Chicago, Illinois & Nationwide

Threat Risk Assessment
Services in Chicago

A structured, 14-step threat risk assessment that identifies vulnerabilities, evaluates impact, and delivers a clear, actionable security plan, before a threat becomes an incident.

Chicago-based firm since 2012
Former CPD Bureau of Counter Terrorism
Marine Corps & law enforcement leadership
Aligned with NIST, ISO 31000 & FAIR
Serving Chicago, IL & nationwide

Understanding Risk Before It Finds You

A threat risk assessment (TRA) is a systematic evaluation of the threats facing your people, properties, and operations, and the vulnerabilities those threats could exploit. The result is a clear, prioritized picture of your risk exposure and a roadmap for reducing it.

At Head of Security, our TRAs go beyond a checklist. We use behavioral science and protective intelligence to uncover risks that traditional security audits miss, including insider threats, behavioral indicators, and operational gaps that leave organizations exposed.

For businesses & organizations

Protect employees, facilities, operations, and intellectual property from workplace violence, theft, sabotage, and physical threats.

For executives & high-profile individuals

Identify personal security vulnerabilities, travel risks, and threat actors before they become a problem.

For events & large gatherings

Assess venue vulnerabilities, crowd dynamics, and threat scenarios before your event takes place.

For schools, nonprofits & houses of worship

Evaluate physical security, access control, and behavioral threat indicators specific to your environment and community.

The P.L.A.T.E. Framework

Every Head of Security threat risk assessment begins by defining scope using our proprietary P.L.A.T.E. framework, ensuring no area of risk is overlooked from the start.

P
People
Employees, clients, VIPs, and individuals at risk
L
Locations
Buildings, offices, facilities, and remote sites
A
Assets
Critical infrastructure, data, equipment, intellectual property
T
Travel
Executive movements, supply chain, high-risk travel zones
E
Events
Conferences, large gatherings, and special occasions

How We Conduct a Threat Risk Assessment

Our assessment process is structured, repeatable, and built on real-world security experience, not theory. Every engagement follows the same rigorous 14-step methodology.

01

Define scope & objectives

Using the P.L.A.T.E. framework to categorize assessment areas.

02

Identify & engage stakeholders

Streamlined to a maximum of three primary points of contact.

03

Inventory & value assets

Physical, digital, and human assets rated by importance and replaceability.

04

Identify threats

Intentional (violence, cyberattack, terrorism) and unintentional (disaster, human error).

05

Identify vulnerabilities

Physical, procedural, technical, and human factors creating security gaps.

06

Evaluate impact

Low, medium, or high consequences if an asset is compromised.

07

Assess risks

Risk Score = Threat × Vulnerability × Impact. Every risk gets a score.

08

Prioritize risks

Risk Matrix determines what needs immediate action vs. long-term management.

09

Develop mitigation strategies

Using the P.P.B.T. framework: People, Processes, Barriers, Technology.

10

Risk communication

Concise reports and executive presentations that secure leadership buy-in.

11

Implement controls

Deploy security measures, update SOPs, train personnel.

12

Document & report

Aligned with NIST, ISO 31000, and FAIR industry standards.

13

Continuous improvement

Ongoing risk monitoring and control updates as threats evolve.

14

Review & security audit

Regular reassessments to verify effectiveness and update strategies.

The P.P.B.T. Mitigation Framework

Once risks are identified and prioritized, we design mitigation strategies across four dimensions, ensuring a layered, comprehensive security response.

P
People
Security personnel, training programs, policies and cultural change
P
Processes
Emergency protocols, standard operating procedures, and response playbooks
B
Barriers
Physical security measures, fencing, locks, access controls, perimeter hardening
T
Technology
Surveillance systems, cybersecurity tools, alarm systems, drone monitoring

Six Phases. One Point of Accountability.

For larger engagements, Head of Security manages the full assessment lifecycle, from initiation through continuous improvement, as a structured project with clear milestones and deliverables.

Phase 1

Project initiation

Define scope using P.L.A.T.E., engage stakeholders, establish timelines and methodology.

Phase 2

Project planning

Inventory assets, identify threats and vulnerabilities, calculate risk scores, build the risk matrix.

Phase 3

Project execution

Prioritize risks, develop P.P.B.T. mitigation strategies, communicate findings, begin implementation.

Phase 4

Monitoring & controls

Document all risks and controls, monitor continuously, adjust based on incident reports and emerging threats.

Phase 5

Finalization & evaluation

Security audit, effectiveness evaluation, stakeholder feedback, and lessons learned.

Phase 6

Continuous improvement

Ongoing monitoring cycles, updated assessments as your organization and threat landscape evolve.

Organizations We Assess

Head of Security conducts threat risk assessments for a wide range of clients across Chicago, Illinois, and nationwide.

Corporations & enterprises
Small & mid-size businesses
Nonprofit organizations
Schools & universities
Houses of worship
Healthcare facilities
Retail & hospitality
Government & municipalities
Event venues & organizers
High-net-worth individuals
Executives & VIPs
Critical infrastructure

Frequently Asked Questions

What is the difference between a threat risk assessment and a security audit? +

A security audit evaluates whether your existing security measures are in place and functioning correctly. A threat risk assessment goes deeper, it identifies what threats exist, what vulnerabilities they could exploit, and what the impact would be if they did. The TRA is the foundation; the audit verifies that your mitigations are working.

How long does a threat risk assessment take? +

Timelines vary depending on scope. A targeted assessment for a single facility or individual can be completed in a few days. A comprehensive organizational TRA covering multiple locations, assets, and threat categories typically takes one to three weeks from initiation to final report delivery.

Do you conduct threat risk assessments outside of Chicago? +

Yes. While Head of Security is headquartered in Chicago with locations in Arlington Heights, IL and Lake Geneva, WI, we conduct threat risk assessments for clients nationwide and internationally. Our team travels as needed for on-site assessments.

What do I receive at the end of the assessment? +

You receive a comprehensive written report documenting all identified risks, vulnerabilities, and mitigation recommendations, prioritized by risk score. We also deliver an executive summary for leadership and, where applicable, present findings in person. All documentation aligns with NIST, ISO 31000, and FAIR standards.

Can Head of Security help implement the recommendations after the assessment? +

Absolutely. Our full engagement model moves from assessment through to implementation oversight and ongoing advisory. We coordinate vendors, manage timelines, and stay engaged through our continuous improvement phase, so recommendations don't sit in a drawer.

Is a threat risk assessment required by law in Illinois? +

Illinois law requires certain industries, particularly healthcare, to conduct workplace violence prevention assessments. Beyond legal requirements, many insurers, regulators, and institutional partners increasingly require documented risk assessments as part of due diligence. We can advise on your specific compliance obligations during the initial consultation.

Ready to Discover Your Risk?

Schedule a consultation with a Head of Security advisor. We'll begin with an intake and initial assessment to determine scope, objectives, and whether a formal engagement is the right fit.

Request a Consultation

Serving Chicago & Beyond

Headquartered in Chicago, IL with locations in Arlington Heights and Lake Geneva.

Chicago, IL
Arlington Heights, IL
Lake Geneva, WI
Chicagoland
Illinois
Nationwide
Scroll to Top

Submit a Service Request:

Submit a service request below or give us a call at (312) 857-5052 to talk one of our security experts today!

LET'S GET STARTED!

Fill out the form below or you can call and text us at (312) 857-5052