In brief

A security project that starts with equipment is a project that will be redone. It starts with an assessment: what threatens this site, how likely is it, what would it cost, and what is already in place. This article sets out the four steps of a security risk assessment, and what to do with the result.

Building, industrial site and retail security is a central concern for organisations of every size. Malicious acts, break-ins and intrusions are becoming both more frequent and more varied — organised theft, cyberattacks targeting security systems themselves, vandalism — and that calls for a methodical approach rather than a reactive one.

Any protection strategy therefore has to start in the same place: a precise assessment of the buildings to be protected.

Why carry out a security risk assessment?

An organisation that underestimates security exposes itself to losses that can affect its business well beyond the incident itself. Beyond material damage, security incidents cause lost productivity, logistical disruption, and potentially legal liability where employees or customers have been put at risk.

The purpose of an assessment is not to justify buying equipment. It is to make sure that whatever is bought answers a risk that has actually been identified, and that the risks left uncovered are known and accepted rather than simply overlooked.

The four steps of a security risk assessment

  1. Identify threats and vulnerabilities
  2. Assess impact and rank the risks
  3. Audit the security measures already in place
  4. Build an action plan and monitor it

1. Identify threats and vulnerabilities

An effective assessment begins by mapping the threats that could affect the site. This means examining both external and internal risks, taking into account the specifics of the building and its surroundings.

  • External threats — intrusion, break-ins, vandalism, and risks associated with social unrest or activity around the site.
  • Internal threats — fraud, theft by employees or contractors, and human error that compromises the security of the installation.

Beyond deliberate acts, environmental and technical factors also belong in the map. A careful assessment anticipates the consequences of a fire, a flood or a technical failure — all events capable of halting operations regardless of anyone’s intent.

2. Assess impact and rank the risks

Once threats are identified, the next step is to measure how critical each one is. That assessment rests on two criteria: likelihood of occurrence and impact on the business.

Look at what has already happened

Past incidents are a valuable source of information. A history of thefts, attempted intrusions and technical failures reveals recurring weaknesses and points preventive measures in the right direction. It is also the least contestable data you have, because it comes from your own site.

Build a criticality matrix

A criticality matrix makes the ranking explicit. A risk judged both highly likely and heavy in consequence calls for an immediate response. A rare risk with limited impact can be monitored without triggering structural changes.

Likelihood \ ImpactLimitedSignificantSevere
HighActAct nowAct now
ModerateMonitorActAct now
LowAccept and recordMonitorAct

Worth remembering: the value of the matrix is not the ranking itself, it is that it makes disagreement visible. Two managers who place the same risk in two different boxes have a conversation to hold — and it is far better to hold it before the incident than after.

3. Audit what is already in place

Before considering improvements, take stock of the existing arrangements. That review covers three areas:

  • Access points and weak spots — doors, fences, windows, secure storage areas.
  • Reliability of monitoring systems — cameras, alarms, motion detectors, biometric readers. Not whether they exist, but whether they work.
  • Effectiveness of internal procedures — visitor management, closing protocols, response plans when an alarm is raised.

A detailed audit brings gaps to light and makes it possible to build a targeted action plan rather than a generic shopping list.

4. Build an action plan and monitor it

Protecting a site means putting in place a structured plan matched to the vulnerabilities identified. It rests on three pillars.

Strengthening physical measures

Access control comes first, to limit intrusion and protect sensitive areas. Electronic badges, security airlocks and automated gates filter entries and exits. Coupled with centralised supervision, these systems allow fine-grained management of permissions and reduce unauthorised access.

Using the technology properly

Monitoring should rely on tools capable of analysing the environment in real time. Artificial intelligence built into video surveillance can automatically flag unusual behaviour, analyse movement flows and raise instant alerts on anomalies. That responsiveness is what allows a threat to be addressed before it materialises.

Involving your people

No system, however advanced, is fully effective without staff awareness. Training people on good practice and security protocols strengthens collective vigilance and reduces human error. An employee who understands the risks and the procedure to follow becomes part of the security of the site — through checking access, respecting closing instructions or managing visitors.

The solutions that address these risks

Access control and flow management

Securing entry points is central to preventing unauthorised access. Current solutions manage entries and exits through badges, codes and biometric readers (fingerprint or facial recognition). Supervision software provides real-time tracking of access, with the ability to restrict certain areas by user profile — securing the site while keeping movement fluid.

Video surveillance and behaviour detection

Modern cameras carry artificial intelligence capable of analysing streams in real time. Algorithms can flag unusual movement, suspicious behaviour or attempted intrusion.

One of the most effective developments is automated behavioural analysis. By studying circulation flows and gestures, these systems flag anomalies — a prolonged presence in a normally empty area, threatening body language, an unusual gathering — and alert security teams within seconds, cutting reaction time considerably.

Licence plate recognition is another useful capability for company car parks, logistics sites and retail premises with parking. The software identifies authorised vehicles and logs entries and exits. It should be treated as a filtering and traceability layer rather than as the sole means of opening a barrier, and the people concerned must be informed that the system is in place.

These systems integrate into a centralised management platform. From a single interface, security managers supervise several sites at once, review recorded sequences and trigger protective measures remotely. Recordings are stored securely and accessible only to authorised people, and intelligent search tools make it possible to find a specific individual or event in moments rather than hours.

Technical and environmental risks

Beyond human threats, site security also depends on preventing incidents caused by damage and technical failure. A fire, a gas leak or a power failure can have serious consequences, damaging infrastructure and endangering occupants.

Smoke and gas detectors, combined with temperature and humidity sensors, identify the early stages of a fire or a technical fault. Connected to a central system, they raise an automatic alert, activate safety protocols and support rapid evacuation. Some arrangements go further, cutting power immediately or isolating a specific zone to limit the spread of damage.

Frequently asked questions

What is a security risk assessment?

It is a structured review that maps the threats affecting a site, ranks them by likelihood and impact, audits the measures already in place, and produces an action plan matched to the vulnerabilities identified. Its purpose is not to justify buying equipment, but to ensure that whatever is bought answers a risk that has actually been identified.

What are the four steps?

Identify threats and vulnerabilities, both external and internal; assess impact and rank the risks using likelihood and business impact; audit the security measures already in place; then build an action plan and monitor it over time.

What is a criticality matrix?

It is a grid that ranks risks by crossing their likelihood with their impact on the business. A risk that is both highly likely and severe calls for immediate action; a rare risk with limited impact can simply be monitored. Its real value is that it makes disagreement between managers visible before an incident rather than after.

What should the audit of existing measures cover?

Three areas: access points and weak spots (doors, fences, windows, secure storage); the reliability of monitoring systems (cameras, alarms, detectors, readers) — not whether they exist but whether they work; and the effectiveness of internal procedures (visitor management, closing protocols, response plans).

Is technology enough to secure a site?

No. No system, however advanced, is fully effective without staff awareness. Training people on good practice and security protocols reduces human error and turns employees into part of the site’s protection. Technology and human involvement are complementary, not alternatives.

Assess the risks on your site

We run the four steps with you, on your own site and your own incident history.

Contact us