Independent protective security consultancy

Understand the threat.
Strengthen the defence.

We assess physical, personnel and procedural security as one system — combining protective security expertise, evidence-led assessment and the perspective of a capable adversary.

Independent

No product or supplier interests.

Evidence-led

Findings supported by documented evidence.

Adversary-informed

Controls considered against credible threat behaviour.

Actionable

Prioritised recommendations for decision-makers.

The distinction

Most reviews establish that controls exist. We establish whether they hold.

Documented arrangements and daily practice diverge over time. Procedures are written for conditions that have since changed, controls are worked around under operational pressure, and responsibility moves without the design moving with it.

We assess security as it is actually practised, establish what the difference permits, and set out what should change. The output supports decisions on risk and on where money is best spent.

How we see it

Protective security is a system, not a checklist

Physical, personnel and procedural measures fail together far more often than they fail alone. We assess them as one arrangement, from the threat it must withstand to the improvements worth making.

Starts with

Credible threat

What a capable adversary would realistically attempt, and why.

Physical

  • Perimeter and approach
  • Access control and zoning
  • Detection and response

Personnel

  • Staff, contractors, visitors
  • Privileged and elevated access
  • Challenge culture and reporting

Procedural

  • Policy and standards
  • Governance and accountability
  • Response and escalation
Assessed through

Assessment and adversarial thinking

Review, survey and interview, with authorised testing where it produces evidence assessment alone cannot.

Producing

Evidence

Observations, artefacts and timelines, each traceable to a finding.

Leading to

Prioritised improvement

Sequenced by the risk reduction achieved against the effort required.

What we do

One proposition, supported by specialist capabilities

Principal service

Protective Security Assessment

An independent assessment of how physical, personnel and procedural security work together — establishing where protection is weaker than assumed, what that permits, and which improvements reduce risk most for the effort involved.

This is BlackTrace’s principal assessment service. What it draws on depends on the question being asked and the scope agreed.

Specialist capabilities

Drawn on as the scope requires

Each may form part of a protective security assessment, or be commissioned on its own where an organisation already knows the question it needs answered. No engagement uses every capability, and adversarial testing is carried out only where the agreed scope provides for it.

Adversarial depth

A core specialist strength. The consultants who assess controls also understand how protective security is defeated in practice.

Physical Intrusion Testing

Authorised testing of whether access can realistically be achieved, and what it permits once it is.

View capability

Adversary Simulation

Extended scenarios showing how separate weaknesses combine into consequence.

View capability

Assessment and assurance

Personnel Security Reviews

Assessment of the controls governing who holds access, and on what basis.

View capability

Security Assurance

Independent review of security governance, management and maturity.

View capability

Methodology

The BlackTrace Protective Security Assessment Framework

Five stages applied to every engagement, from a single site to an estate-wide programme. Each produces a defined output the next stage depends on, which is what makes findings comparable between sites and across years.

01

Define

Establish what must be protected, from whom, and to what standard.

02

Assess

Gather evidence on how security is designed, and on how it is practised.

03

Analyse

Establish what each weakness enables, and how weaknesses combine.

04

Prioritise

Sequence improvement by risk reduction against effort and cost.

05

Improve

Support the change, then evidence that it reduced risk.

Sectors

Sectors we work in

Our work is particularly relevant to organisations where people, facilities, information or operations require effective protective security. The sectors below are representative rather than exhaustive.

Sector 01

Energy & utilities

Generation, network and water operators where physical access carries direct operational and regulatory consequence.

Sector 02

Telecommunications

Exchanges, transmission sites and distributed estates, many of them remote and unstaffed.

Sector 03

Data centres & secure facilities

Colocation and enterprise facilities where physical security underpins customer and regulatory commitments.

Sector 04

Government & public sector

Departments, agencies and arm's-length bodies requiring independent evaluation against defined standards.

Sector 05

Financial services

Branch networks, dealing environments and sensitive processing sites.

Sector 06

Manufacturing & life sciences

Production and research sites where disruption, tampering or loss of intellectual property is consequential.

Next step

Establish your protective security position.

An initial conversation is exploratory, confidential and carries no obligation. If we do not believe an engagement is warranted, we will say so.