ESRM Program · Assets Cluster
Physical Security
Know who can get into your buildings, and what happens when someone does.
$2,500 fixed-fee assessment 3–4 weeks Credited toward the vCSO program
Measured against ANSI/ASIS PAP.1-2012. Led by Don Oxman, CPP, CISSP, CISM. Licensed by Texas DPS. In business since 2013.
Most security systems were bought one piece at a time.
Physical security is one of thirteen domains in our Enterprise Security Risk Management (ESRM) program, and part of the Assets cluster with Cybersecurity, Information Security, and Brand Protection. It covers your buildings, lots, and yards: a distribution center near Alliance, a medical office in Southlake, a fabrication shop in Arlington with copper on the lot.
In most companies, physical security belongs to whoever manages the building. The office manager handles badges, the alarm company placed the cameras, and a facilities lead keeps the keys. Each piece was bought to fix a problem at the time, and nobody has looked at how they work together. Former employees still know door codes, and the alarm company still calls someone who left last year. We look at each site the way an intruder would, then fix the gaps in order of risk.
What can go wrong at your facilities
Unauthorized entry
Tailgating at the front door, a propped-open loading dock, or a door code that hasn’t changed in years lets in people who have no business being there.
Theft & burglary
Tools, inventory, vehicles, and copper draw after-hours theft, especially at sites with dark lots and fence lines nobody has walked in months.
Gaps in coverage
Cameras that are offline, aimed at the wrong spot, or never reviewed give a false sense of protection until you need footage and find nothing usable.
Insider access
Keys and badges that were never collected, shared alarm codes, and contractors with standing access leave doors open after people have moved on.
Emergencies
Fires, severe storms, and power outages test evacuation routes, alarm call lists, and backup power. Many sites have never run a full drill.
Liability & compliance
Poor lighting or a known problem left unfixed can support a premises liability claim. Some industries and customers also require specific physical controls.
Five questions for leadership
- Could you produce a current list of everyone who holds a key, badge, or alarm code for each site?
- When someone leaves the company, is their access shut off the same day, door codes included?
- Has anyone confirmed in the last month that every camera is recording something useful?
- Do you know who the alarm company calls after hours, and do those people still work for you?
- Has anyone walked your entrances and parking areas after dark to check lighting and blind spots?
If you answered “no” or “not sure” to any of these, that is where we would start. Most of these gaps cost little to fix before an incident and a great deal to fix after one.
How an Engagement Works
Every ESRM domain starts with the same fixed-fee assessment. If you decide to continue, we credit the fee toward the program, and physical security becomes part of your vCSO engagement alongside whichever other domains you need.
Physical Security Assessment
- Interviews with facilities, the office or plant manager, HR, IT, and whoever manages your alarm and guard contracts.
- Structured review: a 15-question risk profile, a 25-point practices checklist, and a maturity score from 1 (Initial) to 5 (Optimized).
- Site walk-through by day and after dark: perimeter, lighting, doors, keys, cameras, alarms, and visitor handling.
- Gap analysis against ANSI/ASIS PAP.1-2012, the physical asset protection standard, with CPTED applied to site layout.
- Written report and prioritized roadmap, walked through with your leadership team. The report is yours whether or not you continue.
The fee is credited in full toward the program if you start within 90 days.
The vCSO / ESRM Program
- Assess (Q1): we start from your assessment findings and confirm which sites come first.
- Build (Q2): key and access policy, visitor procedures, camera and alarm standards, after-hours procedures, and an emergency plan.
- Vendors: we write the requirements for integrators, alarm monitoring, and guard services, and confirm guard firms hold Texas DPS licenses.
- Drills for evacuation, shelter in place, and after-hours alarm response, so people know the plan before they need it.
- Operate (Q3+): we stay on as the named owner, with quarterly access reviews, site checks, and reporting to leadership or your board.
Month to month. Cancel with 30 days’ notice. About the vCSO program →
Site Surveys & Design Review
- New-site survey before you sign a lease or buy a building.
- Design review of construction or renovation plans.
- CPTED review of lighting, landscaping, parking, and entrances.
- Post-incident review after a break-in, so it doesn’t happen twice.
Why Total 360
Physical and cyber, one advisor
Door controllers, cameras, and alarm panels now sit on your network. We look at both sides, so a camera system doesn’t become the way into your files.
Independent recommendations
We don’t sell or install cameras or access control systems, and we take no commissions. We specify what fits the site and the risk.
Experienced leadership
Led by Don Oxman: M.S. in Security Management, CPP, CISSP, CISM. U.S. Army and AT&T background. In business since 2013 and licensed by Texas DPS.
Common questions
What does a physical security assessment cost?
$2,500, as a fixed fee. It usually takes three to four weeks from kickoff to the readout. If you start the vCSO program within 90 days, the full fee is credited toward it.
What do we get at the end of the assessment?
A written report with your maturity score from 1 (Initial) to 5 (Optimized), the gaps we found against ANSI/ASIS PAP.1-2012, the physical asset protection standard, with CPTED applied to site layout, and a prioritized roadmap. We walk your leadership team through it, and the report is yours whether or not you continue.
Do we have to sign up for the full program?
No. The assessment stands on its own. If you continue, physical security runs inside the vCSO program at $2,500 to $7,500 a month depending on scope. It is month to month, and you can cancel with 30 days’ notice.
Can we buy site surveys & design review without the program?
Yes. They are available to any client. Billed per site, quoted in advance.
Will you replace the people and providers we already use?
No. We work alongside your IT provider, attorney, insurer, and other advisors. We set the standard, help them meet it, and check that the work gets done.
Start with a 30-minute Risk Discussion
No deck and no sales pitch. Tell us about your sites and what has happened at them. We’ll give you an honest read on the gaps and send a scoped proposal within five business days.
Schedule a Risk Discussion Or call 817-677-0515 · info@total360security.com