Somalia is frequently described as high risk. As a broad national descriptor, that may be understandable. As a framework for operational decision-making, it is inadequate. A country label cannot tell a board which people, activities, routes or sites are exposed, nor which controls would materially reduce that exposure.
The question a national rating cannot answer
Threat is external: the intent and capability of an actor, or the potential for a hazardous event. Operational risk emerges when that threat meets a particular organisation's vulnerabilities, assets, activities and control environment. The useful question is therefore not simply 'How risky is Somalia?' It is: 'Risk to whom, while doing what, in which place, and through which threat vector?'
A national threat label is context. It is not an operational decision.
The exposure paradox
Consider two international non-governmental organisations working from the same part of Mogadishu. Organisation A operates mainly from a fortified, blast-resistant compound with controlled access and vetted static guards. Its most consequential threat vectors may include indirect fire and a complex assault against fixed infrastructure. Its vulnerability is shaped by site design, stand-off distance, access procedures, guard performance and the reliability of safe areas.
Organisation B supports decentralised health activity and regularly moves staff or partners along rural corridors. Its exposure is mobile. Kidnap, improvised explosive devices, changing checkpoints, road accidents and localised clan tension may matter more than compound protection. Its controls depend on route-specific information, acceptance, movement timing, communications, abort criteria and disciplined journey management.
The wider threat environment may be shared, but the operational risk profiles are not. One organisation may need to prioritise physical protection and access control; the other may gain more from community acceptance, route assessment and movement discipline. Applying one national score to both obscures the decisions that need to be made.
Spatial divergence within Somalia
Country-level aggregation also hides the distance between local operating environments. Mogadishu, Garowe, Baidoa and Kismayo should not be treated as interchangeable points on a national map. Open-source reporting supports differentiated assessment, although access restrictions, uneven reporting and rapid local change limit confidence and require regular review.
- Mogadishu: exposure varies sharply by district, route, time and proximity to government or security infrastructure. Complex attacks, improvised explosive devices, indirect fire and targeted violence require site- and movement-specific controls.
- Garowe: the operating environment is generally more stable than Mogadishu, but political tension, local disputes, crime, road movement and organisational compliance still require assessment. Relative stability is not the absence of risk.
- Baidoa: access is shaped by the city's security perimeter, displacement dynamics, surrounding armed-group influence and the routes used to reach programme locations. A city rating alone says little about field movement.
- Kismayo: risk is influenced by Jubaland political dynamics, armed-group activity outside the city, airport-to-city movement and the specific districts an organisation must reach.
Why flat ratings produce bad board decisions
A flat rating can push decision-makers towards two opposite errors. The first is defensive paralysis: suspending activity because the national label is severe even where exposure can be reduced to an accepted level. The second is false reassurance: permitting an activity because an office or city appears comparatively stable while ignoring the route, timing, staff profile or local trigger that creates the real exposure.
Neither error is corrected by adding more alerts. The problem is architectural. Information has not been connected to the organisation's activities, vulnerabilities, controls and decision thresholds.
A more useful risk architecture
A defensible model begins below country level and records the reasoning that turns information into a decision. At minimum, the assessment should distinguish the following elements:
- Activity: the mandate being delivered, its duration, visibility and tolerance for interruption.
- Asset: the people, facilities, information, vehicles, partners and reputation that could be affected.
- Location and route: the site, corridor, destination and time window in which exposure occurs.
- Threat vector: the actor or hazard, its intent, capability, opportunity and recent indicators.
- Vulnerability: the conditions that make harm more likely or increase its consequences.
- Controls: existing preventive, protective and responsive measures, with a named owner.
- Residual risk: the exposure remaining after controls, recorded with confidence and review triggers.
From static spreadsheets to accountable review
The problem is not that spreadsheets are inherently wrong. It is that static files often separate the assessment from the evidence, owner and review trigger. A browser-based register can make the chain visible: source, verification status, threat, vulnerability, likelihood, impact, mitigation, residual position, confidence, owner and next review. The technology is useful only when it improves accountability; it cannot replace judgement or reliable local engagement.
For boards, the reporting line should move from a single colour to a short decision statement: what activity is proposed, what could affect it, why the organisation is exposed, which controls are in place, what remains, what would trigger a pause, and who accepts the residual risk. This makes challenge possible without asking directors to become field security specialists.
Operational implication
Risk intelligence should not exist to defend a country label. Its purpose is to support proportionate action. Granular exposure modelling allows security to identify where an activity can proceed, what must change first, and which indicators would require reconsideration. Used this way, security becomes an operational enabler without pretending that uncertainty can be removed.
This analysis is an independent practitioner assessment based on public sources and established risk-management principles. It does not use privileged operational reporting and should not be treated as organisation-specific advice. Conditions in Somalia vary quickly; any movement or programme decision requires current, locally verified information and an assessment of the organisation's actual profile.