Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
PhysicalSecurity Enterprise ServicesSecurity Leadership and ManagementPhysical Security

Integrated Solutions

3 steps to a comprehensive security threat assessment

How can security executives make sure their organization is prepared for an event?

By Sarah Ludwig Rausch
Comprehensive Security Threat Assessment

champpixs / iStock / Getty Images Plus via Getty Images

February 5, 2024

When there’s an internal or external event on the horizon, physical security is crucial. The best strategy is to conduct a comprehensive physical security threat assessment well before the event to evaluate the threats that face the enterprise and develop contingency plans to secure the organization before, during and after events.

“It’s better to have a plan in place that has been created in a non-stressful situation,” says Jack Leskovar, Director of Security and Risk Management at Edgewood College in Madison, Wisconsin. “We try to come up with every complication that we can think of prior to an incident actually happening because the worst thing would be for something bad to happen and you’re trying to devise the plan as you go along.”

A comprehensive physical security threat assessment is a complex project, but “it’s worth its weight in gold,” says Anthony Brown, Director of Risk and Emergency Management at Gonzaga University in Spokane, Washington, and Owner of S5 Risk Management LLC. “Risk is a result of thousands of small factors. The trick is to identify as many factors as possible to accurately reflect risk, as well as all the opportunities to manage that risk. A threat assessment is an effective tool for providing that context in an efficient manner.”


1. Identify threats and hazards

 In every threat assessment, Brown says a skillful assessor will consider factors such as insider threats, external threats, natural disasters, cyber threats, active shooter threat, criminal behavior in the region, and legislation that impacts the ability to prevent and respond to threats or that increases the likelihood of events.

One standard threat assessment process to consider is the Threat and Hazard Identification and Risk Assessment (THIRA), which divides threats and hazards into three categories: natural, technological and human-caused. THIRA uses “objective analysis to build a comprehensive view of threats the organization faces, and the impacts should those threats occur,” says Brown.

Stay relevant
The security team may already have a baseline list of security threats thanks to regular general risk assessments or yearly events. However, this will need to be updated for each event to keep up with current events, points out Harris D. Schwartz, a strategic security advisor in Las Vegas.

Gather as much data as possible. “As trivial as that information may seem, it’s going to be important to put that full picture together of what you’re dealing with,” Leskovar says.

Include other departments
A threat assessment should involve every department that either contributes to or is impacted by any risk factors. “Every department has value to add to a comprehensive threat assessment and can inform it with concerns, incidents and ongoing issues,” says Brown.

At Edgewood College, the threat assessment team involves people from Residence Life, Student Development, the Wellness Center, and Student Inclusion and Involvement.

“We meet weekly to address the students that may have some issues or stressors so we can prevent incidents and help them be successful,” Leskovar says. “It’s almost like a mentorship process, and it has been phenomenal.”

Gather threat intelligence
Schwartz says it’s a good idea to collect threat intelligence prior to and during the event, and in some cases after the event too. “If people are talking about it, especially special interest groups and other threat actors, it’s important to have a full picture, especially because you’re most likely going to be holding that event again,” he says.

Anthony Brown, Jack Leskovar, Harris Schwartz

"Every department has value to add to a comprehensive threat assessment.”
— Anthony Brown, Director of Risk and Emergency Management at Gonzaga University


2. Assess vulnerabilites

A comprehensive threat assessment should include a vulnerability assessment “because it will identify the factors that are contributing to risk and therefore identify opportunities for improvement,” says Brown. This includes identifying at-risk assets and the financial losses should the specific threat occur, as well as evaluating the target’s appeal while also considering the current security countermeasures that are in place.

Review access control
Schwartz stresses the importance of evaluating access control. Onsite events give you better control over physical access, but in an external venue, it’s essential to review all the potential ways that someone could access the event. “There could be access points that you’re not even aware of, so ensure that you’ve done a full review,” Schwartz says.

“We look at the buildings and event sites here and what would be the most reasonable way that an attacker could access a building or an event undetected,” says Leskovar. “We’re in a college environment and the doors are all open in public spaces, so we have to find other solutions to mitigate threats.”

Inspect systems
A threat assessment should identify existing physical security components, along with how effective they are in decreasing the likelihood of or the impact of a threat against your organization, Brown says. This allows you to pinpoint vulnerabilities and decide which mitigation projects are a high priority.

Perform an advance survey
If the event is external, Schwartz believes an advance assessment of the location is essential, though he acknowledges that not all organizations do this. “You’re assessing where the event is actually going to take place and building your understanding of the surroundings in the area, including knowing where hospitals are and meeting with local law enforcement,” says Schwartz. Security teams can also check lighting, maintenance and other environmental factors.

Include behavior
Innocent situations can quickly be spun into major issues via gossip and rumors, especially in educational environments. Because of this, Leskovar believes that an effective, complete threat assessment should involve a focus on behavior. “If we skip the behavioral side of it, we’re missing a lot,” he says. This is why changes in behavioral patterns are critical to the prediction and mitigation of incidents.

Survey the security climate
“The largest weakness in most security systems is people. Conversely, people are the most important asset organizations employ to reach their goals,” Brown says. In other words, any threat assessment should include the people in your enterprise.

Brown believes understanding the security culture is vital to finding strengths and weaknesses in an organization and that it can give valuable insight into risk factors, especially when it comes to the vulnerability assessment. Survey questions should be deliberately worded so that security is able to discern between relevant factors such as security awareness, compliance and weaknesses, Brown says.


3. Make a plan

 Once threats and vulnerabilities have been assessed, you need to have a well-documented plan in place regarding areas such as crisis communication and incident response, Schwartz says.

This plan should be as simple and clear as possible. “I can give you a telephone book full of rules and regulations and then an incident occurs and no one’s looking at that book,” Leskovar says. “If an incident occurs, (the team) is going to be under a tremendous amount of stress and they’re going to be relying on very basic information in steps that they can follow.”

Brown says generating a risk analysis from the data security has collected can give the function an opportunity to educate stakeholders on risk factors. “By including the vulnerability rankings of each threat into a single chart, a threat assessment can also provide a by-default prioritization list of threats,” he says.

A comprehensive security assessment is not only an opportunity to engage stakeholders, Brown says it’s also an opportunity to educate security officers in the organization. In another role, “I had an expectation that every officer of a certain rank and above should be able to clearly articulate the why behind their tasks,” he says. “Performance improved dramatically from a connection to this higher perspective, as did job satisfaction and employee retention.”

KEYWORDS: comprehensive security plan planning and preparation risk management threat assessment

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Sarah Ludwig Rausch is a Contributing Writer to Security magazine.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Security Leadership and Management
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Cybersecurity Education & Training
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

patient at healthcare reception desk

Almost Half of Healthcare Breaches Involved Microsoft 365

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • risk management freepik

    3 steps to promote a human-centric security awareness culture

    See More
  • Comprehensive Risk Assessment

    Tips for crafting a comprehensive risk assessment

    See More
  • Security officers now require a more comprehensive insider threat solution

    See More

Related Products

See More Products
  • A Leaders Guide Book Cover_Nicholson_29Sept2023.jpg

    A Leader’s Guide to Evaluating an Executive Protection Program

  • security book.jpg

    Security Investigations: A Professional’s Guide

  • Physical-Security-and-Safet.gif

    Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!