"Risk you haven't assessed is risk you've accepted by default."
Threat and Vulnerability Assessment
Professor Sele: Knowing a threat exists is not enough — you need to know how capable the threat is, how much access they have, and how likely they are to act. This module builds the analytical framework for evaluating threats and the vulnerabilities they can exploit.
Section 1 — Threat Actor Analysis
For each identified threat, assess Capability (does the actor have the means, skills, and resources to execute an attack?), Intent (does the actor have a stated or inferred motivation to act against this target?), Access (can the actor reach the target — physically, electronically, or through social engineering?), and History (has this actor or similar actors acted against comparable targets before?).
This mirrors the CAP framework from Course 3, applied here at the organisational rather than individual protection level.
Section 2 — Vulnerability Assessment
A vulnerability is a gap or weakness that a threat actor can exploit. Categories include physical (gaps in perimeter, inadequate lighting, unlocked doors, unmonitored areas), procedural (inconsistent access control, gaps in verification, poor handover practices), personnel (untrained staff, insider risk indicators, insufficient background screening), and technical (CCTV blind spots, communication failures, outdated alarm systems).
Rate each vulnerability: Critical (can be easily exploited with high impact), Significant (exploitable with moderate impact), or Minor (limited exploitability or limited impact).
Section 3 — The Threat-Vulnerability Matrix
The threat-vulnerability matrix maps specific threats against specific vulnerabilities to identify the highest-priority combinations. A high-capability threat matched with a critical vulnerability produces a risk that requires immediate attention. A low-capability threat matched with a well-controlled vulnerability may be acceptable with monitoring only.
Section 4 — Insider Threat Assessment
The insider threat deserves specific attention. Insiders — employees, contractors, domestic staff — have legitimate access that bypasses many physical controls. Indicators include financial stress, grievance expression, unusual access patterns, and unusual interest in sensitive areas or information. The assessment must include controls specifically designed to detect and deter insider activity.
- •Assess each threat on Capability, Intent, Access, and History
- •Vulnerabilities are rated Critical, Significant, or Minor based on exploitability and impact
- •The threat-vulnerability matrix identifies the highest-priority risk combinations
- •Insider threats require specific assessment — they bypass physical controls by design
- •Vulnerability assessment requires physical inspection, not just document review
"The most dangerous vulnerability I ever found was a procedural one, not a physical one. A client's access control system was technically excellent — biometric readers, CCTV, two-person verification. But the procedure for granting temporary access to contractors had been simplified over time until it required only one signature from any manager. Within three months of identifying this, an insider used that gap to bring a criminal associate onto the site. The technology was perfect. The procedure had a hole large enough to drive a truck through."
A risk is rated "Critical" when: