About
An independent protective security consultancy
We exist to tell organisations the truth about their protective security — supported by evidence, and free of commercial interest.
Why BlackTrace Operations exists
Most organisations can demonstrate that their security controls exist. Far fewer can demonstrate that those controls hold when someone capable and patient sets out to defeat them. The gap between the two is where loss occurs, and it is rarely visible from inside the organisation.
Independent assessment can be harder to achieve where the assessor also supplies the remedy. An organisation that installs systems, provides guarding or resells products has a commercial interest in what happens after the assessment. BlackTrace Operations was established to separate assessment and assurance from the sale of remediation.
BlackTrace Operations operates a senior-led delivery model. Engagements are delivered directly by experienced practitioners, maintaining continuity from assessment through analysis and reporting. The consultant who assesses the environment remains accountable for the conclusions and can present and substantiate them directly to senior decision-makers.
To help organisations understand and reduce protective security risk through independent, evidence-led assessment of physical, personnel and procedural security — informed by credible adversary behaviour, so that protection holds when it matters.
Our consultancy philosophy
Three principles govern the consultancy. They are not slogans; they are the criteria against which we decide what to write, what to recommend and what work to accept.
Independent
We sell no products, install no systems and hold no referral arrangements. Findings can be used as impartial evidence in audit, board and regulatory settings.
Evidence-led
Every claim is traceable to an observation, an artefact or a source. Where the evidence does not support a finding, the finding is withdrawn.
Protective
The purpose is to strengthen, not to expose. Adversarial method serves a protective end, and is applied only where it produces evidence that assessment alone cannot.
What that means in practice
Our reporting states what was observed before what it means. “The rear entrance was propped open on three of four visits, which permits unescorted access to the plant room” is a finding. “Access control is poor” is an opinion, and it cannot be acted on, audited or measured.
Findings address controls, procedures, training and environment. An organisation cannot remediate a person; it can remediate a process. Risk is rated against a defined scale published with the report, so ratings can be challenged and compared between sites and across years.
Every recommendation names what should be done, which function owns it and what it achieves, costed against real operational and budgetary constraints. Where one is not adopted, we record the residual risk so the decision is documented rather than left implicit. Where a recommendation implies procurement, we describe the requirement and the performance it must achieve rather than naming a supplier.
We will say when an engagement is not worth commissioning.
Experience behind the practice
BlackTrace is led by practitioners with experience supporting security work across national security, sensitive and high-trust environments, as well as commercial settings. That breadth informs how engagements are planned and conducted — disciplined preparation, realistic threat modelling, proportionality and control — and how legality, risk and client confidence are managed throughout.
It is complemented by delivery within large commercial organisations, so that our work reflects modern enterprise environments, governance expectations, procurement requirements and real operating constraints.
Working with procurement
Professional insurance appropriate to the services delivered is maintained, including Professional Indemnity and Public Liability cover, and certificates are provided on request. Client information is handled under documented information-security, access-control and data-retention procedures, and we are content to work under client non-disclosure agreements.
Registration details, insurance documentation, references and method statements are supplied as part of any tender response or on request. Statutory company information appears in the footer of every page.
Next step
Ask us anything before you commit to anything.
An initial conversation is exploratory and confidential. There is no sales process and no obligation.