The Protective Security Assessment is the principal engagement. The capabilities that
follow may form part of it, or be commissioned on their own where an organisation
already knows the question it needs answered. Our established specialist depth is in
physical intrusion testing and adversary simulation, and that perspective informs how
every assessment is conducted. All work is delivered under the
BlackTrace Protective Security
Assessment Framework.
Principal service
Protective Security Assessment
Physical, personnel and procedural security assessed as one arrangement
An independent assessment designed to establish where protection is weaker than
assumed, what that permits, and which improvements reduce risk most for the effort
involved.
We examine the perimeter, built environment, access control, detection and response,
alongside the procedures and people that make those measures effective. Findings are
set against credible threat and recognised good practice, so recommendations reflect
real risk rather than a generic control set. An assessment can cover a single site, an
estate, or a representative sample.
Depending on the question and the agreed scope, an assessment may draw on:
- Site and physical security assessment
- Document, policy and control review
- Stakeholder interviews and structured observation
- Physical intrusion testing
- Adversary simulation
- Personnel security review
- Security assurance and maturity assessment
No engagement uses every capability. What is included is agreed in writing before work
begins, and proportionate to the risk in question.
Specialist capabilities
Commissioned within an assessment, or on their own
Adversarial capability is where our specialist depth sits. It is applied where it
produces evidence that assessment alone cannot, and only where the agreed scope
provides for it.
Adversarial capability
Physical Intrusion Testing
Establishing how physical access could realistically be achieved, and what it enables
Controlled, fully authorised testing of whether perimeter measures, access control and
on-site security prevent unauthorised entry under realistic conditions. It identifies
credible access routes and establishes what physical presence permits once achieved,
so impact can be assessed rather than assumed.
All activity runs under written rules of engagement, with defined constraints, stop
conditions and named contacts agreed in advance.
This service establishes:
- How access could realistically be achieved by a capable adversary
- Where controls degrade under routine operating pressure
- What physical presence permits in practice
- Which weaknesses represent genuine rather than theoretical risk
Adversarial capability
Adversary Simulation
Demonstrating how individual weaknesses combine into organisational consequence
An extended, scenario-based exercise reflecting how a capable and patient adversary
would plan, adapt and progress against a defined objective. It combines open-source
research, observation, physical access and human interaction to identify chained
routes that isolated testing does not reveal. Scenarios are calibrated to a defined
threat actor profile, so results are meaningful against the organisation's own risk
register.
Engagements may incorporate:
- Hostile reconnaissance
- Physical intrusion
- Social engineering and pretexting
- Human-factor testing
- Multi-stage scenarios against a defined objective
Social engineering establishes how identity verification, challenge procedures and
staff response perform under realistic conditions. Findings address process, training
and environment; they are never used to attribute fault to named individuals.
Cyber validation
Where an organisation explicitly authorises it, a simulation may evidence the
technical exposure that physical compromise creates — demonstrating the
relationship between physical and information risk. This is validation of
consequence within a physical engagement. We do not deliver standalone penetration
testing or cyber security advisory work.
This service establishes:
- Credible end-to-end routes from an external position to a defined objective
- How weaknesses in separate domains compound
- The effectiveness of detection, escalation and response in real conditions
- Impact in operational terms, rather than access in isolation
Assessment and assurance
Personnel Security Reviews
Assessment of the controls governing who holds access, and on what basis
An assessment of the arrangements determining who is admitted to an organisation's
people, sites and information, and how that access is maintained, changed and
withdrawn. Conducted against recognised personnel security guidance, covering both how
the arrangements are designed and how they are applied.
Arrangements assessed include:
- Visitor management and host responsibilities
- Contractor, supplier and temporary staff access
- Screening and vetting arrangements, including aftercare
- Insider risk identification, reporting and escalation
- Joiners, movers and leavers processes
- Privileged and elevated access, including key and pass control
- Security culture, awareness and reporting behaviour
Scope of this capability
We assess personnel security controls. We do not operate a vetting service, conduct
screening on an organisation's behalf, or act as its personnel security function.
Where a finding calls for capability we do not provide, we say so and describe what
is required.
Assessment and assurance
Security Assurance
Independent review of security governance, management and maturity
Independent assurance over how security is governed, managed and evidenced, giving
boards, audit committees and regulators a defensible view of the organisation's
position. Work is conducted against recognised standards and sector guidance, and can
be aligned to sector-specific security obligations where they apply.
Typical scope includes:
- Security governance, roles, accountabilities and reporting lines
- Security policies, standards and supporting procedures
- Security management arrangements and operational oversight
- Maturity assessment against recognised frameworks and good practice
- Independent assurance to support audit, regulatory or board reporting
- Review of third-party and supplier security arrangements