An extension of your security function. Not a vendor.

Ellara Risk is a boutique security and risk management consultancy, advising organisations that operate in complex, high-risk, and politically sensitive environments.

Large firms sell infrastructure: a building, a shift rota, dozens of analysts. That overhead is real, and clients often pay for it whether or not it is ever used. Ellara Risk does not carry that fixed-cost base — but our fee reflects direct, senior access, not a discount. A large firm’s retainer often buys shared, junior-level attention. Ours buys senior judgement, every time, with no layer between you and the person doing the thinking.

We help you understand your actual exposure, prepare properly for a crisis, and meet your duty of care obligations — not as a compliance exercise, but as something you could defend if it were ever tested.

Our Four Pillars

Advisory

Security risk assessment, security policy and governance, and management planning, aligned to ISO 31000. Understanding your actual exposure — and what proportionate looks like for your organisation.

Intelligence

Protective intelligence and threat assessment. Remote assessment of a specific site, route, or operating environment. The analytical foundation that sound security decisions are built on.

Protection

Travel risk management and journey management planning, aligned to ISO 31030. Duty of care is not a policy in a drawer — it is a continuous obligation, and the standard expected of you is rising.

Response

Crisis management aligned to ISO 22361, emergency response planning to ISO 22320, and evacuation planning built for the environment rather than the template. When a client faces a genuine crisis, we activate a global network of vetted providers — security, medical, aviation, logistics — and coordinate the response.

We are advisory, coordination, and consultancy only. We do not provide physical security, close protection, or armed personnel. Where operational support is required, we coordinate vetted third-party providers on your behalf — drawn from a network built over 15 years of operational work. That boundary is deliberate. It defines what we are, and what we are not.

Craig Waugh_Founder_Ellara Risk

“With you, not for you.”

The Practitioner Behind Ellara Risk:

Craig Waugh

  • MSc Security and Risk Management — University of Leicester
  • Member of the Security Institute (MSyI)
  • NEBOSH Health & Safety qualified
  • ISO 31000, ISO 31030, ISO 22361 & ISO 22320 practitioner

Craig Waugh is the Founder and CEO of Ellara Risk, and a Member of the Security Institute (MSyI). Over 15 years of private-sector security and risk consultancy spans Europe, the Middle East, Africa, and South America — advising organisations across mining, oil and gas, finance, technology, and legal sectors through conflict, crisis, civil unrest, and complex security environments. That operational depth is matched by academic rigour: an MSc in Security and Risk Management from the University of Leicester.

His approach was shaped long before he entered consultancy. During 13 years in the Royal Marines, Craig held command and instructional appointments and deployed internationally across a range of medium and high-threat environments. That experience developed the judgement, resilience, and decision-making required to lead through uncertainty — qualities that now underpin the advice he provides to boards, executive teams, and organisations managing complex risk.

More than 25 years of operational leadership and international consultancy. All of it live, none of it theoretical. For a board or executive team, that means independent advice grounded in what has actually happened in the field, assessed with the rigour a governance review demands.

The name is personal

Ella honours my late daughter. Ara reflects protection, sanctuary, and security.

Everything produced under this name carries a personal standard as well as a professional one.

Years Experience
12 +
Cases & Projects
121 +
Deployments
23 +
Major Crisis Events
0 +