Security consulting fees are one of the first things organisations ask about before engaging a consultant — and one of the least transparently answered questions in the industry.
Most security consulting firms don’t publish their fees. Some provide a rate on request. Others scope and quote project by project without any reference point for the buyer. The result is that organisations approaching a security consultant for the first time often have no idea whether the quote they receive is reasonable, inflated, or suspiciously low.
This article explains what security consulting fees look like in Australia, what drives the cost of different types of engagements, and what the fee structure tells you about the type of advice you’re getting.
How Security Consulting Fees Are Typically Structured
Independent security consultants in Australia generally charge in one of three ways.
Hourly or day rate. The consultant charges a fixed rate per hour or per day, and the total fee reflects the time spent on the engagement — site inspection, analysis, report writing, and any follow-up. This is the most common structure for assessments and advisory work where the scope is variable or where the exact time required can’t be determined in advance.
Fixed project fee. A flat fee agreed in advance for a defined scope of work — typically a single-site security risk assessment or CPTED assessment with a specified report format. Fixed fees give the client cost certainty and are appropriate where the scope is well-defined and the site is reasonably straightforward.
Retainer or ongoing advisory. A regular fee — monthly or quarterly — for ongoing access to a consultant’s advice, periodic review work, or support across a portfolio of sites. Less common for independent consultants but used by organisations with continuous security management needs.
For most organisations commissioning a one-off security risk assessment, CPTED report, or security audit, either an hourly rate or a fixed project fee is the relevant structure.
What Drives the Cost of Security Consulting in Australia
Several factors influence what a security consulting engagement will cost. Understanding these helps organisations evaluate quotes and make informed decisions about scope.
Site size and complexity. A single-tenancy office building is a different assessment to a multi-building university campus, a regional hospital with multiple clinical areas, or a council portfolio of 30 parks and community facilities. Larger and more complex sites take longer to inspect, produce more findings to analyse, and require more substantial reports. Fee scales accordingly.
Number of locations. Single-site assessments are simpler to scope and deliver. Multi-site engagements — where an organisation wants a consistent, comparable assessment across several locations — require more time overall but often achieve a better per-site rate, since methodology and context are established once and applied across the portfolio.
Report format and purpose. A brief advisory memo for internal use is a different deliverable to a formal, structured report suitable for board presentation, council committee reporting, regulatory attestation, or insurance submission. The governance standard required directly affects the documentation time involved and therefore the fee.
Site visit timing. After-hours conditions — lighting performance, access control behaviour, patrol coverage, monitoring arrangements — often reveal vulnerabilities that are invisible during business hours. Assessments that include both daytime and after-hours inspections take longer and cost more, but produce a more accurate and complete picture of actual risk exposure.
Travel. For sites outside metropolitan Perth, travel time and costs are a legitimate component of the fee. Regional and remote WA sites — in the Pilbara, Kimberley, Goldfields, or South West — involve either overnight travel or extended travel days that are factored into the engagement cost.
Specialist scope. Some engagements require specialist knowledge beyond general physical security assessment — CIRMP physical security plans under the SOCI Act, aviation security assessments under the ATSA, hostile vehicle mitigation advice, or CPTED work aligned with specific planning standards. Specialist engagements typically carry a higher rate than general security consulting.
What Security Consulting Fees Look Like in Practice
In Australia, independent physical security consulting fees for credentialled practitioners — those holding relevant qualifications, professional memberships, and state licensing — typically fall in the following ranges.
Hourly rate: $180 to $250 per hour, depending on experience, credential level, and the nature of the work.
Single-site security risk assessment (standard commercial or council site): approximately $6,000 to $8,000 for a complete assessment including site inspection, risk rating, and a written report suitable for governance and decision-making purposes. Every site is different — factors such as whether a dedicated lighting assessment is required, the number of access points to evaluate, after-hours inspection requirements, site size, and the report standard needed for the specific purpose (board presentation, DA submission, regulatory attestation) all affect the final fee. These figures are indicative only and a scoped quote is provided before any work begins.
CPTED assessment (single site, DA-linked or operational): approximately $6,000 to $8,000, depending on site size, complexity, and whether the report needs to meet a specific planning authority or DevelopmentWA standard. As with security risk assessments, additional scope elements — lighting analysis, multi-area coverage, specialist DA formatting — will affect the fee.
Multi-site portfolio reviews: priced on a per-site basis with a volume reduction reflecting the efficiency gains from establishing methodology and context once across multiple sites. Organisations managing a portfolio of council facilities, healthcare sites, or commercial properties typically achieve a better per-site rate than commissioning individual assessments separately.
CIRMP physical security plans: $8,000 and above, depending on the type of critical infrastructure asset, the complexity of the site, the documentation standard required for CISC attestation, and whether the plan needs to integrate with existing CIRMP documentation or be developed from scratch. The specialist regulatory knowledge, site-specific analysis, and governance-grade reporting required for CIRMP work reflects the higher fee range for these engagements.
These figures are indicative only. Every site, organisation, and engagement is different — scope, complexity, report purpose, and site-specific factors all influence the final fee. A clear, fixed fee is agreed before any work begins, based on a scoping conversation that costs nothing.
Fees from large national firms — with overhead, business development costs, and multi-layer management structures — will generally be higher. Fees from unqualified or unlicensed operators will often be lower, but the quality and defensibility of the output reflects it.
Why the Cheapest Quote Is Rarely the Best Value
Security consulting is a professional service where the quality of the output — the accuracy of the risk assessment, the specificity of the recommendations, the defensibility of the report — directly determines whether the engagement has been worthwhile.
A low-fee security assessment that misses significant risks, produces generic recommendations, or generates a report that can’t withstand scrutiny from a board or regulator has a negative return. The organisation has spent money, has a false sense of having addressed their security obligations, and is exposed to exactly the risks the assessment was supposed to identify.
A well-scoped, properly conducted assessment from a credentialled independent consultant costs more upfront but delivers a genuine return — through informed investment decisions, avoided expenditure on ineffective controls, and a documented governance position that stands up when it matters.
The specific questions worth asking when evaluating security consulting fees:
Is the consultant independent? A vendor, installer, or guarding company offering a “free assessment” or unusually low-cost review has a commercial interest in the outcome. The assessment will tend to find problems their products or services can solve. An independent consultant has no stake in what you buy — the fee covers the advice, and that’s it.
Are they credentialled and licensed? In Western Australia, security risk consultants are required to hold a WA Security Risk Consultant licence issued under the Security Industry Act 1997. Practitioners also holding the Security Risk Management Certified Professional (SRMCP) credential have demonstrated competency against a national professional standard. These credentials matter — they tell you the person conducting the assessment has been assessed themselves against a benchmark.
Is the methodology documented? An assessment aligned with ISO 31000:2018 applies a recognised, defensible methodology. If the consultant can’t tell you what standard their methodology follows, the output is an opinion, not a risk assessment.
What does the report include? A genuine security risk assessment report documents methodology, findings, risk ratings, and prioritised recommendations — not a summary of what was observed on the day. Ask to see a redacted example before engaging.
WALGA Panel Rates for WA Councils
For WA local government authorities engaging a security consultant through the WALGA Preferred Supplier Panel, the hourly rate is set under the panel arrangement. Councils engaging Smartsec through the WALGA panel (PSP001-002 and PSP001-026) can do so within the panel rate structure, which simplifies procurement and provides cost certainty without requiring a separate tender process.
For council procurement officers who need to understand what a security consulting engagement will cost before approaching the panel, the indicative project fees above provide a realistic reference point for budgeting purposes.
Smartsec Security Solutions – Transparent Fees, Independent Advice
Smartsec Security Solutions is a Perth-based independent physical security consultancy. We provide transparent fee structures — fixed project fees where the scope allows, hourly rates where the engagement is more variable — with no hidden costs and no commercial interest in what you subsequently purchase.
Every engagement begins with a brief scoping conversation at no charge. From that conversation we confirm the scope, the deliverables, the timeframe, and the fee — before any work begins.
We are a WALGA Preferred Supplier (PSP001-002 and PSP001-026), a licensed WA Security Risk Consultant and Security Agent, and hold the Security Risk Management Certified Professional (SRMCP) credential.
Contact Smartsec Security Solutions to discuss your site and get a clear fee estimate for your specific requirements.


