Feeling vulnerable?

April 2012 Security Services & Risk Management

I recently attended the ASIS Middle East Security Conference & Exhibition in Dubai. A presentation by Jean Perois forced those present to ask questions surrounding security vulnerability and preparedness. Are we merely reactive to security threats? Do our investigations and processes lead to solutions and successful outcomes?

Many of us consider that having enlisted the services of a security provider, CCTV cameras, controlled access to buildings and demarcated areas, that our valuable assets are safe. Then, when a security incident occurs, we have a hard time understanding how it could happen and scramble to fix the situation.

Oprah Winfrey once said, “Luck is a matter of preparation meeting opportunity” and instead of being reactive, we need to anticipate issues and prepare for them.

In many countries it is becoming a mandatory exercise to incorporate a comprehensive risk assessment process. Such assessments will enable a corporation to evaluate what threats are credible and whether these could possibly be successful.

So, what does a risk assessment entail?

* Asset characterisation: Your first step is to identify your assets, evaluate their criticality and the impact that would be experienced should they be compromised.

* Threat assessment: Threats need to be identified and ranked, as well as an assessment of your assets according to their attractiveness.

* Vulnerability analysis: The effectiveness of your current security measures need to be evaluated, scenarios and consequences defined and vulnerabilities identified.

* Risk assessment: Based on your vulnerability, threat and attractiveness variables a risk ranking needs to be established.

* Countermeasure analysis: Through this analysis organisational and procedural changes and processes need to be put in place and one needs to ensure that these work.

In order for a risk assessment to be advantageous, it needs to be put into practice. Do not make the mistake of going to all the trouble of identifying threats and creating solutions without applying the information.

A key component to ensuring your risk assessment is viable, is vulnerability testing. This requires you to actually test your security process and response. An example of what a vulnerability test is, if you are a manager at a shopping centre and you want to test your security with regards to car theft, plan a scenario, where a car is stolen, and measure the reaction.

Once you have identified your organisational and procedural changes, communicate and educate your staff on a consistent basis to ensure their understanding. Very often, security measures fail because your workforce is unaware of procedures. I say it again, on a consistent basis. This information needs to be available during the induction process and then through regular training sessions.

Also, risk assessments cannot be a once-off occurrence. You need to conduct assessments on a regular basis. Depending on the value and criticality of your assets, I suggest quarterly or at least twice a year, particularly to assess the effectiveness of your security measures.

I cannot stress enough the importance of preparedness, not only from a security point of view, but from cost as well. It is far more cost effective to do a risk assessment than to lose most or all of your assets.

Jenny Reid
Jenny Reid

For more information contact iFacts, +27 (0)82 600 8225,  [email protected]



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Risk management and compliance enforcement
Security Services & Risk Management
Having a risk management and compliance programme (RMCP) is not just a procedural formality; it is a legal requirement under Section 42 of the Financial Intelligence Centre Act (FICA).

Read more...
The dangers of poor-quality solar cables
Security Services & Risk Management Smart Home Automation
Reports indicate that one in six fires attended by South African firefighters is linked to substandard solar installations, often due to faulty wiring or incompatible components.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it is a gamble.

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
Growing risks for employers
Security Services & Risk Management
With South Africa’s unemployment rate exceeding 32% and expected to rise beyond 33% this year, desperation is fuelling deception in the job market. Trust is no longer a given, it’s a gamble.

Read more...
Managing mining physical security risks
Zulu Consulting Security Services & Risk Management Mining (Industry) Facilities & Building Management
[Sponsored] Risk-IO, a web app from Zulu Consulting, is designed to assist risk managers in automating and streamlining enterprise risk management processes, ensuring no steps are skipped and everything is securely documented.

Read more...
SAFPS issues SAPS impersonation scam warning
News & Events Security Services & Risk Management
The Southern African Fraud Prevention Service (SAFPS) is warning the public against a scam in which scammers pose as members of the South African Police Service (SAPS) and trick and intimidate individuals into handing over personal and financial information.

Read more...
Rewriting the rules of reputation
Technews Publishing Editor's Choice Security Services & Risk Management
Public Relations is more crucial than ever in the generative AI and LLMs age. AI-driven search engines no longer just scan social media or reviews, they prioritise authoritative, editorial content.

Read more...