A security risk assessment is a structured examination that establishes the credible threat to a specific person, family or organization in a specific environment, and determines what protection is actually required — before anyone recommends a product, a headcount or a system. It produces a written program and an order of work, not a shopping list.
The distinction matters because the alternative is so common. Someone decides they need a thing — a vehicle, a guard, a camera system, a monitoring contract — and the justification is written afterward to fit the purchase. The assessment is the discipline that puts the question before the answer.
Match the protection to the credible threat — not to the principal's wealth, title, or perception of what protection should look like.What does a security risk assessment actually examine?
It examines the threat, the environment, and the gap between them. In practice that means answering a fixed set of questions in order, and refusing to skip ahead to the recommendation.
I will use armored vehicles as the worked example, because the reasoning is unusually visible there — but the method is the same whether the subject is a vehicle, a residence, a travel pattern, or an entire family program.
- Where are we operating? Operating in North America may present a completely different threat environment from parts of the Middle East, Africa, Europe or Latin America. Weapon availability, explosive risk, political stability, criminal activity, infrastructure and emergency-response capability all differ, and all change the answer.
- What is the credible threat? Not the imaginable threat. The credible one, specific to this person and this environment.
- What level of protection is actually required? Established from the two answers above, not from a budget or a preference.
- What can deliver that protection and remain reliable? A solution that fails in service is not protection.
- Who has the proven experience to build and support it?
- Does the cost make sense against the assessed risk?
Those six questions are the assessment. Everything else is detail underneath them.
Why is more protection not better protection?
Because every layer of protection carries a cost, and the cost is rarely only financial.
On a vehicle, as protection increases, weight increases substantially. That weight affects acceleration, braking, handling, suspension, tyres, fuel consumption and maintenance. Mobility is itself a component of security, so buying the highest available level of armour can reduce the protection it was bought to provide.
The same trade appears everywhere in a program. Access controls that are too onerous get propped open. Travel protocols that are too rigid get worked around. A protective posture the family finds intolerable is a posture the family will quietly stop following, and a measure nobody follows is worse than no measure at all, because it is still on the paperwork.
Reliability is part of protection. A beautiful solution that continually fails is not a protective solution.How do you evaluate the people who will do the work?
Once the requirement is established, the next exposure is the provider. This is the part of an assessment that most buyers skip, and it is where a good specification quietly becomes a bad outcome.
On the vehicle example, the questions I would want answered are these:
- Has this company done this exact thing before, and how many times?
- What recognized standards are being applied?
- Has the finished work been independently tested or certified against those standards?
- How are the second-order effects handled — in this case, the added weight through suspension, braking, wheels and tyres?
- Can the original reliability be maintained after the work is done?
- What warranty, service, parts and technical support exist afterward?
If a company has never done the particular thing being asked of it, I would think very carefully before allowing the principal to become their experiment. Either find a provider with demonstrated experience, or change the approach.
Purchase price is not cost
Cost is a legitimate part of an assessment, but only if it is the whole cost. On a protected vehicle that means specialised maintenance, tyres, brakes, suspension components, transportation, parts availability, downtime, servicing and eventual replacement. On a program it means the ongoing management the measure creates. A recommendation that ignores lifecycle cost is a recommendation that will be abandoned in year two.
What an assessment will not do
It will not hand you a single product that solves the problem. An armored vehicle does not replace intelligence, advance work, route planning, trained drivers, communications, medical preparedness or contingency planning. It is one layer inside a system, and treating any single layer as the answer creates a false sense of security — which is its own exposure.
This is the most common failure I am asked to look at. Not an absence of security spending, but spending concentrated in one visible layer while the connections between layers belong to nobody.
How do you know an assessment was done properly?
By what it produces. A genuine assessment ends with:
- A written program, not a filed report that nobody opens again.
- A prioritized sequence — what to fix first, what can wait, and why in that order. If everything is urgent, nothing was assessed.
- Named accountability for each item. A finding with no owner is an observation, not a recommendation.
- Reasoning you can follow without the author present. You should be able to hand it to a general counsel or a board and have it stand on its own.
- Things it tells you not to buy. An assessment that recommends only additions, and never removals or reductions, was written by someone with something to sell.
Related reading: security consulting versus guard services, and re-vetting long-tenured household staff — the area where the gap is usually widest and the fix is cheapest.