FAQ
Common questions
Answers on scope, method, governance, deliverables and procurement — written to be useful before you approach us, not after.
Adversarial testing is one capability within our consultancy work. It is applied where it adds evidential value, and only where authorised in writing.
Questions
What to expect before engaging
If your question is not answered here, get in touch. We are happy to talk through any aspect of an engagement before you commit to anything, including whether an engagement is warranted at all.
Section 01
Scope and approach
How is a protective security assessment different from a penetration test?
A penetration test is normally a technical exercise against IT systems, scoped to a defined set of assets and measured by whether access was obtained. A protective security assessment is a consultancy engagement covering physical, personnel and procedural security as one system, and it is measured by whether the organisation understands its position and knows what to change.
The difference shows in the output. A penetration test typically produces a list of technical findings. An assessment produces a view of security maturity, findings traceable to observation, and a prioritised improvement plan written for the people who must act on it and for the board that must fund it.
Physical intrusion testing is one method we may use within an assessment. It establishes what an adversary could achieve in practice; it is not the engagement in itself.
How does an assessment differ from an audit?
An audit generally establishes whether defined controls are present and operating. An assessment establishes whether the overall arrangement protects against the threats the organisation actually faces, including where compliant controls are defeated in practice.
The two are complementary. Our reporting is written to support audit activity rather than duplicate it, and findings are structured so that they can be carried directly into an audit or assurance return.
Do we have to include intrusion testing?
No. Protective security assessments, personnel security reviews and security assurance are delivered without any adversarial testing where that is appropriate. Testing is applied only where it produces evidence that assessment alone cannot, and only with written authorisation.
Do you undertake covert testing?
Yes, where it is proportionate, lawful and authorised in writing by an accountable representative of the organisation.
Covert in this context means that the activity is not announced to the site or to the staff whose response is being assessed. It is never covert to the organisation itself: a small, named group always knows the engagement is running, holds the rules of engagement, and can stop activity immediately. Every consultant carries written authorisation throughout.
Where an organisation prefers announced testing — for example on a live operational site, or where staff wellbeing is a concern — announced activity still produces useful evidence about control design, and we will say which questions it can and cannot answer.
Can cyber validation be included where authorised?
Yes, within limits that we state plainly. Where an organisation explicitly authorises it as part of an adversary simulation, we may evidence the technical exposure that physical compromise creates — for example, what an unsupervised person could reach from an accessible network port or an unattended workstation.
The purpose is to demonstrate consequence, so that physical findings can be assessed against real impact rather than assumed impact. It is bounded by the rules of engagement and evidenced to the minimum extent needed to establish the point.
We do not deliver standalone penetration testing, vulnerability scanning or cyber security advisory work, and we will say so rather than extend beyond our discipline.
Do you carry out social engineering?
Yes. Social engineering, pretexting and human-factor testing form part of adversary simulation, and inform personnel security reviews where identity verification, challenge culture and staff response are in scope.
It is applied proportionately and by agreement. Findings address process, training and environment rather than the conduct of named individuals, and we do not use pretexts that would cause distress or that rely on personal or medical circumstances.
Do you cover cyber security?
We are a physical and personnel security consultancy. Where explicitly authorised as part of an adversary simulation, we may evidence the technical exposure that physical compromise creates, in order to demonstrate consequence. We do not deliver standalone cyber security testing or advisory services.
Section 02
Working with your organisation
Do you provide remediation advice?
Yes. Remediation advice is part of the engagement, not a separate purchase. Every finding carries a recommendation stating what should be done, which function owns it and what it achieves, sequenced by the risk reduction achieved against the effort required.
Beyond the report, we can support remediation planning, review proposed designs and procurement specifications before commitment, and re-assess specific findings once they are closed.
Because we sell no products or systems, our advice describes the requirement and the performance it must achieve rather than naming a supplier — unless we are specifically asked to comment on options already under consideration.
Do you work alongside existing security providers?
Yes, and it is common. Most organisations we work with already hold contracts for manned guarding, systems maintenance, monitoring or facilities management. Our role is to assess the arrangement as a whole, which includes how those services perform in practice.
We work with incumbent providers professionally and without agenda. Findings address controls and processes rather than supplier performance in isolation, and we will say where a weakness originates in a specification or a contract rather than in the provider's delivery of it.
We hold no referral, commission or partner arrangements with any provider, which is what allows our findings to be used as impartial evidence in a contract review or a retender.
Can you re-assess after remediation?
Yes. Re-assessment confirms whether changes have measurably reduced risk, and provides evidence of improvement for audit and board reporting. It is normally offered as an option within the proposal and can also be scoped separately once remediation is complete.
Can you assess multiple sites?
Yes. Multi-site work is common and is usually delivered as one engagement with a defined schedule. This allows us to compare consistency across locations, identify systemic weaknesses and prioritise improvements that reduce risk across the estate rather than at one site.
For large or dispersed estates we normally assess a representative sample and state clearly what the sample supports and what it does not.
Will this disrupt operations?
Disruption is designed out. Activity is planned around operational constraints, with defined windows, deconfliction and clear stop conditions. Where appropriate we work off-peak and use low-footprint methods. If anything creates unintended impact, activity pauses immediately.
Section 03
Governance and conduct
Is assessment activity safe and controlled?
Yes. Any activity beyond observation and document review is governed by written rules of engagement covering objectives, constraints, excluded areas, stop conditions, named contacts and escalation routes. Nothing begins until that framework is agreed and authorised.
Do you attribute findings to individuals?
No. Findings address systems, procedures, training and environment. Where human interaction forms part of an assessment, it is used to identify where controls fail in practice, not to identify individuals.
This is a matter of accuracy as well as of conduct. An organisation cannot remediate a person; it can remediate a procedure, a training gap or an environment that made the wrong action the easy one.
Do you provide written authorisation documents?
Yes. Where an engagement includes adversarial activity, we provide a Letter of Authorisation aligned to the agreed rules of engagement and signed by an authorised representative. It records scope, dates, named contacts and escalation routes. No such activity takes place without it.
How is our information protected?
Engagement information and evidence are handled under agreed confidentiality terms, with retention periods and handling requirements set at the scoping stage. We are content to work under client non-disclosure agreements and sector-specific handling requirements.
We do not publish client names, site details or findings, and we do not use engagement imagery in marketing material of any kind.
Section 04
Commercial and procurement
How long does an engagement take, and when do we get the report?
It depends on scope: the number of sites, the depth of assessment and whether adversarial testing is included. A single-site assessment is a different exercise from an estate-wide programme, and we would rather scope it honestly than quote a standard duration.
Reporting timescales are agreed at the outset and reflected in the written scope, alongside the deliverables and reporting milestones for the engagement. Where something we find warrants immediate attention, we raise it as soon as it is established rather than holding it until delivery.
How is cost determined?
Engagements are quoted at a fixed cost against a written scope, agreed before work begins. Cost is driven by the number of sites, the depth of assessment and whether adversarial testing is included. If scope changes during an engagement, any cost implication is agreed in writing first.
What do we receive at the end?
An executive summary for board and leadership, detailed findings with supporting evidence and risk ratings, an evidence pack, and prioritised recommendations. A leadership debrief is included where required.
Where appropriate, immediate risk themes are raised verbally before the report is issued rather than held until delivery.
Can you support procurement and tender requirements?
Yes. Company registration details, data protection registration, professional insurance information, references and method statements are provided as part of tender responses or on request.
Please include any reference number and submission deadline in your enquiry.
Next step
Still have questions?
Get in touch for a direct conversation with a consultant. No obligation and no sales process.