By Jorge Daniel Mejía
In 1987, Jan Carlzon introduced a concept that transformed the way organizations understood their relationship with customers: Moments of Truth. According to Carlzon, every interaction between an individual and an organization represents an opportunity to strengthen or weaken perceptions of service quality (Carlzon, 1987).
Although this concept originated in the field of customer service, its application extends far beyond marketing. In the field of security, Moments of Truth are arguably even more significant, because they are the precise moments when people evaluate whether protection systems, processes, and resources truly fulfill their intended purpose.
Security is often invisible when it functions effectively. However, when a risk situation, emergency, or need for assistance arises, that invisibility disappears and the ultimate test emerges: the ability to respond.
It is in those moments that people form an opinion about the effectiveness of the entire security program.
When Security Becomes an Experience: The Moment of Truth
Security is one of the few organizational functions whose success often goes unnoticed—until something happens. As long as the environment operates normally, protection remains invisible. However, when an emergency, a risk situation, or even a simple request for assistance arises, that invisibility immediately disappears. It is in that critical moment that every interaction becomes a real-time evaluation of an organization’s ability to protect people and inspire confidence.
Based on this premise, we can define a Security Moment of Truth as:
“Any interaction in which an individual directly or indirectly experiences an organization’s ability to prevent, respond to, protect against, or manage a risk-related situation.”
These moments may last only seconds or extend for hours, but they share one common characteristic: they create a lasting perception of the effectiveness of security.Trust is built—or lost—in those moments.
If we accept that perceptions of security are shaped through experiences, then it becomes essential to identify the key touchpoints where organizations either gain or lose the trust of the people they serve. The following are some of the most significant Moments of Truth in any security program.
The Primary Security Moments of Truth
The First Interaction
The first contact with a security program typically occurs at an entrance, checkpoint, reception area, or access control point. While this may appear to be a routine interaction, it has a significant impact on how people perceive security. The way procedures are implemented immediately communicates messages about an organization’s level of professionalism, organization, and control. When the process is efficient, consistent, and respectful, it fosters confidence and reinforces a sense of security. Conversely, when people perceive improvisation, disorder, or a lack of consistency, doubts begin to emerge regarding the security program’s ability to respond effectively to more complex situations. In many cases, this initial interaction becomes the first assessment an individual makes of an organization’s overall security posture..
Requesting Assistance
Every organization encounters situations in which someone requires assistance. This may involve a simple request for directions, the reporting of suspicious activity, a medical emergency, or any circumstance that creates concern or vulnerability. In these moments, perceptions of security are not shaped solely by the final resolution of the issue. They are also influenced by the manner in which assistance is provided. Responsiveness, empathy, and professionalism often have as much impact as the solution itself. This perspective aligns with the principles of Enterprise Security Risk Management (ESRM) promoted by ASIS International, where stakeholder trust is recognized as a critical component of an effective security program (ASIS International, 2019).
Managing an Emergency
Critical incidents represent the most visible and demanding test of any security program. Fires, threats, accidents, natural disasters, operational disruptions, acts of violence, or any other crisis situation challenge an organization’s true response capabilities. In these circumstances, plans, procedures, and resources cease to be documents and tools; they become actions.
When an emergency occurs, people do not evaluate the quality of written protocols—they evaluate the effectiveness of the response. They assess whether leadership is present, whether actions are coordinated, whether decisions are made quickly, and, above all, whether those managing the situation are capable of conveying confidence, calm, and control amid uncertainty.
Incident Investigation
Once the initial situation has been brought under control, a new need emerges: understanding what happened, why it happened, and what actions will be taken moving forward. At this stage, people expect to be heard, receive follow-up, and obtain clear information about the investigative process. Perceptions of security are no longer shaped solely by the management of the incident itself, but also by the quality of the communication that follows.
When there is silence, a lack of feedback, or a perceived sense of indifference, trust can be damaged even when the investigation is being conducted properly. Conversely, transparency, support, and a commitment to keeping stakeholders informed strengthen organizational credibility and reinforce confidence in the security program.
Crisis Communication
One of the most common mistakes in security management is assuming that an effective operational response is sufficient to meet the expectations of those involved. In reality, people need more than timely action—they need to understand what is happening and how the situation is being managed.
When information is limited or unavailable, uncertainty often gives rise to anxiety, rumors, and a loss of trust. For this reason, communication has become an essential component of modern security management. Research in crisis management has consistently demonstrated that the quality of communication during an emergency significantly influences public perception, organizational trust, and an organization’s ability to recover from disruptive events (Coombs, 2015).
Providing clear, accurate, and timely information not only contributes to more effective incident management, but also strengthens organizational credibility and reinforces a sense of control during periods of uncertainty.
Beyond Technology
Digital transformation has fundamentally reshaped the way organizations manage security. Today, security professionals have access to advanced technologies such as artificial intelligence, video analytics, facial recognition, remote monitoring, automation, and increasingly sophisticated detection systems. These capabilities have significantly enhanced the ability to prevent, identify, and respond to threats.
However, even the most advanced technologies have a limitation: they cannot fully replace the human experience during a critical moment. An organization may possess the most sophisticated security infrastructure available, but if people perceive disorganization, a lack of support, or an inadequate response during a crisis, their perception of security will remain negative.
Technology strengthens operational capabilities and improves decision-making, but it is human interaction that builds trust. This perspective aligns with the principles of organizational resilience outlined in ISO 22316, which recognizes trust, leadership, and organizational culture as essential components of an effective response to disruptive events (ISO, 2017).
In modern security programs, technology and human leadership must work together. True effectiveness is achieved through the integration of technological capabilities and human-centered response.
A New Way to Measure Security
For decades, security effectiveness has been measured primarily through operational indicators such as incident reduction, response times, procedural compliance, and levels of technological coverage. These metrics remain essential for evaluating organizational performance and the maturity of security capabilities.
However, there is another dimension that often receives far less attention: the human experience.
Beyond statistics and performance metrics, organizations should ask themselves a fundamental question: How do people remember the security program when they needed it most?
The answer may reveal strengths and weaknesses that no technical report can fully capture. In this sense, the experiences of users and other stakeholders become a complementary indicator capable of providing valuable insight into the maturity and effectiveness of a security program (ASIS International, 2019).
Ultimately, security should not be viewed solely as an operational function designed to prevent and respond to incidents. It is also an experience—one that directly influences trust, perception, and organizational reputation.
Conclusion
Jan Carlzon demonstrated that an organization’s reputation is not built solely through major strategic decisions, but through thousands of interactions that occur every day between people and the institution. In the field of security, this principle is particularly relevant. Every touchpoint—whether an access control checkpoint, a request for assistance, incident management, an investigation, or the response to an emergency—represents an opportunity to demonstrate professionalism, responsiveness, and commitment to those who depend on the security program.
Although security programs are designed to protect people, assets, and operations, their true value becomes evident when someone faces uncertainty and expects an effective response. It is in those moments that perceptions of security become tangible realities and the true Moment of Truth occurs.
Ultimately, the strength of a security program is not measured solely by the technology it possesses or the resources it manages, but by the trust it is capable of generating when it is needed most.
During a crisis, no one asks how many cameras an organization has, how many procedures have been documented, or how much has been invested in technology. What truly matters is whether the response was effective, whether communication was clear, and whether people felt protected.
KPIs measure security performance. Moments of Truth measure the trust that security inspires.
References
- Carlzon, J. (1987). Moments of Truth. Cambridge, MA: Ballinger Publishing Company.
- Coombs, W. T. (2015). Ongoing Crisis Communication: Planning, Managing, and Responding (4th ed.). Thousand Oaks, CA: Sage Publications.
- International Organization for Standardization (ISO). (2017). ISO 22316: Security and Resilience — Organizational Resilience — Principles and Attributes. Geneva, Switzerland.
- ASIS International. (2019). Enterprise Security Risk Management: Principles and Guidelines. Alexandria, Virginia.
- Pine, B. J., & Gilmore, J. H. (1999). The Experience Economy. Harvard Business School Press.

