How to Assess Security Risk: A Practical Guide for WA Organisations

Most organisations know they should be assessing their security risk. Fewer know what that actually involves – or whether what they’re currently doing qualifies as a genuine assessment.

This article explains what it means to properly assess security risk, what the process looks like in practice, and why the organisations that do it well are consistently better placed to make defensible, cost-effective security decisions than those that don’t.

 

What It Actually Means to Assess Security Risk

To assess security risk is to apply a structured, evidence-based process to three fundamental questions:

What could go wrong? Identifying the realistic threats to your organisation, your site, your people, and your assets. Not a generic list of everything that could theoretically happen – a considered, site-specific view of what threats are actually credible given where you are, what you do, and who uses your space.

How likely is it and how bad would it be? Evaluating each identified threat against the likelihood of it occurring and the consequence if it does. This is the analytical core of a risk assessment – it turns a list of concerns into a priority order that tells you where to focus first.

What’s already in place and is it working? Evaluating your existing controls – CCTV, access control, lighting, perimeter treatments, procedures, patrol arrangements – against each threat. Not whether the systems exist, but whether they’re adequate, configured correctly, and actually reducing the risk they’re supposed to address.

The combination of these three things – threat identification, risk rating, and control evaluation – is what separates a genuine security risk assessment from a site walkthrough, a vendor quote, or a compliance checklist.

 

The Standard That Governs How Security Risk Should Be Assessed

In Australia, the recognised framework for risk management is ISO 31000:2018 – Risk Management: Guidelines. It provides the principles and methodology that a structured security risk assessment should follow.

ISO 31000:2018 establishes that risk assessment involves three sequential steps: risk identification, risk analysis, and risk evaluation. Applied to physical security, this means:

Risk identification – establishing the context (who uses the site, when, how, and what the surrounding environment looks like), then identifying every plausible threat relevant to that context.

Risk analysis – determining the likelihood and consequence of each identified threat, taking into account the existing controls that are currently in place. This produces a risk rating for each threat – typically expressed as a matrix of likelihood against consequence.

Risk evaluation – comparing the risk ratings against the organisation’s risk appetite to determine which risks require treatment, which are acceptable, and in what priority order treatment should occur.

For WA organisations with governance obligations – councils, government agencies, healthcare providers, critical infrastructure operators – alignment with ISO 31000:2018 is increasingly expected as the methodological standard for any security risk assessment that will be presented to a board, audit committee, or regulator.

 

What a Structured Security Risk Assessment Looks Like in Practice

Understanding the framework is one thing. Understanding what actually happens during a well-conducted security risk assessment is another.

Establishing context. Before any site visit, a good assessment starts with understanding the organisation and its operating environment. What type of site is it? Who uses it and when? What are the hours of operation? What is the incident history? What controls are currently in place? This context shapes everything that follows – the threats considered, the controls evaluated, and the risk ratings applied.

Site inspection. There is no substitute for physically being on site. A desk-based assessment that relies on photographs and floor plans misses the things that photographs don’t capture – how the space feels to move through, where the blind corners actually are, how lighting performs in real conditions, what the after-hours access situation looks like in practice. For most sites, a physical inspection is non-negotiable.

After-hours conditions deserve specific attention. Many sites have adequate security during business hours but significant gaps after hours – when staffing is reduced, monitoring is intermittent, and response times are longer. An assessment conducted only during business hours gives an incomplete picture.

Threat identification. Working through the realistic threat profile for the site. For most WA organisations this includes opportunistic theft, vandalism and antisocial behaviour, unauthorised access, aggression toward staff, after-hours intrusion, and – for higher-profile or public-facing sites – the broader threat picture relevant to crowded places or critical infrastructure. Threats are identified based on the site’s specific context, not copied from a generic template.

Control evaluation. Assessing each existing control against the threats it’s supposed to address. CCTV – does it cover the right areas, is it producing usable footage, is the recording and retention configuration correct? Access control – are credentials current, do permissions reflect current roles, is the hardware functioning as intended? Lighting – does it meet the relevant Australian Standards, are there dark patches, does it perform after hours? Procedures – are they documented, current, and understood by the people who need to follow them?

Risk rating. Applying a likelihood-consequence matrix to produce a risk register. Each identified threat is rated – typically on a five-point scale for both likelihood and consequence – producing a risk level that places it in a priority tier. This is the output that tells the organisation where to focus resources first, which is particularly important when budgets are finite and not everything can be addressed simultaneously.

Reporting. A written report documenting methodology, findings, risk ratings, and prioritised recommendations. The report is the formal deliverable – it needs to be clear enough for a decision-maker who isn’t a security specialist to understand and act on, and structured well enough to withstand scrutiny from a board, auditor, or regulator.

 

What Gets Missed When Organisations Try to Assess Security Risk Themselves

Internal security reviews happen in most organisations. They’re useful – they keep security on the agenda and can identify obvious problems. But they have consistent blind spots that a structured independent assessment avoids.

Familiarity bias. People embedded in an organisation stop seeing the things they see every day. The door that’s always propped open, the access card that’s never been deactivated, the CCTV camera that’s been pointing at the wrong angle for six months – these become invisible to people who walk past them daily. An independent assessor sees the site as it is, not as it’s supposed to be.

Absence of methodology. An internal review without a structured methodology produces inconsistent results. The same site assessed by two different internal reviewers will produce different findings – because there’s no common framework for what to look for or how to rate it. ISO 31000:2018 provides that framework, and its application is what makes findings comparable, repeatable, and defensible.

Commercial influence. When a vendor or supplier conducts a security assessment of your site, there is an inherent conflict of interest. The assessment tends to identify problems that the assessor’s products or services can solve. An independent consultant has no commercial interest in the outcome – the assessment reflects what the risk evidence actually shows.

Incomplete scope. Internal reviews frequently focus on the controls that are visible and easy to evaluate – cameras, access readers, fencing – and miss the procedural and operational factors that are equally important. Are incident reports being reviewed? Are access permissions being audited? Are patrol routes still relevant to current risk? Are procedures current and understood? A structured assessment covers all of these.

 

How Often Should You Assess Security Risk?

Security risk isn’t static. The threat environment changes, sites change, operations change, and controls degrade over time. An assessment that was accurate twelve months ago may not accurately reflect the current risk position.

For most organisations, a full security risk assessment every two to three years is a reasonable baseline – with targeted reviews triggered by specific events: a significant incident, a major site change, a change in operating model, a new regulatory obligation, or a change in the local threat environment.

For organisations with ongoing compliance obligations – critical infrastructure operators under the SOCI Act, healthcare facilities under AS 4485:2021, councils with governance obligations under the Local Government Act – the review cycle may be prescribed or implied by the relevant framework. Annual or biennial reviews are common in these contexts.

Between full assessments, an annual desktop review of the risk register – checking whether identified risks have changed in likelihood or consequence, whether treatments have been implemented, and whether new risks have emerged – is a practical way to keep the assessment current without the full resource investment of a new site inspection.

 

When to Engage an Independent Consultant to Assess Security Risk

Some security risk assessments are straightforward enough to be managed internally with appropriate support. Others genuinely require independent expertise. The cases where independent assessment adds the most value include:

Situations where the findings will be presented to a board, council committee, or regulator and need to be independently verified. Situations where the organisation has a known conflict of interest in assessing its own controls. Situations where a significant investment decision – a capital works project, a new guarding contract, a technology upgrade – is being made on the basis of the assessment. Situations where a compliance obligation requires a formal, documented assessment from a credentialed consultant. And situations where an incident has occurred and the organisation needs an objective view of what went wrong and why.

In each of these cases, the investment in an independent assessment is justified by the quality, credibility, and utility of the output.

 

Assessing Security Risk in Perth and WA – Smartsec Security Solutions

Smartsec Security Solutions is a Perth-based independent physical security consultancy delivering security risk assessments for councils, commercial operators, healthcare facilities, critical infrastructure operators, developers, and community organisations across Western Australia.

Our assessments are aligned with ISO 31000:2018, conducted on site by an experienced consultant, and produced to the standard required for governance, compliance, and procurement decisions. We are vendor-neutral – no commercial relationships with security product suppliers or installers – which means every finding and recommendation reflects the actual risk, not a commercial interest.

We hold the Security Risk Management Certified Professional (SRMCP) credential and are licensed as a WA Security Risk Consultant and Security Agent. We are a WALGA Preferred Supplier, enabling WA councils to engage us directly under the panel arrangement without a separate procurement process.

Contact Smartsec Security Solutions to discuss your site and arrange a confidential scoping conversation.

more insights

Call for a scope chat