Independent Advisory

Independent Security Risk Assessment in South Africa

A security risk assessment is only as useful as the independence of the party conducting it. When assessors have a commercial interest in the outcome — in the controls they recommend, the products they specify, or the services they provide — the analysis cannot be fully objective.

Keown & Associates conducts independent, vendor-neutral security risk assessments in South Africa with no commercial relationships with guarding companies, technology vendors or system integrators.

Why Independence Matters in Security Risk Assessment

Security risk assessments are frequently conducted by parties with a direct commercial relationship to the outcome — the guarding company reviewing its own deployment, the technology integrator recommending upgrades to systems it will supply, or the consulting firm with a preferred vendor relationship. In each case, the analysis is constrained by interests that do not align fully with the client's.

The most common consequences of this bias include: over-specification of technology, under-assessment of human and procedural factors, and recommendations that address symptoms visible to the assessor's commercial portfolio rather than the underlying risk profile of the environment.

An independent security risk assessment introduces a different discipline. The assessor's interest is in providing accurate, defensible findings — not in influencing a purchasing decision, retaining a service contract, or protecting an existing deployment from scrutiny.

Vendor-Neutral Security Risk Assessment

Vendor-neutral means that the assessment methodology, findings and recommendations are produced without reference to any product catalogue, guarding contract or technology portfolio. Every control assessed is evaluated on the basis of what risk it actually addresses and how effectively it performs in practice — not on the basis of what the assessor is in a position to supply.

In South Africa, where guard-force quality, response time reliability, and the practical performance of installed technology frequently diverge from contracted or documented standards, this distinction matters considerably. An assessment that evaluates controls against credible operational scenarios — rather than against design specifications or provider reporting — produces a materially different and more useful risk picture.

No product affiliations

Recommendations are not shaped by preferred vendors, technology partnerships or supply-chain relationships. Controls are assessed on effectiveness, not on what is available to supply.

No guarding company relationships

Guard-force performance, patrol discipline, supervision standards and access control procedures are evaluated objectively — not on behalf of the provider or the client relationship.

No system integration interests

Technology infrastructure is assessed against the risk it is intended to mitigate — not against the opportunity it represents for upgrade or extension.

What an Independent Assessment Examines

The assessment covers the full risk environment — not just the controls that are most visible or most commercially interesting to evaluate.

  • Threat context — credible threat actors and scenarios specific to the sector, location, and operating profile of the environment
  • Vulnerability — where design, process or human behaviour creates exposure that a credible threat actor could exploit
  • Control effectiveness — whether physical, procedural and technological controls perform as required in practice, under realistic operational conditions
  • Likelihood and consequence — a structured view of risk level based on credible scenario analysis, not generic matrices
  • Practical treatment priorities — sequenced, operationally realistic recommendations that address the highest-risk exposures first

The assessment methodology applied to every engagement is aligned to ISO 31000 and structured to produce defensible findings that can withstand board, insurer and governance scrutiny.

When to Request an Independent Security Risk Assessment

An independent assessment is particularly valuable where existing advice, internal assessments or provider-led reviews may not be fully objective:

  • When a security provider or integrator is conducting the review of their own work
  • When existing security advice has consistently pointed towards the same supplier's products or services
  • When controls have been installed or upgraded without a documented reduction in risk
  • When a board, executive, insurer or regulator requires independent verification of the security risk position
  • Before appointing, renewing or replacing a security service provider
  • When there is a material gap between security spend and confidence in security outcomes
  • When a significant security incident has occurred and an independent view of root causes is needed

Assessment Outputs and Decision Support

An independent security risk assessment from Keown & Associates delivers structured, actionable outputs designed to support governance and operational decision-making:

  • A structured risk register aligned to ISO 31000, with threat, vulnerability, control effectiveness and consequence documented per risk
  • An objective evaluation of existing controls — what works, what does not, and where the gap between designed and operational performance is material
  • Prioritised treatment recommendations, sequenced by risk reduction impact and operational feasibility
  • An executive-level summary suitable for board, audit committee or insurer presentation
  • Findings structured to support security governance, programme design, and procurement decisions

Where assessment findings identify governance-level decisions — programme restructuring, service provider procurement, or significant security investment — the advisory service provides independent ongoing counsel to support those decisions.

Request an Independent Assessment

Discuss your security risk context with a senior adviser. Keown & Associates will confirm whether an independent assessment is the appropriate next step and outline scope and engagement options.