This is a concept that is often complex in its application, but should be simple in its understanding. The first stage is to understand the operating environment; this involves an appreciation of the background scenario (basic intelligence), information in relation to ongoing activity (current intelligence) and a prediction of future events (applied intelligence). All of this is routine intelligence work and will lead us to a position where we comprehend, in some detail, our suppliers, customers, competitors and all other factors that impact on our operations. As I said, easier said than done, but this represents the baseline product for all further work in quantifying your business risk.
The work conducted above will then lead into a more detailed study of the threats present in your operating environment. There may, for example, be a possibility of a violent change of government or there may be widespread corruption or perhaps the threat comes from strong competitors operating in the same sector; all of these are threats that need to be identified and quantified in the first instance. As with all of these stages, they represent ‘living’ assessments that are likely to change on a constant basis.
We will now identify within your organisation those aspects that are essential to you achieving your mission, whilst taking into consideration those issues that are critical to your competitor’s success. What is it that we need to protect and to what extent? A regular and uninterrupted supply of fuel may, for example, be vital to your operation. A judgement now needs to be made on the value of these key aspects to your mission and the realistic measures that can be put in place to protect them – this gives an indication as to your business’s vulnerability.
An assessment of your business risk can then be ascertained through merging the threats present in your operational environment against the vulnerabilities to your successful mission. Risks will usually be categorised as:
Business – Threats to profitability and continuity of operations
Physical – Threats to buildings, staff, stock, money and equipment
Resources – Threats to supply and distribution lines
Reputation – Threats to business reputation with public, authorities, media, business community and shareholders
A risk mitigation strategy will be developed to achieve one of the following actions:
Avoid the risk
Reduce the impact and likelihood of the risk
Spread the risk
Transfer the risk
Accept the risk
The acceptance of the risk mitigation strategy is a board-level decision and will then pave the way for a corporate security plan to be adopted as policy for business operations.
Do you want to understand better the business dynamics in your sector? Are you looking for options to drive forward your business in a challenging environment? To find out more about what QRO Global could do to assist your business or to learn more about the types of projects that we have worked on in the past, see our Services Page or email us today – info@qro-global.co.uk

Leave A Comment