The Methodology Gap, by Stephen Beels: book cover

The book · Free download

The Methodology Gap

Why physical security assessment has never had a widely accepted methodology, and why that gap can no longer be ignored.

Drawing on more than three decades of practice, Stephen Beels examines why two practitioners can assess the same site and reach different conclusions, and what that means for organisations relying on those assessments to make governance-level decisions.

Download the book

Free PDF. No account required.

The problem

A discipline without a shared architecture.

Financial auditISA 315 and ISA 330
Cyber securityISO 27001 and NIST SP 800-30
Physical security assessmentNo shared framework

The result: two experienced practitioners can examine the same site and produce materially different conclusions. Not because either is wrong, but because nothing governs how evidence is collected, risk is calibrated or findings are reported.

For organisations, that creates a real governance problem. Assessments can't be reliably compared across sites. Risk ratings can't be trusted to mean the same thing from one report to the next. And when a board asks "how confident are we in this conclusion?", the honest answer often depends more on which practitioner was in the room than on the evidence itself.

Why it matters now

Governance expectations have moved faster than assessment practice.

  • The UK Corporate Governance Code 2024Boards must now declare annually on the effectiveness of their material controls, and for many organisations those include physical security.
  • Martyn's LawThe Terrorism (Protection of Premises) Act 2025 places a legal duty on Enhanced tier premises to assess and reduce their vulnerability to terrorist acts, turning vulnerability assessment from good practice into a statutory obligation.
  • Insurers and regulatorsIncreasingly, they ask not just what was concluded, but how: whether the process behind a finding can withstand scrutiny months or years later.

Assessments built on undocumented judgement are becoming harder to defend. The Methodology Gap explains why, and what a more disciplined approach requires.

What's inside

What you'll take from the book.

  1. Why practitioner expertise alone hasn't produced comparable, governance-reliable assessments.
  2. The specific ways current assessment practice breaks down: in terminology, scope, risk calibration and reporting.
  3. Why boards and audit committees struggle to act on security findings, even when the underlying work is technically sound.
  4. What a mature assessment methodology must actually do, illustrated through the Collect, Calibrate, Communicate architecture behind IPSRM™, and how it supports professional judgement rather than replacing it.
  5. Why defensibility, the ability to show how a conclusion was reached, is becoming a professional expectation rather than an optional extra.

About the author

Stephen Beels, creator of IPSRM™

Stephen has worked in physical security, risk and resilience for more than thirty years. He began in counter-terrorism and serious crime roles with the Metropolitan Police Service, before moving into security leadership, advisory and consultancy roles across critical infrastructure, financial services, higher education and other high-consequence environments, including eighteen years of independent consultancy.

He has conducted or reviewed more than 600 physical security assessments across the UK, Europe and Africa, was a Board Director of the Association of Security Consultants from 2015 to 2020, and has been recognised with three UK Outstanding Security Performance Awards.

The Methodology Gap draws directly on that career, examining why the discipline has lacked a governing methodology, and introducing IPSRM™ as one response to it. More about Stephen

Read the case

A more defensible approach to physical security assessment.

Download the book

Free PDF. No account required.

Prefer to see the methodology working? Try the IPSRM Field demo, a complete assessment in your browser, or read the free Handbook excerpt.