"Risk you haven't assessed is risk you've accepted by default."
ESRA Reporting Standards
Professor Sele: The quality of your assessment is only as visible as the quality of your report. A brilliant assessment that produces a confusing, poorly structured report is a wasted assessment. This module sets the standard for ESRA reports that clients read, understand, and act on.
Section 1 — Report Structure
A professional ESRA report follows this structure: Cover page (client name, site, assessment date, assessor name, classification level); Executive summary (key findings and top 5 priority recommendations — maximum 2 pages); Scope and methodology (what was assessed, how, when, and by whom); Site and context overview (brief description of the site, its operations, and the security environment); Threat and hazard assessment (findings on each identified threat and hazard category); Vulnerability assessment (physical, procedural, personnel, technical); Risk register (full register with scores, controls, owners, and review dates); Recommendations (detailed, prioritised action plan); and Appendices (photographs, site plans, interview summaries, reference data).
Section 2 — Writing Principles
Factual: every finding is supported by specific evidence — not impressions. Objective: no blame language, no personal opinions about individuals. Clear: written so that a non-security professional can understand the findings and recommendations. Actionable: recommendations are specific — not "improve access control" but "install a biometric reader at the rear entrance by [date]." Prioritised: recommendations are ranked by risk score so the client knows where to start.
Section 3 — Classification and Handling
ESRA reports must be classified at a minimum of RESTRICTED. The report reveals every vulnerability in the client's security — in the wrong hands, it is an attack planning document.
Distribution must be limited to the named client representative, SafeHaven Operations Command, and any named third parties explicitly approved by the client. Reports must be transmitted securely — not by standard email without encryption.
Section 4 — The Verbal Briefing
The written report is accompanied by a verbal briefing to the client's senior management. This briefing walks through the top findings and priority recommendations, allows the client to ask questions, establishes shared understanding of the risk picture, and agrees initial actions and accountability.
The verbal briefing is not a substitute for the written report — it is a complement to it.
- •Report structure: cover → executive summary → scope → context → threats → vulnerabilities → risk register → recommendations → appendices
- •Every finding is evidence-based and objective — no blame language, no impressions
- •Recommendations must be specific and actionable — not general advice
- •ESRA reports are classified RESTRICTED minimum — they reveal every vulnerability
- •Accompany the written report with a verbal briefing to confirm shared understanding and agree actions
"I once received a competitor's ESRA report that a mutual client had shared for a second opinion. It was 47 pages long. The executive summary was 8 pages. The risk register had 63 items, none prioritised. The recommendations said things like 'enhance perimeter security' and 'improve guard training.' The client told me they had read the first 10 pages and then put it in a drawer. That report cost them significant money and produced zero action. Write for the decision-maker. Short executive summary. Clear priority ranking. Specific actions. If the client doesn't act on your report, the assessment failed — regardless of how thorough it was."
Which of the following is a key output of a completed ESRA?