
A commercial property security assessment is an on-site, standards-based evaluation of a building or campus’s physical security controls — perimeter, access control, lighting, camera coverage, parking, and life-safety integration — measured against the property’s actual crime history and foreseeable risk to produce a prioritized, cost-justified remediation plan. Done well, it is the single document that determines whether an owner’s security spending is defensible in a courtroom and effective on the ground.
Commercial real estate owners commission security assessments for three overlapping reasons: a lender or insurer requires one, a tenant or acquisition due-diligence process demands one, or an incident — or a near miss — has forced the issue. Whatever the trigger, the quality gap between a genuine assessment and a vendor’s sales-oriented “site survey” is enormous, and it is the gap that determines whether the resulting report holds up when a plaintiff’s attorney or an underwriter examines it later. This guide is written for the property manager, CRE owner, or asset manager who needs to understand what a real commercial property security assessment covers, how it differs from a broader enterprise risk assessment, the methodology a competent firm follows, and what the final deliverable should contain.
What is a commercial property security assessment, and who needs one?
A property security assessment is a structured, on-site evaluation of the physical controls protecting a specific building, campus, or portfolio asset — office towers, retail centers, industrial and logistics facilities, mixed-use developments, parking structures, and multifamily communities all fall under this discipline. It is distinct from, and typically narrower than, a full enterprise security risk assessment, which also examines cyber, personnel, and organizational risk across an entire company. Owners, property managers, asset managers preparing for acquisition due diligence, insurers underwriting a general-liability policy, and counsel defending or evaluating a premises-liability exposure are the parties who most often commission this work.
The professional bodies that define the discipline are consistent on this point: ASIS International publishes physical-security and risk-assessment standards that apply directly to commercial real estate, and BOMA International sets the building-operations and emergency-preparedness benchmarks that owners and property managers are measured against. A credible assessment is built against these recognized frameworks, not against an individual vendor’s proprietary checklist.
What does a professional assessment actually evaluate?
A rigorous assessment moves through the property the way an adversary would: from the outside in. The perimeter and site approach — fencing, vehicle gates, landscaping sightlines, and exterior lighting — is examined first, because it establishes whether an intruder even has to be noticed to get close to the building. The building envelope comes next: entrances, loading docks, roof access, service doors, and any point where a door propped open or a lock left unchanged since construction quietly defeats every control layered on top of it.
Inside that envelope, the assessment evaluates access-control systems — card or fob credentialing, visitor and tenant management, elevator and floor restrictions, and how quickly access is revoked when an employee or tenant departs. Camera coverage and lighting are assessed together, since a camera without adequate lighting produces unusable footage and a well-lit area without coverage produces no record at all. Parking lots and structures receive dedicated attention as the highest-liability zone in most commercial portfolios: lighting uniformity, sightlines, call-station function, and patrol coverage all factor into the score. Finally, the assessment examines how security integrates with fire and life-safety systems, emergency action plans, and property-management operations, because a program that is not coordinated with the building’s broader operations creates gaps at exactly the moments — fires, medical events, evacuations — when coordination matters most.
How is a property assessment different from an enterprise security risk assessment?
The two are related but answer different questions. A property assessment asks: are the physical controls at this specific building adequate to its foreseeable risk? An enterprise security risk assessment asks a broader question across an entire organization: what is our total exposure across physical, cyber, personnel, and operational risk, and how do those domains interact? A CRE owner managing a single office tower typically needs a property assessment. A corporate tenant occupying that tower — with data, personnel, and executives to protect — often needs the broader enterprise assessment in addition, and the two should be coordinated rather than run in isolation, since a property-level physical gap (an unrevoked access badge, an unmonitored service entrance) is frequently the entry point for what becomes an enterprise-level incident.

What assessment methods are available, and how do they compare?
Not every property needs the same depth of review, and matching the method to the asset’s risk profile and budget is part of a competent firm’s job. The table below contrasts the three tiers most owners choose among.
| Tier | What it covers | Best suited for |
|---|---|---|
| Desktop review | Incident history, crime data, floor plans, and policy documents; no site visit | Portfolio-wide triage, acquisition due-diligence screening |
| On-site walkthrough | Daytime physical inspection of access points, lighting, cameras, and signage | Routine annual review of a stable, lower-risk asset |
| Comprehensive CPTED-informed assessment | Day and night site visits, incident-data analysis, control testing, life-safety coordination review, and a scored, prioritized report | Higher-risk assets, post-incident review, lender/insurer requirements, litigation exposure |
How do CPTED principles apply to a commercial property assessment?
Crime Prevention Through Environmental Design (CPTED) is the framework that connects physical design to behavior: natural surveillance (sightlines that let legitimate users see and be seen), natural access control (site layout that channels people through defined, monitored entry points rather than dozens of ambiguous ones), territorial reinforcement (landscaping, signage, and maintenance that signal the property is watched and cared for), and maintenance itself (a well-kept property reads as controlled; a neglected one reads as unclaimed). A commercial property assessment applies CPTED criteria systematically rather than as an afterthought — scoring sightline obstructions, identifying entry points that should be consolidated or monitored, and flagging deferred maintenance that signals abandonment to opportunistic offenders.
What is the step-by-step assessment methodology?
- Gather incident and crime data. Pull the property’s internal incident and maintenance logs alongside available police call-for-service data for the address and surrounding block.
- Conduct the site visit — day and night. Physically inspect perimeter, envelope, access control, lighting, cameras, parking, and signage in both daylight and after-dark conditions, since many vulnerabilities only appear once the sun goes down.
- Score against a recognized framework. Evaluate findings against ASIS and CPTED criteria and BOMA operational benchmarks rather than an ad hoc checklist.
- Test, don’t just inventory, key controls. Confirm access-revocation timelines, verify camera retention and footage quality, and check that emergency call stations and alarm response actually function as documented.
- Map foreseeability to adequacy. Connect the incident history to the specific control gaps that leave the property exposed to a similar future event.
- Deliver a prioritized, cost-justified plan. Rank remediation items by risk reduction per dollar, distinguishing urgent life-safety and access-control fixes from longer-term capital projects.
- Set a reassessment cadence. Schedule a follow-up review, typically annually and after any significant incident, so the assessment stays current rather than becoming a one-time snapshot.
What common findings translate directly into negligent-security liability exposure?
Certain findings recur across commercial portfolios and are precisely the ones plaintiffs’ counsel look for in a premises-liability case: burned-out or misaligned parking-structure lighting, cameras that are present but unmonitored or retained for too short a period to matter, access credentials for former tenants or employees that were never revoked, propped or defeated service doors, broken or ignored emergency call stations, and a total absence of documented patrol or inspection activity. None of these findings are exotic — they are exactly the deferred-maintenance and process gaps a competent assessment is designed to surface before an incident, rather than after one, in a deposition.
What should the final assessment deliverable include?
A credible report includes an executive summary in plain business language for ownership and counsel; a detailed, photographed findings section tied to specific locations on the property; a scored risk matrix that ranks each finding by likelihood and consequence; and a prioritized remediation roadmap with rough cost ranges and responsible parties. The report should explicitly reference the standards it was measured against — ASIS, CPTED, BOMA — so its findings are defensible if later examined by an insurer, a lender, or opposing counsel. A one-page punch list with no scoring, no standards reference, and no prioritization is not a security assessment; it is a maintenance memo wearing an assessment’s name.
What drives the cost of a commercial property security assessment, and how often should it be repeated?
Cost scales with the size and complexity of the property, the number of buildings or parking structures in scope, whether the review includes a night-time site visit, and the depth of control testing versus visual inspection alone. A single office building typically costs far less to assess than a mixed-use campus with a garage, retail podium, and multiple tenant floors. Most owners should plan for a full reassessment annually, with an interim review after any significant incident, a change in tenant mix, a major renovation, or new intelligence about crime trends in the immediate area — a risk picture from three years ago tells an owner very little about the property’s exposure today.
How does Honeybadger conduct commercial property security assessments?
Honeybadger Solutions conducts commercial property security assessments as a standalone engagement or as the foundation for an ongoing patrol and access-control program. Every assessment includes a day-and-night site visit, incident-data analysis, and scoring against ASIS, CPTED, and BOMA-aligned criteria, delivered as a prioritized, cost-justified roadmap rather than a generic punch list. Within Arizona, any resulting patrol, access-control, or on-site security program is staffed by our own in-house, AZ DPS-licensed, supervised officers — not subcontracted labor — so the same firm that identifies the gaps is directly accountable for closing them.
Operating from offices in Casa Grande, Phoenix, and Oro Valley, we assess and staff commercial properties across all of Arizona, and we extend assessment and coordination services nationwide and internationally through a commanded network of vetted partners where owned officers are not available. Where an assessment surfaces exposure that touches an ongoing investigation, executive threat, or broader enterprise risk, we can carry findings directly into our investigations and security consulting practices rather than handing off a disconnected report. This content is educational information about industry practice, not legal advice; owners facing an active claim should consult qualified counsel.
Frequently asked questions
Who are Honeybadger’s commercial property assessments performed by, and who staffs the resulting program in Arizona?
Assessments are performed by our own security consulting team. Within Arizona, any on-site patrol or access-control program that follows an assessment is staffed by our own in-house, AZ DPS-licensed, supervised officers, not subcontractors. Outside Arizona, program staffing is delivered through a commanded network of vetted partners.
How is a property security assessment different from an enterprise security risk assessment?
A property assessment evaluates whether the physical controls at a specific building or campus are adequate to its foreseeable risk. An enterprise risk assessment is broader, examining physical, cyber, personnel, and operational risk across an entire organization. Many commercial tenants need both, coordinated together, since a physical gap at the property level is often the entry point for a larger organizational incident.
How often should a commercial property be reassessed?
Most properties should be fully reassessed annually, with an interim review after any significant incident, a major renovation, a change in tenant mix, or new intelligence about crime trends in the surrounding area. A stale assessment can create false confidence in controls that no longer match current risk.
Is this guide legal advice about liability for a specific property or incident?
No. This guide explains how commercial property security assessments are typically conducted and how they relate to general negligent-security concepts as a matter of industry practice. It is not legal advice and does not address the facts of any specific property, incident, or claim. Consult qualified counsel for guidance on an active matter.
About Honeybadger Solutions
Honeybadger Solutions is an Arizona-licensed security and investigations firm. We conduct commercial property security assessments and, within Arizona, staff resulting programs with our own AZ DPS-licensed, supervised in-house guards — not subcontracted labor — across office, retail, industrial, and mixed-use assets statewide. We extend nationwide and international coverage through a commanded network of vetted partners. This content is educational and is not legal advice; consult qualified counsel regarding any specific property or incident.
Offices: Casa Grande (HQ), Phoenix, and Oro Valley, Arizona.
Phone: 602-725-2818
Confidential consultation: speak with a security advisor about scheduling a property security assessment.