Sphere State Group: Investigations and Asset Recovery https://spherestatellc.com/ Solving problems in protection of people, information, reputation, and environments. Coaching young and aspiring professionals. Tue, 12 May 2026 03:04:06 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 https://spherestatellc.com/wp-content/uploads/2024/07/ssg_fav.png Sphere State Group: Investigations and Asset Recovery https://spherestatellc.com/ 32 32 Standardizing Physical Security, Threat Preparedness, and Grant Compliance https://spherestatellc.com/resilience/security-for-nonprofits-blog/standardizing-physical-security-grant-compliance/ Tue, 12 May 2026 02:58:24 +0000 https://spherestatellc.com/?p=8429 Subject: Standardizing Physical Security, Threat Preparedness, and Grant Compliance     Executive Summary  In an era where security challenges require structured, decisive action, Sphere State is committed to establishing robust defense frameworks for our communities and facilities. This bulletin details critical physical vulnerabilities observed in the field, psychological principles of crisis training, and systematic compliance strategies for procuring security hardware. By transitioning […]

The post Standardizing Physical Security, Threat Preparedness, and Grant Compliance appeared first on Sphere State Group.

]]>

Subject: Standardizing Physical Security, Threat Preparedness, and Grant Compliance  

 

Executive Summary 

In an era where security challenges require structured, decisive action, Sphere State is committed to establishing robust defense frameworks for our communities and facilities. This bulletin details critical physical vulnerabilities observed in the field, psychological principles of crisis training, and systematic compliance strategies for procuring security hardware. By transitioning from reactive security measures to active, compliance-driven deterrence, we protect our most vital institutional assets. 

 

  1. Critical Field Observations: Fortifying Access Control

Security evaluations across local facilities have highlighted major, addressable vulnerabilities at primary entry points. To maintain a secure perimeter, nonprofit   administrators must immediately mitigate these physical weaknesses: 

  • Unlocked and Unattended Entrances: Evaluators consistently find main entrance doors left unlocked or wide open. This lack of basic access control has directly enabled unauthorized individuals to walk in unchallenged and perpetrate thefts or security disruptions. 
  • The Risk of Gatekeeper Complacency: Even when staff are present, they occasionally hold doors open for visitors without questioning them, allowing unvetted individuals carrying unmonitored items inside. 
  • Compromised Keypads: Cipher locks and digital keypads are only secure if the combinations are kept private. Staff must stop writing access codes down on paper or posting them near keypads, which completely defeats their electronic security function. 
  • Structural Failures: Many primary entry doors lack forced-entry resistance, displaying worn frames, rusted metal, or unsecure hinges that can be easily pried off from the outside. 
  • Active Screening and the “Power of Hello”: A robust access protocol requires actively challenging all entrants. Staff must engage visitors to verify their identity and purpose before granting access. Implementing proactive screening methodologies, such as the Power of Hello, allows staff to assess incoming individuals in a friendly but vigilant manner. 

 

  1. Training Protocols: Psychology & Frequency

Security hardware is only as reliable as the personnel trained to use it. When implementing emergency plans, Sphere State emphasizes two critical operational realities: 

Overcoming the “Freeze” Response

Most crisis training ignores a simple fact: humans naturally freeze under pressure. We solve this through Situational Awareness Training. 

Our program moves staff past paralysis by teaching them to recognize threats before they escalate. By establishing environmental baselines and mental “if-then” scripts, your team learns to act while others are still processing shock. 

We deliver this training directly to your organization, providing the tools to turn hesitation into decisive action. 

 Increasing Training Frequency

Conducting emergency training on an annual basis is largely ineffective; critical survival information and procedural retention fade within hours or days of a single session. To build reliable muscle memory and maintain operational readiness, facilities should conduct emergency training at least quarterly. 

 

  1. Strategic Procurement & Grant Compliance Framework

Utilizing security grants requires strict adherence to strict purchasing protocols. Sphere State has established a structured methodology to ensure that hardware upgrades are procured legally and with complete financial accountability. 

Appoint a Project Manager 

Assigning a dedicated internal project manager directly correlates with smoother vendor implementation, fewer project delays, and overall grant success. 

Isolate Scopes of Work 

Security upgrades should be separated into distinct scopes of work rather than bundled under a single, massive contract. Standard scopes include: 

  • Fences and gates 
  • Door hardening and locking systems 
  • Access control and video surveillance 
  • Intrusion detection 

Because a single contractor rarely specializes in all of these areas, isolating these scopes prevents low-quality subcontracting and ensures specialized vendor performance. 

Conduct Manufacturer Research 

While grant guidelines prohibit contacting local integrators before officially advertising a bid, facilities can safely contact product manufacturers directly to learn about specific hardware solutions. To safeguard proprietary project details, execute a Non-Disclosure Agreement (NDA) with manufacturers before sharing specific facility schematics. This ensures that regional integrators do not gain premature knowledge of your project before the bidding window opens. 

Ensure Rigid Compliance Safeguards 

When managing grant spending, adhere to the following procedural requirements: 

  • Public Advertisements: Any equipment or installation category valued over $10,000 must be formally advertised in geographically diverse local newspapers. 
  • Diverse Spending (MWBE): Ensure compliance with state-mandated spending allocations to Minority and Women-Owned Business Enterprises (MWBE). 
  • The Three-Bid Mandate: Always secure at least three independent bids for evaluation. 
  • Predetermined Evaluation Criteria: Establish a standardized scoring matrix before sending out bid documents to ensure objective, bias-free vendor selection 
  • Exhaustive Record-Keeping: Keep detailed notes of all meetings, phone calls, and screenshots of bid advertisements. Proper documentation is vital for reimbursement approval. 

 

  1. Technical Deployments & Cloud Surveillance Risks

As surveillance technologies transition to cloud-based infrastructures, nonprofit   administrators must balance analytical benefits against strategic risks: 

  • Bandwidth and System Security: Modern video surveillance systems support off-site cloud backups and advanced video analytics. However, these systems must align with internal IT capabilities to ensure sufficient bandwidth, network security, and consistent uptime. 
  • Mitigating “Hostageware” Risks: Beware of high-pressure sales models where camera hardware is strictly tied to mandatory, ongoing cloud subscription fees. If monthly payments are interrupted or discontinued, vendors can remotely disable the cameras entirely, leaving your facility vulnerable. 

 

Conclusion: Securing Our Common Ground 

Achieving a resilient security posture is not about transforming our community spaces into impenetrable fortresses, but about establishing a culture of active vigilance and disciplined execution. By addressing physical vulnerabilities at our primary entry points, committing to consistent, psychologically grounded training, and adhering to strict, compliant procurement workflows, we ensure that our facilities remain both safe and welcoming. 

Security is an ongoing practice, not a one-off project. Sphere State stands ready to support nonprofit  administrators and safety teams as we collectively implement these vital standards to protect what matters most. 

 

The post Standardizing Physical Security, Threat Preparedness, and Grant Compliance appeared first on Sphere State Group.

]]>
Hardening the Entry: A Strategic Approach to Physical Perimeter Security https://spherestatellc.com/resilience/security-for-nonprofits-blog/hardening-the-entry-a-strategic-approach-to-physical-perimeter-security/ Thu, 26 Mar 2026 03:26:07 +0000 https://spherestatellc.com/?p=8331 In an era where digital threats often dominate the conversation, the fundamental importance of physical security remains a cornerstone of comprehensive risk management. Whether protecting a corporate headquarters, a data centre, or a high-value asset facility, the integrity of your perimeter is only as strong as its weakest point: the entry. To ensure your facility provides more than […]

The post Hardening the Entry: A Strategic Approach to Physical Perimeter Security appeared first on Sphere State Group.

]]>

In an era where digital threats often dominate the conversation, the fundamental importance of physical security remains a cornerstone of comprehensive risk management. Whether protecting a corporate headquarters, a data centre, or a high-value asset facility, the integrity of your perimeter is only as strong as its weakest point: the entry. 

To ensure your facility provides more than just a “false sense of security,” it is essential to move beyond basic hardware and adopt a rigorous, engineering-led approach to door hardening and physical access control. 

  1. The Administrative Foundation: Procurement & Documentation

Before a single bolt is turned, a secure project begins with a robust administrative framework. Effective physical security upgrades require a clear Request for Proposal (RFP) package. This package should go beyond simple product requests and include: 

  • Detailed Specifications: Bulleted lists of specific security needs, materials, and expectations. 
  • Procurement Integrity: Adhering to professional standards by seeking a minimum of three competitive bids. 
  • Audit-Ready Records: Maintaining precise documentation of the bidding process and contractor selection to ensure transparency and accountability. 

  1. The “Code-First” Principle

Security never exists in a vacuum. Every upgrade must balance protection with compliance. 

  • Single-Motion Egress: Safety codes often mandate that exiting a building must be achievable in one fluid motion (e.g., using a panic bar). 
  • Jurisdictional Standards: Building and fire codes vary by region. It is critical to consult with local authorities and ensure all hardware is UL-certified to avoid the costly mistake of installing hardware that must later be removed for non-compliance. 

  1. The Anatomy of a Secure Door

Not all doors are created equal. For high-security environments, the material and assembly of the door are as critical as the lock itself. 

  • Materials: Hollow metal doors and steel frames are generally the most secure. Solid wood doors are a viable secondary option, while storefront aluminium doors with large glass panes are significantly more vulnerable and harder to harden. 
  • Five Essential Hardware Features: 
  1. Grade 1 Mortise Locksets: These offer a sturdy metal assembly far superior to flimsy cylindrical locks. 
  2. Pinned/Concealed Hinges: Preventing a door from being lifted off its hinges is just as vital as the lock. 
  3. Latch Guards: A simple, cost-effective metal plate that protects the latch from physical bypass tools (like credit cards or shims). 
  4. Automatic Door Closers: Human error is a major vulnerability. Closers ensure that a door returns to a latched position without manual intervention. 
  5. Multi-Point Latching: On double doors, vertical rod devices provide multiple points of contact, making the door much harder to force open. 

  1. Electrified Locking & Remote Vetting

Modern security logic prioritizes distance. The further you are from a potential threat actor during the access vetting process, the safer you are. 

  • Remote Access: Electrified mortise locks and electronic strikes allow for remote release. 
  • Intercom Integration: Supplementing doors with video intercoms allows staff to verify visitors from a safe distance rather than standing directly behind a door with a peephole. 
  • Fail-Safe vs. Fail-Secure: It is essential to plan for power outages. Most security hardware requires battery backup, and fire codes mandate that certain electrified locks “fail-safe” (unlock) during an alarm to ensure safe evacuation. 

  1. Beyond the Door: The Wall Factor

A high-security door is useless if an intruder can simply punch through the wall next to it. In facilities with sheetrock or lightweight internal walls, reinforcement is necessary. 

  • Steel Mesh Reinforcement: Installing metal mesh within walls can prevent unauthorized entry through the structure itself. 
  • Structural Integrity: Always evaluate the “demising walls” around your frames to ensure they are as robust as the door assembly. 

  1. The Necessity of Maintenance

Security is not a “plug-and-play” solution. Quality installation must be followed by regular, at least annual, maintenance. Over time, frames can warp, doors can fall out of alignment, and latching mechanisms can fail. Preventative walk-arounds and professional inspections are the only way to ensure your hardware performs when it matters most. 

 

Conclusion 

Physical security is a critical layer in the Sphere State Group approach to risk management. By focusing on verified hardware, code compliance, and professional procurement, organizations can move from a “false sense of security” to a hardened, resilient perimeter. 

Contact Our Advisory Team 

For further inquiries on physical security specifications or risk assessments, please reach out to our regional security advisory team. 

Email: info@spherestatellc.com 

 

The post Hardening the Entry: A Strategic Approach to Physical Perimeter Security appeared first on Sphere State Group.

]]>
Event Security Planning for Nonprofits https://spherestatellc.com/resilience/security-for-nonprofits-blog/event-security-planning-for-nonprofits/ Fri, 27 Feb 2026 06:36:33 +0000 https://spherestatellc.com/?p=8062 Event Security Planning for Nonprofits   Nonprofit organizations thrive on community engagement, and events are often the centrepiece of that mission. Whether it’s a holiday celebration, a fundraising gala, or a public awareness campaign, these gatherings bring people together in meaningful ways. Yet, they also introduce risks that must be carefully managed.   Risk Assessment  […]

The post Event Security Planning for Nonprofits appeared first on Sphere State Group.

]]>
Event Security Planning for Nonprofits

 

Nonprofit organizations thrive on community engagement, and events are often the centrepiece of that mission. Whether it’s a holiday celebration, a fundraising gala, or a public awareness campaign, these gatherings bring people together in meaningful ways. Yet, they also introduce risks that must be carefully managed.

 

Risk Assessment 

The event preparation process begins with a clear-eyed assessment of relevant risks. Factors such as the number of attendees, the location, the prominence of the venue, and the profile of speakers all shape the risk landscape. A small indoor gathering at a familiar site may present minimal challenges, while a large outdoor event featuring a controversial speaker at a high-traffic location could elevate the risk considerably. Organizers should weigh these elements systematically, ensuring that no single factor is overlooked, including modern vulnerabilities, such as cyber exposure through livestreams or social media, which can amplify risks far beyond the physical venue.

 

The Planning Cycle

Once the risk profile is established, planning moves into a more detailed phase. It is important to ask practical questions: Is the venue’s security infrastructure adequate? How will guest registration be managed, and will photo identification be required? Who will serve as the central point of contact for incidents, and how will threat scenarios be documented? These considerations extend beyond the event itself, encompassing pre-event preparations such as staff training and venue walkthroughs, as well as post-event debriefs to capture lessons learned. This cyclical approach ensures that each event contributes to a growing body of organizational knowledge and resilience.

 

Sourcing Security Contractors

Selecting the right security firm is another critical step. Contracts should clearly define expectations, and standard operating procedures must be formalized to ensure consistency. Verify licensing, insurance, and financial stability, while also seeking references from clients with similar event profiles. The operational model of the firm—whether relying on subcontractors or employed staff—should be scrutinized, as should the training and background of individual agents. Ultimately, the culture of the firm, reflected in its senior managers, will shape the quality of the partnership. If communication or flexibility falls short during the selection process, move on quickly to other candidates.

 

Deciding on Security Deployment

For events that demand professional security, organizers should develop and follow minimum selection and staffing requirements. Security personnel roles range from an onsite security executive who coordinates with venue operators, to officers managing entry control, vehicle access, and perimeter patrols, with an emphasis on cross-training so that every officer can adapt to multiple responsibilities. This flexibility is crucial in dynamic environments where incidents can escalate quickly and resources must be deployed efficiently.

 

Conclusion

Taken together, this framework provides a roadmap for hosting safe and secure events. By integrating risk assessment, detailed planning, careful vendor selection, and professional staffing nonprofits can create environments where communities feel welcome and protected. In doing so, they not only safeguard their mission but also reinforce trust among donors, participants, and the broader public.

The post Event Security Planning for Nonprofits appeared first on Sphere State Group.

]]>
Exclusive Analysis from Rob Goldberg: The Current Threat Environment https://spherestatellc.com/resilience/security-for-nonprofits-blog/the-current-threat-environment/ Fri, 23 Jan 2026 07:24:03 +0000 https://spherestatellc.com/?p=7864 The Current Threat Environment   This past year, faith-based and communal nonprofit organizations have been the targets of extreme violence, including bomb, chemical, knife, arson, firebomb, rifle, shotgun, handgun, physical assault, intimidation, and property destruction and defacement attacks or threats. The victims of these incidents include houses of worship, schools, museums, community centers, hospitals, care […]

The post Exclusive Analysis from Rob Goldberg: The Current Threat Environment appeared first on Sphere State Group.

]]>

The Current Threat Environment

 

This past year, faith-based and communal nonprofit organizations have been the targets of extreme violence, including bomb, chemical, knife, arson, firebomb, rifle, shotgun, handgun, physical assault, intimidation, and property destruction and defacement attacks or threats. The victims of these incidents include houses of worship, schools, museums, community centers, hospitals, care centers, and other faith and communal organizations.

 

On January 10, 2026, the historic Jackson, Mississippi Beth Israel synagogue was burned to the ground. On September 28, 2025, an assailant attacked a meetinghouse of The Church of Jesus Christ of Latter-day Saints in Grand Blanc, Michigan, resulting in several deaths and injuries. On August 27, 2025, a mass shooting during a school-wide Mass at Annunciation Catholic Church in Minneapolis killed two children and wounded dozens.

 

These illustrations are reflected in the latest (FY 2025) Nonprofit Security Grant Program (NSGP) Notice of Funding Opportunity (NOFO):The frequency and severity of attacks – whether they are hate-based, group-based, opportunistic, or random – are increasing.”

 

The NSGP program was established by Congress in 2004, in recognition of the frequency and severity of attacks targeting faith-based and nonprofit communal organizations in the post-9/11 environment. Between FY 2005 and FY 2024, Congress appropriated to the NSGP program over $1.8 billion, and the Federal Emergency Management Agency (FEMA) has awarded over 14,000 applications.

FY 2026 NSGP Funding Outlook

 

Deep divisions in Congress are currently impeding final negotiations over the pending FY 2026 Homeland Security spending bill. Congress has until January 30 to complete all outstanding Fiscal Year 2026 spending bills, of which the Homeland Security bill will likely be the last to be decided.

 

Bipartisan efforts to reach a compromise on Homeland Security spending derailed after the January 7th deadly shooting of a Minneapolis, MN, driver by an Immigration and Customs Enforcement (ICE) officer. In response to this incident, Democrats in Congress are demanding the final compromise Homeland Security spending bill include new ICE accountability and use of force measures.

 

If a compromise on Democratic demands is achieved before time expires, NSGP funding is expected to increase to as much as $335 million. If time expires without a breakthrough, Congress is likely to extend the current (FY 2025) NSGP funding level of $274.5 million. Either result means that NSGP will be significantly funded for the next grant cycle.

The Next NSGP Grant Cycle  

 

The next (FY 2026) NSGP funding opportunity could commence by late March or early April. Typically, Congress requires FEMA to release the NSGP Notice of Finding Opportunity (NOFO) within 60 days after the legislation becomes law.

 

This past year, FEMA ignored the 60-day requirement, and the completion of the FY 2025 application process remains several months delayed. FEMA also made the FY 2025 application process more difficult by curbing its grant application assistance to the program’s nonprofit stakeholders and providing incomplete and less than transparent grant guidance to the state-level agencies that administer the program application and implementation processes. Whether the FY 2026 process will improve and smooth out is yet to be determined.

 

To counter these unknowns, it is advisable that interested nonprofits start their application preparations now. They should begin by reviewing their respective state’s most recent grant guidance (FY 2025) and use the guidance as a template for drafting their FY 2026 applications. Adjustments to draft work can be made once the official FY 2026 guidance comes out.

 

The basic requirements for all applicants are to complete a Vulnerability Assessment; complete the 7-part application (Investment Justification); and complete a Mission Statement. Obtaining cost estimates will also be necessary to complete the Investment Justification. All of these steps can occur now.

 

Additionally, the state administrative agencies (SAAs) often maintain list-serves of interested stakeholders so they can share updates, alerts, and instructions with nonprofit stakeholders about current and upcoming grant opportunities and activities. It is advisable that interested parties subscribe to these lists.

 

Finally, SAAs often provide application technical assistance and training opportunities to nonprofit stakeholders. It is advisable that interested parties avail themselves of these opportunities when they are scheduled. 

Need advice on your security challenges? Reach out to us at info@spherestatellc.com.

The post Exclusive Analysis from Rob Goldberg: The Current Threat Environment appeared first on Sphere State Group.

]]>
Decoding door hardware, avoiding code violations, and hardening your perimeter without breaking the bank. https://spherestatellc.com/resilience/security-for-nonprofits-blog/decoding-door-hardware-avoiding-code-violations-and-hardening-your-perimeter-without-breaking-the-bank/ Mon, 19 Jan 2026 09:08:35 +0000 https://spherestatellc.com/?p=7835 Securing a Building Isn’t About the Grant. It’s About the Door.  Getting a grant approved feels like a win. For many organizations, it’s the moment everyone exhales. But that letter isn’t the finish line—it’s the point where things actually start to matter.  Because once the funding is in place, you still have to turn dollars into real security. And that’s where mistakes happen.  Doors get reused because “they look fine.” Locks get chosen because they’re familiar. Vendors […]

The post Decoding door hardware, avoiding code violations, and hardening your perimeter without breaking the bank. appeared first on Sphere State Group.

]]>

Securing a Building Isn’t About the Grant. It’s About the Door. 

Getting a grant approved feels like a win. For many organizations, it’s the moment everyone exhalesBut that letter isn’t the finish line—it’s the point where things actually start to matter. 

Because once the funding is in place, you still have to turn dollars into real security. And that’s where mistakes happen. 

Doors get reused because “they look fine.” 
Locks get chosen because they’re familiar. 
Vendors promise solutions that sound secure but fall apart under scrutiny. 

In security, assumptions are dangerous. A door is not just a door. A lock is definitely not just a lock. And when the hardware doesn’t match the threat, all you’ve really purchased is a false sense of protection. 

This article is about the physical reality of securing a perimeter. Not cameras. Not policies. Not paperwork. Just doors, frames, locks, and the decisions that separate real resistance from the illusion of it. 

 

Start With the Door, Not the Technology 

Most security failures don’t start with electronics. They start with the door itself. 

Walk into almost any community center or house of worship built in the last few decades and you’ll see the same thing: aluminum storefront doors with lots of glass. They look open and inviting. They also happen to be one of the weakest perimeter options available – the only worse alternative being no door whatsoever. 

Storefront doors usually have very narrow metal housings with lots of glass. There simply isn’t enough metal there to properly anchor serious hardware. Under force, these doors flex, frames bend, locks pull away, glass shatters. 

A determined attacker doesn’t need to defeat the lock. They just need to deform the door enough for the latch to slip. They can also simply break a large glass pane. 

If your budget allows for replacement, this is where money should go first.  Storefront doors with thicker metal housings are better, but hollow metal doors are the gold standard. They’re rigid, stable, and designed to take abuse without warping. 

Solid core wood doors can work too, but only if you understand their limitations. Wood moves. Temperature and humidity matter. Once you get into tall exterior wood doors—especially over eight feet—you’re asking for alignment problems. And alignment problems turn locked doors into unsecured ones. 

 

Why the Lock You Choose Matters More Than You Think 

One of the most common—and costly—mistakes in security upgrades is using residential-grade locks on commercial perimeter doors. 

If the key goes into the knob or lever, you’re looking at a cylindrical lock.  

Source: https://www.gharabanao.com/shop/godrej-cylindrical-lock-wooden-keyed-5809-17003

These are fine for houses and interior rooms. They are a poor choice for exterior doors that matter. 

Cylindrical locks rely on short latch bolts and the physical strength of the knob itself. A hard strike can shear the knob off entirely. Even without brute force, the short latch throw makes them easy to pry if the door shifts even slightly out of alignment—which happens in almost every building over time. 

Mortise locks are built for a different world. 

Source: https://www.inoxproducts.com/mortise-locks

With a mortise lock, the cylinder is separate from the handle, and the entire mechanism sits inside a steel pocket in the door. These locks are designed to be abused. The latch throw is deeper. The dead latching is real. Once the door closes, the latch is mechanically frozen in place. 

You can’t slide it back with a tool. You have to operate the lock. 

That distinction alone stops an enormous number of forced-entry attempts. 

 

When Electronics Make Things Worse 

Electronic access control is where good intentions often create new vulnerabilities. 

Magnetic locks are a perfect example. They’re common, familiar, and often pitched as a clean solution for access control. On paper, a maglock sounds impressive—over a thousand pounds of holding force. 

Source: https://www.digimarkbd.com/blog/what-is-an-em-lock/

But here’s the reality: maglocks are fail-safe by design. Lose power or trigger the fire alarm, and the door unlocks. Cut electricity, and your perimeter opens. 

That means your security depends entirely on continuous power. 

Then there’s the exit motion sensor.  

Source: https://warroom.rsmus.com/wp-content/uploads/2014/11/REX.jpg

Most maglocks rely on a PIR sensor to unlock the door as someone approaches from the inside. These sensors are notoriously easy to trick. Warm air. Paper slipped through a gap. A simple tool in the right place. 

The result is a door that can be unlocked from the outside without ever touching the reader. 

There are situations where maglocks are unavoidable—certain glass assemblies leave no alternative—but they should never be the default. 

A better approach is to keep the door mechanically secure and add electronics to the lock itself. 

Electric strikes are common, but they introduce a moving part into the frame. Under impact, that keeper becomes the weak point. 

Source: https://www.securityinformed.com/companies/hid-global/products/assa-abloy-hes-es100-electronic-locking-device-technical-details.html

Electrified mortise-type locksets avoid that problem entirely. The door stays latched. The electronics only control whether the outside handle works. When someone kicks the door, they hit steel—not a small mechanical release. 

 

What to Do When Replacement Isn’t an Option 

Not every building can be gutted and rebuilt. Historic properties, limited grants, and phased projects are realities. 

The good news is that targeted retrofits can still add meaningful resistance. 

Latch guards are a great exampleThey’re simple metal plates that cover the gap between the door and frame near the lock. They aren’t pretty. They are extremely effective. A crowbar can’t reach what it can’t access. 

Source: https://latchprotector.com/products/3-5-x-11-75-latch-protector-full-cut-out-stainless-steel-lp225-latch-guard


 Exposed lock cylinders are another weak point. If a cylinder can be gripped, it can be twisted out. A spinning collar removes that leverage entirely.

Source: https://www.giahardware.com/Em_D_Kay_SPC3_Brass_Spring_Type_Cylinder_Collar_Fo_p/spc3.htm

Outward-swinging doors bring hinge problems. If the pins are exposed, the door can be removed even if it’s locked. Security hinges or non-removable pins solve that issue without changing the door itself. 

Sources: https://www.reddit.com/r/homedefense/comments/1ecdexa/how_to_secure_this_outward_swing_door_hinges_are/

These aren’t high-tech solutions. They’re practical ones. 

 

Glass Is Always the Compromise 

Vision panels in door loafs are often necessary. Blind doors create safety issues. But glass placement matters more than most people realize. 

If someone can break glass and reach the handle, the door is compromised. Glass should be narrow and placed as far from the locking hardware as possible. 

Source: https://www.trend-usa.com/project-vision-panel

And despite what many people believe, wire glass is not a security feature. The embedded wire actually makes the glass weaker by creating fracture points. It was designed for fire containment, not impact resistance. 

If replacement isn’t possible, anchored security films can significantly improve resistance. Laminated glass or polycarbonate is even better. 

 

Security Still Has to Follow the Code 

No matter how serious the threat is, life safety always comes first. 

Egress doors must allow people to exit with a single motion. No keys. No combination. No second step. Double-cylinder deadbolts on exit doors are not just dangerous—they’re illegal. 

Fire Marshals have the authority to shut facilities down over non-compliant hardware. Improper modifications can avoid fire ratings and insurance coverage. These aren’t theoretical risks. 

Good security works with the code, not against it. 

 

The Real Takeaway 

Security isn’t about buying the most advanced system. It’s about choosing the right components for the threat. 

mechanically sound door with a proper mortise lock will outperform an expensive electronic system built on weak hardware. Every time. 

Start with the shell. Strengthen the door and frame. Choose hardware that resists force. Add technology only after the fundamentals are solid. 

That’s how you move from looking secure to being secure. 

 

The post Decoding door hardware, avoiding code violations, and hardening your perimeter without breaking the bank. appeared first on Sphere State Group.

]]>
Sphere State Security Briefing: The Strategic Guide to Grant Compliance and Hardening https://spherestatellc.com/resilience/security-for-nonprofits-blog/sphere-state-security-briefing-the-strategic-guide-to-grant-compliance-hardening/ Mon, 05 Jan 2026 09:52:21 +0000 https://spherestatellc.com/?p=7804 The journey from receiving a security grant award letter to standing behind a hardened perimeter is rarely a straight line. For many organizations, the initial excitement of securing funding is quickly replaced by the crushing administrative weight of procurement rules, environmental reviews, and vendor management.    In this Sphere State Security Briefing, we provide a comprehensive operational roadmap […]

The post Sphere State Security Briefing: The Strategic Guide to Grant Compliance and Hardening appeared first on Sphere State Group.

]]>

The journey from receiving a security grant award letter to standing behind a hardened perimeter is rarely a straight line. For many organizations, the initial excitement of securing funding is quickly replaced by the crushing administrative weight of procurement rules, environmental reviews, and vendor management. 

 

In this Sphere State Security Briefing, we provide a comprehensive operational roadmap to bridge the gap between administrative compliance and physical security implementation. Whether you are navigating the Federal Nonprofit Security Grant Program (NSGP) or a state-level initiative, the difference between a successful project and a bureaucratic nightmare often comes down to strategy, not just funding. 

Below, we dismantle the complexities of the “Three Bid Rule,” debunk common hardware myths regarding barriers and guard posts, and outline how to turn “check-the-box” training into genuine survival muscle memory. 

Part I: The Administrative Foundation 

“If it isn’t written down, it didn’t happen.” 

Before a single screw is turned or a camera mounted, the administrative foundation must be solid. Grant management is not a passive activity; it requires a rigorous devotion to record-keeping that can withstand a state audit three years from now. 

The “Master File” Protocol 

One of the most practical takeaways for any grant recipient is the concept of the Master File. Years after your project is complete, the government may audit your expenses. Will you be able to produce the email chain where you solicited a bid from a minority-owned business? Will you have the screenshot proving you publicly advertised the project in a local journal? 

You must maintain a centralized, redundant repository of every interaction, bid, decision, and delay. This file is your insurance policy. If a vendor delays your project, document the follow-up emails. If you choose the second-lowest bidder because the lowest bidder didn’t meet the technical scope, document the justification immediately. 

The Golden Rule of Procurement: The “Three Bid” Mandate 

The most common point of failure in security execution is the Three Bid Rule. Generally, you are required to solicit three written bids for each project within your grant. 

However, the definition of “project” acts as a trap for the unprepared. If you treat your camera installation, your alarm system, and your access control as three separate projects, you create triple the administrative work. 

The Strategy: Project Consolidation Do not fragment your security upgrades. Instead of managing eight small contracts—one for front doors, one for back doors, one for a camera server—consolidate them. 

  • Bundle Related Systems: Combine CCTV, alarms, and access control into a single “Integrated Security Technology” Request for Proposal (RFP). 
  • The Benefit: You only run one bidding process. You find a single “Prime Contractor” or integrator capable of handling the entire scope. This reduces your administrative burden and prevents the “blame game” where the door vendor blames the lock vendor for a malfunction. 

The Advertising Threshold 

Be aware of the “public advertising” tripwire. For many federal and state grants, if a specific contract exceeds $10,000, you are often required to advertise the bid publicly (e.g., in a local newspaper or business journal) to ensure fair competition. 

  • Sealed Bids: For these larger projects, you must often utilize a formal “sealed bid” process, where contractors submit pricing without seeing competitors’ offers. 
  • The “No Bid” Scenario: If you advertise and only one vendor responds, you cannot simply hire them by default. You must demonstrate a “good faith effort” to find competition. This means documenting phone calls, re-posting ads, and actively soliciting quotes. Without this paper trail, your reimbursement request may be denied. 

Part II: Financial Strategy & Resource Allocation 

Maximizing the “Hidden” Funds 

Many organizations view the grant solely as money for hardware. This is a mistake. A successful security strategy utilizes every allowed expense category to ensure professional implementation. 

Leveraging M&A (Management & Administration) 

Most security grants allow you to allocate up to 5% of the total award for Management & Administration (M&A) costs. This is essentially “free money” to ensure the project is run correctly. 

  • External Support: You can use these funds to hire a dedicated grant writer or project manager to handle the bidding process, paperwork, and vendor oversight. 
  • Internal Staffing: Crucially, you can use M&A funds to pay existing employees, but only for overtime. You cannot “supplant” their regular salary (paying them for work they would have done anyway). It must be for hours worked above and beyond their normal schedule, supported by meticulous timesheets. 

The Reality of Supply Chain Extensions 

In the current global economy, delays are inevitable. Whether it is microchips for cameras or steel for bollards, supply chains are fragile. 

  • Do Not Panic: If you cannot complete your project within the performance period due to vendor delays, extensions are possible. 
  • The “Blanket” Extension: State administering agencies are often aware of these macro-level issues. If you communicate early and document that you placed the order on time, you will likely fall under a “blanket extension” issued to all grantees facing similar shortages. 

 

Part III: Hardening the Target 

Moving from Paperwork to Physical Reality 

Once the procurement hurdles are cleared, the focus shifts to hardware. This is where “shiny object syndrome” often leads organizations astray. We must establish a hierarchy of effectiveness, distinguishing between feeling safe and being safe. 

The Barrier Myth: Boulders vs. Bollards 

A frequent request from organizations is to use grant funding for “aesthetic” barriers—large stone planters, masonry walls, or landscaping rocks—rather than industrial steel bollards. 

The Engineering Reality: A standard stone wall or planter is not a vehicle barrier. Unless a barrier is certified and engineered with a specific Crash Rating (such as K-ratings or ASTM standards) to stop a vehicle moving at speed, it is often ineligible for funding. 

  • The Risk: A truck moving at 30 mph possesses immense kinetic energy. A non-reinforced stone wall will not stop it; it will merely become shrapnel. 
  • The Requirement: If you want to use the grant for vehicle mitigation, you must install rated bollards or engineered barriers. Do not assume a local mason can build a “security wall.” 

The “Guard Shack” Prohibition 

Another common misconception involves the construction of guard booths. 

  • New Construction Rule: Most security grants strictly prohibit “new construction.” They are designed to harden existing infrastructure. 
  • The Verdict: Building a freestanding guard shack in your parking lot is generally not an allowable expense. 
  • The Workaround: You can often use funds to harden an existing vestibule or entryway. Retrofitting an existing structure to create a “man-trap” with electronic locks and bullet-resistant glass is considered a renovation, not new construction, and is usually eligible. 

Gates and Fencing: The Narrative Consistency 

If you intend to install electronic gates or perimeter fencing, ensure this was explicitly detailed in your original Vulnerability Assessment. 

  • The Audit Trail: State analysts will compare your receipts against your initial application. If your assessment focused entirely on active shooter threats inside the building, but you spend $50,000 on a perimeter fence, your reimbursement will be flagged. Your spending must mirror the “Investment Justification” you submitted to win the grant. 

Part IV: The Human Element 

Training, Drills, and “Muscle Memory” 

The most sophisticated lock in the world is useless if the person holding the key panics. Security hardware buys time; security training buys survival. 

Beyond the Lecture Hall 

One of the most critical failures in organizational security is the reliance on passive learning. Sitting in a lecture hall listening to a PowerPoint presentation on “Active Shooter Response” does not create preparedness. It creates awareness, but not competence. 

The Standard: Drills with “Injects” Effective training requires the development of muscle memory. 

  • The Methodology: You must run physical drills. Furthermore, these drills must include “injects”—unexpected variables introduced mid-scenario. 
  • Example: During an evacuation drill, tell a staff member, “This exit is blocked by smoke.” Watch how they react. 
  • The Lizard Brain: In a crisis, the cognitive brain shuts down and the “lizard brain” takes over. If the physical act of locking a door or evacuating hasn’t been rehearsed to the point of instinct, staff will freeze. 

The Role of Law Enforcement 

Do not train in a vacuum. It is highly recommended—and often looked upon favorably by grant administrators—to involve local law enforcement in your training. 

  • Site Familiarity: Invite Community Affairs or Counter-Terrorism officers to walk your site. You want them to know your floor plan before a 911 call is made. 
  • Protocol Alignment: Your staff needs to know how to behave when the police arrive with weapons drawn. (e.g., “Show your palms,” “Do not run toward officers”). This alignment prevents “blue-on-blue” tragedies or confusion during a response. 

 

Part V: Conclusion 

Policy Over Product 

Security is a puzzle. It is not solved by a single camera, a hardened door, or a roll of window film. It is the integration of administrative compliance, sturdy hardware, code-compliant installation, and rigorous operational policy. 

The Final Takeaway: 

  • By following the procurement rules, you ensure you actually receive the funding you were promised. 
  • By choosing the right hardware (rated bollards, anchored film, mortise locks), you ensure the physical barrier holds. 
  • By investing in active training, you ensure your people know how to use the time those barriers buy them. 

In the realm of Sphere State security, we do not rely on luck. We rely on documentation, engineering, and preparation. 

The post Sphere State Security Briefing: The Strategic Guide to Grant Compliance and Hardening appeared first on Sphere State Group.

]]>
Homeland Security Appropriations Update https://spherestatellc.com/resilience/security-for-nonprofits-blog/homeland-security-appropriations-update-2/ Sat, 20 Dec 2025 02:32:29 +0000 https://spherestatellc.com/?p=7749 Dear Nonprofit Security Friends: On Friday, Senate Republican appropriators unveiled a long-delayed Homeland Security bill for fiscal 2026, recommending $65.95 billion in discretionary funding, a slight decrease from the House version. The bill lacked bipartisan support (particularly over border security, immigration enforcement, and detention provisions) and had no committee markup. While the House version also […]

The post Homeland Security Appropriations Update appeared first on Sphere State Group.

]]>
Dear Nonprofit Security Friends:

On Friday, Senate Republican appropriators unveiled a long-delayed Homeland Security bill for fiscal 2026, recommending $65.95 billion in discretionary funding, a slight decrease from the House version.

The bill lacked bipartisan support (particularly over border security, immigration enforcement, and detention provisions) and had no committee markup.

While the House version also lacked bipartisan support, it was reported out of committee in June on a party-line vote.

The House bill contains $335 million for the Nonprofit Security Grant Program. The Senate bill includes $330 million.

Should the competing bills get to a bi-cameral conference (formally or informally) to work out competing differences, the NSGP funding level will likely fall between the narrow margin of difference between the bills.

This all but closes the door on securing the $500 million NSGP allies in Congress and stakeholder advocates have pursued.

When Congress returns from its holiday the first week in January, they will have a little more than 3 weeks to complete the outstanding FY 2026 Appropriations bills before the current temporary funding extension (Continuing Resolution) runs out.

For many years, the Homeland Security spending bill has been one of the hardest for both parties to agree on, and this year’s partisan disagreements are significant and could very well result in another year-long funding extension as a result. If this were to occur, NSGP would be expected to be flat funded again at $274.5 million.

[Note: In 2024, NSGP received an annual appropriation of $274.5 million. But the total amount Congress made available to NSGP that year was significantly boosted by a one-time national security supplemental (HR 815) of $400 million. The total of $674.5 million dwarfed any previous year’s appropriation for NSGP.]

Best,

Rob Goldberg
Principal
Goldberg & Associates LLC
In Partnership with Sphere State

The post Homeland Security Appropriations Update appeared first on Sphere State Group.

]]>
Nonprofit Security Program Updates https://spherestatellc.com/resilience/security-for-nonprofits-blog/nonprofit-security-program-updates-3/ Thu, 18 Dec 2025 01:46:38 +0000 https://spherestatellc.com/?p=7742 Dear Nonprofit Security Friends: Congress established the Nonprofit Security Grant Program in 2004, as the first singular program to provide for the security of the Jewish community and faith-based and other at-risk nonprofit institutions. The Jewish community led on the program’s inception because targeted attacks on synagogues and Jewish Community Centers became a security risk […]

The post Nonprofit Security Program Updates appeared first on Sphere State Group.

]]>
Dear Nonprofit Security Friends:

Congress established the Nonprofit Security Grant Program in 2004, as the first singular program to provide for the security of the Jewish community and faith-based and other at-risk nonprofit institutions.

The Jewish community led on the program’s inception because targeted attacks on synagogues and Jewish Community Centers became a security risk of national importance post-September 11 attacks.

I had already been working with Congress to develop the NSGP program in the winter of 2001, which took on new urgency in June 2002, when the FBI warned that Al-Qaida might attack Jewish targets with gas trucks, leading to widespread concern and need for heightened security in Jewish communities nationwide. (See: JTA, “Jewish vigilance high after FBI warning,” June 25, 2002; Link: https://www.jta.org/2002/06/25/lifestyle/jewish-vigilance-high-after-fbi-warning.) This incident became a unifying catalyst among Jewish communal advocates to secure enactment of NSGP legislation nearly two years later.

Since then, and too frequently, Jewish communal and other faith-based and nonprofits have been targets of foreign terrorist organizations, homegrown violent extremists, racially or ethnically motivated violent extremists, and grievance-driven malicious actors.

The Israel-Hamas war has been a particularly pivotal event that has triggered an escalation of violence in communities throughout the country and globally – and also targeting Muslim and Arab communities at home.
In May, Elias Rodriguez was charged with federal and local murder offenses in connection with the fatal shooting of two Israeli Embassy staff members outside the Jewish National Museum in Washington, D.C. Moments after the shooting, Rodriguez entered the museum, displayed a red keffiyeh and allegedly said, “I did it for Palestine. I did it for Gaza.” (See: U.S. Attorney’s Office, District of Columbia, “Federal Hate Crime and First-Degree Murder Charges Filed Against Alleged Killer of Israeli Embassy Staff Members,” August 7, 2025; Link: https://www.justice.gov/usao-dc/pr/federal-hate-crime-and-first-degree-murder-charges-filed-against-alleged-killer-israeli.)

In June, Mohammed Sabry Soliman was charged with 12 hate crimes and murder for throwing incendiary devices at individuals participating in a pro-Israel gathering near the Boulder, Colorado, Courthouse. 82-year-old Karen Diamond, died of her injuries. When throwing one of the Molotov cocktails, Soliman reportedly shouted, “Free Palestine!” Investigators recovered a handwritten document recovered from the vehicle driven by Soliman that  included the following statements: “Zionism is our enemies untill [sic] Jerusalem is liberated and they are expelled from our land,” and further described Israel as a “cancer entity. (See: Department of Justice, Office of Public Affairs, “Alleged Perpetrator of Terror Attack in Colorado Charged with Hate Crimes,” June 25, 2025; Link: https://www.justice.gov/opa/pr/alleged-perpetrator-terror-attack-colorado-charged-hate-crimes.)

Also in June, Muhammad Shahzeb Khan was extradited to the United States from Canada, in connection with charges he attempted to enter the United States to commit a mass shooting on a Jewish community center in Brooklyn, New York. Khan allegedly planned to carry out this attack “on or around Oct. 7, 2024 — which Khan recognized as the one-year anniversary of the brutal terrorist attacks in Israel by Hamas.” (See: Department of Justice, Office of Public Affairs, “Pakistani National Extradited to Face Charges in Connection with Plot to Carry Out ISIS-Inspired Mass Shooting at Jewish Center in New York City,” June 10, 2025; Link: https://www.justice.gov/opa/pr/pakistani-national-extradited-face-charges-connection-plot-carry-out-isis-inspired-mass.)

Jewish and other religious holidays, including Chanukah and Christmas, have also occasioned terrorist threats and attacks.

In August, Mufid Fawaz Alkhader was sentenced to 10 years in prison for, in part, twice firing a shotgun while standing outside the entrance to Temple Israel in Albany, New York, during Chanukah 2023. During the incident he was allegedly “shouting ‘Free Palestine!’” It was reported that “As a result of Alkhader’s actions, Temple Israel was forced to cancel a planned concert and candle lighting ceremony to celebrate Chanukah that evening, and its congregants were afraid to return to their place of worship.” See: Department of Justice, Office of Public Affairs, “New York Man Sentenced for Firearm and Religious Hate Crimes Involving the Firing of Shots Outside of Temple Israel in Albany,” August 12, 2025; Link: https://www.justice.gov/opa/pr/new-york-man-sentenced-firearm-and-religious-hate-crimes-involving-firing-shots-outside.)

In the U.S. in 2023, the Jewish community faced an already elevated and increasing threat level even before the major spike in antisemitism that occurred (and has been sustained) after the October 7 Hamas attack on Isreal. February, March, April, May, and September 2023 each broke the prior record for the most antisemitic incidents recorded in a single month in ADL’s history. According to the ADL, February, March, April, May, and September 2023 each broke the prior record for the most antisemitic incidents recorded in a single month in ADL’s history. (See: ADL, “Audit of Antisemitic Incidents 2023,” April 16, 2024; Link: https://www.adl.org/resources/report/audit-antisemitic-incidents-2023.) These elevated months coincided with the 2023 Jewish holidays of Purim, Passover, Shavuot, Rosh Hashannah, Yom Kippur, and Sukkot.

The December 14, deadly mass casualty attack targeting Chanukah celebrants in Sydney, Australia, has placed US cities on alert. For instance, the New York Policy Department issued a post-incident assessment that found “there have been at least 48 major incidents targeting synagogues and Jewish community events worldwide, since the 7 October 2023 Hamas-led mass casualty attacks against Israel.” They further assessed that the December 14 attack “and its perpetrators will likely be praised and exploited by a variety of violent extremists to justify or incite similar acts of terrorism against the Jewish community.” (Source: NYPD Shield Post-Attack Assessment, “Mass Casualty Terrorist Attack Targets Hannukah Celebration on Australia’s Bondi Beach,” December 14, 2025.)

2025 has been particularly violent and NYPD’s assessment includes advice that tracks long-standing recommendations: Jewish communal and other faith-based and nonprofit institutions should employ access denial and target hardening measures, tabletop exercises, and emergency protocol/response drills. These are the very investments FEMA’s Nonprofit Security Grant Programs support.

With wave after wave of antisemitic attacks and hate crimes that have occurred in 2025, Congress will return for the second session of the 119th Congress on January 5, 2026, with a number of unfinished nonprofit security measures to consider, including:

– The FY 2026 NSGP program funding. New York Senators Chuck Schumer and Kirsten Gillibrand are seeking $500 million. This would constitute a $225.5 million increase above the $274.5 million appropriated level in 2025.

– The “Pray Safe Act” (H.R. 5645). New York Representatives Grace Meng (D-NY-6), Michael Lawler (R-NY-17), and Daniel Goldman (D-NY-10) are leading on this bipartisan bill, which would establish a federal clearinghouse through which faith-based organizations, houses of worship, and other nonprofits can access information on safety and security best practices, available federal grant programs, and training opportunities.

[I note that in 2019, another deadly Chanukah attack took place in Rep. Lawler’s district, had served to amplify calls from community members and leaders around the country to increase federal funding and actions to protect at-risk nonprofit organizations. (See: JTA, “After a machete stabbing on Hanukkah, Monsey’s Orthodox Jews are defiant but searching for answers,” December 29, 2919; Link: https://www.jta.org/2019/12/29/united-states/after-a-machete-stabbing-on-hanukkah-monseys-orthodox-jews-are-defiant-but-searching-for-answers.)]

– The “DHS Grants Accountability Act” (H.R.6507). New York Representative Timothy Kennedy (D-NY-26) is the author of this bill, which would ensure greater accountability, predictability, and transparency at FEMA over its administration of the State and local preparedness (including NSGP), transit, and port security grant programs.

Of the more than 11 thousand hate crimes (with close to 14 thousand victims) reported by the FBI in 2024, religious bias crimes in 2024 represented 23.5% of all hate crimes reported. Although Jews only make up around 2 percent of the U.S. population, anti-Jewish hate crimes comprised 16 percent of all reported hate crimes and nearly 70 percent of all reported religion-based hate crimes in 2024, slightly higher than the prior year.

In 2025 (as recorded between December 31, 2024 and December 15, 2025), the FBI reports hate crime incidents having occurred against every category of Religion, including Anti-Jewish, Anti-Islamic (Muslim), Anti-Catholic, Anti-Protestant, Anti-Sikh, Anti-Hindu, Anti-Buddhist, Anti-Mormon, Anti-Jehovah’s Witness, Anti-Eastern Orthodox, Anti-Multi-Religious Group, Anti-Other Christian, and Anti-Atheist/Agnostic. Incidents have occurred nationwide. (Source FBI Crime Data Explorer Link: https://cde.ucr.cjis.gov/LATEST/webapp/#/pages/explorer/crime/hate-crime.)

While issues of Jewish communal security are a particular concern for New York (hence the above leadership on the issue), the risks are high, nationally, for Jews and for the faith-based communities and the nonprofit sector at large. This is why over the years, NSGP and related legislation to improve the program and nonprofit security, generally, have been supported in both the House and the Senate, by Members of Congress from across the political spectrum, representing city, urban, and rural communities.

The nation’s law enforcement and counterterrorism experts cannot predict where, when, and how the next terrorist attack targeting a faith-based or communal institution will occur. (Source: DHS Office of Intelligence and Analysis, “Homeland Security Assessment 2025,” October 2, 2024; Link: https://www.dhs.gov/publication/homeland-threat-assessment.)

This is why at-risk faith-based and communal institutions must have access to resources to prepare themselves against likely continued threats. Therefore, it is imperative that the NSGP program, and legislative initiatives to strengthen the program and nonprofit security resources, are available to adequately serve ALL communities. These efforts should be broadly supported by the greater faith-based community and nonprofit sector at large.

When Congress resumes legislative activities in January, I urge ALL OF YOU to reach out to your Members of Congress to seek their support for the above bulleted initiatives, and to call on your state and national advocates, associations, and fellow community partners to do the same.

Thank you for your consideration.

I wish you a safe and happy holiday season.

Best,

Rob Goldberg
Principal
Goldberg & Associates LLC
In partnership with Sphere State
To access content page: https://spherestatellc.com/resilience/security-for-nonprofits-blog/
To inquire about subscription plans: info@spherestatellc.com

The post Nonprofit Security Program Updates appeared first on Sphere State Group.

]]>
Navigating procurement, debunking hardware myths, and maximizing your security funding. https://spherestatellc.com/resilience/security-for-nonprofits-blog/security-grant-procurement-guide/ Tue, 16 Dec 2025 09:03:33 +0000 https://spherestatellc.com/?p=7722 The journey from receiving a security grant award letter to standing behind a hardened door is rarely a straight line. For many organizations, the excitement of securing funding is quickly replaced by the administrative weight of procurement rules, environmental reviews, and vendor management. In this Sphere State Security Briefing, we provide a comprehensive summary of the […]

The post Navigating procurement, debunking hardware myths, and maximizing your security funding. appeared first on Sphere State Group.

]]>

The journey from receiving a security grant award letter to standing behind a hardened door is rarely a straight line. For many organizations, the excitement of securing funding is quickly replaced by the administrative weight of procurement rules, environmental reviews, and vendor management.

In this Sphere State Security Briefing, we provide a comprehensive summary of the essential steps required to bridge the gap between administrative compliance and physical security implementation. Whether you are managing a Federal Non-Profit Security Grant Program (NSGP) award or a State-level Hate Crimes grant, the principles laid out here are the difference between a successful project and a bureaucratic nightmare.

The Administrative Foundation

“If it isn’t written down, it didn’t happen.” Before a single screw is turned, the administrative foundation must be solid. Grant management is not a passive activity. It requires an active relationship with your grant representative and a rigorous devotion to record-keeping.

The Documentation Strategy: The “Master File”

One of the most practical takeaways is the concept of the “Master File.” If the government audits your project three years from now, will you be able to produce the email chain where you solicited a bid from a minority-owned business? Will you have the screenshot proving you advertised the project? You must maintain a centralized repository of every interaction, bid, and decision.

The Golden Rule of Procurement: Three Bids

The most common point of failure is the “Three Bid Rule.” You are generally required to solicit three bids for each project within your grant. If you are installing access control and applying window film, that constitutes two separate projects, requiring two separate sets of three bids.

The Request for Proposal (RFP) Necessity

You cannot simply ask three vendors for a price. If Vendor A quotes you for a basic system and Vendor B quotes you for an enterprise solution, you cannot justify your decision to the state. You must create a Request for Proposal (RFP) that dictates the scope, ensuring an “apples-to-apples” comparison.

Public Advertisement Requirements

For many grants, you are required to publicly advertise the opportunity. Failing to take this step before selecting a vendor can result in reimbursement denial.

Operational Oversight

The Critical Role of the Project Manager

A critical operational gap found in many organizations is the lack of a designated Project Manager. Security upgrades are complex construction projects. Relying on a volunteer committee often leads to missed deadlines or poor vendor oversight.

You do not necessarily need to hire an outside consultant, but you must designate a specific person within your organization who owns the scope, coordination, execution, and documentation of the project.

Hardening the Target: Doors and Hardware

Moving from paperwork to physical security, we must establish a hierarchy of door hardware.

Door Materials and Construction

Not all doors are created equal. Aluminum storefront doors are a security liability. They are lightweight, pliable, and dominated by glass. They cannot withstand forced entry tools or blast waves effectively. Hollow metal doors or solid wood doors are the standard for exterior perimeter security.

Frame Integrity and Anchoring

A heavy door on a weak frame is useless. The frame must be anchored into the structure of the building, not just the drywall.

Locking Mechanisms: Cylindrical vs. Mortise

Details matter. We distinguish between cylindrical locks and Mortise locks.

  • Cylindrical Locks: These have the key cylinder located inside the knob or lever. They are prone to physical attacks and torque.

  • Mortise Locks: These are recessed into the door itself. The key cylinder is separate from the handle mechanism. They are far more robust, offer higher security grades (ANSI Grade 1), and are much harder to force open.

Life Safety and Code Compliance

“Code comes first.” You cannot install a double-cylinder deadbolt (which requires a key to exit) on a fire exit. Security cannot come at the expense of life safety. All hardware must allow for “single motion egress”—meaning one push of a bar or lever opens the door for evacuation.

The Glass and Film Reality Check

Perhaps the most important segment of this briefing is the debunking of “Bulletproof Glass.”

Terminology: “Bullet Resistant” vs. “Bulletproof”

“Bulletproof” does not exist. The correct terminology is Bullet Resistant or Blast Resistant. Given enough time and caliber, everything fails. The goal is resistance—buying time for law enforcement to arrive.

The Necessity of Structural Anchoring

Many vendors will sell security film to apply over existing windows. However, if that film is not anchored to the window frame (using a structural silicone or mechanical attachment), it offers a false sense of security.

In a blast or forced entry event, unanchored filmed glass will simply fly out of the frame as one solid sheet. It might not shatter, but it won’t stop an intruder or a shockwave. Your RFP must specify wet-glazing or mechanical anchoring systems.

Electronic Access Control

Policy Over Product

Organizations must resist “shiny object syndrome.” Buying a complex system is useless without a policy for who gets in.

The Religious Observance Dilemma

For institutions that must adhere to Sabbath or holiday laws (where electricity cannot be used), the challenge is real. Do not rely on mechanical punch codes (cipher locks), as the codes are easily shared and observed. Instead, utilize systems that can switch modes, or rely on physical security guards and manual door operations during religious observances, while utilizing full electronic lockdown capabilities during the week.

Conclusion

Security is a puzzle. It is not just a camera, a lock, or a piece of film. It is the integration of administrative compliance, sturdy hardware, code-compliant installation, and rigorous operational policy. By following the procurement rules, you ensure you get the money. By choosing the right hardware, you ensure you get the protection.

Meet Our Expert Team

Our cases are led by certified investigators and seasoned experts in financial crime, blockchain forensics, and cross-border recovery. We bring decades of experience to your case.

Ilya Umansky Photo

Ilya Umansky

Partner and Director

Former Global Security project executive with over 25 year of experience in risk, security, and crisis management. Delivered more than 500 threat and vulnerability assessments and security upgrade projects for nonprofits.

Björn Wahlström Photo

Björn Wahlström

Partner & Group CEO

More than 20 years in risk, security, crisis management. Numerous international risk assessments.

Jussi Aittola Photo

Jussi Aittola

Senior Partner

Former senior EU law enforcement professional with over 20 years in risk, security, and crisis management.

The post Navigating procurement, debunking hardware myths, and maximizing your security funding. appeared first on Sphere State Group.

]]>
Nonprofit Security Program Updates https://spherestatellc.com/resilience/security-for-nonprofits-blog/nonprofit-security-program-updates/ Mon, 15 Dec 2025 02:08:18 +0000 https://spherestatellc.com/?p=7709 Dear Nonprofit Security Friends, A few updates in the final stretch of the calendar year. I. FY 2025 NSGP Funding Opportunity: We are experiencing an NSGP grant cycle like no other. Never before has there been a level of disengagement and disenfranchisement between FEMA’s Grant Programs Directorate with the State Administrative Agencies (SAAs) and the […]

The post Nonprofit Security Program Updates appeared first on Sphere State Group.

]]>
Dear Nonprofit Security Friends,

A few updates in the final stretch of the calendar year.

I. FY 2025 NSGP Funding Opportunity
:

We are experiencing an NSGP grant cycle like no other.

Never before has there been a level of disengagement and disenfranchisement between FEMA’s Grant Programs Directorate with the State Administrative Agencies (SAAs) and the nonprofit stakeholder community.

The cycle has been defined by late, staggard, and incomplete grant guidance, unexplained (and unpublished) policy and funding decisions (and lack of funding decisions), an absence of stakeholder training, technical assistance, shared or posted notices, updates, and alerts, or even a point of contact.

The previous uniformity of process that made the NSGP program a coordinated, coherent, and accountable program across the States was largely absent for the 2024 NSS funding opportunity and even more so in the present FY 2025 cycle.

While the NSGP application process and program administration have never been perfect, there were efforts within FEMA to advance and improve stakeholder relationships (and a reliable program lead) and legislative efforts to address program and funding short cummings.

The program has followed a predictable, congressionally mandated timeline for years that is now being ignored. The NSGP application process generally took place between February and August, with SAAs receiving FEMA award notifications before September 30, and nonprofits receiving SAA grant acceptance letters between October and November (if not sooner).

In the present FY 2025 environment, twelve State Attorneys General have filed a lawsuit against the Administration challenging their policy and funding decisions surrounding the preparedness grants. This is a fist.

Every SAA has had to act for and by themselves in terms of navigating last year’s (FY 2025 ended September 30th) hollowed out application process. Some have completed the application process, some are just starting it, and others are still waiting, leaving nonprofit applicants across the country with an uneven and unreliable funding opportunity.

Last week, I worked with a client to complete a Florida application, which was due on Friday, December 12. That same day, I received notification from the Oregon Department of Emergency Management (OEM) that they just opened their application process with a January 15, 2026, deadline. The New York State Division of Homeland Security and Emergency Services has only posted a place holder message: “The next round of the NSGP is expected to be released soon.”

One bit of information I gleaned from the OEM notification is that they “must submit project proposals to FEMA by Friday January 30, 2026.” Presumably, this deadline originated from a FEMA communication to OEM and could possibly apply to ALL SAAs
.

OEM also maintains a “Federal Update” page, which includes what I have found to be the most organized and useful archive of preparedness grant programs (including FY 2025 NSGP) details. I recommend ALL interested parties keep tabs on this page regularly:
https://www.oregon.gov/oem/Pages/Federal-Changes.aspx.

II. FEMA Overhaul Spotlight:

Last week, the FEMA Review Council was scheduled to meet to deliberate and vote on a much-anticipated final report on FEMA reform recommendations. White House officials abruptly interceded to cancel the 12-member council meeting just moments before it was set to begin.

The interruption occurred reportedly after and in reaction to a news outlet’s sharing details of a leaked copy of the final report.

According to CNN, Council report recommendations included “the most sweeping overhaul of FEMA in decades, dramatically reducing the federal agency’s role in disaster response by cutting its workforce in half and rolling out a new block grant system designed to get aid to communities faster and with less bureaucratic hassle.”

The article also focused on apparent heavy-handed interference, changes, or elimination of recommendations made by Homeland Security Secretary Kristi Noem to the Council’s recommendations in previous iterations of the report draft. While Council appointees by the President are mostly Republican, they are considered to be experienced and expert in emergency management matters.

The article may be read in its entirety at: https://www.cnn.com/2025/12/10/politics/fema-council-report-recommend-downsizing-overhaul.

Neither DHS, FEMA, nor the White House have announced a rescheduling of the meeting.

III. Protecting the NSGP Program:

Notably, the FEMA preparedness programs that support State and local counterterrorism efforts, including the NSGP program, have been absent from what has been discussed in the context of FEMA’s potential overhaul or demise.

However, they will need a home and what comes of these programs could significantly harm the NSGP program, which has relied upon centralized guidelines, program administration, and a distinct funding stream.

I have explained this concern in past congressional statements for the record and testimonies I have written for myself and others, in support of NSGP over the years.

The following are pertinent parts from testimony I drafted for a March 2017 hearing of the Subcommittee on Economic Development, Public Buildings, and Emergency Management Subcommittee of the House Committee on Transportation & Infrastructure Committee to “Examine National Preparedness System and Capabilities:”

“Prior to the establishment of the NSGP program, there was no committed, coordinated, uniform, centralized program that promoted and ensured that at-risk nonprofit institutions participated in and benefited from meaningful Federal, state, and local homeland security efforts…

The Nonprofit Security Grant Program has become an essential component of the preparedness grant programs at FEMA. With a continuing and growing record of threats, attempted attacks, and deadly occurrences targeting Jewish communal institutions, as well to other vulnerable populations within the nonprofit sector, we believe there is ample justification for Congress to maintain the Nonprofit Security Grant Program as a singular, stand-alone initiative as a matter of national security, and should consider ways to strengthen the program, not dismantle it…

Conversely, we strongly believe that any effort to replace the NSGP program as part of a consolidation of the larger preparedness grant programs would disenfranchise at-risk nonprofit stakeholders, who could not be expected to meaningfully participate in or effectively compete with larger, more formidable and connected stakeholders for resources in an integrated competitive process. Such a move would dilute the connectivity and continuity between the local stakeholders and the State Administrative Agencies, as well between national stakeholders [ ], and FEMA.”

The complete testimony may be viewed at: https://transportation.house.gov/calendar/eventsingle.aspx?EventID=401218.

In my view, the reformation or undoing of FEMA could result in the status quo ante for nonprofit stakeholders before NSGP became a program. Federal responsibility, oversight, and funding could be cut, and the program administration and resources could revert to the States and localities in a widely disparate and unequal application of interest and support, leaving nonprofit stakeholders to fend for themselves.

As FEMA reform considerations continue, NSGP advocates should be strenuously advocating that the Administration and Congress protect NSGP as a committed, coordinated, uniformly funded and administered, centralized, competitive program in partnership with the States, territories, localities, and nonprofit stakeholders.

Best,

Rob Goldberg
Principal
Goldberg & Associates LLC
In partnership with Sphere State
To access content page: https://spherestatellc.com/resilience/security-for-nonprofits-blog/
To inquire about subscription plans: info@spherestatellc.com

The post Nonprofit Security Program Updates appeared first on Sphere State Group.

]]>