Security risk assessment consulting is the process of engaging an independent, credentialled consultant to systematically identify and evaluate the physical security risks facing your organisation — and to provide a documented, evidence-based basis for the decisions that follow.
It is not a free assessment offered by a CCTV company. It is not a generic checklist applied to your site without context. It is a structured professional service that produces findings specific to your organisation, your site, and your threat environment — and that holds up to scrutiny from boards, auditors, regulators, and insurers.
Smartsec Security Solutions delivers independent security risk assessment consulting in Perth and across Western Australia. This page explains what that involves, who it serves, and what makes independent consulting different to vendor-led advice.
What Security Risk Assessment Consulting Involves
Security risk assessment consulting covers the full process of identifying, analysing, and evaluating physical security risk — and providing the documented findings and recommendations that enable an organisation to manage that risk effectively.
The core of any security risk assessment consulting engagement is a structured process aligned with ISO 31000:2018 — Risk Management: Guidelines. This is the recognised Australian and international standard for risk management methodology, and it provides the framework that makes assessment findings consistent, repeatable, and defensible.
Establishing context. Understanding the organisation — its sites, its operations, its user population, its hours of activity, its incident history, and the regulatory or governance obligations that shape what the assessment needs to achieve. Context determines scope, and scope determines whether the assessment is properly calibrated to the actual risk.
Threat identification. Identifying the realistic threats relevant to the specific organisation and site. For physical security, this typically includes theft, vandalism, unauthorised access, aggression toward staff, after-hours intrusion, and — for higher-profile or public-facing sites — the broader threat environment relevant to crowded places or critical infrastructure.
Vulnerability assessment. Evaluating each existing control against the identified threats — whether it’s adequate, whether it’s configured correctly, and whether it’s actually reducing the risk it was put in place to address. CCTV, access control, lighting, perimeter arrangements, alarm systems, and procedures are all assessed.
Risk rating. Applying a likelihood-consequence matrix to produce a risk register that prioritises findings — telling the organisation not just what the risks are, but how serious each one is and where to focus resources first.
Report and recommendations. A written report that documents methodology, findings, risk ratings, and prioritised recommendations — structured for the governance or compliance purpose it’s intended to serve.
Types of Security Risk Assessment Consulting Engagements
Security risk assessment consulting takes different forms depending on the organisation, the site, and the purpose of the engagement.
Physical security risk assessment. The most common engagement type — a structured evaluation of a specific site or portfolio of sites, covering all physical security controls and producing a prioritised risk register and written report. Suitable for councils, commercial operators, healthcare facilities, educational institutions, developers, and government agencies.
CPTED assessment. Crime Prevention Through Environmental Design consulting — evaluating how the design and management of the built environment is influencing safety outcomes. Aligned with ISO 22341:2021 and the WA Government’s Safer Places by Design framework. Often commissioned as a development application requirement or in response to persistent antisocial behaviour or safety concerns in public spaces.
SOCI/CIRMP physical security consulting. For critical infrastructure operators subject to the Security of Critical Infrastructure Act 2018, security risk assessment consulting provides the evidentiary foundation for CIRMP physical security plan development and compliance attestation. The enhanced CIRMP Rules require a dedicated physical security plan by 30 June 2028.
Aviation security assessment. Physical security risk assessment consulting for WA airports, aerodromes, and aviation industry participants under the Aviation Transport Security Act 2004 — supporting Transport Security Program compliance.
Post-incident review. Following a significant security incident, independent security risk assessment consulting provides an objective view of what went wrong, whether existing controls were adequate, and what needs to change. Post-incident reviews are often required by insurers or governance bodies.
Portfolio assessment. For organisations managing multiple sites — councils, healthcare networks, property managers — portfolio assessments apply a consistent methodology across all locations, producing comparable findings and a prioritised investment plan across the entire asset base.
Who Benefits From Security Risk Assessment Consulting
Local government and councils. Managing diverse, publicly accessible asset portfolios across metropolitan and regional WA. Smartsec is a WALGA Preferred Supplier (PSP001-002 and PSP001-026) and an LGCA approved supplier — councils can engage us directly without a separate procurement process.
Healthcare facilities. Hospitals, aged care providers, and community health centres with obligations under AS 4485:2021 and the WA Health Risk Management Policy. Independent security risk assessment consulting provides the documented risk position required for governance and regulatory compliance.
Critical infrastructure operators. Energy, water, transport, health, and communications assets requiring CIRMP physical security assessments and plans under the Security of Critical Infrastructure Act 2018.
Developers and architects. When a development application carries a CPTED or security condition, independent security risk assessment consulting provides the evidentiary basis for planning approval.
Commercial and retail operators. Property managers, retail operators, and commercial facility managers where incidents, insurance requirements, or governance obligations trigger the need for independent assessment.
Mining and resources operators. Remote mine sites, FIFO operations, and resources sector facilities across regional and remote WA where physical security challenges are compounded by isolation and extended response times.
The Case for Independent Security Risk Assessment Consulting
The Perth market for security risk assessment consulting includes vendors, installers, and guarding companies who offer assessment services alongside their product and service sales. The advice these organisations provide can be technically sound — but it comes with a structural incentive that shapes the output.
An independent security risk assessment consultant has no stake in what you subsequently purchase. The fee covers the assessment and the advice — nothing else. Findings reflect the actual risk at your site, and recommendations reflect what the site genuinely needs — which sometimes means confirming that existing controls are adequate, or redirecting budget toward procedural improvements rather than technology.
For organisations that need to present security risk findings to a board, justify expenditure to elected members, demonstrate compliance to a regulator, or satisfy an insurer — independent consulting provides a stronger and more defensible governance position.
Credentials and Standards
Smartsec Security Solutions is led by Khabeer Rockley SRMCP — a licensed WA Security Risk Consultant and Security Agent with technical security licensing and nearly two decades of experience in physical security consulting across the public and private sectors in WA.
The SRMCP credential represents the national professional standard for security risk management practitioners in Australia. WA Security Risk Consultant licensing is a legal requirement under the Security Industry Act 1997 — not all practitioners offering consulting services in WA hold it.
Our security risk assessment consulting is aligned with ISO 31000:2018, ISO 22341:2021, AS 4485:2021, and relevant Australian Standards including AS/NZS 1158 and AS/NZS 62676. We are a WALGA Preferred Supplier and an LGCA approved supplier.
Reports are written for decision-makers — clear enough to present to a board or audit committee, and specific enough to act on directly.
Contact Smartsec Security Solutions to arrange a confidential scoping conversation.


