- Learn
- Align
- Perform
- Review
Review5 min read
Post Coverage Is a Protective Audit, Not a Finance Task
By J Damien Scott, Trusted Advisor
An unfilled post is an unprotected site, and the record that proves the post was filled is the same record that bills the client. Redesigning timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and exception review cut revenue leakage by 95% at a 127-account security enterprise. The finance result was real. The protective result was larger, and it is the one most security leaders never claim.
An unfilled post is an unprotected site
A contract security operation sells hours of presence at defined posts. The client's risk assessment justified the post, the post order defines what the officer does there, and the schedule commits a named, licensed, trained person to it. Every one of those links is a protective control. When a post goes unfilled, or is filled by someone unlicensed, or is filled for six hours and billed for eight, the site is less protected than the contract says and the client does not know.
Finance sees the same event as leakage: hours worked that were never billed, or hours billed that were never worked, or overtime paid that the contract will not recover. The two views are of one record. That is the argument of this article: the controls that stop money leaking are the controls that prove protection was delivered, and a security leader who leaves them to finance has given away the audit of their own program.
“Every hour that leaked from the invoice was an hour a client paid for protection that nobody could prove was delivered.”
What the numbers found
As Chief Operations Officer, with full-charge P&L ownership across 127 accounts, I reduced revenue leakage by 95%. The mechanism was five controls redesigned together: timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and a formal exception review, all under customer account governance. In the same period, overtime expense fell by 90% through restructured staffing models, schedule discipline, supervisor accountability, review of schedule exceptions, and a qualified relief bench.
The leakage was not fraud in the main. It was the accumulated effect of a schedule that lived in one system, a timekeeping record that lived in another, and an invoice built from a third, with nobody reconciling the three at the level of a single post on a single night. Reconciliation exposed the pattern immediately: posts filled from the relief bench and never re-entered against the right contract, call-offs covered by overtime that the contract capped, and a handful of posts where the schedule said covered and the timekeeping said nothing.
That last category is the one that matters for protection. A post where the schedule says covered and the timekeeping record says nothing is either a timekeeping failure or an absence. Until reconciliation forces the question, the program cannot tell which, and a program that cannot tell whether its posts were staffed cannot claim it protected the site.
Preventive controls and detective controls
The 2025 edition of the GAO's Standards for Internal Control, the Green Book, includes an appendix of examples of preventive and detective control activities and the sources of data that support them. The distinction is the right lens for a protective operation. A preventive control stops the unfilled post from happening: a staffing model with a relief bench, a licensing check at onboarding, a scheduling rule that will not assign an unlicensed officer to a regulated state. A detective control finds the unfilled post after the fact: the reconciliation of schedule against timekeeping against invoice.
Programs invest in preventive controls because they are visible and feel like management. They underinvest in detective controls because a detective control's product is bad news. The 95% figure came almost entirely from the detective side. The staffing model and the relief bench prevented recurrence, but the reconciliation is what revealed the scale of the problem, and without the revelation the prevention would have been sized wrong.
COSO's Internal Control Integrated Framework names monitoring as one of the five components of effective internal control, and issued separate guidance in 2009 on monitoring because organizations were treating it as an afterthought. Reconciliation is monitoring. It is the component that tells the other four whether they worked.
Exception review is the review loop
A reconciliation that only produces a corrected invoice has done half its job. The other half is the formal exception review: every mismatch between schedule, timekeeping, and contract is logged as an exception, classified by cause, and reviewed on a fixed cycle by the operations lead and the account owner together. The classification is what converts a billing correction into a protective finding. A run of exceptions at one site means the staffing model is wrong for that site. A run of exceptions from one supervisor means a training or accountability problem. A run of exceptions on one contract means the contract's post structure no longer matches the client's risk.
ISO 31000:2018 sets out monitoring, reviewing, and continually improving risk management as criteria for a functioning framework. Exception review is that criterion applied to the most granular unit a security operation has, one post on one shift. The Three Lines Model adds the question of who reviews the reviewer: the account owner who checks the operations lead's exception log is the second line, and the internal audit that samples the log is the third.
Licensing belongs in the same loop. Full licensing compliance across five regulated states came from onboarding controls, renewal tracking, supervisor verification, compliance reporting, and exception escalation, which is the same five-part structure as the leakage controls. An unlicensed officer on a post is both a regulatory exposure and an unprotected site, and the exception review catches it for the same reason it catches an unbilled hour.
The cycle matters as much as the content. A weekly exception review is short enough that the supervisor who worked the shift is still available to explain it, and long enough that a pattern across a week is visible. Monthly is too slow: by the time a run of exceptions at one site is noticed, the client has had four weeks of thinner coverage than the contract states, and the relief bench that would have fixed it has been assigned elsewhere. The review also needs a written disposition for every exception, even a one-word one, because an exception log with gaps is itself an exception, and an auditor will read it that way.
What the CFO and the CSO share
The chief financial officer wants the invoice to be right and the overtime to be recoverable. The chief security officer wants the post to be filled by the right person. They are looking at the same record, and in most organizations they have never compared notes on it. The security leader who claims the reconciliation as a protective audit gains two things: the evidence that the program delivered what the contract promised, and a seat in the conversation about margin that security is normally excluded from.
Review feeds Learn. The exception log is a map of where the operation's protective posture is weakest, drawn from its own records rather than from an assessment. The posts that keep appearing in it are the posts an adversary would find first. A protective program that reads its own billing exceptions as intelligence has understood what the Review phase is for.
Field Notes · by email
One email when a new article publishes. Nothing else.
Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.
Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes
Related reading
More from Review
Review · 10 September 2026
The After-Action Review Is Where Review Happens
Exercises produce findings. After-action reviews produce change, and only when the corrective action has an owner, a date, and a place in the next plan. Four conflict-affected operating environments, two country evacuations, and a post-earthquake recovery taught what a rigorous after-action review looks like, who has to own what comes out of it, and how findings feed threat intelligence rather than a filing cabinet.
5 min readReview · 9 September 2026
Three Numbers a Protective Program Must Report
Activity counts are not measures. A protective program that reports patrols completed and alerts reviewed is describing effort, and effort is not what leadership is paying for. Three numbers describe effectiveness: detection time, response time, and mitigation effectiveness. Each needs a defined clock and a defined denominator, or the number is theatre. This article sets out how each was defined and moved in practice.
5 min readReview · 8 September 2026
The Internal Audit Is a Protective Control
Operations cannot see its own gaps from inside. An internal audit against a standard and the organization's own documented practice finds what daily work hides, and the closing meeting is where leadership decides what to do about it. Six ISO/IEC 27001 Clause 9.2 audits delivered for client organizations show how the method works, and why protective programs, which are almost never audited this way, need it most.
5 min read