Physical security of sites and operations
A site security audit that shows what to address first
We first clarify what you need to review. On site, we examine entrances, the perimeter, people movement, day-to-day procedures and links to security technology. We rank the findings by impact and hand them over in a written report with practical next steps.
- 01Site
- type, location and day-to-day operation
- 02Objective
- question, incident or planned change
- 03Scope
- zones, documentation and responsible people
- 04Output
- finding, priority and recommended next step
When an audit makes sense
Define the problem before selecting a measure
An audit is useful when a decision needs to reflect actual operations rather than a universal security or technology package.- 01
Before changing security or investing in technology
First establish which problem the new measure should solve and how it affects operations.
- 02
After an incident or recurring losses
The audit reviews the process and looks for the point where rules, people and technology no longer align.
- 03
When operations have outgrown their procedures
We review visitors, contractors, shifts, handovers and restricted areas.
Assessment map
What we actually review on site
The scope follows the audit objective. We review the path from the site boundary and access controls through day-to-day procedures to reporting and escalation.- 01
Perimeter
fencing, lighting and physical entrances
- 02
Access
reception, gatehouse, keys, credentials and restricted areas
- 03
People movement
employees, visitors, drivers and contractors
- 04
Operating procedures
procedure compliance, shift handover and escalation
- 05
Technology and reporting
how CCTV, access control, intrusion detection and records support operations
Inputs before the site review
An operating outline is enough for the first review
Do not send sensitive plans, access lists or internal incident records through the initial form. We request them only after direct contact and only when they are needed for the agreed scope.- 01
site type, location and approximate size
- 02
operating hours, shifts and main movement of people or vehicles
- 03
reason for the audit: change, incident, recurring loss or preventive review
- 04
zones, entrances or procedures that matter most to you
- 05
current security, reception and security technology
- 06
a contact who understands day-to-day operations
Our base is in Brno. Audits outside the region are confirmed according to scope, available documentation and site logistics.
Audit trail
From a question to a traceable conclusion
There is no universal audit duration. We confirm timing after a short brief based on site size, the number of zones, documentation, interviews and any agreed testing.- 01
Short brief
We define the objective, responsible people, available documentation and safe boundaries of the site review.
- 02
Site review and documentation
We examine the agreed zones, operating procedures and how people interact with security technology.
- 03
Evaluation
We describe the findings, check their context and rank them by impact and operating priority.
- 04
Report handover
We explain the conclusions, recommended steps and points requiring a decision by management or the process owner.
Written output
What you receive
A written report in which each finding is described with its impact, priority and recommended next step. The output is intended both for management and for the people implementing changes in day-to-day operations. The audit is a standalone service; you do not have to appoint us as your security provider afterwards.Illustrative report structure · no client data
- Management
- What needs a decision, budget or formal acceptance of risk.
- Operations
- What changes in day-to-day procedures, handover and responsibility.
- Suppliers
- What must connect to security, reception, technology or servicing.
Optional authorised extension
When a controlled test is the right way to verify a procedure
A physical penetration test is included only after written authorisation from a person entitled to approve it for the site operator. We define the objective, locations, time window, prohibited actions, a named contact authorised to stop the test immediately, personal-data handling rules and immediate termination conditions in advance. It is not an improvised attempt to gain entry.How a physical penetration test works- 01written authorisation and a named responsible person
- 02confirmed boundaries, prohibited actions and time window
- 03immediate termination where there is a risk of injury, damage, panic or interference with sensitive rights
Related information
An audit should lead to a decision, not another layer of uncertainty
Security audit FAQ
What to clarify before commissioning an audit
The scope and timing are agreed after an initial brief; these answers describe the working framework of the service.01What do you need before the site review?+
The site type and location, approximate size, day-to-day operation, reason for the audit and a contact who understands the site. We request sensitive documentation only after direct contact.
02How does a security audit work?+
We first define the objective and scope. We then review the agreed zones, operating procedures and links to technology. Findings are checked in context, ranked by priority and handed over in a written report.
03How long does an audit take?+
We confirm timing after a short brief. Duration depends on site size, the number of zones, available documentation, interviews with responsible staff and any authorised testing.
04What do I receive?+
A written report describing each finding, its impact, priority and recommended next step. At handover, we explain which points require a management decision and which need a change in day-to-day operations.
05What is the difference between an audit and a physical penetration test?+
An audit assesses the agreed scope through a site review, documentation and interviews. A penetration test is an optional controlled test of a specific procedure and requires written authorisation, defined boundaries and stop conditions.
06How do you handle sensitive information?+
We do not request it in the initial form. Required documentation, access to zones, documentation methods and report recipients are agreed directly according to the audit scope.
07Do I have to appoint you as the security provider after the audit?+
No. The audit is a standalone service. You can use the output internally or with another supplier. If you want to continue with us, we can prepare a specific security regime or other next steps.
Company information before cooperation
- company identification details
- liability insurance evidence available on request
Non-binding audit enquiry
Send the site and audit objective
For an initial review, send the site type and location, approximate size, day-to-day operation, reason for the audit and preferred date. We request sensitive documents only after direct contact.
- scope and timing are confirmed only after a short brief
- the audit can be commissioned as a standalone service
- do not send sensitive plans or incident data in the initial form
