A risk assessment for security is the structured process of identifying what could go wrong, evaluating how serious it would be if it did, and determining whether the controls currently in place are adequate to manage the risk.
It sounds straightforward. In practice, the quality of a security risk assessment varies enormously depending on who conducts it, what methodology they apply, and whether they have a commercial interest in the outcome.
This guide explains what a proper risk assessment for security involves, how the process works from start to finish, and what distinguishes a genuine, ISO 31000:2018-aligned assessment from a vendor-conducted site walkthrough.
What a Risk Assessment for Security Actually Is
A risk assessment for security is not a checklist. It is not a free assessment offered by a CCTV company or guarding firm. It is a structured, evidence-based professional service that produces findings specific to a particular site, organisation, and threat environment — and that gives decision-makers a prioritised, defensible basis for security investment.
The purpose of a security risk assessment is to answer three questions:
What could realistically go wrong? Not every conceivable threat — a considered, site-specific view of what threats are actually credible given where the organisation operates, what it does, and who uses its spaces.
How likely is it and how bad would it be? Each identified threat is evaluated by the likelihood of it occurring and the consequence if it does. This produces a risk rating that tells the organisation how serious each risk actually is.
Are the existing controls adequate? Evaluating whether the controls currently in place — CCTV, access control, lighting, perimeter arrangements, procedures, patrols — are actually reducing the risks they’re supposed to address, or whether gaps exist that leave the organisation exposed.
The combination of these three elements is what makes a security risk assessment genuinely useful — it produces a priority order rather than a list, and it focuses on what actually needs to change rather than on what’s easiest to sell.
The Methodology: Why ISO 31000:2018 Matters
In Australia, the recognised framework for risk management methodology is ISO 31000:2018 — Risk Management: Guidelines. A security risk assessment aligned with this standard follows a structured, repeatable process that produces findings which are consistent, comparable, and defensible.
ISO 31000:2018 establishes that risk assessment involves three sequential stages.
Risk identification. Establishing the context — who uses the site, when, how, and what the surrounding environment looks like — and then systematically identifying every realistic threat relevant to that context. For physical security, this typically includes theft, unauthorised access, vandalism and antisocial behaviour, aggression toward staff, and after-hours intrusion. For higher-profile or public-facing sites, the threat picture may extend to vehicle-borne threats, crowded places risks, and the broader threat environment relevant to the sector and location.
Risk analysis. Determining the likelihood and consequence of each identified threat, taking into account the existing controls currently in place. This produces a risk rating for each threat — typically expressed on a likelihood-consequence matrix — that reflects not just the theoretical severity of the threat but how well current controls are managing it.
Risk evaluation. Comparing the risk ratings against the organisation’s risk appetite to determine which risks require immediate treatment, which need monitoring, and which are at an acceptable level. This stage produces the priority order that makes the assessment actionable — telling the organisation where to focus first and why.
For organisations that need to present security risk findings to a board, audit committee, regulator, or insurer, alignment with ISO 31000:2018 provides the methodological credibility that makes the assessment stand up to scrutiny.
What the Assessment Covers in Practice
A well-structured security risk assessment for a physical security context evaluates multiple layers of the organisation’s security arrangements.
Physical environment and CPTED factors. How the design and layout of the site is influencing security outcomes. Natural surveillance — whether legitimate users can see activity across the space. Territorial definition — whether the boundary between public and controlled areas is clear. Sightlines, landscaping, lighting, and the design of movement paths. These environmental factors often contribute more to risk outcomes than technology controls, and they’re frequently overlooked in vendor-conducted assessments that focus on hardware.
Access control. Who can access which areas, whether credentials are current and reflect current personnel and roles, whether door hardware is functioning as intended, and whether the audit trail generated by the system is being reviewed. Access control drift — active credentials belonging to former staff, permissions that no longer reflect current roles, hardware that’s been bypassed — is one of the most consistent findings in security risk assessments across WA organisations.
CCTV and surveillance. Camera coverage of key areas against the identified threats, image quality and resolution against the surveillance objective (detection, observation, recognition, or identification), lighting alignment, recording and retention settings, and system health. Assessed against AS/NZS 62676. The most common finding is not insufficient cameras — it’s cameras that aren’t positioned or configured to produce usable footage when an incident occurs.
Lighting. Illumination levels and uniformity assessed against AS/NZS 1158, including after-hours performance. Lighting and CCTV need to work together — a camera covering an inadequately lit area produces unusable footage regardless of specification. After-hours lighting assessments consistently identify gaps that daytime inspections miss entirely.
Alarm and monitoring arrangements. Alarm configuration, monitoring response protocols, integration between systems, and whether alarm events are actually generating an appropriate and timely response.
Perimeter and boundary arrangements. The physical integrity of the perimeter, vehicle access control, the definition of boundaries between public and controlled space, and the specific vulnerabilities created by shared-use environments, carparks, and after-hours access points.
Security procedures and operational factors. Incident reporting, patrol arrangements, key and credential management, visitor and contractor management, and after-hours procedures. Physical controls are only as effective as the procedures governing their use — this element frequently produces the most actionable findings.
After-hours vulnerability. Many sites present a significantly different risk profile after hours — when staffing is reduced, monitoring is less active, and response times are longer. A security risk assessment that only examines daytime conditions gives an incomplete picture of actual exposure.
Who Needs a Risk Assessment for Security
Security risk assessments are relevant across a wide range of sectors and contexts. The most common in Perth and regional WA include:
Local government and councils — managing parks, libraries, civic buildings, carparks, and community facilities. Smartsec is a WALGA Preferred Supplier (PSP001-002 and PSP001-026) — councils can engage us without a separate procurement process.
Healthcare facilities — with obligations under AS 4485:2021 and the WA Health Risk Management Policy. The assessment provides the documented risk position required for governance and regulatory compliance.
Critical infrastructure operators — energy, water, transport, health, and communications assets subject to the Security of Critical Infrastructure Act 2018 — requiring CIRMP physical security assessments and plans under the enhanced CIRMP Rules.
Developers and architects — when a development application carries a security or CPTED condition, an independent assessment provides the evidentiary basis for planning approval.
Commercial and retail operators — where incidents, insurance requirements, or governance obligations trigger independent assessment.
Mining and resources operators — remote mine sites and FIFO facilities where extended response times and isolated locations create specific security challenges.
Aviation industry participants — under the Aviation Transport Security Act 2004, mandatory risk-based physical security assessments are now required for all Transport Security Programs.
Common Triggers for Commissioning a Security Risk Assessment
Organisations commission security risk assessments at different points in the security decision-making cycle. The most common triggers include:
Following an incident. A break-in, assault, theft, or significant security failure prompts an organisation to understand what went wrong and what needs to change.
Before a capital works decision. When a significant investment in security infrastructure is being considered, an assessment provides the risk evidence that justifies the spend and ensures it addresses the actual risk.
For compliance and governance. Councils, government agencies, healthcare facilities, and critical infrastructure operators commission assessments to satisfy governance requirements, insurer expectations, regulatory attestation, or development application conditions.
As part of a regular review cycle. Security risk is not static — organisations that treat assessment as a periodic governance obligation consistently make better security decisions than those that commission assessments only in response to incidents.
Why Independent Assessment Produces Better Outcomes
A risk assessment for security conducted by a vendor, installer, or guarding company comes with a structural incentive — the findings tend to reflect what the assessor can supply. A CCTV supplier will find that more cameras are needed. A guarding company will find that more patrols are required. These findings may be technically defensible, but they reflect commercial interest as much as risk evidence.
An independent security risk assessment has no commercial interest in the outcome. The findings reflect what the risk evidence actually shows, and recommendations reflect what the organisation genuinely needs — which sometimes means confirming existing controls are adequate, or redirecting budget toward procedural improvements rather than technology.
For organisations presenting findings to a board, justifying expenditure to elected members, or demonstrating compliance to a regulator — independent assessment provides a significantly stronger governance position.
Engaging Smartsec for a Security Risk Assessment
Smartsec Security Solutions delivers independent security risk assessments for organisations across Perth and regional WA — aligned with ISO 31000:2018, vendor-neutral, and structured to serve governance, compliance, and operational decision-making purposes.
Our assessments are conducted by Khabeer Rockley SRMCP — a licensed WA Security Risk Consultant and Security Agent with technical security licensing and nearly two decades of experience in physical security across the public and private sectors in WA.
Contact Smartsec Security Solutions to arrange a confidential scoping conversation.


