Contact Form – Event Innovation Forum
Read article

27.08.2026 | 6 min read
Most security plans only get a fundamental review once something forces the issue — an incident, a major investment decision, or a new set of requirements to meet. Until then the reasoning usually runs like this: access control works, the cameras are producing images, the guard force is on site, so the location must be adequately protected.
That conclusion doesn’t hold up. Individual controls can function perfectly well in technical terms while their protective value within the wider system quietly erodes. Buildings change. Responsibilities move. Processes get adjusted and new systems are added. Meanwhile, threats and operational dependencies keep developing.
A Resilience Health Check therefore does not start with the question of what technology to add. It starts by asking whether the security plan you already have still matches the protection your site genuinely requires.
Its value lies in the structure it imposes. A structured review of physical security gives an organisation a clear view of which areas are soundly set up, where weaknesses or ambiguities sit, which risks are visible within the agreed scope, and which next steps follow sensibly from that picture.
Physical security is produced by the interplay of structural, technical, organisational and personnel controls. What matters is not only whether a component works, but whether it performs its intended job inside a coordinated security process.
An intruder alarm system may trigger reliably every time. If it is unclear who assesses the alarm, what response time is required and how the intervention is organised, its real protective effect is limited.
The same logic applies elsewhere:
The technical condition of individual systems, then, says very little about how resilient a site is overall.
A physical security assessment is a structured security analysis carried out within a scope defined in advance. It evaluates the current state of physical and organisational security at a site or facility, identifies weaknesses, and creates a basis for prioritised recommendations and any deeper investigation that may be needed. Depending on the provider, the same exercise is sold as a physical security audit, a site security assessment or — as in the case of the e-shelter security Resilience Health Check — a resilience assessment.
Existing protective controls are not examined in isolation. They are assessed in relation to:
An assessment of this kind is neither a pure technology inspection nor a full risk and threat analysis. It evaluates risks within the agreed scope and shows where a deeper investigation is required.
A physical security assessment is not something you commission only after an incident. Organisational and operational changes are often the earlier signal that the current security plan needs reviewing.
Few security estates were designed in a single project. Controls arrived one at a time: extra cameras, new card readers, revised locking zones, additional barriers, fresh tasks for the guard force.
Each individual addition may have been perfectly sensible. Over time, though, you end up with several generations of technology side by side, inconsistent processes and dependencies nobody can fully trace.
A clear warning sign is when basic questions cannot be answered with confidence:
Where those answers are missing, the security level rests more on inherited assumptions than on a current evaluation.
Weaknesses rarely appear inside a single system. They appear at organisational interfaces. Typical examples include:
When several parties each know only part of the process, a gap opens up in the sequence as a whole.
Refurbishments, new usage areas, altered circulation routes or additional delivery zones all affect existing protection arrangements. So do organisational changes such as remote working, a larger contractor population, new operating hours or revised production processes.
Even small adjustments can invalidate security assumptions made years earlier.
Doors left open, badges that were never deactivated, false alarms and unclear responses do not necessarily cause immediate damage. When they recur, however, they point to structural weaknesses.
This is exactly where we come in. e-shelter security evaluates the current state of physical and organisational security in a structured way and within a defined scope — vendor-independent and with no predetermined technology answer. If you want to place individual observations in their wider context, the Resilience Health Check is the right starting point.
The exact shape of the review depends on the site, the required level of protection and the agreed scope. A physical security assessment normally covers several perspectives.
The first question is what actually needs protecting. That can include:
Not every area needs the same intensity of protection. What matters is whether the objects to be protected and their priorities have been defined in a way that can be followed and justified.
Existing controls are examined in their functional context. That typically covers:
The point is not simply whether technology is present. The review asks whether the controls suit how the site is used, whether they work together sensibly, and whether they can be integrated into day-to-day operations. In a well-designed estate these layers reinforce one another, which is the principle behind multi-layered security.
A reliable security plan needs clear processes. The following areas are therefore examined as well:
These are precisely the areas where the gap between the documented plan and everyday practice tends to widen over time.
Security personnel form part of the overall picture too. Relevant points include:
Again, the question is not whether personnel are deployed, but what function they perform within the security process.
Security does not end when an event is detected. An assessment therefore also looks at how the organisation responds to disruption.
Relevant elements include:
Resilience does not mean preventing every event outright. It means limiting the impact and staying able to act.
Modern security systems are increasingly networked. Access control, video, building services and control room platforms all have digital interfaces and can depend on IT infrastructure — a dependency that grows with every smart building function added to the estate.
A physical security assessment does not replace a full cyber security review. It should, however, make visible where physical security, IT, building operations and organisational processes depend on one another.
The precise sequence depends on the size, complexity and protection requirements of the site. A structured review usually runs through five steps.
At the outset, you define which sites, areas and topics are to be examined. Equally important is the question of what decisions the organisation wants to prepare with the results.
Typical triggers include:
Existing documents provide the first overview. They can include:
Missing, contradictory or outdated documents are themselves an indication that organisational work is needed.
A site walkthrough shows how controls are actually implemented and used. Conversations with the responsible departments make it possible to compare documented processes against operational practice.
Depending on the organisation, that can involve security managers, facility management, IT, health and safety, site management and external service providers.
Findings are not simply collected. They are ranked by significance within the agreed scope — the step that turns a list of observations into a genuine security gap analysis.
The review distinguishes between:
A physical security assessment does not replace a full risk and threat analysis with comprehensive scenario evaluation. It does, however, allow an initial risk classification, and that creates the basis for a defensible order of priority.
The review ends with a structured summary of the current state. It should make clear:
That is what turns a current-state review into a basis for decisions.
The practical benefit of an assessment does not come from producing the longest possible list of defects. It comes from a clear, prioritised classification of what was found.
A robust result should contain:
Not every finding has to lead to a technical investment. The most useful first steps often lie in clearer responsibilities, updated processes, cleaned-up permissions or better documentation.
Other findings will call for a deeper physical security risk assessment, a technical inspection or a revision of the security plan.
Recommendations also have to be more than technically sound. They must fit into existing structures and operating routines, and they must not compromise the availability of critical functions.
Security problems are rarely solved by a single control. Recommendations should therefore be classified according to the functional contribution they make to overall protection.
A technical control might enable better detection. Organisational controls determine how an alarm is assessed and escalated. Personnel controls determine who can respond and what competencies they need to do so.
This technical, organisational and personnel view — often called the TOP principle — helps to prevent controls being planned in isolation. Structural conditions remain a separate element of the physical security architecture and have to be considered alongside them.
A physical security assessment is designed as a structured analysis with a bounded scope. It does not replace:
That boundary matters. An assessment can identify weaknesses, evaluate risks in broad terms and develop concrete recommendations. Complex sites, particularly high protection requirements or specific regulatory obligations will call for further work beyond it.
Not every finding leads to the same follow-up project.
Where the issues are mainly unclear responsibilities, documentation or individual procedures, targeted organisational adjustments may be enough.
Where there is doubt about the function, positioning or interaction of particular systems, a deeper technical evaluation is the right response.
Where protection objectives, threats or impacts have not been sufficiently evaluated, a systematic risk and threat analysis becomes necessary.
Where controls no longer match the required level of protection, or where key relationships are missing, a conceptual redesign is the sensible route — usually with support from security consulting.
Where legal, normative, insurance-related or data protection requirements may apply, those specialist questions should be examined separately.
An assessment does not settle every decision. It does help to prioritise where action is needed and to identify the right next step.
For a single site, a physical security assessment mainly serves to evaluate the current state in a structured way.
Across multiple sites or facilities with elevated protection requirements, a strategic perspective emerges as well. Comparable evaluations make it possible to:
An assessment can therefore support operational improvements and provide a foundation for long-term security decisions at the same time.
The Resilience Health Check from e-shelter security is aimed in particular at critical infrastructure operators and facilities with elevated protection requirements that want to evaluate the current state of their physical and organisational security and develop it in a structured way.
The focus is on the current condition of the site, how the existing controls work together, and the weaknesses and risks within the agreed scope. From that, we derive prioritised technical, organisational and personnel recommendations along with any further review or planning steps.
Depending on the starting position, that may lead to a process adjustment, a detailed technical inspection, a deeper risk analysis, managed security services for alarm handling and intervention, or further security consulting.
Most security gaps do not arise because no controls are in place. They arise because controls, processes and responsibilities drift out of alignment over the years.
A physical security assessment makes those relationships visible. It identifies weaknesses, evaluates the risks apparent within a defined scope, and derives prioritised recommendations from them.
Its value therefore does not lie in reaching a quick recommendation for new technology. It lies in producing a solid basis for the decisions that follow.
Before an organisation decides how to develop its physical security, it should know where it stands today.
Not sure where your site stands right now? The Resilience Health Check from e-shelter security gives you a systematic evaluation of the resilience of your facilities, with prioritised recommendations you can act on. Talk to our experts or explore our solutions — we support you from the first baseline review through to a completed security plan.
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information
