Security Risk Assessment
What you are protecting and from whom.
12 min
Starting from risk
Security spending applied without an assessment produces measures that address the wrong threats while leaving obvious weaknesses. A structured assessment asks four questions: what are we protecting, who would want to harm it, how would they do so, and what would the consequence be?
What is being protected
- People — employees, visitors, contractors and the public. Always the first priority, and the one that changes the calculation entirely.
- Information — commercial, personal and regulated data, in physical and electronic form.
- Assets — equipment, stock, cash, vehicles, tools and materials.
- Operations — the ability to continue functioning, which may be damaged by disruption without anything being taken.
- Reputation — frequently the largest consequence of a security incident.
Threats to consider
- Opportunistic theft — the most common, favouring unattended items, unsecured doors and unchallenged strangers.
- Targeted theft — of specific high-value items, information or equipment, involving reconnaissance.
- Insider activity — by employees, contractors or former staff with knowledge and legitimate access. Frequently the most damaging and the least planned for.
- Unauthorised access — for theft, disruption, protest, or to reach IT systems.
- Violence and aggression — toward staff, particularly in public-facing roles.
- Vandalism and arson — arson is a facilities issue as much as a security one, and waste storage against a building is the classic vulnerability.
- Protest and activism, where the organisation or sector attracts it.
- Terrorism, where the location, sector or profile creates exposure.
Assessing vulnerability
Walk the site as an intruder would, at different times of day and night:
- How would you get in — perimeter, doors, windows, service entrances, roof access, adjoining premises, loading bays?
- Which doors are propped, which locks are defeated, which access control readers are bypassed?
- Would anyone challenge you, and would they know how to?
- What is visible and reachable — equipment, information on desks and screens, keys, passes?
- Where is the lighting poor and where are the blind spots?
- What happens out of hours, at shift change and during works when doors are open for deliveries?
This exercise consistently finds more than any desk-based review, and it should be repeated periodically because conditions drift.
Proportionality
Security measures cost money, impede legitimate users, and create resentment when disproportionate. Measures that make the working day difficult get circumvented, and the circumvention becomes the real arrangement — a propped fire door defeating an expensive access control system is the standard example. Match the measure to the risk, explain why it exists, and design it so the legitimate route is the easy one.