Physical security assessment
A physical security assessment that started with the loading dock
An ASX listed technology manufacturer
The situation
The company had grown out of a building it had secured as a startup. Access control had been added a door at a time, the visitor process was whatever reception could manage on a busy morning, and nobody could say who currently held a key. A customer with its own security requirements had begun asking questions the company could not answer in writing.
The work
- The site was assessed as it actually operates rather than as the plans describe it: the doors people prop, the after hours arrangement rather than the business hours one, and the contractors whose access had outlived their engagement.
- Findings were graded on what a failure would cost this business specifically, since the manufacturing floor and the design office are not the same risk, rather than against a generic severity scale.
- Each recommendation carried what closing it involves, so the report could be worked through by whoever held the budget without needing the consultant to interpret it.
What was delivered
A written assessment the company could hand to the customer asking the questions, with the areas that could not be examined named as gaps rather than left silent.
This engagement is described by sector rather than named, and carries no outcome statistic, because a number nobody measured is not evidence. The other engagements · Talk to a consultant
