Security Risk and Threat Assessments

TRA uses proven techniques to conduct comprehensive risk and threat assessments for an agency’s critical assets. TRA has completed many Threat, Vulnerability, and Risk Assessments that provide quantitative and qualitative results. Our approach aligns with current standards and includes site reviews to identify gaps and recommend improvements.

Frequently Asked Questions

A threat is any source of potential harm, such as a physical attack, natural disaster, insider action, or cyber intrusion. A vulnerability is a weakness in people, process, or technology that a threat could exploit. Risks, in this security sense, can be thought of as the combination of threat likelihood, vulnerability severity, and the potential consequence of an event.

A complete assessment evaluates all three together rather than focusing on any one in isolation. Identifying threats without vulnerabilities leaves agencies unable to prioritize, while tracking vulnerabilities without threat context often produces long lists of issues that no one knows how to rank.

For transit agencies, the list usually includes major stations and terminals, rail yards, bus garages, operations control centers, communications facilities, substations, and key bridges and tunnels. Data centers, fare collection systems, and emergency operations centers are also common focus areas.

Private-sector critical infrastructure owners often need assessments of power plants, refineries, water treatment facilities, distribution hubs, and corporate headquarters. The common thread is that a successful attack or failure at these sites would disrupt essential services, harm people, or generate outsized financial or reputational losses.

Qualitative assessments rate risks on descriptive scales such as low, medium, and high, or use narrative categories like critical, significant, and minor. They are faster to execute and easier to communicate to non-technical leadership.

Quantitative assessments assign numeric values to likelihood and consequence, often drawing on historical incident data, industry benchmarks, and modeled scenarios. They support more precise prioritization and cost-benefit analysis of mitigations. Many mature programs use hybrid approaches, applying quantitative rigor to the highest-consequence scenarios and qualitative ratings to lower-tier risks.

Most agencies conduct comprehensive assessments every three to five years, with targeted updates whenever there is a significant change in infrastructure, threat intelligence, leadership, or operating context. After any major incident, relevant assessments should be reviewed within weeks, not years.

Threat environments change faster than agencies often realize. A five-year-old assessment that does not account for current geopolitical tensions, emerging cyber threats, or changes in domestic extremist activity is likely understating current risk. Maintaining a living risk register between formal assessments keeps the picture current without requiring a full rebuild every year.

How Can We Help You?

With a wealth of industry knowledge and experience, our experts have the skills to solve even the most complex problems. Let us know how TRA can help you meet your goals and improve results.

Contact Us