Contributed by Jim Brigham, LCG VP of Risk Management, Former Operations Chief, State of Vermont, Office of Safety and Security
Organizations frequently use the terms vulnerability assessment, threat assessment, risk assessment, and protective intelligence interchangeably. They are related, but they answer different questions, and confusing them can leave serious gaps in a security program.
A vulnerability assessment examines weaknesses that could be exploited. It considers physical security, technology, policies, staffing, training, communications, and operational practices. In simple terms, it asks: Where are we exposed?
A threat assessment evaluates a person, group, circumstance, or emerging behavior that could cause harm. It considers such factors as intent, capability, access, planning, grievances, escalation, and proximity to a potential target. It asks: Who or what may cause harm, and how likely is the concern to progress?
Protective intelligence is the continuing process of identifying, collecting, evaluating, and sharing information about potential threats. It may include employee reports, open-source information, law-enforcement intelligence, concerning communications, behavioral indicators, and changes in circumstances. It asks: What information do we need to recognize a developing threat early and keep the assessment current?
A risk assessment brings the other elements together. It considers the threat, existing vulnerabilities, likelihood of occurrence, and potential consequences to people, operations, assets, and reputation. It asks: What could happen, how serious would it be, and what should we prioritize?
Organizations confuse these functions because they overlap and often occur simultaneously. A report about a threatening individual may reveal inadequate access control. A facility assessment may identify vulnerabilities that make a particular threat more consequential. Protective intelligence may then change the assessed risk as new information becomes available. The processes are connected, but they are not substitutes for one another.
Effective programs use a structured methodology rather than relying on instinct or labels such as “low,” “medium,” or “high” without explanation. The process should:
- Define the concern and identify what is known and unknown.
- Evaluate the credibility, intent, capability, access, and immediacy of the threat.
- Identify vulnerabilities that could be exploited.
- Assess potential consequences and affected operations.
- Document sources, assumptions, decisions, and responsible authorities.
- Recommend proportionate protective measures.
- Continually reassess the situation as new intelligence develops.
A meaningful assessment does more than describe a problem. It gives leadership a defensible basis for action. It identifies what requires immediate intervention, what can be monitored, where to direct resources, and when protective measures can safely be reduced.
The most important principle is straightforward: An assessment that does not inform a decision, assign responsibility, or produce action is merely documentation, not risk management.





