable,…
-
The Strategy Behind High-Performing Safety CulturesToo often, organizations measure safety by what went wrong instead of what must go right. Shawn Galloway, Best-Selling Author and CEO of ProAct Safety, explains how leaders can focus on the behaviors, decisions, and systems that create stronger safety performance. Shawn challenges leaders to look beyond injury rates and “let’s fail less” thinking to focus…
-
Intelligence-Led Security in an Age of Information OverloadHaving more intelligence does not guarantee better security decisions. Mike Evans, Director of the Risk Intelligence Center at Securitas Risk Intelligence, explains why organizations often struggle to turn growing volumes of threat data into meaningful action. Mike shares how intelligence-led security helps organizations move from reactive reporting to proactive decision-making. He also explains why context,…




