Package theft & mailroom control
Where parcels sit, who can reach them, and whether the camera covering them produces anything usable. Delivery workflow, parcel-room access, and chain of custody from curb to door.
Calibre’s practice is the residential building security assessment — a fixed-fee engagement delivered as a board-ready report. The rest of what we do sits below it, unchanged and available.
Led by a practitioner, not a sales team. Calibre is directed by a security professional holding an MS in Cybersecurity from NYU, with enterprise security audit experience at Goldman Sachs and applied engineering work across access control, credential systems and social engineering.
A residential building has the access-control problem of an office and none of the staff. Deliveries, contractors, guests, dog walkers and short-term renters all move through the same door — and the board is accountable for what happens after it closes.
Where parcels sit, who can reach them, and whether the camera covering them produces anything usable. Delivery workflow, parcel-room access, and chain of custody from curb to door.
Fob sharing, lockbox installs and self check-in workflows that put strangers on residential floors. We assess the controls and give the board an enforceable, documented rule set — we do not surveil residents.
How someone walks in behind a resident, and what would stop them. Vestibule design, intercom and callbox behavior, door-hold culture, and staffed versus unstaffed hours.
Coverage mapping for lobbies, mailrooms, garages, stairwells and elevators — blind spots, low-light performance, retention periods, and whether footage is admissible when police ask for it.
Issuance and revocation on move-out, master-key hierarchies, garage remotes, elevator floor restriction, and the contractor and vendor access nobody tracks.
The lowest-friction way into most buildings. Vehicle tailgating, gate timing, cage and locker security, and the stairwell doors that connect it all to the residential floors.
Before the board budgets for it, walk the building. The 36-point checklist we use as the first lens on any condo, HOA or apartment building — from the garage gate to the package room, in a single walk-through.
Offices, government facilities and critical infrastructure — the same method, scoped to sites with a security team of their own.
The building itself, assessed the way an intruder would approach it — from the perimeter fence to the server room door.

On-site review of perimeter, entry points, reception, secure areas, loading docks, and sensitive zones such as data centers and control rooms.
Camera placement, coverage mapping, blind spots, recording quality, and retention compliance.
Covert and overt assessment of guarding, visitor management, challenge protocols, patrols, and incident readiness.
Security requirements for new builds and fit-outs — protection designed in from the start, where it costs least.
Scenario-based workshops that teach staff to recognize and resist impersonation, tailgating, vishing, and pretexting. On-site or virtual, tailored to your threat profile.
A structured programme covering the physical security every employee owns: badge and visitor etiquette, clean desk, spotting suspicious behavior, and incident reporting.
Delivered as a one-time engagement after an assessment, or as a recurring programme — quarterly refreshers, new-starter inductions, annual updates — under a retainer.
Describe your sites on a twenty-minute call and we’ll tell you where the risk actually is.

A reader on the wall is not a control. We test whether the system behind it grants, updates and revokes access the way your policy says it does.
Card readers, door controllers, turnstiles, mantraps, biometrics — including firmware, default credentials, and fail-safe configuration.
Mechanical and electronic locks, master-key hierarchies, issuance and lost-key protocols.
Sign-in procedures, escort policies, temporary passes, and contractor vetting.
Whether access rights are correctly granted on hire, updated on role change, and fully revoked on departure.
Sites where a single unauthorized entry is a national-scale problem, assessed to the protective security standards that govern them.
Ministerial offices, embassies, courts, and citizen-facing sites — aligned to national protective security standards.
Utilities, transport, energy, and telecommunications — supporting CNI protection frameworks.
Cage and hall access, mantraps, loading bays, and the contractor traffic that never stops. Where physical access defeats every logical control above it.
Pharmaceutical, financial, and research facilities carrying custody, audit, or clearance obligations for their physical estate.
Physical security policies and procedures aligned to ASIS and NPSA guidance.
Benchmarking against industry frameworks, with a prioritized roadmap and price ranges.
Playbooks for intruder, bomb threat, and hostile actor scenarios — written, then exercised.

Cameras record. People decide. We assess both — coverage and retention on one side, operator response and escalation on the other.
Whichever discipline you start with, the shape of the work is the same — and the first stage costs nothing.
Twenty minutes on your building and what prompted the question. If an assessment is not worth the association’s money, we will say so on the call.
What is assessed, when we walk, and the fixed fee — all agreed in writing before anyone sets foot in the building.
The building on foot, in daylight and after dark: every door, the parcel room, the garage, the credential records and the vendor contracts.
Findings ranked by risk, each with evidence, a remediation step and a price range. Written to be read at a board meeting, not decoded.
Support while the board works through the list, and a re-walk to confirm the gap actually closed.
One building, assessed on foot in daylight and after dark, across six areas: entry and perimeter, deliveries and packages, keys and fob credentials, occupancy and short-term lets, garage and common areas, and governance and vendor response. We also review your access-control records and security vendor contracts. You receive a single board-ready report: every finding prioritized, evidenced, and carrying a price range.
It is a fixed fee, quoted before any work starts — not a day rate, and not an hourly meter that runs while we are in your garage. The number depends on the size of the building, the number of entrances and amenity areas, and whether the association has usable access-control records. You get the figure on the twenty-minute scoping call, in writing, with no obligation. Associations tell us it lands in the same range as the third-party reports they already commission.
No, and we will not be asked into a building on that basis. We assess the building’s controls — whether the door latches, whether a credential was deactivated on move-out, whether there is a lockbox on the side gate. We do not observe, log, photograph or profile residents or their visitors, and the enforceable rules we help boards write are about credentials, lockboxes and check-in workflows, never about who a resident is or who comes to see them.
About three weeks from the site walk to a document in your board packet. What the board receives is a prioritized list of findings, each with evidence and a price range, split into fixes that cost nothing, small spends, and items for next year’s budget — plus, if you want it, a presentation of the findings at your board meeting. It is written to be read at that meeting, not decoded afterwards.
For most residential buildings, every eighteen to twenty-four months, and sooner after anything that changes who holds a credential — a management company change, a board turnover, an access-control replacement, or a renovation that puts contractors through the building for months. Controls decay quietly between board terms, which is usually how a building ends up back where it started.
Yes — residential buildings are the practice. Package and mailroom theft, tailgating into lobbies and garages, fob and key control after move-out, camera coverage that produces usable footage, and units being let short-term against building rules. We assess the building’s controls rather than its residents, and findings are delivered as a board-ready document — prioritized, with a price range on every item, so a management company can act on it without translation.
Yes. Alongside the residential practice we advise global enterprises, data centers, critical national infrastructure, government and public-sector buildings, and regulated industries — facility assessment, social engineering testing, access control review and retained advisory. Engagements are aligned to recognized standards such as CPNI/NPSA and ASIS and tailored to each site’s threat profile and compliance requirements.
A physical security audit is a structured assessment of how well your buildings, perimeter, access controls, and procedures protect your people and assets against real-world intrusion. Calibre Security Group reviews every layer — from the perimeter to the secure room door — and delivers a prioritized list of gaps and fixes, each with a price range you can budget against.
An audit evaluates your controls against best practice; a physical penetration test actively attempts to defeat them. Our testers try to gain unauthorized access the way a real attacker would — tailgating, impersonation, lock bypass, and social engineering — to prove which weaknesses are genuinely exploitable rather than just theoretical. Covert testing is scoped for commercial and infrastructure sites, under written authorization; residential engagements are assessments, not covert entry.
Yes. Testing reveals where your people are vulnerable; training closes the gap. We deliver scenario-based social engineering prevention workshops and a structured all-staff security awareness program covering tailgating, vishing, badge etiquette, and incident reporting — available standalone or as part of a retainer. For residential buildings this is usually a short session for front-desk and management staff rather than a program.
Testing people and process.
The best controls can be bypassed by a confident stranger at reception. We test your people the way real adversaries do.
Physical impersonation
Covert access under false pretexts — contractor, delivery, inspection, and maintenance scenarios.
Tailgating & piggybacking
Controlled entry-point bypass testing: challenge behavior, door-hold culture, anti-tailgate measures.
Vishing
Telephone social engineering against reception, helpdesk, and facilities staff.
Pretexting & elicitation
Posing as tenants, auditors, or inspectors to test information-disclosure controls.
Waste & OSINT review
What your bins and your public footprint give an attacker before they ever arrive on site.
Susceptibility reporting
Department-level breakdowns and targeted training recommendations.