Para Special ForcesIndependent Security & Protection Confidential Enquiry

PSF / RISK Risk management & assessment

Structured judgement for uncertain conditions.

Good security decisions rest on a clear, honest understanding of risk: what could happen, how likely it is, how much it would matter and what response is genuinely proportionate. That understanding is what we build first.

  1. R.01IdentifyWhat could affect the objectives?
  2. R.02AssessHow likely, and how serious?
  3. R.03PrioritiseWhat matters most?
  4. R.04MitigateWhat response is proportionate?
  5. R.05MonitorWhat has changed?
  6. R.06ImproveWhat have we learned?

PSF / 01 Principles

Risk management is a discipline of proportion.

Every person and organisation lives with risk. The aim of risk management is not to eliminate it — that is neither possible nor desirable — but to understand it well enough to make sensible, defensible decisions about what to do. Some risks warrant real investment. Many are best handled through small changes of habit. Some are simply accepted, knowingly.

Our approach follows the logic set out in widely recognised risk-management guidance: establish the context and objectives, identify and analyse risks, evaluate them against what the client is prepared to accept, treat those that need treatment, and keep the whole picture under review. The vocabulary is standard for good reason. It lets clients, advisers, insurers and partners discuss risk in the same terms.

What the frameworks cannot supply is judgement. Deciding how likely something really is, how serious it would be for this particular client, and whether a proposed measure is worth its cost and intrusion requires experience applied honestly. That is the part of the work we take most seriously.

Above all, assessment must be proportionate. An assessment that exaggerates danger leads to heavy, conspicuous and expensive arrangements. One that understates it leaves people exposed. Both fail the client.

Illustrative photograph: personnel outdoors among pine trees operating optical observation equipment mounted on tripods.
Fig. 01 — Observation before assessmentIllustrative photograph
Threat
Something with the potential to cause harm.
Vulnerability
A weakness that could allow harm to occur.
Likelihood
How probable it is that a risk will occur.
Impact
How serious the consequences would be.
Control
A measure that changes likelihood or impact.
Residual risk
The risk that remains after controls.
Table 01 — What risk management is, and what it is not
It isIt is not
A structured way of understanding what could affect a person’s or organisation’s objectives.A prediction of exactly what will happen, or when.
Proportionate to realistic threats, vulnerabilities and consequences.A justification for the maximum possible level of security.
Evidence-informed and candid about uncertainty and assumptions.A list of every conceivable danger, weighted equally.
A living record, reviewed as circumstances change.A document written once and filed away.
A basis for decisions that clients understand and own.A substitute for the client’s own priorities and judgement.

PSF / 02 The process

A cycle, not a checklist.

Risk management does not end when a report is delivered. Each stage feeds the next, and the last feeds back into the first.

Six-stage risk management cycle: identify, assess, prioritise, mitigate, monitor and improve, returning to identify. 01 02 03 04 05 06 Identify Assess Prioritise Mitigate Monitor Improve Context & objectives Communicate · Record
Fig. 02 — The continuous risk cycle
  1. Identify

    Key question — What could affect the objectives?

    Identification starts with objectives, not threats. Before asking what could go wrong, it is necessary to understand what the person, family or organisation is trying to do — live privately, travel for business, host an event, run a site — and what they value most. A risk is then anything uncertain that could affect those objectives.

    Information comes from conversations with the client and those around them, observation of places and routines, review of existing arrangements and past concerns, and reputable open sources about the wider environment. Each risk is described precisely, as a cause, an event and a consequence. “Unauthorised access to the residence through an unmonitored service entrance” is useful; “security” is not.

    Typical outputs
    • Context statement
    • Described risks
    • Assumptions & gaps
  2. Assess

    Key question — How likely is it, and how serious would it be?

    Each identified risk is examined for two things: how likely it is to occur within the relevant period, and how serious the consequences would be if it did. Both are judged against clear qualitative scales, so that different assessors reach comparable conclusions and clients can follow the reasoning.

    Good assessment considers existing controls honestly — what is already in place and how well it actually works in practice — and records the evidence behind each rating. Where information is limited, the uncertainty is stated rather than hidden. An assessment that sounds confident but cannot explain itself is of little use to anyone.

    Typical outputs
    • Ratings with reasoning
    • Control effectiveness
    • Stated uncertainty
  3. Prioritise

    Key question — What matters most, and what can wait?

    Not every risk deserves the same attention, and time, money and goodwill are always finite. Prioritisation ranks risks by their assessed level, then tempers that ranking with judgement. Risks that could develop quickly, those with severe consequences even when unlikely, and those that affect people rather than property often warrant earlier attention.

    This stage also compares each risk with what the client is prepared to accept — their risk appetite — so that effort concentrates where the gap between current and acceptable exposure is widest. The aim is a short, honest list of what matters most, not a long one in which everything appears urgent.

    Typical outputs
    • Prioritised risk list
    • Risk appetite statement
    • Immediate actions
  4. Mitigate

    Key question — What response is proportionate?

    For each priority risk the question becomes what response is proportionate. Recognised treatment options include avoiding the activity that creates the risk, reducing its likelihood or impact, sharing it — through insurance or contractual arrangements, for example — or accepting it knowingly where treatment would cost more than it saves.

    Measures are chosen as a balanced set: changes to routines and procedures, physical and technical measures, training and awareness and, where genuinely justified and lawful, protective services. Each has an owner, a timescale and a plain statement of what it is meant to achieve. The least intrusive effective option is usually the right place to start.

    Typical outputs
    • Treatment plan
    • Contingency arrangements
    • Residual risk statement
  5. Monitor

    Key question — What has changed since we last looked?

    Risks and controls both change. Profiles rise and fall, routines shift, environments evolve, and measures that once worked well quietly erode through familiarity. Monitoring keeps the picture current by checking that agreed measures are in place and effective, and by noticing early signals that a risk is growing or fading.

    Monitoring should be proportionate too: light, regular checks for most risks and closer attention for the few that are higher or more volatile. Defined triggers — a change of residence, a new travel pattern, a significant incident nearby — prompt an unscheduled review rather than waiting for the calendar.

    Typical outputs
    • Review schedule
    • Change triggers
    • Control checks
  6. Improve

    Key question — What have we learned, and what should change?

    The final stage turns experience into better arrangements. After incidents, near-misses, exercises and scheduled reviews, the questions are simple: what worked, what did not, and what should change? Honest answers are recorded without blame, because a culture that hides problems loses the chance to fix them.

    Improvements flow back into the first stage. Objectives are re-confirmed, new risks identified and redundant measures retired — which matters as much as adding new ones. Over time, this is what keeps an arrangement proportionate, credible and suited to the client’s life or organisation as it is now, rather than as it was.

    Typical outputs
    • Recorded lessons
    • Updated plan
    • Measures retired or refined

PSF / 03 Assessment matrix

Likelihood × impact, read with judgement.

A qualitative matrix gives everyone a shared language for discussing risk. It supports decisions. It does not make them.

Table 02 — Illustrative qualitative risk matrix
Likelihood ↓Impact → Minor Moderate Significant Major Severe
Almost certainMediumHighHighVery highVery high
LikelyMediumMediumHighHighVery high
PossibleLowMediumMediumHighHigh
UnlikelyLowLowMediumMediumHigh
RareLowLowLowMediumMedium

Rows show likelihood and columns show impact; each cell gives the resulting rating band. Colour is supported by a text label in every cell.

Scroll the matrix sideways →

Rating bands

Low
Accept and manage through routine arrangements; review periodically.
Medium
Manage through defined measures with a named owner, and monitor.
High
Requires senior attention and treatment before or alongside the activity.
Very high
Do not proceed as planned until the risk is reduced or the activity redesigned.

Reading the matrix responsibly

  • Scales are ordinal: ratings are categories, not numbers to multiply or average.
  • A rating records a judgement. The reasoning matters as much as the colour.
  • Unlikely but severe risks may need contingency plans even when rated medium.
  • Speed of onset and potential to escalate are weighed alongside the rating.
  • Scales are calibrated to each client, because “severe” differs from one life to another.

Likelihood scale

  1. Almost certainExpected in most circumstances, or already occurring in comparable settings.
  2. LikelyWill probably occur at some point; there are clear indications or precedents.
  3. PossiblePlausible in the context, though not expected.
  4. UnlikelyCould occur, but there is little to suggest that it will.
  5. RareConceivable only in exceptional circumstances.

Impact scale

  1. SevereGrave harm to people, or consequences that fundamentally threaten the objectives.
  2. MajorSerious harm, prolonged disruption or substantial privacy or reputational damage.
  3. SignificantHarm or disruption that needs deliberate recovery, with some wider effect.
  4. ModerateNoticeable disruption or minor harm, recoverable with modest effort.
  5. MinorBrief inconvenience, readily absorbed, with no lasting effect.

PSF / 04 Risk contexts

One discipline. Eight contexts.

The principles stay constant. What changes is what matters, who is affected and what a useful output looks like.

Table 03 — Typical considerations and outputs by context (general, not exhaustive)
Context Typical considerations Typical outputs Often informs
C.01Individuals Personal profile and visibility; predictability of daily routines; online footprint; home and commute; personal health needs. Personal risk review; practical awareness guidance; a short list of proportionate recommendations. Personal safety training; advisory support
C.02Families The differing needs of each family member; schools and activities; household staff and visitors; privacy on social media; multiple residences. Family security review; simple household protocols; age-appropriate awareness guidance. Residential arrangements; family awareness training
C.03Executives Public and media profile; travel frequency; events and speaking engagements; business sensitivities; the interface between office, home and travel. Executive risk assessment; protective planning options at different levels; travel protocols. Executive protection; travel planning
C.04Businesses People, premises and assets; sensitive information; visitors and contractors; reputational exposure; continuity of critical activities. Security risk assessment; policy and procedure review; continuity considerations. Security consulting; staff training; continuity planning
C.05Events Venue layout and access; audience profile and density; guest and speaker profiles; timings and transitions; coordination with organisers and authorities. Event risk assessment; inputs to the security plan; contingency and communication arrangements. Event security planning; licensed local delivery
C.06Travel Destination environment and official advice; legal and licensing position; access to medical care; itinerary and transport; communications. Travel risk assessment; pre-travel briefing; check-in and escalation arrangements. International support; executive travel
C.07Properties Perimeter and access points; lighting and sightlines; alarms and monitoring; control of keys and access credentials; activity nearby. Site security survey; prioritised physical and procedural recommendations. Specialist security advisory
C.08Organisations Governance and accountability; duty of care to staff and visitors; risk appetite; incident-reporting culture; the gap between policy and practice. Review of the risk framework; defined roles and escalation routes; a sustainable review cycle. Preparedness training; organisational advisory

Travel assessments are closely linked to our approach to international assignments, where lawful authorisation is assessed jurisdiction by jurisdiction. Executive assessments frequently shape the scope of executive protection.

PSF / 05 Judgement

Four principles that keep assessment honest.

Frameworks give structure. These principles decide whether the result is genuinely useful to the client.

J.01

Proportionality

The response to a risk should match its realistic level. Too little leaves people exposed; too much creates cost, intrusion and visibility that can become problems in their own right. Proportionality asks what a reasonable, well-informed person would consider sensible in the circumstances.

It also has a legal and ethical dimension. Measures that affect other people — their privacy, their movement, their dignity — must be justified by the risk they address, and must remain within the law.

J.02

Residual risk

No arrangement removes risk entirely. Residual risk is what remains once agreed measures are in place, and it should be stated plainly rather than implied away. A plan that claims to leave no risk at all has simply not been examined closely enough.

Clients decide whether the remaining level is acceptable. Our role is to make it visible, explain it honestly and describe what further treatment would involve — including its cost and its effect on everyday life — if they wish to go further.

J.03

Avoiding over-specification

Beyond a certain point, additional measures add little protection while adding cost, inconvenience and conspicuousness. Heavy, visible arrangements can attract attention, disrupt normal life and wear away goodwill with neighbours, colleagues and the public.

We would rather recommend a lighter arrangement that people will actually sustain than an impressive one they abandon after a month. Recommending less, when less is enough, is part of professional responsibility.

J.04

Documentation and review

Assessments are recorded clearly: the context, the risks, the reasoning behind each rating, the measures chosen and the residual risk accepted. That record allows decisions to be understood, questioned and revisited — by the client, by us and by anyone else with a legitimate need to know.

Every assessment carries a review point, both scheduled and triggered by significant change. An assessment that is never reviewed gradually becomes a description of a situation that no longer exists.

PSF / 06 From assessment to action

Findings that shape what happens next.

An assessment is only valuable if it changes decisions. Its findings set the scope, level and priorities of any service that follows.

PSF / 06.1 Confidentiality

Assessment findings stay confidential.

An assessment describes vulnerabilities — in a person’s routine, a family’s home or an organisation’s procedures. In the wrong hands, that information could create the very risk it was meant to reduce. Findings are therefore treated as confidential client information from the first conversation onwards.

  • Shared only with people the client authorises, strictly on a need-to-know basis.
  • Handled and stored securely, with sensitive detail kept out of general circulation.
  • Summaries separated from detail, so wider audiences receive only what they need.
  • Retained only while there is a legitimate purpose, then securely disposed of.
  • Never used for publicity, case studies or marketing of any kind.

PSF / 08 Begin with clarity

The right level of protection begins with an honest assessment.

Tell us, in confidence, what you need to protect and what concerns you. We will suggest a proportionate starting point — which may well be lighter than you expect.

Contact person

Mr. Digant Sharma

+91-9769999960 im@digantsharma.com