The architecture

Six interdependent domains.

Physical security assessments have traditionally been shaped by individual experience, organisational preference or sector habit. IPSRM™ replaces that variability with six domains: the same six, in the same order, on every assessment, whatever the organisation.

01

Strategic Threat Context

The strategic threats, intent, capability and operating context that define organisational exposure.

02

Adversarial Pathways

How adversaries could seek to exploit the environment to achieve their objectives.

03

Structural Protection Architecture

The integrated physical protection systems, barriers and infrastructure that prevent, detect, delay and respond.

04

Operational Control Discipline

The effectiveness, consistency and execution of operational controls, procedures and daily management.

05

Control Lifecycle Integrity

How controls are designed, implemented, maintained, tested and reviewed throughout their lifecycle.

06

Systemic Dependency & Resilience

The dependencies, interconnections and resilience factors that influence continuity and recovery.

No domain is assessed in isolation. Findings in one frequently explain or reinforce observations in another, which is what makes the architecture harder to game than a checklist, and harder to shortcut than individual judgement alone.

The sequence

Collect, Calibrate, Communicate.

Every IPSRM™ assessment follows the same three-stage sequence. This is what each stage requires.

01

Collect

Evidence is gathered through document review, interviews, observation, inspection and functional testing, and recorded systematically against the six domains in IPSRM Field. The result is an accurate, evidenced picture of the current physical security environment, not a list of impressions.

02

Calibrate

Professional judgement is applied within a structured calibration framework to determine Residual Impact and Residual Likelihood, and the Residual Risk Score they produce. This is where evidence becomes a consistent, defensible statement of exposure, with the practitioner, not the software, doing the thinking.

03

Communicate

Findings are prioritised by calibrated residual risk in the Executive Report, written for decision-makers rather than practitioners, so that boards can understand current exposure, weigh treatment options and allocate resources with confidence in how the conclusion was reached.

“A methodology does not make decisions. It provides a consistent framework within which informed professional judgement can be exercised and clearly communicated.”

Practitioner Observation · Chapter 2

Residual risk calibration

What exposure remains.

The purpose of an assessment isn't to describe which controls exist. It's to establish what exposure remains once those controls are accounted for. IPSRM™ calibrates that residual exposure using two factors, combined into a single, consistent score.

TierScoreMeaning
Tier 116–25Critical structural exposure: priority action, escalation required
Tier 26–15Material exposure: planned remediation required
Tier 31–5Managed exposure: structured monitoring

“Residual risk reflects the exposure that remains after existing controls have been considered, not the exposure that would exist if no controls were present.”

Practitioner Observation · Chapter 4

Defensibility

Why it holds up under scrutiny.

Structure alone doesn't make an assessment defensible. IPSRM™'s defensibility rests on three things working together.

Evidence before opinion

Calibration begins with evidence, not with what a practitioner already believes about a site. Where evidence is incomplete, that's recorded, not resolved through assumption. A conclusion should trace back to something observed.

Consistency without uniformity

Similar evidence leads to comparable conclusions. Where a judgement departs from what similar evidence would normally produce, the reasoning is written down, and that documented departure is often more valuable to a board than the score itself.

Independence under pressure

Calibration stays objective, free from client expectations, operational convenience or commercial pressure. Where uncertainty exists, it is acknowledged openly rather than concealed behind false confidence.