Access control systems audit
Card readers, door controllers, turnstiles, mantraps, biometrics — including firmware, default credentials, and fail-safe configuration.
Every engagement is scoped and delivered by a physical security specialist — from facility audits to national identity programmes.
The building itself, assessed the way an intruder would approach it — from the perimeter fence to the server room door.
On-site review of perimeter, entry points, reception, secure areas, loading docks, and sensitive zones such as data centers and control rooms.
Camera placement, coverage mapping, blind spots, recording quality, and retention compliance.
Covert and overt assessment of guarding, visitor management, challenge protocols, patrols, and incident readiness.
Security requirements for new builds and fit-outs — protection designed in from the start, where it costs least.
Scenario-based workshops that teach staff to recognize and resist impersonation, tailgating, vishing, and pretexting. On-site or virtual, tailored to your threat profile.
A structured programme covering the physical security every employee owns: badge and visitor etiquette, clean desk, spotting suspicious behavior, and incident reporting.
Delivered as a one-time engagement after an assessment, or as a recurring programme — quarterly refreshers, new-starter inductions, annual updates — under a retainer.
Card readers, door controllers, turnstiles, mantraps, biometrics — including firmware, default credentials, and fail-safe configuration.
Mechanical and electronic locks, master-key hierarchies, issuance and lost-key protocols.
Sign-in procedures, escort policies, temporary passes, and contractor vetting.
Whether access rights are correctly granted on hire, updated on role change, and fully revoked on departure.
For governments, physical security reaches every facility — and every credential those facilities produce. We secure both the buildings and the documents, from passport issuance to ministerial offices. Independent and vendor-neutral throughout.
Ministerial offices, embassies, courts, and citizen-facing sites — aligned to national protective security standards.
Issuance, encoding, and blank-stock controls that prevent cloning and fraudulent provisioning. ICAO Doc 9303 aligned.
The bureaus where credentials are produced — secure printing, chip encoding, supply-chain control.
Utilities, transport, energy, and telecommunications — supporting CNI protection frameworks.
Physical security policies and procedures aligned to ASIS and NPSA guidance.
Benchmarking against industry frameworks, with a prioritized, costed roadmap.
Playbooks for intruder, bomb threat, and hostile actor scenarios — written, then exercised.
Testing people and process.
The best controls can be bypassed by a confident stranger at reception. We test your people the way real adversaries do.
Physical impersonation
Covert access under false pretexts — contractor, delivery, inspection, and maintenance scenarios.
Tailgating & piggybacking
Controlled entry-point bypass testing: challenge behavior, door-hold culture, anti-tailgate measures.
Vishing
Telephone social engineering against reception, helpdesk, and facilities staff.
Pretexting & elicitation
Posing as tenants, auditors, or inspectors to test information-disclosure controls.
Waste & OSINT review
What your bins and your public footprint give an attacker before they ever arrive on site.
Susceptibility reporting
Department-level breakdowns and targeted training recommendations.