Rethinking Security Prioritization: Focus on the “Where” in addition to the “What”
Top 3 Questions to Ask:
-
WHAT are we protecting?
-
What are we protecting it FROM?
-
HOW should we protect it?
Within the industry and at events like the recent Security Industry Association (SIA) conference, security prioritization comes up again and again. The conversation typically starts with how to prioritize WHAT to install – e.g. access control, CCTV, and intrusion detection, and then turns to WHERE to install it.
Security prioritization has become a meaty topic due to some emerging views on how we should be doing it. There is a growing feeling that perhaps we’ve been oversimplifying our decisions about what countermeasures to install and where to install them. This may be getting more attention recently due to growing support of Enterprise Security Risk Management (ESRM) and the ESRM Cycle, which begins with Identifying and Prioritizing Assets and Identifying and Prioritizing Risks before considering how to mitigate those risks.
A Smarter Framework for Security Prioritization
Many security leaders including Tim McCreight, Rachelle Loyear, and Paul Mercer describe the security risk management in these terms (paraphrased):
- What are we protecting? This first step is where we identify and prioritize our assets. What assets, facilities, or locations are most critical to our organization’s ability to execute its mission? For many, that is the primary basis for prioritization of assets.
- What are we protecting it from? In this step, we identify and prioritize risks – often through risk assessment and analysis. What threats are our assets vulnerable to, and how impactful could those threats be to our organization’s ability to execute its mission? By overlaying prioritized assets with prioritized risks, we’re able to clearly answer this.
- How should we protect it? This is the step where we consider which countermeasures should be implemented. And we’re not actually prioritizing We’re prioritizing assets and risks and then tailoring our choice of countermeasures based on their ability to effectively mitigate those risks.
Turning Data into Actionable Insight
CAP Index data and tools are often used as a basis for step 2. CRIMECAST scores quantify crime risk of a given address and dissect those scores into Crimes Against Persons, Property, and Society. CAP RISC scores incorporate additional risk indicators such as incident, threat intel, or alarm data to quantify broader security risk both inside and outside of site perimeters. This data helps define the nature of risks more specifically, enabling selection of countermeasures that are most effective against those particular risks.
CAP Index consultants are often used to navigate the processes in steps 1 & 3. Our consultants are well versed in aligning organizations with ESRM and guiding them through the processes of prioritizing assets, overlaying risks, and defining a mitigation strategy.
Putting It All Together
By focusing on what truly matters—your most critical assets and the risks that threaten them—you can make smarter, more effective security decisions. Discover how CAP Index can help you apply ESRM principles and build a data-driven prioritization strategy that delivers real results.
Recent Posts

Crimes Against Society: A More Complete View of Branch Risk

A Conversation with McDonald’s Director of Security Rob Holm
