ARRC Global
Protective Security & Resilience

Threat-Vulnerability-Risk Assessment

Every TVRA answers one question: can this site safely support its intended mission? ARRC conducts TVRAs using VIGIL — our evidence-driven assessment platform that combines structured methodology, multi-source intelligence, and transparent confidence scoring to produce assessments that are consistent, auditable, and repeatable.

Because critical decisions deserve more than static reports.

Traditional TVRA
VIGIL-powered TVRA
— Static PDF report
Structured PDF + Evidence Register
— Consultant's judgement
MSI — scored across six domains
— Risk narrative
MCI — confidence quantified per source
— Findings in a document
Risk Register with L×I scoring
— No baseline established
Site Record — auditable & transferable
— Point-in-time only
MRI — 20-year trajectory assessed
— Finding belongs to consultant
Finding belongs to the methodology
Powered by VIGIL

ARRC is the practitioner.
VIGIL is the platform.

Security investments made without a clear understanding of what you are protecting against — and where you are genuinely exposed — are rarely proportionate, and frequently misallocated.

A TVRA establishes that foundation. Every ARRC TVRA is conducted through VIGIL — transforming the assessment from a standalone report into a structured digital record where evidence, assumptions, confidence levels, and site characteristics remain connected long after the engagement concludes.

TVRA is one application of VIGIL. VIGIL defines what a modern TVRA should be.

"Every security conversation eventually comes back to the same question: what are you actually trying to protect against? A TVRA answers that question with rigour. VIGIL ensures the answer remains available, auditable, and useful long after the report has been delivered."

— ARRC Global, Practice Philosophy

What a TVRA was always supposed to answer.

The question was always right. What broke down — consistently, across the industry — was what happened to the answer after it was delivered.

Traditional assessments captured one moment, filed a report, and left — without a baseline, without auditable evidence, without a way to answer: "Would we make the same decision today?"

📄 The finding lived in a document

The assessment was delivered as a PDF. Filed. The team changed. Assumptions were forgotten. The environment evolved. The finding remained — static, disconnected, and increasingly irrelevant.

"The report aged. The risk didn't."

👤 The finding belonged to the consultant

Two qualified practitioners, same site, same information — different conclusions. Neither could be challenged against the other. When the consultant left, the rationale left with them.

"The finding was personal, not institutional."

❓ Confidence was never measured

A conclusion backed by six data points was presented with the same authority as one backed by sixty. There was no mechanism to ask how much confidence to place in a finding — or receive a quantified answer.

"Uncertainty was hidden, not disclosed."

⏱️ Point-in-time, not lifecycle

The assessment captured one moment. Infrastructure evolved, threats adapted, the environment changed. The original finding could not be revisited against a baseline — because no baseline had been structured.

"Would we make the same decision today? Nobody could answer."

📊 Traditional outputs vs VIGIL outputs

Traditional: PDF · Risk Register · Roadmap

VIGIL-powered: PDF · Evidence Register · MSI · MCI · MRI · Risk Register · Site Record · Reassessment Baseline

Finding belongs to the methodology.

Not the consultant. Not the report. The finding is institutional, reproducible, and auditable. Same site, same evidence, same framework — same result. The assessment survives personnel change and stands up in any room.

How VIGIL changes TVRA

The methodology was always sound. VIGIL makes it durable.

Every ARRC TVRA conducted through VIGIL produces a structured digital record — not just a report. The finding becomes institutional, not personal.

🔁

Reproducible findings

Anchor statement methodology generates scores from evidence, not judgement alone. Same site, same evidence, same framework — same result. The finding survives personnel change and consultant rotation.

🎯

Confidence measured, not assumed

The Mission Confidence Index (MCI) quantifies the quality, recency, and corroboration of evidence behind every finding. A high-confidence assessment and a provisional one are explicitly and visibly different.

🔗

Evidence trail built in

Every indicator carries a named source, a recorded date, and the basis for the conclusion. The evidence trail is created at assessment — never reconstructed when scrutiny arrives.

📈

Trajectory, not just snapshot

The Mission Resilience Index (MRI) projects where the site is heading — accounting for infrastructure evolution, threat trajectory, and regulatory change over a 20-year horizon.

What a TVRA examines

A credible TVRA operates across three interconnected dimensions — each informing the other, and none sufficient on its own.

Our methodology draws on internationally recognised frameworks — including ASIS, ISO 31000, and government-sector risk guidance — adapted to the specific context of each engagement. All delivered through VIGIL.

🔭

Threat Analysis

Identification and characterisation of the threat actors, attack methodologies, and threat scenarios that are credible in the context of your organisation, location, and sector. Assessment is intelligence-led, drawing on open-source, sector-specific, and where available, proprietary threat data — all confidence-rated through VIGIL.

🔍

Vulnerability Assessment

A structured examination of the weaknesses that exist across your physical security measures, access control systems, personnel and visitor management practices, procedural controls, and security culture. Vulnerabilities are assessed in relation to the specific threats identified — not in isolation.

📊

Risk Evaluation & Prioritisation

Combination of threat likelihood and vulnerability severity to produce a risk-ranked picture of your security exposure using VIGIL's structured L×I methodology — transparent, auditable, and directly usable as the basis for resource allocation decisions.

🗺️

Mitigation Recommendations

Practical, proportionate security measures mapped to specific risks — covering physical countermeasures, technology systems, procedural improvements, and organisational changes. Sequenced by priority with indicative cost ranges and implementation complexity.

Powered by VIGIL

The platform isn't replacing TVRA.
It's elevating it.

Traditional TVRAs are delivered as standalone reports. The intelligence that produced them — the sources, the assumptions, the confidence behind each finding — exists in the consultant's notes, if at all.

VIGIL transforms the assessment into a structured digital record where evidence, assumptions, confidence levels, and site characteristics remain connected long after the report has been delivered. Your assessment becomes easier to revisit, compare, and build upon as the operating environment evolves.

"TVRA is one application of VIGIL. VIGIL defines what a modern TVRA should be."

VIGIL TVRA — Full Output Set

PDF Assessment Report
Executive summary + full technical report
Evidence Register
Every source named, dated, and confidence-rated
Mission Suitability Index (MSI)
Scored across six assessment domains
Mission Confidence Index (MCI)
Evidence quality quantified per indicator
Mission Resilience Index (MRI)
20-year trajectory assessment
Risk Register
Prioritised, L×I scored, directly actionable
Site Record
Auditable — transferable with the asset
Reassessment Baseline
Foundation for every future engagement

ARRC Assessment Methodology

A structured five-stage process, applied consistently across all engagements whilst remaining fully adaptable to the specific nature, scale, and complexity of each site. All stages powered by VIGIL.

Engagements typically span one to four weeks depending on site complexity, geographic locations to cover, and reporting requirements.

01

Context & Scoping

We begin by developing a detailed understanding of your organisation — its assets, operations, stakeholder obligations, regulatory environment, and specific concerns. This stage establishes the boundaries and objectives of the work, and initialises the VIGIL site record that will carry all subsequent findings.

  • Asset and operational profile documentation
  • Stakeholder briefings
  • Scope and methodology confirmation
  • VIGIL site record initialised
02

Threat Environment Assessment

A tailored assessment of the threats that matter most — mapped to your geographic location, sector, and operational profile. Threat actors are identified and profiled across more than twenty distinct scenarios. Every source is named and confidence-rated through VIGIL's MCI framework.

  • Threat actor identification and profiling
  • Attack scenario development
  • Geopolitical and crime trend analysis
  • Threat likelihood rating · MCI applied
03

Vulnerability Assessment

On-site inspections combined with an operational audit — evaluating how people, security processes, and technology are actually deployed. Vulnerabilities are assessed in relation to the specific threats identified, not in isolation. All findings recorded with precision in the VIGIL record.

  • Physical site inspection
  • Security systems and technology review
  • Personnel and procedural assessment
  • Vulnerability severity rating · VIGIL scored
04

Risk Analysis & Prioritisation

Threat likelihood and vulnerability severity combined to produce a risk-ranked assessment using VIGIL's structured L×I methodology — transparent, auditable, and directly usable as the basis for resource allocation decisions. The Mission Suitability Index is produced at this stage.

  • Risk matrix development
  • Consequence and impact assessment
  • MSI produced · Risk register finalised
  • Stakeholder validation
05

Recommendations, Reporting & Site Record

Prioritised, proportionate mitigation measures — each linked to a specific risk finding — with implementation sequencing and budget guidance. Reports delivered in two layers: executive summary and full technical report. The VIGIL site record is finalised, establishing the reassessment baseline.

  • Prioritised mitigation register
  • Implementation roadmap
  • Executive summary report
  • Full technical report · Site Record finalised · Baseline set

What you receive

Every ARRC TVRA concludes with nine structured outputs — designed to serve different audiences and remain useful long after initial delivery.

Deliverable format and classification level are agreed at scoping stage. Outputs marked VIGIL are part of the structured site record.

📋
Executive Summary Report

A concise, plain-language summary of key findings, risk priorities, and strategic recommendations — for boards, senior leadership, and external stakeholders.

📁
Full Technical Assessment Report

A comprehensive technical document covering the full methodology, findings, evidence base, risk ratings, and detailed recommendations — for security and operations teams.

📊
Mission Suitability Index (MSI) VIGIL

A structured suitability score across six assessment domains — a single, defensible verdict derived from evidence, not opinion.

🎯
Mission Confidence Index (MCI) VIGIL

A quantified confidence score reflecting the quality, recency, and corroboration of evidence behind the assessment. Stated explicitly — never hidden.

⚠️
Risk Register VIGIL

A structured, risk-ranked register with L×I scoring — formatted for ongoing management and integration into enterprise risk frameworks.

📂
Evidence Register VIGIL

Every source named, dated, and confidence-rated. The complete audit trail that makes findings defensible in any room, at any time.

🏛️
Site Record & Reassessment Baseline VIGIL

The structured digital record of the site — auditable, transferable with the asset, and available as the baseline for every future reassessment.

🗓️
Mitigation & Implementation Roadmap

A prioritised action plan mapping each recommendation to a risk finding, with indicative sequencing, complexity ratings, and budget guidance.

💬
Findings Briefing & Post-Delivery Support

A structured verbal briefing covering key findings and recommendations. Followed by a defined period of post-delivery availability for clarification and follow-on scoping.

When to commission a TVRA

A TVRA is relevant at multiple points in the lifecycle of an asset or organisation — not only in response to a specific incident or concern. The earlier an assessment is conducted, the more durable the VIGIL site record becomes.

New Development or Acquisition

At feasibility or early design stage, before security requirements are embedded in the brief — ensuring protection is designed in rather than retrofitted at higher cost and lower effectiveness.

Periodic Review

As part of a regular security governance cycle — typically every two years. Reassessment against the VIGIL baseline makes change visible and intervention timely.

Change in Risk Profile

Following a significant operational change, expansion into a new geography, a change in the threat environment, or an incident that has revealed gaps in existing security arrangements.

Regulatory or Insurer Requirement

Where a TVRA is required as a condition of regulatory approval, insurance coverage, or a contract — and must meet a defined standard delivered by a recognised independent practitioner.

Pre-Investment Due Diligence

As part of the due diligence process for a real estate transaction, infrastructure investment, or operational joint venture — providing an independent view of security risk before commitment.

Security Investment Planning

When preparing a capital or operational security budget, to ensure investment decisions are grounded in a clear understanding of risk priority rather than vendor recommendations or internal assumptions.

Commission a TVRA powered by VIGIL.

Whether you are at the design stage of a new facility, reviewing an existing operation, or responding to a regulatory requirement — a TVRA from ARRC provides the evidence base your security decisions deserve. And the site record your organisation will rely on for years to come.

Initial conversations are obligation-free. We will discuss your situation, outline what a scoped assessment would involve, and provide an indication of timeline and cost before any commitment is made.

Liked what you encountered? Let's connect
Contact Us →