Using ESRM Principles to Revamp Your Risk Management Plan
Trackforce
May 21, 2021 · 8 min read

Using ESRM Principles to Revamp Your Risk Management Plan
Enterprise Security Risk Management, or ESRM, has been a trusted methodology among corporate security professionals for years. ESRM approaches risk by aligning security practices with a company’s overall mission and goals. As threats grow more complex and leadership expects security to show its value, now is an opportune time to revisit your risk management plan with ESRM principles.
New to the framework? Start with what enterprise security risk management is and why it matters to security operations.
ESRM principles, alongside tools like the risk matrix, apply to every area security covers, including physical security and cybersecurity. The convergence of physical and cybersecurity deserves its own attention, so this article focuses primarily on physical security.
Key takeaways
- ESRM ties security to the business.
It aligns security decisions with the organization’s mission, assets and tolerance for risk. - ESRM is a cycle, not a project.
Identify assets, identify risks, mitigate the priorities and improve continuously. - ALIGN turns strategy into action.
Policies, technology, vetting, trust and communication close the human-error gaps where vulnerabilities hide. - ALARP defines “good enough.”
Reduce risk until further reduction would cost far more than the benefit, and keep residual risk in the tolerable range. - Data makes the plan defensible.
With TrackTik, incident trends, tour compliance and dashboards show where risk is rising and whether mitigations are working.
The ESRM Cycle at a Glance
ASIS International describes ESRM as a continuous cycle. Each pass through it sharpens your understanding of what matters most and how well it is protected.
- Identify and prioritize assets. Work with business leaders to agree on the people, property, information and operations that matter most.
- Identify and prioritize risks. Assess the threats to each asset, how likely they are and what their impact would be.
- Mitigate prioritized risks. Put controls in place for the highest risks, in partnership with the asset owners.
- Improve continuously. Review incidents, measure results and update the plan as the business and threat landscape change.
What is the Objective of Risk Management?
How organizations identify risks and prevent threats depends on the way hazards, harms, and risks are quantified. Evaluating these factors leads to the start of an ESRM mitigation strategy, or action plan that determines the right level of response.
Free workbook: The Cross-Functional Incident Workbook
Map how a single incident reaches every department it touches, before it happens for real. Download the workbook.
The right level of response often requires leaders to understand two principles: ALIGN and ALARP.
ALIGN: The Simple Way to Direct Your Organization’s Action Plan
Unintentional human error, fear of discipline for mistakes and failure to follow standard procedures are just a few of the reasons security vulnerabilities go unaccounted for. By ALIGNing your organization’s direction, you can begin to optimize how your team responds to risk.
- Align policies with proven safety practices
- Leverage technology to fill natural human-error gaps
- Investigate security personnel backgrounds and histories
- Gain trust among internal and external stakeholders with strong company values and intent
- Network among security personnel and stakeholders to improve communication and continued education
Technology does the heavy lifting on the “L.” Digital post orders in TrackTik Guard Management keep policies current and acknowledged at every post, and a TrackTik security guard tour system verifies that the controls in your plan are actually carried out on every shift.
ALARP: How Organizations Decide How Much Risk Reduction Is Enough
ALARP stands for As Low As Reasonably Practicable. It is the principle security leaders use when a risk cannot be eliminated entirely. Under ALARP, you keep reducing a risk until the cost, time or effort of further reduction would be grossly disproportionate to the benefit gained.
The result is a residual risk that sits in the tolerable range of your risk matrix. Risks rated critical or catastrophic are not candidates for ALARP. They require action until they move into a tolerable range, or the activity creating them is reconsidered.
Using a Risk Matrix to Decide Your Response
A risk matrix rates each risk by likelihood and impact, then assigns a response level. Here is a simple way to connect each rating to action.
| Risk rating | What it means | Typical response |
|---|---|---|
| Tolerable | Low likelihood and low impact | Accept and monitor through routine patrols and reporting |
| Undesirable | Moderate likelihood or impact | Reduce with added controls where reasonably practicable (ALARP) |
| Critical | High likelihood or high impact | Act promptly with new controls, escalation paths and leadership review |
| Catastrophic | Severe impact on people, operations or reputation | Take immediate action and do not accept the risk as it stands |
The hardest part of a risk matrix is estimating likelihood honestly. Your own operational history is the best evidence. TrackTik security incident reporting builds a time-stamped record of what actually happens at each site, and TrackTik Business Intelligence turns that record into trends by site, type and time period.
Putting ESRM into Practice with TrackTik
ESRM depends on reliable information at every step of the cycle. Here is how TrackTik, the security workforce management platform from Trackforce, supports each one.
- Identify assets: TrackTik Asset Tracking keeps a record of equipment, keys and critical items, which supports better asset management as a risk control.
- Identify risks: Incident trends and patrol data reveal where risk is rising before it becomes a crisis. Pair them with these intelligence gathering tools for security risk assessments.
- Mitigate risks: Post orders, guard tours and the TrackTik Command Center turn mitigation plans into consistent action and fast response.
- Improve continuously: Standardized tasks and dashboards show whether controls are working, helping you move from reactive reporting to proactive risk management.
How Often to Review a Risk Management Plan
There isn’t one right answer, because it depends on the organization. A risk management plan should be reviewed as often as leaders are able and willing to do it well. Many organizations review their plans quarterly and use assessment tools to support the process.
Beyond the regular schedule, trigger a review whenever something important changes:
- After a major incident or a near miss
- When you open a new site or take on a new client
- When the threat landscape shifts, such as new crime trends or regulations
- After organizational changes, such as mergers, restructuring or new leadership
- When your data shows a sustained change in incident patterns
Reviews are faster and more accurate when your data lives in one place. Learn why fragmented tools undermine enterprise risk strategy, or book a TrackTik demo to see how a unified platform supports your ESRM program.
Frequently Asked Questions
Latest Articles
Featured Resources
See Trackforce in action
Book a walkthrough with our team and see how it fits your operation.












