Insights & Analysis
Analytical, structured perspectives on contemporary security risk management. We publish authoritative guidance to help executives navigate complex threat landscapes.
Understanding Threat, Vulnerability and Risk
A common weakness in organisational security strategy is the imprecise use of core terminology. When the terms threat, vulnerability, and risk are used interchangeably, security decisions become unclear and resources may be misallocated.
Read Analysis →Why Perfect Security Is Impossible
Perfect security is a theoretical impossibility. Real-world advisory requires balancing operational friction, financial expenditure, and residual risk.
Read Analysis →When Organisations Should Conduct a Security Risk Assessment
Identifying the precise inflection points—mergers, expansions, or threat escalations—when assumptions must be replaced with empirical data.
Read Analysis →Why Many Residential Estate Security Strategies Fail
Examining the over-reliance on visible deterrents and technology at the expense of invisible architecture, operational protocols, and environmental design.
Read Analysis →Why Most Security Programmes Fail: The Missing Step of Asset Criticality
Security programmes often begin by evaluating threats or installing controls, rather than first determining what the organisation must protect and why it matters.
Read Analysis →How Structured Security Risk Analysis Works
Security programmes often evolve organically. Structured security risk analysis replaces assumptions about security effectiveness with disciplined evaluation of threats, vulnerabilities, and potential consequences.
Read Analysis →What Is a Physical Security Risk Assessment (ISO 31000 Explained)
A clear, ISO 31000-aligned explanation of physical security risk assessments, covering threat, vulnerability, control effectiveness, and consequence to support structured security decision-making.
Read Analysis →Why Installed Security Controls Do Not Always Reduce Risk
Installed guards, cameras, alarms, fences and access controls do not automatically reduce risk. Understand why control effectiveness matters in physical security risk assessment.
Read Analysis →Control Effectiveness in Practice: Three Worked Scenarios
Three worked scenarios — a corporate head office, a residential estate and a logistics gate — showing how a control-effectiveness test exposes weaknesses that a compliance check would miss.
Read Analysis →Security Risk Assessment vs Security Audit: Why the Difference Matters
Understand the difference between a security risk assessment and a security audit, and why organisations need structured risk analysis before making security decisions.
Read Analysis →Why Security Recommendations Must Be Independent of Product Sales
Security recommendations should be based on assessed risk, not on products, guarding contracts or technology sales. Learn why independent security advice matters.
Read Analysis →Residential Estate Security: Why Layered Controls Often Fail in Practice
Community estates are widely marketed as layered, secure environments. In practice, trustees often have little independent assurance that the layers actually work. A practical look at where they break and what trustees should be testing.
Read Analysis →Executive Movement Risk: Assessing Travel, Routine and Public Exposure
Executive movement risk is not addressed by adding a vehicle and a driver. It is addressed by understanding how routine, public exposure, travel patterns and information leakage combine to create assessable risk — and which controls actually reduce it.
Read Analysis →Why Poor Security Risk Decisions Persist — And How to Avoid Them
Poor security risk decisions are seldom the result of bad people or careless analysis. They are usually the result of structural conditions — incentives, information asymmetry, decision pressure and weak governance — that make the wrong decision the easier one. A practical look at the patterns, and the disciplines that interrupt them.
Read Analysis →Related Services
These articles discuss the principles underlying Keown & Associates' advisory practice. The following services are available to organisations seeking structured, independent security risk analysis.
Security Risk Assessments
Structured, independent analysis of threats, vulnerabilities and control effectiveness.
Core ServiceSecurity Governance Advisory
Independent advisory for boards and executives navigating security governance and programme design.
Our ApproachAssessment Methodology
The structured, ISO 31000-aligned process used in every security risk assessment engagement.
Core ServiceCapability Development
Programme design and assurance cycles that build auditable, sustainable security competence.
Core ServiceSite-Specific Security Training
Procedure-based training for guards and supervisors, designed for your specific operating environment.
EngageSchedule a Consultation
Request a confidential introductory consultation to discuss your security risk priorities.
RelatedIndependent Security Risk Assessment
Why vendor-neutral independence matters in security risk assessment and what it examines differently.
RelatedEstate Security Risk Assessment
Dedicated assessment service for residential estates, golf estates, HOAs and mixed-use precincts.
RelatedControl Effectiveness Review
Independent assessment of whether guarding, access control, patrols, procedures and technology are reducing risk as intended.