Methodology

The BlackTrace Protective Security Assessment Framework

A five-stage consultancy framework applied to every engagement, providing a consistent and auditable route from an organisation's context to evidenced improvement.

Referred to throughout this site as the Framework, or BPSAF.

Five stages

Each stage produces a defined output that the next depends on.

The framework is the same for a single site and for an estate-wide programme. What changes is depth, which is what makes results comparable between sites and across years.

Stage 01

Define

Establish what must be protected, from whom, and to what standard.

OutputAn agreed scope and assessment plan.

Stage 02

Assess

Gather evidence on how security is designed, and on how it is practised.

OutputA documented evidence base.

Stage 03

Analyse

Establish what each weakness enables, and how weaknesses combine.

OutputFindings traceable to evidence.

Stage 04

Prioritise

Sequence improvement by risk reduction against effort and cost.

OutputA prioritised improvement plan.

Stage 05

Improve

Support the change, then evidence that it reduced risk.

OutputEvidenced reduction in risk.

Throughout

Adversarial thinking is a principle applied across all five stages, not a stage of its own. Arrangements are examined from the position of someone attempting to defeat them; testing is one method within Assess, used where it produces evidence that assessment alone cannot.

Applied consistently

One framework, scaled to the engagement

A single-site assessment may complete the framework in weeks; an estate-wide programme may run each stage across months. The sequence does not change.

Governance

Governance is not a stage. It applies from initial scoping through to final reporting, and either party may stop activity at any point.

1
Stage 01

Define

Establish what must be protected, from whom, and to what standard.

Every engagement begins by establishing context rather than by inspecting controls: what the organisation is protecting, which functions depend on it, what obligations apply, and what a realistic adversary would be trying to achieve. Judgements formed before this point are assumptions. Define also fixes the governance of the engagement — scope, constraints, excluded areas, named contacts and stop conditions, recorded in writing before any assessment activity takes place.

  • Scope, objectives and success criteria agreed in writing
  • Sites, critical assets, dependencies and single points of failure identified
  • Threat picture developed with the organisation and from open sources
  • Regulatory, contractual and sector security obligations identified
  • Previous findings, audits and known issues reviewed
  • Rules of engagement, constraints and stop conditions agreed and authorised

Output  An agreed scope and assessment plan that both parties have signed.

2
Stage 02

Assess

Gather evidence on how protective security is designed, and on how it is practised.

Assessment covers physical, personnel and procedural security as one system. We examine governance and documented arrangements, then establish how they function on an ordinary working day — under staffing pressure, during contractor works, out of hours, and where responsibility passes between teams.

Adversarial method belongs to this stage. Where proportionate and authorised in writing, arrangements are tested from the position of a capable adversary; where it is not proportionate, the framework proceeds without it.

  • Governance, policy, standards and procedure review
  • Site survey: perimeter, built environment, access control, detection and response
  • Personnel security: vetting, visitors, contractors, privileged access and culture
  • Interview and structured observation of routine operation
  • Where authorised: physical intrusion testing, hostile reconnaissance and social engineering
  • Where explicitly authorised: validation of the technical exposure that physical compromise creates

Output  A documented evidence base: observations, artefacts, timelines and photography.

3
Stage 03

Analyse

Establish what the evidence means, and separate material risk from theoretical concern.

A list of weaknesses is not an assessment. Analysis establishes what each weakness genuinely enables in operational terms, how weaknesses in separate domains combine into a credible route, and where practice has diverged from design. Findings are set against recognised good practice and regulatory expectation, so the organisation sees not only what is weak but how far it sits from where it should be. Where the evidence does not support a finding, the finding is withdrawn.

  • What each weakness enables, stated in operational terms
  • Chained routes that isolated testing would not reveal
  • Divergence between documented arrangements and daily practice, and its causes
  • Comparison against recognised good practice and regulatory expectation
  • Materiality assessed, so that theoretical concerns are not presented as real exposure
  • Systemic causes identified — findings address controls and process, never individuals

Output  Findings, each traceable to the evidence that supports it.

4
Stage 04

Prioritise

Sequence improvement so that effort and expenditure go where risk reduction is greatest.

Recommendations are only useful if they can be acted on. Each is written as an instruction: what should be done, which function owns it, and what it achieves. Risk is rated against a defined scale published with the report, so ratings can be challenged and compared. Measures costing little are separated from those requiring capital investment, so a security team is not asked to choose between them.

  • Risk rated against a defined, published scale
  • Recommendations sequenced by risk reduction against effort and cost
  • Each recommendation assigned to an accountable function
  • Immediate low-cost measures separated from capital investment
  • Indicative effort and dependencies stated
  • Residual risk recorded where a recommendation is not adopted

Output  A prioritised improvement plan that a security team can take to a board.

5
Stage 05

Improve

Support the change, then evidence that it worked.

The framework closes by supporting improvement rather than concluding at the report: an assessment that is filed and not acted on has reduced no risk. We review proposed designs and procurement specifications before commitment, re-assess findings once closed, and repeat the assessment on a defined cycle so movement in maturity is measured rather than asserted.

  • Remediation planning and advice during implementation
  • Review of proposed designs, specifications and procurement requirements
  • Re-assessment of specific findings once remediation is complete
  • Repeat assessment on a defined cycle to evidence movement in maturity
  • Comparable results across sites and across years
  • Evidence suitable for internal audit, board assurance and regulatory engagement

Output  Evidenced reduction in risk, and a defensible record of the improvement.

Governance throughout

Governance applies across all five stages, not at a single point within them.

  • Written authorisation before any assessment activity begins
  • Named client contacts and agreed escalation routes
  • Proportionate methods, agreed constraints and excluded areas
  • Deconfliction with operational and business-critical activity
  • Defined evidence handling, retention and confidentiality terms
  • Immediate stop conditions available to either party

Why a defined framework matters

A consistent method makes findings comparable, defensible and useful beyond the engagement itself.

  • Results can be compared across sites and across years
  • Findings withstand internal audit and regulatory scrutiny
  • Progress can be measured rather than asserted
  • A second assessor could reach the same conclusion from the same evidence

Outputs

What the framework produces

A full Protective Security Assessment produces a consistent core set of deliverables, scaled to the scope and complexity of the engagement.

Output 01

Executive summary

A decision-grade overview for board and executive audiences: position, material risks and priorities.

Output 02

Detailed findings

Each finding stated with supporting evidence, rationale and an assessed risk rating.

Output 03

Evidence pack

Timeline, observations, photography and artefacts aligned to the agreed objectives.

Output 04

Prioritised recommendations

Measures sequenced by risk reduction, with indicative effort and named ownership.

Output 05

Leadership debrief

A structured walkthrough for stakeholders, with questions taken and next actions agreed.

Next step

Ask how the framework would apply to your estate.

We are happy to talk through scope, sequencing and proportionality before any proposal is prepared.