EPS Dispatch

Workplace Violence Prevention Is a Program, Not a Poster

A policy in the handbook and a sign by the break room is not prevention. Real workplace violence prevention is a living program: understanding the four types, building a threat assessment team, creating a reporting culture, training response, and planning for the aftermath.

KR
Kawika Rogers
6 min read

Most organizations believe they have addressed workplace violence because there is a policy in the handbook and a laminated sign by the break room. That is not prevention. That is documentation of good intentions. Real prevention is a living program with people, process, and practice behind it, and it is one of the most underbuilt areas of corporate security in the country.

Understand the Categories

Workplace violence is commonly sorted into four types, and the distinction matters because the defenses differ. Type one involves an offender with no legitimate relationship to the workplace, typically during a crime such as a robbery. Type two involves a customer, client, patient, or other recipient of services. Type three involves a current or former employee. Type four involves someone with a personal relationship to an employee, often a domestic situation that follows a person to work. A plan built only around the active shooter scenario ignores three of the four most common pathways to harm.

Build a Threat Assessment Capability

The single most effective investment an organization can make is a threat assessment team. This is a small, trained, cross functional group, usually drawing from human resources, security, legal, and management, that evaluates concerning behavior and decides on a measured response. The discipline here is behavioral. Violence is rarely a sudden break. It tends to follow an observable pathway that can include grievance, ideation, planning, preparation, and finally action. People around the subject usually notice something. The question is whether the organization has built a way for those observations to reach someone who can act.

Create a Reporting Culture

A threat assessment team is useless if nothing reaches it. Employees need a clear, low friction, and trusted way to report concerns, and they need confidence that doing so will not blow up into an overreaction or be ignored entirely. The goal is to normalize early reporting of behavior that feels off, well before it becomes a crisis. Fear of being wrong, fear of getting a colleague in trouble, and fear of retaliation are the three things that keep critical information buried until it is too late.

Train Response, Not Just Awareness

When an incident does occur, the staff response is shaped almost entirely by what was rehearsed beforehand. The widely taught framework moves through avoiding the threat, denying it access, and defending as an absolute last resort. The specifics matter less than the fact that people have thought about it, walked their space, identified exits and barricade options, and practiced making fast decisions. A workforce that has never considered these questions will freeze. A workforce that has rehearsed them, even briefly, moves.

Plan for the Aftermath

The incident is not the end of the event. Reunification, communication with families, support for traumatized staff, continuity of operations, and coordination with responders all happen in the hours and days afterward. Organizations that have not planned for the recovery phase often handle the crisis competently and then compound the harm through a chaotic and impersonal aftermath.

Prevention is not a product you buy once. It is a capability you build and maintain, and it lives or dies on whether the people inside the organization trust the system enough to feed it.

What a Working Program Actually Contains

The difference between a program and a poster is whether a reported concern has somewhere to go. Use the list below as an audit rather than a wish list, and mark each item as present, partial, or absent:

  • A written policy that names prohibited conduct in concrete terms, including threats, intimidation, stalking, and weapons on premises, rather than gesturing at professionalism.
  • A standing multidisciplinary team with named members from human resources, legal, security, operational management, and an employee assistance or behavioral health resource.
  • A reporting channel with low friction and an anonymous option, published where employees actually look rather than buried in an onboarding packet.
  • A documented triage step, so that every report is assessed by someone qualified within a defined time rather than absorbed by whoever received it.
  • Case management with written records, assigned ownership, and review dates, because most concerning situations develop over weeks rather than minutes.
  • Explicit escalation criteria for involving law enforcement, agreed in advance so the decision is not improvised under pressure.
  • A separation protocol that treats terminations as security events, with access revocation, timing, location, and staffing planned before the meeting.
  • Access control and visitor management tied into the program, so that a restricted individual is actually restricted at the door.
  • Training differentiated by role, because a supervisor needs to recognize and route concerns while a frontline employee needs to know how to report and how to respond.
  • Drills that include the awkward scenarios, followed by post incident support, after action review, and an annual audit of the program itself.

Common Questions

Who belongs on a threat assessment team?

At minimum human resources, legal, security, and the management chain over the individual concerned, with access to behavioral health expertise. The team needs enough authority to act and enough distance to stay objective, which is why the reporting employee's direct manager should inform the process without owning the decision.

What is the most common failure mode?

Not the absence of warning signs. In the overwhelming majority of reviewed cases the concerns were noticed, and often mentioned to someone, but never reached anyone with the authority and the information to connect them. The failure is routing, not detection.

Does annual awareness training count as a program?

No. Awareness without a case management path produces employees who recognize a problem and have nowhere useful to take it, which is arguably worse than doing nothing because it manufactures the appearance of diligence.

When should law enforcement be brought in?

As soon as conduct crosses into criminal territory, including explicit threats, stalking behavior, or weapons, and without waiting for internal process to conclude. Involving police does not remove the organizational obligation to keep managing the situation.

More from EPS: Bleeding Control Belongs in Every Security Plan, and Walking the Perimeter: A Practical Approach to Physical Security Assessment.

Reference Material: Monitor The Situation; the workplace violence prevention guidance from the Occupational Safety and Health Administration; the threat assessment frameworks developed by the United States Secret Service National Threat Assessment Center; ASIS International and SHRM workplace violence standards; and the Cybersecurity and Infrastructure Security Agency active assailant resources.

Somebody’s gotta do it. Might as well be us.

Mahalos.


About the Author

Kawika Rogers is Managing Partner at Eight Point Solutions LLC, a veteran-led defense consulting and training firm based in Maryland. He served as an Infantry Team Leader in the United States Marine Corps, then directed the Field Training Officer program and served as an Armorer for Triple Canopy at Camp Arifjan and Camp Buehring in support of Operation Inherent Resolve. He has also served in an advisory and operational capacity in Eastern Europe. Rogers holds over 15 instructor certifications in firearms, defensive tactics, and emergency medicine, and studied International Relations and Global Security at American Military University.

Eight Point Solutions LLC 7404 Executive Place, 5th Floor, Suite L-17, Lanham, MD 20706 // rogers@eightpointsolutions.com // eightpointsolutions.com SDVOSB // eightpointsolutions.app // eightpointsolutions-tech.com // SAM UEI: EY34ARER2TD9

Share:

Keep reading