All insights
SecurityThreat AssessmentCounter Terrorism

Building a threat assessment that actually drives decisions

Most threat assessments end up as background documents. The useful ones change where money is spent — and where it isn't.

Oakwood Risk & Resilience7 min read

A threat assessment is only useful if a decision-maker reads it and changes their mind about something. By that standard, most of the threat assessments we see are not useful. They are comprehensive, well-sourced, and operationally inert.

The pattern that separates the useful from the decorative is specificity. A statement that 'the terrorism threat to the UK remains SUBSTANTIAL' tells a board nothing they didn't already know. A statement that 'our flagship site in central Manchester sits within a higher-risk profile because of these three site-specific factors, and here are the two protective measures that would most reduce the residual risk' is a different document entirely.

Useful threat assessments are short, prioritised, and recommend action. They distinguish between threats that are credible, threats that are merely possible, and threats the organisation is comfortable accepting. They make trade-offs visible and they are revisited when the picture changes — not on an annual schedule.

If your assessment doesn't end with a small number of decisions for the executive to take, it isn't doing the job. Write the document that someone in the C-suite will actually read on a Friday afternoon and act on the following Monday.

Talk to us

Want to discuss how this applies to your organisation?

Speak with us