2.3 Qualitative vs Quantitative Assessment Methods
Key Takeaways
- Qualitative methods use ordinal labels or 1–5 scores from workshops and subject-matter judgment; they rank, they do not mint dollars.
- Quantitative methods use counts and money: single loss expectancy times annualized rate of occurrence produces annualized loss expectancy.
- A 1–5 workshop score is not a currency; multiplying it as if it were dollars is fake precision.
- Hybrid work uses annualized loss where history and asset values are reliable, and ordinal ranking where events are rare or data are sparse.
- Inventing an annualized rate to two decimal places from a national crime ranking is theater, not measurement.
Qualitative Versus Quantitative Methods, and the Hybrid in Between
Once the assessment plan names assets and a lead model, the team still needs a method for judging risk. Independent OpenExamPrep teaching for published PSP Domain 1 tasks separates two families. Qualitative methods use words or ordinal scores from workshops and subject-matter experts. Quantitative methods use counts, rates, and money. Most honest physical security work is a hybrid: dollars where the books can support dollars, ordinal ranking where they cannot. The trap is theater: a 1–5 score treated as currency, or an annualized rate invented to two decimal places because a spreadsheet had a slot for it.
Qualitative methods: high, medium, low, and workshops
Qualitative work is appropriate when you must compare unlike harms, when frequency is too low for a stable rate, or when the useful output is a priority list for a hospital or campus leadership team that will not fund a full actuarial model.
Typical mechanics:
- A facilitated workshop with operations, facilities, security, EHS, and IT.
- Agreed definitions of likelihood and consequence before scoring. High cannot mean both a stolen laptop and a blocked emergency department.
- Scores recorded as high/medium/low or as 1–5, with a written rule for each bin.
- A heat map that plots those two axes so the room can see clusters.
Example likelihood bins for a warehouse (write these in the plan so they are not invented at the whiteboard):
| Score | Likelihood meaning on this site |
|---|---|
| 1 | Not observed in five years and no plausible path this year |
| 2 | Possible; similar sites have seen it; no local event in three years |
| 3 | Happened here or at a sister site in the last two years |
| 4 | Several times per year or a current, repeating process gap |
| 5 | Ongoing; cycle counts or incidents already show it |
Example consequence bins for the same warehouse:
| Score | Consequence meaning |
|---|---|
| 1 | Nuisance; absorbed in ordinary shrinkage reserve |
| 2 | Notable loss or delay; one manager can recover |
| 3 | Material loss, customer miss, or reportable safety event |
| 4 | Site stoppage, major customer loss, or serious injury potential |
| 5 | Life safety, regulated-product integrity, or enterprise-level outage |
Those tables are ordinal. 4 is worse than 2. 4 is not twice 2, and 4 minus 2 is not two dollars.
Qualitative heat map: four facilities, one picture
Use a heat map to rank, not to mint a budget. The cells below are teaching examples for a mixed portfolio. Your site must replace them with workshop evidence.
| Scenario | Likelihood | Consequence | Qualitative risk |
|---|---|---|---|
| Hospital: controlled-substance diversion from the pharmacy anteroom | Medium | High | High |
| Hospital: infant abduction from labor and delivery | Low | Extreme | High |
| Data center: tailgate through the visitor mantrap into a customer cage | Medium | High | High |
| Data center: copper theft from the exterior yard | High | Medium | High |
| Warehouse: pallet theft from an unattended high-value cage | High | Medium | High |
| Warehouse: chaining a required exit to stop shrink | Medium | Extreme (life safety / citation) | High |
| Corporate campus: visitor tailgate into open office seating | High | Low | Medium |
| Corporate campus: insider removal of R&D prototype from the lab | Medium | High | High |
| Corporate campus: graffiti on a remote parking garage | High | Low | Low |
Notice what the map does well: it keeps infant abduction on the leadership page even though likelihood is low. Notice what it does not do: it does not say the hospital should spend exactly 4.2 times as much on the pharmacy as on graffiti. Anyone who multiplies the scores and presents the product as a funding formula has left qualitative method and entered fake precision.
Quantitative methods: counts, expected loss, and ALE
Quantitative work needs defensible inputs: an asset value or loss magnitude, an exposure factor, and a rate grounded in history or a documented model. The classic identity taught in physical security and information-risk practice is:
ALE = SLE × ARO
- SLE (single loss expectancy) is the expected money lost in one event. A common construction is asset value times exposure factor (the fraction of value lost in that scenario).
- ARO (annualized rate of occurrence) is how many times per year that event is expected, including fractions for rare events (0.25 means about once in four years).
- ALE (annualized loss expectancy) is the expected yearly loss from that scenario, which you can compare with the yearly cost of a control.
Quantitative work also includes counts that never become money: badge-exception volume, door-held-open events per week, lighting readings below a stated site criterion, inventory variances, or tailgates observed in a timed lobby study. Those counts are still quantitative. They are often more honest than a forced dollar figure.
Worked ALE example: electronics cage in a warehouse
A third-party warehouse stores mixed consumer electronics in a chain-link interior cage. Operations and loss-prevention agree on the following site facts, not national averages:
- A typical stolen pallet, at landed cost, is $12,000.
- When a theft succeeds, the entire pallet leaves; exposure factor is 1.0.
- SLE = $12,000 × 1.0 = $12,000.
- Incident and cycle-count history: six successful pallet thefts in the last 18 months. That is four per year, so ARO = 4.
- ALE = $12,000 × 4 = $48,000 per year for this scenario alone.
Now test a control with the same identity, still using operations' judgment rather than theater:
- Hardened cage plus dock-release dual control is estimated to drop successful pallet thefts to about one every two years (ARO = 0.5) if the process is actually followed.
- New ALE = $12,000 × 0.5 = $6,000 per year.
- Expected annual reduction = $48,000 − $6,000 = $42,000.
- If the extra hardware and labor cost $15,000 per year, the control is plausible on this scenario. If they cost $80,000 per year, leadership may still buy them for customer-contract reasons, but they should not pretend the ALE math justified $80,000.
That is honest quantitative work: visible inputs, visible arithmetic, and a sentence about what the arithmetic does not capture (injury, customer chargebacks, or a burned contract).
When numbers are fake-precise
Fake precision is not the use of numbers. It is the use of undue significant digits and false units.
Common tells:
- Converting a workshop 1–5 score into dollars with a hidden rule such as each point equals $10,000, then reporting $37,500 of risk as if it were an accounting entry.
- Setting ARO to 0.37 because a national burglary rate was divided by the building's square footage, with no local history and no adversary story.
- Reporting ALE to the nearest dollar on a rare hospital event (infant abduction) for which the organization has zero frequency data. Consequence can still be described in qualitative terms; inventing a rate does not make the event more managed.
- Averaging unlike scores: pharmacy diversion at 4 and graffiti at 2 become a campus risk of 3 that funds nothing useful.
Trap: treating a 1–5 score as if it were dollars. Ordinal scores support ranking and heat maps. They do not support subtraction, ratios, or net-present-value. If leadership needs money, build an SLE from invoices, inventory, outage-cost models, or insurance worksheets. If those inputs do not exist, stay qualitative and say so.
Hybrid methods that stay defensible
A hybrid assessment uses quantitative ALE or counts where loss history and asset values are reliable, and qualitative ranking where events are rare, harms are unlike, or data are sparse.
Practical split across facility types:
| Situation | Better method | Why |
|---|---|---|
| Warehouse electronics shrink with 18 months of cycle counts | Quantitative ALE plus process counts | History supports ARO; invoices support SLE |
| Data-center copper theft with invoices and repeated yard incidents | Quantitative for that scenario | Money and rate both exist |
| Hospital infant abduction | Qualitative extreme consequence, low likelihood | Rate would be invented |
| Campus insider theft of unreleased intellectual property | Qualitative or scenario narrative; money only if a defensible valuation exists | Prototype value is often a guess |
| Lighting below a stated site criterion | Quantitative counts (measured illuminance, dark zones) | You measured something real |
| Workplace-violence severity | Qualitative plus incident counts, not a fake ALE | Human harm does not become precise by spreadsheet |
Write the split in the assessment plan. A warehouse report that shows ALE for cage theft and a heat map for life-safety and insider scenarios is coherent. A campus report that shows a single $2,847,291.04 figure built from averaged 1–5 scores is not.
Close the method section the way you close the plan: name what you measured, what you ranked, and what you refused to invent. PSP candidates are expected to know the ALE identity and to know when not to use it, not to decorate every door with a fake dollar.
In quantitative physical security assessment, annualized loss expectancy (ALE) equals which of the following?
Why is treating a qualitative 1–5 workshop score as if it were dollars a professional trap?
When is a hybrid qualitative-plus-quantitative assessment most defensible?