The CSO’s New Requirement: Tools That Work Beyond the Guard Booth
Trackforce
August 6, 2026 · 12 min read

At a recent industry event, David Fortino, head of corporate security at New York Blood Center Enterprises, put a question to the vendors in the room that should reframe how every security software provider thinks about their product roadmap:
“How are you going to make my life easier as a CSO? That is what I’m looking for from a vendor. I’m looking for a tool that will help the entire enterprise, not just physical security.”
That line appears in SIA’s 2026 Security Megatrends report, but it could just as easily have come from our own recent webinar, “From Badge to Boardroom,” with Todd Kreisher, a 27-year Secret Service veteran and former CSO of a global automotive manufacturer. Todd spent an hour with Jeff DiDomenico walking through exactly what Fortino is describing: what happens when a security incident stops being a security-only problem the moment it’s reported.
Key takeaways
- CSOs are now buying for the enterprise, not for security.
The purchasing question has shifted from whether a platform can log an incident to whether it can get that incident to the department that owns the fix. - The most valuable incidents often are not security incidents.
A pattern of truck turnarounds logged by security turned out to be a logistics problem worth real money, and it only surfaced because the data left the security system. - Generic categories destroy the signal.
A break room lunch theft and 50 stolen catalytic converters are both “theft”. Only one needs to reach production planning within the hour. - Five departments touch a single serious incident.
HR, Legal, IT, Risk and the executive team each need a different slice, not the whole security report. - Data ownership is an evaluation criterion, not a footnote.
If your incident history and reporting configuration leave with your service provider, you never owned your own operating record.
The incident that wasn’t a security incident
Early in the webinar, Todd told a story from his time as a manufacturing CSO. His team was running trailer inspections as part of a CTPAT compliance requirement, comparing bills of lading against actual loads. Through good incident reporting, he noticed something: trucks were turning around far more often than they should have been.
His words: “I also started to realize, that’s not really a security incident. I mean, it wasn’t a security topic, it was a business topic, it was a logistics topic.”
With that data in hand, Todd didn’t file it away in a security report nobody else would read. He took it to the logistics department and the executive team, and together they fixed the process, saving the company real money along the way.
That’s the whole argument in miniature. The incident was logged by security. The fix belonged to logistics. The value went straight to the P&L. If the data had stayed locked inside a security-only system, none of that would have happened. Spotting it at all required reporting across sites and months rather than a stack of individual incident forms.
One incident, five departments
Todd’s most direct example of this came from something as ordinary as a theft report. As he put it:
“Theft. Well, was it theft of somebody’s lunch out of the break room? Or was it theft of 50 catalytic converters that was going to impact production?”
Both are technically “theft”. Only one of them needs to reach production planning, risk management, and possibly law enforcement within the hour. Without a system built to capture that level of detail, and route it to the right people, a CSO is stuck choosing between generic categories that tell nobody anything or a flood of noise that buries the incidents that matter.
Scale that same idea across a corporate security operation and the list of stakeholders touching a single incident report gets long fast:
- HR: when an incident involves an employee investigation or workplace violence concern
- Legal: when there’s liability exposure or a compliance obligation
- IT: when access credentials need to be revoked or an insider threat is suspected
- Risk and insurance: when a claim needs to be filed or a pattern needs to be flagged before it becomes a bigger loss
- Executive leadership: when the incident touches business continuity or brand risk
Todd made the same point about relationships, not just data: “Key internal partnerships with HR, legal, compliance department, the IT department… that’s a pretty critical partnership for this corporate security team.” He also described a former CFO who once asked him, half seriously, whether the company even needed a formal crisis management team anymore, because incidents at his facility so rarely escalated into one. That’s what happens when the right information reaches the right department before a small problem becomes a big one. Getting there in practice usually means integrations into the systems those departments already live in, rather than asking five teams to learn a security tool. There is a fuller walkthrough of that in our guide to integrating physical security into the enterprise stack.
The industry agrees this is no longer optional
SIA’s 2026 Security Megatrends report names this shift outright as Megatrend 3, “Security Solutions Lose Their Boundaries,” describing an industry-wide move from siloed physical security systems toward platforms that connect security data with IT, facilities, and operational systems.
Tara Dunning, vice president of converging technology at Wesco, frames it this way in the report: “Our industry’s boundaries are rapidly vanishing. Convergence across all technology stacks allows us to provide unified insights and control across the business ecosystem, which leads to safer, more efficient, more sustainable and more resilient enterprises.”
Read Fortino’s quote, Dunning’s quote, and Todd’s truck turnaround story together, and a pattern emerges. Buyers are no longer asking whether a security platform can log an incident. They’re asking whether it can get that incident to the people across the enterprise who need to act on it, in a format they can actually use. That is a change in what enterprise security teams are being asked to deliver, and it lands squarely on the tooling.
What this means for how you evaluate incident reporting
If you’re a CSO or security director sitting through your next platform evaluation, a few questions from Todd’s own experience are worth asking directly:
- Can incident categories be customized enough to separate a break room theft from a production-impacting theft, or will everything get lumped into one generic bucket?
- If your service provider changes, does your incident history and reporting configuration go with them, or does it walk out the door?
- Can HR, Legal, IT, and Risk get the specific piece of an incident they need without wading through a full security report that wasn’t built for them?
- Does your platform support the kind of real-time dashboard access that lets your team spot a pattern, the way Todd’s team spotted a logistics problem hiding inside a security log?
How those four questions get answered in practice
Those are the right questions to put to any vendor, including us. Here is how each one maps onto TrackTik, so you have something concrete to compare against:
- On category granularity. Incident reporting uses configurable types and guided fields, so a break room theft and a production-impacting theft are different records rather than the same bucket, and each carries time-stamped photo, video and GPS evidence.
- On data ownership. This is the one to get in writing from anyone. TrackTik supports data replication out to your own warehouse and connectors into Power BI and Tableau, so the operating record sits somewhere you control rather than only inside a vendor’s system.
- On giving each department its own slice. Shareable, role-appropriate views mean HR, Legal, IT and Risk receive the part they need, and ReportPro AI generates executive summaries so a board-level reader is not handed a full field report.
- On spotting the pattern. Business intelligence is where a truck-turnaround anomaly becomes visible, with a drag-and-drop dashboard builder rather than a report request queued with a vendor. Where alarms, video and dispatch also need to sit together, the Command Center consolidates them into one workspace.
The honest framing is that no platform removes the need for the internal partnerships Todd describes. Tooling makes the handoff possible; the relationship with HR, Legal and IT is what makes it happen. If you are building those relationships now, the challenges corporate security managers run into and how teams align around the wider security ecosystem are both worth reading alongside this.
Hear the full conversation
Todd’s webinar with Jeff DiDomenico covers a lot more ground than we can fit into one post, including how he built direct ownership of his incident data during a service provider re-bid, how he turned a company with no security culture into one where officers were treated as trusted teammates, and how he thinks CSOs should be evaluating AI-driven technology without getting swept up in the hype.
Watch the full on-demand webinar, From Badge to Boardroom, to hear Todd’s complete story in his own words. If you would rather see how the security operations side works against your own estate, you can book a TrackTik demo.
Frequently Asked Questions
Latest Articles
Featured Resources
See Trackforce in action
Book a walkthrough with our team and see how it fits your operation.












