Quantitative and qualitative risk analysis

Residential Estate Security Handbook 2016 - Vol 1 Residential Estate (Industry), Security Services & Risk Management

In order to recognise the value and purpose of a security risk analysis it is necessary to place it within the context of the wider discipline of security risk management, which in turn can be broadly be defined as the management of security threats by analysing risks, assessing the effectiveness of existing risk controls, determining the consequences of such risks and developing appropriate countermeasures for those risks.

Aaron Schnehage.
Aaron Schnehage.

It is therefore clear that in order to succeed in managing security risks one needs to identify such risks by means of an appropriate risk analysis methodology. Failure to do so would almost certainly result in ill-conceived countermeasures for vaguely defined risks ultimately constituting the foundation of a condemned security programme.

Still, many security practitioners consider the use of a generic checklist as the core of risk analysis without giving much thought to the four basic elements of any respectable risk analysis methodology, which is the consideration of threat/risk, probability, vulnerability and consequence. Checklists invariably focus on vulnerabilities, but more often than not miss those vulnerabilities which are not contained within that checklist and in doing so, itself becomes a vulnerability. Use a checklist to facilitate the administration of the assessment, but it may not be prescriptive and inflexible to the task at hand.

Combating contemporary security risks relies greatly upon the development of a security programme underscored by the application of a risk analysis methodology that is focused upon the examination of empirical data from which informed decisions can be made, rather than mere assumptions drawn from inferior checklists. As the function of risk analysis has become a specialised skill utilising a variety of tools such as formulae, quantitative and qualitative analysis, the facility or security manager should ensure the risk analysis being conducted should consist of the following steps:

• Asset characterisation: Categorise the facility or organisation’s assets. Is it people, machinery, immovable property etc.

• Risk or threat identification: Analyse the risks and threats there are against the facilities assets. For example, is the facility appealing to petty criminals and economic criminal alike and what risks do these threat actors pose?

• Consequence analysis: Analyse how essential such assets are to the facilities operations and what the consequences may be should a harmful event occur and those assets are somehow compromised.

• Vulnerability analysis: Develop scenarios of all possible harmful events that may occur at the facility. For example, would armed men be able to overpower the security guard at the entrance. And then consider the consequence or consequences thereof.

• Probability assessment: Understand how probable a threat or risk is likely to occur by the use of historical data such as crime stats. Here a basic risk formula can be applied to estimate probability: Risk = Probability x Vulnerability x Consequence.

• Risk estimation: Demonstrate the risk in the form of calculations by using spreadsheets and developing templates. For example, apportion a value ranging from 1 to 5, with five being the most severe, of the criticality of a particular risk such as the theft of records of the accounting system of an organisation.

• Risk prioritisation: Limited budgets almost always dictate, therefore the most important risks must be mitigated first and the least, last.

• Risk management: Research, budget and provide recommendations for countermeasures to mitigate the risks.

By following these steps the analyst shall be applying two critical skills in conducting assessments; quantitative and qualitative analysis. And these in fact, represent the two main schools of risk analysis reporting. Quite simply put, quantitative analysis concerns the interpretation of numbers from data and estimates, such as in the case of allocating a value from 1 to 5 in estimating the criticality of a particular risk as discussed above.

Various matrices could be developed to express certain aspects in numbers. For example, by developing a Vulnerability Matrix using a spreadsheet, one could numerically estimate the vulnerability of a facility by considering the level of difficulty in accessing the facility, what physical security measures are currently in place, what electronic measures are used and so forth. The same rings true for developing a Consequence Matrix in response to the Consequence Analysis step listed above.

Qualitative analysis, on the other hand, represents the interpretation of interviews and descriptions of characteristics, features or values of the subject under consideration. It relies heavily on the skill of the analyst’s research, analysis and interpretation of data collected since conclusions and recommendations are drawn from this.

Considering the specialisation of risk analysis it is posited that the application of both methods will produce a much more thorough result. Similarly, the quality of the analysis will rely heavily of the analyst’s ability to be critical during the assessment and to avoid prejudices and pre-conceived ideas of what the analysis will entail.

What used to be a clipboard approach with a long checklist has evolved into what may seem to be an overwhelming and convoluted process. On the contrary, a methodical, well researched and critical analysis will mitigate and hopefully prevent a harmful event from taking place. The security management environment changes rapidly and is locked in a constant campaign to appropriately respond to the ingenuities of criminals who always seem to be one step ahead. Failing to develop a compelling response founded upon a scientifically based risk analysis, is surely an exercise in futility.

Moreover, a well-developed risk analysis is the cornerstone of any security plan from which countermeasures are advanced and standard operating procedures are formulated to support such countermeasures. Poor identification and treatment of risks will inevitably lead to the misallocation of budget on risk measures that are inappropriate and ineffectual.

The international security association, the American Society for Industrial Security, better known as ASIS, has developed several standards and guidelines for best practice in risk analysis and several books by ASIS members have been written on the subject. These resources provide a wealth of information on the subject and address the whole spectrum of risk analysis from Department of Homeland Security approved methodologies right down to small facilities and organisations. It is therefore possible and quite frankly incumbent on the responsible facility manager or security practitioner to become aware and avail them of the importance of risk analysis to any security programme.

References

1. Risk Analysis and the Security Survey: 4th Edition (James F. Broder; Eugene Tucker);

2. Risk Assessment (ASIS Commission on Standards and Guidelines);

3. General Security Risk Assessment Guideline (ASIS International Guidelines Commission).

For more information contact Aaron Schnehage, Definitive Risk Services, +27 (0)11 476 1895, www.definitive.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
The post-Q1 security checklist
Asset Management Security Services & Risk Management
By this time of year, employees have changed jobs or roles, suppliers may have changed, and devices have moved between offices, homes, and sites. This is the right time for businesses to run a practical post-Q1 security check.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Your company is already breached, you just do not know it yet
Information Security Security Services & Risk Management
Attackers are no longer relying on sophisticated exploits to break-in. Instead, they are systematically targeting weak credentials, misconfigured systems, and exposed devices stemming from preventable gaps such as identity weaknesses and poor visibility across digital environments.

Read more...
Excellerate Services sets a new standard
News & Events Security Services & Risk Management
Excellerate Services relies on specialist expertise and the sophistication of its operations deployment and management. Central to this is an investment in smarter, data-driven operations through the Velocity and Performance Centre platforms.

Read more...
957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...
The security debt hidden in residential estates
Security Services & Risk Management Integrated Solutions Residential Estate (Industry)
Many residential estates undermine their own security not through a lack of technology, but through hidden weaknesses in gate design, fragmented systems, recurring software dependence, weak operational ownership, and insufficient estate management input.

Read more...
Service robot technology for residential complexes
Suprema AI & Data Analytics Infrastructure Residential Estate (Industry)
Suprema has signed a three-party memorandum of understanding (MOU) with Hyundai Motor Group Robotics LAB and Hyundai Engineering & Construction (Hyundai E&C) to collaborate on advancing residential complexes through service robot technology.

Read more...
Africa’s opportunity to shape the future of human-centred AI
AI & Data Analytics Security Services & Risk Management
Across the Global South, countries are not yet locked into decades of legacy AI systems, energy-intensive infrastructure, or governance frameworks designed for a different technological era. That creates something rare in technology development: a cleaner slate.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.