How to conduct a security risk assessment
A step-by-step guide to a security risk assessment — identify assets, evaluate current measures, identify threats, prioritise risks and monitor controls.
By Knighthood Team
Published 5 January 2023

A security risk assessment identifies the risks and vulnerabilities in your security infrastructure so you can build a plan to protect against them. This guide walks through the steps.

Identify critical assets
Identify the critical assets of your technology and physical infrastructure. Consider the value of each asset and the potential impact of its loss or damage — property, equipment, data and personnel.
Evaluate current security measures
Review your current security measures to find the gaps that need addressing. Evaluate physical security measures, access controls and data protection measures.
Identify threats and vulnerabilities
Identify all potential threats and vulnerabilities that could affect your people and assets. Consider a broad range of hazards — cyber threats, natural disasters and human error.
Determine and prioritise risks
For each identified threat, determine the likelihood and potential impact on your business. Prioritise the risks and develop mitigation plans for each.
Implement controls and monitor risks
Implement controls to mitigate the identified risks and monitor them over time. Ensure a business continuity plan is in place so operations can continue when a risk materialises. Review security policies and procedures regularly, run security audits, and provide security training to employees.
What this does not cover
This guide covers the assessment process. It does not cover the legal authority to deploy guards (a PSARA licence, granted state by state) or the supervision and reporting model that makes a vendor accountable — those are separate decisions covered in the vendor-selection and due-diligence resources.
Send the requirement
If this post points at a decision you are close to making, send us the scope — sites, roles and shifts — and we will confirm the licence, supervision and commercial position for your situation.
Discuss your requirement