Security
risk management
A six-stage framework that turns an uneasy feeling into a documented, prioritised and proportionate set of decisions.
01 Framework
Six stages, run as a cycle
It is a loop, not a line. Stage 06 feeds directly back into Stage 01.
Stage 01
Assess
Understand the environment. Who is the client, what do they actually do, where do they do it, and what does a normal week look like before anyone introduces the word “risk”?
Stage 02
Identify
Identify relevant vulnerabilities and risks. Where does exposure genuinely arise — in routine, information, access, dependency, geography or relationships?
Stage 03
Prioritise
Determine relative importance using likelihood and impact, so that finite attention and budget are directed at what matters rather than at what is most easily imagined.
Stage 04
Mitigate
Develop proportionate controls. Prefer measures that remove exposure over measures that manage it, and accept that some risk will be tolerated deliberately and explicitly.
Stage 05
Monitor
Review changing conditions. Circumstances, exposure and the client’s own activity move; an assessment that is not monitored silently becomes inaccurate.
Stage 06
Improve
Update the security strategy. Feed findings, incidents and near misses back into the assessment so the framework reflects experience rather than assumption.
02 Prioritisation
The matrix is a communication tool. It makes disagreement about priority visible and therefore resolvable.
The risk matrix
Each identified risk is placed by likelihood and impact. The resulting rating sets the required response, the level at which it must be accepted, and how often it is reviewed.
| Likelihood against impact | Negligible | Minor | Moderate | Major | Severe |
|---|---|---|---|---|---|
| Almost certain | Low | Medium | High | Critical | Critical |
| Likely | Low | Medium | Medium | High | Critical |
| Possible | Very low | Low | Medium | High | High |
| Unlikely | Very low | Very low | Low | Medium | High |
| Rare | Very low | Very low | Very low | Low | Medium |
- Very low — monitor only
- Low — routine controls
- Medium — active mitigation
- High — priority action and senior acceptance
- Critical — immediate action; proceed only with explicit written acceptance
| Rating | Required response | Accepted by | Review interval |
|---|---|---|---|
| Critical | Immediate action. Activity is modified, deferred or declined unless exposure can be reduced. | Client principal, in writing | Continuous |
| High | Prioritised mitigation with a named owner and a defined completion date. | Client senior decision-maker | Monthly or on change |
| Medium | Active mitigation planned and scheduled within the agreed programme. | Assignment lead | Quarterly |
| Low | Managed through routine controls and existing procedure. | Assignment lead | Half-yearly |
| Very low | Recorded and monitored. No specific action required. | Recorded only | Annually |
03 Treatment
Four ways to treat a risk
Not every risk should be mitigated. Choosing deliberately between the four options is what distinguishes risk management from risk anxiety.
- Avoid Remove the exposure by changing the activity. Frequently the cheapest and most effective option, and the one most often overlooked because it requires changing a plan rather than adding provision.
- Reduce Apply proportionate controls that lower likelihood, impact, or both. The majority of security work sits here.
- Transfer Shift financial consequence through insurance or contract. Note that this transfers cost, not harm — it is never a substitute for mitigation.
- Accept Tolerate the risk deliberately, at the appropriate level of authority, with the decision recorded. Unrecorded acceptance is not acceptance; it is drift.
On honesty in assessment
Every assessment we produce separates what we know from what we assess and what we assume, and states the confidence attached to each. Assumptions are listed explicitly so that a client can challenge them — they are the most common source of error in security work, and the easiest to correct once visible.
We do not inflate risk to justify provision. If the honest assessment is that a client’s existing arrangements are adequate, that is what the report will say.
04 Next Step
Commission an assessment you can act on
An assessment should leave a client with a prioritised list and a clear first action — not a document that describes the obvious at length.