Demonstrations Incident Management

Incident Management Guidelines

Many groups will use public demonstrations to gain media exposure, as well as impede business activities. Demonstrations may be singular events lasting hours, or may be protracted, lasting days to months and evolving into site occupancy (e.g., tree sitting). Demonstrations are typically nonviolent and involve chanting, banners, and costumes. Demonstrations may also involve the symbolic burning of items, or the leaving of obstructive or unpleasant items such as tree stumps or manure. In the most extreme cases, demonstrations may lead to an escalation in violence and may turn into riots.
In the event of a demonstrations incident occurring, the following points should be addressed:

Sabotage Incident Management

Incident Management Guidelines

The sabotage of a facility or equipment can be through common vandalism damaging or making resources inoperable or faulty, or may be through focused and wellplanned activities by organized crime, insurgency, special interest groups, or terrorists. Sabotage may be dramatic in nature, resulting in catastrophic effects, or may be subtle and difficult to detect. Sabotage may place personnel at risk, may disrupt operations or may result in structural failure or other secondary risk effects.

In the event of a sabotage incident occurring, the following points should be addressed:


 Action Points

  1. Stand up the Incident Management and Crisis Response Teams using the SAD CHALETS system.
  2. Lock down the facility or work site, alert personnel, and move employees to safe areas or safe havens if necessary.
  3. Mobilize security personnel to secure access points and highvalue areas; all area movements are to stop until response measures are completed.
  4. Conduct security sweeps and searches to locate any additional acts of sabotage, as well as search for saboteurs.
  5. Determine what has been sabotaged:
    • Machinery and equipment.
    • Materials and resources.
    • Structures and systems.
    • Technology and communications.
  6. Are the saboteurs still onsite? Can they be detained by security or police agencies?
  7. Are the saboteurs violent? Are they armed? How will they respond if apprehended? What risks are associated with the individuals themselves?
  8. Determine what risks are connected to the act:
    • Explosive
    • Failure
    • Disruptive
    • Toxic
    • Structural
    • Information
  9. What risks are presented to personnel directly, or as a result of secondary hazard?
  10. Raise the alert status and security posture of the facility to the predefined planning level, and mobilize security staff, closing down access control points and securing buildings.
  11. Alert law enforcement agencies to investigate or prosecute groups or individuals.
  12. Cordon the affected area or resources to enable an investigation to be conducted; do not contaminate the area in terms of forensics requirements.
  13. Document and photograph sabotaged materials, assets, or structures.
  14. Provide an IMP Risk Assessment Report as soon as possible.

Complex Attack Incident Management

Incident Management Guidelines

A hostile person or group may use several forms of attack against a target concurrently. The complex attack typically aims to kill or injure as many people as possible, significantly damage critical infrastructures, or enable instigators to effect a kidnapping. Such attacks are usually more thoroughly planned than other forms of risk, and are typically aimed at a specific target rather than being opportunistic in nature due to the complexity of planning required and the resources required. Effective risk mitigation and security planning will form the basis for responding to complex attacks.

In the event of a complex attack incident occurring, the following points should be addressed:

Action Points
  1. Stand up the Incident Management and Crisis Response Teams using the SAD CHALETS system.
  2. Mobilize all security personnel, and implement security response protocols.
  3. Notify all employees, and move staff to safe areas/havens if possible.
  4. Lock down all access control points and facilities to restrict unauthorized movements.
  5. Raise the alert status and security posture of the facility to the predefined state and mobilize security staff, closing down access control points and securing buildings.
  6. Notify supporting military or police agencies; nominate an incident control point (ICP) and safe route into the area.
  7. Locate aggressors and establish a cordon with security response groups.
  8. Determine the size and composition of the aggressor group, and relay the information to security response personnel.
  9. Determine the agenda and objectives of the aggressor group, and instigate countermeasures.
  10. Implement other aspects of the IMP as they relate to the incident.
  11. Provide an IMP Risk Assessment Report as soon as possible.
  12. Provide a postincident report when the crisis is over.

Popular Posts