
Manufacturing security review and enterprise security risk management audit

A multinational manufacturing organization commissioned an independent security review to evaluate governance, physical security, emergency measures, and Enterprise Security Risk Management at a major production facility.
The Challenge
The organization sought an independent assessment of security at one of its manufacturing facilities to determine whether existing governance, physical security measures, emergency preparedness, and risk management practices remained appropriate for its operating environment. While the site already maintained a generally strong security posture, leadership wanted an objective review that could validate existing practices and identify opportunities for improvement.
The engagement was initiated to complete a physical security audit and Enterprise Security Risk Management review that examined current threats, protection measures, detection capabilities, intervention processes, and site preparedness. The objective was to identify vulnerabilities and provide practical recommendations that aligned with the organization’s broader risk management objectives.
The work required evaluating governance, operational practices, emergency measures, and physical security as an integrated program rather than separate disciplines. Recommendations also had to reflect the realities of an active industrial facility, including production continuity, employee and contractor movement, shipping and receiving operations, sensitive areas, and business continuity considerations. Confidentiality remained essential because the assessment documented vulnerabilities that could not be publicly disclosed.
Our Approach
The engagement began with a review of the organization’s security governance structure, including decision-making processes, accountability, existing procedures, and the relationship between security activities and broader organizational objectives. Particular attention was given to the role of Health and Safety in supporting physical security and risk management.
A detailed field assessment followed, examining perimeter security, access control, lighting, locking systems, emergency exits, video surveillance, sensitive areas, and the site’s ability to deter, detect, delay, and respond to security events. Emergency measures, business continuity considerations, and operational procedures were also reviewed to understand how security supported day-to-day manufacturing activities.
The Enterprise Security Risk Management review involved collaboration with site leadership to evaluate assets, threats, vulnerabilities, preparedness, governance, organizational practices, learning and development, and performance management. Findings from the field assessment and ESRM review were analyzed together to identify practical opportunities for strengthening governance and physical security.
The engagement applied Enterprise Security Risk Management principles, physical security audit methodology, security governance review, threat and risk assessment principles, Deter, Detect, Delay thinking, emergency measures review, business continuity considerations, and professional security risk management judgement. The work involved Health and Safety leadership, site management, operations personnel, corporate partners, and personnel responsible for physical security, emergency measures, and risk management.
Final deliverables
The Outcome
The engagement confirmed that the site’s physical security measures and governance structure were generally effective while identifying opportunities to strengthen access control, reduce unauthorized entry risks, and enhance emergency measures. The review provided leadership with an objective assessment that balanced recognition of existing strengths with practical recommendations for continued improvement.
The completed assessment documented site assets, threats, vulnerabilities, and Enterprise Security Risk Management findings, including a low-risk ESRM result. Eleven prioritized recommendations established a practical roadmap for improving governance and physical security without disrupting manufacturing operations.
Without this independent review, the organization may have continued relying on generally effective controls without a fully documented understanding of remaining opportunities to strengthen governance, emergency preparedness, and access control practices.
Key insight
Get the strategy needed to reduce risk with confidence
Get the strategy needed to reduce risk with confidence
Start with a confidential discussion about your right next step.
Related Case Studies

Expert security opinion in public attraction assault litigation

National loss prevention program development for a distribution and logistics organization

