Page 14 - CITS Theft Guide
P. 14
CITS Guide for Theft Prevention
- 14 -
4.2. Stage 2 — Adversarial Threat Assessment
The team identifies potential threat actors — for example the terrorist, the activist or protestor, the
criminal, or the insider — and asks why each might be interested in the asset. For each identified actor,
the team should establish intent, motivation, capability, and attack methodology (modus operandi),
drawing where possible on whether the organisation, or a similar one, has been attacked before. Good
practice summarises this stage as the discipline to "think like your enemy," and requires the team to
consider both physical and cyber attack routes, consistent with Section 8 of this guide. Current reporting
(see Annex A) indicates that organised groups increasingly use drone reconnaissance to identify high-value
assets and access points before an attack, and are willing to disable telematics and tracking devices before
removing plant from site, so this assessment should be kept current rather than treated as a one-off
exercise.
Stage outcome (products)
(a) A list of people or groups (adversaries) who might attack the asset.
(b) Their motivations and capabilities.
(c) Their attack methodologies.
(d) Their strengths.
4.3. Stage 3 — Vulnerability Analysis
The team examines what security arrangements, planned or existing, are already in place, and identifies
the vulnerabilities — the gaps or weaknesses — within them. The critical step is to match each adversary's
strengths and attack methodology, identified in Stage 2, against these vulnerabilities: how exposed is the
critical asset to this threat actor and their particular method of attack, considering both physical and cyber
routes? This matching exercise is what distinguishes an adversarial vulnerability analysis from a generic
site survey, and it is where the site's perimeter, lighting, access control, and cyber hygiene (see Sections 5
and 8) are tested against a specific, credible adversary rather than assessed in the abstract.
Stage outcome (products)
(a) An understanding of the current security arrangements.
(b) A list of vulnerabilities (gaps) in the current security arrangements that could be exploited by the threat
(adversary).
4.4. Stage 4 — Adversarial Risk Assessment
The team assesses what adversarial risks the identified threat actors present — for example cyber-attack,
sabotage, theft, or damage — and drafts representative risk statements, building a risk register specific to
the asset or process in question. Each risk is scored as likelihood multiplied by consequence, using a proven
risk assessment tool to produce an unmitigated risk score, giving the review team and the Senior Risk
Owner a shared, defensible understanding of the risk rather than a subjective impression.
As an illustration, a representative risk statement might read: "Due to the lack of control at the entrance
of the work area there is an increased risk that unknown person(s) can sabotage installed equipment,
rendering it unusable. This could impact commissioning, increase cost, or delay production, and lead to
reputational damage," scored as a likelihood of 5 and a consequence of 3, giving a risk score of 15 —
categorised as High. The table below reproduces this example.

