Public Profile, Public Exposure: Why Threat, Risk and Vulnerability Assessments Matter in Politics
Politics has always carried risk.
Today, however, the threat landscape facing politicians and politically exposed individuals is broader, more accessible and more complex than ever before. Physical threats, cyber attacks, hostile reconnaissance, online abuse, insider threats, disinformation campaigns and foreign influence activity all exist alongside the traditional risks associated with public life.
Yet one of the greatest vulnerabilities we encounter is not technology, infrastructure or procedure.
It is the belief that “it won’t happen to me.”
Most security failures occur not because the threat was unforeseeable, but because organisations and individuals assumed they were not important enough, controversial enough or visible enough to become a target.
Unfortunately, threat actors do not always think the same way.
Effective protective security begins with understanding three simple questions:
Understanding Threat, Vulnerability and Consequence
- Who might target me and why?
- How could they reach me?
- What would happen if they succeeded?
Threat, Risk and Vulnerability Assessments
These terms are often used interchangeably, but they describe very different parts of the security picture.
Threat Assessment – Who could cause harm and why?
A Threat Assessment focuses on identifying the people, groups or events that could cause an attack, incident or disruption.
This includes understanding:
- Who the potential threat actors are.
- Their aims and motivations.
- Their capability and resources.
- Their intent to act.
- Their preferred methods of operation.
For a political figure, potential threat actors may include fixated individuals, extremists, activists, hostile states, organised crime groups, disgruntled insiders or opportunistic criminals.
Understanding both capability and intent is essential. A highly capable adversary with little interest in a target may present a lower threat than an individual with limited capability but a strong personal grievance and determination to act.
Vulnerability Assessment – How could they reach you?
A Vulnerability Assessment examines the weaknesses, gaps and opportunities that would allow a threat actor to gain access to their target or achieve their objective.
This considers:
- Physical security weaknesses.
- Predictable routines and travel patterns.
- Poor access control.
- Residential vulnerabilities.
- Insider access.
- Weak cyber security controls.
- Excessive information available online.
- Family and associate exposure.
In simple terms, the Vulnerability Assessment asks:
“If someone wanted to target me, how would they do it?”
Examples might include known travel routes, publicly advertised appearances, unsecured side gates, poor visitor management procedures or social media posts that reveal location, lifestyle or routines.
Risk Assessment – What is the likelihood of success and what would the consequences be?
Risk is created when a capable and motivated threat actor is presented with an opportunity to exploit a vulnerability.
The Risk Assessment considers:
- The capability and motivation identified in the Threat Assessment.
- The opportunities identified in the Vulnerability Assessment.
- The potential consequences if the attack or incident were successful.
For example, a politician who has attracted hostile attention online, follows highly predictable travel routines and regularly leaves residential access points unsecured may face a significantly higher level of risk than someone with a similar public profile but stronger protective measures and lower predictability.
What Should a Robust Threat, Risk and Vulnerability Assessment Include?
A comprehensive assessment should examine:
- Public profile and visibility
- Political affiliations and policy positions
- Physical exposure through events, travel and public engagements
- Online presence and digital footprint
- Family members and close associates
- Staff, volunteers and insider risks
- Residential security arrangements
- Travel patterns and routines
- Similar incidents against others
- Existing protective measures
- The potential consequences of an incident
Importantly, these assessments should not be viewed as a one-off exercise.
Political events, media attention, elections, controversial policy decisions and geopolitical developments can alter an individual’s threat profile rapidly. Effective protective security therefore relies on regularly reviewing assumptions, reassessing risks and adapting protective measures as circumstances change.
Risk is rarely static.
Political events, elections, controversial legislation, media attention and geopolitical developments can alter an individual’s threat profile almost overnight. An assessment conducted several years ago and filed away in a drawer provides little reassurance when circumstances change.
Threat assessments should therefore be reviewed regularly and updated whenever there is a significant change in profile, role or exposure.
Professional Threat Monitoring Matters
Protective security should never rely solely on reacting to incidents after they occur.
Professional threat monitoring allows organisations and individuals to identify warning signs before escalation occurs.
This may include:
- Monitoring hostile rhetoric and online discussion.
- Identifying fixation behaviours.
- Detecting hostile reconnaissance.
- Monitoring geopolitical developments.
- Identifying emerging activist or extremist interest.
- Understanding foreign influence activity.
- Tracking reputational threats and misinformation.
For many incidents, warning signs exist long before the event itself.
The challenge is recognising them.
Security is a Capability, not a Product
Installing CCTV cameras, alarms and access control systems does not automatically create security.
Security is the combination of people, procedures, technology and behaviour working together effectively.
One of the most overlooked aspects of protective security is practising responses to foreseeable incidents.
Consider the following questions:
- What would you do if someone entered your home unexpectedly?
- How would your family respond?
- Is there a safe room or rendezvous point?
- What would happen if an altercation developed at a venue you regularly visit?
- Does your staff team understand escalation procedures?
- Who contacts emergency services and who manages family members?
Emergency procedures are rarely effective if they are being considered for the first time during the emergency itself.
The military, emergency services and security professionals train repeatedly because performance under stress depends on familiarity and repetition.
Predictability Creates Opportunity
Threat actors value predictability.
The same school route every morning.
The same coffee shop every Friday.
The same arrival entrance at every event.
The same running route posted repeatedly on social media.
Patterns create opportunity.
Varying routes, timings and routines does not need to become disruptive or intrusive, but introducing unpredictability significantly increases the difficulty for anyone conducting hostile reconnaissance or planning an attack.
Recognising Surveillance
Most people assume surveillance is obvious.
In reality, effective surveillance is designed specifically not to be noticed.
Understanding the indicators of physical hostile surveillance can provide valuable early warning.
Examples may include:
- Repeated sightings of the same individual or vehicle
- Individuals appearing in locations where there is no obvious reason for them to be present.
- Unusual interest in routines, schedules or movements.
- Photography or recording activity focused on entrances, vehicles or family members.
- Persistent online engagement that escalates in frequency or intensity.
- Suspicious behaviour, things that are not normal
Awareness training is often one of the simplest and most effective investments available to public figures and their families.
Equally important is understanding where your nearest police station or safe place is located and how to reach it quickly if you believe you are being followed or at risk.
Simple actions can often interrupt the decision cycle of an adversary and provide valuable time for law enforcement intervention.
Security Controls Must Be Tested
One of the biggest mistakes organisations make is assuming that because a control exists, it works. Another is having security at the workplace but assuming at home there is no risk. Adversaries will often take the path of least resistance.
Security controls should be tested and should not stop at the outer perimeter of a workplace.
Physical Penetration Testing goes further by assessing how an adversary would actually attempt to bypass security measures.
This may involve testing:
- How easy staff and executives are to follow home
- Access control, at work and at home
- Workplace visitor management and tailgating vulnerabilities
- Insider threat exposure (workplace and domestic staff)
- Staff challenge culture
- Physical barriers
- Alarm response procedures
- Security officer responses
Real adversaries do not follow audit checklists.
Security testing should reflect real-world methods, behaviours and attack paths.
Technology Choices Matter
Technology is increasingly central to modern security programmes, but not all technology offers equal security.
CCTV, access control systems, network video recorders, smart home devices and other connected technologies should be sourced from reputable manufacturers with transparent supply chains and strong security practices. They should be installed and configured by companies with a security approach, not just a technical one.
It is important to understand:
- Where equipment is manufactured
- Ownership structures and legal obligations of suppliers
- Software support arrangements
- Patch management processes
- Data storage locations
- Known vulnerabilities and exposure history
Poorly secured technology can transform a protective measure into an attack vector.
Other important considerations include risks around electric vehicle and wearable technology choices, although each of these requires a blog of their own
Security Is a Continuous Process
The reality is that no individual, organisation or public figure can eliminate risk entirely.
The objective is not to eliminate every possible threat or pursue security at any cost.
The objective is to understand the threat, identify and reduce vulnerabilities, prepare for foreseeable scenarios and ensure that protective measures continue to perform when they are needed most.
Equally important is ensuring decisions are driven by evidence rather than assumption. Robust Threat, Risk and Vulnerability Assessments provide the information required to make informed, proportionate decisions about security investment, operational procedures and protective measures.
Sometimes that decision will be to implement additional mitigations. Sometimes it will be to accept the risk.
Both are valid outcomes, provided they are informed decisions based upon an understanding of the threat, the vulnerabilities that exist and the potential consequences should an incident occur.
The question should never be:
“Will this happen to me?”
A better question is:
“If it happened tomorrow, am I prepared to detect it, respond appropriately and protect what matters most?”




