GUARDIANINTEGRATED SECURITY & INTELLIGENCE
← All insightsGUARDIAN INSIGHTS

What Should Be Included in a Corporate Physical Security Assessment?

Learn what a corporate physical security assessment should cover, from access control and guards to emergency planning and prioritized improvements.

By Guardian ISIUpdated 11 min read
Security consultant and facilities director reviewing access controls in a Manhattan corporate office lobby.

A corporate physical security assessment should do more than document cameras, locks, and guard posts. It should identify the people, property, operations, and information the organization needs to protect; evaluate credible threats and vulnerabilities; and produce a practical plan for reducing risk.

For Manhattan offices, assessments also need to reflect the realities of shared lobbies, multiple tenants, loading areas, high visitor volume, executive travel, public-facing events, and dependence on building management. The goal is not to promise that every incident can be prevented. It is to help decision-makers understand where risk exists, which safeguards are working, and where resources should be directed next.

1. Scope, objectives, and critical assets

The assessment should begin with a clearly defined scope. A single-floor office has different needs from a corporate headquarters, a multi-building campus, or a company operating across several New York locations.

The assessor should document:

  • Locations, floors, and spaces included in the review
  • Normal and after-hours operating schedules
  • Employee, contractor, visitor, and delivery volumes
  • Critical departments and business functions
  • Executive offices and other sensitive areas
  • Valuable equipment, inventory, records, and intellectual property
  • Dependencies on property management, vendors, utilities, and nearby facilities
  • The organization’s risk tolerance and business priorities

This step prevents the assessment from becoming a generic checklist. Controls should be evaluated based on what the organization actually needs to protect and the consequences if access, safety, or operations are disrupted.

2. Threat and incident review

A useful corporate physical security assessment considers credible threats rather than every imaginable scenario. Relevant concerns may include unauthorized entry, theft, workplace violence, protest activity, vandalism, package incidents, executive targeting, utility interruption, fire or life-safety events, and severe weather.

The review should examine available information such as:

  • Recent security incidents and near misses
  • Access-control alarms and exception reports
  • Lost credentials and key records
  • Visitor-management issues
  • Theft, property damage, and suspicious activity reports
  • Employee safety concerns
  • Local conditions around entrances and commuting routes
  • Operational disruptions affecting the building or surrounding area

Interviews with reception personnel, security officers, facilities teams, human resources, IT, and selected employees often reveal issues that are not visible during a walkthrough. Incident data should be handled carefully and shared only with people who have a legitimate need for it.

3. Site, perimeter, and building access

The physical walkthrough should evaluate how people and vehicles approach, enter, move through, and leave the property. In Manhattan, the company may control only part of this process, so the assessment should distinguish tenant responsibilities from landlord or property-management responsibilities.

Exterior and approach

Review areas such as:

  • Visibility around primary and secondary entrances
  • Exterior lighting and sightlines
  • Signage and wayfinding
  • Street-level doors, windows, and service entrances
  • Parking or vehicle-access points, where applicable
  • Areas where employees wait for transportation
  • Conditions that could conceal unauthorized activity

Entry points and interior movement

The assessment should examine:

  • Main lobby and reception procedures
  • Employee and tenant entrances
  • Turnstiles, doors, elevators, and stairwells
  • Emergency exits and reentry considerations
  • Loading docks, freight elevators, and mailrooms
  • Connections to neighboring tenant or shared spaces
  • Access to executive suites, IT rooms, records, storage, and mechanical areas

The assessor should observe actual behavior, not only written procedures. A controlled door provides limited protection if it is routinely propped open or if tailgating goes unchallenged.

4. Access control, credentials, and key management

Access control should be reviewed as a complete process—from authorization through removal—not simply as installed hardware.

A thorough review asks:

  • Who approves access, and is approval documented?
  • Are permissions based on job responsibilities and location needs?
  • How quickly is access removed after termination or role changes?
  • Are temporary employees and contractors assigned expiration dates?
  • How are lost cards, mobile credentials, and physical keys handled?
  • Are access levels reviewed periodically?
  • Who can retrieve reports or change system settings?
  • Are mechanical keys inventoried and duplication risks addressed?
  • Is after-hours access monitored or treated differently?

The assessment should also look for excessive permissions, shared credentials, inconsistent naming conventions, and accounts that remain active unnecessarily.

5. Visitor, contractor, and delivery procedures

Corporate offices often focus on employee access while giving less attention to vendors, messengers, maintenance personnel, and event guests. The assessment should follow each visitor type from arrival to departure.

Key questions include:

Employees entering a Manhattan office through access-controlled turnstiles near a staffed reception desk.
Employees entering a Manhattan office through access-controlled turnstiles near a staffed reception desk.
  • Are visitors identified, registered, and connected to a host?
  • Is identification verification appropriate to the site’s risk level?
  • Are visitor badges visually distinct and collected or deactivated?
  • When is an escort required?
  • How are large meetings and corporate events managed?
  • Are contractors restricted to authorized work areas and schedules?
  • Where are food, mail, and package deliveries accepted?
  • How are unexpected or refused visitors handled?

Procedures should be workable during busy periods. If a process creates long lobby delays, personnel may bypass it under pressure.

6. Security personnel and post operations

Where security officers are used, the assessment should evaluate what they are expected to accomplish and whether staffing, supervision, training, and equipment support those expectations.

The review may cover:

  • Post orders and escalation procedures
  • Lobby, patrol, loading-area, and control-room assignments
  • Staffing by time of day and day of week
  • Shift changes and relief coverage
  • Patrol routes and documentation
  • Communication with reception, facilities, and building management
  • Radio, phone, duress-alarm, and incident-reporting procedures
  • Response to unauthorized access, medical events, suspicious activity, and disruptive behavior
  • Supervisor availability and quality-assurance practices

A staffing recommendation should be tied to identified risks and duties—not simply to a preferred officer count. If the assessment identifies gaps in front-desk protection, patrol coverage, or event staffing, corporate security guard coverage may be one part of the improvement plan.

7. Cameras, alarms, and security technology

Technology should be evaluated based on the operational purpose it serves. More cameras or alarms do not automatically create better security if alerts are not monitored, footage cannot be retrieved, or responsibilities are unclear.

The assessment should review:

  • Camera placement, fields of view, lighting, and obstructions
  • Image usefulness at entrances and other critical areas
  • Recording availability and retrieval procedures
  • Who monitors live video and when
  • Intrusion, door-held, door-forced, and duress alarms
  • Intercoms and remote-release functions
  • System health checks and maintenance responsibilities
  • Backup power and network dependencies
  • User permissions and administrative access
  • Coordination among video, access-control, visitor, and alarm systems

Retention settings, monitoring practices, and use of recorded information should be reviewed with the organization’s legal, privacy, IT, and human-resources stakeholders as appropriate.

8. Emergency and fire-life-safety coordination

Physical security must support—not conflict with—emergency response and life safety. The assessment should consider how employees, visitors, security personnel, and building teams communicate and act during urgent events.

Review areas may include:

  • Emergency contact and notification procedures
  • Evacuation, shelter-in-place, and accountability processes
  • Medical response and automated external defibrillator access
  • Roles during fire alarms and other building emergencies
  • Communication with property management and first responders
  • Procedures for disabled employees and visitors
  • After-hours incidents and reduced staffing
  • Alternate work locations and business-continuity dependencies
  • Drills, exercises, and corrective-action tracking

New York City fire and life-safety staffing or planning requirements can depend on building use, occupancy, systems, and other site-specific factors. The assessment should identify questions requiring confirmation with qualified professionals, property management, or the authority having jurisdiction rather than making unsupported compliance assumptions. For buildings that require designated personnel, Guardian also provides Fire and Life Safety Director coverage.

9. Workplace violence prevention and sensitive incidents

A physical security assessment should review how concerning behavior is reported, evaluated, and escalated. This is a cross-functional issue involving security, management, human resources, legal counsel, and sometimes outside specialists.

The assessment should consider:

  • Confidential reporting channels
  • Threat-management roles and decision authority
  • Procedures for terminations or high-conflict meetings
  • Duress notifications and safe-room options
  • Reception response to hostile or persistent visitors
  • Support for targeted employees or executives
  • Information-sharing boundaries
  • Post-incident care, documentation, and review

The assessor should avoid treating every difficult interaction as a security threat. Effective programs use defined criteria and multidisciplinary judgment.

10. Cyber-physical and operational dependencies

Physical security systems often depend on corporate networks, cloud services, mobile devices, and third-party support. The assessment does not replace a cybersecurity review, but it should identify important points of coordination.

Examples include:

  • Network-connected cameras and access-control panels
  • Remote system administration
  • Vendor credentials and support access
  • Protection of telecom, server, and network rooms
  • Employee directories used by visitor systems
  • Access-control integrations with HR systems
  • Response when internet, power, or cloud services are unavailable

Findings in this area should be reviewed jointly by physical security and IT teams so that improvements in one discipline do not create problems in the other.

11. Policies, training, and security culture

Even well-designed controls can fail when employees do not understand them or believe they are optional. The assessment should compare written policy with day-to-day practice.

Corporate security, facilities, human resources, and IT representatives reviewing a physical security improvement plan.
Corporate security, facilities, human resources, and IT representatives reviewing a physical security improvement plan.

Useful topics include:

  • Badge display and anti-tailgating expectations
  • Visitor and delivery procedures
  • Lost credential reporting
  • Clean-desk and sensitive-document handling
  • Suspicious activity reporting
  • Emergency communications
  • Personal-safety guidance for early or late workers
  • Manager responsibilities during incidents
  • Training for receptionists and other high-contact employees

Recommendations should be proportionate. Brief, role-specific training is often more effective than giving every employee the same lengthy security presentation.

12. A prioritized findings report

The final report is one of the most important assessment deliverables. It should help leadership make decisions rather than present an unranked list of deficiencies.

A strong report typically includes:

Report elementWhat it should explain
Executive summaryMajor risks, strengths, and decisions requiring leadership attention
Scope and methodologyLocations reviewed, interviews conducted, records considered, and limitations
Existing safeguardsControls already reducing risk effectively
FindingsThe condition observed and why it matters
Risk prioritizationRelative likelihood, potential consequence, and control effectiveness
RecommendationsSpecific operational, procedural, staffing, or technology improvements
OwnershipDepartment or stakeholder responsible for each action
Time horizonImmediate, near-term, and longer-term priorities
Budget contextPlanning-level cost or resource considerations where available
Validation planHow completed improvements will be checked and maintained

Recommendations should include both quick operational improvements and longer-term capital projects. For example, updating post orders or removing obsolete credentials may be addressed quickly, while redesigning a lobby could require coordination, budgeting, and landlord approval.

Questions to ask before hiring an assessor

Before selecting a provider, ask:

  1. What types of corporate environments have you assessed?
  2. How will you tailor the methodology to our business and building?
  3. Who will be interviewed, and what documents will you request?
  4. Will the review cover staffing, procedures, and technology together?
  5. How will findings be prioritized?
  6. Will recommendations account for budget and operational constraints?
  7. How will sensitive site information be protected?
  8. Can you help translate findings into an implementation plan?

Be cautious of assessments that lead with a predetermined product or staffing solution. The recommended controls should follow the identified risks.

How often should an assessment be updated?

There is no universal schedule for every company. Many organizations establish a regular review cycle and reassess sooner when conditions change. Useful triggers include:

  • Moving to or substantially renovating an office
  • Expanding headcount or changing work schedules
  • Adding public events or high-profile operations
  • Experiencing a serious incident or repeated near misses
  • Changing access-control, video, or visitor systems
  • Replacing a security provider
  • Receiving new threat information
  • Changing building management or shared-space arrangements

Between full assessments, management should track whether corrective actions were completed and whether those actions produced the intended result.

Turn assessment findings into practical coverage

A corporate physical security assessment is valuable only when its findings lead to action. Guardian ISI can help Manhattan organizations evaluate security operations and provide commercial office security aligned with the property’s actual needs. Short-notice options are also available through our emergency security coverage service.

To discuss an office-security concern or request staffing, call or text (212) 602-1695 or request coverage online.

Frequently asked questions

What is the main purpose of a corporate physical security assessment?

Its purpose is to identify critical assets, credible threats, vulnerabilities, and existing safeguards, then prioritize practical steps that reduce risk to people, property, information, and operations.

How long does a physical security assessment take?

Timing depends on the number of locations, facility size, operating hours, interview requirements, and available records. A single office may require a focused review, while a multi-site organization generally needs a longer process.

Does an assessment only cover cameras and access control?

No. It should also examine staffing, visitor management, keys and credentials, emergency procedures, workplace violence concerns, deliveries, training, incident reporting, and coordination with building management.

Who should participate in the assessment?

Typical participants include security, facilities, reception, human resources, IT, legal or risk personnel, business leaders, property management, and employees familiar with daily operations.

Should the assessment include fire and life safety?

Yes, it should review coordination with emergency and life-safety procedures. Site-specific regulatory or technical questions should be confirmed with qualified professionals, building management, or the authority having jurisdiction.

What should the final assessment report include?

It should include the scope, methodology, existing strengths, clearly explained findings, prioritized recommendations, responsible stakeholders, suggested time horizons, and a way to verify completed improvements.