Consultancy / Assessment

Security risk assessment and threat vulnerability analysis

Before specifying a single camera, establish what you are protecting, from whom, and where the current controls fail. The assessment is the document every later design decision is justified against.

In short

Security Risk AssessmentThreat, vulnerability and risk assessment for critical facilities: asset criticality, adversary paths, control gaps and a prioritised mitigation roadmap.

Overview

Service overview

Every defensible security design starts with an evidence base. Our risk and threat assessment establishes what a facility must actually protect against — from opportunistic intrusion and theft to insider misuse, forced vehicle entry, sabotage and terrorism — and translates those threats into engineering requirements rather than opinion.

We combine site survey, asset criticality mapping, adversary path analysis and stakeholder interviews to produce a rated risk register. Each risk is scored on likelihood and consequence, then treated with layered controls across deterrence, detection, delay and response, so investment lands where exposure is highest.

The output is written for both boards and engineers: an executive summary that supports budget approval, and a technical annex that the subsequent master plan, CCTV, access control and PIDS designs can be procured against.

Capabilities

What this service covers

Asset criticality

Ranking of people, assets and processes by consequence of loss.

Threat profiling

Credible adversary types, capability and likely attack paths.

Vulnerability survey

Site walkdown or remote survey identifying exploitable gaps.

Mitigation roadmap

Prioritised, costed controls mapped to residual risk reduction.

Key capabilities

  • Threat, vulnerability and criticality assessment (TVRA) aligned to recognised international practice
  • Asset and adversary path analysis, including standoff and vehicle-borne threat review
  • Crime prevention through environmental design (CPTED) review of layout, lighting and sightlines
  • Operational and manpower review — guarding posture, patrol routes, response timelines
  • Regulatory, insurer and client-specific compliance gap analysis
  • Risk-treatment roadmap phased by budget cycle and criticality
Method

A structured, defensible method

We follow a recognised TVRA sequence: asset identification, threat characterisation, vulnerability analysis, risk rating and treatment. Findings are traceable, so each recommended control links back to a specific risk.

Deliverables

  • Asset criticality register
  • Threat and adversary path analysis
  • Vulnerability findings with photographic or drawing references
  • Risk matrix with pre- and post-treatment ratings
  • Prioritised mitigation roadmap with indicative budget bands
  • Rated risk register with likelihood, consequence and residual-risk scoring
  • Executive risk summary for board and budget approval
  • Technical annex defining performance requirements for downstream design packages
Where it applies

Typical environments

Oil & gas
Ports and terminals
Critical infrastructure
Data centres
Industrial facilities
Commercial high-rise
Government facilities
Transport hubs
FAQ

Frequently asked questions

Can an assessment be done remotely?

Yes. Drawings, existing surveys, video walkthroughs and stakeholder interviews support a full remote assessment, with an optional site visit for high-criticality assets.

How long does an SRA take?

A single facility typically runs two to four weeks depending on size, drawing availability and stakeholder access.

Is the output vendor-neutral?

Always. The assessment recommends capabilities and performance requirements, never a specific brand.

Scope this service for your facility

Send drawings, site details or an existing specification and we will respond with a scoped proposal.

Talk to our engineers