Release of the December 2025 Safeguards Consulting Chronicle

Our team is proud to share that we recently released the December issue of our firm's monthly newsletter, The Safeguards Consulting Chronicle, and we would love to invite you to subscribe for free. This year, we are also proudly celebrating the Chronicle’s third anniversary!   

Our newsletter covers numerous industry events, news, and updates.  

Some of the items we included in our December issue were:       

+ A featured friend spotlight piece on our friend and past client, the US CPTED Association.   

+ An exclusive article written by our Physical Security and Fire Alarm Systems Specialist and Instructor, Donald “Don” McInnes, and our Marketing and Design Operations Specialist, Harris Rowe, entitled, “When Access Control and Life Safety Conflict - And When They Work Together”.    

+ A list of beneficial industry events, that includes events we are supporting/speaking at, as well as other events we recommend attending.      

+ Our list of useful blog articles.       

+ A selection of key industry news and updates.       

+ A quick industry tip provided by our experts.      

This month’s “Featured Friend” will also feature our friend and partner, BSides ICS/OT Miami.  

If interested, please subscribe using the hyperlink included below.     

https://www.safeguardsconsulting.com/newslettersignup?utm_source=SocialMedia&utm_medium=OrganicSocial&utm_campaign=2025-01-31_SGC-C_JanuarySMPostNewsletterSignUp&utm_content=Newsletter%20Signup%20Link%20Blog

When you subscribe to our newsletter, you gain access to all the exclusive security content mentioned above, as well as our newsletter archive, so that you never miss an issue! We hope these resources will help you in your role as a security professional. It also allows us to keep you updated regarding company news, updates, or events.  

Safeguarding The New Year: Security Assessments Should Be the Top New Year’s Resolution

As we enter a new year brimming with opportunities, many of us commit to resolutions aimed at bettering different areas of our lives, including our career operations. Yet, amidst these goals, one vital resolution is frequently overlooked: analyzing the security of your facility. At Safeguards Consulting, we are convinced that including a security assessment in your New Year’s resolutions could be the most valuable choice you make for your organization in 2026. 

Why Prioritize a Security Assessment? 

Every facility, whether it is a data center, utility, hospital, university, or even a commercial office, faces unique security challenges. As threats evolve, from physical intrusions and theft to unauthorized entry and safety risks, it is critical to remain vigilant. A thorough physical security risk assessment analyzes your existing systems, identifies potential flaws, and provides customized improvement strategies to improve your protection. 

What are The Benefits of a Security Assessment as a New Year’s Resolution?  

1. Identify Vulnerabilities Early: A physical security risk assessment can reveal gaps and flaws in your systems, processes, or physical environment before they are exploited by criminals or other perpetrators.  

2. Reduce the Risk of Breaches: By identifying and addressing security vulnerabilities, you reduce the opportunity for security incidents including violence, theft, damage, or other impacts that could disrupt your business or staff’s lives.  

3. Increase Peace of Mind: Having your team and staff know that your security measures are current and effective allows you to focus on your goals for the year without worrying about potential threats. 

4. Stay Compliant: Many industries have regulations that require specific security measures and operations. Regular assessments ensure that you stay compliant and avoid penalties.  

5. Optimize Security Investments: Understanding your security posture allows you to allocate resources wisely, investing in the tools and training that provide the best protection. 
 
Make 2026 the Year You Take Control of Your Security 

Avoid waiting for a security breach or incident to reveal weaknesses in your defenses. By scheduling a professional physical security risk assessment today, you are proactive in ensuring your facility's long-term safety and success. Our skilled team of security experts is ready to assist you in identifying risks and implementing effective strategies to protect what is most important. 

Secure Your New Year Today  

Begin your New Year's resolutions with a commitment that matters. Contact our team today to set up a security assessment and begin 2026 with confidence and peace of mind.  

Protecting and Securing Facilities During the Holiday Travel Season

The holiday season is a time for celebration, but for organizations, it also brings heightened security challenges. With many employees traveling or working remotely, facilities often operate with reduced staffing, creating opportunities for bad actors to exploit vulnerabilities. Proactive planning is essential to safeguard assets and maintain operational continuity during this period. 

When fewer employees are on-site, response times slow, and empty offices become attractive targets. Property crimes spike during the holidays: U.S. data shows property crimes increase by 10–15% in December compared to other months. Opportunistic theft, vandalism, and unauthorized access are common issues. Cyber threats also surge, as attackers exploit distracted teams and unattended systems. In fact, more than half of ransomware attacks occur during holidays or weekends, making this season particularly risky for organizations that rely on remote connectivity. 

Physical security gaps are one of the most pressing concerns. Reduced staff presence makes it easier for bad actors to tailgate or force entry. FBI data shows property crimes peaked in December 2024 with 66,676 incidents - a 10.8% jump from November. Retail theft alone rises by 14% during holiday months, and similar trends affect office spaces and warehouses. Cybersecurity vulnerabilities also escalate during this time. Holiday-themed phishing and account takeover attacks spike sharply; researchers tracked a 92% increase in malicious configurations targeting retail and a 400% increase against hospitality sectors ahead of the holiday season. Environmental hazards, such as winter storms, can further complicate matters by causing outages or damage if not properly monitored. 

To mitigate these risks, organizations should strengthen access control by updating credentials, deactivating unused badges, and restricting access to non-essential areas. Surveillance and monitoring systems should be tested to ensure cameras and alarms are fully operational, and remote monitoring or third-party security services can provide continuous oversight. Cybersecurity measures are equally critical, such as implementing multi-factor authentication for remote access, patching systems before staff leave, and communicating clear guidelines for secure remote work practices. Emergency preparedness is another key step: distribute updated contact lists and escalation procedures, and conduct quick refresher drills to ensure readiness. Finally, visitor and delivery management should be tightened by using digital systems to track entries and limiting non-essential traffic during low-staff periods. 

The holiday season should be a time of celebration, not concern. By taking proactive steps, strengthening physical security, reinforcing cybersecurity, and preparing for emergencies, organizations can minimize risks and maintain a safe, secure environment. A layered approach ensures that even when staffing is reduced, your facility remains protected.  

Author: Harris Rowe, Marketing and Design Operations Specialist at Safeguards Consulting, Inc.

References 

2024 ransomware holiday risk report. (2025, November 18). Semperis. https://www.semperis.com/resources/2024-ransomware-holiday-risk-report/ 

Crime trends in U.S. cities: Year-end 2024 update - Council on criminal justice. (2025, January 28). My WordPress. https://counciloncj.org/crime-trends-in-u-s-cities-year-end-2024-update/ 

FBI Releases 2024 Reported Crimes in the Nation Statistics. (n.d.). FBI News. https://www.fbi.gov/news/press-releases/fbi-releases-2024-reported-crimes-in-the-nation-statistics 

Karen Dooley. (2025, November 25). As holiday shopping season nears, UF experts warn retail theft is growing more sophisticated. News | University of Florida. https://news.ufl.edu/2025/11/uf-lprc-warns-of-growing-retail-theft/ 

Detecting Fake Account Recovery Emails

Account Recovery Phishing is a type of attack used by scammers to gain unauthorized access to user accounts. Attackers send emails or text messages claiming that you need to reset your password or provide personal information to verify your account. These account recovery messages and websites often appear to come from genuine companies, but if you look closely, they are fake.  

Kasada, a cybersecurity company specializing in account-takeover attacks, observed in its 2025 report, “a 250% increase in account takeover attacks […] resulted in over 6 million compromised accounts, affecting large brands across several industries, including retail, hospitality, travel, entertainment, and food and beverage.” While not all these attacks involved Account Recovery Phishing, this highlights the growing risk of account compromise, including threats that exploit password reset flows. The FBI reported in a recent Security Alert that account takeover fraud has already caused losses exceeding US$262 million in 2025.  

Why Is This Relevant?  

The holiday season creates prime opportunities for cybercriminals to launch phishing attacks. During this time, people’s attention and online activity change significantly. Many spend more time shopping online, logging in to banking apps, delivery services, and social media, making each login a potential target. 

Additionally, holiday activities such as shopping, travel, and family gatherings make people busier and more stressed, increasing the likelihood of overlooking warning signs in emails.  

Common Signs of an Account Recovery Phishing Attempt 

Phishing emails are designed to look like official communications from trusted sources, but there are usually clues that reveal they are fake. These are some of the most common signs of a phishing attempt that targets your password: 

1. Receiving unsolicited password recovery requests by email or text asking you to reset your password without initiating it yourself is the main warning sign. These messages may also claim your account has been compromised or that your password will expire soon. 

2. Account recovery emails that use generic greetings such as “Dear User” or “Dear Customer” instead of your name are suspicious. Legitimate companies typically have your contact details and will address you by your name for more personal communication. 

3. The use of urgent or threatening language can create panic and push you to act quickly without carefully verifying the message. Legitimate companies will not demand urgent action on this type of message. If you feel rushed or pressured, stop and evaluate the situation carefully. 

4. Account recovery emails that include suspicious attachments are a clear sign that something is not right. Legitimate password reset notifications typically do not include attachments, so any email with them should be treated with caution, as it may contain malware. 

5. The sender’s email address does not match the company domain, which is typically an indicator that the message is fake. Password reset messages are only sent from verified company domains. 

6. Misaligned logos, incorrect brand colors, low‑resolution images, or anything that looks unfamiliar are signs of fraudulent emails or websites. 

How to Protect Yourself  

A password reset request is a critical security measure and should not be taken lightly or ignored. If a security-related communication is received, it should be reviewed carefully. The following are tips to verify the authenticity of this type of notification, and additional advice to be better protected. 

1. Verify The Email Domain. 

When receiving a password request notification, pause and review that the sender’s email address is authentic and comes from the expected source. For example, Microsoft will not send emails from a Gmail account. Also, watch for subtle changes in the domain or intentional misspellings. For example, support@google.com is not the same as support@googIe.com where the lowercase “l” is replaced by an uppercase “i”.  Adding hyphens and dots is also common to trick the user.  

2. Look Closely at The Link. 

Cybercriminals often hide malicious links behind buttons or text. Hover over links without clicking to reveal the actual URL and inspect it closely to see where it really leads. Another tactic to hide links is the use of URL shorteners. Genuine companies typically do not use shortened URLs for password reset links, so be cautious. 

Even better is to avoid clicking the link directly and instead go to the website or the service’s application. Request a new password through the official “Forgotten password” feature.  

3. Use a Unique Password. 

Do not reuse passwords across multiple sites and services. Create a unique password for each account. This way, if one service is compromised, your other accounts remain secure. It is also highly recommended to use a password manager to store and manage your passwords. 

4. Use Multi-Factor Authentication. 

Review your accounts and enable Multi-Factor Authentication (MFA). Although attackers can sometimes bypass MFA during Account Recovery Phishing attacks by tricking users into providing their verification code, it still adds an additional layer of protection for your accounts. 

5. Protect Your Sensitive Information. 

Never provide sensitive information such as passwords, verification codes, or your Social Security Number, via email or text message. Reputable companies will not ask you to provide sensitive information over insecure channels. 

What to Do if You Think Your Account Has Been Compromised? 

In case your account has been compromised, the first step is to try to recover it through the official password reset process. If you are unable to regain access, contact customer support and notify them about the incident. This is especially important for financial institutions or e-commerce platforms, where they can freeze any activity, restore access, review transactions, and monitor the account for further abuse. 

Review purchase history, messages, login logs, account changes, and connected services. Document anything suspicious with screenshots and timestamps. Even if you cannot access the compromised account, you may still review email notifications, transaction and login attempt alerts, and messages from the service provider.  

Finally, it is highly recommended to submit a report through the Internet Crime Complaint Center (IC3), especially if the compromised account involves financial transactions or the exposure of sensitive information. 

Although this type of phishing is not new, it continues to be highly effective. Always verify any account recovery requests and practice strong security habits. 

Author: The Safeguards Consulting, Inc. Cybersecurity Team

Release of the November 2025 Safeguards Consulting Chronicle

Our team is proud to share that we recently released the November issue of our firm's monthly newsletter, The Safeguards Consulting Chronicle, and we would love to invite you to subscribe for free. This year, we are also proudly celebrating the Chronicle’s second anniversary, and in addition, this June, we celebrated our 30th anniversary issue!   

Our newsletter covers numerous industry events, news, and updates.  

Some of the items we included in our November issue were:       

+ A featured friend spotlight piece on our friend and past client, the Electric Power Research Institute (EPRI).  

+ An exclusive article written by our Principal Consultant and President, Mark Schreiber, “The Underlying Value of Physical Security Systems”.    

+ A list of beneficial industry events, that includes events we are supporting/speaking at, as well as other events we recommend attending.      

+ Our list of useful blog articles.       

+ A selection of key industry news and updates.       

+ A quick industry tip provided by our experts.      

This month’s “Featured Friend” will also feature our friend and partner, US CPTED! We will also have two guest speakers, Harris and Don, writing this month’s Expert Article. Harris Rowe is our Marketing and Design Operations Specialist, and Donald “Don” McInnes is our Physical Security and Fire Alarm Systems Specialist and Instructor.   

If interested, please subscribe using the hyperlink included below.     

Newsletter Signup — Safeguards Consulting, Inc.

When you subscribe to our newsletter, you gain access to all the exclusive security content mentioned above, as well as our newsletter archive, so that you never miss an issue! We hope these resources will help you in your role as a security professional. It also allows us to keep you updated regarding company news, updates, or events.  

Schreiber Aids SIA’s SPARC and VOI Committees with Their New Artificial Intelligence (AI) Report

Safeguards Consulting is proud to announce that our President and Principal Consultant, Mark Schreiber, recently contributed to the Security Industry Association (SIA)’s Security Practitioners Advancing Real Conversations (SPARC) Community, as an original draft author and content contributor. As a member of SIA’s Voice of Industry (VOI) Steering Committee, Schreiber played a key role in creating the new SPARC Intelligence Report: Guidance for Evaluating Artificial Intelligence Vendors/Service Providers. VOI and SPARC developed this report with valuable input from the SIA AI Advisory Board and the International Association of Professional Security Consultants (IAPSC)

Among the others who contributed to the report are:  

+ Bobby Louissaint | SPARC Chair 

+ King Lam | SPARC Vice Chair 

+ Phil Jang | SPARC VOC Rep 

+ Julaine Simmons | VOI Chair 

+ Brad Aikin | VOI Vice-Chair 

+ Heidi Tripp | VOI Vice-Chair 

+ Josh Chin | VOI Member and Content Contributor 

+ James Connor | VOI Member and Content Contributor 

Overall, the report aims to clarify the specific AI technologies employed in various security solutions by establishing consistent terminology and educating industry professionals in their respective roles. Additionally, it offers a practical questionnaire for end users to utilize when evaluating physical security solutions, ensuring that all stakeholders have a clear and accurate understanding of the core AI technologies involved. Given that the content spans multiple technology areas and industry domains, this paper also serves as a comprehensive guide for navigating the complex landscape of AI in security. 

We hope this report offers valuable insights to support you in your role and that you find it both informative and helpful. 

To read the report, visit:  

SPARC Intelligence Report: Guidance for Evaluating Artificial Intelligence Vendors/Service Providers - Security Industry Association 

To learn more about Schreiber’s involvement in the VOI Committee and the SPARC Community, visit:  

https://www.safeguardsconsulting.com/knowledge/schreiber-joins-sias-voice-of-the-industry-voi-committee-to-assist-security-practitioners-advancing-real-conversations-sparc  

Release of the October 2025 Safeguards Consulting Chronicle

Our team is proud to share that we recently released the October issue of our firm's monthly newsletter, The Safeguards Consulting Chronicle, and we would love to invite you to subscribe for free. This year, we are also proudly celebrating the Chronicle’s second anniversary, and in addition, this June, we celebrated our 30th anniversary issue!   

Our newsletter covers numerous industry events, news, and updates.  

Some of the items we included in our October issue were:       

+ A featured friend spotlight piece on our friend and newest client, the Isuzu North America Corporation.  

+ An exclusive article written by our Principal Consultant and President, Mark Schreiber, “Security Compliance: Helpful or Limiting?”.    

+ A list of beneficial industry events, that includes events we are supporting/speaking at, as well as other events we recommend attending.      

+ Our list of useful blog articles.       

+ A selection of key industry news and updates.       

+ A quick industry tip provided by our experts.      

This month’s “Featured Friend” will also feature our friend and past client, EPRI!    

If interested, please subscribe using the hyperlink included below.     

Newsletter Signup — Safeguards Consulting, Inc. 

When you subscribe to our newsletter, you gain access to all the exclusive security content mentioned above, as well as our newsletter archive, so that you never miss an issue! We hope these resources will help you in your role as a security professional. It also allows us to keep you updated regarding company news, updates, or events.  

Release of the January 2025 Safeguards Consulting Chronicle

We are proud to share that we recently released the January issue of our firm's monthly newsletter, The Safeguards Consulting Chronicle, and we would love to invite you to subscribe for free. This year we are also proudly celebrating its second anniversary!  

Our newsletter covers numerous industry events, news, and updates.  

Some of the items we included in our January issue was:    

+ A featured friend spotlight piece on GDS Associates.    

+ A exclusive article written by our Founder, Mark Schreiber, “The Key Value of Physical Security Business Relationships”.  

+ A special New Year’s message. 

+ A list of beneficial industry events, that includes events we are supporting/speaking at, as well as other events we recommend attending.    

+ Our list of useful blog articles.     

+ A selection of key industry news and updates.     

+ A quick industry tip as provided by our experts.     

This month’s featured friend will also be our partner, Sasaki Associates!   

If interested, please subscribe using the hyperlink included below.    

Newsletter Signup — Safeguards Consulting, Inc.    

If you subscribe to our free newsletter, you gain access to all the exclusive security content mentioned above as well as additional content we hope will help you in your role as a security professional. It is also a wonderful way for my firm to stay in contact with you regarding company news, updates, or events so please consider subscribing in time for our February issue!