The U.S. Bureau of Labor Statistics counted 470 workplace homicides in 2024, up from 458 the year before, in its Census of Fatal Occupational Injuries released in February 2026. Nearly every one of those buildings had security cameras. Many had a completed physical security risk assessment sitting in a compliance folder.
That gap is the point. A physical security risk assessment is the most valuable exercise a facility can run, and it is also the exercise most often reduced to a checklist that counts equipment instead of measuring risk. A camera in the parking lot earns a checkmark. Whether anyone is watching that camera at 2:14 a.m. is a question most templates never ask.
This is a working framework for 2026: how to scope the assessment, how to score risk in a way that survives a budget conversation, and how to close the one finding that appears in almost every report and gets fixed the least often.
What is a physical security risk assessment?
A physical security risk assessment is a structured evaluation of a facility's assets, the threats against them, the vulnerabilities that would let a threat succeed, and the consequences if it did. The output is not a list of broken locks. It is a prioritized, defensible ranking of risks that tells leadership where the next dollar should go.
Three terms do the heavy lifting, and mixing them up is the most common reason assessments produce unusable results:
- Threat is what could happen and how likely it is: armed intrusion, theft, workplace violence, unauthorized access, vandalism, or an environmental event.
- Vulnerability is the weakness that lets the threat succeed: an unlocked side entrance, a fence line no one observes, a camera pointed at a wall, an alarm nobody answers.
- Consequence is what it costs when it does succeed: injury or loss of life, operational downtime, property loss, regulatory exposure, litigation.
Risk lives at the intersection. A high-likelihood threat against a hardened asset with low consequence is not your priority. A moderate-likelihood threat against an undefended asset with severe consequence is where your budget belongs. An assessment that never scores all three dimensions cannot tell you which is which.
The five-step framework federal facilities use
The most rigorous publicly available methodology is the Interagency Security Committee's Risk Management Process standard, maintained by CISA and updated in its 2024 Edition. It governs federal facilities, but the logic transfers cleanly to hospitals, schools, manufacturing plants, and corporate campuses, and it is far more defensible than a vendor checklist.
The process runs in five steps, each one gating the next.
- Determine the facility security level. Score the site on factors such as population, mission criticality, symbolic value, and threat environment. A 40-person back office and a regional trauma center do not warrant the same controls, and this step is what stops you from over-hardening one and under-hardening the other.
- Identify the baseline level of protection. Establish what a facility at that security level is expected to have before you look at what it actually has. This is your yardstick.
- Identify and assess the risks. Walk the site against a defined list of undesirable events, and score each one on threat, vulnerability, and consequence. This is the step where most assessments quietly go wrong, for reasons covered below.
- Determine the necessary or highest achievable level of protection. Reconcile what the risk demands with what the budget, the building, and the operating reality allow. Document the delta honestly, because that documented delta is what protects the organization later.
- Implement and measure performance. Deploy the countermeasures, then test whether they perform. A control that has never been tested is an assumption, not a control.
Step five is where most programs stop reading. It is also the step that separates an assessment from a document. The U.S. Department of Energy's Physical Security Systems Assessment Guide devotes entire appendices to performance testing precisely because paper compliance and real protection diverge fast.
How to score physical security risk without guessing
Scoring turns an assessment from a narrative into a decision tool, and the simplest defensible model rates threat likelihood, vulnerability, and consequence on a 1 to 5 scale, then multiplies them. Every competitor checklist skips this step, which is why so many assessments end with twenty findings and no argument for which three to fund.
| Score | Threat likelihood | Vulnerability | Consequence |
|---|---|---|---|
| 1 | No credible history, low regional incidence | Layered controls, tested and monitored | Minor property loss, no injury |
| 2 | Rare, isolated regional precedent | Controls present and generally effective | Contained loss, short recovery |
| 3 | Documented incidents in the sector | Controls present but unverified | Meaningful downtime or moderate loss |
| 4 | Incidents on site or at peer facilities | Controls exist but nobody observes them | Serious injury, major loss, regulatory exposure |
| 5 | Active, credible, current threat | No effective control at all | Loss of life, catastrophic liability |
Multiply the three columns for a composite score from 1 to 125. Anything above roughly 45 belongs in the current fiscal year. The specific thresholds matter less than the discipline: the same scale, applied by the same team, across every finding, so that two people looking at the same report reach the same priority order.
One scoring rule is worth writing into your template. A control that exists but is not observed scores a 4 on vulnerability, not a 1. That single rule changes what most assessments conclude.
What a physical security risk assessment usually misses
The most common unaddressed finding in facility security is not a missing camera, it is a camera nobody is watching. Assessment templates ask whether video coverage exists at each entry point, and a facility with cameras everywhere passes that line item cleanly while remaining entirely reactive.
Federal guidance is unusually direct on this distinction. The DOE assessment guide treats detection and assessment as two separate functions of a security system, noting that intrusion detection systems "consist of both an alarm and an assessment system," and that video is most effective when it "can automatically call the operator's attention to an alarm-associated camera display." Passive recording satisfies neither function. It produces evidence after the fact.
The same guide names the failure mode that follows: "A high rate of false and/or nuisance alarms may lead the protective force to ignore or improperly assess an intrusion." It specifically calls out legacy video motion detection as vulnerable to nuisance alarms from "reflected light, cloud motion, vehicle headlights, and camera vibration due to wind." Anyone who has watched a security team mute a motion zone after the third windy night knows exactly how that ends. We have covered what a 98 percent false alarm rate actually costs an organization in operational terms.
Three findings belong in every assessment and appear in almost none:
- Monitoring coverage, not camera coverage. Record how many cameras exist, then record how many are viewed by a person or a system during each shift. The second number is usually a small fraction of the first. Cameras that record incidents rather than prevent them are a documentation system, not a security control.
- Operator attention limits. Human video monitoring degrades measurably within the first half hour of a shift, which is why wall-of-monitors deployments fail predictably rather than occasionally. If your countermeasure for an unattended perimeter is a guard watching sixteen tiles, score it accordingly.
- Camera health. An assessment that counts cameras from a floor plan instead of from live video will count devices that have been offline for months. Continuous camera health monitoring turns that from an annual surprise into a daily report.
How often should you reassess?
Reassessment should be driven by change, not only by the calendar, with a floor of every one to three years depending on facility risk level. Federal practice runs slower than most people assume: a Government Accountability Office survey of 32 agencies, published in 2013, found median reassessment intervals of 36 months for medium and high risk facilities and 60 months for the lowest tier.
For most private and institutional facilities in 2026, an annual review with a full reassessment every two to three years is a reasonable baseline. Any of the following should trigger an out-of-cycle assessment regardless of where you sit in that cycle:
- A security incident, near miss, or credible threat at your site or a peer facility
- A renovation, expansion, or change in how the building is entered
- A significant change in occupancy, hours, or public access
- A new regulatory or insurance requirement
- Turnover in the security leadership responsible for the last assessment
Sector-specific guidance is worth layering on top of the general framework. Our vulnerability assessment checklist for houses of worship shows how the same five steps get tuned for a specific environment and threat profile.
Turning assessment findings into actual detection
The fastest way to close a monitoring gap is to add detection to the cameras already installed rather than replace the camera system. This is the practical answer to the finding that shows up in nearly every honest assessment: adequate coverage, inadequate observation.
AI video analytics layers onto existing camera infrastructure and analyzes those feeds continuously, sending an alert within seconds when it identifies a weapon, a person in an area that should be empty, a fall, a crowd forming, a vehicle where vehicles do not belong, or smoke and fire. No hardware replacement, no rip and replace of a system a facility has already paid for, and no facial recognition. IntelliSee does not identify individuals, and for most assessment teams that is a feature rather than a limitation, because it removes an entire category of privacy findings from the report.
In scoring terms, this is what moves a line item from a vulnerability score of 4, a control that exists but nobody observes, down to a 2. It is one of the few remediations that improves a score without a capital project, which is why it tends to survive the budget conversation that follows every assessment.
Key takeaways
- Score every finding on threat, vulnerability, and consequence. A checklist without scoring cannot prioritize.
- Write the rule into your template: a control nobody observes is a high vulnerability, not a satisfied requirement.
- Measure monitoring coverage separately from camera coverage. The two numbers are rarely close.
- Test your controls. An untested countermeasure is an assumption.
- Reassess on change, not only on the calendar, with a full cycle every two to three years.
Frequently asked questions
What is the difference between a physical security risk assessment and a security audit?
A security audit measures compliance against a fixed standard and answers whether required controls are present. A physical security risk assessment measures exposure and answers which risks matter most and what should be funded first. Audits produce pass or fail results; assessments produce a priority order.
Who should conduct a physical security risk assessment?
A cross-functional team gives the most reliable result: security leadership, facilities, operations, and someone from the department that actually occupies the space. Independent third party assessors reduce internal bias and are commonly required for insurance or grant purposes, but internal teams can run the framework credibly if the scoring model is applied consistently.
How long does a physical security risk assessment take?
A single-building assessment typically takes one to three days on site plus one to two weeks for scoring, documentation, and review. Multi-site portfolios are usually staged by facility security level, with the highest-tier sites assessed first.
Does a physical security risk assessment require replacing existing cameras?
Usually not. Most assessments find that camera coverage is adequate while monitoring is not, which is a software and process gap rather than a hardware one. AI video analytics that layer onto existing cameras address the monitoring finding without a camera replacement project.
Can grant funding cover physical security improvements found in an assessment?
Yes, and many federal and state security grant programs require a completed vulnerability or risk assessment as part of the application. The assessment is often the document that justifies the funding request, which makes running one a prerequisite rather than an afterthought.
The assessment is only as good as what it changes
A physical security risk assessment earns its cost in the findings it forces an organization to act on. Scored honestly, the report will show what security leaders across every sector already suspect: the cameras are installed, the coverage is fine, and nobody is watching. That is a solvable finding, and it does not require tearing out a camera system to solve.
IntelliSee exists to turn passive cameras into proactive protectors, adding real-time AI detection to the infrastructure a facility already owns. If your last assessment flagged a monitoring gap, talk with our team about what detection on your existing cameras would look like. If funding is the obstacle, our grant funding resources map the programs that pay for security improvements identified in an assessment.