Leaders in risk & security: Assessing threat, risk and vulnerability

Issue 4 2020 Editor's Choice

After serving a 27-year ‘life sentence’ in the military, Andy Lawler has spent over ten years in the private security industry as a risk specialist. He left the defence force in 2007 and spent two years as chief operating officer of a company in Roodepoort.

He was then approached to join Sentinel Risk Management in 2009, which he did, and he eventually purchased the company outright in 2013.

Lawler says his time in the military gave him a good grounding for running Sentinel as he was able to attend numerous courses that not only gave him a broad range of skills, but also direction in terms of what he wanted to do after his service. Among the various positions he held, in 1999 he was appointed as security manager and adjutant at 1 Military Hospital. In this position he was required to oversee a number of security projects, which piqued his interest in the physical security industry.

Due to his legal and analytical talents, he was head-hunted by the Chief of Defence Legal Services and was transferred to the headquarters of the Minister of Defence. Here he was sent on a number of courses including military law, law of armed conflict, law of war, international humanitarian law and the conventions of the Red Cross and Red Crescent.

More pertinent to his future life as a civilian, Lawler was also sent on training in strategic planning and management, security risk management, information security, corporate governance, business continuity, enterprise risk management and cyber forensics.


Civilian life

Lawler was initially hired at Sentinel to provide training on risk management and this evolved into him combining security and risk management, which is where his specialist knowledge stood out. He began encouraging people to think about what steps they could or should take to secure their homes, estates and businesses by starting at the beginning – in other words, first assessing the risks they faced before looking for solutions.

His cybersecurity training also introduced him to the concept of penetration testing, and he evolved this into his risk management process for the physical security industry. He adapted the generic Threat, Risk and Vulnerability Assessment (TRVA), into a unique Security Threat Risk and Vulnerability Assessment (S-TRVA).

Over the course of the past decade, Lawler has been invited to speak on a variety of risk-related matters and explain and implement his S-TRVA process throughout Africa, while also providing assessments for large and small clients in the region. And it seems the S-TRVA risk assessment process is expanding as a company in Japan has also adopted it.

Lessons in security

Lawler has learned many lessons from his time in the security industry, but he says the most important is the ability to communicate with people. Effective communication allows for faster problem resolution, but it also prevents many problems from appearing in the first place.

One of the most common failures of communication with customers in the industry is the inability to avoid the ‘grudge purchase’ mentality. This occurs when people feel they have to pay for some form of security because the police force is not doing its job in protecting them. This grudge attitude leads to people cutting corners and opting for cheap security solutions or services that don’t actually keep them safe. “If you pay a second-rate price you get a second-rate service,” states Lawler.

He has explained to many customers and potential customers that the police are not there to keep people safe. The police force is there to respond to crime, investigate it and ensure evidence is collected that can lead to a successful prosecution of the criminal. People must realise they are responsible for their own safety and security and therefore need to secure their own environment. We must all remember the unpleasant reality that crime in South Africa is a case of when, not if.

“You can’t absolve yourself of responsibility by blaming the police for your insecurity,” he says. “Putting your head in the sand and hoping it will go away only serves to expose the lower part of your anatomy as a target to be kicked.”

He says it’s therefore critical for everyone to understand that security begins in their own heads, by creating a security mindset. Every person and organisation must focus on what they do and how to secure themselves. Alarms, cameras and armed response services don’t make you secure. Once you understand your own security, or lack thereof, and where you are vulnerable, then you can make use of the technology and services available as add-ons to mitigate the risks. If you don’t know what and where the risks are, simply spending money is not going to ensure the safety of your person or the people in your environment.


Andy Lawler.

Starting out in security

The police force and the military are no longer feeder organisations for a career in the private security industry as they once were. Lawler says that the training and education a police or military officer receives today no longer makes them an authority on security matters. He suggests that young people wanting a career in the security industry take matters into their own hands to ensure they are trained properly and gain the experience required to reach their goals. He offers some suggestions as to a career path.

A first step could be to join an armed response company and receive training to become an officer. However, the individual should not make this their final career, but once they have two or three years’ experience they need to look for the next step. People in response cars don’t understand the ‘big picture’ of running a company, for example, so they would need to look at moving in a management direction. This could mean moving into sales where you learn to sell armed response services and help clients or potential clients understand where their risks and vulnerabilities lie.

Another path could perhaps be a job at an installation company where the individual learns the ins and outs of security technology and how to install it. Again, moving into a sales position after a while will also allow one to learn how to identify risks and so forth.

Finally, one can also look at studying security at legitimate institutions that offer recognised certificates, diplomas or degrees. However, it may be wise to take this route only after gaining some experience ‘on the ground’ as the ability to translate theory into practical advice and solutions is critical. Some of the larger security companies also have training academies that offer good training and a clear career path, so these should not be ignored as worthwhile ways to establish your career in security.

“There are different options for young people entering the security industry today,” Lawler explains. “My advice is to look at where your interest lies and then enter the industry and move up the ranks in a logical way that builds on the skills you have already gained. Then look at how you can use the skills you have gained to make a real contribution to the security field in South Africa.”


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SMARTpod talks about HomeSec Expo 2026
SMART Security Solutions Technews Publishing News & Events Residential Estate (Industry) Videos
SMARTpod, the podcast from SMART Security Solutions, finds out more about the upcoming HomeSec Expo happening at Gallagher Estate on 4 & 5 March 2026.

Read more...
The challenges of cybersecurity in access control
Technews Publishing SMART Security Solutions Access Control & Identity Management Information Security
SMART Security Solutions summarises the key points dealing with modern cyber risks facing access control systems, from Mercury Security’s white paper “Meeting the Challenges of Cybersecurity in Access Control: A Future-Ready Approach.”

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...
Securing your access hardware and software
SMART Security Solutions Technews Publishing RBH Access Technologies Access Control & Identity Management Information Security
Securing access control technology is critical for physical and digital security. Every interaction between readers, controllers, and host systems creates a potential attack point for those with nefarious intent.

Read more...
From the editor's desk: It’s all about data
Technews Publishing News & Events
      Welcome to the SMART Access and Identity Handbook 2026. We have slightly changed the handbook this year, specifically the selection guides, but there is still a lot of industry information inside, and ...

Read more...
Access trends for 2026
Technews Publishing SMART Security Solutions RR Electronic Security Solutions Enkulu Technologies IDEMIA neaMetrics Editor's Choice Access Control & Identity Management Infrastructure
The access control and identity management industry has been the cornerstone of organisations of all sizes for decades. SMART Security Solutions asked local integrators and distributors about the primary trends in the access and identity market for 2026.

Read more...
Access data for business efficiency
Continuum Identity Editor's Choice Access Control & Identity Management AI & Data Analytics Facilities & Building Management
In all organisations, access systems are paramount to securing people, data, places, goods, and resources. Today, hybrid systems deliver significant added value to users at a much lower cost.

Read more...
Beyond the fence
Technews Publishing Fang Fences & Guards SMART Security Solutions Perimeter Security, Alarms & Intruder Detection Access Control & Identity Management
In a threat landscape characterised by sophisticated syndicates, harsh environmental conditions, and unstable power grids, a static barrier is no longer a defence; it is merely a brief delay.

Read more...
Zero Trust access control
Technews Publishing SMART Security Solutions CASA Software NEC XON Editor's Choice Access Control & Identity Management Information Security
Zero Trust Architecture enforces the rule of ‘never trust, always verify’. It changes an organisation’s security posture by assuming that threats exist both inside and outside the perimeter, and it applies to information and physical security.

Read more...
Holding all the cards
neaMetrics Suprema SMART Security Solutions Technews Publishing Access Control & Identity Management
After so many years of offering alternatives to card technology for access control, one could be forgiven for assuming we are all using biometrics or mobile credentials for all our physical and digital access requirements.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.