Where do you start when you are given security risk responsibility? Start by agreeing what you are responsible for, finding urgent issues and recording a small number of decisions someone can act on. Starting security risk management does not require a complete new system in the first week.

Start with the responsibility you hold: Agree the role; Find existing risks and controls; Set the first priorities.
Make the first week produce decisions.

First, agree what the role actually covers

Ask the manager who assigned the work to confirm the sites, services and activities in scope. Clarify your authority to request information, commission assessments and recommend spending. Identify who can accept a risk and who can approve a treatment. These may be different people.

Write down the first decision the organisation needs. “Improve security” is too broad. “Decide how to control after-hours access at the main depot” gives you a starting point. If the remit remains unclear, use the questions in setting the scope of a security risk assessment.

Find out what already exists

Before creating another spreadsheet, locate the existing risk register, security policy, incident records, site plans, emergency arrangements and contracts that affect security. Ask the people doing the work which documents they actually use.

Keep a short discovery list:

What to find Why it matters What to record
Existing assessments Avoid repeating work or missing known issues Owner, date, scope and review status
Recent incidents and near misses Understand specific failure scenarios What happened, controls involved and outstanding actions
Current controls Separate plans from working arrangements Who operates the control and how performance is checked
Decision authorities Make recommendations actionable Who accepts risk, approves money and owns delivery
Obligations and commitments Identify work that needs specialist interpretation Relevant requirement and person responsible for confirming it

Do not assume a document is current because it is the first search result on the shared drive. Confirm its owner and status before treating it as the baseline.

Separate immediate action from the assessment backlog

A broken access door needs an operational response; it should not wait for the new risk register to be finished. Follow existing incident and emergency procedures for urgent issues, and involve the relevant owner. Record what was done and what still needs a decision.

For the remaining issues, distinguish an observation from a risk scenario. “Visitors are not signing in” describes an observation. “An unverified visitor could access the dispatch area and remove customer goods” describes one possible scenario to examine. Check whether that scenario fits the actual site before rating it.

Make the first week produce decisions

This is an illustrative sequence, not a universal timetable:

  1. Agree the remit. Confirm the initial scope and decision owner.
  2. Read and listen. Review existing records and speak with the people who operate the service.
  3. Check the work on site. Observe how the relevant controls work, including exceptions and busy periods.
  4. Draft a short risk list. Record specific scenarios, current controls, evidence gaps and proposed owners.
  5. Hold a decision meeting. Agree immediate actions, assessment priorities and the next review date.

You may need more time, specialist support or a narrower scope. Make that constraint explicit rather than filling gaps with confident-looking ratings.

Worked example: a facilities manager's first week

In this fictional example, a facilities manager takes on security coordination for three depots. They cannot assess every site in five days. The operations director agrees that the first decision concerns after-hours access at the busiest depot.

The manager finds an old register, speaks with dispatch staff and reviews the access process with the site supervisor. A shared access code is still active after several contractors have left. The manager refers that issue for prompt action under the existing access procedure and records the response. The wider assessment covers who needs access, who approves it, how access is withdrawn and how exceptions are checked.

The week ends with an agreed scope, an owner for the immediate action, a list of missing evidence and a date for the assessment decision. It does not end with an unsupported claim that all three depots are secure.

Keep one working record

Use an existing approved register if it meets the need. If there is no usable register, start with a simple structure and a named owner. Avoid maintaining a private copy that nobody else can find or update.

Once the initial scope is agreed, follow the guide to building your first risk register. As proposed actions become clearer, connect them to a risk treatment schedule with owners, dates and evidence of completion.

Get a practical starting resource

The SRMBOK Risk Register Starter Pack gives you a starting structure for recording risks and actions. Adapt it to your agreed scope and decision process, then use the first review meeting to test whether it helps people make decisions.