October is Domestic Violence Awareness Month, and most of the conversation around it happens in HR newsletters and employee assistance program reminders. Security teams usually get pulled in later, often when an employee tells their manager that a former partner has been calling the front desk or was waiting in the parking garage last week.
That conversation is the point where a personal situation becomes a workplace security issue. The office is one of the few places an abuser can reliably find someone who has moved, changed their phone number, or blocked them on every platform. Shift schedules are predictable, the building address is public, and the employee's job title is probably listed on LinkedIn.
This post walks through what happens after an employee discloses a threat: how GSOC and HR teams can work the case together, which online signals are worth watching, and what to have in place before the first call.
The most detailed national study on domestic violence remains a NIOSH analysis of Census of Fatal Occupational Injuries data from 2003 to 2008. Intimate partners killed 142 women at work during that period, which was 22 percent of all workplace homicides of women. More than half of those killings happened in parking lots and public buildings.
Later Bureau of Labor Statistics data points in the same direction. In 2016, relatives or domestic partners were the most common assailant in work-related homicides of women at 40 percent, compared with 2 percent for men. That BLS category also counts relatives who aren't partners, so it is higher than an intimate-partner-only figure.
The first person to hear about a threat to an employee is usually a direct manager, HR, or a coworker who sits nearby; it's hardly ever someone on the security team. That's why the most useful thing a security leader can do ahead of time is make sure managers and HR know who to call, and that they can make that call the same day.
The employee should stay in the loop on every decision. They know the person threatening them better than anyone in the building does, and they're the one living with the consequences of each step. Acting without them, like calling the police or confronting the other person, can make them less likely to share updates when the situation changes.
Once security is involved, the first conversation should cover a short set of facts:
Some protective measures can start right away. Reception and lobby staff can get a photo and instructions on what to do if that person arrives. The employee can be offered an escort to their car, a different parking spot, or a desk away from ground-floor windows. HR can remove their name and photo from public staff pages, and screen calls to their extension.
These cases go sideways when two departments each assume the other one has it covered. A simple division of ownership, agreed on before any case comes in, prevents most of that.
HR owns the employee relationship. That includes check-ins, schedule changes, leave, and any accommodations. Leave and confidentiality rules differ by state and province, so HR and legal should confirm what applies in each location where the company has staff.
The GSOC owns the threat picture. Operators watch for the named individual in access control and visitor management logs, monitor relevant online activity, and stay in contact with local police if a protective order is in place. They also keep the timeline so that every call to reception, sighting in the parking garage, and concerning post is recorded with a date and time. That timeline matters if the employee later needs to go back to court.
Both teams should work from one shared record. A tool with a Case Manager can keep notes, evidence, and tasks in a single file with access limited to the people who need it. Confidentiality matters a lot here, since the employee is trusting the company with something very personal, and that file should be visible to a small, named group.
It also helps to agree on a review schedule. A weekly check-in between the HR lead and the GSOC lead is usually enough, with extra reviews scheduled ahead of known flashpoints like a court hearing, a custody exchange, or the date a protective order expires.
Many of the behavioral indicators we covered in our post on using OSINT to understand indicators of potential workplace violence apply here too. The difference in a domestic violence case is that the team already knows who the person of concern is, so threat monitoring can be narrow and specific.
The signals that matter most tend to fall into a few groups. Start with any mention of the workplace itself, such as the company name, the building, the employee's team, or coworkers by name. A post complaining that the company is 'hiding' the employee tells the GSOC that the other person sees the employer as part of the conflict.
Location awareness is another group. It includes check-ins or photos near the office, comments that reference the employee's shift times, or questions to mutual friends about where the employee parks or when they leave.
Tone deserves close attention around legal milestones, such as the week a protective order is served, the days after a court hearing, or a change to a custody arrangement. Language about having nothing left to lose, references to weapons, or a sudden shift from angry posting to silence should all go to an analyst for review. Our post on measuring escalation velocity covers how to tell a fast-moving change from normal background noise.
New accounts are the last group. If the employee has blocked someone, a fresh profile contacting them or their coworkers a few days later should be treated as a likely workaround until the analyst can rule it out. Investigations & Identity Resolution can help analysts connect a new account back to a known individual, and Threat Monitoring & Alerting can flag new mentions of the employee or the workplace as they appear.
The employee's own exposure is worth a look too. Tagged photos from friends, public fitness app routes, and property records can all reveal where someone lives or works.
Monitoring in these cases should stay tied to the specific threat, the named individual, and a documented purpose that legal has reviewed. A narrow scope also makes the program much easier to explain if anyone later asks why the company was watching a private individual's accounts.
A short written protocol settles what needs to be done in advance. It should name who a manager calls first, who opens the case file, what information gets collected at intake, and who has access to it.
Training matters most for the people who are likely to see the threat first. Reception staff, lobby security officers, and front-line managers should know how to flag a concern and what to do if a named individual shows up.
It also helps to set up outside relationships ahead of time. A contact at the local police department, an introduction to a domestic violence advocacy organization near each major office, and a clear handoff to the employee assistance program give the employee support that goes well beyond what the security team can offer on its own. That broader support is a core part of an employer's duty of care to its people.
Domestic Violence Awareness Month is a good reason to put the protocol in front of HR, legal, and the GSOC leads together. Walking through one realistic scenario, such as an employee disclosing on a Friday afternoon that their former partner has been parked outside the building, will show quickly where the handoffs are unclear and who still needs training.