
Critical infrastructure risk assessments across energy sites

A large multi-site energy organization required structured security risk assessments to strengthen the protection of critical operational infrastructure across Ontario.
The Challenge
The organization operated multiple critical infrastructure sites that supported the production and distribution of energy across Ontario. Protecting these facilities required a structured understanding of site-specific risks while maintaining a consistent approach to security across the broader organization.
The engagement was initiated to meet an industry regulatory requirement by conducting security risk assessments using the RCMP Harmonized Threat Risk Assessment methodology. The objective was to identify existing and emerging security risks and develop practical mitigation strategies for each operational site.
The work was complicated by the number of locations involved, each with its own operational purpose, physical environment, existing controls, and risk profile. The engagement also required coordination across multiple business units while balancing regulatory obligations, due diligence expectations, and the need for recommendations that were practical to implement throughout a large operational environment.
Our Approach
The engagement began with planning and conducting specialized security risk assessments across approximately forty critical operational sites. Each assessment followed the RCMP Harmonized Threat Risk Assessment methodology to provide a consistent and defensible evaluation process while recognizing the unique conditions at each location.
Site reviews examined existing security measures, asset protection requirements, operational conditions, potential threats, and identified vulnerabilities. The findings were used to develop mitigation strategies and management recommendations tailored to the needs of each facility.
Beyond the site assessments, the engagement included ongoing security advisory support to managers, operational leaders, and asset protection stakeholders across multiple business units. The work also involved collaboration with internal and external partners to support the development of asset protection strategies, security standards, policies, awareness programs, and long-term security planning.
The engagement applied RCMP Harmonized Threat Risk Assessment methodology, critical infrastructure protection principles, corporate security and asset protection practices, due diligence-based security assessment, and sector-specific legal and regulatory considerations.
Final deliverables
The Outcome
The engagement provided the organization with detailed, site-specific security risk assessments across its critical operational facilities. Each report identified current and potential risks while providing practical mitigation strategies to strengthen asset protection and support operational decision making.
The completed assessments established a consistent basis for security planning across multiple locations while supporting regulatory requirements, security awareness, and due diligence. The organization gained clearer insight into the risks affecting its most critical assets and a structured path for addressing them over time.
Without this work, critical operational sites may have continued to operate with unidentified or insufficiently mitigated risks, inconsistent asset protection standards, and a reduced ability to demonstrate due diligence for critical infrastructure security.
Key insight
Get the strategy needed to reduce risk with confidence
Get the strategy needed to reduce risk with confidence
Start with a confidential discussion about your right next step.
Related Case Studies

Expert security opinion in public attraction assault litigation

National loss prevention program development for a distribution and logistics organization

