Why premises risk usually sits between equipment, people, procedure, and response.
|
Author Greg “Dutch” Holland-Merten, MSc, MSyI Reviewed by HMH Physical Security Team |
Best for Business owners,
COOs, facilities leaders, law firms, clinics, jewelers, dealerships, retailers,
offices, and site managers responsible for staff, visitors, assets, and
premises. |
Key takeaway:Physical security rarely fails because one product is missing. It fails in the gaps between equipment, people, procedure, and response.
Physical Security Fails in the Gaps.
Most physical security failures do not start with a dramatic breach. They start with a gap.
A door that does not close properly. A camera that cannot identify a face. A staff member who does not know who to call. A visitor who is not challenged. A delivery procedure that everyone bypasses. A side entrance nobody owns. A key or access card that was never recovered. A report that was never written. A pattern that nobody noticed until after the incident.
That is where physical security usually fails.
Not in the brochure. Not in the equipment list. In the gap between what leadership thinks is happening and what is actually happening on site.
CCTV records problems. It does not automatically prevent them.
A camera can show someone entering a building. It does not stop them entering. A camera can record a theft. It does not recover the loss.
Too many businesses install cameras and then assume the security problem has been solved. It has not.
At best, cameras provide visibility. Security requires control.
Equipment is not the same as security.
Many businesses can point to equipment: cameras, locks, alarms, access control, fences, lighting, guards, badges, and visitor logs.
All of that may be useful. None of it automatically proves security.
Physical security is not just what you bought. It is how the site actually operates.
A camera is only useful if it sees the right thing, at the right time, in the right quality, and someone knows what to do with the footage. An alarm is only useful if it triggers an appropriate response. Access control is only useful if permissions are reviewed and doors are not propped open.
A guard is only useful if expectations, authority, reporting, and escalation are clear. A policy is only useful if staff understand it and follow it under pressure.
Why this matters now.
Physical risk is back on the leadership agenda for a reason.
Retail theft, workplace violence, organized crime, targeted harassment, protest activity, and opportunistic offending have all pushed businesses to take premises security more seriously. NRF reporting continues to highlight rising theft, fraud, and violence as serious operational concerns for retailers and their staff.
The issue is no longer only loss. It is staff safety, client confidence, business continuity, liability, reputation, and whether leadership can show that reasonable steps were taken before something happened.
Many businesses respond by adding more visible security: more cameras, more guards, more locks, more signs. Sometimes that helps. Sometimes it just adds cost without fixing the underlying weakness. If the process is poor, more equipment may only give you a better recording of the same failure.
The real site is not the floorplan.
Security reviews often fail when they are conducted from a desk.
Floorplans matter. Policies matter. System diagrams matter. But the real site tells the truth.
Walk the car park. Stand at the rear entrance. Look at the lighting after dark. Watch how staff arrive. Watch how deliveries happen. Watch where visitors hesitate. Watch which doors are used because they are convenient. Watch where vehicles can sit without being questioned.
Look at whether the front desk is actually controlling access or simply greeting people. Look at how long someone can stand near an entrance before anyone notices. Look at whether staff understand the difference between being polite and surrendering control.
The site will usually show you the truth within the first hour.
Where premises security usually breaks down
- Access control exists, but nobody reviews who has access.
- CCTV exists, but it does not cover the right decision points.
- Alarms exist, but response expectations are unclear.
- Visitor logs exist, but nobody checks identification properly.
- Staff are told to report concerns, but nobody trains them on what suspicious behavior looks like.
- Doors are secure in theory, but propped open in practice.
- Security officers are present, but their post orders are vague.
- Policies exist, but supervisors tolerate workarounds.
- Incident reports are written, but patterns are not reviewed.
- Management assumes one location works like another, even when the site layout, clientele, hours, and threat profile are different.
These are ordinary failures. That is why they are dangerous. They do not look dramatic until they matter.
A physical assessment should test the system.
A serious physical security assessment should not just count cameras and doors.
It should examine how the site works under normal conditions, peak pressure, after-hours activity, staff distraction, emergency conditions, and deliberate probing.
The assessment should consider how someone approaches the premises, where they could wait, what they could see, how they could enter, how quickly they could be challenged, where staff would move, what assets are exposed, how evidence would be preserved, and how leadership would be notified.
This is not about turning a business into a fortress. Most businesses do not need that, and customers certainly do not want it.
The objective is appropriate control: enough security to reduce risk without killing the business environment.
The staff factor.
Staff are often the most important control and the most overlooked vulnerability.
They see patterns before management does. They know which doors stick, which visitors push boundaries, which delivery drivers ignore process, which camera never works, and which routine gets bypassed when the site is busy.
But staff need permission, training, and a clear reporting route.
If staff do not know what to report, they will normalize risk. If they report concerns and nothing happens, they will stop reporting. If leadership treats security as an inconvenience, staff will copy that attitude.
Culture is not a poster in the break room. It is what people are allowed to ignore.
Leadership questions to ask this week
- Who owns physical security at each site?
- When was the last independent premises assessment?
- Are access permissions reviewed regularly?
- Are old keys, badges, and codes removed from circulation?
- Do cameras cover decision points or just open space?
- Can footage be exported quickly and correctly?
- Are alarms linked to a clear response process?
- Do staff know who to call and what to report?
- Are deliveries, contractors, and visitors controlled?
- Are opening and closing procedures tested?
- Are incident reports reviewed for patterns?
- Does each location have a site-specific risk profile?
If the answers are vague, the weakness is not the equipment. The weakness is control.
What good looks like
- Good physical security is calm, layered, and practical.
- Clear ownership
- Controlled access
- Useful CCTV
- Effective lighting
- Tested alarms
- Trained staff
- Documented procedures
- Practical reporting
- Routine review
- Site-specific planning
- Leadership follow-through
It should be professional enough to reduce exposure but measured enough not to make the business feel like a prison yard. There is a balance. Good security finds it.
The HMH view
Physical security does not usually fail because one thing is missing. It fails because the pieces do not work together.
A premises assessment should identify the real gaps between equipment, people, procedure, and response. It should show leadership what is exposed, what is working, what is assumed, and what needs to change first.
At HMH Consulting, we look at physical risk from the outside in and the inside out. We assess how the site appears to staff, visitors, vendors, opportunists, and someone deliberately looking for weakness.
No scare tactics. No overbuilt solutions. No pretending a camera on the wall is a security programme. Just practical assessment, clear findings, and sensible risk reduction.
If your business has not reviewed its premises security in the last 12 months, or if you have added new sites, staff, assets, or operating hours, now is the time to walk the ground properly.
Â
Luxury retail and jewellery businesses cannot afford guesswork.
HMH Consulting helps leadership identify where risk actually lives across premises, people, systems, and process, then provides practical guidance on what to fix first.
Discreet outreach. No obligation