Corporate security budgets tend to cluster around two things: an access control system at the front door and a camera network nobody watches. Both are useful. Neither addresses what actually happens at offices and campuses, which is a mix of ordinary property crime, a slow bleed of insider loss, and a small number of interpersonal incidents that account for nearly all of the real harm.
Getting the proportions right matters more than getting any single control right.
The frequency layer: theft and unauthorised access
Most incidents at an office are unglamorous. Laptops from unattended desks. Deliveries taken from a lobby. Catalytic converters and vehicle break-ins in the car park. Someone tailgating through a controlled door behind a person holding coffee.
Tailgating deserves particular attention because it defeats the control most organisations spent the most money on. A badge reader that admits three people per swipe is a log of one entry and a record of nothing. Cameras confirm this happens constantly; almost nobody acts on it, because the cultural cost of asking a colleague to badge in separately is higher than the perceived risk.
Car parks are consistently the highest-incident area on a corporate site and consistently the least covered. They are large, dark, on the perimeter, and outside the badge-controlled envelope. If you are choosing where to add lighting or a patrol pass, that is usually where the return is.
The severity layer: violence
Low frequency, disproportionate consequence.
The Bureau of Labor Statistics recorded 5,070 fatal work injuries in 2024, a 4.0% decrease from 5,283 in 2023, at a rate of 3.3 per 100,000 full-time equivalent workers. Within that, violence and other injuries by persons or animals accounted for 733 deaths. Homicides rose to 470 from 458 the year before, representing 64.1% of that category, while workplace suicides fell to 263.
Those numbers do not support panic, and they do not support ignoring the problem either. Homicide rose while overall workplace fatalities fell — the trend is going the wrong way against a background that is improving.
More usefully, workplace violence is rarely spontaneous. It is usually preceded by observable behaviour: escalating grievance, threats, boundary-testing, a termination handled badly, a domestic situation following someone to work. The control that works is not a guard at the door. It is a behavioural threat assessment process — a way for staff to report concerns, a named group that reviews them, and a documented response.
Most organisations have no such process. They have an HR complaint channel for employment matters and a security function for physical matters, and the cases that matter fall between them.
The quiet layer: insider loss
The largest financial loss at most corporate sites is not taken through a door. It is intellectual property, client lists, pricing, and data leaving with departing staff. It generates no alarm, no camera footage and no incident report.
The signals are procedural rather than physical: large downloads before a resignation, access to systems outside a person’s role, badge activity at unusual hours by someone whose work does not require it. Correlating physical access records against system activity is the single most underused capability in corporate security, and it usually requires nothing more than getting two existing logs into the same place.
What the general crime trend does and does not tell you
The FBI reported that national violent crime decreased an estimated 4.5% in 2024 against 2023, with murder down 14.9%, robbery down 8.9% and aggravated assault down 3.0%.
That is genuinely good news and it is close to useless for planning a specific site. National trends do not predict what happens at one address. What predicts that is the local pattern — incidents on the block, the character of the surrounding area after dark, the history at this building — and the internal pattern, which is what your own incident log would tell you if it were being read.
Where campuses differ from offices
A multi-building campus has problems a single tenancy does not. The perimeter is long and often notional. Movement between buildings puts people outside at night. Landscaping that looks good creates concealment and blocks sightlines. Contractors and vendors move around with legitimate reasons to be anywhere. And the site is usually large enough that a single guard post covers a fraction of it.
The right answer on a campus is almost always a mixed posture — a controlled point where people and risk concentrate, a varied patrol covering the rest, and technology filling the gaps between passes. How to choose between those is set out in our piece on standing post, patrol or armed coverage.
An honest priority order
- Read your own incident log. Twelve months of your own data beats any general threat report. Most sites have never analysed it.
- Fix the car park. Highest incident count, lowest typical coverage.
- Stand up a threat assessment process. Low cost, addresses the highest-severity risk, and gives staff somewhere to take a concern before it becomes an emergency.
- Close the tailgating gap where it actually matters — not everywhere, but at the doors protecting something.
- Correlate badge and system logs to see the insider picture you already have the data for.
- Then consider more cameras.
Honeybadger Solutions assesses corporate sites against what is actually happening there rather than against a template. Where the concern is a specific individual or a pattern of conduct, that moves into private investigations; where staff need to recognise and report the early signals, security awareness training is the mechanism; and where an executive faces a named threat, that is executive protection.
Access control is the control that actually decides the outcome
Most corporate security spending goes to visible measures — officers, cameras, a staffed lobby — while the mechanism behind the majority of incidents is simpler: someone was inside who should not have been, and nothing stopped them at the door.
Three failures account for most of it. Tailgating, where a person follows an authorised employee through a controlled door, defeats badge systems entirely and is socially difficult to prevent because holding a door is ordinary politeness. Credential lifecycle, where badges are issued promptly and revoked slowly, leaves former employees and departed contractors with working access for weeks. And propped and unmonitored doors, usually at loading areas and smoking areas, quietly undo the entire perimeter.
The fixes are procedural more than technological: an audited termination checklist that includes badge revocation on the day, periodic access reviews that actually remove stale credentials, door-held-open alarms that someone responds to, and a culture where challenging an unfamiliar person is expected rather than awkward. None of these is expensive. All of them are routinely absent.
The contractor and vendor population
Every campus has a second workforce nobody counts: cleaners, maintenance, landscapers, vending, IT contractors, couriers and the occasional consultant. They frequently have after-hours access, they are frequently badged by a different process, and they are frequently invisible in access reviews.
Ask three questions. Who currently holds credentials who is not an employee? Who issued them, and who reviews them? What happens when that vendor’s employee leaves their employer — does anyone tell you? In most organisations the honest answer to the third is that nobody does, which means the vendor’s turnover is silently your access problem.
A vendor access policy with named sponsors, expiry dates on every credential and a quarterly review closes this. It is unglamorous work that removes a genuine and common attack path.
Where physical and cyber security actually meet
The distinction between physical and information security dissolves in practice, and a campus programme that treats them separately misses the overlap.
Unattended unlocked workstations are a data exposure created by a physical behaviour. Documents left at printers are the same. Network ports in conference rooms and lobbies that remain live give anyone who sits down a foothold. Server and communications rooms with doors that do not lock or that share a master key with the janitorial closet are a physical control protecting a digital asset. And a badge system, a camera system and an alarm system are themselves networked computers, frequently unpatched, frequently on the same flat network as everything else.
Anyone reviewing campus security should walk the site asking both questions at once. The findings are usually cheap to fix and materially reduce risk on both sides.
Workplace violence: what prevention actually consists of
Violence is the low-frequency, high-consequence layer, and the temptation is to address it with equipment. The evidence points elsewhere: the most effective interventions are early recognition and a functioning reporting path, not hardware.
That requires three things. A named channel where staff can raise a concern about a colleague, a customer or a former employee without it becoming a formal HR complaint on day one. A threat assessment approach — a small standing group including HR, legal, security and, where appropriate, outside expertise — that evaluates concerns against behaviour rather than instinct. And documented follow-through, because the pattern in almost every reviewed case is that concerns existed, were mentioned, and were not connected.
Terminations deserve specific planning. The elevated-risk window around a separation is well documented, and simple measures — badge revocation timed to the meeting, a considered location, escort arrangements that preserve dignity, a plan for retrieving property — reduce both the risk and the humiliation that frequently precedes escalation.
Emergency planning that survives contact
Most campus emergency plans fail on the same points. Nobody knows who is in the building. There is no way to communicate with everyone quickly. Assembly points have never been used. And the plan assumes the emergency happens on a Tuesday at 10am rather than during a shift change or a large meeting.
Test the parts that are testable. Run a mass notification drill and measure how many people actually received it. Check that the visitor log or badge system can produce an occupancy list in under five minutes. Walk the evacuation route with someone who uses a wheelchair. Confirm that the person named in the plan still works there.
An honest sequence for a campus programme
- Fix access control hygiene: revocation, reviews, tailgating, propped doors.
- Inventory and govern vendor and contractor credentials.
- Stand up a reporting channel and a threat assessment process.
- Close the physical-digital overlaps found on a joint walkthrough.
- Make emergency communication work and prove it with a drill.
- Then consider additional guarding hours, cameras or hardware against what the incident data actually shows.
This is general information and not legal advice; employment and privacy questions around monitoring, reporting and terminations should be reviewed with counsel.
Sector-specific guidance
- Healthcare security in Arizona — Clinical settings add patient safety, controlled substances and visitor management to the campus picture.
- HOA and property management security — Where a campus abuts residential community property, the governance and privacy rules differ.
Browse by topic
Security guard services  · Private investigations  · Cybersecurity  · Digital forensics  · Financial fraud investigation  · Executive protection  · All articles