Physical Security Assessment

Why Conduct a Physical Security Assessment?
Organizations conduct comprehensive security assessments for different reasons. Some respond to a safety or security incident. Others face regulatory compliance requirements. Many pursue assessment to qualify for grant funding for physical infrastructure improvement. Some respond to community concerns about facility safety. Others simply recognize that increasing protection for their people is the right investment.
Regardless of what prompts the assessment, the goal is the same: identify vulnerabilities now, before they compound into liability. A thorough physical security assessment reveals gaps in your facility's layout, access points, communications systems, and emergency procedures. These elements must work together during a crisis. A single vulnerability in one area cascades through others. Most organizations don't discover these gaps until after an incident occurs. Threat Suppression assessments identify vulnerabilities now, prioritize practical improvements, and give your leadership confidence in your preparedness.
A carefully selected, qualified, and credentialed vendor is essential in the physical security assessment process. Reputable vendors bring unique expertise and current knowledge of best practices, products, and industry standards. A vendor's extensive experience, board certifications, and broad experience with safety and security directly influence assessment quality and organizational liability.
Threat Suppression has conducted hundreds of security assessments for military installations, federal agencies, K-12 schools, universities, hospitals, nonprofits, and corporations. Our assessments are grounded in over 50,000 hours of research into how threats actually unfold and how organizations respond.
Why Use Threat Suppression?
Threat Suppression has conducted hundreds of security assessments for military installations, federal agencies, K-12 schools, universities, hospitals, nonprofits, and corporations. Our assessments are grounded in over 50,000 hours of research into how threats develop and how organizations respond.
Our consultants hold board certifications including Certified Protection Professional (CPP), Certified Threat Manager (CTM), Physical Security Professional (PSP), Crime Prevention Through Environmental Design (CPTED), Certified Clery Compliance Officer (CCO), Certified Human Resources Manager (SHRM-CP), and Certified OSHA General Industry Inspector. These certifications require months of rigorous study and examination, ensuring our personnel are highly qualified to conduct comprehensive physical security assessments.
Threat Suppression does not sell any products, endorse any products, or receive remuneration for products. This product neutrality allows us to provide recommendations driven solely by your organization's needs, not vendor relationships or commercial interests. Security firms without product neutrality are likely to recommend unnecessary, costly solutions that require significant organizational investment.
We understand that an assessment full of expensive recommendations provides little value to organizations. Because of this, we break the findings up in three areas:
-
Immediate Actionability: 70% of recommendations require no budget or minimal cost. These are operational adjustments, policy changes, or environmental design improvements you can implement immediately. Approximately 20% of recommendations are in a mid-cost range. Less than 10% of recommendations are capitol improvement budget items.
-
Prioritization by Risk: Recommendations are organized by threat likelihood and severity, then by implementation cost. You know which gaps matter most.
-
Scope for Implementation: Recommendations span no-cost/low-cost improvements, mid-range investments, and capital projects. You can prioritize based on budget and timeline.

Effective security programs require more than a review of physical infrastructure. Security conditions are influenced by the interaction of multiple factors including threat environments, behavioral risk indicators, building design, security technology systems, and operational coordination between departments responsible for safety.
Threat Suppression conducts security assessments using a model that evaluates these interconnected elements together rather than examining them independently. This approach allows the assessment team to understand how your security program functions as a coordinated system and to identify areas where improvements may strengthen prevention, detection, and response capabilities.The Threat Suppression Comprehensive Security Assessment Model evaluates four primary domains that influence organizational safety.
Threat and Risk Analysis
The engagement includes development of a detailed threat and risk analysis examining the security environment affecting your organization. This analysis evaluates threats most likely to affect your community and assesses the potential consequences associated with those risks. The threat analysis considers historical incident data, crime trends affecting your sector, emerging threat environments, and operational factors unique to your organization. This analysis provides leadership with a structured understanding of the risks most relevant to your operations and helps prioritize safety initiatives based on realistic threat conditions.
Behavioral Threat Assessment and Management
Organizations increasingly rely on behavioral threat assessment teams to identify and manage individuals who may present a risk of targeted violence. The assessment will evaluate your current threat assessment processes and examine how your organization identifies, evaluates, and manages concerning behavior before it escalates into violence. This review examines reporting mechanisms, case management procedures, coordination between departments, and information-sharing practices that support early identification of potential threats.
Infrastructure Security
The assessment will evaluate physical security infrastructure and technology systems supporting safety operations. This includes building access control practices, surveillance coverage, emergency communication systems, lighting conditions, and other environmental factors that influence safety conditions within facilities. Observations from the site assessment will help determine how existing infrastructure supports prevention, detection, and response capabilities.
Operational Security Coordination
Security systems are most effective when they support coordinated response between personnel responsible for safety. The assessment will examine operational practices that influence safety including communication processes, coordination with security and emergency services, emergency response procedures, and collaboration between departments responsible for safety. This operational review helps determine how infrastructure, policies, and personnel interact during critical incidents and whether existing systems support effective coordination during emergencies. Together, these four domains provide a comprehensive understanding of how your security program functions across infrastructure, operations, and risk management.
Service Tiers
Bronze Engagement: Foundational Security Assessment
The Bronze Engagement provides a structured evaluation of security conditions across your facilities. This engagement focuses on physical security infrastructure, security technology systems, emergency notification, and general operational observations. The assessment includes on-site evaluation of selected facilities, review of relevant policies and procedures, and identification of observable conditions that may influence safety. Observations focus on access control practices, surveillance systems, environmental design, and general security measures present within assessed facilities.
The Bronze Engagement includes a written report summarizing observations and general considerations for improving security. The engagement concludes with a two-hour executive briefing presenting key findings.This option provides a baseline understanding of security conditions and may be appropriate for organizations seeking an initial evaluation of infrastructure and operational practices.
Silver Engagement: Comprehensive Security and Risk Assessment
The Silver Engagement expands the scope to include detailed evaluation of operational practices, threat environments, and institutional risk factors affecting safety. In addition to Bronze components, this option includes a detailed threat and risk analysis examining the most relevant risks affecting your organization and potential consequences associated with those risks. Threat Suppression will develop a comprehensive written threat assessment, typically ranging from 40 to 50 pages, providing structured analysis of your threat environment.
The Silver Engagement includes a limited review of fire and life safety considerations, Americans with Disabilities Act (ADA) considerations, and Occupational Safety and Health Administration (OSHA) considerations as they relate to observed conditions. This review is not a regulatory compliance audit and does not constitute certification of compliance with any applicable codes or standards. The engagement also includes evaluation of behavioral threat assessment processes and coordination between departments responsible for identifying and managing concerning behavior.
This tier incorporates additional subject matter expertise, including support from legal and investigative professionals and critical infrastructure risk specialists. The engagement concludes with a half-day executive briefing and leadership discussion to review findings, discuss priorities, and consider next steps. This option is appropriate for organizations seeking a comprehensive understanding of safety conditions and risks affecting their community.
Gold Engagement: Strategic Security and Risk Management Assessment
The Gold Engagement represents the most comprehensive level of service and is designed to provide a detailed evaluation of security conditions, emerging threats, and long-term strategic considerations for safety. In addition to all Silver Engagement components, this option expands the scope to include evaluation of emerging and complex threat environments. This includes assessment of unmanned aerial system risks, chemical hazard considerations, and elevated threat scenarios involving long-range or complex attack environments.
The Gold Engagement also incorporates considerations related to large crowd events and high-occupancy environments, including athletic events, performances, and major organizational gatherings. This analysis evaluates how security systems and operational coordination support safety during large-scale events. Analysis may include UAV-based mapping to evaluate line-of-sight considerations and vulnerabilities associated with elevated threat scenarios.
This tier includes expanded involvement from senior subject matter experts in legal analysis, critical infrastructure protection, public safety leadership, and emerging threat environments. The engagement may also include optional components such as compliance reviews and operational assessments of security operations, depending on your priorities.
The Gold Engagement concludes with a full-day leadership workshop and executive briefing presenting a comprehensive assessment of safety conditions and facilitating discussion of long-term security strategy and investment priorities. This option is appropriate for organizations seeking a detailed, strategic evaluation that addresses both current conditions and future risk considerations.
Click the image below to expand showing the different tiers:

Assessment by Organization Type
Businesses, private organizations, and houses of worship
The Challenge: Security needs vary widely based on facility type, staff size, public access, occupancy patterns, and threat profile. Many organizations lack security expertise internally and must balance protection with operational accessibility. Houses of worship face particular challenges maintaining welcoming environments while addressing increasing security concerns.
Threat Suppression Approach: We tailor assessment to your specific operations and threat environment. We evaluate physical security infrastructure, staff preparedness, emergency procedures, communication systems, and coordination with local law enforcement. Recommendations emphasize practical, affordable improvements and high-impact, low-cost changes. When applicable and requested, we can address NFPA 3000, NFPA 730, OSHA requirements, ADA accessibility, DHS Safety Act standards, and other applicable government or industry standards.
Assessment Level: Usually Tier 1 for smaller or lower-risk organizations. Tier 2 for larger organizations, those with elevated risk profiles (legal services, government contractors, financial institutions), or houses of worship with high occupancy or public access. Tier 3 for industrial facilities, complex multi-building operations, critical infrastructure, or organizations with specialized security requirements.
Schools and Universities
The Challenge: Balancing open campus culture with security requirements. Assessing threat response across multiple buildings and staff with varying emergency training.
Threat Suppression Approach: We evaluate physical security alongside staff preparedness, evacuation procedures, lockdown capability, communication systems, and coordination with local law enforcement. Recommendations address NFPA 3000 alignment, Clery Act compliance, and state school safety requirements. When applicable and requested, we can address NFPA 101, NFPA 730, OSHA requirements, ADA accessibility, DHS Safety Act standards, and other applicable government or industry standards.
Assessment Level: Usually Tier 2 or 3, depending on campus size and complexity.
Government and Critical Infrastructure
The Challenge: Evaluating distributed assets with different security postures. Assessing both facility hardening and field operations. Ensuring compliance with federal and agency-specific requirements.
Threat Suppression Approach: We evaluate primary facilities and representative distributed assets. Assessment includes threat analysis specific to infrastructure sector, operational response under degraded conditions, and coordination across multiple sites or agencies. We address ASHER requirements, DAFI 32-2001, federal procurement standards, and critical infrastructure protection guidelines. When applicable and requested, we can address NFPA 101, NFPA 730, OSHA requirements, ADA accessibility, DHS Safety Act standards, and other applicable government or industry standards.
Assessment Level: Usually Tier 2 or 3, often with optional tabletop exercises and multi-agency coordination assessment.
Hospitals and Healthcare Facilities
The Challenge: Healthcare facilities are open to the public but must protect patients, staff, and critical operations. Balancing accessibility with security. Managing threat response in environments with vulnerable populations.
Threat Suppression Approach: We evaluate active assailant response, workplace violence prevention, emergency department security, visitor management, staff communication systems, and coordination with law enforcement. Recommendations address NFPA 3000 alignment, Joint Commission standards, and healthcare-specific threat profiles.
Assessment Level: Usually Tier 2 or 3, depending on facility size and complexity.
The Next Step
We do not apply a standardized package for every client. Every organization has distinct vulnerabilities, resources, and threat profiles. Our assessments identify what matters at your specific location. Our training is built around your emergency operations plan, your staff capabilities, and your institutional priorities.
All services are competitively priced. We work directly with you to understand constraints and deliver solutions that fit your budget and timeline. Use the contact form to the right, call us at 1-800-231-9106 or email us info@threatsuppression.com for more information.

