Independent Vendor-neutral Northern California
ASSESS

Physical security risk and vulnerability assessments.

A physical security risk and vulnerability assessment is a structured evaluation of a facility's real exposure: what could go wrong, how likely it is, what it would cost you, and what actually reduces the risk. It covers the site and its perimeter, the building envelope, the electronic systems, and the human procedures around them.

Done properly, it produces a prioritized list of findings ranked by risk, cost, and impact, not a catalogue of everything that could theoretically be improved.

What the assessment actually covers

Every facility is different, so the scope is set with you before anything starts. A typical assessment looks at:

  • The perimeter and approach. Fencing, gates, vehicle routes, standoff, parking, and how someone would actually get close to the building.
  • The building envelope. Doors, locks, hardware, glazing, roof access, and the openings people forget exist.
  • Electronic systems. Video surveillance, access control, intrusion detection, and communications, including whether they are positioned and configured to do the job they were bought for.
  • Interior zoning. Public, semi-restricted, and restricted areas, and whether the boundaries between them hold up in practice.
  • Lighting and sightlines. What can be seen, from where, at what hour.
  • Procedures and human factors. Key control, visitor management, after-hours protocols, and what staff actually do rather than what the binder says.

How it works

  • Scoping. A conversation about your facility, your concerns, and what triggered the request. This determines the depth and the price, and it happens before you commit.
  • On-site survey. Paul walks the site personally, in daylight and after dark where it matters, because a facility at 2pm and the same facility at 11pm are two different buildings.
  • Analysis. Findings are weighed against real threat likelihood and consequence, not a generic checklist.
  • Report. A written assessment with prioritized, costed recommendations you can act on, take to a board, or put out to bid.
  • Debrief. A conversation to walk through the findings, because a report nobody understands changes nothing.

What you get

  • A prioritized findings list ranked by risk, cost, and impact.
  • Clear separation between what is urgent, what is worth doing, and what is optional.
  • The no-cost items. Most assessments surface procedural fixes that cost nothing, and an independent consultant has no reason to hide them.
  • Findings written to be defensible to a board, an insurer, or a regulator.
  • Where systems work is warranted, specifications you own and can competitively bid.

Independent, with nothing to sell you

Wittner Security Consultants staffs no guards, sells no hardware, and does not bid or install the work it recommends. You own every deliverable and can competitively bid it to any installer. Read the full independence policy.

Common questions

How long does a physical security assessment take?

It depends entirely on the size and complexity of the site. A single building is a different job from a multi-site utility district. The on-site portion is usually one to several days, with the written assessment following. You get a realistic timeline in writing before you commit, not after.

What does a physical security assessment cost?

Published industry ranges for independent physical security assessments run from roughly $3,600 to $15,000 per engagement, and up to $50,000 for large or complex sites, according to published figures from consultancies including SEVN-X and Silva Consultants. Those are market figures rather than our rate card. Your price depends on facility size, number of sites, complexity, and scope, and you get a fixed number before any work starts.

What is the difference between an assessment and a security audit?

An audit measures you against a fixed standard and asks whether you comply. An assessment asks a harder question: what are the actual threats to this facility, and where are you genuinely exposed? A site can pass an audit and still be vulnerable, because the standard did not anticipate its specific situation.

Will the assessment just tell us to buy more equipment?

No, and this is where independence matters. Wittner Security Consultants sells no equipment and installs nothing, so there is no incentive to inflate the recommendation. Assessments regularly conclude that an existing system is adequate, or that the real fix is procedural and costs nothing. A vendor structurally cannot deliver that finding.

Is the assessment confidential?

Yes. A security assessment is a map of your weaknesses, and it is treated accordingly. Confidentiality is governed by the engagement agreement, and we are glad to work under your own NDA.

Related services

Often paired with this.

View all services

Request an assessment

Talk it through with Paul.

Tell him what you are protecting and what prompted the question. He will tell you honestly what the work involves and whether he is the right person for it.

Call Paul Request assessment