Physical Security

19 - Physical Security

Physical
Security

Practical physical security assessments for Australian organisations. Physical security protects people, sites, systems and sensitive information from unauthorised access, disruption and misuse. RTCS reviews access controls, visitor processes, CCTV coverage, secure areas, server rooms, building technology and procedures - and provides clear steps to reduce risk.

  • Site, office, facility and campus security reviews
  • Data centre, server room and communications room assessments
  • Physical access control and pass management review
  • Visitor and contractor management review
  • CCTV coverage, placement and operational review
  • Tailgating risk assessments where authorised
  • Physical penetration testing where authorised
  • Building technology and BMS risk review
  • Policy, procedure and remediation planning
Discuss This Service
Site Types
Offices - campuses - warehouses - data centres - communications rooms - critical sites
Review Areas
Access control - visitor mgmt - CCTV - secure areas - server rooms - building tech - procedures
Engagement Types
Site review - access & CCTV review - server room assessment - authorised physical test
Outputs
Risk-rated findings - evidence - remediation roadmap - executive summary
ISO 27001 PSPF SOCI Act Essential Eight
Site
Office & Facility Reviews
CCTV
Coverage & Retention
Tail
Tailgating & Access Tests
AU
Onshore Delivery
01 / Context

Cyber controls don't help if someone can walk in.

Cyber security controls can be weakened if physical access is not managed properly. Unauthorised access to offices, server rooms, network cabinets, security systems or restricted areas can expose systems, data and business operations. RTCS assesses physical security across offices, facilities, data rooms, campuses, warehouses and critical sites - and provides practical, prioritised remediation.

02 / Common Gaps

The physical issues that keep showing up.

G1

Weak visitor sign-in processes

G2

Poor access card controls

G3

Staff allowing tailgating

G4

Unsecured server rooms or network cabinets

G5

Limited CCTV coverage

G6

Shared or unmanaged access passes

G7

Poor separation between public and restricted areas

G8

Inconsistent after-hours access controls

G9

Building systems connected to business networks

G10

Outdated or unfollowed physical security procedures

03 / Access Control

Only authorised people in restricted areas.

RTCS reviews how access is approved, issued, monitored and removed across staff, contractors, visitors, after-hours access and sensitive areas. The goal is consistent enforcement - not access policies that only exist on paper. For broader joiner/mover/leaver and privileged access work, pair with Identity & Access Management.

Access card processes Door & lock controls Privileged area access Staff & contractor access Joiner, mover, leaver process Access review practices Tailgating controls Alarm & escalation
04 / CCTV & Surveillance

CCTV should support prevention, detection and investigation.

RTCS reviews CCTV coverage, camera placement, retention, monitoring, access control and operational use - so footage is actually useful when something happens.

Coverage of key entry points Blind spot review Camera placement Recording & retention Access to footage Monitoring processes Signage & privacy Integration with IR
05 / Server & Data Rooms

The rooms holding your critical systems.

Server rooms, communications rooms and network cabinets often contain critical systems. RTCS reviews physical controls protecting these areas - access restrictions, environmental controls, monitoring, visitor access and supporting procedures.

Room access controls Network cabinet security Visitor & contractor access CCTV coverage Environmental monitoring Backup media protection Key & pass management Periodic access reviews
06 / Visitors & Contractors

Visitor and contractor management.

Visitors and contractors can create security risk if access is not controlled. RTCS reviews visitor and contractor processes to confirm they are practical, consistent and appropriate for the site.

Sign-in & identity checks Escort requirements Temporary access cards Contractor access approvals Visitor logs After-hours access Restricted area controls Pass return on exit
07 / Building Technology

When building systems meet the corporate network.

Modern facilities rely on connected systems - access control, CCTV, alarms, lifts, HVAC and building management. RTCS reviews the security risks created when physical security and building systems connect to IT networks. For industrial control and critical infrastructure environments, see OT & ICS Security.

Building Management Systems Physical access control systems CCTV networks Alarm systems Visitor management platforms Smart building devices Vendor remote access Network separation Ownership & support

Scope to Improve

A practical, staged engagement that reviews the controls, validates the real-world weaknesses (where authorised), and prioritises remediation that works on-site.

01
Scope

Confirm the sites, areas, systems and testing activities included in the review.

02
Review

Assess physical controls, procedures, access processes, technology and key risk areas.

03
Validate

Where authorised, test practical risks such as tailgating, visitor controls or restricted area access.

04
Report

Provide clear findings, evidence, business impact and remediation steps.

05
Improve

Prioritise actions that reduce risk without making operations harder than necessary.

08 / Who It's For & What You Receive

Who This Service Is For

  • Need to review site security
  • Operate offices, campuses, warehouses or facilities
  • Manage server rooms or communications rooms
  • Need to improve visitor and contractor controls
  • Want to assess CCTV and access control effectiveness
  • Need to review physical security before an audit
  • Need authorised physical penetration testing
  • Want practical recommendations without complexity

Typical Deliverables

  • Physical security assessment report
  • Site security findings
  • Access control observations
  • CCTV review findings
  • Visitor management review
  • Server room or data room review
  • Building technology risk observations
  • Risk-rated recommendations
  • Remediation roadmap
  • Executive summary
09 / Related Services

Where physical security connects to the rest of the program.

Identity & Access Management →

Joiner / mover / leaver, privileged access and access reviews that align with physical pass controls.

OT & ICS Security →

Industrial control, SCADA and critical infrastructure environments beyond standard building tech.

Security Awareness Training →

Tailgating, visitor handling and clean-desk training so staff actually follow the controls.

Penetration Testing →

Pair authorised physical assessments with red team or network testing for a fuller picture.

Red Team & Adversary Simulation →

End-to-end adversary emulation that may include physical entry, social engineering and digital access.

Governance, Risk & Compliance →

Physical controls mapped to PSPF, ISO 27001 and SOCI Act expectations.

Crisis Management →

Site-level incident response, evacuation interaction and crisis comms when a physical event occurs.

Incident Response Readiness →

How physical events feed into cyber incident response, evidence handling and investigation.

Physical security should be clear, practical and appropriate to the site. Talk to us about a physical security assessment, access control review, CCTV review, server room assessment or authorised physical security test.

Common Questions

What is a physical security assessment?

A physical security assessment reviews the controls used to protect people, facilities, systems and sensitive areas from unauthorised access or disruption.

Do you test tailgating?

Yes. Tailgating assessments can be included where explicitly authorised and safely scoped.

Do you review CCTV?

Yes. RTCS can review CCTV coverage, camera placement, retention, access to footage and monitoring processes.

Do you assess server rooms?

Yes. RTCS can assess server rooms, data rooms and network cabinets for access control, monitoring and operational risks.

Do you review building systems?

Yes. RTCS can review building technology such as access control, CCTV, alarms, visitor systems and building management systems where they create physical or cyber risk.

See Every Service.

View All Services Get in Touch