SIA New Member Profile: Strategic Security Advisors

SIA New Member Profile: Strategic Security Advisors Daniel Schneider, founder, Strategic Security Advisors

New Security Industry Association (SIA) member Strategic Security Advisors builds prevention-first safety strategies, early threat detection systems and cross-functional leadership to help organizations shift from reactive defense to proactive protection. The company is headquartered in Wickenburg, Arizona, performs on-site work across Arizona and the Southwest and offers advisory offerings nationally.

SIA spoke with Daniel Schneider, founder of Strategic Security Advisors, about the company, the security industry and working with SIA.

Tell us the story of your company.

Daniel Schneider: Strategic Security Advisors came out of a pattern I couldn’t stop seeing. I served in the Israel Defense Forces, active duty and reserves. Then I spent about 15 years inside corporate security at a national wireless carrier, working asset protection, loss prevention, investigations and cybersecurity. Thousands of locations. Real budgets, real exposure. That’s a long time to watch how large organizations actually handle risk, and it’s a very different education than you get from the outside.

What stuck with me wasn’t the incidents—it was the paperwork afterward. Every serious after-action review told the same story. Somebody had noticed something first, sometimes months earlier. It was reported. Logged. Escalated. Discussed. Then nothing moved. The information existed. It was usually written down. What failed wasn’t detection. It was the decision to act on what was already visible.

So I built a firm around that window instead of around the incident. Most of this industry is organized to respond, and it responds well. My argument is that by the time you’re responding, the outcome was already decided by everything that happened before it. Strategic Security Advisors works in that earlier space. We help organizations build the governance, ownership and decision thresholds that let them move on a concern while it’s still a concern and not yet a crisis. I wrote a book about it, The Space Before Crisis, because explaining the idea one conference room at a time was too slow.

Our clients are usually organizations carrying serious exposure without a security department to match it. K-12 and charter schools. Houses of worship. Health care. Property managers. Faith-based and nonprofit institutions. Midmarket companies where somebody in operations inherited security along with three other jobs. Those are the places where a prevention gap is most likely to stay invisible right up until it isn’t.

What solutions/services does your business offer in the security industry? And what makes your offerings/company unique?

DS: We sell prevention. Everything else we do exists to deliver it.

Prevention program design is the work: governance, thresholds, ownership and a written standard for what triggers action before an incident, not after one. Who receives a concern. Who owns the call. What level of worry is enough to move on. What happens if nobody does. My framework, See · Connect · Own the Call · Act, is published in the book and I’m glad for people to use it. The four words aren’t the hard part. Setting a threshold your leadership will honor at 4:30 on a Friday is the hard part.

Fractional security leadership is how that gets delivered. Small and midsized organizations carry the same exposure as large ones and can’t justify a full-time chief security officer, so the seat stays empty and prevention stays unassigned. Fractional puts C-level security leadership in reach of a company that could never hire it outright. I step into that seat. I own the call, build the escalation path, sit with the executive team and train the people who receive reports. Same authority at a fraction of the cost, and prevention becomes somebody’s actual job instead of an expectation nobody was given.

What makes us different is the lens. This industry is staffed with capable people, and a large share of them spent 20 or 30 years in law enforcement or the military. That’s the world they lived in, and it produces real expertise: containment, stabilization, evidence, prosecution. It’s also a reactive lens by design, because in that world the event has already happened by the time you’re called. The corporate world runs differently. I know the adjustment firsthand. I came up through contract security and had to rebuild how I saw the business when I moved into corporate security. Different pressures, different timelines, different definition of a win. That shift is the whole distinction between reaction and proaction, and proaction is prevention. I’m not offering a better version of what response professionals already do well. I work in a different window, and I’m explicit about it.

We do assessments too, and we do them well, including grant-supporting vulnerability assessments for schools and houses of worship. But I’ll be honest about where they sit. Assessments are the commodity end of this field, and a report by itself has never prevented anything. We use them as a starting point, not as the product.

What is something we might not know about your company—or something new you are doing in security?

DS: For a firm our size, an unusual amount of what we produce is instruments rather than reports. A prevention readiness review that scores whether concerns actually reach a decision. A facilitator card deck staff use to work real scenarios in a room together. A board-level session built to assign ownership of the prevention call before anyone needs to make one. A report gets read once. An instrument gets used quarterly. That distinction has shaped almost everything we build.

The newer development is that I’ve stopped treating prevention as a service line and started treating it as an argument this industry needs to have out loud.

I’m speaking at GSX 2026 in Atlanta on Sept. 14 on why most security programs activate too late. I co-host The Security Shift Podcast, which passed 500,000 combined views in its first six weeks. I write a biweekly newsletter on the same subject and publish regularly on prevention as a governance function. The consulting funds the work. The argument is the point of it.

What is your company’s vision, and what are your goals for the security industry?

DS: Make prevention a named job with a named owner. Every organization I walk into can tell me who runs incident response. Almost none can tell me who decides to act on a concern that hasn’t become an incident yet. That seat is empty, and it’s empty at organizations with otherwise excellent security programs. It isn’t a training gap. It isn’t a technology gap. Nobody was ever assigned, so nobody is accountable, so the concern sits.

For the industry, I want prevention to stop being used as a synonym for cameras and bollards. Deterrence is a control. Prevention is a decision process: who owns it, what threshold trips it, what gets recorded when it does and what happens if nobody moves. When a board can answer that in one sentence, everything downstream gets stronger without buying a single new thing.

What do you think are the biggest opportunities in the security industry right now?

DS: The widening gap between what our technology can see and what organizations actually do with it. The technology side of this industry has gotten very good. Analytics, access control, weapons detection, behavioral flagging. The bottleneck has moved. It’s no longer whether anyone saw it—it’s whether anyone owned it, and whether anything happened in the next twenty minutes. The manufacturers and integrators designing for what happens after the alert, meaning routing, escalation, accountability and closure, are solving the problem that’s actually limiting outcomes right now.

The second opportunity is funding driven. School security grant programs, house of worship security funding, and workplace violence requirements in healthcare have put real money and real compliance pressure into segments that had neither five years ago. Those buyers need assessment, prioritization and justification before they can spend a dollar. That’s a large, underserved layer of work sitting upstream of every product sale in this space.

What are your predictions for the security industry in the short and long term?

DS: Short-term, liability does what persuasion hasn’t. In January, the families of the four University of Idaho students killed in 2022 filed a wrongful death and gross negligence suit against Washington State University, where the man convicted of the murders was a graduate student. The complaint alleges the university had 13 documented complaints about his behavior and failed to act on them. The university denies it, and the case will take years to resolve. That isn’t my point. My point is what discovery asks. What did you know. When did you know it. What did you do about it. Institutions are going to find themselves reading their own records into evidence, and that will change behavior faster than any pitch I could make.

I’d add a caution about workplace violence prevention (WVP), since that’s where most of the compliance energy is going. WVP programs are narrow by definition—they’re bounded by “workplace” and bounded by “violence.” Real concerns respect neither boundary. What gives a WVP program its power isn’t the policy document—it’s whether someone is authorized to make a call on incomplete information, under uncertainty, while the picture is still ambiguous. Ambiguity is the normal operating condition of prevention work. Most programs are built as though clarity arrives first. It doesn’t, and the programs that wait for it are the ones that activate too late.

Long-term, prevention follows the path workplace safety took. Safety was once an afterthought handled reactively. It became a named function with an owner, a budget, metrics and audits. Prevention is roughly where safety was several decades ago. The organizations that get there first will look, in hindsight, like they were simply better run.

What are the biggest challenges facing your company and/or others int he security industry?

DS: The hardest problem in my business is that prevention succeeds invisibly. Nobody holds a press conference about the incident that didn’t happen, and no budget line ever got approved because nothing occurred. Security money moves after events, which means the field is structurally funded to be reactive even when the people in it know better. I don’t have a clean answer for that. The best I can do is make the pre-incident window legible enough that leadership can see what it’s choosing.

What makes that math worse is what I call the invisible invoice. Organizations price security against the cost of the program. They almost never price it against the bill that arrives after a crisis: legal exposure, insurance repricing, turnover, recruiting, leadership hours diverted for a year, the contract that quietly doesn’t renew, the families who don’t come back. None of it appears in the security budget. All of it gets paid. I’ve watched an organization decline a program because the number felt high, then absorb 10 times that number 18 months later without ever connecting the two events. The invisible invoice is the real comparison, and almost nobody prepares for it.

The related industrywide challenge is what I call the wait-and-document trap. Organizations build careful processes for recording concerns and no process at all for acting on them. The file grows. The threshold never gets defined. Then something happens, and the after-action report reads like a list of things the organization already had in writing.

What do you enjoy most about being at your company—and in the security industry?

DS: The best moment in my work is watching a leadership team realize they already had the information. Not that they were negligent. That’s almost never true. The signal was in the building and there was no mechanism to carry it to a decision. That realization is uncomfortable for about 90 seconds. Then it becomes the most productive conversation the room has had all year.

What I’m really building toward is a culture where “see something, say something” can actually live and work. Most organizations have the slogan and none of the plumbing behind it. People do see something. They say something. It reaches a supervisor with no idea what to do with it, no authority to act, and no obligation to close the loop. So the next time, they don’t bother. The slogan isn’t the problem—the receiving end is. Building that receiving end is the most satisfying work I do: where a report goes, who owns it, what triggers action and what the person who spoke up hears back.

I also like the people in this industry—it’s full of practitioners who take the work seriously because they’ve seen what happens when it isn’t taken seriously, and there’s very little pretense in a room of security professionals. The best work I’ve been part of has been collaborative and cross-vertical. School leaders learning from health care. Houses of worship learning from retail loss prevention. Consultants and integrators working the same problem instead of protecting turf. Threats don’t respect verticals, and neither should we. I’ve never seen a win-win arrangement in this field that didn’t outperform the zero-sum version of the same deal.

What does SIA offer that is most important to you/your company? And what do you most hope to get out of your membership with SIA?

DS: Proximity to the build side of the industry. I sit on the advisory and end-user side of the table. I assess, specify and help clients decide what to buy, when and whether they need it at all. My recommendations are only as current as my understanding of what’s actually being made. SIA’s standards work, education programming and member research keep me close to the people building it, which beats learning it from a trade show floor once a year.

The larger reason I’m here is that I’m looking for a partner. My position is that no security system is complete unless prevention sits upstream of the technology. Sensors, analytics and access control can tell you something is happening. They can’t tell you who decides, at what threshold or what happens when nobody does. Sell the technology without that layer and the client ends up owning an excellent detection system attached to nothing. I’m actively seeking to partner with a technology company that already understands this and wants to bring it to their clients. Not as a bolt-on service, but as the layer that makes their product perform the way it was designed to perform. The people who design and integrate these systems have more leverage over whether an organization acts in time than almost anyone else in this industry. SIA is where those companies are, and that conversation is the one I most want to be in.

How does your organization engage with SIA, and what are your plans for involvement in the next year?

DS: Right now I’m engaging primarily through member resources, education and industry programming. Over the next year I want to move from consuming to contributing. I’ve submitted two proposals for ISC West 2027 as a speaker and panelist, and I’d like to bring the prevention framework to that audience directly. I’m also interested in the education and standards conversations where end-user practice meets product design. That seam is exactly where prevention either gets designed in or gets left out.

I’d welcome the chance to contribute written work as well. I publish regularly on prevention as a governance function, and I’m glad to make that thinking available to SIA members in whatever format is most useful.

The views and opinions expressed in guest posts and/or profiles are those of the authors or sources and do not necessarily reflect the official policy or position of the Security Industry Association.