A security master plan is a multi-year roadmap that sequences security investment against real risk and a real budget. It answers the question that follows every assessment: given that we cannot do everything at once, what do we do first, what comes next, and what can wait?
It is the document that turns a list of findings into something a finance committee can actually approve.
Master planning earns its cost when any of these are true:
A plan that assumes unlimited funding is entertainment. A useful master plan assumes constraints, sequences the work so that each phase delivers value on its own, and stays legible to the people who approve the money. It should still make sense to a facilities director three years from now, after the person who ordered it has moved on.
Wittner Security Consultants staffs no guards, sells no hardware, and does not bid or install the work it recommends. You own every deliverable and can competitively bid it to any installer. Read the full independence policy.
An assessment tells you where you are exposed today. A master plan tells you what to do about it over the next several years, in what order, and at what cost. Assessments are frequently the input to the plan, and for a single small facility an assessment alone is often enough.
Three to five years is typical, aligned to your capital planning cycle rather than an arbitrary horizon. It should be reviewed when something material changes: a new facility, a significant incident, a regulatory change, or a technology shift that alters the economics.
Yes, and multi-site organizations are where it delivers the most value. Consistent standards across sites reduce cost, simplify training and maintenance, and stop each facility from making isolated purchasing decisions that nobody can support later.
Tell him what you are protecting and what prompted the question. He will tell you honestly what the work involves and whether he is the right person for it.