What is ESRM and Why is it Important to Security Operations

The Trackforce Team

Trackforce

May 14, 2021 · 12 min read

Enterprise security risk management strategy session with business stakeholders

What is Enterprise Security Risk Management (ESRM)?

ESRM approaches risk management in a manner that aligns security practices directly to a company’s overall mission and specific goals. ESRM principles can be applied to any area of security and task that is performed by security, including physical security and the convergence of cybersecurity.

When applying risk management principles to enterprise security, the concept of Enterprise Security Risk Management (ESRM) has been around for quite some time. Every ESRM plan must:

  • Define what your overall security program looks like
  • Build an understanding of the role of security in all areas of your business
  • Become a major component of your company’s strategy
  • Introduce security processes and structure for stakeholders at every level

Key takeaways

  • ESRM is a way of deciding, not a set of controls.
    It connects every security activity back to a business asset and the risk appetite of whoever owns that asset.
  • The business owns the risk, security advises on it.
    This is the shift most teams find hardest, and it is also what moves security out of the second-tier department bracket.
  • Assets first, then risks, then mitigation.
    Programmes that start with controls rather than an asset register end up defending things nobody prioritised.
  • ESRM lives or dies on its reporting cycle.
    A risk register reviewed once a year is documentation. Reviewed continuously against real incident data, it becomes management.
  • TrackTik supplies the evidence layer ESRM needs.
    Asset records, incident data, patrol verification and cross-site reporting are what turn an ESRM plan into something you can actually review each quarter.

The Principle That Makes ESRM Different

Most security programmes are built around what security thinks needs protecting. ESRM inverts that. The asset owner, meaning the business leader accountable for a facility, a product line or a data set, is the one who decides how much risk is acceptable. Security’s job is to make that decision an informed one by presenting the risk clearly, laying out the options and the cost of each, and then executing whatever the owner chooses.

That sounds like a reduction in authority. In practice it is the opposite, because it removes the argument security usually loses. You are no longer asking for budget to satisfy a standard nobody else has read. You are documenting a risk, naming the owner, and recording their decision. When something goes wrong afterwards, the conversation is about a business decision that was made with full information, not about whether security asked loudly enough.

For corporate and in-house security teams, this is the mechanism that gets security into the strategy conversation rather than the facilities budget.

What ESRM Fixes in Corporate Security

Companies that haven’t implemented ESRM practices risk misalignment between stakeholders and their security workforce. While everyone knows that company assets and personnel need to be protected, very few conversations take place regarding how overall security fits in with a company’s strategic business plan.

Companies that are serious about their corporate security management don’t regard their security operations as a “second tier” department. They’re included in the company’s most important strategy meetings, right next to representatives from the finance department and human resources.

The practical barrier is usually evidence rather than willingness. Finance and HR arrive at those meetings with numbers. Security often arrives with narrative, which is why fragmented tooling is such a problem for enterprise risk work and why fragmented systems undermine enterprise risk strategy more than most teams realise.

How ESRM Integrates With Business Plans and Goals

So, we understand how important it is to include enterprise security operations in all levels of your overall business strategy. But how do you really do that?

The first step is to work with business leaders to identify all company assets and prioritize them. Next, identify and prioritize the risks associated with each of those assets. Then, start working on plans to mitigate those prioritized risks. Remember, this process should apply to all levels of strategy and overall business goals.

Once the plans are laid out, a detailed reporting system should be established so that risks can be frequently assessed and risk management tactics can be adjusted accordingly. That last step is where most programmes quietly fail, because the reporting has to run on its own rather than depending on somebody assembling it by hand each quarter.

If you want the implementation detail rather than the overview, using ESRM principles to revamp your risk management plan walks through building the plan itself, and intelligence gathering tools for risk assessments covers how to source the risk data the register depends on.

Where ESRM Programs Stall

ESRM rarely fails because somebody disagreed with it. It fails in predictable, unglamorous places. Knowing them in advance is most of the work.

Where it stallsWhat unblocks it
No agreed asset registerStart with the ten assets the business would notice losing, not an exhaustive inventory
Nobody named as asset ownerEvery risk line gets a person, not a department
Risk ratings argued in the abstractRate against real incident history from your own sites
The register is reviewed annuallyTie the review to a reporting cycle that already happens
Security reports activity, not riskReport on exposure and trend, not tours completed
Cyber and physical assessed separatelyOne register covering both, since attackers do not respect the split

The last row is worth dwelling on. ESRM was designed to be applied across every security discipline, which is exactly why compliance and risk mitigation in physical security cannot sensibly be run in a separate register from the cyber programme.

ESRM Is Not Just for Security Teams

Hopefully, we’re getting the message across here, but we can’t stress it enough. Effective ESRM isn’t something that falls only on the shoulders of corporate security departments. Sure, they’ll take care of security-specific activities like incident reporting, site access, and more. Integrating an overall security culture with business goals should be the responsibility of all leaders at a company.

In practice that means the asset owners in finance, operations, HR and IT each hold a line on the risk register, and the review meeting is theirs as much as it is security’s. A register that only security attends is a register that only security believes in.

What ESRM Needs From Your Security Operations Data

Identifying strategic risk is only one part of a holistic ESRM approach. When it comes time to mitigate those risks and then prove you are managing them, you need an operational record rather than a document. TrackTik, the security workforce management platform from Trackforce, is where each of the following comes from.

  • An asset register that stays current. Asset tracking keeps the list of what you are protecting tied to reality rather than to a spreadsheet somebody last edited two reorganisations ago.
  • Incident history to rate risk against. Real reports from your own sites are far more defensible than a generic likelihood score, and they let you show an asset owner what has actually happened rather than what might.
  • Evidence that mitigations are being performed. A control that exists on paper and a control that runs every shift are different things. Security operations data closes that gap.
  • Response capability when a risk materialises. The command center is where a documented escalation path becomes an actual dispatch with a recorded response time.
  • The recurring report the cycle depends on. Business intelligence reporting across sites produces the trend view an ESRM review needs, without anybody building a deck for it.
  • One record across every site and team. The TrackTik platform holds it together, which matters because an ESRM register assembled from four disconnected systems is a register nobody trusts.

A risk register is only as credible as the operational data behind it. If you cannot show what happened last quarter, you cannot argue convincingly about what might happen next quarter.

A First Ninety Days for an ESRM Program

ESRM presented as a full framework tends to stall before it starts. Presented as a quarter of concrete work, it usually gets approved. This sequence keeps the early effort small and visible.

  1. Weeks 1 to 3: name ten assets and their owners. Not a complete inventory. The ten things the business would genuinely feel the loss of, each with a named person who is accountable for it.
  2. Weeks 4 to 6: rate the risks using your own history. Pull the incident record for each asset and rate against what has actually occurred. This is the step that makes the register hard to dismiss.
  3. Weeks 7 to 9: hold the first owner conversations. Present the risk, the mitigation options and the cost of each, then record the decision. Including the decision to accept the risk, which is a legitimate answer.
  4. Weeks 10 to 12: wire up the reporting. Decide what the quarterly review will show and make it generate itself. If it needs manual assembly it will not survive a busy quarter.
  5. End of quarter: run the review once. A short meeting with the asset owners present, looking at movement rather than a full re-rating. Getting one real cycle completed matters more than getting the framework perfect.

Once that cycle has run twice it tends to become self-sustaining, because the asset owners start arriving with their own questions. That is the point at which security is genuinely part of the strategy conversation rather than presenting to it. Shifting from incident-driven firefighting to this kind of cadence is the same move described in going from reactive reporting to proactive risk management.

The team at Trackforce can help you respond to risks efficiently and produce the recurring reports an ESRM cycle depends on. Schedule a demo today to see how your company can take a holistic approach to integrating enterprise security risk management methods.

Frequently Asked Questions

ESRM stands for Enterprise Security Risk Management. It is an approach that ties every security activity back to a specific business asset and the level of risk the owner of that asset is prepared to accept. The word enterprise matters: it is intended to cover physical security, cyber security, brand, personnel and information under one method rather than running each as a separate programme.

Traditional security management decides what to protect and how, based on security’s own judgement of what matters. ESRM moves the decision to the business leader who owns the asset, with security acting as the advisor who presents the risk, the options and the cost. The practical difference shows up in budget conversations: instead of requesting funding for controls, you are recording a business decision about accepted risk, which is a far harder position to dismiss.

With a short asset list, not a framework document. Name the ten assets the business would genuinely feel the loss of, assign a named owner to each, then rate the risks using your own incident history rather than generic likelihood scores. Most failed ESRM attempts began with an attempt to inventory everything. Asset tracking is useful here because the register stays accurate instead of drifting out of date between reviews.

No, though the name suggests it. The method scales down cleanly because it is a way of making decisions rather than a set of required controls. A mid-sized organisation with one site and a handful of officers can run the same cycle on a single page: assets, owners, risks, decisions, review date. What changes with size is the number of asset owners involved, not the approach.

By supplying the evidence the cycle runs on. Incident reports give you real history to rate risks against, patrol and checkpoint records show that agreed mitigations are actually being performed, and the command center records what happened when a risk materialised. Business intelligence reporting then produces the recurring cross-site view an ESRM review needs, which is the part that usually decides whether the programme survives its second quarter.

Quarterly works for most organisations, with an out-of-cycle review after any significant incident or material change to a site or business line. Annual review is too slow to count as management, because the risk picture will have moved several times before anyone looks. The practical test is whether the review can run without someone spending a week assembling it. If it needs that much preparation, it will be skipped the first time the quarter gets busy. You can book a TrackTik demo to see what that reporting looks like against live site data.

Related resources

More on building security into business strategy