A physical security risk and vulnerability assessment is a structured evaluation of a facility's real exposure: what could go wrong, how likely it is, what it would cost you, and what actually reduces the risk. It covers the site and its perimeter, the building envelope, the electronic systems, and the human procedures around them.
Done properly, it produces a prioritized list of findings ranked by risk, cost, and impact, not a catalogue of everything that could theoretically be improved.
Every facility is different, so the scope is set with you before anything starts. A typical assessment looks at:
Wittner Security Consultants staffs no guards, sells no hardware, and does not bid or install the work it recommends. You own every deliverable and can competitively bid it to any installer. Read the full independence policy.
It depends entirely on the size and complexity of the site. A single building is a different job from a multi-site utility district. The on-site portion is usually one to several days, with the written assessment following. You get a realistic timeline in writing before you commit, not after.
Published industry ranges for independent physical security assessments run from roughly $3,600 to $15,000 per engagement, and up to $50,000 for large or complex sites, according to published figures from consultancies including SEVN-X and Silva Consultants. Those are market figures rather than our rate card. Your price depends on facility size, number of sites, complexity, and scope, and you get a fixed number before any work starts.
An audit measures you against a fixed standard and asks whether you comply. An assessment asks a harder question: what are the actual threats to this facility, and where are you genuinely exposed? A site can pass an audit and still be vulnerable, because the standard did not anticipate its specific situation.
No, and this is where independence matters. Wittner Security Consultants sells no equipment and installs nothing, so there is no incentive to inflate the recommendation. Assessments regularly conclude that an existing system is adequate, or that the real fix is procedural and costs nothing. A vendor structurally cannot deliver that finding.
Yes. A security assessment is a map of your weaknesses, and it is treated accordingly. Confidentiality is governed by the engagement agreement, and we are glad to work under your own NDA.
Tell him what you are protecting and what prompted the question. He will tell you honestly what the work involves and whether he is the right person for it.