Protection needs assessment

The foundation of corporate security

Before an organisation can take effective security measures, it has to know what it is protecting and how strong that protection has to be. This is exactly where the protection needs assessment under Section 5 of DIN SPEC 14027 comes in. It provides a systematic, traceable method for identifying material assets, assessing their criticality and deriving suitable protective measures.

The process is required for all organisations with business-critical values, irrespective of sector, size or organisational form. It forms the basis for most of the other fields of action, such as site security, personal protection or know-how protection.

Learning objectives of this lesson

After this lesson you will be able to:

  • identify your organisation's assets systematically,
  • derive strategic and operational protection objectives,
  • assess asset criticality and threat intensity on four levels,
  • apply the protection needs matrix and distinguish gross risk from net risk.

The process at a glance

The protection needs assessment follows a logical sequence. First the organisational assets are identified and classified. Then protection objectives are defined. Building on this, asset criticality and threat intensity are assessed. Both dimensions are set against each other in a protection needs matrix, from which the protection needs category is derived. The final step is drawing up the concept, with a gross and a net perspective.

Important: this is not a one-off exercise. Alongside the initial assessment, a continuous assessment process is required that regularly re-evaluates existing assets and classifies newly added assets for the first time.

Key terms from practice:

Asset (value)
All tangible and intangible resources of an organisation, including data, systems, processes, intellectual property and people that matter to business operations.
Asset criticality
The parameter that determines how severe the impact of security incidents is on specific corporate assets. Assessed on 4 levels (A = very high to D = low).
Threat intensity
A measure of how strongly an asset is endangered, depending on the number of relevant attack vectors, the probability of occurrence and how attractive the asset is to attackers.
Protection need
What an asset requires in terms of the protection objectives availability, integrity and confidentiality. It follows from the criticality of the asset and the intensity of the threats acting on it.
Gross risk
The current security position (as-is state) based on the protective measures already in place. The starting point of the systematic analysis.
Net risk
The residual exposure once all needs-based protective measures have been implemented. An important indicator of how effective the protection concept is.

Deep dive

The following sections explore the course of the protection needs assessment in more depth.

1. Identifying organisational assets (Section 5.2.2)
To determine the protection need systematically, all material organisational assets have to be identified, structured and classified. Guiding questions help with this: which factors make the organisation particularly valuable? What is unique about it? In addition, a responsible body must be assigned to each asset. Possible asset classes include people and functions, documents and information, projects and organisational functions, IT applications and infrastructure, properties (laboratories or data centres, for example), production equipment and physical assets such as materials.
2. Defining protection objectives (Section 5.2.3)
Protection objectives should first be formulated generically as strategic protection objectives and then specifically as operational ones. A proven approach is to determine which events, states or effects must under no circumstances occur. Examples of strategic protection objectives: protecting human life and health, fulfilling statutory duties, maintaining operational capability, averting economic and reputational damage. Protection objectives can also arise from regulatory requirements (the protection of critical infrastructure, for example). Important: the fact that no critical events have occurred so far does not automatically indicate effective threat management.
3. Assessment: asset criticality and threat intensity (Sections 5.2.3.2 and 5.2.4)
Asset criticality describes the potential impact of incidents. Relevant dimensions include financial damage, consequences for supplying the population, regulatory impact, replacement lead times, reputational damage, risks to individuals (life and limb) and cascade effects. Threat intensity follows from abstract and concrete threats, existing vulnerabilities and the exposure of the assets. Only the interplay of a relevant threat and an existing vulnerability leads to a concrete exposure. Both dimensions are assigned, weighted or unweighted, to one of four intensity levels (A to D).
4. The protection needs matrix with gross and net risk (Sections 5.2.5 and 5.2.6)
The gross assessment is the starting point and describes the current security position based on existing protective measures. For new buildings, the as-is state can be considered hypothetically without existing measures (set to zero). The need for action follows from the gross assessment. For unacceptable exposures, a protection concept is developed with preventive, reactive and corrective measures as well as intervention and detection. The theoretical net risk describes the residual exposure after implementation. The protection concept must be approved by top management, and the concept has to be updated regularly.

The protection needs matrix

The central instrument of the protection needs assessment is the matrix of threat intensity (vertical) and asset criticality (horizontal). Both dimensions are classified on four levels (A to D). Their combination yields the protection needs category, from low (dark green) to very high (red).

Where high asset criticality meets high threat intensity, the result is a very high protection need. Depending on the organisation's security culture or on regulatory requirements, thresholds and weightings can be adjusted. The resulting category is the basis for assessing the as-is state, identifying vulnerabilities and deriving relevant measures.

Protection needs assessment under DIN SPEC 14027

Assessment matrix

The protection needs matrix sets asset criticality and threat intensity against each other systematically. Select a combination to see the resulting protection need, an example scenario and recommended measures.

Asset criticality →
Avery high
Bhigh
Cmedium
Dlow
↑ Threat intensity
very high protection need
high protection need
medium protection need
low protection need
Basis: DIN SPEC 14027:2026-04, Corporate Security, Section 5 “Schutzbedarfsermittlung” (Figure 1, assessment matrix). Interactive presentation for Continuitylab.

The key points in brief

  • The protection needs assessment is the foundation of all further corporate security measures and is required for every organisation with business-critical values.
  • The process follows the chain: identify assets → define protection objectives → assess criticality and threat intensity → apply the matrix → derive the concept.
  • Criticality and threat intensity are each assessed on four levels (A–D) and set against each other in the protection needs matrix.
  • The gross assessment shows the as-is state, the net risk the residual exposure once the measures have been implemented.
  • The protection concept is approved by top management; the entire process has to be updated continuously.

Looking ahead: the next lesson turns to the security situation picture (Section 6). You will get to know the situation picture process in five phases, distinguish internal from external information sources and learn when a monitoring system should be established and when it is mandatory.