A site security risk assessment evaluates the specific physical environment your organisation operates in — the building, the precinct, the campus, the facility — and produces a structured, evidence-based picture of the threats present, the vulnerabilities that exist, and how well the current controls are actually performing.

The word “site” matters here. Generic security advice can be applied anywhere. A site security risk assessment is grounded in what’s actually happening at your specific location — the access points, the sightlines, the lighting, the after-hours conditions, the incident history, the surrounding environment. That specificity is what makes the findings actionable rather than theoretical.

At Smartsec Security Solutions, every assessment we conduct is a site assessment. We don’t produce reports from desks — we attend your site, walk it, and evaluate it against a structured methodology aligned with ISO 31000:2018.

 

What a Site Security Risk Assessment Evaluates

A comprehensive site security risk assessment examines multiple layers of physical security, each of which contributes to the overall risk picture.

Perimeter and access control. How people, vehicles, and deliveries enter and exit the site. Fencing, gates, boom barriers, access control readers, credential management, and the integrity of the boundary between public and controlled areas. Weak or poorly managed perimeters are consistently one of the most common findings in site assessments across Perth and regional WA.

CCTV and surveillance. Camera placement, coverage, image quality and resolution against the surveillance objective (detection, observation, recognition, or identification), recording and retention settings, system health, and whether camera positioning reflects current risk rather than original installation convenience. Assessed against AS/NZS 62676.

Lighting. Illumination levels and uniformity assessed against AS/NZS 1158, including after-hours performance. Lighting and CCTV need to work together — a camera covering an inadequately lit area produces unusable footage regardless of its specification. After-hours lighting assessments frequently identify gaps that daytime inspections miss entirely.

Alarm and monitoring arrangements. Alarm configuration, monitoring centre response protocols, integration between intruder, duress, and access control systems, and whether alarm events are actually generating an appropriate response.

Security procedures and staff practices. Incident reporting, patrol routines, escalation pathways, key and credential management, visitor and contractor management, and after-hours procedures. Physical controls are only as effective as the procedures that govern their use — this element of the assessment is frequently the most revealing.

Environmental and CPTED factors. Natural surveillance — how well legitimate users can see activity across the site. Territorial definition — whether the boundary between public and controlled space is clear to users. Sightlines, landscaping, and the design of movement paths. Assessed against ISO 22341:2021 and the WA Government’s Safer Places by Design framework where relevant.

After-hours vulnerability. Many sites present a significantly different risk profile after hours — when staffing is reduced, monitoring is less active, and response times are longer. A site assessment that only examines daytime conditions gives an incomplete picture. After-hours inspections are included where the risk warrants it.

 

Who Commissions Site Security Risk Assessments in Perth

Site security risk assessments are commissioned across a wide range of sectors in Perth and regional WA.

Local government and councils. Parks, libraries, civic buildings, carparks, community centres, laneways, and public open space. Smartsec is a WALGA Preferred Supplier (PSP001-002 and PSP001-026) — councils can engage us directly under the panel arrangement without a separate procurement process.

Healthcare facilities. Hospitals, aged care providers, and community health centres with obligations under AS 4485:2021 and the WA Health Risk Management Policy. Site-specific assessment is required for compliance documentation.

Commercial and retail operators. Office buildings, retail centres, shopping precincts, and mixed-use developments where incidents, insurance requirements, or governance obligations trigger independent assessment.

Developers and architects. When a development application carries a security or CPTED condition, a site assessment provides the evidentiary basis for planning approval. Early engagement at design stage is significantly more cost-effective than a retrospective assessment after construction.

Critical infrastructure operators. Energy, water, transport, health, and communications assets subject to the Security of Critical Infrastructure Act 2018. Site-specific physical security assessment is the foundation of a compliant CIRMP physical security plan.

Educational institutions. Schools, TAFEs, and universities with open campuses, diverse user groups, and specific after-hours vulnerability profiles.

Mining and resources operators. Remote mine sites and FIFO facilities across the Pilbara, Kimberley, and Goldfields where extended response times and isolated locations create specific site security challenges.

 

Common Triggers for Commissioning a Site Security Risk Assessment

Organisations commission site assessments at different points in the security decision-making cycle. The most common triggers in Perth and regional WA include:

Following an incident. A break-in, assault, theft, or significant security failure often prompts an organisation to commission an independent assessment — to understand what went wrong, whether existing controls were adequate, and what needs to change.

Before a capital works decision. When a significant investment in CCTV, access control, or perimeter infrastructure is being considered, a site assessment provides the risk evidence that justifies the spend and ensures the investment addresses the actual risk rather than a perceived one.

For compliance and governance purposes. Councils, government agencies, healthcare facilities, and critical infrastructure operators commission assessments to satisfy governance requirements, insurer expectations, regulatory attestation, or development application conditions.

In response to a change. New tenancy, site expansion, change in operating hours, change in user population, or significant change in the surrounding environment — all of which can alter the site’s risk profile in ways that existing controls may not address.

As part of a regular review cycle. Security risk is not static. Organisations that treat site assessment as a periodic governance obligation — rather than a reactive response to incidents — are consistently better placed to make evidence-based security decisions.

 

The Site Assessment Process

Every Smartsec site security risk assessment follows a structured process. The scope and depth varies by site and purpose — a single-building assessment for a commercial operator looks different to a multi-site portfolio review for a regional council — but the methodology is consistent.

Scoping conversation. Before any site visit, we take the time to understand the organisation, its operating environment, the known concerns, and what the assessment needs to achieve. This shapes the scope and ensures the assessment is properly calibrated to the site.

Site inspection. Physical inspection of the site — access points, perimeter, surveillance, lighting, internal circulation, sensitive areas, and any locations identified as higher risk. Where relevant, both daytime and after-hours inspections are conducted.

Threat identification. Identifying the realistic threats relevant to the specific site — not a generic list, but a considered assessment of what threats are actually credible given the site’s location, use, operating hours, and incident history.

Vulnerability assessment. Evaluating each existing control against the identified threats — whether it’s adequate, configured correctly, and actually performing the function it was installed to serve.

Risk rating. Applying a likelihood-consequence matrix aligned with ISO 31000:2018 to produce a risk register — telling you not just what the risks are, but how serious each one is and where to focus first.

Report and recommendations. A written report documenting methodology, site-specific findings, photographic evidence of key issues, risk ratings, and prioritised recommendations. Written for decision-makers — clear enough to present to a board, council committee, or auditor, and specific enough to act on without translation.

 

Why Independent Assessment Matters

A site security risk assessment conducted by a vendor, installer, or guarding company carries an inherent bias — the findings tend to reflect what the assessor can supply. An independent assessment has no commercial interest in the outcome. The findings reflect the actual risk at your site, and recommendations reflect what the site genuinely needs.

For organisations presenting security decisions to a board, justifying expenditure to elected members, demonstrating compliance to a regulator, or satisfying an insurer — independence provides a stronger governance position and a more defensible basis for decisions.

Smartsec has no commercial relationships with any security product supplier, installer, or guarding company. Every site assessment is conducted on its merits — nothing else.

Contact Smartsec Security Solutions to arrange a scoping conversation for your site.

more insights

Call for a scope chat