IPSRM™ Methodology
A structured methodology, built to be defended.
IPSRM™ governs how physical security assessments are planned, conducted, evaluated and reported. It doesn't replace professional judgement; it gives that judgement a consistent framework to operate within.
Two experienced practitioners assessing the same site should reach comparable conclusions. Most physical security assessment today can't promise that. IPSRM™ was built to change it.
The architecture
Six interdependent domains.
Physical security assessments have traditionally been shaped by individual experience, organisational preference or sector habit. IPSRM™ replaces that variability with six domains: the same six, in the same order, on every assessment, whatever the organisation.
01
Strategic Threat Context
The strategic threats, intent, capability and operating context that define organisational exposure.
02
Adversarial Pathways
How adversaries could seek to exploit the environment to achieve their objectives.
03
Structural Protection Architecture
The integrated physical protection systems, barriers and infrastructure that prevent, detect, delay and respond.
04
Operational Control Discipline
The effectiveness, consistency and execution of operational controls, procedures and daily management.
05
Control Lifecycle Integrity
How controls are designed, implemented, maintained, tested and reviewed throughout their lifecycle.
06
Systemic Dependency & Resilience
The dependencies, interconnections and resilience factors that influence continuity and recovery.
No domain is assessed in isolation. Findings in one frequently explain or reinforce observations in another, which is what makes the architecture harder to game than a checklist, and harder to shortcut than individual judgement alone.
The sequence
Collect, Calibrate, Communicate.
Every IPSRM™ assessment follows the same three-stage sequence. This is what each stage requires.
01
Collect
Evidence is gathered through document review, interviews, observation, inspection and functional testing, and recorded systematically against the six domains in IPSRM Field. The result is an accurate, evidenced picture of the current physical security environment, not a list of impressions.
02
Calibrate
Professional judgement is applied within a structured calibration framework to determine Residual Impact and Residual Likelihood, and the Residual Risk Score they produce. This is where evidence becomes a consistent, defensible statement of exposure, with the practitioner, not the software, doing the thinking.
03
Communicate
Findings are prioritised by calibrated residual risk in the Executive Report, written for decision-makers rather than practitioners, so that boards can understand current exposure, weigh treatment options and allocate resources with confidence in how the conclusion was reached.
“A methodology does not make decisions. It provides a consistent framework within which informed professional judgement can be exercised and clearly communicated.”
Practitioner Observation · Chapter 2
Residual risk calibration
What exposure remains.
The purpose of an assessment isn't to describe which controls exist. It's to establish what exposure remains once those controls are accounted for. IPSRM™ calibrates that residual exposure using two factors, combined into a single, consistent score.
| Tier | Score | Meaning |
|---|---|---|
| Tier 1 | 16–25 | Critical structural exposure: priority action, escalation required |
| Tier 2 | 6–15 | Material exposure: planned remediation required |
| Tier 3 | 1–5 | Managed exposure: structured monitoring |
“Residual risk reflects the exposure that remains after existing controls have been considered, not the exposure that would exist if no controls were present.”
Practitioner Observation · Chapter 4
Defensibility
Why it holds up under scrutiny.
Structure alone doesn't make an assessment defensible. IPSRM™'s defensibility rests on three things working together.
Evidence before opinion
Calibration begins with evidence, not with what a practitioner already believes about a site. Where evidence is incomplete, that's recorded, not resolved through assumption. A conclusion should trace back to something observed.
Consistency without uniformity
Similar evidence leads to comparable conclusions. Where a judgement departs from what similar evidence would normally produce, the reasoning is written down, and that documented departure is often more valuable to a board than the score itself.
Independence under pressure
Calibration stays objective, free from client expectations, operational convenience or commercial pressure. Where uncertainty exists, it is acknowledged openly rather than concealed behind false confidence.
None of this replaces professional judgement.
It's what makes that judgement possible to explain, six months later, to someone who wasn't in the room. See the methodology applied to a complete assessment in IPSRM Field, the app our Founder Practitioners are using on live work ahead of public release.
Try the demo