Product vs risk assessment

1 January 2016 Security Services & Risk Management

An unfortunate reality that needs to be recognised is that many security companies actually use the security risk assessment as a sales boosting gimmick and this is not always to the benefit of the unsuspecting end-user. A lesser known fact is that this service, which is either provided dirt cheap or even for free, is not an independent security risk assessment but merely a product assessment. Remuneration and commission is made on the sales of the hardware purchased and installed or other services that the client signs up for. In this case, the assessor is simply a salesman.

When reviewing a site, the assessor-salesman will have a checklist through which he determines which products from his inventory can be installed and where. Furthermore, these solutions are generally predetermined prior to the inspection on what the consultant feels the client can comfortably afford.

The problem here lies in the fact that sometimes there may be certain weaknesses within the client’s physical security that the assessor’s limited stock cannot always remedy. The result is that the salesman does not reveal this to the client so that the sale is not lost and, more often than not, the end user only realises there is a problem after he has already had the system installed. Additionally, the advisor does not always have the relevant knowledge in terms of the actual functionality of his product, only the specification sheet. Most of the clients do not have a security background and simply accept the quotation spreadsheet without understanding what this entails or what he is paying for.

Successful security cannot be based on guesswork. An independent risk assessor visits the site blind and only once all the threats and vulnerabilities have been revealed in full does he begin to consider possible solutions. It should further be noted that the independent security risk assessment encompasses many different facets with respect to the client’s security status and not just hardware. Some of these elements are intangible and not even considered by the salesman-assessor despite the fact that these directly influence the overall security status.

The independent is focused on the functionality of hardware components and when providing the client with a complete security plan covering all interrelated elements of a good security system, he will recommend items generically. The client is provided with a highly detailed report clearly explaining what is required for his security system and how it works.

No quotation with item codes and prices listed is ever handed to the client, who decides in the end which specific brand he would like to purchase as he will have the understanding through the assessment of what is needed. In the event that the independent does supply a specific model or make, it is only because his team’s extensive research has shown that this particular item outshines others in its category, but the independent will ensure that his client understands exactly what the product’s pros and cons are.

For more information contact Alwinco, +27 (0)74 222 0284, dianne@alwinco.co.za, www.alwinco.co.za



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
Making a mesh for security
Information Security Security Services & Risk Management
Credential-based attacks have reached epidemic levels. For African CISOs in particular, the message is clear: identity is now the perimeter, and defences must reflect that reality with coherence and context.

Read more...
Privacy by design or by accident
Security Services & Risk Management Infrastructure
Africa’s data future depends on getting it right at the start. If privacy controls do not withstand real-world conditions, such as unstable power, fragile last-mile connectivity, shared devices, and decentralised branch environments, then privacy exists only on paper.

Read more...
From friction to trust
Information Security Security Services & Risk Management Financial (Industry)
Historically, fraud prevention has been viewed as a trade-off between robust security and a seamless customer journey, with security often prevailing. However, this can impair business functionality or complicate the customer journey with multiple logins and authentication steps.

Read more...
Security ready to move out of the basement
AI & Data Analytics Security Services & Risk Management
Panaseer believes that in 2026, a board member at a major corporation will lose their job amid rising breaches and legal scrutiny, as organisations recognise that cyber risk is a business risk that CISOs cannot shoulder alone.

Read more...
Cyber remains top business risk, but AI fastest riser at #2
News & Events Security Services & Risk Management
The Allianz Risk Barometer 2026 ranks cybersecurity, especially ransomware attacks, as the #1 risk, while AI is the biggest riser and jumps from #10 to #2, highlighting the emerging risks for companies in almost all industry sectors.

Read more...
OT calculator to align cyber investments with business goals
Industrial (Industry) Information Security Security Services & Risk Management
The OT Calculator has been developed specifically for industrial organisations to assess the potential costs of insufficient operational technology (OT) security. By offering detailed financial forecasts, the calculator empowers senior management to make well-informed decisions.

Read more...
From digital transformation to digital sovereignty
Security Services & Risk Management IoT & Automation
As cyberthreats grow, data regulations tighten, and AI becomes central to economic competitiveness, countries are recognising the need to control and protect their own digital assets.

Read more...
The age of Lean 4.0: Orchestrating intelligence and efficiency
Security Services & Risk Management
The convergence of Lean principles and AI (what we now call Lean 4.0) is no longer a theoretical exercise; it is the defining operational paradigm for survival and growth in a complex, data-intensive economy.

Read more...
Risks of open-source intelligence escalating in crime
Security Services & Risk Management Residential Estate (Industry) Smart Home Automation
CMS estimates that open-source intelligence has played a role in 20 - 30% of robberies over the past 12 months. In cybercrime, global research consistently shows that many offences rely on some form of open-source data exploitation.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.