Questions to ask before commissioning a mitigation plan
Ask the right questions before commissioning a mitigation plan. Learn what good answers sound like and which responses signal weak consulting.
A mitigation plan sits between diagnosis and action. Someone has assessed your security weaknesses; now you need a roadmap to fix them within your constraints. But a plan is only useful if it's tailored to your reality, not a generic template, and if the person writing it has tested their recommendations against your actual environment. Before you commission one, you need to know whether the consultant understands your business and your limits.
"How will you involve my team in developing this?"
A mitigation plan that ignores how your business actually works will sit on a shelf. A good answer here includes site visits, interviews with staff who manage security day-to-day, and walkthroughs of your systems. The consultant should ask *you* questions about workflow, budget cycles, staffing constraints and what you've already tried. Watch for vague promises—"we'll assess your environment"—versus specific commitments. They should explain how they'll translate technical findings into steps your team can execute. If they suggest outsourcing everything rather than building capability in-house, ask whether that's because you genuinely can't do it, or because it's easier for them to sell.
"What's your process for prioritising recommendations?"
An unranked list of 50 fixes is useless. Ask how they decide what comes first. A solid answer ties priority to *your* risk tolerance and budget: which vulnerabilities pose the greatest threat, which are cheapest to fix, which will unlock other improvements. They should explain their logic—not just hand you a spreadsheet. If they say "we'll prioritise based on industry best practice," push back. Best practice for a bank differs wildly from best practice for a small retail business. They should ask you directly: if you can only act on three things this year, what matters most to your operations? Their answer should reflect that conversation, not a formula.
"Will you spell out what 'done' looks like for each step?"
Vague language kills plans. Instead of "improve access control," a good mitigation plan says "install biometric readers on the warehouse door, log all entries, audit logs monthly, and retrain staff on badge protocol by March." Before you commission the plan, ask the consultant how detailed they'll get. A strong answer includes measurable outcomes, timelines, who's responsible, and how you'll know it's working. They should also explain which recommendations have dependencies—step two can't happen until step one is complete. If they're comfortable with loose language now, their plan will be too.
"How will you account for what we're already doing?"
Mitigation plans are often written without seeing what's already in place. Ask whether the consultant will audit your current measures before drafting the plan. A good answer is yes—they'll document locks, cameras, software, staff training, visitor protocols, everything—then build on that foundation rather than proposing redundant layers. They should also ask what you've *tried and abandoned* and why, so they don't repeat dead ends. An evasive answer—"we'll work from your risk assessment"—suggests they plan to write the plan without properly knowing your baseline. That's a red flag. They're less likely to deliver something realistic, and you'll waste time explaining why their recommendations won't work for you.
The consultant should be comfortable with tough questions now because implementing the plan will involve even harder conversations later. If they deflect when you're vetting the approach, imagine how they'll handle pushback when your finance team balks at a five-figure bill or your operations manager says a recommendation breaks the workflow.
When you're ready to find someone to develop a plan, Strove lets you compare consultants' experience, qualifications and client feedback, then request quotes from several to see how each one approaches the problem.
Common questions
- Should the consultant see our building and systems before drafting the plan?
- Yes. A plan built without site visits and interviews with your team will likely miss critical context about your actual workflows, constraints and existing measures. The consultant should audit your current setup, not just work from a prior risk assessment report.
- What if the consultant's timeline doesn't match our budget cycle?
- Discuss this upfront. A good consultant will help you phase the plan—urgent fixes first, longer-term improvements staged across budgets. If they insist on an all-or-nothing approach, it signals they're not thinking about your reality.
- How do we know if the plan is realistic or just a wish list?
- Test it against your actual constraints. The consultant should explain *why* they've prioritised each step, what resources and skills it requires, and how you'll execute it with your current team. If the answers feel vague or disconnected from your operations, it's a wish list.
- Should we ask for references from other clients in our industry?
- Yes, if possible. But also ask to speak with clients in *different* industries—that shows the consultant adapts their approach rather than applying templates. Listen for whether the consultant involved the client's team and delivered a usable plan, not just a report.
Find a verified provider on Strove
Compare vetted risk mitigation planning providers, check their credentials, and book or request a quote — all in one place.
Find a Business