s 3 Questions That Change the Way You Think About Security Risk (ESRM) | CAP Index

In this episode of Conversations with CAP, Walter Palmer and Rachelle Loyear explore how Enterprise Security Risk Management (ESRM) helps organizations put risk at the center of security planning. By identifying what needs protection, understanding specific threats, and using objective data to guide mitigation, security leaders can build more focused, defensible strategies that align with broader business priorities.

 

Building a Smarter Security Program Starts with Risk

When organizations look to improve security, conversations often turn quickly to cameras, access control, guards, and other solutions. A stronger starting point is understanding the risks the organization actually needs to address.

In a recent episode of Conversations with CAP, CAP Index Senior Advisor Walter Palmer spoke with security and resilience professional Rachelle Loyear, VP of Integrated Security Solutions at Allied Universal, about Enterprise Security Risk Management, or ESRM, and how organizations can use a risk-led approach to make more informed security decisions.

With roughly 20 years of experience in security and resilience, Loyear has helped advance conversations around ESRM through her work, writing, teaching, and involvement with ASIS International. Her central message for organizations is straightforward: understand the risk before deciding how to mitigate it.

Three Questions for Risk-Based Security

Loyear simplifies ESRM into three practical questions:

1. What do you need to protect?
2. What do you need to protect it from?
3. How do you most effectively and efficiently protect it?

The sequence matters. Understanding assets and their specific exposures allows organizations to select security measures based on actual needs.

This can also help organizations avoid applying the same controls everywhere. A location primarily concerned with trespassing or loitering, for example, may require a very different approach from a site with significant risks to employees or customers.

Data Becomes More Important at Scale

Understanding the environment surrounding one familiar location may be relatively straightforward. The challenge grows significantly for security leaders responsible for locations across a state, the country, or the world.

During the conversation, Palmer uses an organization with 2,000 locations as an example. Conducting individual risk assessments remains valuable, but leaders operating at that scale also need a consistent way to understand and compare risk across their portfolio.

Loyear explains that objective crime risk data can help answer the second ESRM question: What do you need to protect your assets from?

With a clearer understanding of exposure, organizations can focus resources on the threats most relevant to each location.

Make Risk Understandable to the Business

Loyear also emphasizes the importance of communication.

Security professionals may be comfortable with detailed models, charts, maps, and terminology. Business stakeholders need the findings translated into language that helps them make decisions.

Clear risk communication can strengthen budget discussions as well. Rather than presenting a security expenditure without context, leaders can explain the asset being protected, the identified exposure, and how the proposed investment addresses that risk.

This also gives stakeholders a meaningful role in security decisions.

Security teams provide expertise and communicate potential consequences, while the appropriate business leaders participate in decisions about how much risk the organization is willing to accept. When everyone understands the exposure beforehand, the organization is better prepared to respond if that risk is eventually realized.

Five Takeaways for Security Leaders

Organizations looking to strengthen their security programs can apply five lessons from the conversation:

  • Start with risk. Understand your assets and exposures before selecting security measures.
  • Use objective data. Consistent risk information becomes increasingly valuable as organizations expand across multiple locations and markets.
  • Match controls to threats. Security investments should reflect the specific risks facing each asset or location.
  • Engage business stakeholders. Give risk owners the information they need to understand exposure and participate in decisions.
  • Keep security understandable. Translate complex analysis into clear business language that supports action.
Better Questions Lead to Better Security Decisions

A risk-led security program gives organizations a framework for making more deliberate decisions about where to focus resources.

For leaders managing large portfolios, objective data can bring greater consistency to that process. For executives evaluating security investments, understanding the risk behind a recommendation creates a stronger basis for decision-making.

The process can begin with three questions: What do we need to protect? What do we need to protect it from? And what is the most effective and efficient way to protect it?

Answering those questions can help organizations build security programs that are more focused, defensible, and aligned with the needs of the business.

Summary

Enterprise Security Risk Management (ESRM) helps organizations make smarter security decisions by focusing on three questions: What do you need to protect? What do you need to protect it from? And how can you protect it effectively and efficiently? By combining objective risk data with stakeholder input and clearly defined priorities, organizations can focus resources on the threats that matter most and build a more informed, business-aligned security program.

To hear Rachelle Loyear’s full perspective and career insights, listen to the complete episode of Conversations with CAP.

Don’t miss this episode of Conversations with CAP!

 

Walter Palmer sits down with Rob Holm, the head of Security and Asset Protection for McDonald’s USA. Rob delves into what it really takes to protect the world’s largest quick-service restaurant brand.

It’s worth a listen…check it out here! 

Recent Posts

Beyond the Map: How Place Shapes Health in Arkansas
Beyond the Map: How Place Shapes Health in Arkansas
Explore with Dr. Michael Niño how the Arkansas Health Survey and AR-COMPASS are using geospatial data to uncover ...
Beyond the Headlines: Q2 2026 Crime Trends
Beyond the Headlines: Q2 2026 Crime Trends
Explore the latest Q2 2026 crime trends and discover what more than 5 million crime records reveal about ...
Crimes Against Society: A More Complete View of Branch Risk
Crimes Against Society: A More Complete View of Branch Risk
Discover how Crimes Against Society metrics help banks evaluate branch risk, track emerging threats, and identify ...
No results found.