Umspannwerk mit Strommasten und elektrischer Infrastruktur unter blauem Himmel

Resilience Health Check: how an initial security audit is conducted and what it achieves

27.08.2026 | 6 min read

Most security plans only get a fundamental review once something forces the issue — an incident, a major investment decision, or a new set of requirements to meet. Until then the reasoning usually runs like this: access control works, the cameras are producing images, the guard force is on site, so the location must be adequately protected.

That conclusion doesn’t hold up. Individual controls can function perfectly well in technical terms while their protective value within the wider system quietly erodes. Buildings change. Responsibilities move. Processes get adjusted and new systems are added. Meanwhile, threats and operational dependencies keep developing.

A Resilience Health Check therefore does not start with the question of what technology to add. It starts by asking whether the security plan you already have still matches the protection your site genuinely requires.

Its value lies in the structure it imposes. A structured review of physical security gives an organisation a clear view of which areas are soundly set up, where weaknesses or ambiguities sit, which risks are visible within the agreed scope, and which next steps follow sensibly from that picture.

Why Working Controls Don’t Add Up to a Reliable Security Plan

Physical security is produced by the interplay of structural, technical, organisational and personnel controls. What matters is not only whether a component works, but whether it performs its intended job inside a coordinated security process.

An intruder alarm system may trigger reliably every time. If it is unclear who assesses the alarm, what response time is required and how the intervention is organised, its real protective effect is limited.

The same logic applies elsewhere:

  • Access control protects sensitive rooms only if permissions are kept current and exceptions are controlled.
  • Video surveillance supports situational assessment only if the relevant areas are covered and events are spotted in time.
  • Perimeter security works only when detection, alarm handling and response are aligned with one another.
  • A guard force can act dependably only when tasks, escalation paths and decision-making authority are clearly defined.

The technical condition of individual systems, then, says very little about how resilient a site is overall.

What a Physical Security Assessment Is

A physical security assessment is a structured security analysis carried out within a scope defined in advance. It evaluates the current state of physical and organisational security at a site or facility, identifies weaknesses, and creates a basis for prioritised recommendations and any deeper investigation that may be needed. Depending on the provider, the same exercise is sold as a physical security audit, a site security assessment or — as in the case of the e-shelter security Resilience Health Check — a resilience assessment.

Existing protective controls are not examined in isolation. They are assessed in relation to:

  • the people, assets and processes to be protected,
  • the required level of protection,
  • relevant hazards and dependencies,
  • organisational responsibilities,
  • the detection and handling of incidents,
  • and the ability to keep essential operations running during a disruption.

An assessment of this kind is neither a pure technology inspection nor a full risk and threat analysis. It evaluates risks within the agreed scope and shows where a deeper investigation is required.

Warning Signs That a Security Assessment Is Overdue

A physical security assessment is not something you commission only after an incident. Organisational and operational changes are often the earlier signal that the current security plan needs reviewing.

The security plan has grown piece by piece

Few security estates were designed in a single project. Controls arrived one at a time: extra cameras, new card readers, revised locking zones, additional barriers, fresh tasks for the guard force.

Each individual addition may have been perfectly sensible. Over time, though, you end up with several generations of technology side by side, inconsistent processes and dependencies nobody can fully trace.

Nobody can explain the current security level

A clear warning sign is when basic questions cannot be answered with confidence:

  • Which areas need the highest level of protection?
  • Which threats and disruptions were taken into account?
  • Why were the existing controls chosen?
  • Which processes depend on individual buildings or systems?
  • Which residual risks are being knowingly accepted?
  • How is the effectiveness of the controls verified?

Where those answers are missing, the security level rests more on inherited assumptions than on a current evaluation.

Responsibilities are unclear

Weaknesses rarely appear inside a single system. They appear at organisational interfaces. Typical examples include:

  • issuing and withdrawing access rights,
  • handling visitors and contractors,
  • processing technical alarms,
  • cooperation between the security organisation, facility management and IT,
  • and escalation during a security incident.

When several parties each know only part of the process, a gap opens up in the sequence as a whole.

Buildings and processes have changed

Refurbishments, new usage areas, altered circulation routes or additional delivery zones all affect existing protection arrangements. So do organisational changes such as remote working, a larger contractor population, new operating hours or revised production processes.

Even small adjustments can invalidate security assumptions made years earlier.

Incidents and near misses keep repeating

Doors left open, badges that were never deactivated, false alarms and unclear responses do not necessarily cause immediate damage. When they recur, however, they point to structural weaknesses.

This is exactly where we come in. e-shelter security evaluates the current state of physical and organisational security in a structured way and within a defined scope — vendor-independent and with no predetermined technology answer. If you want to place individual observations in their wider context, the Resilience Health Check is the right starting point.

What a Site Security Assessment Examines

The exact shape of the review depends on the site, the required level of protection and the agreed scope. A physical security assessment normally covers several perspectives.

Protection objectives and critical functions

The first question is what actually needs protecting. That can include:

  • people,
  • buildings and physical assets,
  • technical installations,
  • information,
  • production or operating processes,
  • and the availability of critical services.

Not every area needs the same intensity of protection. What matters is whether the objects to be protected and their priorities have been defined in a way that can be followed and justified.

Structural and technical security

Existing controls are examined in their functional context. That typically covers:

  • site and perimeter protection,
  • building security,
  • access control,
  • intruder and hold-up alarm and detection systems,
  • video surveillance,
  • lighting,
  • alarm transmission,
  • and the connection to security control rooms or intervention forces.

The point is not simply whether technology is present. The review asks whether the controls suit how the site is used, whether they work together sensibly, and whether they can be integrated into day-to-day operations. In a well-designed estate these layers reinforce one another, which is the principle behind multi-layered security.

Organisational processes

A reliable security plan needs clear processes. The following areas are therefore examined as well:

  • roles and responsibilities,
  • permission management,
  • visitor and contractor processes,
  • key and badge administration,
  • alarm and escalation paths,
  • documentation,
  • training and exercises.

These are precisely the areas where the gap between the documented plan and everyday practice tends to widen over time.

Personnel controls

Security personnel form part of the overall picture too. Relevant points include:

  • the tasks and qualifications of security officers,
  • staffing levels and availability,
  • intervention procedures,
  • cover and deputising arrangements,
  • and cooperation with internal and external parties.

Again, the question is not whether personnel are deployed, but what function they perform within the security process.

Response and recovery

Security does not end when an event is detected. An assessment therefore also looks at how the organisation responds to disruption.

Relevant elements include:

  • alarm assessment,
  • intervention,
  • internal and external communication,
  • handover to police, fire service or emergency medical services,
  • maintaining essential business operations,
  • and the controlled resumption of normal operations.

Resilience does not mean preventing every event outright. It means limiting the impact and staying able to act.

Interfaces with IT and operations

Modern security systems are increasingly networked. Access control, video, building services and control room platforms all have digital interfaces and can depend on IT infrastructure — a dependency that grows with every smart building function added to the estate.

A physical security assessment does not replace a full cyber security review. It should, however, make visible where physical security, IT, building operations and organisational processes depend on one another.

How a Physical Security Assessment Works, Step by Step

The precise sequence depends on the size, complexity and protection requirements of the site. A structured review usually runs through five steps.

1. Agree the scope and purpose of the review

At the outset, you define which sites, areas and topics are to be examined. Equally important is the question of what decisions the organisation wants to prepare with the results.

Typical triggers include:

  • a general stocktake of where the site stands,
  • planned investment,
  • recurring security problems,
  • a refurbishment,
  • changed operating processes,
  • or an increased level of required protection.

2. Review the existing documentation

Existing documents provide the first overview. They can include:

  • security and emergency plans,
  • site and building drawings,
  • access and zoning schemes,
  • alarm and escalation plans,
  • technical documentation,
  • standing orders,
  • and incident records.

Missing, contradictory or outdated documents are themselves an indication that organisational work is needed.

3. Walk the site and involve the people responsible

A site walkthrough shows how controls are actually implemented and used. Conversations with the responsible departments make it possible to compare documented processes against operational practice.

Depending on the organisation, that can involve security managers, facility management, IT, health and safety, site management and external service providers.

4. Evaluate weaknesses and risks in a structured way

Findings are not simply collected. They are ranked by significance within the agreed scope — the step that turns a list of observations into a genuine security gap analysis.

The review distinguishes between:

  • weaknesses that are immediately apparent,
  • organisational ambiguities,
  • missing or outdated foundations,
  • relevant dependencies,
  • risks that can already be assessed in broad terms,
  • and topics that require deeper specialist examination.

A physical security assessment does not replace a full risk and threat analysis with comprehensive scenario evaluation. It does, however, allow an initial risk classification, and that creates the basis for a defensible order of priority.

5. Derive recommendations and next steps

The review ends with a structured summary of the current state. It should make clear:

  • which areas appear soundly set up,
  • where weaknesses or concrete risks exist,
  • which points can be improved in the short term,
  • which technical, organisational or personnel controls make sense,
  • which structural constraints have to be taken into account,
  • and which topics should be examined in more depth.

That is what turns a current-state review into a basis for decisions.

What a Physical Security Assessment Should Deliver

The practical benefit of an assessment does not come from producing the longest possible list of defects. It comes from a clear, prioritised classification of what was found.

A robust result should contain:

  • a structured overview of the security areas examined,
  • weaknesses and observations described in a way that can be followed and verified,
  • an initial evaluation of the relevant risks within the agreed scope,
  • a prioritisation of where action is needed,
  • specific technical, organisational or personnel recommendations,
  • notes on relevant structural constraints,
  • and recommendations for any deeper work required.

Not every finding has to lead to a technical investment. The most useful first steps often lie in clearer responsibilities, updated processes, cleaned-up permissions or better documentation.

Other findings will call for a deeper physical security risk assessment, a technical inspection or a revision of the security plan.

Recommendations also have to be more than technically sound. They must fit into existing structures and operating routines, and they must not compromise the availability of critical functions.

Technical, Organisational and Personnel: Assessing Controls in Context

Security problems are rarely solved by a single control. Recommendations should therefore be classified according to the functional contribution they make to overall protection.

A technical control might enable better detection. Organisational controls determine how an alarm is assessed and escalated. Personnel controls determine who can respond and what competencies they need to do so.

This technical, organisational and personnel view — often called the TOP principle — helps to prevent controls being planned in isolation. Structural conditions remain a separate element of the physical security architecture and have to be considered alongside them.

What a Physical Security Assessment Does Not Replace

A physical security assessment is designed as a structured analysis with a bounded scope. It does not replace:

  • a full risk and threat analysis,
  • detailed design of a security plan,
  • technical specialist planning,
  • comprehensive functional testing of individual systems,
  • a data protection review,
  • certification,
  • detailed regulatory examination,
  • or formal evidence of compliance.

That boundary matters. An assessment can identify weaknesses, evaluate risks in broad terms and develop concrete recommendations. Complex sites, particularly high protection requirements or specific regulatory obligations will call for further work beyond it.

Which Next Step Follows from the Results

Not every finding leads to the same follow-up project.

Organisational correction

Where the issues are mainly unclear responsibilities, documentation or individual procedures, targeted organisational adjustments may be enough.

Detailed technical inspection

Where there is doubt about the function, positioning or interaction of particular systems, a deeper technical evaluation is the right response.

Risk and threat analysis

Where protection objectives, threats or impacts have not been sufficiently evaluated, a systematic risk and threat analysis becomes necessary.

Revision of the security plan

Where controls no longer match the required level of protection, or where key relationships are missing, a conceptual redesign is the sensible route — usually with support from security consulting.

Specialist or regulatory review

Where legal, normative, insurance-related or data protection requirements may apply, those specialist questions should be examined separately.

An assessment does not settle every decision. It does help to prioritise where action is needed and to identify the right next step.

From a Single Site to a Security and Resilience Strategy

For a single site, a physical security assessment mainly serves to evaluate the current state in a structured way.

Across multiple sites or facilities with elevated protection requirements, a strategic perspective emerges as well. Comparable evaluations make it possible to:

  • identify recurring weaknesses,
  • benchmark security standards across the portfolio,
  • prioritise investment on a defensible basis,
  • and develop the overarching security and resilience strategy in a targeted way.

An assessment can therefore support operational improvements and provide a foundation for long-term security decisions at the same time.

The Resilience Health Check from e-shelter security

The Resilience Health Check from e-shelter security is aimed in particular at critical infrastructure operators and facilities with elevated protection requirements that want to evaluate the current state of their physical and organisational security and develop it in a structured way.

The focus is on the current condition of the site, how the existing controls work together, and the weaknesses and risks within the agreed scope. From that, we derive prioritised technical, organisational and personnel recommendations along with any further review or planning steps.

Depending on the starting position, that may lead to a process adjustment, a detailed technical inspection, a deeper risk analysis, managed security services for alarm handling and intervention, or further security consulting.

Conclusion: Understand First, Then Decide

Most security gaps do not arise because no controls are in place. They arise because controls, processes and responsibilities drift out of alignment over the years.

A physical security assessment makes those relationships visible. It identifies weaknesses, evaluates the risks apparent within a defined scope, and derives prioritised recommendations from them.

Its value therefore does not lie in reaching a quick recommendation for new technology. It lies in producing a solid basis for the decisions that follow.

Before an organisation decides how to develop its physical security, it should know where it stands today.

Not sure where your site stands right now? The Resilience Health Check from e-shelter security gives you a systematic evaluation of the resilience of your facilities, with prioritised recommendations you can act on. Talk to our experts or explore our solutions — we support you from the first baseline review through to a completed security plan.

— More interesting articles