The Five Questions Every Physical Security Assessment Must Answer

A physical security risk assessment that does not produce actionable recommendations is a liability exercise, not a security tool. The difference between the two is not length or methodology jargon. It is whether the document answers five questions in terms a decision-maker can act on.

1. What are we protecting, and what is it worth?

Every defensible assessment begins with an asset inventory: people first, then operations, information, property, and reputation. “Worth” is not only replacement cost. A server room and a childcare room may occupy the same square footage; no rational program protects them equally. If an assessment does not rank assets by consequence of loss, every subsequent recommendation floats free of justification.

2. Who or what threatens it?

Threat identification has to be specific to the site, the occupant, and the moment. A commercial landlord, an NGO field office, and a consulate in the same building face different adversaries with different capabilities and intent. The assessment should name threat categories (criminal, protest-related, terrorist, insider, workplace violence, natural hazard) and state the evidentiary basis for each: incident history, local crime data, the occupant’s public profile, and regional threat reporting. Where the basis is thin, the assessment should say so rather than inflate.

3. Where are we exposed?

Vulnerability is the gap between the threat’s capability and the site’s current condition. This is the fieldwork core of the assessment: perimeter and approach, access control points and their failure modes, interior compartmentation, security staffing and post orders, technical systems and their maintenance state, and procedures as practiced rather than as written. The written program and the observed program are often two different programs; the assessment must document the one that actually operates.

4. What happens if we fail?

Consequence analysis converts vulnerabilities into stakes: injury or loss of life, operational interruption, legal exposure, reputational harm. This is the question that connects the security assessment to the organization’s own risk language, and it is the reason the standard threat, vulnerability, and consequence structure appears in recognized guidance such as ISO 31000 and ASIS International’s risk assessment standards. An assessment written in this structure can be read by a board, an insurer, or counsel without translation.

5. What do we fix first, and what does it cost?

The output that separates a security tool from a liability exercise: a ranked list of recommendations, each tied to a specific vulnerability, with an order-of-magnitude cost and an owner. Ranking forces the assessor to commit. Twenty recommendations of equal apparent weight transfer the prioritization problem to the client, who is the person least equipped to perform it.

The Unwritten Sixth Question

Will any of it be implemented? Assessments fail at the implementation boundary more often than at the analytical one. The practical remedies are unglamorous: recommendations phased against real budget cycles, quick wins identified for the first ninety days, and the assessor available past the report date. In my own practice, assessment-driven programs have produced measured results, including a 60% reduction in incident rates across a portfolio of 15 embassies and international NGOs in East Africa over a seven-year tenure. None of that came from the report. It came from what was built, staffed, and drilled afterward.

Further Reading

ISO 31000, Risk management. Guidelines: https://www.iso.org
ASIS International, standards and guidelines on security risk assessment: https://www.asisonline.org

Murray Physical Security Group delivers site-specific physical security risk assessments in New York City and worldwide. Schedule a consultation.