Physical security onlyNot a service line bolted onto a cyber practice. Buildings, people and credentials are the entire remit.
Vendor-neutralNo product resale, no installer partnerships, no referral fees. The findings are the only deliverable.
Controls, never residentsWe assess what the building does, not who lives in it or who visits. No resident monitoring, in the assessment or in the rules we help you write.
Assessed against
ASISCPTED principlesFire & egress code awareISO/IEC 27001

Led by a practitioner, not a sales team. Calibre is directed by a security professional holding an MS in Cybersecurity from NYU, with enterprise security audit experience at Goldman Sachs and applied engineering work across access control, credential systems and social engineering.

01 / The assessment

Condo, HOA and apartment buildings.

A residential building has the access-control problem of an office and none of the staff. Deliveries, contractors, guests, dog walkers and short-term renters all move through the same door — and the board is accountable for what happens after it closes.

Package theft & mailroom control

Where parcels sit, who can reach them, and whether the camera covering them produces anything usable. Delivery workflow, parcel-room access, and chain of custody from curb to door.

Unauthorized short-term rentals

Fob sharing, lockbox installs and self check-in workflows that put strangers on residential floors. We assess the controls and give the board an enforceable, documented rule set — we do not surveil residents.

Tailgating & lobby control

How someone walks in behind a resident, and what would stop them. Vestibule design, intercom and callbox behavior, door-hold culture, and staffed versus unstaffed hours.

Camera placement & coverage

Coverage mapping for lobbies, mailrooms, garages, stairwells and elevators — blind spots, low-light performance, retention periods, and whether footage is admissible when police ask for it.

Fob, key & vendor access

Issuance and revocation on move-out, master-key hierarchies, garage remotes, elevator floor restriction, and the contractor and vendor access nobody tracks.

Garage, bike room & storage

The lowest-friction way into most buildings. Vehicle tailgating, gate timing, cage and locker security, and the stairwell doors that connect it all to the residential floors.

Written for a board packet, not a security teamboard-ready
Every finding prioritized, with a price rangeactionable
Controls assessed — never residentsprivacy first
ASISCPTED principlesLocal fire & egress code aware
Request a building assessment
Board document / Free

The Residential Self-Check.

Before the board budgets for it, walk the building. The 36-point checklist we use as the first lens on any condo, HOA or apartment building — from the garage gate to the package room, in a single walk-through.

Entry, deliveries, credentials, occupancy, common areas, governance6 sections
Scoring guide included36 points
Controls assessed — never residentsprivacy first

Get the Residential Self-Check

Free PDF, sent instantly. No sales calls unless you ask for one.

We occasionally send practical physical-security notes. Unsubscribe anytime. By submitting, you agree to our privacy policy.

Other engagements

The rest of the practice.

Offices, government facilities and critical infrastructure — the same method, scoped to sites with a security team of their own.

02 / Physical security

Facility testing and audit.

The building itself, assessed the way an intruder would approach it — from the perimeter fence to the server room door.

A ceiling-mounted dome camera overlooking a public concourse below.
Fig. 01Coverage mapping — what the camera sees, and what it misses
CSG-01

Facility security assessment

On-site review of perimeter, entry points, reception, secure areas, loading docks, and sensitive zones such as data centers and control rooms.

CSG-02

Surveillance & CCTV gap analysis

Camera placement, coverage mapping, blind spots, recording quality, and retention compliance.

CSG-03

Guard-force & procedure review

Covert and overt assessment of guarding, visitor management, challenge protocols, patrols, and incident readiness.

CSG-04

Security design & planning

Security requirements for new builds and fit-outs — protection designed in from the start, where it costs least.

03 / Social engineering

Testing people and process.

The best controls can be bypassed by a confident stranger at reception. We test your people the way real adversaries do.

Physical impersonation

Covert access under false pretexts — contractor, delivery, inspection, and maintenance scenarios.

Tailgating & piggybacking

Controlled entry-point bypass testing: challenge behavior, door-hold culture, anti-tailgate measures.

Vishing

Telephone social engineering against reception, helpdesk, and facilities staff.

Pretexting & elicitation

Posing as tenants, auditors, or inspectors to test information-disclosure controls.

Waste & OSINT review

What your bins and your public footprint give an attacker before they ever arrive on site.

Susceptibility reporting

Department-level breakdowns and targeted training recommendations.

04 / Training

Testing finds the gaps. Training closes them.

CSG-05

Social engineering prevention

Scenario-based workshops that teach staff to recognize and resist impersonation, tailgating, vishing, and pretexting. On-site or virtual, tailored to your threat profile.

CSG-06

All-staff security awareness

A structured programme covering the physical security every employee owns: badge and visitor etiquette, clean desk, spotting suspicious behavior, and incident reporting.

Delivered as a one-time engagement after an assessment, or as a recurring programme — quarterly refreshers, new-starter inductions, annual updates — under a retainer.

Not sure which of these you need?

Describe your sites on a twenty-minute call and we’ll tell you where the risk actually is.

Book a scoping call
A fingerprint and keypad reader mounted beside the glass door of a server room containing IT racks.
Fig. 02Biometric reader on a server room door
05 / Access control

Who can go where — and whether your systems enforce it.

A reader on the wall is not a control. We test whether the system behind it grants, updates and revokes access the way your policy says it does.

Access control systems audit

Card readers, door controllers, turnstiles, mantraps, biometrics — including firmware, default credentials, and fail-safe configuration.

Key & lock management

Mechanical and electronic locks, master-key hierarchies, issuance and lost-key protocols.

Visitor & contractor management

Sign-in procedures, escort policies, temporary passes, and contractor vetting.

Joiner / mover / leaver controls

Whether access rights are correctly granted on hire, updated on role change, and fully revoked on departure.

06 / Infrastructure

Government & critical infrastructure.

Sites where a single unauthorized entry is a national-scale problem, assessed to the protective security standards that govern them.

Government & public buildings

Ministerial offices, embassies, courts, and citizen-facing sites — aligned to national protective security standards.

Critical national infrastructure

Utilities, transport, energy, and telecommunications — supporting CNI protection frameworks.

Data centers & AI infrastructure

Cage and hall access, mantraps, loading bays, and the contractor traffic that never stops. Where physical access defeats every logical control above it.

Regulated & high-security sites

Pharmaceutical, financial, and research facilities carrying custody, audit, or clearance obligations for their physical estate.

NPSA / CPNIASISISO/IEC 27001
Discuss a site
07 / Strategy

A security function, not a stack of reports.

Policy development

Physical security policies and procedures aligned to ASIS and NPSA guidance.

Maturity assessment

Benchmarking against industry frameworks, with a prioritized roadmap and price ranges.

Incident response planning

Playbooks for intruder, bomb threat, and hostile actor scenarios — written, then exercised.

A security operator monitoring a wall of CCTV feeds from a darkened control room.
  Fig. 03 — Monitoring

Cameras record. People decide. We assess both — coverage and retention on one side, operator response and escalation on the other.

08 / Process

How an engagement runs.

Whichever discipline you start with, the shape of the work is the same — and the first stage costs nothing.

Step 01

Scoping callFree

Twenty minutes on your building and what prompted the question. If an assessment is not worth the association’s money, we will say so on the call.

Step 02

Scope

What is assessed, when we walk, and the fixed fee — all agreed in writing before anyone sets foot in the building.

Step 03

Walk

The building on foot, in daylight and after dark: every door, the parcel room, the garage, the credential records and the vendor contracts.

Step 04

Report

Findings ranked by risk, each with evidence, a remediation step and a price range. Written to be read at a board meeting, not decoded.

Step 05

Fix

Support while the board works through the list, and a re-walk to confirm the gap actually closed.

09 / Questions

Asked often.

One building, assessed on foot in daylight and after dark, across six areas: entry and perimeter, deliveries and packages, keys and fob credentials, occupancy and short-term lets, garage and common areas, and governance and vendor response. We also review your access-control records and security vendor contracts. You receive a single board-ready report: every finding prioritized, evidenced, and carrying a price range.

It is a fixed fee, quoted before any work starts — not a day rate, and not an hourly meter that runs while we are in your garage. The number depends on the size of the building, the number of entrances and amenity areas, and whether the association has usable access-control records. You get the figure on the twenty-minute scoping call, in writing, with no obligation. Associations tell us it lands in the same range as the third-party reports they already commission.

No, and we will not be asked into a building on that basis. We assess the building’s controls — whether the door latches, whether a credential was deactivated on move-out, whether there is a lockbox on the side gate. We do not observe, log, photograph or profile residents or their visitors, and the enforceable rules we help boards write are about credentials, lockboxes and check-in workflows, never about who a resident is or who comes to see them.

About three weeks from the site walk to a document in your board packet. What the board receives is a prioritized list of findings, each with evidence and a price range, split into fixes that cost nothing, small spends, and items for next year’s budget — plus, if you want it, a presentation of the findings at your board meeting. It is written to be read at that meeting, not decoded afterwards.

For most residential buildings, every eighteen to twenty-four months, and sooner after anything that changes who holds a credential — a management company change, a board turnover, an access-control replacement, or a renovation that puts contractors through the building for months. Controls decay quietly between board terms, which is usually how a building ends up back where it started.

Yes — residential buildings are the practice. Package and mailroom theft, tailgating into lobbies and garages, fob and key control after move-out, camera coverage that produces usable footage, and units being let short-term against building rules. We assess the building’s controls rather than its residents, and findings are delivered as a board-ready document — prioritized, with a price range on every item, so a management company can act on it without translation.

Yes. Alongside the residential practice we advise global enterprises, data centers, critical national infrastructure, government and public-sector buildings, and regulated industries — facility assessment, social engineering testing, access control review and retained advisory. Engagements are aligned to recognized standards such as CPNI/NPSA and ASIS and tailored to each site’s threat profile and compliance requirements.

A physical security audit is a structured assessment of how well your buildings, perimeter, access controls, and procedures protect your people and assets against real-world intrusion. Calibre Security Group reviews every layer — from the perimeter to the secure room door — and delivers a prioritized list of gaps and fixes, each with a price range you can budget against.

An audit evaluates your controls against best practice; a physical penetration test actively attempts to defeat them. Our testers try to gain unauthorized access the way a real attacker would — tailgating, impersonation, lock bypass, and social engineering — to prove which weaknesses are genuinely exploitable rather than just theoretical. Covert testing is scoped for commercial and infrastructure sites, under written authorization; residential engagements are assessments, not covert entry.

Yes. Testing reveals where your people are vulnerable; training closes the gap. We deliver scenario-based social engineering prevention workshops and a structured all-staff security awareness program covering tailgating, vishing, badge etiquette, and incident reporting — available standalone or as part of a retainer. For residential buildings this is usually a short session for front-desk and management staff rather than a program.

Contact

Not sure where to begin?

Tell us about your building. We’ll point you at the highest-priority gaps — even if that means a smaller engagement than you expected, or none at all.