6.2 Threat, Vulnerability, and Consequence (T×V×C) Analysis

Key Takeaways

  • The risk equation Risk = Threat x Vulnerability x Consequence demonstrates that risk exists only when an active threat intersects with an unmitigated vulnerability to produce a measurable impact.
  • Threat assessment evaluates external and internal threat actors, measuring their capability, intent, past history, and overall likelihood of occurrence.
  • Vulnerability assessment identifies weaknesses or gaps across physical, technical, procedural, and human security controls.
  • Consequence assessment quantifies the full spectrum of loss, measuring potential impacts across financial, operational, reputational, legal, and life safety dimensions.
Last updated: July 2026

6.2 Threat, Vulnerability, and Consequence (T×V×C) Analysis

In physical security and enterprise risk management, risk is rarely a vague, amorphous concept. To evaluate and manage security risks systematically, security managers use analytical models that decompose risk into measurable components. The most widely adopted formula for facility and asset risk assessment is the Threat, Vulnerability, and Consequence (T×V×C) model.

Mathematically, the fundamental risk equation is expressed as: Risk=Threat×Vulnerability×Consequence\text{Risk} = \text{Threat} \times \text{Vulnerability} \times \text{Consequence} (or $R = T \times V \times C$)

This multiplicative relationship illustrates a vital security truth: If any single variable equals zero, total risk equals zero. For example, if a severe threat exists (e.g., an active hostile adversary) and the potential consequence is catastrophic, but the asset possesses absolute zero vulnerability (100% invulnerable defense), the calculated risk to that asset remains zero. Security countermeasures focus on reducing vulnerabilities and mitigating consequences, even when external threats cannot be eliminated.


Deconstructing the Three Core Variables

                    +----------------------------+
                    |       THREAT (T)           |
                    | Capability x Intent x Hist |
                    +----------------------------+
                                  |              
                                  v              
  +--------------------+                   +--------------------+
  | VULNERABILITY (V)  | ===>  RISK  <===  |  CONSEQUENCE (C)   |
  | Control Weaknesses |    (T x V x C)    | Financial/Impact   |
  +--------------------+                   +--------------------+

1. Threat Assessment (T)

AA threat is any entity, event, or force with the potential to cause harm, disruption, destruction, or unauthorized access to an organizational asset.

Threat assessment evaluates threat actors and natural hazards across four key attributes:

  • Capability: The technical skills, tools, equipment, financial backing, manpower, and operational sophistication required by a threat actor to execute a specific attack.
  • Intent: The motivation, desire, and determination of an adversary to target a specific enterprise or facility. Intent may stem from economic gain (criminals), political ideologies (activists/terrorists), personal grievances (insiders), or state interests (espionage).
  • History & Frequency: Historical patterns of past occurrences, local crime statistics, regional hazard history, and industry targeting trends.
  • Likelihood / Opportunity: The probability that a threat event will manifest within a defined timeframe based on environmental and situational factors.

Categories of Threats:

  1. Adversarial / Intentional Human Threats: Terrorists, violent criminals, organized syndicates, disgruntled internal employees, corporate spies, and cyber attackers.
  2. Natural Hazards: Earthquakes, floods, hurricanes, severe winter storms, tornadoes, and wildfires.
  3. Accidental & Technical Hazards: Structural fires, hazardous chemical spills, power grid failures, industrial machinery accidents, and human operator errors.

2. Vulnerability Assessment (V)

AA vulnerability is an internal flaw, weakness, gap, or deficiency in an asset's design, physical layout, protective systems, operating procedures, or human controls that an adversary can exploit to gain access or cause harm.

Vulnerability assessment involves systematically identifying defense weaknesses across four security layers:

  • Physical Security Weaknesses: Low perimeter fencing, unmonitored emergency exit doors, inadequate exterior lighting, single-pane glass windows, lack of vehicle anti-ram barriers.
  • Technical & Logical Weaknesses: Unencrypted wireless networks, outdated access control software, unmonitored CCTV blind spots, shared admin passwords.
  • Procedural & Operational Weaknesses: Inadequate visitor badging policies, lack of background checks for contractors, key control policy gaps, weak escort protocols.
  • Human & Cultural Weaknesses: Lack of security awareness training, employee susceptibility to social engineering or tailgating, low security policy compliance.

Conducting a vulnerability assessment requires physical site surveys, penetration testing, policy audits, staff interviews, and inspection of electronic security hardware.


3. Consequence / Impact Assessment (C)

Consequence (also termed Impact) measures the total severity and extent of loss, damage, or disruption that occurs if a threat successfully exploits a vulnerability against an asset.

Consequence assessment quantifies losses across five essential dimensions:

  • Financial Loss: Direct cash losses, repair/replacement costs of damaged physical property, stolen inventory, legal fees, and regulatory non-compliance fines.
  • Operational Disruption: Facility downtime, loss of core utility services, supply chain halts, reduced productivity, and inability to meet customer contractual obligations.
  • Reputational & Brand Damage: Negative national media exposure, loss of public trust, plummeting shareholder stock value, and customer defection.
  • Legal & Regulatory Liabilities: Civil lawsuits from injured parties, statutory fines for safety failures (e.g., OSHA or regulatory breaches), and contractual breach penalties.
  • Life Safety & Security: Fatalities, severe physical injuries, chronic health exposures, and psychological trauma suffered by employees, contractors, or visitors.

T×V×C Risk Calculation & Scoring Framework

To standardize assessments, security managers assign numeric scores (e.g., 1 to 5 scale) to Threat, Vulnerability, and Consequence based on predefined qualitative rubrics:

VariableScore 1 (Very Low)Score 3 (Moderate)Score 5 (Very High)
Threat (T)Unskilled, no intent, no historical occurrencesModerately skilled adversary, opportunistic intentHighly trained adversary, explicit targeting intent, frequent history
Vulnerability (V)Multiple redundant, hardened controls; zero single points of failureBasic controls in place; minor procedural or physical gapsNo physical/technical controls; wide open access points
Consequence (C)Minimal disruption (<$5k loss); zero injury; negligible operational impactTemporary facility halt (<24 hrs); moderate repair costs (<$100k)Loss of life; total facility destruction; severe brand damage (>$5M)

Composite Risk Score Example:

For a remote storage building storing non-critical spare parts:

  • Threat (T) = 2 (opportunistic vandals)
  • Vulnerability (V) = 4 (unlocked perimeter door)
  • Consequence (C) = 1 (low-value inventory) Risk Score=2×4×1=8(Out of max 125)\text{Risk Score} = 2 \times 4 \times 1 = 8 \quad (\text{Out of max 125})

By comparing composite T×V×C scores across all facility assets, security managers can rank risks objectively and allocate mitigation capital where potential exposure is highest.

Test Your Knowledge

In the fundamental security risk equation R = T x V x C, what does a vulnerability value of zero (V = 0) mathematically imply regarding total risk?

A
B
C
D
Test Your Knowledge

Which component of a threat assessment specifically evaluates an adversary's training, technical knowledge, firepower, and financial resources to execute an attack?

A
B
C
D
Test Your Knowledge

A security inspection reveals that a corporate facility relies on unmonitored emergency exit doors with non-functioning alarm switches. In a T x V x C analysis, how is this finding classified?

A
B
C
D