A security risk assessment methodology should do more than produce a coloured heat map and a list of actions.
It should help the person responsible make better decisions before a threat, failure or crisis forces the issue. If it cannot show what may happen, why it matters and who needs to act, it is paperwork rather than risk reduction.
That distinction matters. Many organisations can produce policies, complete training records and show an assessment was carried out. Far fewer can explain whether their people would recognise an emerging problem, make a sound decision under pressure and carry out the response expected of them.
Modern threats expose old security thinking, particularly where assessment is treated as a compliance event rather than an operational discipline.
Start with the decision, not the template
Templates have their place, but they can quietly dictate the assessment.
The assessor works through pre-set headings, rates a series of risks and reaches a conclusion that looks complete because every box is filled in. The harder question is whether the assessment has addressed the decisions the organisation genuinely faces.
Begin by defining the asset, activity or environment being protected. This may be people in a public-facing venue, a construction project, a corporate office, a critical service or a major event. Then establish what an unacceptable outcome would look like. Loss of life and serious harm rightly sit at the top, but disruption, reputational damage, loss of sensitive information, commercial loss and prolonged operational failure may also be material.
Context changes everything. A reception desk in a low-footfall office has different exposure, staffing and response options from a hospitality venue at peak capacity. A security risk assessment cannot simply be copied between sites because the building layout is similar. The operating pattern, local environment, public access, workforce experience, management oversight and available support all alter the risk.
A useful assessment also identifies the decisions it needs to inform. Is the issue a need for better access control, revised staffing, clearer escalation arrangements, technical advice, improved training or a change to the operating model?
Without this focus, teams can spend time describing risk without reducing it.
A security risk assessment methodology needs credible threats
Threat assessment is often weakened by two opposite mistakes. The first is listing every imaginable threat until the document becomes unfocused. The second is dismissing a threat because it has not happened locally before. Neither approach helps a decision maker.
Credibility comes from relevance. Consider the organisation’s profile, location, visibility, operating hours, visitor numbers, sector, history of incidents, known tensions and dependence on particular systems or suppliers. Consider foreseeable hostile acts alongside accidental events, insider concerns, disorder, suspicious behaviour and failures that could create security consequences.
The point is not to predict a specific incident. It is to understand plausible routes to harm and to identify where reasonable measures can interrupt them. Counter terrorism planning, for example, should be grounded in the reality of the site and its people. Generic awareness material may improve recognition, but it does not automatically prove that staff know what to report, who will assess it or how leaders will make decisions when information is incomplete.
This is where professional judgement matters. Threat information should inform the assessment, but a site does not need a dramatic intelligence picture to justify sensible protective measures. Equally, an unlikely threat does not justify unlimited spending.
Proportionate security is based on consequence, exposure and practicality, not anxiety.
Look beyond physical vulnerabilities
Security surveys tend to find physical weaknesses because they are visible.
A poorly controlled door, inadequate lighting, obscured sightlines or a faulty camera can be identified quickly. These issues matter, but the most serious vulnerabilities are often found in the gap between people, procedures and management.
Ask what happens when the usual person is absent, the site is busy, a contractor needs access or a member of staff is challenged by an angry visitor. Consider whether front-line staff can identify abnormal behaviour, whether they have the confidence to report concerns and whether someone is accountable for acting on that report. A procedure that depends on perfect judgement from an inexperienced person at the busiest point of the day is not a control. It is an assumption.
Technical systems should be assessed in the same way. The presence of CCTV, access control or an alarm system is not evidence of effective security. Does the system support a defined operational purpose? Are alerts seen by someone able to respond? Is footage usable? Are faults reported and resolved? Does the workforce understand the limits of the technology?
Equipment can support good decisions, but it cannot compensate for unclear responsibility.
A practical assessment examines controls in three layers: deterrence and prevention, detection and reporting, then response and recovery. Weakness in any one layer may be acceptable if the others are genuinely capable.
A lightly staffed site may not prevent every unauthorised approach, for instance, but it may still manage risk well if it has clear zoning, effective detection, confident staff and reliable escalation.
The assessment must show that logic rather than award an optimistic score.
Score risk carefully, then test the result
Risk scoring provides a common language, but it can create false precision.
A likelihood score of three rather than four is rarely an objective fact. If a numerical model is used, the reasoning behind it matters more than the number itself.
Assess consequence in realistic terms. Do not rely on a single generic label such as ‘major’. Explain what the consequence means for that environment: harm to people, closure of a venue, interrupted operations, loss of confidence or a failure to meet a critical obligation.
Then consider likelihood by looking at opportunity, exposure, threat relevance and the effectiveness of current controls.
The uncomfortable part is testing those controls. This should not mean setting traps for staff or conducting intrusive exercises without proper authority. It means asking sensible questions and observing ordinary operations. Are visitors consistently received as the procedure states? Can shift staff describe their escalation route? Do managers know who takes command during an incident? Has the response plan been practised under realistic pressure, or merely circulated by email?
There is a material difference between a control that exists and one that performs. Organisations often discover this only after an incident, when the access procedure was bypassed to save time or a report was not escalated because nobody wanted to cause disruption.
A good assessor notices workarounds. They are often a more accurate measure of risk than the formal procedure.
Turn findings into accountable action
A long list of recommendations is easy to write and difficult to deliver.
Each action should have a clear purpose, a named owner, a realistic timescale and a way of confirming that it has improved the position. ‘Improve security awareness’ is not an action. Define who needs what knowledge or behaviour, how it will be developed and how competence will be checked.
Prioritisation should be based on risk reduction, not just cost or convenience. Some improvements are straightforward: repairing a failed lock, clarifying an emergency contact route or removing ambiguity from visitor arrangements. Others need investment, planning or senior approval.
The assessment should distinguish between immediate controls, short-term improvements and longer-term strategic changes so that important work does not disappear beneath urgent but minor tasks.
Capability development deserves particular attention. If the recommended control relies on staff recognising concern, challenging appropriately, communicating accurately or leading a response, training must move beyond attendance. People need opportunities to make decisions, receive feedback and understand the consequence of hesitation or poor judgement.
This is especially relevant for organisations preparing for Martyn’s Law, where written arrangements alone will not create readiness.
Mildot Group’s approach is built around this operational reality: security improves when people understand their role and can carry it out under pressure.
An assessment should therefore identify not only control gaps, but capability gaps.
Review when conditions change
An annual review date is useful, but it is not enough.
Reassess when the environment changes: a new site opens, footfall rises, construction alters access, a new system is introduced, staffing changes, a significant incident occurs or a new threat becomes relevant. Small operational changes can undermine controls that were sensible six months earlier.
Keep the review focused on what has changed and what that means. The aim is not to recreate the whole report every time. It is to keep the risk picture honest and ensure that actions have not stalled. Senior leaders should see the decisions required, while operational teams should understand the practical changes expected of them.
The most useful question at the end of an assessment is simple: if this risk developed tomorrow, would our people know what to do, have the authority to do it and be supported when they act?
Where the answer is uncertain, the work is not finished.
.
Useful Links:
.
