Service — Strategic Consulting

Turn Complex Threats Into A Clear, Long-Term Strategy

Risk Analysis & Strategic Planning

We pride ourselves as a big-picture group, executing analysis and strategy with the long-term in mind. HSCG turns risk, threat, and vulnerability data into a roadmap your organization can actually execute — not a binder that sits on a shelf.

3Core assessment types: risk, threat & vulnerability
Long-TermRoadmaps built for multi-year execution
2007Since our founder began advising on federal preparedness programs

Critical Infrastructure Owners

Facilities that need a defensible risk picture, not just a checklist.

Government & Public Agencies

Agencies building or refreshing a multi-year preparedness strategy.

Corporate Security Programs

In-house teams that need outside analysis to validate or reset direction.

Venues & Special Events

One-time and recurring events that need a real vulnerability assessment.

Security Technology Companies

Vendors needing market and positioning strategy alongside the technical case.

How We Think About It

Analysis That Feeds A Strategy, Not Just A Report

Most security assessments stop at a list of findings. HSCG treats analysis as the input to a decision, not the deliverable itself — every risk, threat, and vulnerability assessment we run is built to feed directly into a prioritized, resourced strategy your team can act on.

That means benchmarking against recognized frameworks where they apply — DHS guidance, ASIS standards, NFPA 3000 for active shooter and hostile event planning — while staying grounded in your actual budget, staffing, and timeline. A strategy that ignores those constraints is just a wish list.

3 Assessment Lenses: Risk, Threat & Vulnerability
1 Prioritized Roadmap, Not A Findings Dump
Std Benchmarked Against ASIS & DHS Guidance
Yrs Roadmaps Built For Multi-Year Execution
What We Deliver

Three Ways We Bring Clarity

Engagements usually start with one of these and expand as priorities get clearer.

Assess

Risk & Threat Assessments

  • Site, program, or organization-wide risk assessments
  • Threat identification specific to your sector and location
  • Vulnerability analysis against current defenses
  • Findings ranked by likelihood and consequence
Review

Program Evaluation & After-Action

  • Evaluation of existing security programs against goals
  • After-action review following incidents or exercises
  • Tabletop exercise design and facilitation
  • Recommendations to close the gaps that surface
How HSCG Works

From Current State To A Strategy You'll Actually Use

Assess The Current State

We review your existing program, threats, and vulnerabilities firsthand — not just on paper.

Identify Gaps & Priorities

We rank findings by real-world impact, not just by what's easiest to fix.

Build The Strategy

We turn the analysis into a sequenced, resourced roadmap your team can commit to.

Support Execution

We stay engaged as the plan rolls out, adjusting as new information comes in.

What Clients Say

Trusted With Ongoing Security Programs

“Washington Hebrew Congregation has successfully worked with David McWhorter for the past five years on enhancing our security policies and preparedness. As a high-profile organization in the nation's capital, his involvement has brought a high level of expertise and professionalism to our initiatives.”

Washington Hebrew Congregation Washington, D.C.

I have had the pleasure to work with Dave over the last several years. He's one of the best idea guys I know, and matches the big picture well, with exceptional abilities to understand and decipher complex technical issues.”

Industry Partner

FAQ

Common Questions On Analysis & Strategy

An assessment tells you where you stand today — your risks, threats, and vulnerabilities. A strategy tells you what to do about it, in what order, and with what resources. We typically deliver both, with the assessment feeding directly into the plan.

Yes. Many of our clients don't have a dedicated security function. We work directly with leadership or operations staff to build a plan that fits the team you actually have.

It depends on scope — a single-site assessment can wrap in a few weeks, while an organization-wide strategic roadmap usually runs longer. We scope timeline and cost together before starting.

Often, yes. A solid risk and vulnerability analysis is frequently part of the evidence base for both a SAFETY Act application and a grant investment justification, so this work can directly support either.

Where relevant, yes — including DHS guidance, ASIS standards, and NFPA 3000 for active shooter and hostile event response planning. We apply the standards that fit your sector rather than a one-size-fits-all checklist.

Let's figure out where to start.