International Security Journal hears exclusively from Stephen Beels, Creator of IPSRM and physical security professional.
Early in my career as a security consultant, I came to realise that the physical security assessment discipline was missing something.
It took time to see that inconsistency between assessments was not a knowledge problem.
Better-trained practitioners would not, on their own, produce more reliable or comparable outputs.
I knew many able, professional and talented practitioners, particularly during my time as a Board Director of the UK’s Association of Security Consultants.
Looking back over more than thirty years of practice, including counter terrorism and serious crime work with the Metropolitan Police Service and eighteen years of independent consultancy, what I kept encountering was an absence of methodological architecture around that knowledge: a structure capable of turning individual expertise into something consistent, comparable and defensible.
The challenge of consistency
That pattern repeated itself across hundreds of assessments over three decades.
Scope was frequently shaped by what was visible on the day rather than what mattered most. Risk was calibrated to instinct rather than a transparent, reproducible framework.
Reports were written for security managers rather than for the boards and audit committees who ultimately had to act on them. And two assessors, given the same site and the same evidence, could reasonably arrive at different conclusions, not because either was wrong, but because neither was working from a shared basis for what “high risk” actually meant in that context.
That last point is easy to underestimate until you see its practical consequence.
An organisation managing assessments across a multi-site estate, using different practitioners over several years, often ends up with reports that use different terminology, different rating criteria and different structures entirely.
A finding rated critical by one assessor might be rated moderate by another, on materially similar evidence.
Portfolio-level comparison, in that situation, becomes closer to interpretation than governance.
And if an incident occurs, the question of whether the prior assessment was methodologically sound stops being academic.
I have seen this play out concretely more than once.
Two practitioners, each competent and each acting in good faith, assess the same category of exposure, such as a perimeter with partial CCTV coverage and an inconsistently enforced vehicle checkpoint, and arrive at different tiers of concern.
One treats the checkpoint failure as the dominant factor and rates the finding severe.
The other treats the same evidence as two moderate issues that happen to sit side by side, and rates it accordingly lower. Both readings are defensible in isolation.
Read together, without a shared calibration basis, they cannot be reconciled within a consistent framework and a board relying on either report has no way of knowing which one to trust.
Other risk disciplines have already addressed this. Financial audit operates within recognised standards such as ISA 315 and ISA 330, which structure how risk is identified, assessed and reported.
Clinical risk assessment frequently works within frameworks such as those published by NICE.
Cybersecurity has ISO 27001 and NIST SP 800-30 behind it.
None of these frameworks removes professional judgement from the discipline they govern.
What they provide is the architecture within which that judgement can be applied consistently, audited transparently and defended afterwards.
Why physical security needs stronger framework
This is not leaning on history. In July this year, the UK government launched its Cyber Resilience Pledge, formally asking boards to treat cyber risk as a direct governance responsibility rather than something delegated downward, with legislation following behind it through Parliament.
Cybersecurity has just been told, plainly, by government, that board-level accountability is no longer optional.
Physical security is still waiting for its equivalent moment.
I must emphasise that I am not criticising practitioner capability.
It is an observation about the foundations that capability sits on.
Nor is it answered by pointing to the various British Standards governing individual security products and components; those tell you how well a door or barrier performs, not how an assessment of the site around it should be scoped, calibrated or reported.
The terminology alone illustrates the problem: audit, review, survey and assessment are used almost interchangeably across the profession, despite implying materially different levels of rigour.
A client commissioning a “security review” might receive a short observational walkthrough, or a structured multi-day engagement involving interviews, documentation review and calibrated risk analysis.
The title tells them little about which they are getting.
Scope suffers from a related weakness.
Visible, physical deficiencies, such as an ageing perimeter fence or a poorly lit goods yard, naturally draw attention because they can be observed directly during a site visit.
Less visible exposures, such as weak contractor governance or informal supervisory workarounds, often receive proportionally less scrutiny, even where they represent the more credible route for an adversary.
The gap here is rarely one of practitioner competence.
It is a lack of governing structure disciplined enough to direct attention according to actual risk rather than observational convenience.
Building a methodology around expertise
I do not think the answer is to strip judgement out of the profession in favour of a checklist.
A methodology that removes professional interpretation produces worse assessments, not better ones; it simply substitutes box-ticking for understanding and boxes get ticked without being understood.
What is missing is not a replacement for expertise but a structure around it: a consistent approach to gathering evidence, so that significant exposures are not overlooked because they happened not to be visible on the day; a calibration model that gives two practitioners common ground for scoring severity; and a reporting structure built to answer the questions a governance audience actually needs answered, rather than simply describing what was found.
Boards are increasingly used to receiving structured, evidenced risk information from every other function that reports to them.
When physical security arrives instead as a narrative account of findings, however well-informed, it reads differently from the risk data they are accustomed to acting on, and that difference has consequences for how much weight the assessment is given.
I recognise the reluctance some practitioners feel towards anything that sounds like standardisation.
It is a reasonable concern, and any methodology worth adopting should be tested against it directly: does it make expert judgement more visible and more defensible, or does it simply constrain it? In my experience, structured properly, it does the former.
It gives an experienced practitioner a way of showing their reasoning, not replacing it, which matters considerably more now than it did when I started in this profession, given how much further governance scrutiny has extended into physical security in recent years.
The expertise within this profession has never been the shortfall. What has been missing is the architecture to carry that expertise reliably from the site to the boardroom.
Building it is, I think, the more pressing task now facing the discipline.
Stephen Beele, Creator of IPSRM
Stephen has worked in physical security, risk and resilience for more than thirty years, beginning in Special Branch of the Metropolitan Police Service, before moving into security leadership, advisory and consultancy roles across critical infrastructure, financial services, higher education and other high-consequence environments.
He has conducted or reviewed more than 600 physical security assessments across the UK, Europe and Africa, served as a Board Director of the Association of Security Consultants, and is a multi-award winner at the Outstanding Security Performance Awards (OSPAs).
His book ‘The Methodology Gap‘ draws directly on that career, examining why the discipline has lacked a governing methodology and providing a workable solution.