Services

Protective security consultancy

One principal engagement — the Protective Security Assessment — supported by four specialist capabilities, drawn into it or commissioned on their own.

The Protective Security Assessment is the principal engagement. The capabilities that follow may form part of it, or be commissioned on their own where an organisation already knows the question it needs answered. Our established specialist depth is in physical intrusion testing and adversary simulation, and that perspective informs how every assessment is conducted. All work is delivered under the BlackTrace Protective Security Assessment Framework.

Principal service

Protective Security Assessment

Physical, personnel and procedural security assessed as one arrangement

An independent assessment designed to establish where protection is weaker than assumed, what that permits, and which improvements reduce risk most for the effort involved.

We examine the perimeter, built environment, access control, detection and response, alongside the procedures and people that make those measures effective. Findings are set against credible threat and recognised good practice, so recommendations reflect real risk rather than a generic control set. An assessment can cover a single site, an estate, or a representative sample.

Depending on the question and the agreed scope, an assessment may draw on:

  • Site and physical security assessment
  • Document, policy and control review
  • Stakeholder interviews and structured observation
  • Physical intrusion testing
  • Adversary simulation
  • Personnel security review
  • Security assurance and maturity assessment

No engagement uses every capability. What is included is agreed in writing before work begins, and proportionate to the risk in question.

Specialist capabilities

Commissioned within an assessment, or on their own

Adversarial capability is where our specialist depth sits. It is applied where it produces evidence that assessment alone cannot, and only where the agreed scope provides for it.

Adversarial capability

Physical Intrusion Testing

Establishing how physical access could realistically be achieved, and what it enables

Controlled, fully authorised testing of whether perimeter measures, access control and on-site security prevent unauthorised entry under realistic conditions. It identifies credible access routes and establishes what physical presence permits once achieved, so impact can be assessed rather than assumed.

All activity runs under written rules of engagement, with defined constraints, stop conditions and named contacts agreed in advance.

This service establishes:

  • How access could realistically be achieved by a capable adversary
  • Where controls degrade under routine operating pressure
  • What physical presence permits in practice
  • Which weaknesses represent genuine rather than theoretical risk
Adversarial capability

Adversary Simulation

Demonstrating how individual weaknesses combine into organisational consequence

An extended, scenario-based exercise reflecting how a capable and patient adversary would plan, adapt and progress against a defined objective. It combines open-source research, observation, physical access and human interaction to identify chained routes that isolated testing does not reveal. Scenarios are calibrated to a defined threat actor profile, so results are meaningful against the organisation's own risk register.

Engagements may incorporate:

  • Hostile reconnaissance
  • Physical intrusion
  • Social engineering and pretexting
  • Human-factor testing
  • Multi-stage scenarios against a defined objective

Social engineering establishes how identity verification, challenge procedures and staff response perform under realistic conditions. Findings address process, training and environment; they are never used to attribute fault to named individuals.

Cyber validation

Where an organisation explicitly authorises it, a simulation may evidence the technical exposure that physical compromise creates — demonstrating the relationship between physical and information risk. This is validation of consequence within a physical engagement. We do not deliver standalone penetration testing or cyber security advisory work.

This service establishes:

  • Credible end-to-end routes from an external position to a defined objective
  • How weaknesses in separate domains compound
  • The effectiveness of detection, escalation and response in real conditions
  • Impact in operational terms, rather than access in isolation
Assessment and assurance

Personnel Security Reviews

Assessment of the controls governing who holds access, and on what basis

An assessment of the arrangements determining who is admitted to an organisation's people, sites and information, and how that access is maintained, changed and withdrawn. Conducted against recognised personnel security guidance, covering both how the arrangements are designed and how they are applied.

Arrangements assessed include:

  • Visitor management and host responsibilities
  • Contractor, supplier and temporary staff access
  • Screening and vetting arrangements, including aftercare
  • Insider risk identification, reporting and escalation
  • Joiners, movers and leavers processes
  • Privileged and elevated access, including key and pass control
  • Security culture, awareness and reporting behaviour
Scope of this capability

We assess personnel security controls. We do not operate a vetting service, conduct screening on an organisation's behalf, or act as its personnel security function. Where a finding calls for capability we do not provide, we say so and describe what is required.

Assessment and assurance

Security Assurance

Independent review of security governance, management and maturity

Independent assurance over how security is governed, managed and evidenced, giving boards, audit committees and regulators a defensible view of the organisation's position. Work is conducted against recognised standards and sector guidance, and can be aligned to sector-specific security obligations where they apply.

Typical scope includes:

  • Security governance, roles, accountabilities and reporting lines
  • Security policies, standards and supporting procedures
  • Security management arrangements and operational oversight
  • Maturity assessment against recognised frameworks and good practice
  • Independent assurance to support audit, regulatory or board reporting
  • Review of third-party and supplier security arrangements

Safety and governance

Any activity beyond observation and document review runs under written rules of engagement covering objectives, constraints, excluded areas, stop conditions, named contacts and escalation routes, authorised by an accountable representative before anything begins.

Governance across the framework

Engagement principles

The same basis applies regardless of capability or scale.

  • Objective-led and proportionate to the assessed risk
  • Discreet delivery with minimal operational disruption
  • Recommendations that are implementable, not aspirational
  • Reporting written for the audience that must act on it

Scope, cost and timescales

Engagements are quoted at a fixed cost against a written scope agreed before work begins, driven by the number of sites, the depth of assessment and whether adversarial testing is included. Reporting timescales, deliverables and reporting milestones are agreed at the outset and set out in that scope. Where scope changes mid-engagement, the cost implication is agreed in writing first.

What is delivered

Deliverables are agreed to suit the engagement. For a full Protective Security Assessment, these typically include an executive summary, detailed findings with evidence and risk ratings, an evidence pack, prioritised recommendations and a leadership debrief where required.

Next step

Discuss which service fits the question you need answered.

If a different provider would serve you better, we will say so and point you in a sensible direction.