Nobody goes to work in the morning thinking they are going to make a decision that causes a company-wide security alert, and ends up in the newspaper.
A decision gets made in a few seconds. Most of the time, nothing happens. Occasionally, the consequences travel much further.
Travelodge recently provided a very public example. The hotel chain came under scrutiny after incidents in which unauthorised people were given access to guests’ rooms. In one case, a man was reportedly given a room key after falsely claiming his girlfriend was in distress, without the necessary verification taking place.
The consequences extended considerably beyond the reception desk.
Travelodge subsequently reviewed its security procedures, tightened room-access controls, audited secondary locks and began retraining more than 12,000 employees. On 20 August, chief executive Joanna Boydell resigned amid the wider fallout.
The Guardian reported on the incidents, Travelodge’s response and the subsequent resignation.
This is not really a story about one hotel company.
It is a particularly visible example of a problem every large organisation faces: security policies may be created centrally, but thousands of individual security decisions are made every day by people operating far away from the people who wrote them.
The distance between a five-second decision and a company-wide security alert can be surprisingly short.