Signs a plan is a shopping list, not a strategy
Spot the difference between a security shopping list and a real strategy. Learn what makes a plan actionable and how to avoid wasting money on disconnected fixes.
You've just received a document from a security consultant. It's thick, professional-looking, and lists dozens of things you should do: upgrade locks, install cameras, train staff, monitor access points, conduct audits, test response procedures. You scan the pages and feel a mix of relief (there's a plan) and dread (where do you even start?). That relief might be misplaced. What you're holding could be a shopping list dressed up as strategy—and the difference between the two will determine whether your business actually becomes safer or simply spends money on disconnected fixes.
A shopping list looks complete because it names many things. A strategy explains *why* those things matter in relation to each other, *which ones address your actual exposure*, and *what happens when*. When a consultant delivers a document that reads like a catalogue without connecting tissue, you've spotted a common failure mode early enough to course-correct.
How shopping lists hide as plans
The mistake often begins innocently. A consultant interviews staff, reviews your site, asks about past incidents, then compiles every control that could theoretically reduce risk. The document feels thorough. It addresses physical security, personnel vetting, incident response, technology, compliance. For a reader who doesn't work in security, it looks responsible—comprehensive, even.
But listen for these warning signs that you're reading a list, not a strategy:
- No stated threat model. The plan doesn't explain what you're actually defending against or why. It just says you need better controls. A strategy opens with the specific risks you face—theft by staff, external break-ins, data breaches, supply chain disruption—and each recommendation traces back to one of those concrete threats.
- Measures sit in isolation. You'll see "implement access control system" in one section and "review visitor procedures" somewhere else, with no explanation of how they work together. A real strategy shows you the connections: this access system feeds into this incident response process, which assumes you've already trained people in these procedures.
- No sequencing or phasing. A shopping list treats everything as equally urgent. A strategy ranks actions by impact and feasibility: which controls address your highest exposures, which are prerequisites for others, which can you realistically resource in the next quarter. Without this, you end up paralysed or spending first on the easiest item rather than the most critical one.
- Cost estimates are vague or missing. A list says "upgrade CCTV" without clarifying scope, configuration, or total cost. A strategy breaks this down: why that system, what coverage it covers, what it costs, whether it's phase one or phase two, and how it depends on other measures already in place.
- No measurable outcome. After you've done everything on the list, how will you know you're safer? A shopping list assumes completion itself is the goal. A strategy defines what success looks like—maybe it's reducing theft incidents by a target percentage, or ensuring incident response drills meet a time threshold—and explains how the plan leads there.
Spotting the pivot point
If you're holding a document that feels like a list, don't reject it outright. Use it as a starting point for a conversation. Ask the consultant to map each recommendation back to a specific threat or vulnerability you're facing. Ask them to show the sequence and dependencies. Ask what happens if you can only afford 60 per cent of the plan—which pieces do you implement first, and why.
A consultant who can answer these questions has a real strategy underneath the recommendations. One who responds with vague assurances or repetition has delivered a list and stopped before the harder work of connecting it to your reality.
The cost of a shopping list is wasted budget and false confidence. You feel like you've done something because you've bought the items, but the items don't address your actual exposure or work together. A strategy costs the same in consultant time but saves money downstream—because you're investing in the right things, in the right order, with clear sight lines to measurable safety improvement. When you're vetting someone to build your plan, listen for their ability to move beyond items into logic. Strove can help you find consultants who build mitigation strategies that hold together, not catalogues of isolated fixes.
Common questions
- What's the difference between a list and a strategy in a risk mitigation plan?
- A list names controls without explaining why they matter, how they connect, or which to do first. A strategy traces each recommendation back to a specific threat, shows how measures work together, sequences them by priority and feasibility, and defines measurable outcomes. The same consultant could produce either—the difference is in the thinking, not the length of the document.
- How do I ask a consultant about their approach before I hire them?
- Ask them to walk you through an example of a past plan: what threat did it address, how did they prioritise recommendations, and how did the client know whether it worked. If they can't explain the logic or keep referring back to the individual items rather than the overall strategy, that's a flag.
- Can I turn a shopping list into a strategy myself?
- You can try, but it requires understanding your actual exposures and how controls interact—the same expertise a consultant brings. If you're doing this yourself, start by naming the threats you're most concerned about, then map each control to one of those threats and decide the order based on urgency and dependencies. This process often reveals gaps in the list that professional advice would have caught.
Find a verified provider on Strove
Compare vetted risk mitigation planning providers, check their credentials, and book or request a quote — all in one place.
Find a Business