Getting branch security right requires balancing the risks of both under-protection and over-investment. By grounding decisions in objective, third-party risk data, bank security leaders can allocate resources more effectively, reduce unnecessary costs, and build security strategies that are consistent, proportionate, and easier to defend.
When bank security directors think about the cost of getting branch security wrong, they usually think about the obvious scenarios. A robbery. An assault. An incident that makes the news. These are the incidents that are easy to quantify: insurance claims, legal exposure, reputational damage, the human cost to staff and customers.
While those errors certainly command attention, there is a more subtle, more dangerous, and far more common error that can potentially undermine all of your security controls. The remedy for this error can be answered with one simple question: WHAT IS THE BASIS FOR YOUR BRANCH SECURITY DECISIONS?
Any decision, no matter how wise, is likely to be ineffective if it’s based on errant data. If your security decisions aren’t based on objective data, you run the very real risk of missing the mark. This error can compound as more decisions are made, increasing your trajectory further from the risk management bullseye.
Using the wrong data creates two ways to get branch security wrong, and they’re equally costly in different ways.
The Cost of Under-Protection
The first and more obvious failure mode is under-protecting a location…deploying insufficient security measures at a branch that has higher risk than anticipated.
The direct costs here are well understood: incident response, potential liability, workers’ compensation claims if staff are harmed, the cost of reactive upgrades after something goes wrong. But the indirect costs are often larger.
Staff turnover is a significant consequence of chronic under-protection. Associates who feel unsafe at work leave. Recruiting and training replacements is expensive…estimates for replacing a single bank branch employee run between 50% and 200% of annual salary* when you account for recruiting, onboarding, and lost productivity. In a high-crime location where turnover is consistently elevated because staff don’t feel protected, that cost compounds year over year, though it’s largely invisible in any security budget conversation.
Operational disruption is another. A branch that experiences a serious incident often faces days or weeks of reduced operating capacity, staff reassignments, management attention diverted from normal operations, and a prolonged period of elevated anxiety that affects customer experience and staff performance.
Reactive upgrades cost more than proactive ones. Besides the additional cost of crisis management following an incident, installing security equipment reactively typically costs more. Rushing enhancements like installing additional cameras, adding a vestibule, or bringing in a guard service on short notice limit the ability to vet costs and vendors, and will likely end up costing more…you’re paying a premium for urgency
There’s another cost that’s hard to put a number on but is a serious consideration. When a location had risk indicators that weren’t recognized or weren’t acted on, and something subsequently happened, the question follows “Why didn’t we know this was a risk?” That’s a difficult question for any security director to face.
The Cost of Over-Protection
The issue of over-protection gets less attention, but can be equally problematic.
This can happen fairly often and for understandable reasons. When local staff are vocal about perceived risk, like a branch manager who insists their location needs enhanced measures, it can be easier to approve the request than to push back without objective evidence. When there’s been a high-profile incident somewhere in the portfolio, security protocols across all locations tend to elevate, regardless of whether individual locations warrant it.
The result is security spend that doesn’t match actual risk.
Direct over-investment is the most obvious consequence: money spent on equipment, services, or personnel at locations where a lower-cost alternative would have been entirely adequate. For a mid-size bank managing 50 to 300 branches, even modest over-investment per location aggregates into a significant budget problem.
Operational friction is a less obvious but equally real cost. Over-secured branches create friction for customers and staff alike. Excessive access controls, unnecessary guard presence, layouts that treat every customer as a threat…these things affect the customer experience and can work against the relationship-banking model most institutions are embracing. Security measures that don’t match the environment don’t just waste money; they can actively work against the bank’s customer experience goals.
Credibility with leadership. Perhaps the most damaging long-term cost of over-investment is what it does to the security function’s standing in budget conversations. When leadership perceives that security spending isn’t calibrated to actual risk, or when enhancements are approved at locations that never experience issues, it becomes harder to make the case for investment where it genuinely matters. These kinds of misjudgments at lower risk locations make it harder to get approval for the higher-risk ones.
Why Both Failures Share the Same Root Cause
Under-protection and overprotection look like opposite problems, but they share a common origin: security decisions made without an objective baseline for what the risk actually is.
When decisions are driven by incident history, local perception, staff advocacy, or gut instinct, and without an actual risk assessment, the result is a security posture that can reflect the loudest voices and the most memorable events rather than the actual distribution of risk across the portfolio.
The branch manager who’s been desensitized to chronic low-level crime gets under-resourced. The branch manager who’s still shaken by a robbery three years ago gets over-resourced. Neither outcome is based on a clear-eyed view of current risk.
This is the core problem that objective, third-party risk data solves. It’s not about replacing local knowledge because local context will always matter. But security leaders need a consistent, defensible, objective baseline that isn’t subject to the distortions of human perception and organizational politics. A baseline that lets you look at every location in the portfolio and say, with confidence: “This is what the risk actually is here, independent of what anyone thinks or remembers or feels about it.”
The Justification Problem
There’s a final cost worth naming, because it affects security directors personally and professionally even when nothing goes wrong.
Making security recommendations without objective data means defending every decision on the basis of judgment alone. That’s a difficult position to be in, especially in budget conversations with executives who are weighing security investment against competing priorities and asking pointed questions about return and necessity.
The security leader who can point to an independent, third-party risk assessment and say “this is what the data shows about this location, and here’s what it indicates we need to do” is in a fundamentally stronger position than one who is asking leadership to trust their instincts. The decision is the same. The defensibility is completely different.
Getting branch security right isn’t just about preventing incidents. It’s about using objective data to make risk-based decisions that are proportionate, consistent, and justifiable. Decisions that hold up whether the outcome is an uneventful year or something that ends up in front of a board.
* Source: https://www.joinforma.com/resources/employee-replacement-costs?
—
Want to see how a mid-size national bank built a more objective, defensible security decision frameworks with CRIMECAST from CAP Index? See the story here.
Recent Posts

Beyond the Map: How Place Shapes Health in Arkansas

3 Questions That Change the Way You Think About Security Risk (ESRM)
