"Risk you haven't assessed is risk you've accepted by default."
Post-Assessment Action Planning
Professor Sele: An ESRA that produces a list of risks without a clear action plan is an academic exercise — not a security tool. This module focuses on translating assessment findings into implemented improvements through structured, accountable action planning.
Section 1 — From Risk to Action
Each significant or critical risk in the risk register requires a corresponding action: What will be done (the specific control measure), Who is responsible for doing it (named individual — not a job title, not a team), By when (a realistic, specific deadline — not "ASAP"), How will we know it's done (a measurable completion criterion), and What is the residual risk once the action is complete.
Without these five elements, the action plan is incomplete and unenforceable.
Section 2 — Prioritisation of Actions
Not all risks can be addressed simultaneously. Prioritise: Critical risks first (highest risk scores and highest potential for immediate harm); Quick wins (high-impact actions that can be implemented at low cost and quickly — these build momentum and demonstrate value); Structural improvements (longer-term actions requiring investment or operational change); and Monitoring actions (for lower-priority risks that require periodic review rather than immediate change).
Section 3 — Accountability Mechanisms
The action plan must have an accountability mechanism built in: a named action owner for each item, a progress review date — not just a completion deadline, an escalation path if an action is not completed on time, and a sign-off process when an action is completed and the risk is re-assessed.
The SOC or client security manager is responsible for driving the action plan to completion. The assessor's role ends at delivery — but SafeHaven can offer follow-up support as an additional service.
Section 4 — Tracking and Reporting
The action plan should be maintained as a live document — updated as actions are completed and new information emerges. A monthly progress report against the action plan should be provided to client senior management, showing actions completed this month, actions overdue and the reason for delay, new risks identified since the assessment, and updated risk scores where controls have been implemented.
- •Each action must have: what, who, when, success criterion, and residual risk
- •Prioritise: Critical risks first, then quick wins, then structural improvements
- •Build in accountability: named owners, progress reviews, escalation paths, sign-off processes
- •The action plan is a live document — update it as actions are completed
- •Monthly progress reporting to senior management drives accountability
"Six months after delivering an ESRA to a logistics client, I visited for an unrelated meeting and asked to see the action plan. Of 22 recommendations, 3 had been completed. The rest were assigned to people who had since changed roles, with deadlines that had passed months earlier. Nobody owned it. I now build a mandatory 30-day and 90-day review into every ESRA contract. The assessment is not complete when the report is delivered. It is complete when the actions are implemented."
Post-assessment action planning should assign each recommended control measure: