Security Risk Advisory

Your Security Professional. Inside the ESRM framework.

Regent Intel operates as the Security Professional within the ESRM model — identifying and assessing security risk, presenting mitigation options to the asset owner, and executing the program they approve. Whether we extend your existing security function or become it entirely, the role is the same: trusted advisor, subject matter expert, and practitioner.

Two Engagement Models

How the advisory relationship works depends on who you are.

The ESRM framework defines the Security Professional as the trusted advisor and subject matter expert who guides asset owners through the risk decision-making process. Regent Intel fills that role — either alongside your existing security function, or as the function itself.

You have a security function

Extending Your Program

Your CSO or security director owns the ESRM relationship internally. You need specialized capability you don't have in-house: intelligence-trained investigators, TSCM, executive protection operators with government backgrounds, or the analytic depth to support your risk assessments. Regent Intel plugs into your existing governance structure, reports through your chain, and delivers capability that extends your program without duplicating your role.

You don't have a security function

Becoming Your Security Professional

Principals, family offices, executives, and smaller organizations without a dedicated security function. Regent Intel fills the entire Security Professional role: we identify the assets that matter most, assess the risks to those assets, present mitigation options with clear analysis, and execute and monitor the program you approve. You make the risk decisions. We do everything else.

The ESRM Lifecycle

What the advisory relationship delivers at every phase.

The four-phase ESRM cycle governs every Regent Intel advisory engagement. This is not a one-time assessment. It is a continuous loop that adapts as the threat landscape, organizational priorities, and operating environment evolve.

Identify & Prioritize Assets

Exposure & Asset Assessment

We catalogue what matters most — people, operations, facilities, information, reputation — and map each asset against your mission and priorities. Ownership is assigned. The asset owner is the risk owner. We advise; they decide what gets protected first.

Identify & Prioritize Risks

Threat Analysis & Risk Prioritization

For each asset, we identify the threats and vulnerabilities that could cause harm. Digital footprint, travel patterns, insider risk, physical exposure, adversarial intent — assessed through intelligence-grade methodology and scored for likelihood and impact. Risks are ranked by priority, not assumed equal.

Mitigate Prioritized Risks

Protection Design & Risk Treatment

For each prioritized risk, we develop mitigation options — accept, avoid, transfer, or reduce — and present them to the asset owner with cost, timeline, and expected risk reduction. The asset owner decides the appropriate risk appetite and approves the mitigation. We design and deploy the program: EP details, TSCM sweeps, travel security, intelligence monitoring, or any combination the risk picture requires.

Continuous Improvement

Monitoring, Reporting & Adaptation

Intelligence collection runs continuously. We monitor for changes in the threat landscape, conduct periodic reassessments, incorporate incident learning, and report on risk posture and control effectiveness. The program adjusts as conditions evolve. Every action is documented. Every decision is defensible and auditable.

Governance-Grade Deliverables

What the advisory relationship produces.

Every deliverable is structured for the audience that needs it — whether that is a board risk committee, a general counsel, a family office director, or the principal themselves. Documentation is not an afterthought. It is a core discipline.

Risk Assessment

Security Risk Register

Catalogued assets, identified threats, scored risks, and prioritized treatment recommendations. The foundation of the ESRM program and the basis for every resource allocation decision.

Mitigation

Security Risk Management Plan

Documented mitigation strategy for each prioritized risk: controls selected, rationale, cost-benefit analysis, asset owner approval, and implementation timeline.

Monitoring

Threat Intelligence Briefings

Regular intelligence products covering emerging threats, changes in the risk landscape, escalation indicators, and recommended adjustments to the security posture.

Governance

Board-Level Risk Reporting

Quarterly or periodic reports on risk posture, control effectiveness, residual risk trends, and program performance — structured for board presentation, audit committee review, or fiduciary oversight.

Why Regent Intel

Built at the intersection of five disciplines.

The practitioners who fill the Security Professional role at Regent Intel each came from a distinct discipline — OGA programs, Army intelligence, special operations, Treasury financial investigations, and FBI investigative work. That integration is what the methodology reflects, and it is why the advisory capability operates at a level most firms cannot replicate.

No comparable firm has integrated all five disciplines. Most operate in a single lane. Regent Intel was built at the intersection of all of them — and the advisory practice reflects every one.

↓ Capability Statement Our Framework →
Capability

Government Grade. Commercial Speed.

Security risk management delivered in moments, not weeks and months.

We solve difficult problems.

All inquiries are handled with complete confidentiality.

Request a Consultation