Youngupstarts iconYoungupstartsSep 11, 2026 ~4 min source read

Frank Elsner on Fractional CSOs, Practical Risk Reviews, and Workplace Violence Prevention

Frank Elsner, founder of Stonehaven Risk Group Ltd., explains why companies hire fractional chief security officers, what he looks for in security risk reviews and crisis exercises, and how to build usable workplace violence prevention and supply chain security programs.

Share this story

Send the public story page.

Useful takeaways from this story.

Effective risk reviews start with observing real operations—entry flows, contractor handling, camera coverage and routine weak points—then prioritize fixes into immediate and planned actions.

Crisis exercises should create realistic pressure and information gaps to reveal decision slowdowns and unclear responsibilities, producing concrete changes to plans and roles.

Workplace violence prevention requires a usable reporting and escalation process, clear handoffs between supervisors, HR, security and executives, plus policies, intake processes and post-incident support.

# Overview Frank Elsner has more than 30 years of experience in security, public safety, crisis management and executive leadership. He founded Stonehaven Risk Group Ltd. to provide senior security leadership on a project, retainer, fractional or urgent-response basis. His clients include manufacturers, multi-site businesses, distribution and logistics operations, private companies and family enterprises dealing with security gaps or heightened risk.

# Why fractional CSO? Many companies reach a point where security belongs at the executive table but do not need—or cannot justify—a full-time chief security officer. Elsner built Stonehaven around a fractional CSO model to give organizations one senior person who can: set priorities, advise the CEO or ownership, review budgets, manage vendors and establish accountability. The role provides continuity so a security program advances proactively instead of waiting for a serious incident to force action.

# What a practical security risk review looks like Elsner begins onsite and focuses on how the facility actually operates rather than only on written procedures. He watches how employees enter, how visitors and contractors are processed, which areas are restricted, and whether camera coverage matches exposure. He checks routines that create weak points—for example, differences between daytime staffing and what happens at a loading dock at 6:00 a.m. or late-night operations.

He also reviews policies and interviews the people responsible for the facility to identify gaps between documentation and practice. Final recommendations are prioritized so leadership can see which fixes need immediate attention and which can be scheduled as planned improvements.

# Running useful crisis exercises Elsner designs exercises that deliberately create incomplete information and rising pressure to force real decision-making. Typical decisions tested include whether to shut down operations, who communicates with employees, when to involve legal counsel, who handles external statements, and how to keep essential functions running during an unfolding incident.

# Workplace violence prevention that works Serious prevention starts with a reporting process employees and managers will actually use. When someone reports threatening behavior, harassment, intimidation or escalating conflict, the organization needs a clear path: where information goes, who reviews it and what happens next.

# Supply chain security and C-TPAT experience Elsner led a supply chain security program that met U.S. Customs and Border Protection audit requirements under C-TPAT. That experience informs his advice: examine how goods move, who can access them, how third parties are controlled, what records are kept, and whether documented procedures match daily operations. When reviewing programs he looks for controls that can be demonstrated in an audit and sustained in everyday work.

# Practical implications for leaders Leaders should consider a fractional CSO when security is an executive issue but a full-time hire is not yet justified. Risk reviews must include direct observation of operations and prioritized recommendations. Crisis exercises should simulate information gaps and pressure to expose decision and role weaknesses. Workplace violence programs must provide usable reporting, defined handoffs and follow-through.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app