Site icon GM Group Services

Threat Assessment Guide: 7 Practical Steps for Safer Events

threat assessment safety guide

Threat assessment starts with a practical question: what could happen here, to these people, under these conditions, and what would we do next? On a Wednesday afternoon, that might mean a site supervisor reviewing an unsecured delivery gate at a construction project. For a festival organiser, it might mean checking whether a protest has been announced near the main entrance, whether ticketing systems can fail, or whether crowd movement changes after alcohol service begins.

A useful threat assessment turns intelligence, site conditions, and operational judgement into controls that people can use. It identifies likely threats, exposed assets, vulnerabilities, consequences, and response actions. The seven steps below are designed for events, venues, corporate sites, retail environments, and construction projects across NSW, VIC, QLD, and the ACT.

Why Threat Assessment Matters More Than Ever in 2026

A festival organiser discovers a coordinated protest has been planned outside the venue only hours before doors open. The protest appears peaceful, but the route affects the queue, a vehicle access lane and the public entrance. There's no alternative screening point, no agreed liaison officer and no briefing for security staff. The team now has to improvise under pressure, while patrons, performers, police and nearby businesses all need clear information.

That situation is exactly why a threat assessment isn't a binder on a shelf. It's a living operational document that maps who might target an event, venue or worksite, how they could act, which vulnerabilities they might exploit and what the consequences would be. It also assigns ownership, controls and escalation points before the situation becomes urgent.

Australia's national terrorism threat level moved from POSSIBLE to PROBABLE on 12 September 2024. Official guidance defines PROBABLE as a greater than fifty per cent chance of an onshore attack or attack planning within the next twelve months, as explained by the Australian National Security website. The change reflected a degrading security environment and reset the baseline for public-facing operations.

Practical rule: National threat settings don't tell a site supervisor exactly what will happen. They tell the supervisor that local intelligence, documented judgement and tested controls can't be treated as optional.

The wider security picture is also broader than terrorism. The 2024 Annual Threat Assessment stated that threats to Australia's way of life had surpassed terrorism as the principal security concern, while espionage and foreign interference were assessed at the highest level, CERTAIN, in the same national guidance. A sound assessment therefore considers protest, violence, cyber disruption, disinformation, supply interruption, insider activity and reputational harm alongside terrorism.

The cost of skipping the process is often operational confusion, delayed decisions and controls that arrive after the crowd has formed. The time required to identify scenarios, inspect the site, score the risks and brief the team is modest by comparison. The remaining sections provide a practical seven-step approach.

Gathering Pre-Event Intelligence and Context

Start with the event, not the spreadsheet. Write down the date, operating hours, venue footprint, performers or speakers, expected audience profile, alcohol arrangements, access points, transport links, neighbouring sites and any recent change that could affect behaviour or vulnerability.

An operations lead can gather useful information in a single afternoon, but the process needs discipline.

Build an intelligence picture

Use open sources to identify signals, not to confirm assumptions. Check social media platforms, local community pages, Google News alerts and publicly visible extremist or activist forums for references to the venue, event name, performers, speakers, organisers and relevant issues. Look for planned protests, calls for disruption, hostile commentary, suspicious interest in access arrangements and false information that could cause confusion at the gate.

The presence of online discussion isn't proof of intent. Record the original post, date, platform, account context and exact relevance to the event. Separate a direct call to attend from speculation, sarcasm or recycled material.

Liaison adds context that open-source monitoring can't provide. Contact the relevant local police area command, state policing command intelligence unit, venue management, neighbouring businesses and council event liaison officers where council-controlled land is involved. Ask what information they can share about planned activity, road impacts, nearby events, known access constraints and escalation contacts. Don't expect police to provide sensitive intelligence or guarantee a risk-free operation. The likely outcome may be confirmation that no shareable information is available, or a request for your event plan and contact details.

Record confidence and deadlines

A threat assessment should show how each finding was handled. A simple register can include:

Set a cut-off date for new intelligence before go-live, then define what happens if credible information arrives afterwards. A late update might trigger a revised briefing, altered entry arrangements, a police liaison call or a decision to pause operations. Without a cut-off and escalation rule, teams either ignore late information or overreact to every rumour.

The ASIO Threat Assessment Centre framework supports jurisdictions and special-event planning by assessing the likelihood and possible nature of terrorism and protest violence. Site operators still need to translate that higher-level context into local controls and a traceable decision record.

Conducting a Thorough Site Survey

A site survey should be completed on foot, not by relying on an old venue plan or a satellite image. Walk the location at the same time of day, and where possible under similar lighting, traffic and weather conditions to the event. A space that looks straightforward during a quiet morning can behave very differently during evening arrivals, wet weather or a high-volume delivery window.

Begin at the public edge and follow the patron journey. Inspect queue lanes, bag-check zones, vehicle screening points, ticket validation areas and points where several streams merge. Note where a queue could block an emergency route, where a person can bypass screening, and where staff would struggle to see the next section of the line.

Follow the less visible routes

Back-of-house areas often carry more exposure than the main entrance. Check delivery docks, staff entries, plant rooms, waste zones, temporary structures, contractor parking and equipment storage. Confirm who holds keys, who can authorise access and how an unfamiliar contractor is challenged without creating an unnecessary confrontation.

Adjacent sites belong in the assessment because they can affect your operation. Review neighbouring buildings, public transport nodes, car parks, laneways, raised positions and areas with limited natural surveillance. A nearby loading area may provide concealment, while a public transport interchange may create a crowd surge unrelated to your event.

Map the crowd and the blind spots

Mark the places where density monitoring matters most, including:

Document lighting gaps, signage that directs people towards a closed route, CCTV blind spots between towers and dark zones behind vendor sheds. Check whether cameras show faces, hands, vehicle approaches and queue behaviour, rather than merely recording a wide image of the area.

The survey should produce an annotated site plan, photo log, perimeter map and written survey notes. Those artefacts give the risk matrix evidence instead of leaving the assessment dependent on someone's memory. Australia's critical infrastructure guidance recommends identifying critical nodes, possible threats, vulnerabilities, consequences, attack methods and off-site interdependencies before selecting mitigation measures, as set out in the national critical infrastructure protection guidelines.

Scoring Threats With a Practical Risk Matrix

Gut feel is useful during the first conversation, but it isn't enough for a defensible decision. A risk matrix gives different supervisors a common language and makes handovers clearer. The method used by NSW Police is modelled on the Australian and New Zealand risk management standard, AS/NZS ISO 31000:2009, according to the NSW Counter Terrorism Plan record.

Use likelihood on one axis and consequence on the other. The likelihood scale runs from rare to almost certain. Consequence runs from insignificant to catastrophic. Before assigning a rating, define what consequence means across safety, reputation, operations and legal exposure, so one shift doesn't call a serious disruption “minor” because nobody was injured.

Apply the matrix consistently

Likelihood Insignificant Minor Moderate Major Catastrophic
Rare Low Low Low Moderate High
Unlikely Low Low Moderate High High
Possible Low Moderate Moderate High Extreme
Likely Moderate Moderate High Extreme Extreme
Almost certain Moderate High High Extreme Extreme

Consider four common scenarios. A crowd crush at a festival main stage may rate likely and major, producing an extreme inherent risk where entry pressure, poor egress or performer timing create credible conditions. A hostile actor with an improvised weapon may be possible and major, making the inherent rating high. A vehicle ramming attempt at an unprotected venue entry may be unlikely and catastrophic, still producing a high rating because the consequence is severe.

A ransomware attack that shuts down ticketing may be possible and moderate, producing a moderate inherent rating. That rating doesn't make the issue unimportant. If the event has no offline validation process, the operational consequence can rise, and the residual risk may remain high after other controls are considered.

Written justification beats subjective adjustment. If a supervisor changes “possible” to “unlikely” because the venue has never experienced an incident, record that reasoning and the evidence supporting it. Past silence isn't proof that a scenario is implausible.

Existing controls should reduce likelihood, consequence or both. Physical vehicle barriers may reduce the likelihood of vehicle intrusion, while an emergency medical plan may reduce consequences without changing the initiating threat. Don't apply a mysterious modifier because the final score feels more comfortable. Record the control, its owner, its status and the reason the residual rating changed.

Matching Controls to Identified Risks

A scored threat without a control is just a documented worry. The control map should connect each risk to one or more measures across deter, detect, delay and respond. Australia's security risk management guidance distinguishes identifying and assessing risk from risk treatment, which is the point where teams select actions, processes and resources to reduce likelihood or consequences, as explained in the Defence security risk management fact sheet.

Use layers, not a shopping list

Guard placement should follow the threat and the site geometry. Fixed posts belong at chokepoints, access-control points and locations where staff need a visible deterrent. Roving patrols are more useful in back-of-house areas, delivery zones and perimeter sections where a fixed post would leave gaps. K9 teams can suit large open sites where hostile reconnaissance is credible, while concierge-style officers may be appropriate in VIP or corporate areas where access control must remain welcoming.

CCTV needs the same analysis. Check coverage between towers, behind vendor sheds, along service roads and at staff entries. Overt cameras can deter and reassure; covert cameras may support investigations where appropriate and lawful. Neither option replaces a person who can interpret behaviour and act on an alert.

Access control can be proportionate. A small venue may use wristband colour tiers and supervised staff entrances. A complex conference or construction site may need credential scanning, visitor logs, escort rules and separate contractor access. The assessment should explain why each layer is present.

Emergency response arrangements need operational detail:

Two identical controls don't produce double the risk reduction. Adding another guard to a poorly designed queue may have less value than relocating a barrier, improving lighting or changing the entry sequence. Fit the control to the failure mode.

GM GROUP Services provides security risk assessments and site-specific threat evaluation for venues, events, retail sites and construction projects, with controls matched to the operating environment.

Meeting Legal and Compliance Checkpoints

A threat assessment may be operationally sensible and still fail under scrutiny if it doesn't show who was licensed, consulted, trained and authorised. Requirements vary between jurisdictions, so confirm the applicable rules before engaging contractors. In NSW, review the Security Industry Act 1997 and licensing arrangements. Victoria operates under the Private Security Act 2004, while Queensland, South Australia and Western Australia have their own security licensing regimes.

Crowd controllers need the correct licence for the work they perform, and supervision arrangements need to be clear. A contractor's uniform or prior experience doesn't establish compliance. Record licence checks, roles, shift arrangements, supervisor details and any restrictions relevant to the engagement.

Connect security with WHS and RSA

Responsible Service of Alcohol is part of the threat picture for licensed venues and events. Intoxication can increase conflict, unsafe movement, poor judgement and resistance to directions. The assessment should identify who monitors service, who handles refusal of service, how staff request security assistance and how incidents are recorded without escalating unnecessarily.

Work health and safety duties also belong in the document. Under the model WHS Acts, a PCBU has duties to manage risks and consult with workers. Section 19 duties under the model framework connect directly to hazard identification, safe systems and the provision of information, training and supervision. Security planning shouldn't sit separately from WHS planning, because a control that protects patrons can expose workers if it creates an unsafe manual-handling task, blocked exit or uncontrolled vehicle interaction.

Align the document with AS/NZS ISO 31000:2018 principles and terminology. That makes the assessment easier for insurers, police liaison teams, council event officers and internal legal reviewers to understand. The assessment should show the context, criteria, risks, controls, monitoring and review process.

Keep a revision history, document the person responsible for each update, include sign-off lines and retain the evidence trail. Store intelligence sources, briefing records, licence checks, site photos, control inspections and incident reports. A clean record helps explain why decisions were made if an incident leads to an insurer review, regulator investigation or coronial inquiry.

Reporting, Post-Event Review and Common Questions

The final document should be useful to operations, WHS, legal and the frontline team. A practical reporting pack normally contains an executive summary, risk register, control matrix, incident log and sign-off block. Keep the executive summary short enough for a venue manager to use, but make the underlying register detailed enough for a supervisor to check controls during a shift.

The risk register should identify each scenario, affected people or assets, inherent rating, current controls, residual rating, owner and review trigger. The control matrix should state what must happen, when, by whom and how completion will be verified. An incident log should capture time, location, people involved, action taken, escalation and outstanding follow-up.

Review what actually happened

Hold the debrief within 72 hours, using the Safe Work Australia risk management method, which follows the cycle of identifying hazards, assessing risks, controlling risks and reviewing controls. Compare the planned control with observed effectiveness, not merely whether someone ticked a box.

Capture near-misses, queue surges, radio failures, access breaches, delayed medical response and situations that staff resolved before they became incidents. Update the risk register, assign corrective actions and feed the lessons into the next event's intelligence gathering.

Frequently asked questions

Does a small community event need a formal assessment?
Yes, although the format can be proportionate. A single-page risk register may be suitable for a small gathering, provided it covers the site, crowd, alcohol, access, emergency contacts and credible threats. Small scale doesn't remove responsibility. It usually means the assessment can be simpler.

How should promoters receive hostile actor intelligence?
Use factual language, confidence levels and operational implications. Explain what is known, what isn't known and which control is changing. Avoid dramatic labels that create panic or encourage staff to profile lawful attendees.

Who owns the document?
The event organiser, site operator or PCBU should own the assessment because that party controls the activity and resources. A security provider can prepare or maintain it, but ownership, approval and decision authority must remain clear.

How often should it be refreshed?
Refresh it whenever the event scope, crowd profile, venue layout, performer or speaker, access arrangement, intelligence picture or control effectiveness changes. A new delivery route or temporary structure can invalidate an otherwise sound site survey.

How do you balance cost and risk?
Start with the highest residual risks and select controls that address the actual failure mode. A well-positioned barrier, reliable communication plan or supervised access point may deliver more value than adding identical personnel without changing the exposure.

A threat assessment earns its place when a supervisor can use it during a live operation, a manager can approve resources from it and a reviewer can trace each decision afterwards.


GM GROUP Services can help organisations across NSW, VIC, QLD and the ACT turn threat assessment findings into practical security plans for events, venues, businesses and construction sites. Speak with the team about a site-specific assessment and control plan, then visit GM GROUP Services to discuss the operating environment, risks and next steps.

Exit mobile version