Assess Every Threat on Its Own Terms
A fire extinguisher reduces fire risk. It does nothing for a tornado. Circadian Risk models every threat scenario independently because the variables that drive risk, and the controls that reduce it, are different for every threat type.
Why a Single General Assessment Cannot Accurately Measure Physical Security Risk
Most physical security programs conduct one assessment per location. It covers all threats simultaneously, applies a common set of evaluation criteria across every risk type, and produces a single combined score or report. The problem is not the assessment itself. The problem is treating fundamentally different threats as if they are governed by the same variables.
The probability of an active shooter event at a given location is driven by factors like organizational controversiality, workforce size, termination patterns, and the emotional context of the surrounding community. The probability of a flood is driven by elevation, proximity to waterways, regional weather history, and drainage infrastructure. Measuring these disparate risk drivers with the same instrument does not produce a combined picture of risk. It produces a distortion of both. Circadian Risk was built on the premise that the only accurate way to model physical security risk is to assess each scenario independently, using the variables that actually drive that specific threat.
How Physical Risk Intelligence Works
Physical risk intelligence starts with a framework. Circadian Risk’s platform is built around three interconnected layers that take organizations from raw assessment data to a quantified, actionable risk score.
Threat Scenarios
Human-Initiated Risk Events. Threat scenarios involve deliberate human actions directed at a location, its people, or its assets. Each threat type has its own risk drivers, its own countermeasures, and its own probability profile that changes based on organizational and environmental characteristics.
Example scenarios include: active shooter, workplace violence, aggravated assault, theft and robbery, vandalism, arson, espionage, abduction, explosives, and executive protection.
Hazard Scenarios
Naturally Occurring and Environmental Risk. Hazard scenarios involve naturally occurring events or accidental incidents that expose a location to physical risk. Geographic location, climate, proximity to industrial facilities, and site-specific environmental conditions all drive inherent hazard risk.
Example scenarios include: tornadoes, hurricanes, floods, earthquakes, wildfires, severe winter weather, chemical spills, and nearby industrial hazards.
Compliance Scenarios
Regulatory and Standards-Based Risk Assessment. Compliance scenarios evaluate a location’s adherence to specific regulatory frameworks and industry standards. Each standard defines its own requirements, and compliance risk is assessed against those specific criteria rather than a generic security framework.
Example scenarios include: CT-PAT, PCI DSS, Joint Commission healthcare standards, ASIS International standards, including K-12 school security standards, and custom internal compliance frameworks.
What Scenario-Based Risk Modeling Makes Possible That General Assessments Cannot
Countermeasures That Actually Match the Threat
When risk is assessed scenario by scenario, the countermeasures evaluated are those that are relevant to that specific threat. Circadian Risk does not ask whether a location has a camera and count it toward every scenario equally. It asks whether the camera placement, coverage, and condition reduce risk for the specific scenario being assessed. The result is a controls assessment that reflects actual risk reduction rather than a simple asset inventory.
Risk Prioritization Across Scenarios, Not Just Across Locations
With scenario-specific scores for every location, security leaders can do something no general assessment makes possible: compare risk across scenarios as well as across locations. Which scenario represents the greatest exposure across the entire portfolio? Which locations are high-risk for multiple scenario types? Where should capital investment go to reduce the most risk across the most scenarios? These are the questions that drive a mature risk program, and they can only be answered when scenarios are modeled independently.
A Risk Program That Evolves as Threats Change
Because scenarios are modeled independently, adding a new scenario or updating an existing one does not require rebuilding the entire assessment framework. When a new compliance standard becomes relevant, when an emerging threat type needs to be tracked, or when organizational characteristics change in ways that affect a specific scenario’s risk profile, Circadian Risk can accommodate that change without disrupting the rest of the program.
Scenario Frameworks Built on ASIS International Standards
As a partner of ASIS International, Circadian Risk can convert any ASIS standard directly into a structured scenario assessment framework within the platform. This means organizations can assess scenario-specific risk using internationally recognized, professionally validated criteria rather than internally developed frameworks that may not hold up to regulatory or legal scrutiny. It is the only platform in the world with this capability.
A Scenario Library Built for the Full Range of Physical Security Risk
Circadian Risk supports scenario-based modeling across threats, hazards, and compliance frameworks, covering the risks that matter most to security leaders across every industry and location type.
Threats:
- Active Shooter
- Workplace Violence
- Aggravated Assault
- Theft and Robbery
- Vandalism
- Arson
- Espionage
Hazards:
- Tornado
- Hurricane
- Flood
- Earthquake
- Wildfire
- Severe Winter Weather
- Chemical Spill
Compliance:
- CT-PAT
- PCI DSS
- Joint Commission
- K-12 School Security
- ASIS Physical Asset Protection
- Custom Internal Standards
Scenario-Based Scoring Tells You Where Risk Is. Remediation Workflows Tell You What to Do About It.
Once every scenario has been independently assessed and scored, Circadian Risk’s Risk Remediation Workflows convert every deficiency into a trackable, assignable task connected directly to its impact on the residual risk score. Remediation is prioritized by scenario, by location, and by the magnitude of risk reduction each action will produce.
Frequently Asked Questions About Scenario-Based Physical Security Risk Modeling
What is scenario-based risk modeling in physical security?
Scenario-based risk modeling is the practice of assessing physical security risk independently for each specific threat type rather than through a single general assessment. Each scenario, whether a threat event like workplace violence, a natural hazard like a flood, or a compliance framework like PCI DSS, is evaluated using its own set of probability and severity variables. The result is a risk score that accurately reflects the actual drivers of that specific threat rather than a blended score that obscures the differences between fundamentally different risk types.
Why does Circadian Risk assess each scenario separately instead of using a combined assessment?
Because the variables that drive risk are different for every scenario type. An active shooter risk assessment is driven by organizational and human factors. A flood risk assessment is driven by geographic and environmental factors. Combining them into a single assessment either averages out the differences or applies irrelevant criteria to one or both scenarios. Circadian Risk assesses each scenario independently so that probability and severity scores are accurate, countermeasure evaluations are relevant, and residual risk scores reflect the actual state of exposure for each specific threat.
What scenarios does Circadian Risk support?
Circadian Risk supports scenario-based modeling across three categories: threat scenarios including active shooter, workplace violence, theft, vandalism, arson, espionage, and more; hazard scenarios including tornadoes, floods, hurricanes, earthquakes, and industrial hazards; and compliance scenarios including CT-PAT, PCI DSS, Joint Commission healthcare standards, and ASIS International standards, including K-12 school security. The platform also supports custom scenarios built to an organization’s own standards or internal frameworks.
Can organizations add their own custom scenarios to the platform?
Yes. Circadian Risk is fully customizable. Organizations can build custom scenarios using their own variables, frameworks, and evaluation criteria. Circadian Risk’s client success team works with each organization to configure scenarios that reflect their specific risk environment and operational requirements.
See Scenario-Based Physical Security Risk Modeling in Action
Walk through Circadian Risk’s scenario-based risk modeling with a member of our team. See how your organization’s threat, hazard, and compliance risk profiles would look when every scenario is assessed independently and scored on a common, comparable scale.