Service · Physical security assessment

Security Assessment

A professional, independent evaluation of your physical security posture — seen from an attacker's perspective. You get a clear, measurable picture of where you stand and a prioritised action plan.

What it is

An assessment seen from the other side of the door

A Security Assessment is a professional, independent evaluation of your physical security posture — seen from an attacker's perspective. We simulate realistic attack scenarios and systematically review 200+ control points to give you a clear, measurable picture of your security level and a prioritised action plan.

It is not a review of your policies. We look at how security behaves on an ordinary Tuesday: which doors actually stand open, who gets challenged at reception, what is left out on the desks, and how easily someone gets from the visitor area to the plant room.

Along the way we make controlled intrusion attempts — enough to test the assumptions, but without the full attack scenario a penetration test consists of. That is why a Security Assessment is the natural first step for most organisations: you see the whole picture before you decide how deep to dig.

Need to go all the way in? See physical penetration testing

The process

Three phases over four to five days

Two of the phases run remotely. Only the assessment itself requires us to be on your site — and it is planned to disturb day-to-day operations as little as possible.

1

OSINT and preparation 1 day · remote

Mapping of the organisation's digital exposure: building plans, ID cards, suppliers, employee data and organisational structure. Preparation of attack scenarios.

2

On-site assessment 1–2 days

Passive observation of security culture and patterns. Intrusion attempts via tailgating or pretext. Then a systematic walkthrough of the entire facility using a checklist, interviews and photo documentation.

3

Report and presentation 1–2 days · remote

Professional report with findings, risk assessment, quantitative scoring and a three-phase action plan (immediate / tactical / strategic). Presentation for management.

The engagement can be extended with network and specialist testing: network scanning, vulnerability scanning, assume-breach, Wi-Fi audit, phishing and vishing campaigns or a tabletop workshop. Add-ons run in parallel with the main engagement, are delivered as separate chapters in the report, and are agreed in advance.

Methodology

Four tracks — the same ones an attacker would choose

The order is not accidental. Information first, people next, and only then the technical layer. An attacker works the same way — the difference is that we write all of it down and hand it to you.

Everything happens within Rules of Engagement you have approved in advance. We never remove or change anything without agreement, and no employee is named and shamed in the report. The purpose is not to catch anyone. It is to find the way in before someone else does.

Questions we answer

  • What can an attacker learn about you before they turn up?
  • Is an unknown person challenged — or is the door held open?
  • How far in can someone get, and how long does it take?
  • Who notices, and what happens afterwards?

How we measure

Eight categories, one score

Each category is scored with a percentage value. That gives you an objective baseline you can use to track improvements over time — and to prioritise where the money does the most good.

CPTED
Access control
Visitor management
CCTV & surveillance
Interior security
Information security
Employee security
Cyber-physical convergence

The control points are built around recognised frameworks, so the findings can be tied directly to the requirements you already have to meet — whether the requirement comes from a regulator, an insurer or a customer. We are not certified against them; we use them as a yardstick.

Reference framework
  • ISO 27001 (Annex A)
  • CPTED
  • F&P Security Guide
  • NIS2 / CER
  • NIST SP 800-115

Deliverables

What you get in your hands

The action plan comes in three parts: immediate — what has to be closed now. Tactical — what can be planned into day-to-day operations. Strategic — what belongs in the budget or in the next building project. So you know what is urgent and what can wait.

Three deliverables

  • Security Assessment report

    Detailed findings with photo documentation, risk assessment and concrete recommendations in three phases.

  • Scoring checklist (appendix A)

    Quantitative assessment of 200+ control points across eight categories.

  • Management briefing

    Presentation of key findings and recommendations for management, 45–60 minutes.

Price and time

What it costs

The price covers the whole engagement: preparation, on-site work, report, scoring and management briefing — as well as travel and expenses.

Indicative price, excl. VAT From47,500DKK
Typical duration 4–5working days
Scope 200+control points

All prices are indicative and can be adapted to the client's specific needs and the complexity of the engagement. All prices are excluding VAT and follow the net price index with annual adjustment. Network and specialist add-ons are agreed separately.

Next step

Test the assumptions.
Find the way in.

A short conversation is enough to work out whether a Security Assessment or a full penetration test suits you best. It costs nothing and commits you to nothing.