Good security decisions rest on a clear, honest understanding of risk: what could happen, how likely it is, how much it would matter and what response is genuinely proportionate. That understanding is what we build first.
Every person and organisation lives with risk. The aim of risk management is not to eliminate it — that is neither possible nor desirable — but to understand it well enough to make sensible, defensible decisions about what to do. Some risks warrant real investment. Many are best handled through small changes of habit. Some are simply accepted, knowingly.
Our approach follows the logic set out in widely recognised risk-management guidance: establish the context and objectives, identify and analyse risks, evaluate them against what the client is prepared to accept, treat those that need treatment, and keep the whole picture under review. The vocabulary is standard for good reason. It lets clients, advisers, insurers and partners discuss risk in the same terms.
What the frameworks cannot supply is judgement. Deciding how likely something really is, how serious it would be for this particular client, and whether a proposed measure is worth its cost and intrusion requires experience applied honestly. That is the part of the work we take most seriously.
Above all, assessment must be proportionate. An assessment that exaggerates danger leads to heavy, conspicuous and expensive arrangements. One that understates it leaves people exposed. Both fail the client.
Fig. 01 — Observation before assessmentIllustrative photograph
Threat
Something with the potential to cause harm.
Vulnerability
A weakness that could allow harm to occur.
Likelihood
How probable it is that a risk will occur.
Impact
How serious the consequences would be.
Control
A measure that changes likelihood or impact.
Residual risk
The risk that remains after controls.
Table 01 — What risk management is, and what it is not
It is
It is not
A structured way of understanding what could affect a person’s or organisation’s objectives.
A prediction of exactly what will happen, or when.
Proportionate to realistic threats, vulnerabilities and consequences.
A justification for the maximum possible level of security.
Evidence-informed and candid about uncertainty and assumptions.
A list of every conceivable danger, weighted equally.
A living record, reviewed as circumstances change.
A document written once and filed away.
A basis for decisions that clients understand and own.
A substitute for the client’s own priorities and judgement.
PSF / 02 The process
A cycle, not a checklist.
Risk management does not end when a report is delivered. Each stage feeds the next, and the last feeds back into the first.
Fig. 02 — The continuous risk cycle
01
Identify
Key question — What could affect the objectives?
Identification starts with objectives, not threats. Before asking what could go wrong, it is necessary to understand what the person, family or organisation is trying to do — live privately, travel for business, host an event, run a site — and what they value most. A risk is then anything uncertain that could affect those objectives.
Information comes from conversations with the client and those around them, observation of places and routines, review of existing arrangements and past concerns, and reputable open sources about the wider environment. Each risk is described precisely, as a cause, an event and a consequence. “Unauthorised access to the residence through an unmonitored service entrance” is useful; “security” is not.
Typical outputs
Context statement
Described risks
Assumptions & gaps
02
Assess
Key question — How likely is it, and how serious would it be?
Each identified risk is examined for two things: how likely it is to occur within the relevant period, and how serious the consequences would be if it did. Both are judged against clear qualitative scales, so that different assessors reach comparable conclusions and clients can follow the reasoning.
Good assessment considers existing controls honestly — what is already in place and how well it actually works in practice — and records the evidence behind each rating. Where information is limited, the uncertainty is stated rather than hidden. An assessment that sounds confident but cannot explain itself is of little use to anyone.
Typical outputs
Ratings with reasoning
Control effectiveness
Stated uncertainty
03
Prioritise
Key question — What matters most, and what can wait?
Not every risk deserves the same attention, and time, money and goodwill are always finite. Prioritisation ranks risks by their assessed level, then tempers that ranking with judgement. Risks that could develop quickly, those with severe consequences even when unlikely, and those that affect people rather than property often warrant earlier attention.
This stage also compares each risk with what the client is prepared to accept — their risk appetite — so that effort concentrates where the gap between current and acceptable exposure is widest. The aim is a short, honest list of what matters most, not a long one in which everything appears urgent.
Typical outputs
Prioritised risk list
Risk appetite statement
Immediate actions
04
Mitigate
Key question — What response is proportionate?
For each priority risk the question becomes what response is proportionate. Recognised treatment options include avoiding the activity that creates the risk, reducing its likelihood or impact, sharing it — through insurance or contractual arrangements, for example — or accepting it knowingly where treatment would cost more than it saves.
Measures are chosen as a balanced set: changes to routines and procedures, physical and technical measures, training and awareness and, where genuinely justified and lawful, protective services. Each has an owner, a timescale and a plain statement of what it is meant to achieve. The least intrusive effective option is usually the right place to start.
Typical outputs
Treatment plan
Contingency arrangements
Residual risk statement
05
Monitor
Key question — What has changed since we last looked?
Risks and controls both change. Profiles rise and fall, routines shift, environments evolve, and measures that once worked well quietly erode through familiarity. Monitoring keeps the picture current by checking that agreed measures are in place and effective, and by noticing early signals that a risk is growing or fading.
Monitoring should be proportionate too: light, regular checks for most risks and closer attention for the few that are higher or more volatile. Defined triggers — a change of residence, a new travel pattern, a significant incident nearby — prompt an unscheduled review rather than waiting for the calendar.
Typical outputs
Review schedule
Change triggers
Control checks
06
Improve
Key question — What have we learned, and what should change?
The final stage turns experience into better arrangements. After incidents, near-misses, exercises and scheduled reviews, the questions are simple: what worked, what did not, and what should change? Honest answers are recorded without blame, because a culture that hides problems loses the chance to fix them.
Improvements flow back into the first stage. Objectives are re-confirmed, new risks identified and redundant measures retired — which matters as much as adding new ones. Over time, this is what keeps an arrangement proportionate, credible and suited to the client’s life or organisation as it is now, rather than as it was.
Typical outputs
Recorded lessons
Updated plan
Measures retired or refined
PSF / 03 Assessment matrix
Likelihood × impact, read with judgement.
A qualitative matrix gives everyone a shared language for discussing risk. It supports decisions. It does not make them.
Table 02 — Illustrative qualitative risk matrix
Likelihood ↓Impact →
Minor
Moderate
Significant
Major
Severe
Almost certain
Medium
High
High
Very high
Very high
Likely
Medium
Medium
High
High
Very high
Possible
Low
Medium
Medium
High
High
Unlikely
Low
Low
Medium
Medium
High
Rare
Low
Low
Low
Medium
Medium
Table 02 — Illustrative qualitative risk matrixRows show likelihood and columns show impact; each cell gives the resulting rating band. Colour is supported by a text label in every cell.
Scroll the matrix sideways →
Rating bands
Low
Accept and manage through routine arrangements; review periodically.
Medium
Manage through defined measures with a named owner, and monitor.
High
Requires senior attention and treatment before or alongside the activity.
Very high
Do not proceed as planned until the risk is reduced or the activity redesigned.
Reading the matrix responsibly
Scales are ordinal: ratings are categories, not numbers to multiply or average.
A rating records a judgement. The reasoning matters as much as the colour.
Unlikely but severe risks may need contingency plans even when rated medium.
Speed of onset and potential to escalate are weighed alongside the rating.
Scales are calibrated to each client, because “severe” differs from one life to another.
Likelihood scale
Almost certainExpected in most circumstances, or already occurring in comparable settings.
LikelyWill probably occur at some point; there are clear indications or precedents.
PossiblePlausible in the context, though not expected.
UnlikelyCould occur, but there is little to suggest that it will.
RareConceivable only in exceptional circumstances.
Impact scale
SevereGrave harm to people, or consequences that fundamentally threaten the objectives.
MajorSerious harm, prolonged disruption or substantial privacy or reputational damage.
SignificantHarm or disruption that needs deliberate recovery, with some wider effect.
ModerateNoticeable disruption or minor harm, recoverable with modest effort.
MinorBrief inconvenience, readily absorbed, with no lasting effect.
PSF / 04 Risk contexts
One discipline. Eight contexts.
The principles stay constant. What changes is what matters, who is affected and what a useful output looks like.
Table 03 — Typical considerations and outputs by context (general, not exhaustive)
Context
Typical considerations
Typical outputs
Often informs
C.01Individuals
Personal profile and visibility; predictability of daily routines; online footprint; home and commute; personal health needs.
Personal risk review; practical awareness guidance; a short list of proportionate recommendations.
Personal safety training; advisory support
C.02Families
The differing needs of each family member; schools and activities; household staff and visitors; privacy on social media; multiple residences.
Family security review; simple household protocols; age-appropriate awareness guidance.
Residential arrangements; family awareness training
C.03Executives
Public and media profile; travel frequency; events and speaking engagements; business sensitivities; the interface between office, home and travel.
Executive risk assessment; protective planning options at different levels; travel protocols.
Executive protection; travel planning
C.04Businesses
People, premises and assets; sensitive information; visitors and contractors; reputational exposure; continuity of critical activities.
Security risk assessment; policy and procedure review; continuity considerations.
Venue layout and access; audience profile and density; guest and speaker profiles; timings and transitions; coordination with organisers and authorities.
Event risk assessment; inputs to the security plan; contingency and communication arrangements.
Event security planning; licensed local delivery
C.06Travel
Destination environment and official advice; legal and licensing position; access to medical care; itinerary and transport; communications.
Travel risk assessment; pre-travel briefing; check-in and escalation arrangements.
International support; executive travel
C.07Properties
Perimeter and access points; lighting and sightlines; alarms and monitoring; control of keys and access credentials; activity nearby.
Site security survey; prioritised physical and procedural recommendations.
Specialist security advisory
C.08Organisations
Governance and accountability; duty of care to staff and visitors; risk appetite; incident-reporting culture; the gap between policy and practice.
Review of the risk framework; defined roles and escalation routes; a sustainable review cycle.
Frameworks give structure. These principles decide whether the result is genuinely useful to the client.
J.01
Proportionality
The response to a risk should match its realistic level. Too little leaves people exposed; too much creates cost, intrusion and visibility that can become problems in their own right. Proportionality asks what a reasonable, well-informed person would consider sensible in the circumstances.
It also has a legal and ethical dimension. Measures that affect other people — their privacy, their movement, their dignity — must be justified by the risk they address, and must remain within the law.
J.02
Residual risk
No arrangement removes risk entirely. Residual risk is what remains once agreed measures are in place, and it should be stated plainly rather than implied away. A plan that claims to leave no risk at all has simply not been examined closely enough.
Clients decide whether the remaining level is acceptable. Our role is to make it visible, explain it honestly and describe what further treatment would involve — including its cost and its effect on everyday life — if they wish to go further.
J.03
Avoiding over-specification
Beyond a certain point, additional measures add little protection while adding cost, inconvenience and conspicuousness. Heavy, visible arrangements can attract attention, disrupt normal life and wear away goodwill with neighbours, colleagues and the public.
We would rather recommend a lighter arrangement that people will actually sustain than an impressive one they abandon after a month. Recommending less, when less is enough, is part of professional responsibility.
J.04
Documentation and review
Assessments are recorded clearly: the context, the risks, the reasoning behind each rating, the measures chosen and the residual risk accepted. That record allows decisions to be understood, questioned and revisited — by the client, by us and by anyone else with a legitimate need to know.
Every assessment carries a review point, both scheduled and triggered by significant change. An assessment that is never reviewed gradually becomes a description of a situation that no longer exists.
PSF / 06 From assessment to action
Findings that shape what happens next.
An assessment is only valuable if it changes decisions. Its findings set the scope, level and priorities of any service that follows.
Input
Assessment findings
Prioritised risks, recommended measures and the residual risk the client has chosen to accept.
An assessment describes vulnerabilities — in a person’s routine, a family’s home or an organisation’s procedures. In the wrong hands, that information could create the very risk it was meant to reduce. Findings are therefore treated as confidential client information from the first conversation onwards.
Shared only with people the client authorises, strictly on a need-to-know basis.
Handled and stored securely, with sensitive detail kept out of general circulation.
Summaries separated from detail, so wider audiences receive only what they need.
Retained only while there is a legitimate purpose, then securely disposed of.
Never used for publicity, case studies or marketing of any kind.
The right level of protection begins with an honest assessment.
Tell us, in confidence, what you need to protect and what concerns you. We will suggest a proportionate starting point — which may well be lighter than you expect.