s Focus on the Where AND the What | CAP Index

Rethinking Security Prioritization: Focus on the “Where” in addition to the “What”

Top 3 Questions to Ask:

 

  • WHAT are we protecting?
  • What are we protecting it FROM?
  • HOW should we protect it?

Within the industry and at events like the recent Security Industry Association (SIA) conference, security prioritization comes up again and again. The conversation typically starts with how to prioritize WHAT to install – e.g. access control, CCTV, and intrusion detection, and then turns to WHERE to install it.

Security prioritization has become a meaty topic due to some emerging views on how we should be doing it.  There is a growing feeling that perhaps we’ve been oversimplifying our decisions about what countermeasures to install and where to install them.  This may be getting more attention recently due to growing support of Enterprise Security Risk Management (ESRM) and the ESRM Cycle, which begins with Identifying and Prioritizing Assets and Identifying and Prioritizing Risks before considering how to mitigate those risks.

 

A Smarter Framework for Security Prioritization

Many security leaders including Tim McCreight, Rachelle Loyear, and Paul Mercer describe the security risk management in these terms (paraphrased):

  1. What are we protecting? This first step is where we identify and prioritize our assets.  What assets, facilities, or locations are most critical to our organization’s ability to execute its mission?  For many, that is the primary basis for prioritization of assets.
  2. What are we protecting it from? In this step, we identify and prioritize risks – often through risk assessment and analysis.  What threats are our assets vulnerable to, and how impactful could those threats be to our organization’s ability to execute its mission?  By overlaying prioritized assets with prioritized risks, we’re able to clearly answer this.
  3. How should we protect it? This is the step where we consider which countermeasures should be implemented.  And we’re not actually prioritizing  We’re prioritizing assets and risks and then tailoring our choice of countermeasures based on their ability to effectively mitigate those risks.

Turning Data into Actionable Insight

CAP Index data and tools are often used as a basis for step 2. CRIMECAST scores quantify crime risk of a given address and dissect those scores into Crimes Against Persons, Property, and Society.  CAP RISC scores incorporate additional risk indicators such as incident, threat intel, or alarm data to quantify broader security risk both inside and outside of site perimeters.  This data helps define the nature of risks more specifically, enabling selection of countermeasures that are most effective against those particular risks.

CAP Index consultants are often used to navigate the processes in steps 1 & 3.  Our consultants are well versed in aligning organizations with ESRM and guiding them through the processes of prioritizing assets, overlaying risks, and defining a mitigation strategy.

Putting It All Together

By focusing on what truly matters—your most critical assets and the risks that threaten them—you can make smarter, more effective security decisions. Discover how CAP Index can help you apply ESRM principles and build a data-driven prioritization strategy that delivers real results.

 

Recent Posts

Crimes Against Society: A More Complete View of Branch Risk
Crimes Against Society: A More Complete View of Branch Risk
Discover how Crimes Against Society metrics help banks evaluate branch risk, track emerging threats, and identify ...
A Conversation with McDonald’s Director of Security Rob Holm
A Conversation with McDonald’s Director of Security Rob Holm
Quick serve restaurant security is a challenge...especially when you're doing it for McDonald's who serves more ...
Stop Guessing Which Branches Need Attention First
Stop Guessing Which Branches Need Attention First
Banks can use crime risk insights to implement better security protocols adapted to each branch's specific risk profile.
No results found.