---
title: Michael J. Gugliotti Brings Security Governance Into the Boardroom
description: Former Waterbury police chief Michael J. Gugliotti on bringing security governance to the boardroom through MJG Consulting Group and HSOS.
author: Darie Nani (Editor-in-Chief)
date: 2026-09-23T10:22:27.747Z
updated: 2026-09-23T10:22:27.763Z
canonical: https://www.sovereignmagazine.com/article/michael-j-gugliotti-security-governance
image: https://cdn.nanimediahouse.com/michael-gugliotti-featured-v3.webp
categories: Leadership, Business
content_type: Spotlight
region: Florida
publication: Sovereign Magazine
about:
  - type: Person
    name: Michael J. Gugliotti
    description: Michael J. Gugliotti served as Chief of Police of Waterbury, Connecticut from 2009 to 2013, capping 25 years in law enforcement, followed by about 15 years in private-sector security leadership. He founded MJG Consulting Group LLC and created HSOS, the Hospitality Security Operating System.
    jobTitle: Founder and Principal Consultant
    worksFor: MJG Consulting Group LLC
    sameAs:
      - https://www.linkedin.com/in/michael-j-gugliotti-91b79644/
---

Michael J. Gugliotti spent 25 years in law enforcement, rising to Chief of Police for the Waterbury Police Department in Connecticut, before moving into [private-sector security leadership](https://www.sovereignmagazine.com/article/strategic-solutions-to-fill-security-gaps) for more than 15 years. That combined experience led him to found MJG Consulting Group LLC, a Lake Worth, Florida, firm organized around a trademarked framework and philosophy he calls "Governance Before Guarding™": the principle that effective security starts before an officer ever reaches a post.

Gugliotti argues that guarding is an activity, while governance is the system that gives that activity direction, accountability and purpose. In practice, that means defining who is accountable for security decisions, what risks an organization is managing, what standards apply, and how leadership measures whether a security program is actually working. He says organizations can own strong policies, trained officers, cameras and access control and still lack governance, because those elements do not automatically connect into a functioning system.

## Security Manager Responsibilities at a Luxury Resort

Before founding the firm, Gugliotti was hired as Security Manager at a luxury resort to professionalize its security department. As he understood the brief, the job covered the day-to-day operation plus the work of setting standards: managing personnel, writing policies and standard operating procedures, improving training, standardizing operations and introducing a consistent program for new hires.

He received little direction from his Director of Security, and his questions and emails about priorities and implementation often went unanswered. Nobody had set out what he was expected to achieve first, which decisions he could make on his own, what resources he had or how his performance would be measured. He wrote a structured training manual for new security officers, but it was never put into use. New officers continued to learn the job from whichever colleague happened to be available, and each trainer passed on his or her own way of doing things rather than a common standard.

Although he had been hired to manage, he was expected to spend much of his time on the same frontline work as the officers he supervised, which left little time for policy, training or planning. The organizational structure gave Human Resources significant oversight of the department, operational matters were regularly passed up to HR, and in practice HR held decision authority over security. Gugliotti says that left it unclear who owned the security function and who was accountable for its performance. The experience became the blueprint for MJG Consulting Group and its governance-first approach.

> "Hiring a security professional is not the same thing as enabling a security professional to lead."
> — Michael J. Gugliotti

His view is that an organization hiring a security manager, a security director or a chief security officer should settle the terms of the job before that person starts. That includes what the new hire is expected to accomplish, who they report to, which decisions they can take independently, what their first priorities are and how success will be judged. Without those answers, he says, leadership may conclude it hired the wrong person when the difficulty lay in how the role was set up, and the next hire is likely to run into the same problem.

## Physical Security Governance and the Law Enforcement Model

All 25 of Gugliotti's police years were spent in Waterbury, where he served as chief from 2009 to 2013, leading a department of about 300. He says he has seen the same governance gap throughout his 40-year career, in policing and in the 15 or so years since in private-sector security. In his experience, law enforcement is organized around a formal governance structure, and [physical security](https://www.sovereignmagazine.com/article/is-safety-an-illusion), which carries many of the same risks and responsibilities, generally is not.

He also sees structured governance as less mature and less consistently formalized in physical security than in cybersecurity, where organizations increasingly operate within established regulatory and governance frameworks.

## Security Governance at Board Level

For executives and boards, Gugliotti frames this as a risk question rather than an operational one. Security failures, he notes, can carry consequences that extend into finances, reputation, insurance considerations, regulatory exposure and litigation. His position is that boards do not need to run daily security operations, but they do need visibility into significant organizational risk, resourcing decisions and accountability structures, in the same way they oversee other material risks.

He says one of the most common misconceptions among executives is that security is primarily an operating expense. He treats it as a form of risk management, and the question he would put to them is what risks the organization is managing, how effectively it is managing them and what the consequences would be if it did not.

When a chief executive, general manager or board member tells him their security program is already good, he starts with a challenge. "I'd tell them that's a good starting point. Then I'd ask them to prove it," he said in an interview with SecuritySolutionsWatch.com. He then asks what the organization's top security risks are, who owns them, how they are measured, when the program was last formally assessed, how the organization knows its employees are properly trained, how deficiencies are documented and corrected, and what security information reaches executive leadership.

## The Security Governance Maturity Assessment, Executive Guide and HSOS

MJG Consulting Group works at three connected levels, starting with the Security Governance Maturity Assessment™, which measures how developed a client's security program is and identifies where the gaps are. The second level, the [Executive Security Governance Framework™](https://www.mjgconsultinggroupllc.com/executive-guide-new), educates leadership. HSOS™, the Hospitality Security Operating System, is the full security governance framework and methodology used to put the changes in place. Gugliotti says he knows of no other consultancy that offers identification, education and implementation as one connected system.

Written for executives rather than security practitioners, the framework gives them a condensed view of organizational risk, strategy, accountability, performance and compliance without requiring them to read a full operational manual. It is also meant to change what security reports to leadership, which in his words should go beyond "We had 14 incidents this month" to cover emerging trends, rising risks, corrective actions taken, remaining deficiencies, the resources required and the decisions that need executive attention.

Gugliotti developed HSOS for organizations that must secure people, property, information and business continuity in environments open to guests, employees, contractors and the public. It covers governance, policies, standard operating procedures, security post orders, forms, training, accountability, audits, implementation and continuous improvement. A standard operating procedure tells an officer how to respond to a situation. Under HSOS, the organization also records who approved that procedure, whether the officer was trained and their competency verified, whether the procedure was followed, how compliance is measured and whether it still suits current risk. HSOS is written for hospitality, though Gugliotti says the thinking behind it applies to other industries.

## Expert Witness and Litigation Support

Gugliotti also works as an expert witness and provides litigation support, applying the same approach to incidents that reach court. An incident may involve one security officer, but his review extends to the system around it: what policies existed, what training was provided, how the property was staffed, what supervision was in place, whether known risks had been identified, whether previous incidents were documented and corrected, and what management knew. Those findings help establish whether an incident was isolated or happened within a wider organizational deficiency.

Gugliotti is direct that governance does not eliminate risk. What it does, in his account, is create a documented record of what an organization identified, decided and did about that risk, and how it responded when something did not work. That record, he suggests, is what distinguishes a governed security program from a collection of disconnected security activities.

## FAQ

**Q: What is security governance?**
Security governance is the structure that sets who is accountable for security, which risks an organization is managing, what standards apply and how leadership knows whether the security program is working. In Gugliotti's "Governance Before Guarding™" approach, it sits above day-to-day activities such as guarding, cameras and access control, and connects them into one managed system.

**Q: What are the responsibilities of a hotel security manager?**
A hotel or resort security manager typically manages security staff, maintains policies, standard operating procedures and security post orders, runs training for new and existing officers, standardizes operations and reports on security risk to leadership. In Gugliotti's experience at the resort, those responsibilities also needed matching authority, agreed priorities and a clear reporting line before a manager could carry them out.

**Q: What is the role of the board in security?**
Boards do not run daily security operations. In Gugliotti's view, their role is to establish accountability, understand the organization's significant security risks, make sure appropriate resources are available and make informed decisions, treating security in the same way as other material risks.

**Q: How to perform a maturity assessment?**
A security maturity assessment reviews how developed each part of a security program is and where the gaps lie. It typically covers questions of the kind Gugliotti puts to leaders, including the top risks and who owns them, how they are measured, when the program was last formally assessed, how training is verified and how deficiencies are corrected. At MJG Consulting Group, the Security Governance Maturity Assessment™ is the first of three levels, followed by the Executive Security Governance Framework™ for leadership and implementation through HSOS™.

**About Michael J. Gugliotti**
Founder and Principal Consultant, MJG Consulting Group LLC

Michael J. Gugliotti served as Chief of Police of Waterbury, Connecticut from 2009 to 2013, capping 25 years in law enforcement, followed by about 15 years in private-sector security leadership. He founded MJG Consulting Group LLC and created HSOS, the Hospitality Security Operating System.
