How to Earn Employee Trust in Corporate Security
Trust is the foundation of every strong security program, according to Joella Dunn-Bernstein, Head of Security at an innovative aviation company. Joella draws on her experiences in intelligence and security operations at organizations like World Bank to explain how risk leaders can build security cultures that empower employees.
Joella shares practical advice for communicating risk in ways that resonate with workers and how to create an environment where employees feel safe and secure, no matter where they work.
In this episode, you’ll learn how to:
- Tailor risk communication to different audiences for greater impact
- Build trust by making security a partner instead of an enforcer
- Adapt security programs to match organizational culture and priorities
Transcript
(Automatically transcribed)Peter Steinfeld: Hello and welcome to The Employee Safety Podcast from AlertMedia, where you’ll hear advice from industry leaders on how to protect your people and business. I’m Peter Steinfeld.
Joella Dunn-Bernstein has spent her career guiding leaders through information overload and translating data into action.
She’s worked in intelligence and security operations roles supporting the World bank and Fortune 50 organizations, and now serves as head of security for an innovative aviation company.
Today, she shares how leaders can build trust, communicate risk effectively, and create security cultures that empower their people. Here’s our conversation. Hey, Joella, thanks for being here.
Joella Dunn-Bernstein: Hi, Peter. Thanks for having me today.
Peter Steinfeld: So what first drew you into the security and intelligence field?
Joella Dunn-Bernstein: So, I am from New Jersey originally. I was 12 when 9, 11 happened. And so that was a really big moment for me, like it was for a lot of other Americans. Right.
It made me realize how important it was to think about risk and prevention and how do I protect people? So that journey eventually led me into corporate security, where I found I can make a real difference in people’s daily lives.
Peter Steinfeld: Well, that’s great. You took something that was so awful and turned it into a career where you could help people.
I’ve talked to a lot of folks in the past that have done something very similar, and it’s fantastic to hear that you kind of of shaped your career in life based on that incident. Could you share an early moment or perhaps an incident that made the realities of security work feel tangible to you?
Joella Dunn-Bernstein: In 2017, I was working in the Global Security Operations center at the World bank as a watch officer. Hurricane Ria, which was a Category 5 hurricane, stranded two of our folks at a coastal hotel in Dominica. When communications were lost.
Post impact, we tried to, you know, make contact communication, continuously monitor open sources and social media, hoping to see whether or not their hotel had been damaged like the rest of the island was severely impacted.
I managed to scour social media, and we eventually found aerial footage confirming that the hotel was very heavily damaged but still standing, giving us hope that those folks had actually survived this really deadly storm. So once contact was reestablished during the following shift, we were able to coordinate their evacuation.
And that really, really crystallized for me, you know, why this work matters or the impact that it can have because it’s not abstract or theoretical. You know, lives depend on that preparation, the communication, and the ability to adapt when those things go wrong.
Peter Steinfeld: Absolutely. That’s a fantastic story. So how has your, I would say, really deep intelligence background shaped the way that you approach security leadership?
Joella Dunn-Bernstein: I started to think in layers and probabilities rather than certainties. And so you’re always working with incomplete information and intelligence. And so you have to ask, what are we missing? What assumptions are we making?
How confident are we really in this answer or this analysis? And so that mindset translates directly into security leadership.
So when I’m assessing a program or I’m assessing a risk, I’m not looking for one answer.
I have to ask hard questions, I have to triangulate information and I have to help leaders understand what we know, what we don’t know, and where we need to be cautious.
Peter Steinfeld: And what’s the feedback you get from the leaders that you report to when they start seeing all these questions that you’re asking? How does it make them feel? How do you manage that situation?
Joella Dunn-Bernstein: Sure, it entirely depends on the leader. So you have some leaders that are more security minded and so they’ll understand where you’re coming from.
You’ll have some where, you know, they’ve never really had to think about security up until now. And so you get some pushback on. Well, is that really necessary? Right. And that’s totally understandable.
So it’s just a matter of who is the leader, kind of what they’ve dealt with before with security experiences and how do you justify what you are talking to them about.
Peter Steinfeld: Interesting. And as you join an organization, does that change how you approach what you’re going to do next as you try to build it out and improve it?
If you’ve got someone who’s highly receptive, you’re like, great, off to the races, I’m going to do this stuff. If not, you slow down and you say, wait a minute, we’ve got some cultural stuff to do here.
Joella Dunn-Bernstein: Oh yeah, the culture thing is really difficult. You think it’s easy?
You’re one of the lucky ones who kind of, you know, the organization loves everything that they do or you’re seriously underestimating the culture piece. Right.
I’ve seen a lot of security leaders try to impose programs without understanding the unique culture, risk tolerance, priorities, the people that they’re protecting. There is absolutely no one size fits all approach.
So you need to figure out how to get folks on board, understand what risks they’re willing to tolerate, and know what their actual priorities are, not what you think they should be. Which is hard sometimes. Right. People outside of our profession do not see things the same way that we do, at least initially.
So your strategy will need to be different from each organization you work with. And depending upon the organization, it might need to be a different approach. With each individual team.
Peter Steinfeld: Yeah, I can imagine that if you come in from the outside and just try to impose some program in a place where they’re not ready to receive it, it can make them feel pretty disconnect from the overall security program. What happens when that happens?
Joella Dunn-Bernstein: I think that the signs can be really clear for some of that stuff. You know, the lack of reporting security concerns. You have low participation in training or security initiatives.
You have a general sense that security is something that is done to them rather than something that they are actively a part of. They don’t understand how their own behavior influences risk. And that creates a big problem for an organization.
And you’ll see skepticism when security makes policy changes rather than just understanding, hey, this is for our best interest. Right.
When issues arise, people also might not come to security either because they don’t understand security’s role and functions, or they don’t think that security has their back.
Peter Steinfeld: It’s almost like people start sensing a fear when it comes to security and their interaction with them as opposed to, hey, we’re all on the same team here.
Joella Dunn-Bernstein: Absolutely. And I think that when you’re interacting with people in, you know, an organization, there’s a lot that informs decisions. Right.
So sometimes it’s trauma, sometimes it’s fear, sometimes it’s a want, whatever the case may be.
But for the ones that are fear based, it is something that usually they’ve had a really negative interaction with security before or they’ve brought something to security’s attention before, maybe in a different organization and security judged them for it or scolded them for it rather than be the person there to help them take that off of their plate so that that person can go back to doing their job and security can handle the rest. Each organization or each team in each organization has the amount of risk that they’re willing to either take on or be comfortable with or avoid.
Right. In most corporations, unsurprisingly, teams like security, legal, HR are very risk averse and so the rest of the company might not be.
So one of the things that you need to pay attention to when building this culture is how are you communicating risk to each of those organizations or each of those team within that organization. People can be really selfish and they tend to care more when they see how risk directly impacts them.
And so like I said, some teams are more risk averse, some teams are more risk tolerant when it comes to their organization and the work that they’re doing.
Peter Steinfeld: Communicating risk to employees can be difficult. So what do security leaders tend to get wrong when they’re trying to communicate that risk to employees.
Joella Dunn-Bernstein: If you tell someone about like a vague threat without explaining what it means for their job, they tune out. Like I said earlier, you know, people are selfish.
They only care about how risk can impact them and they have an understanding of what is important to them. That might be different from your understanding of what is important from a security perspective.
If you tell that same person, hey, I am seeing this particular threat vector targeting people in your role and it’s actually leading to financial loss and IP theft, they will understand the risk better because you’ve empowered them to understand why this risk doesn’t just impact what they’re doing, but maybe the company as a whole or the security posture as a whole.
Peter Steinfeld: Yeah, that’s a really good point. That you should not ignore the fact that just naturally as humans, we tend to be a bit selfish.
We’re involved in our own worlds, we have our own jobs to do, we’ve got stresses and things like that. So use that to your advantage. Don’t ignore it. Don’t just impose your will on someone.
Explain personally to them why it matters and it’s going to resonate so much more.
Joella Dunn-Bernstein: Absolutely. Some of those folks are more story driven with some of those examples. Some folks are more data driven.
You just have to find out what that person really responds to and get them to understand it in that way.
Peter Steinfeld: Where do security communications commonly break down?
Joella Dunn-Bernstein: I think when they’re too sterile, if they don’t need to be. I think when they’re condescending, when they’re lengthy, which I am totally guilty of that last one.
If there’s like a really detailed process involved that I want everyone to understand, I find that it helps to work with your company’s communications team so that it not only fits the branding, vibe, culture aspect of the company, but comms will also assist with rolling out what you want to convey to the entire company and will often suggest better ways to communicate it well.
Peter Steinfeld: When an organization is growing or just changing quickly, how should leaders think about building their security programs?
Joella Dunn-Bernstein: You need to think about programs that can mature alongside the business. So sometimes you’re not implementing policies just once. You are constantly reassessing and adapting, which can be really frustrating.
The approach though, isn’t really fundamentally different from building security programs in stable environments or more established environments. You’re just doing it more frequently and with more agility. You have to assess company direction, priorities and risk appetite regularly.
The risk is, you know, if you’re doing it too often, you’re Consuming time and resources. Again, it can be really frustrating if you’re not doing it enough. You are out of sync with the business and potentially compliance requirements.
And so that’s something that you need to constantly be thinking about. In an environment that changes quickly, is.
Peter Steinfeld: There a rule of thumb on how frequently you can push change? Is it like once a quarter, once a year? Once every five years?
Outside of, obviously, a massive change that would require an immediate change to the program.
Joella Dunn-Bernstein: In every organization I’ve been a part of, it’s been very different. Some are willing to adapt or able to adapt really quickly.
Others, it will take several months to get something through, through different internal processes in order to go live or go the route that we need to in order to implement something.
Peter Steinfeld: Okay.
And I can assume that whatever it is you do, you always have to start with the why, as the saying goes, and help people understand, like, why you’re doing this change.
Joella Dunn-Bernstein: That is correct, yes.
Peter Steinfeld: In your experience, what are the earliest signs that a security culture is actually working and clicking trust.
Joella Dunn-Bernstein: You know, people are reporting security concerns to your team proactively and not just when there’s a crisis.
Teams are involving security when actually needed on new projects or ideas that they have, rather than treating security as a box to check at the end.
Most importantly, people trusting security when we make recommendations or implement policy changes, you know, they’re not assuming that we’re being obstructive or paranoid. You know, they think, hey, if this is something that they’re doing, there must be a good reason behind it.
Peter Steinfeld: Yeah, that trust is so crucial. And I’ve had different folks on the show that talk about different ways to do that.
Oftentimes they’ll say, when someone is new to an organization, like, they spend time with security early on, so they see them as a friend and part of the team, as opposed to just this guard in the corner looking at them with a skeptical eye and then just involving them in any kind of decisions moving forward where it makes sense. And that can really build that trust. Do you agree with those things? Are there other things that you do to establish trust?
What else can you say on that topic?
Joella Dunn-Bernstein: So I think there is a few things. One, you do need to get on the ground and speak with your people.
You need to understand how your security organization works, if there’s one that already exists in the organization that you’re joining. I think it’s also really important to spend time with executive leadership.
I don’t think that there are a lot of organizations out there where security is necessarily at the forefront of the mind of some executives.
And so it is important to make sure that you are getting time with them early on to let them know, hey, security isn’t just, you know, these guards, gates and guns kind of a thing. I want you to be able to trust me.
I want you to be able to come to me with any concern, give me a tall at 2 o’ clock in the morning when you know something is on your mind, I will be there for you to answer it. And if I don’t know the answer, I will figure it out. And so I think that that is really important.
Like I said, boots on the ground, making sure that you’re understanding how the organization actually operationally works and then also making sure that you’re talking to leadership. Because I think that that’s where a really big gap happens in some of these larger organizations a lot of the time.
Peter Steinfeld: Yeah. Ultimately your job at Security, I would say, is to just enable people to be more productive and do more of what they do.
Joella Dunn-Bernstein: I want people to feel capable and supported after interacting with security at any level in an organization. I want them to feel like they aren’t being judged if they did something wrong or bring something to our attention.
I want people to feel like there’s a team of people who understand the risks their organization faces, you know, the realities of human nature, and make sure that we have their back.
People should feel really informed and confident after meeting with Security and convinced that security is genuinely interested in making their jobs easier, not harder. Like I said earlier, trying to take that risk off of their plate so they can go back to doing what they love to do in their job.
Peter Steinfeld: You know, that’s interesting. People seem to be overloaded with information, but it’s important to keep them up to speed on the risks that are facing them.
So how do you balance that? Like letting people know about, hey, here’s some risks you should be aware of, but not bombarding them like three times a day.
With the latest update, I think there’s.
Joella Dunn-Bernstein: Three ways to really approach this.
The first would be, you know, in person, one on one, maybe talking with someone, if you’re comfortable with a person, if they’re comfortable with security, or, you know, if it’s something that may not be too serious of a risk, that you don’t need to put it into writing, but you want to just give them a heads up like, hey, I got your back.
I noticed this sort of thing, and I want to make sure that you understand this thing here so that way you can keep an eye out for it, and if it’s something that you have seen or might experience, like, please come talk to me about it. Right.
I think the second one is, you know, if it’s serious enough that it needs to be put into writing and documented, you know, I’ll notify the appropriate parties that way.
And then the third thing would be notifying the entire company, whether that’s via email, and making sure that they understand what the threat vector is or what the risk is and any actions that they may or may not need to take as a result of it.
Sometimes it’s, you know, making sure that everyone knows in all hands where they can engage with you and ask questions, where you can allay any sort of fears or you can explain things a little bit more. That might be kind of harder to do in an email.
Peter Steinfeld: Just in general, how do you want people to feel after interacting with a very strong security program?
Joella Dunn-Bernstein: I want them to feel empowered. I want them to come away from meeting with security and being like, you know what? I’m really glad that I said something. You know what?
I’m really glad that I met with that security person, because I feel better about something that had been bugging me or something that I thought was kind of suspicious but wasn’t really sure what to do about it, or, you know, hey, I noticed something, and I’m, like, really proud of myself for saying something. And so I want people to feel empowered. I want them to feel like security is a shared responsibility.
I want them to feel like they’ve done something to better their organization.
Peter Steinfeld: A lot of security teams will keep metrics on the different kinds of things they’re tracking throughout the day, how they protect the organization. Is that a metric you would add, like, how many times people have come to the security team and said, hey, guys, thank you.
Like, that really helped me out there.
Joella Dunn-Bernstein: In one of my old roles. We actually used to keep a binder of when people would thank security or, like, share, like, a really positive impact that security had on them.
And while it was never an official metric, it was something that was really nice for us to have and kind of look back on. I think a lot of stuff with security is, you know, it’s sometimes a thankless job, right? You always need to be on.
You can’t really miss anything because when you miss something, that’s when security gets scrutinized.
And so I would say that it would be a very nice metric to have and something that I think I’ll consider as I move forward in my career to have that officially be part of the metric. I think that’s great.
Peter Steinfeld: Yeah. I think it’s so important because it is a really negative role if you think about it.
It’s, you know, when bad stuff happens, that’s when security pops in and no one’s happy about it while it’s happening. But if you can get those great stories, it could be an amazing morale booster for the team.
Joella Dunn-Bernstein: Absolutely.
Peter Steinfeld: Before we wrap up, any final thoughts you want to share with the audience?
Joella Dunn-Bernstein: Yes. Please advocate for your team. I know that this is easier said than done.
In my early professional years, I was constantly told that security operates silently in the background and that it’s expected that people don’t hear from you unless something goes wrong or there’s a failure somewhere. I fully disagree with that philosophy at this point.
And no one knows your team’s capabilities like you do you know your strategic thinking or the threats you prevented? Right. You need to evangelize and promote what’s corporate security does tell the story of what you’ve prevented.
Help leadership understand the security investment isn’t a cost center, it’s a risk mitigation engine. Your people deserve to know that they’re protected by confident and thoughtful security leaders. And your security team deserves to be seen.
So get out there, build relationships and be visible.
Peter Steinfeld: Well, Joella, thank you so much for being on the show. A lot of great advice.
Joella Dunn-Bernstein: Thank you so much for having me, Peter.
Peter Steinfeld: To learn more about Joella, click the links in the episode description. You can also watch the video Highlights on AlertMedia’s YouTube channel. Don’t forget to subscribe, rate and review the show wherever you get your podcasts. Stay safe out there.
Outro: Thank you for listening to the The Employee Safety Podcast from AlertMedia, the world’s leading provider of risk intelligence and response solutions. To learn more about how to protect your people in business during critical incidents, visit alertmedia.com.
Head of Security

More Episodes You May Be Interested In
-
The Information Accessibility Gap in Incident ResponseWhen the pressure is on, people do not rise to the level of their plan. They fall to the speed of their clarity. That’s why safety information should be easily accessible when people need it most. Joe Heinzen is the CEO of WorldSafe, an organization that helps leaders make safety and resilience guidance more understandable,…
-
Intelligence-Led Security in an Age of Information OverloadHaving more intelligence does not guarantee better security decisions. Mike Evans, Director of the Risk Intelligence Center at Securitas Risk Intelligence, explains why organizations often struggle to turn growing volumes of threat data into meaningful action. Mike shares how intelligence-led security helps organizations move from reactive reporting to proactive decision-making. He also explains why context,…
-
The Strategy Behind High-Performing Safety CulturesToo often, organizations measure safety by what went wrong instead of what must go right. Shawn Galloway, Best-Selling Author and CEO of ProAct Safety, explains how leaders can focus on the behaviors, decisions, and systems that create stronger safety performance. Shawn challenges leaders to look beyond injury rates and “let’s fail less” thinking to focus…




