
What Goes Into a Commercial Security Assessment for a Central Pennsylvania Facility
A commercial security assessment is a structured walkthrough and analysis of your facility that identifies what you need to protect, what threatens it, where your current defenses fall short, and what to fix first. A qualified assessor forms a team, characterizes the site, classifies threats, tests each protective layer from the property line inward, then delivers a written report that ranks every finding by risk and pairs it with a recommended fix. Most single-building assessments take a half day on site and produce a report within one to two weeks.
This guide walks through each stage, shows what gets inspected at the perimeter, entrances, interior, and systems, explains the standards assessors work from, and describes what a usable report should contain.
What Is a Commercial Security Assessment
It is the study that comes before any equipment decision. The assessment tells you where your gaps are. The system is what closes them.
The National Fire Protection Association publishes NFPA 730, the Guide for Premises Security. It is the reference document most professional assessors work from, and it calls this study a security vulnerability assessment, or SVA. NFPA 730 covers the assessment itself, security plan design, interior and exterior protection, security personnel, and measures for specific building types including offices, retail, healthcare, education, lodging, and industrial sites.
NFPA 730 is paired with NFPA 731, the Standard for the Installation of Electronic Premises Security Systems. NFPA 730 defines what should be protected. NFPA 731 defines how the equipment gets installed, tested, and maintained. A complete assessment references both.
NFPA 730 also states that the building owner or the owner’s designated representative is responsible for the SVA. You can hire it out, but the accountability stays with you.
What Are the Seven Steps of a Security Vulnerability Assessment
Chapter 5 of NFPA 730 lays out a seven-step process. A serious assessment follows all seven. A sales walkthrough usually skips to step five.
|
Step |
What Happens | What It Produces |
| 1. Form the team | Pull people from the areas that matter, including operations, facilities, HR, and IT |
A group that knows how the building actually runs |
|
2. Characterize the facility |
Document the site, layout, hours, staffing, traffic flow, and operations | An accurate picture of the building in use |
| 3. Assess threats | Classify critical assets, identify likely targets, analyze consequences of loss, define who the realistic adversaries are |
A ranked threat list specific to your site |
|
4. Analyze vulnerabilities |
Walk through actual and potential attack scenarios and estimate a risk level for each | A scored gap list |
| 5. Define countermeasures | Specify the fixes that address the gaps found in steps two through four |
A recommended scope of work |
|
6. Reassess risk |
Recalculate risk levels assuming the countermeasures are in place, then add more where the number stays too high | Proof the plan actually reduces risk |
| 7. Document and track | Record findings and recommendations, then track which ones get implemented |
A written report and an accountability trail |
NFPA 730 adds that risks found in the assessment should be arranged by frequency and severity. A finding that is likely and damaging outranks one that is rare and minor, even when the rare one is more dramatic.
The guide also addresses who should do the work. Section 5.3 says the assessment provider should supply evidence of qualifications, education, certification, or experience on request, and that personnel conducting the assessment should hold certification from a nationally recognized organization in security or crime prevention. Ask for that before the walkthrough, not after the proposal.
What Does the Assessor Inspect at Your Facility
The walkthrough works from the outside in. NFPA 730 organizes protection into a primary security perimeter covering the whole area in the security plan, with secondary perimeters inside it. Areas get designated as unsecured, open, protected, secured, controlled, or restricted, and each designation carries different expectations.
|
Zone |
What Gets Checked | Common Findings |
| Property line and parking | Fencing integrity, sight lines, signage, vehicle entrances, pedestrian routes, lighting coverage |
Overgrown fence lines, unlit lots, unmarked property boundaries |
|
Building exterior |
Doors, windows, roof hatches, skylights, ventilation openings, loading docks, dumpster placement | Exposed hinge pins, unsecured roof access, propped dock doors |
| Entry points and portals | Lock function, latching, credential control, after-hours entry procedure, visitor routing |
Too many active entrances, doors that fail to latch, no visitor screening |
|
Interior zones |
Server rooms, cash handling areas, records storage, inventory rooms, mechanical and electrical spaces | Restricted areas with no separate control, shared master keys |
| Existing systems | Camera placement and image quality, alarm zones, sensor coverage, panel condition, backup power, network path |
Cameras that record motion but cannot identify a face, dead zones, no cellular backup |
|
People and records |
Badge policy, background screening, key inventory, incident logs, vendor handling, workplace violence plan |
No key inventory, terminated staff still holding credentials |
A few specifics from NFPA 730 that assessors check directly. The number of portals in a security perimeter should be limited to the minimum needed for safe and efficient operation. Exterior hinge pins on perimeter doors should be secured against removal. Key and credential control should include re-keying when a key to a controlled or restricted area goes missing, an annual inventory of keys and credentials, and records showing the number assigned to each key and lock, the lock location, who holds it, the issue date, and the return date.
On cameras, the guide notes that video surveillance should be tested to produce recognition of a subject, and preferably identification. Those are different standards. A camera that proves someone was there is not the same as a camera that proves who it was. Assessors verify this by walking the frame, not by reading a spec sheet. This is a common gap in existing commercial video surveillance installations that were placed for coverage rather than for evidence.
Access control gets similar treatment. NFPA 730 states that access control systems should be designed to control movement through portals as determined by the assessment, meaning the door list comes out of the study rather than out of a catalog. The same logic applies to intrusion detection, which should be designed against the specific vulnerabilities the assessment identified and installed to NFPA 731. Many existing commercial alarm systems protect the front door thoroughly and leave a rear service entrance on no zone at all.
One constraint sits above all of this. Security hardware cannot defeat egress. NFPA 730 references NFPA 101, the Life Safety Code, and every locking decision has to clear fire and life safety requirements first. An assessor who recommends a lock that traps people is not an assessor worth hiring.
How Are Lighting and Landscaping Evaluated
Chapter 8 of NFPA 730 covers Crime Prevention Through Environmental Design, and lighting is the largest part of it.
The guide says protective lighting should be lumen efficient, should create adequate levels without being excessive, and should minimize night sky pollution. Levels should follow what the assessment calls for rather than a default.
|
Area |
NFPA 730 Guidance |
| Pedestrian entrances and walkways |
Reasonable illumination provided and maintained |
|
Exterior doors |
Reasonable illumination provided and maintained |
| Vehicular entrances |
Reasonable illumination provided and maintained |
|
Parking areas |
Reasonable illumination provided and maintained |
| Perimeter fence line |
Illuminated where the assessment calls for it |
|
Areas under video surveillance |
Constant interior lighting at minimum levels the cameras need |
| All security lighting |
Protected against vandalism and kept maintained |
Plantings get measured, not eyeballed. The guidance in the NFPA 730 annex material offers a working benchmark. Shrubbery should be kept to a maximum of about three feet in height, and tree branches should be trimmed so the lowest ones sit at least seven feet off the ground. That leaves roughly a four-foot clear band for natural surveillance across the property. Overgrown shrubs give concealment. Trees planted close to a fence line or a building give a route over the fence or onto the roof.
Assessors also flag foliage that blocks a camera, a light, or a sight line from the street. Trimming costs nothing compared with the hardware that would otherwise be needed to cover the same ground.
What Local Rules Apply to Central PA Facilities
Two local layers matter for facilities in Carlisle, Harrisburg, Mechanicsburg, and the surrounding counties.
The first is building code. The Pennsylvania Construction Code Act, Act 45 of 1999, established the Uniform Construction Code as the statewide standard, and the UCC adopts International Code Council model codes including the International Building Code. According to the Pennsylvania Department of Labor and Industry, more than 90 percent of the state’s 2,562 municipalities have elected to administer and enforce the UCC locally, using either their own staff or certified third-party agencies. The baseline is uniform, but the office you deal with, and how it interprets a given detail, is local. A good assessor knows which jurisdiction you are in before recommending hardware.
The second is the local alarm ordinance. The Borough of Carlisle addresses this in Chapter 76 of its Borough Code, which covers alarm systems, sets a yearly charge for each subscriber connected to the police receiving station, and assesses false alarm charges due 30 days after the notice is mailed. Municipalities across Cumberland, Dauphin, and York counties handle permits and false alarm penalties differently. The assessment should list your specific ordinance obligations, since an unpermitted system or a repeat false alarm history changes both your cost and your police response.
Federal help is also available and free. The Cybersecurity and Infrastructure Security Agency runs a Security Assessment at First Entry, or SAFE, delivered by its Protective Security Advisors. It is a rapid physical security assessment built around a brief walkthrough and a discussion of existing features and concerns, and it produces a report in under two hours listing observed vulnerabilities with voluntary mitigation options, security points of contact, and references. CISA also offers the Infrastructure Survey Tool, a voluntary web-based assessment covering physical security, security forces, security management, information sharing, protective measures, and dependencies, with results delivered as a written report plus a dashboard that compares your facility to similar ones.
Different building types carry different obligations. Healthcare, government, education, and manufacturing sites each get their own chapter in NFPA 730 with occupancy-specific measures, which is why industry-specific security requirements shape the scope of the assessment before the walkthrough starts.
What Should Be in the Final Assessment Report
A verbal summary and a quote is not an assessment. NFPA 730 lists what a security plan should contain, and the assessment report feeds directly into it.
|
Report Section |
What It Covers |
| Statement of purpose and scope |
Which buildings, zones, and assets were reviewed, and why |
|
Facility description |
Layout, operations, hours, staffing, and organizational structure |
| Asset classification |
What matters most, ranked |
|
Threat assessment |
Realistic adversaries and consequences of loss |
| Vulnerability findings |
Each gap, with a risk level, arranged by frequency and severity |
|
Recommended countermeasures |
The specific fix for each finding |
| Post-fix risk reassessment |
What the risk level becomes once the fixes are in |
|
Implementation tracking |
Who owns each item and when it is due |
| Supporting material |
Maps, floor plans, contact lists, and emergency procedures |
NFPA 730 adds that plan objectives should be specific, measurable, achievable, relevant, and timely. If a recommendation cannot be measured or dated, it is a suggestion rather than a finding.
The guide also notes that a security plan has public and private components, and that the private components should be kept confidential. Your vulnerability list is a roadmap for anyone who wants to exploit it. Control distribution and keep a documented master copy.
How Long Does an Assessment Take and How Often Should You Repeat One
A single-building walkthrough usually runs a half day. A multi-building site or a campus takes longer, and the report typically follows within one to two weeks. CISA’s SAFE assessment sits at the fast end, producing a report in under two hours, because it is built as a first step for facilities with little or no existing program.
On frequency, NFPA 730 does not fix a calendar. It says the review and update should be based on the level of risk, the threats, the crime situation, and changes in conditions within the organization. In practice, these events should trigger a fresh look.
- A renovation, expansion, or layout change
- A move, a new tenant, or a change in building use
- A break-in, theft, or violent incident on site
- A change in what you store or how much of it
- A shift in neighborhood crime patterns
- Turnover in the staff who hold credentials or run security
- A new access control or camera deployment
- An insurance carrier or compliance review
NFPA 730 also calls for periodic drills at various times and locations, critiqued afterward for effectiveness, with the lessons folded back into the plan. And it asks for a repair log listing the impairment, the date and time it occurred, the repairs completed, and the date of each repair, retained for at least one year. That log becomes evidence if a claim or a lawsuit ever turns on whether your systems were working.
Why the Assessment Matters More Than the Equipment
The research backs the sequence.
The FBI recorded 779,542 burglaries across the United States in 2024. Residences accounted for 405,776 of them, leaving roughly 373,000 at businesses and other non-residential buildings.
A University of North Carolina at Charlotte study led by Dr. Joseph Kuhns of the Department of Criminal Justice and Criminology surveyed 422 incarcerated burglars from North Carolina, Kentucky, and Ohio. When selecting a target, they weighed how close other people were, whether escape routes existed, and whether the site showed signs of security including alarm signs, alarms, dogs, and outdoor cameras. About 83 percent said they checked for an alarm before attempting entry, and roughly 60 percent said they would move to a different target once they found one. The study also found male burglars were more likely to target commercial buildings after business hours.
Every one of those factors is something an assessment measures and a catalog cannot. Escape routes, sight lines, and visible deterrence are properties of your site, not of your hardware.
Internal risk needs the same treatment. The Association of Certified Fraud Examiners published Occupational Fraud 2026: A Report to the Nations, covering 2,402 cases across 143 countries. The median loss was $104,000 per case, the typical scheme ran about 12 months before it was caught, and the ACFE estimates organizations lose roughly 5 percent of revenue to fraud each year. Access logs and camera coverage in the right places shorten that 12-month window. Cameras pointed at the parking lot do not.
Safety is part of the same study. The Bureau of Labor Statistics recorded 5,070 fatal work injuries in the United States in 2024, down 4.0 percent from 5,283 in 2023. Assaults caused 470 of those deaths. NFPA 730 asks employers to build a workplace violence prevention program around six components: management commitment, employee involvement, worksite hazard analysis, hazard prevention and control, training, and evaluation. The worksite hazard analysis is the assessment.
How Do You Prepare for a Security Assessment
You will get more out of the visit if these are ready before the assessor arrives.
- Floor plans and site drawings. Current ones, including any recent renovations.
- Your door and key list. Every exterior opening, every controlled interior door, and who holds which keys or credentials.
- Incident history. Break-ins, thefts, vandalism, and safety incidents from the past three years, on the property and in the immediate neighborhood.
- Existing system documentation. Camera counts and locations, alarm zone lists, panel model, monitoring contract, and service records.
- Operating details. Hours, shift patterns, headcount by area, delivery schedules, and after-hours activity.
- Your asset list. What would hurt most to lose, including inventory, equipment, data, and records.
- Compliance obligations. Anything your industry, insurer, or landlord requires.
- The right people on site. Someone from operations and someone from facilities, since the two rarely see the same problems.
Businesses across Carlisle, Harrisburg, Mechanicsburg, and Camp Hill get better results from commercial security systems in Central PA when the design starts with this study rather than a product list.
Final Thoughts
A commercial security assessment identifies your assets, classifies the threats against them, tests every layer from the property line to your most restricted room, and hands you a written report that ranks each gap by risk and pairs it with a fix. NFPA 730 sets the seven-step method, NFPA 731 governs how any resulting systems get installed and maintained, and local rules in Cumberland, Dauphin, and York counties add permit and code obligations on top.
Skip the study and you buy equipment that guards the wrong things. Run it properly and every dollar afterward goes where the risk actually sits. The assessment also creates something equipment never will, which is a documented record showing you identified your risks and acted on them.
If you want a walkthrough of your facility, start with Hilton’s Security Advisor from Hilton’s Electronic Security. It takes a few minutes, captures your property type and primary concerns, and puts a technician on your site to assess the building rather than sell you a package.


