Back to Blog
Access Control

Physical Security Consulting: What Actually Moves the Needle

Monarch ConnectedJune 29, 202611 min read
Five business professionals huddle over a glowing tactical map table during a physical security consulting briefing.

Updated September 16, 2026.

Most physical security problems aren't equipment problems — they're decision problems. A facility with a hundred cameras can be less secure than one with twelve, if the twelve are pointed at the right doors and someone actually reviews the footage. Consulting, done well, fixes the decisions first. The gear comes later.

This article walks through what good consulting looks like, what to watch out for, and how to evaluate whether the person you hire is doing useful work. It's written for facility owners, operations leaders, and small-business decision-makers who need a plain-English framework — not a sales pitch.

What Physical Security Consulting Actually Is

Strip away the jargon and physical security consulting has one core job: figuring out how a realistic adversary — a thief, a disgruntled former employee, a trespasser — would compromise your site, and then recommending changes that make that harder.

A consulting engagement typically includes:

  • A site walk focused on finding weaknesses, not selling products
  • A threat model specific to your business (a jewelry store and a logistics yard face very different problems)
  • A gap analysis comparing your current posture to what the threat model demands
  • A prioritized roadmap with realistic budget ranges
  • Recommendations that are, ideally, vendor-neutral

What it isn't: a generic PDF full of stock photos and "best-in-class" language. If the deliverable looks like a template lightly customized with your logo, that's a signal to push back.

One useful reference for the underlying discipline is the Interagency Security Committee's Best Practices for Planning and Managing Physical Security Resources, published through CISA. It's written for federal agencies but the framework — identifying assets, assessing risk, prioritizing countermeasures — translates well to private-sector facilities. You can find it on the CISA resources page.

Three Questions Every Consultant Should Ask First

Verkada security camera

Before anyone measures a doorway or counts cameras, a competent consultant will work through three foundational questions. If they skip these, that's a warning sign.

  1. What are you actually trying to protect? People, inventory, data, brand reputation, continuity of operations — each of these leads to different solutions. "Everything" is not a workable answer.
  2. What does a bad day look like for you? Not abstractly. Specifically. Overnight theft? An employee assault? A vendor let into the wrong area? The realistic worst-case scenario shapes the entire plan.
  3. What's your operational reality? A 24/7 distribution center has very different needs than a Monday-to-Friday office. A small team that already wears multiple hats can't reasonably add "monitor 40 cameras" to its duties.

None of these questions are about technology. The tech conversation should come later, once the decisions above are clear.

The Risk Assessment — The Highest-Value Deliverable

The most useful output of a consulting engagement is a real risk assessment. Not a checklist exercise — an actual walk-through of the property at the times a bad day would happen, looking at what regular occupants have stopped noticing.

A proper assessment covers four areas:

People. Who's coming and going. How visitors are handled. Who has keys, fobs, and codes — and who used to have them but never turned them in.

Process. What happens when an alarm goes off at 11pm. Who calls whom. Whether the night manager knows camera angles. Whether procedures are written or exist only in the memory of long-tenured staff.

Physical layout. Doors, fences, lighting, sightlines, blind spots, parking areas, loading docks, and yes — the dumpster area, which is frequently overlooked despite being a common entry point.

Technology. Cameras, access control, intercoms, alarms, monitoring. This category tends to attract the most attention and is often less important than the other three.

The federal design world takes a similar layered approach. The VA's Physical Security and Resiliency Design Manual, for example, categorizes facilities by criticality (Critical, Essential, Ancillary) and requires that Critical and Essential facilities support continued operations for a minimum of 96 hours during and following an extreme event. Even if you're not building a hospital, the principle — designing to a defined performance target, not a product list — is worth borrowing.

A well-executed assessment produces a picture of where actual risk concentrates, not a shopping list. If the deliverable contains more product SKUs than findings, that's a red flag.

Where Technology Enters the Conversation

Verkada intercom device mounted on a black metal perimeter gate outdoors.

Once the assessment and priorities are clear, technology decisions become easier. Even here, the consulting mindset matters more than the product list.

Access Control

Many facilities run access control systems installed a decade or more ago. They technically function — but they may not give you fast revocation, clean audit logs, or the ability to issue temporary credentials without physically being on site.

The useful questions are operational: When someone leaves, how quickly can you kill their access? When a contractor needs a one-day pass, how is that issued? A consultant should evaluate your access control setup against those questions, not against a feature checklist.

Cameras

Camera projects tend to fail for one of two reasons: too few cameras aimed at things that matter, or too many cameras aimed at things that don't.

A camera plan should answer, for each location, a specific question: "Who came through this door?" is a question a camera can answer. "General awareness of the parking lot" is a wish, and it's why so many post-incident reviews end with unusable footage.

Analytics have changed what's realistic. Modern systems can flag a person loitering at a loading dock overnight without a human watching the screen in real time. For a non-marketing overview of what those capabilities actually do, see this plain-English breakdown of AI security systems.

Intercom and Visitor Management

Intercoms are frequently underrated, especially for facilities with controlled lobbies, loading bays, or after-hours deliveries. The right questions: When someone presses the button, does the right person get the call? Can they see who's there? Can they unlock the door without walking down a hallway? If any answer is no, that's a finding worth documenting.

Monitoring

Cameras nobody watches function as evidence collection, not deterrence. That's a legitimate choice, but it should be a conscious one. A consultant should help you decide between self-monitoring, contracted monitoring, analytics-assisted monitoring, or a hybrid. Each has real costs and real trade-offs.

A Typical Engagement, Start to Finish

A reasonable engagement structure looks something like this:

Scoping call. The consultant asks the foundational questions above. You explain your operation. They request floor plans, current asset lists, incident history, and any relevant insurance requirements. If your incident history is "we don't really track that," that's already a finding.

Site visits, plural. Daytime and after hours, because facilities behave differently at 6pm than at 10am. A consultant who only visits during business hours is doing half the job.

Stakeholder interviews. The night manager, receptionist, loading dock lead, IT contact, and often the cleaning crew — who tend to see things others miss.

Draft report. Findings, risk ratings, recommendations, budget ranges, and suggested sequencing.

Review session. You push back on anything that doesn't match operational reality. They defend or revise. The final report should reflect both.

Implementation oversight (optional). A consultant who hands over a report and disappears leaves value on the table. Ongoing oversight during installation helps keep integrators honest.

Ask for a written scope with hours, deliverables, and revision cycles defined. Flat fees without scope tend to compress the work to fit the fee.

Red Flags When Hiring a Consultant

Security operator monitors Verkada intercom camera feeds on a desktop computer at a reception desk.

Warning signs, in no particular order:

  • Product recommendations before any site walk. That's selling, not consulting.
  • Inability to name a manufacturer they wouldn't recommend. Everyone with real experience has opinions.
  • Boilerplate-heavy reports where only a small portion appears to be about your facility.
  • Reluctance to share references from similar facilities.
  • Flat fees quoted without a scope of work.
  • Financial ties to specific integrators or manufacturers that aren't disclosed up front.

On credentials: ASIS International is the primary standards-setting body for the physical security profession. Their Standards & Guidelines catalog lists frameworks that reputable consultants often work within — including Physical Asset Protection, Security Risk Assessment, and Workplace Violence and Active Assailant standards. Asking a prospective consultant which standards they use as a reference is a legitimate screening question.

The Center for Development of Security Excellence also publishes a public Physical Security Toolkit with training materials that can help you evaluate whether a consultant's language and framework are grounded in established practice.

The Pilot Question

Most modern engagements end with the same choice: implement the full plan at once, or pilot a piece first?

Piloting first tends to be the safer default. It validates recommendations in real operating conditions, builds internal familiarity with the new systems, and gives you leverage in later pricing conversations. See this walkthrough on running an AI security pilot for a more detailed treatment.

The main exceptions are situations where risk is acute — recent break-ins, an active threat, or a regulatory deadline. In those cases, speed can matter more than staged rollout.

Where Consulting Ends and Operations Begin

Verkada intercom device mounted on a post at a gated parking lot entrance.

Even a well-designed plan can fail if no one owns it operationally. Before the engagement wraps, someone internal needs to own:

  • Daily verification that alarms are armed, cameras are online, and access logs are being reviewed at a defined interval
  • Quarterly access list reviews to catch stale credentials from departed employees and contractors
  • Annual revisits to the threat model, since business changes and security should follow
  • Debriefs after every incident, including small ones — patterns emerge over time

If there's no one to assign these to, that's a finding the consultant should raise before signing off. The answer might be hiring, outsourcing to a managed service, or reallocating existing staff time — but "we'll figure it out later" rarely holds up.

What Success Looks Like Six Months Later

Reasonable indicators that the engagement worked:

  • Your team can describe the security plan without reading from a binder
  • Incident response has named owners, not just steps
  • You've stopped doing at least one thing that wasn't actually helping
  • Real-time detection of unusual events has improved
  • Staff can articulate what to do when something is off

If none of those are true after six months, it's worth revisiting why — most often the cause is rushed implementation or unclear operational ownership.

FAQ

How much does physical security consulting cost?

Costs vary widely by facility count, complexity, and scope. Rather than relying on published ranges, ask for a written scope of work with defined deliverables and hours, and get quotes from two or three firms. Ask specifically whether the consultant earns product margin on any recommended equipment, and how their fee changes if you buy through their preferred integrator.

How is a consultant different from an integrator?

A consultant designs the plan and is paid for judgment. An integrator installs and maintains systems. The conflict of interest matters: if the same firm designs and installs, they have a financial reason to recommend more equipment. Some firms do both credibly, but you should know which hat is on at any given moment and how they're compensated for each role.

Do small businesses really need a security consultant?

Not always. The threshold depends on what you're protecting, foot traffic, staffing complexity, and incident history. For very small operations, a paid half-day walkthrough can surface most of the meaningful issues without a full engagement — ask consultants whether they offer this scaled-down option.

What's the difference between a security audit and a risk assessment?

An audit checks whether you're doing what a written policy or standard says you should be doing. A risk assessment asks whether the policy itself is right for the threats you actually face. You can pass an audit and still be exposed if the underlying assumptions are wrong. Most facilities benefit from a risk assessment first, with audits as follow-up.

How often should we revisit our physical security plan?

At minimum annually, and any time something material changes — a new facility, significant staffing changes, a merger, a new product line, a recent incident, or shifts in the surrounding area. Threat models drift over time.

Will a consultant work with the systems we already have?

A good one will look for reconfiguration and reuse before recommending replacement. Rip-and-replace should be a last resort. If a consultant recommends scrapping everything on day one, ask them to walk through the specific reasoning for each item.

Can one consultant cover both physical and cyber security?

Some can, and the overlap grows as cameras, access control, and intercoms increasingly live on IP networks. But deep dual-domain expertise is uncommon. More often, a physical security lead should coordinate with your IT or cybersecurity team. Ask for specific credentials or work samples in each domain if someone claims both.

What deliverables should we expect?

At minimum: a written risk assessment, a prioritized findings list with severity ratings, a recommended roadmap with budget ranges, and a stakeholder presentation. Stronger engagements also include vendor-neutral technical specifications you can put out to competitive bid, sample policies, and optional implementation oversight. If the deliverable is a PDF and an invoice with nothing else, ask what else is included.

Related Solutions

Explore how Monarch Connected can help with your specific security needs.

Shop Access Control

Ready to Upgrade Your Security?

Talk to our experts about Verkada cameras, access control, and sensors — book a demo.

More Articles