A physical security review is an independent evaluation of how well your current security arrangements are performing — whether the controls you have in place are adequate against the threats your site actually faces, and where the gaps are.
It is related to, but distinct from, a full security risk assessment. A security risk assessment starts from scratch — establishing context, identifying all relevant threats, rating risk, and producing a comprehensive risk register. A physical security review typically starts from what already exists — evaluating the controls currently in place, identifying where they’re working and where they’re not, and producing a prioritised set of findings and recommendations.
For organisations that have had a security risk assessment conducted in the past and want to check whether the situation has changed, or that want an independent view of their current security posture before making a significant investment decision, a physical security review is often the right starting point.
What a Physical Security Review Evaluates
A physical security review examines the full range of physical controls and operational arrangements that contribute to how secure a site actually is — not just how secure it looks on paper.
Existing controls — are they working? The most important question a physical security review answers is not whether controls exist, but whether they’re performing the function they were installed to perform. A CCTV camera that’s pointed at the wrong area isn’t a security control — it’s security theatre. An access control system with active credentials belonging to staff who left twelve months ago isn’t managing access — it’s creating uncontrolled entry points. A patrol that follows the same route at the same time every night isn’t providing unpredictable deterrence — it’s providing predictable gaps.
A physical security review identifies these performance failures — the difference between what the security arrangements are supposed to do and what they’re actually doing.
Physical access controls. Entry and exit points, access control hardware and software, credential currency, door hardware performance, and the movement of people through the site. Are credentials current? Are permissions appropriate to current roles? Is the hardware functioning as intended? Are there routes through or around controlled access points that the access control system doesn’t cover?
CCTV and surveillance. Camera coverage against the site’s specific risk profile, image quality and resolution, lighting alignment, recording and retention settings, and system health. Assessed against AS/NZS 62676. Are cameras covering the right areas? Is the footage actually usable? Is the system recording correctly and retaining footage for the required period?
Lighting. Illumination levels and uniformity assessed against AS/NZS 1158. Are the key areas — entry points, carparks, pedestrian paths, after-hours access points — adequately lit? Are there dark patches that create concealment opportunities? Does the lighting perform adequately after hours, or does it rely on ambient light that disappears once business hours end?
Perimeter and boundary arrangements. The physical integrity of the site boundary, vehicle access control, and the definition of the boundary between public and controlled space. Are there gaps or weaknesses in the perimeter? Is vehicle access adequately controlled? Is the territorial boundary clear to users of the space?
Alarm and monitoring. Alarm configuration, monitoring centre arrangements, response protocols, and integration between security systems. Are alarms generating an appropriate and timely response? Are forced-door events being captured and acted on? Is the monitoring arrangement adequate for after-hours conditions?
Security procedures and operational factors. Incident reporting, key and credential management, visitor and contractor management, after-hours procedures, and patrol arrangements. Physical controls are only as effective as the procedures that govern their use. A review that only examines hardware and technology without evaluating the operational layer is incomplete.
CPTED and environmental factors. Natural surveillance, sightlines, territorial definition, lighting, and the management of the physical environment. How the design and management of the space is influencing safety outcomes — and where environmental factors are creating vulnerabilities that controls alone won’t address.
How a Physical Security Review Differs From a Security Risk Assessment
The distinction is worth understanding clearly before commissioning either.
A security risk assessment is the more comprehensive of the two. It starts from the beginning — establishing context, identifying the full threat picture, evaluating controls against each threat, rating likelihood and consequence, and producing a risk register and prioritised report. It’s aligned with ISO 31000:2018 and produces a formal, governance-grade document.
A physical security review is typically narrower in scope — focused on evaluating what currently exists rather than conducting a full threat identification and risk rating exercise from scratch. It’s the right choice when:
- A full assessment has been conducted previously and the organisation wants to check whether the situation has changed
- A specific concern or incident has prompted a targeted review of particular controls or areas
- An organisation wants an independent view before making a capital investment decision
- A compliance or governance requirement calls for a periodic review rather than a full reassessment
- An insurer or auditor has asked for an independent evaluation of existing arrangements
Many organisations start with a physical security review and progress to a full security risk assessment when the review identifies gaps significant enough to warrant a more comprehensive response.
Who Commissions Physical Security Reviews in Perth
Physical security reviews are commissioned across a range of sectors and contexts in Perth and regional WA.
Commercial property managers. Regular reviews of access control, CCTV, and building security arrangements for office buildings, retail centres, and mixed-use developments — particularly before lease renewals, after tenant changes, or following incidents.
Local government and councils. Reviews of security arrangements across council-managed assets — civic buildings, libraries, community centres, carparks, and public open space. Smartsec is a WALGA Preferred Supplier (PSP001-002 and PSP001-026) — councils can engage us directly without a separate procurement process.
Healthcare facilities. Periodic reviews of physical security arrangements under AS 4485:2021 and the WA Health Risk Management Policy — which require security arrangements to be tested and maintained on a regular cycle.
Critical infrastructure operators. Reviews of physical security controls under the SOCI Act and enhanced CIRMP Rules — where the requirement to test and maintain security arrangements is an active compliance obligation with a 30 June 2028 attestation deadline.
Educational institutions. Schools, TAFEs, and universities conducting regular reviews of access control, CCTV, and campus security arrangements as part of their duty of care obligations.
Mining and resources operators. Periodic reviews of remote site security arrangements — perimeter, access control, CCTV, after-hours monitoring — where extended response times and isolated locations make regular review particularly important.
What the Review Produces
A physical security review produces a written report documenting findings across each element reviewed, with specific observations supported by photographic evidence where relevant, and a prioritised set of recommendations distinguishing between immediate actions, medium-term improvements, and longer-term strategic investments.
For most organisations, the report is used to:
- Justify a security upgrade or capital investment decision
- Satisfy an insurer, auditor, or regulator that security arrangements have been independently reviewed
- Provide a baseline for tracking improvement over time
- Brief a security supplier or installer on what’s needed and to what performance standard — without being locked into a particular vendor’s solution
Reports are written for decision-makers, not security specialists — clear enough to present to a board or audit committee, specific enough to act on directly.
Why Independent Reviews Produce Better Outcomes
A physical security review conducted by a vendor, installer, or guarding company comes with a structural incentive — the findings tend to reflect what the assessor can supply. An independent review has no commercial interest in the outcome.
Smartsec doesn’t sell CCTV, access control, or guarding services. We have no commercial relationships with any security supplier or installer. Every finding reflects what’s actually happening at the site, and every recommendation reflects what the site genuinely needs — which sometimes means confirming that existing controls are adequate and no additional investment is warranted.
For organisations presenting review findings to boards, justifying expenditure to elected members, or demonstrating to regulators that security has been independently evaluated — independence provides a significantly stronger governance position.
Engaging Smartsec for a Physical Security Review in Perth
Smartsec Security Solutions delivers independent physical security reviews for commercial, civic, healthcare, educational, critical infrastructure, and mining sector organisations across Perth and regional WA.
Our reviews are aligned with ISO 31000:2018, AS/NZS 62676, AS/NZS 1158, and relevant Australian Standards. We are vendor-neutral, WALGA Preferred Supplier listed, and hold the Security Risk Management Certified Professional (SRMCP) credential alongside WA Security Risk Consultant and Security Agent licensing.
Contact Smartsec Security Solutions to arrange a confidential scoping conversation.


