A security risk assessment is the starting point for almost every engagement we conduct at Smartsec. Before recommending a single control, upgrade, or procedure change, we need to understand what the risk actually is — what threats are realistic, what vulnerabilities exist, and what the consequence of something going wrong would be.
This article explains what a security risk assessment in Perth involves, how the process works, and what organisations across WA receive at the end of it.
What a Security Risk Assessment Actually Is
A security risk assessment is a structured, evidence-based process for identifying threats to an organisation’s people, assets, and operations — and evaluating how well existing controls are managing those threats.
It is not a site walkthrough. It is not a quote for CCTV or access control. It is not a generic checklist applied to every site regardless of context. A genuine security risk assessment produces findings that are specific to your site, your threat environment, and your current control arrangements — and it tells you, in priority order, what needs to change and why.
In Australia, the recognised framework for security risk assessment methodology is ISO 31000:2018 — Risk Management: Guidelines. At Smartsec, all assessments are aligned with this standard, which means the methodology is structured, repeatable, and defensible when findings are presented to boards, audit committees, insurers, or regulators.
Who Needs a Security Risk Assessment in Perth
Security risk assessments are commissioned across a wide range of organisations and contexts in Perth and regional WA. The most common include:
Local government and councils — managing parks, laneways, civic buildings, libraries, carparks, and community facilities. Many WA councils commission assessments as part of their annual risk management cycle, in response to community safety concerns, or to support capital works decisions. Smartsec is a WALGA Preferred Supplier, which means councils can engage us directly under the panel arrangement without a separate tender process.
Developers and architects — when a development application carries a security or CPTED condition, an independent assessment provides the evidentiary basis required for planning approval. We work with architects and planning consultants at design stage and at DA lodgement.
Healthcare facilities — hospitals, aged care providers, and community health centres have specific security obligations under AS 4485:2021 and the WA Health Risk Management Policy. An independent physical security assessment provides the documented risk position required for governance and regulatory purposes.
Commercial operators — retail, hospitality, property managers, and strata operators commissioning assessments in response to incidents, insurance requirements, or operational concerns.
Critical infrastructure operators — energy, water, transport, and health assets subject to the Security of Critical Infrastructure Act 2018 requiring CIRMP physical security plans and documented risk assessments aligned with the PSPF Facility Security Plan principles.
Educational institutions — schools, TAFEs, and universities managing open campuses with diverse user groups and specific after-hours vulnerability.
How the Process Works
Every security risk assessment Smartsec conducts follows a structured process. The specifics vary by site and scope — a single-site assessment for a council carpark looks different to a portfolio review across 20 community facilities — but the methodology is consistent.
Scoping conversation. Every engagement starts with a brief conversation — usually 10 to 15 minutes — to understand the site, the known concerns, and what the assessment needs to achieve. This shapes the scope, confirms the right approach, and prevents the assessment from being broader or narrower than it needs to be.
Site inspection. There is no substitute for physically being on site. We walk the site and evaluate the physical environment — access points, sightlines, lighting, CCTV coverage, perimeter arrangements, and the areas that are most vulnerable to the threats identified in context. Where relevant, we conduct both a daytime and after-hours inspection, because many sites look very different after hours and the risk profile changes accordingly.
Threat identification. We identify the realistic threats relevant to your specific site and operational context. For most WA organisations this includes opportunistic theft, vandalism and antisocial behaviour, unauthorised access, aggression toward staff, and after-hours intrusion. For higher-profile or public-facing sites, the threat picture may extend to vehicle-borne threats, crowded places risks, and the broader threat environment relevant to the sector.
Vulnerability assessment. We evaluate each existing control against the threats it’s supposed to address — whether it’s adequate, whether it’s configured correctly, and whether it’s actually reducing the risk it was installed to manage. CCTV coverage, access control arrangements, lighting performance against AS/NZS 1158, alarm systems, perimeter treatments, and procedures are all evaluated.
Risk rating. Each identified threat is rated using a likelihood-consequence matrix aligned with ISO 31000:2018. This produces a risk register that tells you not just what the risks are, but how serious each one is and where to focus resources first. This prioritisation is critical for organisations working within constrained budgets — it distinguishes between risks requiring immediate action and those that can be managed progressively.
Report and recommendations. You receive a written report documenting methodology, findings, site-specific observations, risk ratings, and prioritised recommendations. Reports are written for decision-makers, not security specialists — clear enough to present to a board, council committee, or auditor, and specific enough to act on directly.
What You Receive at the End of a Smartsec Assessment
Depending on the scope and purpose of the assessment, deliverables typically include:
A written risk assessment report aligned with ISO 31000:2018, documenting methodology, findings, and a prioritised risk register.
Photographic evidence of key vulnerabilities and control gaps identified during the site inspection.
Prioritised recommendations distinguishing between immediate actions, medium-term improvements, and longer-term strategic investments — so the organisation knows where to start and what can wait.
Vendor-neutral recommendations that specify performance outcomes rather than particular brands or products — so the findings can be used to brief suppliers and run a proper procurement process without being locked into a specific vendor’s solution.
A report format suitable for governance — board presentations, council committee approval, audit evidence, insurance submissions, and regulatory attestation as required.
Why Independent Assessment Matters
Most security advice in Perth comes from organisations that also sell products, install systems, or supply guards. The advice is often useful, but it comes with an inherent conflict of interest — the assessment tends to find problems that the assessor’s product range can solve.
Smartsec is an independent physical security consultancy. We don’t sell CCTV, access control, alarms, or guarding services. We have no commercial relationships with any security product supplier or installer. Every finding and recommendation reflects the actual risk and what the site needs — not what generates a follow-on sale.
For organisations that need to present security decisions to a board, justify a budget to elected members, or demonstrate compliance to a regulator, independent assessment provides a stronger and more defensible governance position than a vendor-conducted review.
Security Risk Assessments Across Perth and Regional WA
Smartsec conducts security risk assessments across metropolitan Perth and regional and remote WA — including the Pilbara, Kimberley, Goldfields, South West, Wheatbelt, and Great Southern regions.
We understand the specific operating environments across WA — the extended response times and isolation challenges of remote and regional sites, the planning and procurement frameworks that apply to WA councils, the SOCI obligations that apply to WA critical infrastructure operators, and the development application conditions that increasingly require security and CPTED reports across metropolitan and regional local government areas.
This local knowledge shapes assessments that are genuinely relevant to the WA context, rather than assessments adapted from national templates that don’t account for the realities of operating in Western Australia.
About Smartsec Security Solutions
Smartsec Security Solutions is a Perth-based independent physical security consultancy delivering security risk assessments for councils, developers, healthcare facilities, critical infrastructure operators, commercial operators, and community organisations across Western Australia.
Our assessments are delivered by Khabeer Rockley SRMCP — a licensed WA Security Risk Consultant and Security Agent with technical security licensing and nearly two decades of experience in physical security across the public and private sectors in WA.
We are a WALGA Preferred Supplier (PSP001-002 and PSP001-026) and an approved supplier through Local Government Contracts Australia (LGCA). Our methodology is aligned with ISO 31000:2018 and relevant Australian Standards.
Contact Smartsec Security Solutions to arrange a scoping conversation — no obligation and no fee for the initial call.


