2.3 Qualitative vs Quantitative Assessment Methods

Key Takeaways

  • Qualitative methods use ordinal labels or 1–5 scores from workshops and subject-matter judgment; they rank, they do not mint dollars.
  • Quantitative methods use counts and money: single loss expectancy times annualized rate of occurrence produces annualized loss expectancy.
  • A 1–5 workshop score is not a currency; multiplying it as if it were dollars is fake precision.
  • Hybrid work uses annualized loss where history and asset values are reliable, and ordinal ranking where events are rare or data are sparse.
  • Inventing an annualized rate to two decimal places from a national crime ranking is theater, not measurement.
Last updated: September 2026

Qualitative Versus Quantitative Methods, and the Hybrid in Between

Once the assessment plan names assets and a lead model, the team still needs a method for judging risk. Independent OpenExamPrep teaching for published PSP Domain 1 tasks separates two families. Qualitative methods use words or ordinal scores from workshops and subject-matter experts. Quantitative methods use counts, rates, and money. Most honest physical security work is a hybrid: dollars where the books can support dollars, ordinal ranking where they cannot. The trap is theater: a 1–5 score treated as currency, or an annualized rate invented to two decimal places because a spreadsheet had a slot for it.

Qualitative methods: high, medium, low, and workshops

Qualitative work is appropriate when you must compare unlike harms, when frequency is too low for a stable rate, or when the useful output is a priority list for a hospital or campus leadership team that will not fund a full actuarial model.

Typical mechanics:

  • A facilitated workshop with operations, facilities, security, EHS, and IT.
  • Agreed definitions of likelihood and consequence before scoring. High cannot mean both a stolen laptop and a blocked emergency department.
  • Scores recorded as high/medium/low or as 1–5, with a written rule for each bin.
  • A heat map that plots those two axes so the room can see clusters.

Example likelihood bins for a warehouse (write these in the plan so they are not invented at the whiteboard):

ScoreLikelihood meaning on this site
1Not observed in five years and no plausible path this year
2Possible; similar sites have seen it; no local event in three years
3Happened here or at a sister site in the last two years
4Several times per year or a current, repeating process gap
5Ongoing; cycle counts or incidents already show it

Example consequence bins for the same warehouse:

ScoreConsequence meaning
1Nuisance; absorbed in ordinary shrinkage reserve
2Notable loss or delay; one manager can recover
3Material loss, customer miss, or reportable safety event
4Site stoppage, major customer loss, or serious injury potential
5Life safety, regulated-product integrity, or enterprise-level outage

Those tables are ordinal. 4 is worse than 2. 4 is not twice 2, and 4 minus 2 is not two dollars.

Qualitative heat map: four facilities, one picture

Use a heat map to rank, not to mint a budget. The cells below are teaching examples for a mixed portfolio. Your site must replace them with workshop evidence.

ScenarioLikelihoodConsequenceQualitative risk
Hospital: controlled-substance diversion from the pharmacy anteroomMediumHighHigh
Hospital: infant abduction from labor and deliveryLowExtremeHigh
Data center: tailgate through the visitor mantrap into a customer cageMediumHighHigh
Data center: copper theft from the exterior yardHighMediumHigh
Warehouse: pallet theft from an unattended high-value cageHighMediumHigh
Warehouse: chaining a required exit to stop shrinkMediumExtreme (life safety / citation)High
Corporate campus: visitor tailgate into open office seatingHighLowMedium
Corporate campus: insider removal of R&D prototype from the labMediumHighHigh
Corporate campus: graffiti on a remote parking garageHighLowLow

Notice what the map does well: it keeps infant abduction on the leadership page even though likelihood is low. Notice what it does not do: it does not say the hospital should spend exactly 4.2 times as much on the pharmacy as on graffiti. Anyone who multiplies the scores and presents the product as a funding formula has left qualitative method and entered fake precision.

Quantitative methods: counts, expected loss, and ALE

Quantitative work needs defensible inputs: an asset value or loss magnitude, an exposure factor, and a rate grounded in history or a documented model. The classic identity taught in physical security and information-risk practice is:

ALE = SLE × ARO

  • SLE (single loss expectancy) is the expected money lost in one event. A common construction is asset value times exposure factor (the fraction of value lost in that scenario).
  • ARO (annualized rate of occurrence) is how many times per year that event is expected, including fractions for rare events (0.25 means about once in four years).
  • ALE (annualized loss expectancy) is the expected yearly loss from that scenario, which you can compare with the yearly cost of a control.

Quantitative work also includes counts that never become money: badge-exception volume, door-held-open events per week, lighting readings below a stated site criterion, inventory variances, or tailgates observed in a timed lobby study. Those counts are still quantitative. They are often more honest than a forced dollar figure.

Worked ALE example: electronics cage in a warehouse

A third-party warehouse stores mixed consumer electronics in a chain-link interior cage. Operations and loss-prevention agree on the following site facts, not national averages:

  • A typical stolen pallet, at landed cost, is $12,000.
  • When a theft succeeds, the entire pallet leaves; exposure factor is 1.0.
  • SLE = $12,000 × 1.0 = $12,000.
  • Incident and cycle-count history: six successful pallet thefts in the last 18 months. That is four per year, so ARO = 4.
  • ALE = $12,000 × 4 = $48,000 per year for this scenario alone.

Now test a control with the same identity, still using operations' judgment rather than theater:

  • Hardened cage plus dock-release dual control is estimated to drop successful pallet thefts to about one every two years (ARO = 0.5) if the process is actually followed.
  • New ALE = $12,000 × 0.5 = $6,000 per year.
  • Expected annual reduction = $48,000 − $6,000 = $42,000.
  • If the extra hardware and labor cost $15,000 per year, the control is plausible on this scenario. If they cost $80,000 per year, leadership may still buy them for customer-contract reasons, but they should not pretend the ALE math justified $80,000.

That is honest quantitative work: visible inputs, visible arithmetic, and a sentence about what the arithmetic does not capture (injury, customer chargebacks, or a burned contract).

When numbers are fake-precise

Fake precision is not the use of numbers. It is the use of undue significant digits and false units.

Common tells:

  • Converting a workshop 1–5 score into dollars with a hidden rule such as each point equals $10,000, then reporting $37,500 of risk as if it were an accounting entry.
  • Setting ARO to 0.37 because a national burglary rate was divided by the building's square footage, with no local history and no adversary story.
  • Reporting ALE to the nearest dollar on a rare hospital event (infant abduction) for which the organization has zero frequency data. Consequence can still be described in qualitative terms; inventing a rate does not make the event more managed.
  • Averaging unlike scores: pharmacy diversion at 4 and graffiti at 2 become a campus risk of 3 that funds nothing useful.

Trap: treating a 1–5 score as if it were dollars. Ordinal scores support ranking and heat maps. They do not support subtraction, ratios, or net-present-value. If leadership needs money, build an SLE from invoices, inventory, outage-cost models, or insurance worksheets. If those inputs do not exist, stay qualitative and say so.

Hybrid methods that stay defensible

A hybrid assessment uses quantitative ALE or counts where loss history and asset values are reliable, and qualitative ranking where events are rare, harms are unlike, or data are sparse.

Practical split across facility types:

SituationBetter methodWhy
Warehouse electronics shrink with 18 months of cycle countsQuantitative ALE plus process countsHistory supports ARO; invoices support SLE
Data-center copper theft with invoices and repeated yard incidentsQuantitative for that scenarioMoney and rate both exist
Hospital infant abductionQualitative extreme consequence, low likelihoodRate would be invented
Campus insider theft of unreleased intellectual propertyQualitative or scenario narrative; money only if a defensible valuation existsPrototype value is often a guess
Lighting below a stated site criterionQuantitative counts (measured illuminance, dark zones)You measured something real
Workplace-violence severityQualitative plus incident counts, not a fake ALEHuman harm does not become precise by spreadsheet

Write the split in the assessment plan. A warehouse report that shows ALE for cage theft and a heat map for life-safety and insider scenarios is coherent. A campus report that shows a single $2,847,291.04 figure built from averaged 1–5 scores is not.

Close the method section the way you close the plan: name what you measured, what you ranked, and what you refused to invent. PSP candidates are expected to know the ALE identity and to know when not to use it, not to decorate every door with a fake dollar.

Warehouse electronics cage — example annualized dollars
Test Your Knowledge

In quantitative physical security assessment, annualized loss expectancy (ALE) equals which of the following?

A
B
C
D
Test Your Knowledge

Why is treating a qualitative 1–5 workshop score as if it were dollars a professional trap?

A
B
C
D
Test Your Knowledge

When is a hybrid qualitative-plus-quantitative assessment most defensible?

A
B
C
D