
Frank Elsner has spent more than 30 years working in security, public safety, crisis management, and executive leadership. He is the Founder of Stonehaven Risk Group Ltd., an advisory firm that gives companies access to senior security leadership on a project, retainer, fractional, or urgent-response basis.
Through Stonehaven, Elsner works with manufacturers, multi-site businesses, distribution and logistics operations, private companies, family enterprises, and leadership teams dealing with security gaps or elevated risk. His work includes fractional Chief Security Officer engagements, workplace violence prevention, independent security reviews, crisis exercises, executive advisory, and supply chain security.
Q: Why did you build Stonehaven around the fractional Chief Security Officer model?
Frank Elsner: A lot of companies reach a point where security has become an executive issue, yet they still do not need a full-time Chief Security Officer on payroll. They may be expanding to new sites, managing more vendors, formalizing reporting to ownership, or realizing security decisions are scattered across several departments. A fractional role gives them one senior person who can oversee the entire program, set priorities, advise the CEO or ownership group, review budgets, manage vendors, and establish accountability. It also gives the company continuity. Someone is responsible for keeping the security program moving instead of waiting until a serious incident forces the issue.
Q: What do you look for during a security risk review?
Frank Elsner: My work starts by walking through and looking at how the site actually functions. I want to see how employees enter, how visitors and contractors are handled, which areas have restricted access, whether camera coverage matches the real exposure, and where daily routines have created weak points. I also review policies and speak with the people responsible for the facility because a written procedure can differ greatly from what happens at 6:00 in the morning at a loading dock or late at night when staffing is reduced. The final recommendations are prioritized so leadership can see which issues require immediate attention and which can be addressed through planned improvements.
Q: How do you make a crisis exercise useful for an executive team?
Frank Elsner: I put the leadership team into a realistic situation where the information is incomplete, and the pressure builds as the exercise develops. They may have to decide whether to shut down operations, who communicates with employees, when to involve legal counsel, who speaks externally, or how to keep essential functions running while the incident is still unfolding. The value comes from watching where decisions slow down, or responsibilities become unclear. Afterward, I document those gaps and turn them into specific changes to the crisis plan, communication process, or decision structure. That gives the next exercise a clear purpose and gives the organization something concrete to improve.
Q: What does serious workplace violence prevention look like inside a company?
Frank Elsner: It starts with a reporting process that employees and managers can actually use. If someone raises a concern about threatening behaviour, harassment, intimidation, or an escalating conflict, the organization needs to know where that information goes, who reviews it, and what happens next. Stonehaven’s work in this area can include policy review, escalation pathways, threat intake processes, management guidance, training, and post-incident support. I pay particular attention to handoffs between departments because that is where information often gets lost. A concern may begin with a supervisor, move to human resources, and then require security or executive involvement. Those transitions need to be clear before an incident occurs.
Q: How does your C-TPAT experience shape the way you advise companies on supply chain security?
Frank Elsner: I designed and led a supply chain security program that met U.S. Customs and Border Protection audit requirements under C-TPAT, so I have worked through the level of detail that formal compliance demands. You have to examine how goods move, who can access them, how third parties are controlled, what records are maintained, and whether the documented procedures match what happens in practice. When I review a program, I am looking for controls that can be demonstrated during an audit and sustained in day-to-day operations.
***





