Security Guides

How to Carry Out a Security Risk Assessment for Your Business (Step-by-Step Guide)

Buying security without assessing your risk is like buying insurance without knowing what you own. A security risk assessment tells you what you are protecting, what could go wrong, how likely it is, and which measures give you the most protection for your budget. This guide walks through the process step by step, with a risk matrix and a checklist, and is written by Citi Guard Services, whose senior officers carry out site surveys for clients across London every week.

Key takeaways

  • A security risk assessment identifies assets, threats and vulnerabilities, scores the risks, and sets out proportionate controls.
  • Walk the site inside and out, at different times of day, and talk to the people who work there.
  • Score each risk on likelihood and impact, then treat the highest scores first.
  • Review at least annually and after any incident or change.

What is a security risk assessment?

It is a structured review of how your premises, people, information and operations could be harmed by crime, disorder or malicious action, and what you should do about it. The output is a document that records the risks, scores them, and lists the controls you have decided to put in place. It sits alongside your fire risk assessment and health and safety assessment, and for many venues it now supports duties under the Terrorism (Protection of Premises) Act 2025, known as Martyn’s Law.

How to carry out a security risk assessment

Step 1: Define the scope and gather information

Decide what you are assessing: a single building, a site with grounds and car parks, or multiple locations. Gather floor plans, opening hours, staff numbers, incident logs, crime data for the area (police.uk publishes it), insurance requirements and any previous assessments.

Step 2: Identify what you are protecting

List your assets: people (staff, visitors, contractors), property (buildings, plant, stock, vehicles), information (data, cash, keys) and reputation. Note which are most critical to the business.

Step 3: Identify threats

Consider burglary and theft, robbery, vandalism, arson, trespass, violence and aggression towards staff, protest or disorder, insider theft, vehicle crime and, for public-facing venues, terrorism. Use local crime data and your own incident history to decide which are realistic.

Step 4: Walk the site and find vulnerabilities

Survey the premises inside and out, in daylight and after dark. Look at the perimeter, gates and fencing, lighting, doors and windows, locks and access control, CCTV coverage and blind spots, alarm systems, reception and visitor management, key control, cash handling, deliveries and loading bays, car parks and the surrounding streets. Talk to staff: they know where the back door is propped open.

Step 5: Score the risks

For each threat and vulnerability, score likelihood and impact from 1 to 5 and multiply. Anything scoring 15 or more needs urgent action; 8 to 12 needs a plan; below 8 can be monitored.

Impact 1 (minor) Impact 3 (moderate) Impact 5 (severe)
Likelihood 1 (rare) 1 low 3 low 5 medium
Likelihood 3 (possible) 3 low 9 medium 15 high
Likelihood 5 (likely) 5 medium 15 high 25 critical

Step 6: Choose proportionate controls

Match controls to the highest risks first, using layers: deter (signage, lighting, visible patrols), detect (alarms, monitored CCTV), delay (locks, screens, access control) and respond (key holding, on-site officers, police liaison). Cost the options and pick the mix that reduces risk most per pound. Our manned guarding, mobile patrols, CCTV monitoring and key holding services are usually combined rather than chosen in isolation.

Step 7: Record, assign and act

Write it down: the risk, the score, the control, who owns it and the deadline. Brief staff on what changes. Keep the document with your other statutory assessments.

Step 8: Review and test

Review at least annually and after every incident or change. Test controls: walk the site at night, check alarm response times, run a visitor who should be challenged. Assessments that are never tested drift out of date.

Security risk assessment checklist

  • Scope, plans, opening hours and staff numbers gathered
  • Local crime data and internal incident log reviewed
  • Assets listed and critical ones identified
  • Realistic threats listed
  • Site walked by day and by night, inside and out
  • Perimeter, lighting, doors, locks, access control, CCTV, alarms, reception, keys, cash, deliveries and car parks assessed
  • Staff interviewed
  • Risks scored with the matrix and prioritised
  • Controls chosen across deter, detect, delay and respond
  • Owners and deadlines assigned
  • Review date set and controls tested

Get a professional assessment free of charge

Our senior officers carry out site surveys and risk assessments as part of every proposal, with no obligation. You get a written summary of vulnerabilities and recommended controls, whether or not you go ahead with us. Book a free site survey.

Know your risks before you spend

Book a free security survey with Citi Guard and receive a clear, prioritised plan for your premises.

Book a free survey

Frequently asked questions

Is a security risk assessment a legal requirement?

There is no single law requiring one, but the Health and Safety at Work Act, the Management of Health and Safety at Work Regulations and, for many venues, the Terrorism (Protection of Premises) Act 2025 (Martyn's Law) require you to assess and manage risks to people. Insurers and clients increasingly expect a documented security assessment.

How often should a security risk assessment be reviewed?

Review it at least once a year, and immediately after any incident, change of use, building work, significant staff change or new threat information. Many businesses do a light quarterly review and a full annual one.

Who should carry out the assessment?

A competent person with knowledge of physical security: an experienced security manager or an external specialist. Independent assessors often spot risks that familiar eyes miss, and a good security company will carry one out free of charge as part of a proposal.

What is the difference between a threat, a vulnerability and a risk?

A threat is something that could cause harm, such as burglary. A vulnerability is a weakness that lets the threat succeed, such as an unmonitored rear door. Risk is the combination of how likely the threat is and how severe the impact would be.

Ready to Secure Your Business?

Get a free, no-obligation security assessment from our expert team. Available 24/7 across London and the UK.