Crisis and security risk consulting
A maritime security plan that had to survive an audit, not just an approval
A northern Australian port operator
The situation
The operator held an approved security plan that had been written to get approved. It described a facility that had since changed, referred to roles nobody currently held, and would not have survived contact with an inspection.
The work
- The security risk assessment underneath the plan was rebuilt first, because a plan that is not traceable to an assessment cannot explain why any of its controls exist.
- The plan was rewritten against the regime the operator actually carries, with the maritime security levels and the reporting obligations stated in the operator’s own terms rather than quoted from the Act.
- Personnel security was addressed as a process rather than a card count: who needs unmonitored access, what happens when they leave, and who notices if a card is not returned.
What was delivered
A plan the operator could work from on an ordinary day, and defend on an inspection day.
This engagement is described by sector rather than named, and carries no outcome statistic, because a number nobody measured is not evidence. The other engagements · Talk to a consultant
