The CSO’s New Requirement: Tools That Work Beyond the Guard Booth

The Trackforce Team

Trackforce

August 6, 2026 · 12 min read

Featured image for The CSO's New Requirement: Tools That Work Beyond the Guard Booth

At a recent industry event, David Fortino, head of corporate security at New York Blood Center Enterprises, put a question to the vendors in the room that should reframe how every security software provider thinks about their product roadmap:

“How are you going to make my life easier as a CSO? That is what I’m looking for from a vendor. I’m looking for a tool that will help the entire enterprise, not just physical security.”

That line appears in SIA’s 2026 Security Megatrends report, but it could just as easily have come from our own recent webinar, “From Badge to Boardroom,” with Todd Kreisher, a 27-year Secret Service veteran and former CSO of a global automotive manufacturer. Todd spent an hour with Jeff DiDomenico walking through exactly what Fortino is describing: what happens when a security incident stops being a security-only problem the moment it’s reported.

Key takeaways

  • CSOs are now buying for the enterprise, not for security.
    The purchasing question has shifted from whether a platform can log an incident to whether it can get that incident to the department that owns the fix.
  • The most valuable incidents often are not security incidents.
    A pattern of truck turnarounds logged by security turned out to be a logistics problem worth real money, and it only surfaced because the data left the security system.
  • Generic categories destroy the signal.
    A break room lunch theft and 50 stolen catalytic converters are both “theft”. Only one needs to reach production planning within the hour.
  • Five departments touch a single serious incident.
    HR, Legal, IT, Risk and the executive team each need a different slice, not the whole security report.
  • Data ownership is an evaluation criterion, not a footnote.
    If your incident history and reporting configuration leave with your service provider, you never owned your own operating record.

The incident that wasn’t a security incident

Early in the webinar, Todd told a story from his time as a manufacturing CSO. His team was running trailer inspections as part of a CTPAT compliance requirement, comparing bills of lading against actual loads. Through good incident reporting, he noticed something: trucks were turning around far more often than they should have been.

His words: “I also started to realize, that’s not really a security incident. I mean, it wasn’t a security topic, it was a business topic, it was a logistics topic.”

With that data in hand, Todd didn’t file it away in a security report nobody else would read. He took it to the logistics department and the executive team, and together they fixed the process, saving the company real money along the way.

That’s the whole argument in miniature. The incident was logged by security. The fix belonged to logistics. The value went straight to the P&L. If the data had stayed locked inside a security-only system, none of that would have happened. Spotting it at all required reporting across sites and months rather than a stack of individual incident forms.

One incident, five departments

Todd’s most direct example of this came from something as ordinary as a theft report. As he put it:

“Theft. Well, was it theft of somebody’s lunch out of the break room? Or was it theft of 50 catalytic converters that was going to impact production?”

Both are technically “theft”. Only one of them needs to reach production planning, risk management, and possibly law enforcement within the hour. Without a system built to capture that level of detail, and route it to the right people, a CSO is stuck choosing between generic categories that tell nobody anything or a flood of noise that buries the incidents that matter.

Scale that same idea across a corporate security operation and the list of stakeholders touching a single incident report gets long fast:

  • HR: when an incident involves an employee investigation or workplace violence concern
  • Legal: when there’s liability exposure or a compliance obligation
  • IT: when access credentials need to be revoked or an insider threat is suspected
  • Risk and insurance: when a claim needs to be filed or a pattern needs to be flagged before it becomes a bigger loss
  • Executive leadership: when the incident touches business continuity or brand risk

Todd made the same point about relationships, not just data: “Key internal partnerships with HR, legal, compliance department, the IT department… that’s a pretty critical partnership for this corporate security team.” He also described a former CFO who once asked him, half seriously, whether the company even needed a formal crisis management team anymore, because incidents at his facility so rarely escalated into one. That’s what happens when the right information reaches the right department before a small problem becomes a big one. Getting there in practice usually means integrations into the systems those departments already live in, rather than asking five teams to learn a security tool. There is a fuller walkthrough of that in our guide to integrating physical security into the enterprise stack.

The industry agrees this is no longer optional

SIA’s 2026 Security Megatrends report names this shift outright as Megatrend 3, “Security Solutions Lose Their Boundaries,” describing an industry-wide move from siloed physical security systems toward platforms that connect security data with IT, facilities, and operational systems.

Tara Dunning, vice president of converging technology at Wesco, frames it this way in the report: “Our industry’s boundaries are rapidly vanishing. Convergence across all technology stacks allows us to provide unified insights and control across the business ecosystem, which leads to safer, more efficient, more sustainable and more resilient enterprises.”

Read Fortino’s quote, Dunning’s quote, and Todd’s truck turnaround story together, and a pattern emerges. Buyers are no longer asking whether a security platform can log an incident. They’re asking whether it can get that incident to the people across the enterprise who need to act on it, in a format they can actually use. That is a change in what enterprise security teams are being asked to deliver, and it lands squarely on the tooling.

What this means for how you evaluate incident reporting

If you’re a CSO or security director sitting through your next platform evaluation, a few questions from Todd’s own experience are worth asking directly:

  • Can incident categories be customized enough to separate a break room theft from a production-impacting theft, or will everything get lumped into one generic bucket?
  • If your service provider changes, does your incident history and reporting configuration go with them, or does it walk out the door?
  • Can HR, Legal, IT, and Risk get the specific piece of an incident they need without wading through a full security report that wasn’t built for them?
  • Does your platform support the kind of real-time dashboard access that lets your team spot a pattern, the way Todd’s team spotted a logistics problem hiding inside a security log?

How those four questions get answered in practice

Those are the right questions to put to any vendor, including us. Here is how each one maps onto TrackTik, so you have something concrete to compare against:

  • On category granularity. Incident reporting uses configurable types and guided fields, so a break room theft and a production-impacting theft are different records rather than the same bucket, and each carries time-stamped photo, video and GPS evidence.
  • On data ownership. This is the one to get in writing from anyone. TrackTik supports data replication out to your own warehouse and connectors into Power BI and Tableau, so the operating record sits somewhere you control rather than only inside a vendor’s system.
  • On giving each department its own slice. Shareable, role-appropriate views mean HR, Legal, IT and Risk receive the part they need, and ReportPro AI generates executive summaries so a board-level reader is not handed a full field report.
  • On spotting the pattern. Business intelligence is where a truck-turnaround anomaly becomes visible, with a drag-and-drop dashboard builder rather than a report request queued with a vendor. Where alarms, video and dispatch also need to sit together, the Command Center consolidates them into one workspace.

The honest framing is that no platform removes the need for the internal partnerships Todd describes. Tooling makes the handoff possible; the relationship with HR, Legal and IT is what makes it happen. If you are building those relationships now, the challenges corporate security managers run into and how teams align around the wider security ecosystem are both worth reading alongside this.

Hear the full conversation

Todd’s webinar with Jeff DiDomenico covers a lot more ground than we can fit into one post, including how he built direct ownership of his incident data during a service provider re-bid, how he turned a company with no security culture into one where officers were treated as trusted teammates, and how he thinks CSOs should be evaluating AI-driven technology without getting swept up in the hype.

Watch the full on-demand webinar, From Badge to Boardroom, to hear Todd’s complete story in his own words. If you would rather see how the security operations side works against your own estate, you can book a TrackTik demo.

Frequently Asked Questions

Value beyond the security department. The buying question has moved from whether a platform can log an incident to whether it can route that incident to whoever owns the fix, in a form they can use. As David Fortino put it, the ask is for a tool that helps the entire enterprise rather than just physical security. In practice that means configurable incident data, reporting other departments can consume, and integrations into the systems they already work in.

Because the department that logs an incident is often not the department that can fix the cause. A pattern of trailer turnarounds looked like a security record and was actually a logistics problem with a measurable cost attached. If that data had stayed in a security-only report, nobody with the authority to change the process would ever have seen it. Reporting across sites and time is what makes those patterns visible at all.

Granular enough that two incidents sharing a label do not require the same response. “Theft” covering both a break room lunch and fifty catalytic converters is the failure case, because one needs no escalation and the other needs production planning and possibly law enforcement within the hour. Look for configurable types with guided required fields rather than a fixed list, and check that the detail survives into the reporting layer rather than being flattened.

This is the question most evaluations skip, and it is worth getting in writing. If your incident history and your reporting configuration sit only inside a provider’s tenancy, a re-bid means starting your operating record from zero. Ask specifically what can be exported, in what format, whether attachments such as photos and video come with it, and whether data can be replicated continuously to a warehouse you control rather than extracted at the end.

It is the trend SIA identifies in its 2026 Security Megatrends report describing the move away from siloed physical security systems toward platforms that connect security data with IT, facilities and operational systems. The practical implication for a buyer is that a platform which cannot exchange data with the rest of the business is increasingly a liability rather than a neutral choice, because the value of an incident record now depends on who else can see it.

Through role-appropriate views and summaries rather than forwarding the full field report. HR does not need patrol context and a board reader does not need officer narrative detail. TrackTik handles this with shareable reporting views plus AI-generated executive summaries, and where alarms, video and dispatch need to sit alongside the record the Command Center consolidates them into one workspace.

Four questions cover most of it: can categories separate incidents that need different responses, does your data and configuration survive a provider change, can other departments get their slice without the whole report, and can your own team build a dashboard to spot a pattern without raising a vendor ticket. Ask for each answered with a live demonstration rather than a roadmap commitment. You can book a TrackTik demo and put all four to us directly.

Related resources

More on security data that reaches the whole enterprise