Security Management

Security Risk Assessment Methodologies for Corporate Facilities

Apply recognised security risk assessment methodologies, from structured site surveys to scoring matrices, to produce findings that corporate facility decisions can actually be based on.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Two security consultants can walk the same corporate facility and produce very different risk findings, not because one is more experienced but because they are applying different, often unstated, methodologies, which makes the resulting recommendations hard to compare or defend to a board. This course sets out a small number of recognised security risk assessment methodologies, aligned to the process described in ISO 31000 and the techniques catalogued in ISO 31010, and teaches participants when to apply a qualitative scoring approach, a quantitative model, or a structured site survey checklist. Work covers scoping an assessment, gathering evidence through document review, interviews and physical inspection, scoring likelihood and consequence consistently across assessors, and writing findings as a prioritised set of recommendations rather than an unranked list of observations. Participants complete a full assessment cycle against a corporate facility scenario, from terms of reference through to a report ready for a facilities or risk committee, and leave with a methodology they can defend when a finding is challenged.

Expected Learning Outcomes

01

Select an appropriate risk assessment methodology for a facility's size, use and threat profile.

02

Scope a security risk assessment with clear terms of reference and assessment boundaries.

03

Gather assessment evidence through document review, interviews and structured site inspection.

04

Score likelihood and consequence consistently using a defined rating scale.

05

Apply a threat-vulnerability-consequence model to identify a facility's principal exposures.

06

Prioritise findings into recommendations a facilities or risk committee can act on.

07

Defend an assessment's methodology and findings when a rating or recommendation is challenged.

Who Should Attend

01

Corporate security managers who commission or conduct facility risk assessments.

02

Security consultants and surveyors assessing client sites and premises.

03

Facilities managers who need to interpret and act on security assessment findings.

04

Risk management professionals extending enterprise risk methods to physical security.

05

Insurance and audit professionals who review security risk documentation.

06

Security officers moving into an assessment or risk analyst role.

Course Modules

Select any module to see its sessions and points.

01

Choosing and Scoping a Risk Assessment Methodology

2 sessions · 8 points

Session 1Comparing Recognised Methodologies

  • Compare qualitative, semi-quantitative and quantitative security risk assessment approaches.
  • Relate a chosen methodology to the risk management process described in ISO 31000.
  • Select assessment techniques from a recognised catalogue such as ISO 31010 for a given facility.
  • Match methodology complexity to the facility's risk profile, avoiding over-engineering a low-risk site.

Session 2Scoping the Assessment and Terms of Reference

  • Draft terms of reference that define assessment boundaries, assets and assumptions.
  • Agree assessment timelines and access arrangements with facility and security stakeholders.
  • Identify the assets, functions and information that fall inside and outside the assessment scope.
  • Clarify how findings will be reported, scored and escalated before work begins.
02

Gathering and Structuring Assessment Evidence

2 sessions · 8 points

Session 1Document Review and Stakeholder Interviews

  • Review incident history, policies and prior assessments before visiting a facility.
  • Structure interviews with facility staff to surface risks not visible in documentation.
  • Cross-check verbal accounts of controls against physical evidence during a site visit.
  • Record evidence in a consistent format that supports later scoring and reporting.

Session 2Conducting a Structured Site Survey

  • Walk a facility using a structured checklist covering perimeter, access and internal controls.
  • Assess lighting, sightlines and natural surveillance as part of a physical inspection.
  • Test selected controls directly, such as attempting unauthorised access at a controlled point.
  • Photograph and annotate findings so evidence can be reviewed without a further site visit.
03

Scoring, Modelling and Analysing Risk

2 sessions · 8 points

Session 1Likelihood, Consequence and Scoring Consistency

  • Define likelihood and consequence scales with descriptors that reduce assessor subjectivity.
  • Score identified risks using a matrix and justify each score against recorded evidence.
  • Calibrate scoring across multiple assessors to keep ratings consistent across a facility portfolio.
  • Distinguish inherent risk from residual risk after existing controls are taken into account.

Session 2Applying a Threat-Vulnerability-Consequence Model

  • Identify credible threat sources relevant to the facility's location, sector and profile.
  • Assess vulnerability by testing existing controls against each identified threat source.
  • Estimate consequence in terms of safety, operational, financial and reputational impact.
  • Combine threat, vulnerability and consequence ratings into a single prioritised risk view.
04

Reporting Findings and Supporting Decisions

2 sessions · 8 points

Session 1Writing Findings and Recommendations

  • Structure a report so findings, evidence and recommendations are clearly separated.
  • Write recommendations as specific actions with an owner and indicative timeframe.
  • Rank recommendations by risk reduction achieved relative to implementation cost and effort.
  • Avoid vague or generic recommendations that a facility team cannot act on directly.

Session 2Presenting to Decision-Makers and Tracking Action

  • Present assessment findings to a facilities or risk committee in business, not technical, language.
  • Respond to challenge on methodology, scoring or recommendation from senior stakeholders.
  • Track recommendation implementation and re-assess residual risk once actions are complete.
  • Schedule a reassessment cycle appropriate to the facility's risk level and rate of change.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course