Choosing the Right Security Consulting Group for Your Business

Choosing a security consulting group is a decision that directly affects the quality of the advice you receive — and the quality of the advice you receive directly affects the security decisions your organisation makes.

Get it right and you have an independent, credentialled consultant who gives you an accurate picture of your risk and what to do about it. Get it wrong and you have a vendor who has conducted a site walkthrough and produced a report that recommends what they can supply.

This guide explains what to look for when choosing a security consulting group in Perth, what questions to ask before engaging, and why the factors that matter most are often the ones that aren’t obvious from a website.

 

Independence Is the Most Important Factor

The single most important question to ask any security consulting group is whether they are genuinely independent — and what that independence means in practice.

In the security industry, “consulting” is offered by a wide range of organisations. Guarding companies offer security assessments. Alarm installers offer security reviews. CCTV suppliers offer free site assessments. Integrated security providers offer consulting as part of their service bundle.

None of these are independent consulting. In each case, the organisation conducting the assessment has a commercial interest in the outcome — their assessment tends to find problems that their products or services can solve. This isn’t necessarily dishonest, but it is structurally biased, and it means the advice you receive reflects what they can supply rather than what your site actually needs.

A genuinely independent security consulting group has no products to sell, no systems to install, and no operational services to provide. The fee covers the assessment and the advice — nothing else.

Questions to ask:

  • Do you sell or install security products?
  • Do you supply security guards or monitoring services?
  • Do you receive referral fees or commissions from security suppliers?

If the answer to any of these is yes, the advice comes with a conflict of interest. That doesn’t mean it’s worthless — but it does mean you should understand what’s shaping it.

 

Credentials and Licensing Matter — and Are Verifiable

In Western Australia, security risk consulting is a regulated activity. Practitioners must hold a WA Security Risk Consultant licence issued under the Security Industry Act 1997. This licensing requirement exists because security risk advice has real consequences — it shapes investment decisions, influences governance positions, and contributes to whether organisations are actually protected.

Not all organisations offering security consulting in WA hold this licence. It is a legal requirement to practise as a security risk consultant in this state, but it is not always prominently disclosed and is rarely verified by buyers before engagement.

Beyond licensing, the Security Risk Management Certified Professional (SRMCP) credential represents the national professional standard for security risk management practitioners in Australia. Practitioners holding this credential have demonstrated competency against a national benchmark — it’s the closest thing the industry has to a professional standard that buyers can independently verify.

Questions to ask:

  • Do you hold a WA Security Risk Consultant licence?
  • Do you hold the SRMCP credential or equivalent professional certification?
  • Are your assessments aligned with ISO 31000:2018?

The answers to these questions tell you whether the person conducting your assessment has been assessed themselves — and whether the methodology they apply meets a recognised standard.

 

Methodology Determines the Quality of the Output

A security risk assessment is only as good as the methodology it applies. An assessment that consists of a site walkthrough and a list of observations is an opinion. An assessment that applies ISO 31000:2018 risk management methodology — identifying threats, evaluating controls, rating likelihood and consequence, and producing a prioritised risk register — is a structured, defensible professional service.

The distinction matters for two reasons.

First, the quality of the findings. A structured methodology produces findings that are specific to the site, calibrated to the actual risk, and prioritised in a way that helps the organisation decide where to focus resources. A walkthrough and observation list produces the same generic findings regardless of site, risk profile, or existing controls.

Second, the defensibility of the output. When you present the findings to a board, a council committee, an auditor, or an insurer, the quality of the methodology behind the assessment determines whether it withstands scrutiny. An ISO 31000:2018-aligned assessment from a credentialled independent consultant carries weight. A vendor-conducted checklist does not.

Questions to ask:

  • What methodology do your assessments follow?
  • Are your assessments aligned with ISO 31000:2018 or equivalent standards?
  • Can you provide an example of a risk assessment report (redacted)?

 

Local Knowledge and Sector Experience Are Underrated

Security risk varies significantly by location, sector, and operating context. A consulting group that primarily works in Sydney or Melbourne applying national templates to Perth sites will miss the local threat environment, planning and procurement frameworks, and operational realities that shape what good security looks like in WA.

For local government work in WA, familiarity with the WALGA procurement framework, DevelopmentWA planning conditions, and the specific threat profiles of WA council environments matters. For critical infrastructure work, understanding the SOCI Act obligations that apply to WA energy, water, and transport assets — and the enhanced CIRMP Rules that require physical security plans by 30 June 2028 — is essential. For regional and remote WA sites, understanding the specific challenges of extended response times, isolated locations, and limited monitoring capability shapes what recommendations are actually achievable.

A Perth-based consulting group with direct experience across WA sectors and environments will produce more relevant and more actionable findings than one applying a national framework without local context.

Questions to ask:

  • Are you based in Perth and do you work across regional WA?
  • Do you have experience in my specific sector — council, healthcare, critical infrastructure, commercial, mining?
  • Are you familiar with WA-specific frameworks including WALGA procurement, DevelopmentWA requirements, and WA Health system obligations?

 

What the Report Should Deliver

The written report is the deliverable. It’s what you present to decision-makers, what you submit to regulators, what you give to your insurer, and what you use to justify security investment. It needs to be clear, specific, and structured for the purpose it’s intended to serve.

A quality security risk assessment report should include:

Documented methodology. How the assessment was conducted, what standard it follows, and what the scope covered. This provides the evidentiary foundation for every finding that follows.

Site-specific findings. Observations that are specific to your site — not generic statements that could apply to any commercial building. Supported by photographic evidence of the specific issues identified.

A risk register. Each identified risk rated by likelihood and consequence, producing a priority order that tells the organisation where to focus first.

Prioritised recommendations. Specific, achievable recommendations that distinguish between immediate actions, medium-term improvements, and longer-term strategic investments — so the organisation knows where to start and what can wait.

A format suitable for governance. Clear enough to present to a board or council committee, specific enough to act on directly, and structured to support whatever compliance or governance purpose it serves.

Questions to ask:

  • Can I see an example of a risk assessment report before engaging?
  • Is the report structured for board or audit committee presentation?
  • Does it include a risk register with likelihood and consequence ratings?

 

Red Flags to Watch For

A few things that should prompt caution when evaluating a security consulting group:

Free assessments. Genuine security risk assessment consulting is a professional service that takes time, expertise, and methodology. Free assessments are either loss leaders designed to generate product sales, or they’re not genuine assessments at all.

Generic reports. If a consulting group can’t show you an example report, or if their example looks like it could have been written about any site, the quality of the specific assessment you receive is likely to be the same.

No licensing disclosure. Any security consulting group operating in WA should be able to confirm their WA Security Risk Consultant licence. If they can’t or won’t, they may not hold one.

Recommendations that always involve the same products or services. If every assessment from the same consulting group concludes that the same type of product or service is required, the assessment is probably working backwards from the solution rather than forwards from the risk.

 

Why Smartsec Security Solutions

Smartsec Security Solutions is an independent physical security consultancy based in Perth. We are a consulting-only practice — no products, no installation, no guarding services, no commercial relationships with any security supplier.

Our assessments are conducted by Khabeer Rockley SRMCP — a licensed WA Security Risk Consultant and Security Agent with technical security licensing and nearly two decades of experience in physical security across the public and private sectors in WA. Our methodology is aligned with ISO 31000:2018, ISO 22341:2021, and relevant Australian Standards.

We are a WALGA Preferred Supplier (PSP001-002 and PSP001-026) and an LGCA approved supplier — which means WA councils can engage us directly without a separate procurement process.

We work across local government, developers, healthcare, critical infrastructure, commercial, hospitality, aviation, and mining and resources sectors across Perth and regional WA.

Contact Smartsec Security Solutions to arrange a confidential scoping conversation.

more insights

Call for a scope chat