Dynamic risk assessment triangle: what are you protecting, from what, and how vulnerable is it, Jijiga, Ethiopia, 2005

One Threat, One Asset, One Decision

The moment I really understood security risk management was not in a classroom. It was during the 2005 elections in Ethiopia, two weeks into a new job, and it came down to a single dynamic risk assessment.

I had joined the Carter Center as security adviser for its election observation mission. My area ran from Jijiga down to the Somali border, covering every observation post in between. As the capital of Ethiopia’s Somali Region, Jijiga was the most significant of those posts, and the one that mattered most to the results.

The 2005 elections were the most competitive Ethiopia had seen, and they were tense. Within weeks of the national vote, protests over the results turned deadly in Addis Ababa, and the unrest that followed left around 200 people dead.

Preparing the people I was responsible for

The observers were civilians, volunteering their time so that the elections could be independently scrutinised. My job was to keep them safe.

The week before the elections, I travelled the region with one of the Carter Center’s social scientists to review each observation post. Through a British university that had carried out a study in the area, I arranged to meet a tribal chief. We explained who we were, what we were doing and what our vehicles and branding would look like, and asked for peaceful right of transit. He offered us military protection. I had to decline: our credibility as observers depended on staying neutral.

That ground reconnaissance shaped the security plan, including the evacuation routes from each post to a safe location. Back in Addis Ababa, I set up a makeshift operations centre and training environment in a hotel. As the observers arrived, I trained them to operate safely in the field, to use satellite communications, to conduct themselves and to report. I linked the operations centre with the security teams of other agencies and the government bodies we could reach, creating an intelligence-sharing network. Once the observers deployed, we monitored their movements from there, with air assets ready to extract people and get them to hospital if something went wrong.

None of that is unusual. It is the normal work of a security adviser: prepare, put controls in place, and be ready to respond. What I had not yet done was make a call that tested all of it, live.

Election day in Jijiga

On election day, reports came in from our team in Jijiga. The main voting centre had opened later than planned, and as the hours passed, the crowd’s patience wore thin. Local security officers fired shots to control it, and an older woman was shot and killed.

My pre-deployment research and the ground recce had already told me a good deal about the area. Tribal tensions, political rivalries and unresolved disputes ran deep, and many people nearby had access to firearms and even explosives. The conditions for a violent reaction were all there.

A dynamic risk assessment, made from the operations room

I was hundreds of miles away, working only from what the team was reporting. So I worked through the same three questions I would ask in any security risk assessment.

What was I trying to protect? Our observer team in Jijiga.

What was I trying to protect it from? A violent response to her shooting. Several groups now had a motive for revenge: her family, her tribe and, increasingly, the politics of the day. And I knew all of them had the capability, with access to both small arms and explosives.

How vulnerable were they? Very. They were at the focal point of the tension, with little between them and whatever came next.

One asset. One threat. A clear and rapidly worsening vulnerability. That was a dynamic risk assessment I could carry out in my head, and the answer was plain: the risk now outweighed the value of staying.

A structured conversation with leadership I had never met

The harder part was the conversation that followed. Observing the election mattered. It was the reason we were there, and a transparent democratic process depended on people like us being present. I was asking the organisation to pull its team out of the most important post in the region, two weeks into the job.

First, I took my assessment to the Carter Center’s in-country leadership, who asked me to put it directly to the leadership at headquarters in Atlanta. I had never met them. One of the first things they asked was whether I had specific intelligence that an attack was going to take place.

I didn’t. Events were moving too fast for that. But the process gave me something just as useful. I could set out what we were protecting, what we faced and how exposed the team was. The motive was there, the capability was there, and the team was in the middle of it. I could tell them what the risk was. And I could tell them I couldn’t give them a single reason why it wouldn’t happen.

It was a calm conversation, not an alarmed one, and it gave them what they needed to decide. They authorised an immediate evacuation from Jijiga.

Getting them out before dark

Our team in Jijiga was two people. One was a former Kenyan special forces soldier, very capable in his own right. The other was a British social scientist who spoke the local dialect. Both had every reason to read the situation differently from someone in an operations room hundreds of miles away, and I wondered whether they would push back.

They didn’t. I had the same conversation with them that I’d had with Atlanta, built on the same three questions, and it landed with both of them in exactly the same way.

Then time became the issue. On the recce, we had mapped the evacuation route from Jijiga to a pre-planned safe hotel, and along it we had identified a likely ambush point. Intelligence told us that anyone passing it after dark stood a good chance of being carjacked. They had to move quickly to get through it in time.

They made it, and checked into the hotel. I remember thinking I was unlikely to be very popular: I had just cancelled the mission at its most important post. They were sitting down to eat when the call came through the intelligence-sharing network we had built. A device had gone off at the election observation post in Jijiga.

What that dynamic risk assessment taught me

That was the day the theory became real for me. The structured process I had been taught was not paperwork. Used properly, under pressure, it let me reach the right answer quickly and, just as importantly, explain it to people who had every reason to question it, whether that was a leadership team I had never met, a former special forces soldier or an academic who knew the area far better than I did.

Four things made the difference:

  • Understanding the operation, what was at stake and my client’s appetite for risk.
  • Assessing the threat in a logical way my client could follow.
  • Communicating the risk clearly and simply, so leadership could act.
  • Having a plan ready: a reconnoitred route, a safe destination, and the timing to get there.

From one threat to thousands

Here is the point I keep coming back to. That day I was dealing with one threat against one asset, in a very tangible situation. A dynamic risk assessment on that scale is something you can hold in your head.

Businesses don’t have that luxury. A security leader has to weigh many threats against many assets, across sites and countries, physical and cyber, while meeting compliance obligations and reporting to a board. Asking one person, or a team working from spreadsheets, to hold all of that in their heads simply isn’t feasible.

That is why I have spent more than a decade building the HawkSight platform, first as a digital framework and now with AI-enabled threat intelligence through Talon. The scale has changed. The fundamentals haven’t. Every assessment still comes back to the same three questions: what am I trying to protect, what am I trying to protect it from, and how vulnerable is it?

The question for you

If you had to make that call today, from an operations room and on the strength of a few reports, could you explain your reasoning to a leadership team you had never met? And could you do it across every site and every threat you are responsible for?

If you’d like to talk about how HawkSight brings that structure to your organisation, get in touch.

hotel_blog_1600

Do you know how secure your hotels are? Why hotel groups need a portfolio view of security risk

Ask the board of a hotel group how its hotels are performing and you will get an answer within minutes. Occupancy, rate, revenue per room and guest scores, all broken down by property and region. Now ask the same board about hotel security risk, site by site. In most cases, nobody can give an equivalent answer. That is the gap in risk insight for hotel leadership.

The information exists somewhere. It sits in audits, incident logs, training records and the heads of general managers. However, nobody brings it together in a form leadership can see and act on. This year has shown why that matters.

What 2026 has shown

In February, a court jailed a man for seven and a half years for sexually assaulting a woman in her room at a hotel in Maidenhead. He had talked his way into a key card at reception in the early hours by claiming to be her boyfriend. Afterwards, more than a hundred MPs signed a letter demanding a meeting with the chain’s chief executive.

Then, in August, a second woman spoke out. She described an attack at a London hotel in the same chain in October 2025. Her abuser told reception she was having a seizure, and staff gave him a key and directed him to her room. The company said staff had not followed its policy, which is never to confirm to a third party that a guest is staying.

In July, a guest at a hotel in Dundee entered another couple’s room while they slept. Once again, the company said staff had not followed its room access procedures correctly.

How the industry is responding

Since then, the chain has commissioned an independent review led by Paul Greaney KC. It now requires explicit guest permission before staff issue any additional key. It has also retrained 12,000 customer-facing colleagues, brought in independent audit and mystery shopping, and changed chief executive.

Meanwhile, UKHospitality is developing sector-wide Guest Security Principles and Good Practice guidance through a guest security working group.

I am not writing this to single out one company. Every large hotel group I have looked at faces the same underlying problem. This one has simply had it exposed in public.

One standard, hundreds of front desks

The detail that stays with me is this. In two of those three cases, the company says a policy existed but staff did not follow it. In the third, staff followed the procedure in place, and it still failed.

That is the portfolio problem in its simplest form. Head office writes the standard. Hundreds of front desks then apply it, often at three in the morning with one person on shift. Someone convincing is usually standing at the desk. As a result, leadership has very little sight of where the standard holds and where it does not. In most cases, it finds out after something has gone wrong.

Hotel security risk reaches beyond locks and cameras

These cases also show that hotel security risk, like all security risk, reaches well beyond physical protection. Talking a receptionist into handing over a key card is a deception aimed at a person, not an attack on a door. In fact, attackers used the same basic technique against the IT help desk at M&S in 2025. Locks and cameras matter, but they do little when someone hands over the key at the front desk.

When it goes wrong, the impact is plain to see. First, and most importantly, it falls on the guest, who had every reason to feel safe in their own room. After that, it falls on the brand. In this case, that meant national headlines, a letter from more than a hundred MPs, an independent review and a change of chief executive. For any hotel group, that is the real measure of security risk.

The wider threat picture for a hotel estate is broad. It includes room access and key control, violence against women and girls, and staff working alone at night. It also covers theft, large events and functions, guest data and booking systems, and at the far end, terrorism. None of it is new. What has changed is the level of scrutiny. Boards now need to show they have a grip on it.

Martyn’s Law adds a legal reason

From spring 2027, Martyn’s Law (the Terrorism (Protection of Premises) Act 2025) adds a compliance reason. Schedule 1 covers “Hotels etc”, and the Home Office guidance extends this to hostels and holiday parks.

The test is simple. Can you reasonably expect 200 or more people on site at the same time, at least occasionally? If so, you will need public protection procedures and must notify the regulator, the Security Industry Authority. At 800 or more, the heavier enhanced tier duties apply. Staff count towards both figures.

For a multi-site operator, the first challenge is knowing which sites are in scope. For example, a sixty-room country house hotel can sit well below the line on a weekday. On a wedding Saturday, however, it can clear it comfortably. Because the test looks at what you can expect occasionally, that hotel is in scope. Across an estate of hundreds of properties, many sites will sit close to the line.

The government intends that standard tier sites can comply without buying specialist services, and I think that is right. Even so, answering the scope question needs the same thing as answering the guest security question. You need a consistent, current picture of every property.

What a portfolio view of hotel security risk would look like

In practice, I think a useful portfolio view would do six things well:

  • Ask every site the same questions. Cover room access and key issue, escalation, night staffing, CCTV and access control, training and event capacity. The people who run each property can answer them, without a specialist on site.
  • Roll it up for leadership. Show one view across the estate, by brand, region and site, in language a board can act on.
  • Highlight the exceptions. The value lies in surfacing the twenty sites that need attention, not confirming the four hundred that are fine. Specialist time can then go to those sites first.
  • Look beyond the physical. Include procedures, people, guest data and systems as well as locks and cameras.
  • Track it over time. Policies change, staff move on and sites change use, so a one-off audit soon goes stale.
  • Answer the compliance questions too. Show which sites are in scope for Martyn’s Law, which tier, and on what evidence.

How HawkSight approaches it

We have built this kind of capability at HawkSight for other sectors. Our Gateway tool gathers structured site data from the people on the ground. Alongside it, HawkSight’s enhanced threat intelligence capability draws on more than 750 global news and intelligence sources. It assesses the adversarial threat at each individual site and maps it against the key assets the hotel depends on. It then sets out the controls needed to mitigate it.

Together, these give leadership both halves of the picture. First, what the threat is at each property. Second, whether the controls to meet it are actually in place.

Right now, I am exploring whether hotel operators want a version of this built for their estates. After all, guests trust a hotel with their safety, and shareholders trust leadership to protect the brand. Do you not owe both of them that picture?

I would like to hear from you

If you are responsible for security, safety or risk across a hotel portfolio, I would value your view. What would you want a single view of security risk across your properties to tell you? And what gets in the way of having one today?