ESRM Program · People Cluster
Travel Risk Management
Know where your people are, and know what to do when a trip goes wrong.
$2,500 fixed-fee assessment 3–4 weeks Credited toward the vCSO program
Measured against ISO 31030. Led by Don Oxman, CPP, CISSP, CISM. Licensed by Texas DPS. In business since 2013.
Most travel programs stop at booking and expenses.
Travel risk is one of thirteen domains in our Enterprise Security Risk Management (ESRM) program, and part of the People cluster with Workplace Violence Prevention and Threat Management. It applies to anyone who travels for work: a sales team flying to a trade show, a field crew on the Gulf Coast during hurricane season, an executive closing a deal in Mexico City.
In most companies, travel is handled by whoever books the flights and approves the expense reports. Nobody owns the harder questions. What happens when a traveler is injured, arrested, or caught in a storm? What happens to the company data on the laptop they carried through customs? When something goes wrong, the response gets improvised by whoever picks up the phone. We help you settle those answers in advance, write them down, and practice them.
What can go wrong on a business trip
Health & medical
A traveler gets sick or hurt somewhere without trusted care, and someone has to decide whether to treat locally or evacuate, usually with no plan and no approved budget.
Security & crime
Theft, express kidnapping, and civil unrest are real risks in many ordinary business destinations, including places with no government travel warning.
Disaster & disruption
Hurricanes, airport closures, and power outages can strand people for days and pull them away from the work they were sent to do.
Digital exposure
Laptops and phones get inspected at borders, joined to hotel Wi-Fi, and left in rooms. Whatever data is on them is exposed along with the device.
Executive targeting
Social media posts, shared calendars, and fitness-app check-ins can reveal where an executive is staying. Fake travel confirmations are a favorite phishing lure for their assistants.
Legal & reputational
Employers owe traveling staff a duty of care. A badly handled incident can turn into a lawsuit, a problem with local authorities, or a news story.
Five questions for leadership
- Could you confirm the location and status of every traveler within one hour of an incident?
- Is there a written travel policy with approval thresholds for higher-risk destinations?
- Do executives travel internationally with the same laptop that holds your most sensitive data?
- Does your team know exactly who to call — assistance provider, insurer, counsel — and in what order?
- Has anyone ever rehearsed a “traveler in distress” scenario end to end?
If you answered “no” or “not sure” to any of these, that is where we would start. Most of these gaps cost little to fix before an incident and a great deal to fix after one.
How an Engagement Works
Every ESRM domain starts with the same fixed-fee assessment. If you decide to continue, we credit the fee toward the program, and travel risk becomes part of your vCSO engagement alongside whichever other domains you need.
Travel Risk Assessment
- Interviews with HR, whoever books travel, IT, and one or two frequent travelers.
- Structured review: a 15-question risk profile, a 25-point practices checklist, and a maturity score from 1 (Initial) to 5 (Optimized).
- Traveler profile: who goes where, how often, and what company data they carry.
- Gap analysis against ISO 31030, the international standard for travel risk management.
- Written report and prioritized roadmap, walked through with your leadership team. The report is yours whether or not you continue.
The fee is credited in full toward the program if you start within 90 days.
The vCSO / ESRM Program
- Assess (Q1): we start from your assessment findings.
- Build (Q2): travel policy, destination risk ratings, approval rules for higher-risk trips, a traveler check-in and escalation process, and an incident playbook.
- Providers: we help you choose assistance, evacuation, and insurance providers that fit how your people actually travel.
- Tabletop exercise with your leadership team, so the first run of the playbook is not a real emergency.
- Operate (Q3+): we stay on as the named owner, with quarterly reviews, annual traveler training, and reporting to leadership or your board.
Month to month. Cancel with 30 days’ notice. About the vCSO program →
Trip & Traveler Services
- Pre-trip briefing on the destination: security, health, local laws, and customs.
- Itinerary and hotel review for high-profile or higher-risk trips.
- Secure travel devices: clean or loaner laptops and phones, set up with your IT provider.
- Executive protection when the risk calls for it, planned and coordinated by Total 360.
Why Total 360
Physical and cyber, one advisor
Travel risk involves both the person and the devices they carry. Most firms handle one or the other. We handle both, so nothing gets lost between two vendors.
Independent recommendations
We don’t resell assistance, insurance, or tracking products, and we take no commissions. We recommend what fits your travelers.
Experienced leadership
Led by Don Oxman: M.S. in Security Management, CPP, CISSP, CISM. U.S. Army and AT&T background. In business since 2013 and licensed by Texas DPS.
Common questions
What does a travel risk assessment cost?
$2,500, as a fixed fee. It usually takes three to four weeks from kickoff to the readout. If you start the vCSO program within 90 days, the full fee is credited toward it.
What do we get at the end of the assessment?
A written report with your maturity score from 1 (Initial) to 5 (Optimized), the gaps we found against ISO 31030, the international standard for travel risk management, and a prioritized roadmap. We walk your leadership team through it, and the report is yours whether or not you continue.
Do we have to sign up for the full program?
No. The assessment stands on its own. If you continue, travel risk runs inside the vCSO program at $2,500 to $7,500 a month depending on scope. It is month to month, and you can cancel with 30 days’ notice.
Can we buy trip & traveler services without the program?
Yes. They are available to any client. Billed per trip, quoted in advance.
Will you replace the people and providers we already use?
No. We work alongside your IT provider, attorney, insurer, and other advisors. We set the standard, help them meet it, and check that the work gets done.
Start with a 30-minute Risk Discussion
No deck and no sales pitch. Tell us where your people travel and what concerns you. We’ll give you an honest read on the gaps and send a scoped proposal within five business days.
Schedule a Risk Discussion Or call 817-677-0515 · info@total360security.com