A physical security assessment should help an owner decide where to act first. A long list of cameras, fences, doors and procedural gaps is not enough. The assessment must connect assets, credible threats, vulnerabilities and consequences in a form that leaders can fund, engineers can design and operators can maintain.

Define the decision before the site walk

Begin by stating what the assessment must support: a capital plan, acquisition review, insurance discussion, design basis, incident follow-up or periodic risk update. Confirm the sites, buildings, operating hours, occupied areas, critical processes and excluded topics. A clear scope prevents the assessment from drifting into a generic checklist.

Use four connected questions

  1. Asset: What people, functions, information, equipment or dependencies require protection?
  2. Threat: What credible intentional, accidental or environmental event could affect them?
  3. Vulnerability: What feature, condition or process allows the event to succeed?
  4. Consequence: What life-safety, operational, financial, legal or reputational harm could follow?

Risk scoring can help compare issues, but the number is not the analysis. Document assumptions and use consistent definitions. A simple, transparent matrix is usually more useful than a complex formula that leaders cannot explain.

Inspect the full protection path

The site review should begin outside the property and move inward. Observe public approaches, neighboring uses, elevation, vegetation, lighting, vehicle routes, parking, gates, fences, loading areas and emergency access. At the building, review entrances, glazing, walls, roofs, utility penetrations, service rooms, access credentials, monitoring and response paths.

Interview the people who operate the facility. They often know where doors are propped open, cameras are obstructed, gates fail, deliveries bypass procedures or critical equipment cannot be shut down. Drawings show intended conditions; operators reveal actual conditions.

Separate observations from findings

An observation records a condition. A finding explains the risk. “Electrical equipment is visible from the road” is an observation. A complete finding identifies the affected asset, credible threat, vulnerability, consequence, existing controls and recommended next step.

Build a decision-ready risk register

FieldPurpose
Asset and ownerNames what matters and who is accountable.
ScenarioStates the threat action and pathway.
Existing controlsPrevents the team from treating every site as unprotected.
Vulnerability and consequenceExplains why the issue deserves attention.
Priority and rationaleSupports consistent capital decisions.
Mitigation, cost and scheduleTurns analysis into a managed action.
Residual riskRecords what remains after completion.

Choose the right mitigation layer

Not every finding requires construction. Some can be addressed through procedures, staffing, access administration, lighting, vegetation management or equipment relocation. Others require physical delay, ballistic resistance, forced-entry resistance or a hardened enclosure. The assessment should state the performance need without prematurely locking the owner into one product.

Implementation reference: When the risk register identifies a need for hardened concrete or masonry, owners can compare systems such as Amidon Shield and ArmorBlock with other qualified approaches using the same evidence criteria.

Reassess after change

Update the assessment after construction, a major tenant or process change, an incident, a new neighboring development or a meaningful change in threat information. A risk register that is never updated becomes a historical document rather than a management tool.

Frequently asked questions

How often should an assessment be performed?

There is no universal interval. Use a scheduled review appropriate to the site and trigger a reassessment when assets, occupancy, layout, operations, threat information or surrounding conditions materially change.

Who should participate?

Include facilities, security, operations, safety, information technology, risk management and leadership. Add engineering, insurance, emergency response and legal input where relevant.

Should the assessment recommend products?

It should define performance needs and possible solution categories. Product selection should follow evidence review, design coordination, procurement and site-specific engineering.

Need to frame a facility decision?

ISCoA helps owners organize physical security exposure, mitigation priorities and evidence requirements before product selection.

Request a preliminary review