In The Boardroom™ With...
Michael J Gugliotti
Founder
MJG Consulting Group LLC
SecuritySolutionsWatch.com: Thank you for joining us today, Michael ! Please tell us about your background and what led you to establish MJG Consulting Group ?
Michael J. Gugliotti: My career has given me the opportunity to see security from several different perspectives. I spent 25 years in law enforcement and then transitioned into private-sector security leadership, where I spent more than 15 years managing security operations and dealing with the challenges organizations face every day.
That experience taught me something important: security problems are rarely just about the person standing at the door or responding to an incident.
Very often, the underlying issue is the system surrounding that person.
Are expectations clearly defined? Is the organization properly staffed? Are people trained? Are supervisors equipped to manage the operation? Are policies current? Are risks being identified and addressed? Is leadership receiving meaningful information about security performance?
Those questions ultimately led me to establish MJG Consulting Group.
I wanted to help organizations move beyond simply providing security and toward actually governing security.
SecuritySolutionsWatch.com: You use the phrase “Governance Before Guarding™.” What does that mean?
Michael J. Gugliotti: It means that effective security starts before the security officer ever arrives at the post.
Organizations often focus heavily on the operational side of security—guards, cameras, access control, patrols, incident response and technology. Those things are important, but they are only components of a larger system.
Governance establishes the structure around those components.
It answers questions such as:
Who is accountable?
What risks are we trying to manage?
What standards are we establishing?
How are we measuring performance?
How does leadership know whether the security program is actually working?
What happens when deficiencies are identified?
Guarding is an activity. Governance is the system that gives that activity direction, accountability and purpose.
That's the thinking behind “Governance Before Guarding™.”
SecuritySolutionsWatch.com: Why do you believe security governance needs to be discussed at the executive and board level?
Michael J. Gugliotti: : Because security decisions can have consequences far beyond the security department.
A security failure can affect people, operations, finances, reputation, insurance, regulatory exposure and litigation.
Yet in many organizations, security remains primarily an operational conversation.
I believe leadership should be asking:
What are our significant security risks, how are we managing them, and how do we know?
That's a governance question.
The board and executive team don't need to manage the security department's daily operations. That's not their role.
Their role is to establish accountability, understand significant organizational risk, ensure appropriate resources are available, and make informed decisions.
Security belongs in the boardroom and for the same reason other material organizational risks belong there.
SecuritySolutionsWatch.com: What do you see as one of the biggest weaknesses in today's security industry?
Michael J. Gugliotti: One of the biggest weaknesses is fragmentation.
An organization may have excellent policies, good officers, cameras, training and technology—but those elements don't necessarily constitute a functioning security system.
You can have all the pieces and still lack governance.
I've seen organizations devote significant attention to individual incidents while paying less attention to the larger questions surrounding their security program.
My approach is to step back and examine the entire structure.
What was the organization supposed to do? Who was responsible? What processes were in place? What training does it occur? What supervision existed? What risks have been identified? What documentation existed? And what did leadership know?
That broader perspective can reveal vulnerabilities that aren't visible when looking at a single incident in isolation.
SecuritySolutionsWatch.com: How does security governance reduce organizational risk?
Michael J. Gugliotti: Governance doesn't eliminate risk. No legitimate security professional can promise that.
What governance does is help an organization identify, understand, manage and document risk more effectively.
A mature governance program creates accountability.
It establishes expectations, assigns responsibility, creates standardized procedures, measures performance and provides mechanisms for corrective action.
It also creates a record of organizational decision-making.
That's important because effective risk management isn't simply about what an organization says it believes.
It's about what it does, how consistently it does it, how it measures its performance, and how it responds when something isn't working.
SecuritySolutionsWatch.com: You developed the Hospitality Security Operating System, or HSOS™. What prompted you to create it?
Michael J. Gugliotti: HSOS grew out of the same problem I had been seeing throughout my career: organizations often have security resources, but they don't necessarily have a comprehensive framework connecting those resources.
Hospitality is particularly challenging because you're protecting people, property, information, reputation and business continuity while operating in an environment that's open to guests, employees, contractors and the public.
The environment is constantly changing.
I wanted to create something that brought governance, risk management and security operations together in a structured system.
HSOS is the result.
It's designed to provide organizations with a framework for governance, policies, SOPs, Post Orders, forms, training, accountability, audits, implementation and continuous improvement.
But the underlying concept is actually very simple:
Security should operate as a managed organizational system—not as a collection of disconnected activities.
SecuritySolutionsWatch.com: How is HSOS different from simply giving an organization a collection of security policies and SOPs?
Michael J. Gugliotti: That's an important distinction.
A policy manual tells people what the organization expects.
A governance system goes much further.
It establishes the relationship between risk, leadership, policy, operations, training, accountability, measurement and continuous improvement.
For example, an SOP may tell an officer how to respond to a particular situation.
Governance asks additional questions:
Who approved the procedure?
Was the officer trained?
Was competency verified?
Was the procedure actually followed?
How is compliance measured?
What happens when it isn't followed?
Is the procedure still appropriate based on current risk?
How does leadership know?
That's the difference between documentation and governance.
SecuritySolutionsWatch.com: You also developed an Executive Security Governance Framework. Why was that necessary?
Michael J. Gugliotti: Because executives shouldn't have to read an entire operational security manual to understand whether their organization is managing security effectively.
Leadership needs a different level of information.
The Executive Security Governance Framework is designed to give executives visibility into areas such as organizational risk, security strategy, accountability, performance, compliance, corrective actions and decision-making.
It essentially translates security operations into an executive governance language.
The goal isn't to turn executives into security directors.
The goal is to give leadership enough visibility to ask the right questions and make informed decisions.
SecuritySolutionsWatch.com: How does this approach change the relationship between security leadership and executive leadership?
Michael J. Gugliotti: It changes security from being primarily a cost center or operational function into a component of organizational risk management.
A security director shouldn't simply report:
“We had 14 incidents this month.”
The executive conversation should be more meaningful:
What happened?
What trends are emerging?
What risks are increasing?
What corrective actions have been taken?
Where are the deficiencies?
What resources are required?
What decisions need executive attention?
That creates a much more productive relationship between security and leadership.
SecuritySolutionsWatch.com: What role does documentation play in your philosophy?
Michael J. Gugliotti: Documentation is extremely important, but I don't believe organizations should document things simply for the sake of creating paperwork.
Good documentation demonstrates that an organization has a process for managing its responsibilities.
It can establish what was expected, who was responsible, what training occurred, what decisions were made, what actions were taken and whether corrective measures were implemented.
It also becomes extremely important when an organization has to explain its decisions later.
That's particularly relevant in litigation.
A strong security program should be able to demonstrate not only what happened, but also how the organization was managing the risk before it happened.
SecuritySolutionsWatch.com: Your work also includes expert witness and litigation support. How does your governance philosophy apply to litigation?
Michael J. Gugliotti: My approach to litigation is very consistent with my approach to security governance.
I look beyond the individual incident to evaluate the security system surrounding it.
An incident may involve one security officer, but the relevant questions can extend much further.
What policies existed?
What training was provided?
How was the property staffed?
What supervision existed?
Were appropriate procedures established?
Were known risks identified?
Were previous incidents documented?
Were corrective actions taken?
What did management know?
Those questions can help determine whether an incident was an isolated event or whether it occurred within a larger organizational deficiency.
My role is to evaluate that security environment objectively and provide an informed professional analysis.
SecuritySolutionsWatch.com: What do you think executives frequently misunderstand about security?
Michael J. Gugliotti: I think one of the biggest misconceptions is that security is primarily an operational expense.
Security is a form of risk management.
The question shouldn't simply be:
“How much are we spending on security?”
It should be:
“What risks are we managing, how effectively are we managing them, and what is the consequence if we don't?”
That changes the conversation.
It allows executives to evaluate security based on risk, performance and organizational objectives rather than simply looking at the security budget.
SecuritySolutionsWatch.com: What would you tell a CEO, general manager or board member who believes their organization already has a good security program?
Michael J. Gugliotti: I'd tell them that's a good starting point.
Then I'd ask them to prove it.
Not because I assume the program is deficient, but because mature organizations should be able to demonstrate how their security program works.
I'd ask:
What are your top security risks?
Who owns those risks?
How are they being measured?
When was the program last formally assessed?
How do you know your employees are properly trained?
How are deficiencies documented and corrected?
What security information reaches executive leadership?
If leadership can answer those questions confidently and demonstrate the supporting evidence, that's a strong indication of maturity.
SecuritySolutionsWatch.com: Where do you see the future of physical security heading?
Michael J. Gugliotti: I believe physical security is moving toward greater integration with enterprise risk management.
Technology will continue to evolve. Artificial intelligence, analytics, access control, video surveillance and other technologies will become increasingly important.
But technology doesn't eliminate the need for governance.
In fact, as organizations become more technologically sophisticated, governance becomes even more important.
The future isn't simply about having better security technology.
It's about having better systems for managing security.
SecuritySolutionsWatch.com: What is your vision for MJG Consulting Group?
Michael J. Gugliotti: My vision is to help change the way organizations think about security.
I don't want MJG Consulting Group to simply be another security consulting company.
I want MJG to be recognized for bringing governance, risk management and operational discipline into security decision-making.
HSOS is an important part of that vision, particularly within hospitality, but the underlying philosophy extends beyond one industry.
Ultimately, I'm trying to help organizations Michael J. Gugliotti: a fundamental question:
Are we governing our security program, or are we simply operating it?
That distinction matters.
SecuritySolutionsWatch.com: Finally, what message would you like to leave with today's executives and security leaders?
Michael J. Gugliotti: Don't wait for an incident to discover whether your security program is actually working.
Build the system before you need it.
Understand your risks
Establish accountability
Train your people
Standardize your processes
Measure performance
Document your decisions
Correct deficiencies
And make sure leadership understands the security risks the organization is carrying.
Because effective security isn't simply about responding well when something goes wrong.
It's about building an organization that is prepared, accountable and resilient before something goes wrong.
That's what I mean when I say:
Governance Before Guarding™
SecuritySolutionsWatch.com: Thank you for joining us today, Michael!
For more information:
Michael J Gugliotti
Founder/Principal Consultant
MJG Consulting Group LLC
203-228-3014
Lake Worth, FL.
mjgconsulting@mjgconsultinggroupllc.com
Connect with Michael Gugliotti on LinkedIn
2026–2030 Private Security Industry Gaps & Strategic Opportunities
Executive Summary for Hospitality Leaders
The private security sector is entering a period of accelerated disruption. Luxury hospitality, in particular, is facing a widening gap between what properties believe they are delivering and what modern risk environments actually require. This condensed brief outlines the eight structural gaps shaping the next five years — and the strategic opportunities for organizations that modernize now.
1. The Governance Gap
Most properties still operate without a unified governance framework. Policies, procedures, and standards vary by shift, by manager, and by property.
Opportunity: Implementing a centralized governance system (such as HSOS) creates consistency, accountability, and measurable performance across the portfolio.
2. The Technology Gap
Hotels continue to rely on outdated surveillance, access control, and incident reporting tools that were never designed for today’s risk environment.
Opportunity: Integrated platforms, automation, and real‑time analytics reduce blind spots, compress response times, and elevate decision‑making.
3. The Training & Competency Gap
Security teams are often undertrained, under‑evaluated, and misaligned with modern threat profiles and guest expectations.
Opportunity: Competency‑based training and recurring assessments create a professionalized, high‑reliability workforce that can execute consistently under pressure.
4. The Leadership Gap
Security departments frequently lack executive‑level leadership, resulting in reactive operations instead of strategic risk management.
Opportunity: Elevating security leadership to the executive table aligns operations with brand, guest experience, and liability reduction.
5. The Operational Drift Gap
Without governance, teams drift from standards over time — creating inconsistency, exposure, and preventable incidents.
Opportunity: Governance frameworks eliminate drift and ensure every shift performs to the same standard, regardless of who is on duty.
6. The Data & Reporting Gap
Most properties collect data but do not convert it into intelligence that informs decisions or investments.
Opportunity: Structured reporting, dashboards, and trend analysis transform security from a cost center into a strategic asset.
7. The Compliance & Liability Gap
Fragmented documentation and inconsistent practices increase legal exposure and weaken defensibility when incidents occur.
Opportunity: Standardized documentation and audit‑ready systems reduce risk and strengthen the organization’s legal posture.
8. The Guest Experience Gap
Security is often treated as a back‑of‑house function, yet it directly shapes guest perception, brand trust, and loyalty.
Opportunity: Modern security governance enhances guest experience through professionalism, discretion, and visible consistency.
Strategic Outlook: 2026–2030
Organizations that modernize now will gain:
- Stronger brand protection
- Lower liability exposure
- Higher operational consistency
- Improved guest experience
- A durable competitive advantage in an increasingly volatile environment
Those that delay will face widening gaps, higher costs, and increased risk as the operating environment continues to evolve.
Download the Full White Paper
For a deeper dive into the eight structural gaps and the HSOS governance model, download the full white paper.