Threat-Vulnerability-Risk Assessment
Every TVRA answers one question: can this site safely support its intended mission? ARRC conducts TVRAs using VIGIL — our evidence-driven assessment platform that combines structured methodology, multi-source intelligence, and transparent confidence scoring to produce assessments that are consistent, auditable, and repeatable.
Because critical decisions deserve more than static reports.
ARRC is the practitioner.
VIGIL is the platform.
Security investments made without a clear understanding of what you are protecting against — and where you are genuinely exposed — are rarely proportionate, and frequently misallocated.
A TVRA establishes that foundation. Every ARRC TVRA is conducted through VIGIL — transforming the assessment from a standalone report into a structured digital record where evidence, assumptions, confidence levels, and site characteristics remain connected long after the engagement concludes.
TVRA is one application of VIGIL. VIGIL defines what a modern TVRA should be.
"Every security conversation eventually comes back to the same question: what are you actually trying to protect against? A TVRA answers that question with rigour. VIGIL ensures the answer remains available, auditable, and useful long after the report has been delivered."
What a TVRA was always supposed to answer.
The question was always right. What broke down — consistently, across the industry — was what happened to the answer after it was delivered.
Traditional assessments captured one moment, filed a report, and left — without a baseline, without auditable evidence, without a way to answer: "Would we make the same decision today?"
📄 The finding lived in a document
The assessment was delivered as a PDF. Filed. The team changed. Assumptions were forgotten. The environment evolved. The finding remained — static, disconnected, and increasingly irrelevant.
"The report aged. The risk didn't."
👤 The finding belonged to the consultant
Two qualified practitioners, same site, same information — different conclusions. Neither could be challenged against the other. When the consultant left, the rationale left with them.
"The finding was personal, not institutional."
❓ Confidence was never measured
A conclusion backed by six data points was presented with the same authority as one backed by sixty. There was no mechanism to ask how much confidence to place in a finding — or receive a quantified answer.
"Uncertainty was hidden, not disclosed."
⏱️ Point-in-time, not lifecycle
The assessment captured one moment. Infrastructure evolved, threats adapted, the environment changed. The original finding could not be revisited against a baseline — because no baseline had been structured.
"Would we make the same decision today? Nobody could answer."
📊 Traditional outputs vs VIGIL outputs
Traditional: PDF · Risk Register · Roadmap
VIGIL-powered: PDF · Evidence Register · MSI · MCI · MRI · Risk Register · Site Record · Reassessment Baseline
Finding belongs to the methodology.
Not the consultant. Not the report. The finding is institutional, reproducible, and auditable. Same site, same evidence, same framework — same result. The assessment survives personnel change and stands up in any room.
How VIGIL changes TVRA
The methodology was always sound. VIGIL makes it durable.
Every ARRC TVRA conducted through VIGIL produces a structured digital record — not just a report. The finding becomes institutional, not personal.
Reproducible findings
Anchor statement methodology generates scores from evidence, not judgement alone. Same site, same evidence, same framework — same result. The finding survives personnel change and consultant rotation.
Confidence measured, not assumed
The Mission Confidence Index (MCI) quantifies the quality, recency, and corroboration of evidence behind every finding. A high-confidence assessment and a provisional one are explicitly and visibly different.
Evidence trail built in
Every indicator carries a named source, a recorded date, and the basis for the conclusion. The evidence trail is created at assessment — never reconstructed when scrutiny arrives.
Trajectory, not just snapshot
The Mission Resilience Index (MRI) projects where the site is heading — accounting for infrastructure evolution, threat trajectory, and regulatory change over a 20-year horizon.
What a TVRA examines
A credible TVRA operates across three interconnected dimensions — each informing the other, and none sufficient on its own.
Our methodology draws on internationally recognised frameworks — including ASIS, ISO 31000, and government-sector risk guidance — adapted to the specific context of each engagement. All delivered through VIGIL.
Threat Analysis
Identification and characterisation of the threat actors, attack methodologies, and threat scenarios that are credible in the context of your organisation, location, and sector. Assessment is intelligence-led, drawing on open-source, sector-specific, and where available, proprietary threat data — all confidence-rated through VIGIL.
Vulnerability Assessment
A structured examination of the weaknesses that exist across your physical security measures, access control systems, personnel and visitor management practices, procedural controls, and security culture. Vulnerabilities are assessed in relation to the specific threats identified — not in isolation.
Risk Evaluation & Prioritisation
Combination of threat likelihood and vulnerability severity to produce a risk-ranked picture of your security exposure using VIGIL's structured L×I methodology — transparent, auditable, and directly usable as the basis for resource allocation decisions.
Mitigation Recommendations
Practical, proportionate security measures mapped to specific risks — covering physical countermeasures, technology systems, procedural improvements, and organisational changes. Sequenced by priority with indicative cost ranges and implementation complexity.
The platform isn't replacing TVRA.
It's elevating it.
Traditional TVRAs are delivered as standalone reports. The intelligence that produced them — the sources, the assumptions, the confidence behind each finding — exists in the consultant's notes, if at all.
VIGIL transforms the assessment into a structured digital record where evidence, assumptions, confidence levels, and site characteristics remain connected long after the report has been delivered. Your assessment becomes easier to revisit, compare, and build upon as the operating environment evolves.
"TVRA is one application of VIGIL. VIGIL defines what a modern TVRA should be."
VIGIL TVRA — Full Output Set
ARRC Assessment Methodology
A structured five-stage process, applied consistently across all engagements whilst remaining fully adaptable to the specific nature, scale, and complexity of each site. All stages powered by VIGIL.
Engagements typically span one to four weeks depending on site complexity, geographic locations to cover, and reporting requirements.
Context & Scoping
We begin by developing a detailed understanding of your organisation — its assets, operations, stakeholder obligations, regulatory environment, and specific concerns. This stage establishes the boundaries and objectives of the work, and initialises the VIGIL site record that will carry all subsequent findings.
- Asset and operational profile documentation
- Stakeholder briefings
- Scope and methodology confirmation
- VIGIL site record initialised
Threat Environment Assessment
A tailored assessment of the threats that matter most — mapped to your geographic location, sector, and operational profile. Threat actors are identified and profiled across more than twenty distinct scenarios. Every source is named and confidence-rated through VIGIL's MCI framework.
- Threat actor identification and profiling
- Attack scenario development
- Geopolitical and crime trend analysis
- Threat likelihood rating · MCI applied
Vulnerability Assessment
On-site inspections combined with an operational audit — evaluating how people, security processes, and technology are actually deployed. Vulnerabilities are assessed in relation to the specific threats identified, not in isolation. All findings recorded with precision in the VIGIL record.
- Physical site inspection
- Security systems and technology review
- Personnel and procedural assessment
- Vulnerability severity rating · VIGIL scored
Risk Analysis & Prioritisation
Threat likelihood and vulnerability severity combined to produce a risk-ranked assessment using VIGIL's structured L×I methodology — transparent, auditable, and directly usable as the basis for resource allocation decisions. The Mission Suitability Index is produced at this stage.
- Risk matrix development
- Consequence and impact assessment
- MSI produced · Risk register finalised
- Stakeholder validation
Recommendations, Reporting & Site Record
Prioritised, proportionate mitigation measures — each linked to a specific risk finding — with implementation sequencing and budget guidance. Reports delivered in two layers: executive summary and full technical report. The VIGIL site record is finalised, establishing the reassessment baseline.
- Prioritised mitigation register
- Implementation roadmap
- Executive summary report
- Full technical report · Site Record finalised · Baseline set
What you receive
Every ARRC TVRA concludes with nine structured outputs — designed to serve different audiences and remain useful long after initial delivery.
Deliverable format and classification level are agreed at scoping stage. Outputs marked VIGIL are part of the structured site record.
Executive Summary Report
A concise, plain-language summary of key findings, risk priorities, and strategic recommendations — for boards, senior leadership, and external stakeholders.
Full Technical Assessment Report
A comprehensive technical document covering the full methodology, findings, evidence base, risk ratings, and detailed recommendations — for security and operations teams.
Mission Suitability Index (MSI) VIGIL
A structured suitability score across six assessment domains — a single, defensible verdict derived from evidence, not opinion.
Mission Confidence Index (MCI) VIGIL
A quantified confidence score reflecting the quality, recency, and corroboration of evidence behind the assessment. Stated explicitly — never hidden.
Risk Register VIGIL
A structured, risk-ranked register with L×I scoring — formatted for ongoing management and integration into enterprise risk frameworks.
Evidence Register VIGIL
Every source named, dated, and confidence-rated. The complete audit trail that makes findings defensible in any room, at any time.
Site Record & Reassessment Baseline VIGIL
The structured digital record of the site — auditable, transferable with the asset, and available as the baseline for every future reassessment.
Mitigation & Implementation Roadmap
A prioritised action plan mapping each recommendation to a risk finding, with indicative sequencing, complexity ratings, and budget guidance.
Findings Briefing & Post-Delivery Support
A structured verbal briefing covering key findings and recommendations. Followed by a defined period of post-delivery availability for clarification and follow-on scoping.
When to commission a TVRA
A TVRA is relevant at multiple points in the lifecycle of an asset or organisation — not only in response to a specific incident or concern. The earlier an assessment is conducted, the more durable the VIGIL site record becomes.
New Development or Acquisition
At feasibility or early design stage, before security requirements are embedded in the brief — ensuring protection is designed in rather than retrofitted at higher cost and lower effectiveness.
Periodic Review
As part of a regular security governance cycle — typically every two years. Reassessment against the VIGIL baseline makes change visible and intervention timely.
Change in Risk Profile
Following a significant operational change, expansion into a new geography, a change in the threat environment, or an incident that has revealed gaps in existing security arrangements.
Regulatory or Insurer Requirement
Where a TVRA is required as a condition of regulatory approval, insurance coverage, or a contract — and must meet a defined standard delivered by a recognised independent practitioner.
Pre-Investment Due Diligence
As part of the due diligence process for a real estate transaction, infrastructure investment, or operational joint venture — providing an independent view of security risk before commitment.
Security Investment Planning
When preparing a capital or operational security budget, to ensure investment decisions are grounded in a clear understanding of risk priority rather than vendor recommendations or internal assumptions.
Commission a TVRA powered by VIGIL.
Whether you are at the design stage of a new facility, reviewing an existing operation, or responding to a regulatory requirement — a TVRA from ARRC provides the evidence base your security decisions deserve. And the site record your organisation will rely on for years to come.
Initial conversations are obligation-free. We will discuss your situation, outline what a scoped assessment would involve, and provide an indication of timeline and cost before any commitment is made.