Professor Sele
Principal Consultant & Policy Advisor | SafeHaven Strategies

"Good advice changes something. Great advice changes the right thing."

Module 6

Security Needs Assessment

Professor Sele: A security needs assessment answers the most fundamental consulting question: what is the gap between where the client is now and where they need to be? Get this right and everything else follows. Get it wrong and you are solving the wrong problem brilliantly.

Section 1 — What Is a Security Needs Assessment?

A security needs assessment (SNA) identifies the gap between an organisation's current security capability and the level required to adequately protect its people, assets, and operations given the current and foreseeable threat environment.

It differs from a risk assessment (which focuses on threats and vulnerabilities) by focusing specifically on capability — what the organisation can and cannot do — and the investment required to close the gap.

Section 2 — The SNA Framework

An SNA examines capability across six dimensions: Leadership and governance — is there clear accountability and effective oversight of security? Policy and procedures — are there documented, current, and followed security policies and SOPs? Personnel — are security staff sufficiently trained, vetted, and supervised? Physical security — are the physical protection measures adequate for the threat level? Technology — are the technical systems (CCTV, alarms, communications) fit for purpose? Intelligence and information — does the organisation have access to relevant intelligence and act on it?

Each dimension is assessed on a maturity scale from 1 (ad hoc) to 5 (optimised).

Section 3 — Data Collection for an SNA

Effective SNA data collection uses multiple methods: document review (policies, training records, incident logs, audit reports); interviews (senior management, security managers, operational staff, and where possible clients or beneficiaries); observation (watching actual security operations, not just reviewing what is documented); and benchmarking (comparing the organisation's capability against recognised standards such as ASIS, ISO 31000, UNDSS).

Section 4 — From Needs to Recommendations

The SNA produces a gap analysis: for each capability dimension, the current maturity level and the required maturity level are mapped, and the gap is quantified. Recommendations are then developed to close each gap — prioritised by risk significance and feasibility.

Key Points
  • An SNA identifies the gap between current security capability and the level needed — not just the threats
  • Six capability dimensions: leadership/governance, policy/procedures, personnel, physical, technology, intelligence
  • Use a maturity scale (1–5) for consistent assessment across dimensions
  • Multi-method data collection: documents, interviews, observation, benchmarking
  • Recommendations close the capability gap — prioritised by risk significance and feasibility
Field Note · Professor Sele

"I conducted an SNA for an NGO operating in a challenging environment. Their physical security was excellent — good fencing, access control, CCTV. Their intelligence and information capability was rated 1 out of 5 — they had no formal mechanism for monitoring the security environment or receiving intelligence. When I asked how they monitored threats, the security manager said: 'We watch the news.' In a complex threat environment, watching the news is not an intelligence function. Their investment priority was completely wrong — excellent locks on a building they had no early warning system to protect."

Knowledge Check

A security needs assessment identifies: