Security governance · Intelligence · GRC
Four things that are worth more together than apart
Security risk consulting, intelligence, GRC software and a managed security workforce. Most organisations buy them from four suppliers and get four disconnected answers.
Published 31 August 2026 · 2 min read
Most organisations end up buying security in four pieces. A consultant writes the risk assessment. Somebody else provides threat information, or nobody does. A platform holds the compliance evidence. A guarding company supplies the people. Each is bought separately, from a different supplier, on a different cycle, and the result is four answers that do not reference each other.
What each one is missing on its own
- A risk assessment without intelligence is a judgement about likelihood with nothing behind the likelihood. It ages the day it is signed.
- Intelligence without a programme to feed is interesting reading. If nothing changes as a result, it was a subscription rather than a capability.
- A GRC platform without either is a filing cabinet. It records what you decided; it does not tell you the decision is now wrong.
- A workforce without the other three is presence rather than protection: people deployed to a threat picture nobody has revisited, following procedures written for a site that has changed.
What changes when they are one programme
The intelligence picture sets what the risk assessment treats as likely. The assessment decides which controls are worth their cost. The platform holds those controls, their evidence and their review dates, so the position is current rather than remembered. The workforce is deployed against that picture and reports back into it, which is the part that is usually lost.
That last loop is the whole argument. Officers on a site see things: an approach that did not fit, a vehicle that returned, a door that keeps being propped. In a fragmented arrangement that observation dies in a shift log the guarding company keeps and the consultant never sees. In a single programme it is a collection source, and it is the cheapest one you have.
The test to apply to your own arrangement
- When your threat picture changes, what happens to your risk assessment? If the answer is "nothing until the next review", they are not connected.
- When an officer reports something unusual, who assesses it, and does the assessment reach whoever decides on resourcing?
- When a regulator asks what you have done about a specific risk, how long does assembling the answer take? Days means the evidence was not captured as it happened.
- Who is accountable when the four disagree? If the answer is "us, by convening a meeting", you are doing the integration work you thought you had bought.
The honest caveat
Buying all four from one provider concentrates risk, and it is fair to say so. The mitigation is not to fragment on purpose; it is to insist on the things that make a single provider safe: evidence you hold rather than they hold, a programme documented well enough that a successor could run it, and reporting frank enough to tell you when something is not working.
Empire Protection delivers all four: security risk and crisis consulting, intelligence, governance, risk and compliance software, and a contracted specialist workforce under one principal; and holds the security officer role for clients who want one accountable person across them.
Read next
General information, not advice for your circumstances. Obligations change: confirm anything you intend to rely on against the current instrument.
