Zohar Global Security
Insights · The method

What is a security risk assessment?
It begins before the product.

Most security decisions are made backwards — the product is chosen first and the reasoning is assembled afterward. An assessment reverses that order.

A security risk assessment is a structured examination that establishes the credible threat to a specific person, family or organization in a specific environment, and determines what protection is actually required — before anyone recommends a product, a headcount or a system. It produces a written program and an order of work, not a shopping list.

The distinction matters because the alternative is so common. Someone decides they need a thing — a vehicle, a guard, a camera system, a monitoring contract — and the justification is written afterward to fit the purchase. The assessment is the discipline that puts the question before the answer.

Match the protection to the credible threat — not to the principal's wealth, title, or perception of what protection should look like.
01

What does a security risk assessment actually examine?

It examines the threat, the environment, and the gap between them. In practice that means answering a fixed set of questions in order, and refusing to skip ahead to the recommendation.

I will use armored vehicles as the worked example, because the reasoning is unusually visible there — but the method is the same whether the subject is a vehicle, a residence, a travel pattern, or an entire family program.

Those six questions are the assessment. Everything else is detail underneath them.

02

Why is more protection not better protection?

Because every layer of protection carries a cost, and the cost is rarely only financial.

On a vehicle, as protection increases, weight increases substantially. That weight affects acceleration, braking, handling, suspension, tyres, fuel consumption and maintenance. Mobility is itself a component of security, so buying the highest available level of armour can reduce the protection it was bought to provide.

The same trade appears everywhere in a program. Access controls that are too onerous get propped open. Travel protocols that are too rigid get worked around. A protective posture the family finds intolerable is a posture the family will quietly stop following, and a measure nobody follows is worse than no measure at all, because it is still on the paperwork.

Reliability is part of protection. A beautiful solution that continually fails is not a protective solution.
03

How do you evaluate the people who will do the work?

Once the requirement is established, the next exposure is the provider. This is the part of an assessment that most buyers skip, and it is where a good specification quietly becomes a bad outcome.

On the vehicle example, the questions I would want answered are these:

If a company has never done the particular thing being asked of it, I would think very carefully before allowing the principal to become their experiment. Either find a provider with demonstrated experience, or change the approach.

The cost question, answered properly

Purchase price is not cost

Cost is a legitimate part of an assessment, but only if it is the whole cost. On a protected vehicle that means specialised maintenance, tyres, brakes, suspension components, transportation, parts availability, downtime, servicing and eventual replacement. On a program it means the ongoing management the measure creates. A recommendation that ignores lifecycle cost is a recommendation that will be abandoned in year two.

04

What an assessment will not do

It will not hand you a single product that solves the problem. An armored vehicle does not replace intelligence, advance work, route planning, trained drivers, communications, medical preparedness or contingency planning. It is one layer inside a system, and treating any single layer as the answer creates a false sense of security — which is its own exposure.

This is the most common failure I am asked to look at. Not an absence of security spending, but spending concentrated in one visible layer while the connections between layers belong to nobody.

05

How do you know an assessment was done properly?

By what it produces. A genuine assessment ends with:

The objective is never the most heavily protected option available. The objective is the right one for the threat, the environment, and the life the person actually intends to live.

Related reading: security consulting versus guard services, and re-vetting long-tenured household staff — the area where the gap is usually widest and the fix is cheapest.