
Multi-country manufacturing site threat, vulnerability and risk assessment

A multinational manufacturer required a coordinated security assessment across four facilities to evaluate governance, physical security, emergency preparedness, and enterprise security risk management.
The Challenge
The organization sought an independent review of its security framework across four manufacturing facilities in three countries. Leadership wanted a clearer understanding of how effectively security governance, physical protection, emergency preparedness, and enterprise security risk management supported the protection of people, operations, critical assets, and business continuity.
The engagement was initiated to complete Threat, Vulnerability and Risk Assessments, security governance reviews, physical security audits, emergency measures reviews, and Enterprise Security Risk Management assessments across selected sites. The objective was to identify vulnerabilities, validate existing security practices, and establish priorities for future improvements.
The project required balancing enterprise-wide consistency with the operational realities of individual facilities. Each site operated within a different regulatory environment, physical layout, and threat landscape. The work also relied on collaboration with local management while protecting confidential information that could expose vulnerabilities or operational details if publicly disclosed.
Our Approach
The engagement began with a review of the organization’s security governance framework. This included evaluating security strategy, organizational structure, responsibilities, procedures, skills, training needs, performance measures, incident management considerations, and the alignment of security activities with business objectives.
Comprehensive physical security audits were then completed at each site. Assessments examined perimeter protection, access control, surveillance, lighting, emergency exits, sensitive areas, guarding, patrols, response capability, and opportunities to strengthen existing security measures. Emergency measures, labour disruption planning, business continuity considerations, information management practices, and site resilience were also reviewed.
Enterprise Security Risk Management workshops engaged site managers and operational stakeholders in identifying critical assets, evaluating threats, assessing vulnerabilities, and reviewing preparedness across governance, business support, learning and development, and performance management. Findings from each site were analyzed to identify enterprise-wide themes while preserving site-specific recommendations.
The engagement applied Threat, Vulnerability and Risk Assessment methodology, Enterprise Security Risk Management principles, physical security audit methodology, security governance review, Deter, Detect, Delay strategy, emergency measures review, business continuity principles, information security awareness considerations, and risk-based prioritization. The work involved site managers, operations leaders, Health, Safety and Environmental personnel, IT teams, production managers, maintenance managers, human resources representatives, corporate leadership, and other operational stakeholders.
Final deliverables
The Outcome
The engagement provided leadership with a consistent view of security across four manufacturing facilities while recognizing the unique operating environment of each location. The assessment confirmed that physical security measures and governance structures were generally effective while identifying practical opportunities to strengthen access control, surveillance, perimeter protection, emergency measures, and operational procedures.
The completed review documented asset criticality, evaluated site preparedness, identified enterprise-level threats, and established priorities for future security investment. Forty-one recommendations gave the organization a structured basis for improving governance and physical security while supporting long-term operational resilience.
Without this engagement, the organization may have continued operating with site-specific vulnerabilities, inconsistent preparedness, untested assumptions about asset criticality, and fewer tools for prioritizing security improvements across the enterprise.
Get the strategy needed to reduce risk with confidence
Get the strategy needed to reduce risk with confidence
Start with a confidential discussion about your right next step.
Related Case Studies

Expert security opinion in public attraction assault litigation

National loss prevention program development for a distribution and logistics organization

