Using ESRM Principles to Revamp Your Risk Management Plan

The Trackforce Team

Trackforce

May 21, 2021 · 8 min read

Chess board representing strategic security risk management

Using ESRM Principles to Revamp Your Risk Management Plan

Enterprise Security Risk Management, or ESRM, has been a trusted methodology among corporate security professionals for years. ESRM approaches risk by aligning security practices with a company’s overall mission and goals. As threats grow more complex and leadership expects security to show its value, now is an opportune time to revisit your risk management plan with ESRM principles.

New to the framework? Start with what enterprise security risk management is and why it matters to security operations.

ESRM principles, alongside tools like the risk matrix, apply to every area security covers, including physical security and cybersecurity. The convergence of physical and cybersecurity deserves its own attention, so this article focuses primarily on physical security.

Key takeaways

  • ESRM ties security to the business.
    It aligns security decisions with the organization’s mission, assets and tolerance for risk.
  • ESRM is a cycle, not a project.
    Identify assets, identify risks, mitigate the priorities and improve continuously.
  • ALIGN turns strategy into action.
    Policies, technology, vetting, trust and communication close the human-error gaps where vulnerabilities hide.
  • ALARP defines “good enough.”
    Reduce risk until further reduction would cost far more than the benefit, and keep residual risk in the tolerable range.
  • Data makes the plan defensible.
    With TrackTik, incident trends, tour compliance and dashboards show where risk is rising and whether mitigations are working.

The ESRM Cycle at a Glance

ASIS International describes ESRM as a continuous cycle. Each pass through it sharpens your understanding of what matters most and how well it is protected.

  1. Identify and prioritize assets. Work with business leaders to agree on the people, property, information and operations that matter most.
  2. Identify and prioritize risks. Assess the threats to each asset, how likely they are and what their impact would be.
  3. Mitigate prioritized risks. Put controls in place for the highest risks, in partnership with the asset owners.
  4. Improve continuously. Review incidents, measure results and update the plan as the business and threat landscape change.

What is the Objective of Risk Management?

How organizations identify risks and prevent threats depends on the way hazards, harms, and risks are quantified. Evaluating these factors leads to the start of an ESRM mitigation strategy, or action plan that determines the right level of response.

Free workbook: The Cross-Functional Incident Workbook
Map how a single incident reaches every department it touches, before it happens for real. Download the workbook.

The right level of response often requires leaders to understand two principles: ALIGN and ALARP.

ALIGN: The Simple Way to Direct Your Organization’s Action Plan

Unintentional human error, fear of discipline for mistakes and failure to follow standard procedures are just a few of the reasons security vulnerabilities go unaccounted for. By ALIGNing your organization’s direction, you can begin to optimize how your team responds to risk.

  • Align policies with proven safety practices
  • Leverage technology to fill natural human-error gaps
  • Investigate security personnel backgrounds and histories
  • Gain trust among internal and external stakeholders with strong company values and intent
  • Network among security personnel and stakeholders to improve communication and continued education

Technology does the heavy lifting on the “L.” Digital post orders in TrackTik Guard Management keep policies current and acknowledged at every post, and a TrackTik security guard tour system verifies that the controls in your plan are actually carried out on every shift.

ALARP: How Organizations Decide How Much Risk Reduction Is Enough

ALARP stands for As Low As Reasonably Practicable. It is the principle security leaders use when a risk cannot be eliminated entirely. Under ALARP, you keep reducing a risk until the cost, time or effort of further reduction would be grossly disproportionate to the benefit gained.

The result is a residual risk that sits in the tolerable range of your risk matrix. Risks rated critical or catastrophic are not candidates for ALARP. They require action until they move into a tolerable range, or the activity creating them is reconsidered.

Using a Risk Matrix to Decide Your Response

A risk matrix rates each risk by likelihood and impact, then assigns a response level. Here is a simple way to connect each rating to action.

Risk ratingWhat it meansTypical response
TolerableLow likelihood and low impactAccept and monitor through routine patrols and reporting
UndesirableModerate likelihood or impactReduce with added controls where reasonably practicable (ALARP)
CriticalHigh likelihood or high impactAct promptly with new controls, escalation paths and leadership review
CatastrophicSevere impact on people, operations or reputationTake immediate action and do not accept the risk as it stands
Linking risk matrix ratings to a response level.

The hardest part of a risk matrix is estimating likelihood honestly. Your own operational history is the best evidence. TrackTik security incident reporting builds a time-stamped record of what actually happens at each site, and TrackTik Business Intelligence turns that record into trends by site, type and time period.

Putting ESRM into Practice with TrackTik

ESRM depends on reliable information at every step of the cycle. Here is how TrackTik, the security workforce management platform from Trackforce, supports each one.

How Often to Review a Risk Management Plan

There isn’t one right answer, because it depends on the organization. A risk management plan should be reviewed as often as leaders are able and willing to do it well. Many organizations review their plans quarterly and use assessment tools to support the process.

Beyond the regular schedule, trigger a review whenever something important changes:

  • After a major incident or a near miss
  • When you open a new site or take on a new client
  • When the threat landscape shifts, such as new crime trends or regulations
  • After organizational changes, such as mergers, restructuring or new leadership
  • When your data shows a sustained change in incident patterns

Reviews are faster and more accurate when your data lives in one place. Learn why fragmented tools undermine enterprise risk strategy, or book a TrackTik demo to see how a unified platform supports your ESRM program.

Frequently Asked Questions

ESRM principles tie security decisions to the organization’s mission and assets. Security partners with asset owners to identify what matters most, assess the risks to it and agree on mitigations. TrackTik Security Operations helps put those decisions into practice with standardized post orders, tours and reporting.

The ESRM cycle has four steps: identify and prioritize assets, identify and prioritize risks, mitigate prioritized risks, and improve continuously. TrackTik Business Intelligence supports the improvement step with dashboards that show whether controls are working.

ALARP stands for As Low As Reasonably Practicable. It means reducing a risk until further reduction would cost far more than the benefit, leaving residual risk in the tolerable range. Regular security risk assessments help confirm where each risk sits.

ALIGN is a simple way to direct your action plan: Align policies with safety practices, Leverage technology, Investigate personnel backgrounds, Gain stakeholder trust and Network to improve communication. TrackTik Guard Management supports the technology step with digital post orders officers must acknowledge.

List your risks, rate each one by likelihood and impact, then assign a response level such as tolerable, undesirable, critical or catastrophic. Use real incident history to estimate likelihood. TrackTik security incident reporting provides a time-stamped record of what actually happens at each site.

Many organizations review quarterly, with additional reviews after major incidents, new sites, organizational changes or shifts in the threat landscape. The TrackTik Command Center captures the full incident lifecycle, so post-incident reviews start with accurate information.

Technology fills human-error gaps, verifies that controls are carried out and turns daily activity into data leaders can act on. TrackTik brings scheduling, guard tours, incident reporting and analytics into one platform, so your ESRM program runs on a single source of truth.

Report on risk in business terms: which assets are protected, which risks were reduced and what incidents cost. TrackTik ReportPro AI can generate executive summaries in seconds, making it easier to share clear results with leadership.

Related resources

More on proving the work to clients