Analytical Framework

Our ISO 31000-Aligned Security Risk Analysis Methodology

Good security decisions depend on a clear analytical framework — one that examines risk not as a static checklist, but as a dynamic relationship between the threats an environment faces, the weaknesses those threats can exploit, and the controls available to reduce exposure.

This framework underpins every engagement Keown & Associates conducts, whether that is a structured physical security risk assessment or an independent advisory relationship with executive leadership.

Methodology abstraction

Risk as a Relationship

Risk is not a property of a place or an organisation. It arises from the interaction of four connected elements: a credible threat, a vulnerability the threat can exploit, the effectiveness of the controls intended to reduce that exposure, and the consequence that would follow if an event occurred.

This means that risk cannot be assessed in isolation. An organisation may face significant threats but have strong controls that prevent exploitation — in which case actual risk may be limited. Alternatively, an environment may appear well-resourced with security infrastructure, yet contain significant vulnerabilities that existing controls do not address.

The framework is designed to examine these relationships precisely — rather than inferring risk from the presence or absence of security measures alone.

The Four Components

Keown & Associates assesses security risk through four connected components:

T

Threat

The credible source of harm, including intent, capability, opportunity and proximity.

V

Vulnerability

The exposure or weakness that could allow the threat to succeed, including weaknesses in people, process, infrastructure, technology or operating practice.

CE

Control Effectiveness

The practical effectiveness of existing controls in deterring, detecting, delaying, responding to or recovering from the threat scenario.

C

Consequence

The likely impact if the event occurs, including harm to people, operational disruption, financial loss, legal exposure and reputational damage.

Control effectiveness is assessed separately because the presence of a control does not mean the control will work. Where controls are weak, poorly integrated or unreliable, residual vulnerability remains high.

Why Control Effectiveness Matters

Many organisations evaluate their security environment by reference to what is installed — cameras, fencing, guarding contracts, access systems. These are inputs to security, not evidence of it.

The analytical framework applied by Keown & Associates evaluates whether controls produce the outcomes they are designed for: whether deterrence is meaningful, whether detection is reliable, whether delay is sufficient to support effective response, and whether response capability is realistic in practice.

This distinction — between the presence of security measures and their actual effectiveness — is often where the most significant gaps are found. It is also where the most consequential improvements can be made.

ISO 31000 Alignment

The analytical approach is aligned to ISO 31000, the international standard for risk management. ISO 31000 establishes that risk should be understood in context, that risk management should be structured, iterative, and integrated with decision-making, and that it should be based on the best available information rather than on assumption.

In practice, this means that every engagement begins with a clear definition of context and objectives — what matters to this organisation, in this environment, at this point in time. Analysis is anchored to that context, not applied generically across all clients and sectors.

ISO 31000 alignment also means that risk ratings and recommendations are structured to be defensible — capable of withstanding scrutiny from boards, audit committees, regulators, and insurers.

Structured Analysis, Not Audit

The framework does not produce compliance checklists or audit scores. It produces a structured understanding of where risk resides, how material it is, and what actions would reduce it most effectively — in the shortest operational path and with the clearest accountability.

This enables decision-makers to move from the imprecise question — "Are we secure?" — to the precise questions that lead to rational resource allocation: which assets are most critical, which threats are most credible, where do our most significant vulnerabilities exist, and what level of residual risk is acceptable?

Where This Framework Is Applied

This analytical framework is the foundation of all Keown & Associates engagement types, each addressing a different decision requirement:

  • Physical security risk assessmentswhere the framework is applied to a specific site, estate or portfolio to produce a structured risk register and prioritised recommendations.

  • Independent security risk assessmentwhere independence from vendor and provider relationships is the primary requirement for unbiased, defensible findings.

  • Security control effectiveness reviewswhere the focus is on whether existing controls — guarding, access, surveillance, procedures — are performing effectively against credible threats.

  • Independent security advisorywhere the framework informs strategic counsel, governance structures and board-level decision support for executive leadership and risk owners.

  • Security Capability Developmentwhere the framework informs structured capability cycles so that personnel, procedures and supervision sustain control effectiveness in practice.

Desmond Keown, CPP — Practice Principal, Keown & Associates
Practice Principal

A practitioner-led methodology

The Keown & Associates methodology reflects the practical security risk work of Desmond Keown, CPP, combining structured risk analysis, control-effectiveness assessment and governance-ready reporting across complex operating environments.

Discuss Your Security Risk Context

Engagements are structured to the specific environment and objectives of each client.

Request a Confidential Discussion