Skip to content Skip to sidebar Skip to footer

Security Risk Assessments: A Practical Guide

Outdoor CCTV security camera against a blue sky
CCTV camera mounted on an outdoor wall

Most organisations don’t fail at security because they lack guards, cameras or firewalls. They fail because they spent on the wrong things. A security risk assessment is how you stop guessing.

Without one, budgets follow habit, fear or the last incident. A branch gets another camera while a poorly vetted supplier holds the keys to the server room. A risk assessment replaces that with evidence: what you must protect, what could realistically go wrong, and which gaps deserve money first.

This guide walks through what a security risk assessment is, how to run one, and the mistakes that quietly make most of them useless.

What a security risk assessment actually is

A security risk assessment is a structured way to identify what you need to protect, what could harm it, and how much that harm would matter. Every assessment, whatever the framework, rests on five ideas:

  • Asset: anything of value: people, buildings, cash, data, systems, reputation.
  • Threat: something that could cause harm, such as armed robbery, insider fraud, ransomware, fire or civil unrest.
  • Vulnerability: a weakness a threat can exploit, like an unmonitored back entrance or an unpatched server.
  • Likelihood: how probable it is that the threat succeeds in your context.
  • Impact: the damage if it does: financial loss, injury, downtime, regulatory penalties, lost trust.

Risk is the combination of those factors. A severe threat against a well-protected asset can be a lower priority than a modest threat against an exposed one. Established references such as ISO 31000, NIST SP 800-30 and the ASIS risk assessment standard all follow this logic, so you can adopt one without reinventing the method.

The process, step by step

A good assessment is repeatable. Follow the same seven steps each time and results become comparable from site to site and year to year.

  1. Define scope and context. Decide what is in: one branch, a country operation, a new building, a business process. Agree who owns the decisions and what the organisation can tolerate.
  2. Identify and value assets. List people, property, information and critical processes. Rank them by how badly their loss would hurt, not by purchase price.
  3. Identify threats. Use incident history, local crime and police data, intelligence reports, staff and community input, and sector alerts. Include accidental and natural threats, not only malicious ones.
  4. Find vulnerabilities. Walk the site, test the controls, review procedures, interview staff and check how guards, alarms, access control and response actually perform on a bad day.
  5. Rate the risk. Score likelihood and impact for each threat-asset pair using a consistent scale, then rank the results.
  6. Treat the risk. For each priority risk, choose to reduce it with a control, transfer it through insurance or contract, avoid the activity, or knowingly accept it. Record who decided and why.
  7. Report, monitor and review. Present findings in plain language with costed recommendations, assign owners and deadlines, and schedule the next review.

Live sites versus new builds

Security guard standing in a building foyer by the entrance
Security guard at a building entrance

An operating branch and a site still on the drawing board need different assessments, and it pays to keep a separate template for each.

A live site is assessed against what actually happens there. You observe real opening and closing routines, cash movements, guard handovers and visitor flows, and you test the controls in place. The questions are practical: do cameras cover the cash point and the entrance, does the access control log match who is on site, does the alarm reach someone who will respond, and is the staffing on each post matched to its job? Findings are usually retrofits that must fit around trading hours and existing systems.

A new site or refurbishment is assessed against the design. You review layouts, entrances, sight lines, vehicle approaches, plant and server rooms, and the planned security systems before anything is built. Fixing a blind spot on a drawing costs almost nothing. Fixing it after fit-out can mean breaking walls.

In both cases, the biggest gains come from consistency. Use the same template, the same scoring scale and the same finding format at every location, so a new security officer can carry out an assessment and reach conclusions that line up with their colleagues’ work. When one report covers several sites, represent every site in every section rather than letting the best-documented one dominate.

Assess physical and cyber risk together

Modern concrete building with a large window and a security camera mounted on the wall
Building entrance with a mounted security camera

Attackers do not respect the line between your physical and digital security, so your assessment shouldn’t either. Many serious incidents cross it:

  • A tailgater walks into a server room and plugs in a device. That is a physical failure with a cyber outcome.
  • A compromised access control system or CCTV network lets an intruder unlock doors or blind cameras. That is a cyber failure with a physical outcome.
  • An insider with legitimate badge access copies sensitive records. Both disciplines own part of that risk.
  • A cut cable or power failure takes a site offline. Facilities, security and IT each see a different symptom of the same event.

In practice, this means shared asset registers, joint site walks between security and IT, and one risk rating scale that both teams use. When security and IT score risks differently, leadership gets two competing priority lists and neither gets funded properly.

Scoring and prioritising: a worked example

The simplest workable method scores likelihood and impact from 1 (low) to 5 (high) and multiplies them. Scores of 15 and above need action now, 8 to 14 need a plan, and anything lower is monitored.

Risk score = Likelihood × Impact

Here is how that looks for a hypothetical retail branch. The figures are illustrative, not real data:

RiskLikelihood (1-5)Impact (1-5)ScoreResponse
Armed robbery at the counter3515Act now: review cash handling, response times and guard posture
Tailgating into the server room4416Act now: add a door controller and anti-tailgating procedure
Staff fraud over weak segregation of duties3412Plan: tighten approvals and audit logging
Power outage disabling alarms4312Plan: backup power and alarm health monitoring
Graffiti on the exterior wall414Monitor

The value is in the conversation the table forces. The server room scores highest because a common, easily exploited weakness meets a severe consequence, even though robbery feels more alarming. Keep your scales written down, with clear definitions for what a “4” means in money, injury or downtime, so two assessors reach the same score.

Write findings people can act on

A score ranks a risk. A finding gets it fixed. The format that works best for site reports is a five-column register in which every row is short enough to read in one breath:

FindingRisk / impactRecommendationDevices / qtyResponsible party
Rear service door has no door contact and is out of CCTV viewUndetected after-hours entry to the cash and server areaFit a door contact linked to the alarm panel and add one fixed camera covering the door1 contact, 1 cameraSecurity
Customer entrance leads straight to the teller line with no controlled pauseArmed intruder reaches staff and cash within secondsConvert the entrance to a mantrap with interlocked doors1 mantrapSecurity
Fire detection shares a panel with the legacy intruder alarmA fault on one system can silence the otherInstall an independent, dedicated fire panel1 panelSecurity with the fire contractor
Guard post log is not reconciled with the access control logCannot show who was on site during an incidentReconcile both logs daily and record exceptionsNoneSecurity

Three habits keep the register honest:

  • Name one responsible party per row. If the assessor does not state one, default to the function that owns the risk, which for security findings is Security, not Facilities or IT by assumption. Confirm it with the person named before the report circulates.
  • Keep cells to a sentence or a short bullet. Long explanations belong in an appendix.
  • Flag blank fields. Missing quantities, owners or distribution lists should surface in the draft, not be discovered at the review meeting.

Make findings defensible: standards, staffing and costs

Auditors, finance teams and executives challenge numbers, not opinions. Three practices make a recommendation survive that challenge.

Cite the standard it answers to. Map findings to the frameworks your organisation is already measured against. For physical security these commonly include PCI DSS Requirement 9 for physical access to cardholder data environments, SWIFT customer security programme physical security expectations, ISO 27001 physical and environmental controls, local health and safety (HSE) obligations, and NFPA 72 for fire detection and alarm systems. A recommendation tied to a named requirement is far easier to approve than one tied to “best practice”.

Justify staffing with ratios. “We need two more guards” invites an argument. “This site has three access points, a ten-minute cash cycle and a queue area that needs one steward per set number of customers” invites a calculation. Express headcount as a ratio, such as posts per access point, stewards per customer volume or guards per cash movement, and show the working so anyone can audit it.

Label costs as indicative. An assessor can estimate what a mantrap, a camera or an alarm panel costs, but only procurement can confirm it. State estimates as indicative pending procurement validation, and keep device quantities in the findings so finance can price them.

One more design point: keep critical systems separate. Where a new system is recommended, say whether it should be independent and dedicated, such as a stand-alone fire panel, or whether sharing a legacy system is acceptable. Shared panels save money until one fault takes down two protections.

Common mistakes to avoid

  • Treating it as a one-off compliance exercise. An assessment filed in a drawer protects nothing. If no one acts on the findings, the exercise was wasted.
  • Using a generic checklist instead of local threats. A Nairobi branch, a border-town agency and a data centre face different risks. Use local incident data and context.
  • Assessing controls instead of risks. Counting cameras tells you what you have, not whether it reduces a threat.
  • Ignoring people and process. Most real failures come from untrained staff, skipped procedures or weak vetting, not missing hardware.
  • Scoring without definitions. If “high” means different things to different assessors, the ranking is opinion.
  • Skipping the people who do the work. Guards, tellers, cleaners and facilities staff know where the process really breaks. Interview them.
  • Reporting without costs and owners. Recommendations with no price, owner or deadline rarely get approved.
  • Never testing the controls. Drill the response, test the alarm and try the door. Assumed controls fail more often than tested ones.

Keep it alive

Security camera on a pole with a building in the background
Security camera on a pole outside a building

Risk changes faster than reports age. Review the assessment on a fixed schedule, at least annually for stable sites, and whenever something material shifts:

  • A serious incident or near miss, at your site or a comparable one.
  • A new site, a relocation, a renovation or a major system change.
  • A change in the local threat picture, such as elections, unrest, new crime patterns or regulatory shifts.
  • A new supplier, outsourced guard force or technology platform.

Give every risk a named owner, track mitigation actions to closure, and report a short top-risks summary to senior leadership on a regular cycle. Leaders do not need every score. They need to know the five risks that matter most, what is being done, and what decision they are being asked to make.

Keep a single tracker of recommendations across all sites, with status, owner and target date for each. A simple check such as “which entrances have been converted to mantraps, and which are still pending?” tells leadership more about security progress than any score. Treat each assessment as iterative: expect the first draft to be refined as owners confirm responsibilities, procurement validates costs and distribution lists are completed.

n

Start with one site

You don’t need a perfect framework to begin. Pick one site or process, list its most valuable assets, name the three threats that worry you most, and score them honestly with the people who work there. That single exercise will surface gaps no budget meeting ever has.

Security spending is a set of trade-offs. A risk assessment is the tool that lets you make those trade-offs openly, defend them to leadership, and show later that the money went where the danger was.