A pilot-tested multi-site security risk assessment method gave a multinational industrial technology company a consistent view of security across its Australian sites and a prioritised plan for improvement.
THE CHALLENGE
A multinational industrial technology company operates a head office, distribution centres, a manufacturing site and a multi-function facility across Australia. Following security incidents, the company needed to test whether its security measures were adequate and whether they met its global security directives. It wanted an independent assessment of the protective security arrangements at each site, the vulnerabilities that remained, and practical, prioritised recommendations that would strengthen security at both site and national level. Because the sites differed in function and scale, the method also had to be consistent enough for leadership to compare results across the business. The results also needed to support executive decision-making and investment planning.
OUR APPROACH
Agilient designed a risk-based methodology drawing on AS ISO 31000:2018 and the Protective Security Policy Framework (PSPF) as a reference framework. The method combined site visits, stakeholder consultation, review of physical and electronic security systems, and assessment of behavioural and procedural controls. Agilient also developed a custom threat and risk assessment workbook for the engagement, giving the team a common structure for rating threats and risks at every site. Before rolling the method out, Agilient ran a proof of concept at one distribution site to pilot the approach, refine the workbook and agree the structure of the consolidated national report with the client. Once the client approved the pilot, the team completed assessments at the remaining sites. Findings were captured in detailed risk registers site by site and then brought together, so that local issues and patterns across the national operation were both visible to management.
THE OUTCOME
The company gained a standardised yet flexible framework for evaluating and improving security controls across its Australian operations.
- A consolidated national risk assessment report supported by site-specific findings
- Detailed risk registers and prioritised security enhancements for each site
- Practical recommendations to support executive decision-making, investment planning and national security governance
Related services: security risk assessment consultants, protective security and PSPF consulting, physical security consultant. To discuss a similar project, contact Agilient.