An honest answer, rather than a reassuring one
Most organizations have security and safety measures. Rather fewer have tested whether those measures work under the conditions they were bought for, and the gap between the two is where incidents happen.
A security and safety assessment establishes what your arrangements actually do — at a specific site, for a specific workforce, against the threats that are realistic for you rather than the ones a generic template lists. It covers physical security, the systems and procedures around it, emergency and evacuation planning, and whether your people know what to do without being told.
We do this across every risk environment, from a warehouse in a stable market to a facility where evacuation planning is not hypothetical. The output is written to be uncomfortable where that is warranted. An assessment that tells you everything is fine has not earned its fee.

Questions clients bring us
What the assessment covers
An assessment examines the arrangements as they operate, not as documented. In practice that means:
- Physical security — perimeter, access control, who actually holds keys and credentials, and whether the badge system reflects the current headcount.
- Systems and monitoring — detection, alarms, and whether an alert reaches a person who is empowered to act on it at three in the morning.
- Emergency and evacuation planning — including personnel evacuation from a deteriorating environment, which is the plan most often written once and never rehearsed.
- People — whether staff and contractors recognize a problem and know the route to report it. Most incidents are noticed by somebody before they escalate.
- Regulatory obligations — the safety and security standards that apply to your sites and sector, and whether you can evidence compliance.
Where the exposure runs to travelling or posted staff, it connects directly to duty of care, which is a legal obligation in many jurisdictions and follows where your people are rather than where you are. Where the concern is a digital route into a physical facility, it runs alongside cybersecurity.
What it is not. We are not selling you equipment, and we do not take a margin on anything we recommend. That independence is the point: an assessment written by a party who profits from the remediation is not an assessment.
How the engagement runs
Assessments can be one-off or recurring. The stages are the same either way.
The testing stage is what separates an assessment from an inspection. A door that locks, an alarm that sounds and a plan that exists all pass inspection; whether the alarm reaches somebody who acts on it at three in the morning is a different question.
1. Scoping to realistic threats
We establish what is actually plausible for your sites, sector and locations — theft, intrusion, violence, industrial accident, civil disruption, or the need to move people out quickly — and scope to those rather than to a generic checklist.
2. On-site inspection and interviews
Walk-throughs, documentation review and conversations with the people who work the site. Staff generally know where the weaknesses are, and are rarely asked.
3. Testing
Where appropriate and agreed, we test rather than assume: whether access control can be walked past, whether an alarm produces a response, whether the emergency plan survives contact with the people expected to execute it.
4. Reporting and prioritization
Findings are ranked by exposure and by cost to close, so a limited budget goes to the things most likely to hurt you. Recurring assessments then track whether last year’s findings were actually closed — which, honestly, is where most programs fall down.
When to commission one
- Before opening or acquiring a site, particularly in an unfamiliar market.
- After an incident or a near miss — including one at a comparable organization.
- When the security arrangements were designed for an operation you have since outgrown.
- When an insurer, regulator or major client asks for evidence of your arrangements.
- When conditions in a location are deteriorating and evacuation has moved from theoretical to foreseeable.
- On a schedule, where sites are numerous enough that memory is not a control.
What you get
- A written report per site, with findings ranked by exposure.
- For each finding: what is wrong, what it would take to fix, and what it costs to leave.
- An assessment of emergency and evacuation planning against realistic scenarios.
- Findings on regulatory obligations and whether compliance can be evidenced.
- A short list of what to do first, on the assumption that the budget is finite.
Straight answers
Are our systems ready for new threats?
Usually partly. Systems tend to be sound against the threat that prompted their purchase and untested against everything since. The gap is normally in procedure and response rather than in equipment.
Do we have the right resources allocated?
The common pattern is over-investment in visible measures and under-investment in the unglamorous ones — access reviews, drills, keeping the call list current. Visible security is easier to fund because it is easier to point at.
Are our people sufficiently aware?
Awareness is not the binding constraint as often as people assume. Willingness to report is. If raising a concern has ever been treated as an inconvenience, that is the finding.
Do we need to overhaul everything?
Rarely. Most assessments produce a handful of things that genuinely matter and a longer list that can wait. Anyone recommending a full overhaul as a matter of course is describing their commercial model rather than your risk.
Can you assess sites in difficult locations?
Yes. That is where the work is most worth doing and where a remote or desk-based assessment is least reliable.
Falcone International
Get in touch about security and safety assessments
Tell us the sites and what worries you about them. We will tell you what an assessment would cover and what it would establish — without obligation, and in confidence.
Further reading
Selected from our Book of the Month series for their bearing on this service.
People HackerBarratt’s account of physical intrusion makes the point that the barrier is never the control — the person operating it is. Any assessment that stops at doors, locks and cameras will miss the route she would actually take.
SpycraftAkkerman and Langman trace four centuries of measure and countermeasure in concealment, interception and verification. It is a long view that helps distinguish a genuinely new threat from an old one in different clothes.
The Gift of FearThe signals that precede an incident are almost always present and almost always ignored. De Becker’s practical contribution is showing how to train staff to verify politely, rather than making them choose between rudeness and risk.
