Special Frontier Force Independent Security & Protection

+91 97699 99960 im@digantsharma.com

Confidential Enquiry

See the risk before it becomes the incident

Risk management is the discipline that converts unease into something a client can act on: named, assessed, ranked, owned and reviewed.

Framework
Six stages, applied consistently
Method
Qualitative and evidenced; reasoning recorded
Not used
Invented percentages, scores or probability claims
Ownership
Every risk has a named owner and a review date

Why a framework rather than a judgement

Experienced people form good intuitions about risk, and those intuitions are worth listening to. They are also inconsistent, unevenly distributed across a team, and impossible to hand over when the person holding them leaves.

A framework does not replace judgement; it makes judgement comparable. When risks are assessed the same way each time, they can be ranked against one another, resources can go to the ones that matter, and a decision not to act on something becomes a recorded choice rather than an oversight.

On numbers

We do not publish statistics about threat frequency, incident rates or the effectiveness of security measures. Figures of that kind circulate widely in this industry and are rarely traceable to a source. Where an assessment uses a rating, it is a qualitative judgement with its reasoning recorded — not a measurement, and it is presented as such.

03 The Framework Six stages

The six-stage risk framework

01

Identify

What could go wrong

Establish the full set of risks relevant to the client — not only the ones that prompted the enquiry. Identification draws on observation, interviews with people at different levels, examination of processes and routines, and structured consideration of categories that are commonly overlooked.

The most frequent failure at this stage is narrowness: assessing the risk the client named while leaving the adjacent one unexamined. The second most frequent is the opposite — an unusable list of everything conceivable.

02

Assess

How likely, how serious

Evaluate each identified risk for likelihood and for consequence, using consistent qualitative bands and recording the reasoning behind each judgement. Assessment considers existing controls: the question is the residual risk that remains after what the client already does.

Recording the reasoning matters more than the rating itself. A rating without reasoning cannot be challenged, updated or handed over.

03

Prioritise

What comes first

Rank risks so that attention and expenditure go where they have most effect. Prioritisation is where a client's own tolerances become explicit: what they are prepared to accept, what they are not, and what they are obliged by regulation or duty of care to address regardless.

This stage frequently reduces the amount of work rather than increasing it. Several identified risks are usually best accepted, knowingly and on the record.

04

Mitigate

Reduce it, or accept it deliberately

Select proportionate measures — procedural, physical, personnel or planning — and assign each an owner and a date. Mitigation includes the decision to accept a risk, which is a legitimate outcome when it is deliberate, documented and taken by someone with authority to take it.

Procedural measures usually precede expenditure. A change in who holds a schedule frequently reduces exposure more than equipment does.

05

Monitor

Watch what changes

Keep the assessment current. Monitoring means defined review intervals, named responsibility, and agreed triggers — a change of premises, a new market, a public appointment, an incident, a change in a principal's circumstances — that cause the assessment to be revisited before its scheduled date.

An assessment describes a moment. Unreviewed, it does not merely become outdated; it becomes misleading, because people continue to rely on it.

06

Improve

Learn from what actually happened

Feed experience back into the framework. Near-misses, minor incidents, rehearsal findings and even routine observations reveal where an assessment was wrong, and are the most valuable information available — provided the culture allows them to be reported without penalty.

Organisations that punish the reporting of near-misses stop hearing about them. They do not stop having them.

04 Risk Matrix Qualitative, illustrative

A qualitative matrix, used honestly

The matrix below illustrates how likelihood and consequence are combined to produce a priority band. It is a structure for comparison, not a calculation, and the bands mean what an assessment says they mean for a particular client.

How to read it

Read down for consequence and across for likelihood. The response band indicates how a risk in that position is treated — not how probable an event is. Every placement in a real assessment carries written reasoning, and a client is entitled to disagree with it.

Abstract analytical field: a five-by-five grid with plotted points and a rising dashed trend line, used as a design motif for risk assessment.
Analytical study — decorative Fig. 04
Illustrative qualitative risk matrix — consequence against likelihood
Consequence Unlikely Possible Likely
Severe PriorityTreat and plan. Mitigation and contingency arrangements both required. ImmediateAddress first. Escalate to the client decision-maker. ImmediateAddress before the activity proceeds, or reconsider the activity.
Major ManageMitigate proportionately; confirm contingency exists. PriorityTreat and plan; assign an owner and a date. ImmediateAddress first; review the underlying activity.
Moderate Accept or monitorRecord the decision; set a review interval. ManageProcedural mitigation usually sufficient. PriorityTreat; recurrence is the principal concern.
Minor AcceptDocument the acceptance and who made it. Accept or monitorLow-cost procedural adjustment where available. ManageFrequency may make a minor risk significant.

Illustrative only. Bands, definitions and thresholds are agreed with each client and are not transferable between engagements. Table scrolls horizontally on small screens.

R.01

People

Risks to individuals: principals, staff, families, travellers, visitors and contractors.

R.02

Places

Premises, residences, venues and the routes and approaches between them.

R.03

Movement

Travel, transfers and any activity that makes a pattern predictable to observers.

R.04

Information

Who knows a schedule, an address or an association — and how that information moves.

R.05

Process

Routines, approvals and responsibilities that create exposure without anyone intending it.

R.06

Continuity

The activities a client cannot afford to have interrupted, and their dependencies.

Begin with an assessment

Most clients discover their exposure is not where they expected it.

An assessment is the least expensive part of any security engagement and the part that determines the value of everything after it.