People and roles
Who is responsible, how decisions are made, and where accountability may be unclear.



Cameras, access control, alarms, guards, policies, or informal procedures may be in place, but that does not mean they are aligned with the actual risk. An assessment helps determine whether current measures are appropriate, effective, and defensible.
Security controls often exist in separate pieces. Technology, procedures, staff roles, documentation, maintenance, and response may not be connected. This can create gaps between what appears to be protected and how security would actually perform under pressure.
After an incident, audit, claim, or leadership concern, decisions may need to be explained. Weak documentation can make it harder to show what was known, what was considered, and why specific actions were taken or delayed.
Risk & Security Management is an independent assessment and advisory service that helps clients understand how well their current security measures align with their actual exposure. The work looks beyond visible controls to assess how security functions across people, processes, technology, governance, documentation, and response.
Who is responsible, how decisions are made, and where accountability may be unclear.
How procedures, records, and decision rationale support the way security is expected to work.
How people enter, move through, and use the site, including visitor flow and restricted areas.
How physical controls support access, detection, response, and overall site protection.
What past events reveal about exposure, readiness, communication, and follow-through.
How security issues are tracked, escalated, documented, and reviewed over time.
This service does not include guard services, alarm monitoring, equipment sales, product installation, engineering services, architectural drawings, or legal advice. Recommendations may include these areas, but MWG remains independent from vendors and implementation services.
At the end of the engagement, clients receive practical documentation that clarifies the current security posture, identifies exposure, and supports better decisions. The list below outlines common deliverables that may be provided, depending on the scope and needs of the engagement.
Clients gain a clearer understanding of their actual security posture, where they may be exposed, and which actions should be prioritized first. This helps leadership avoid reactive spending, reduce reliance on vendor-led recommendations, strengthen documentation, and make more informed decisions about people, assets, operations, and reputation.
Common triggers include a recent incident, recurring losses, public safety concerns, unauthorized access, workplace violence risk, a new facility, renovation, leadership change, insurance pressure, board concern, regulatory expectations, vendor uncertainty, or the need to validate an existing security program.
This service is suited for organizations with people, property, operations, assets, or reputation to protect. Common clients include municipalities, critical infrastructure operators, utilities, property managers, education, healthcare-related environments, manufacturing, logistics, corporate offices, public-facing facilities, and high-value commercial or private sites.
Yes. For high-net-worth individuals, executives, prominent families, and public-facing leaders, the assessment may focus on residential security, privacy, personal safety, household routines, travel patterns, public exposure, events, and coordination with family offices, estate managers, legal counsel, or protective providers.
The work is independent and risk-based. The assessment is not designed to sell a product, justify a pre-selected solution, or apply a generic checklist. It considers how security would perform under real-world conditions and how decisions may be examined after an incident.
Depending on the scope, the assessment may draw from recognized risk management, physical security, CPTED, government, and sector-specific guidance. This can include ISO 31000, ASIS guidance, RCMP-style threat/risk assessment concepts, Government of Canada Physical Security Guides, Public Safety Canada resources, People-Process-Technology analysis, and Defence in Depth thinking.
This service looks at security as a system, not a list of visible controls. The assessment considers people, process, technology, governance, accountability, documentation, physical conditions, and response. The goal is to understand how security would perform in real-world conditions.
A smaller single-site assessment may take 2 to 4 weeks from kickoff to final report. A more complex site, multi-site organization, critical infrastructure environment, or combined governance and physical security review may take 4 to 8 weeks. Additional phases may extend the timeline.




Start with a confidential discussion about your right next step.