Physical security consulting for any organization, any sector

Government agencies, private businesses, nonprofits and critical infrastructure operators all protect the people inside and the building around them. We assess the building and its network as one target.

Every sector, the same threats

Offices, data centers, clinics, nonprofits and private businesses all face unauthorized entry, insider risk, targeted vandalism, workplace violence and the new exposure that shows up when door locks and cameras go on the network. Most of these programs were built years ago and have not been looked at since.

Someone who walks into an unlocked network closet can do in five minutes what a remote attacker would work at for months. Compromise the building management system instead and you knock out the door controls your staff counts on.

We treat physical security the way we treat cybersecurity, as risk management. Spencer Wood, our Founder, CEO and Principal Consultant, has assessed government offices, critical infrastructure sites and election facilities across the six states of CISA Region 5, much of that assessment work done during his CISA service.

What is included

We scope the work to the building, the threat picture around it and what has to keep running while you fix things.

  • Physical security assessments

    We walk the building. Perimeter, entry points, camera coverage, lighting, how visitors are handled and what the staff actually does versus what the policy says. You get the findings ranked by risk, each one with a fix attached.

  • Threat and vulnerability analysis

    What is likely to come at this building, and what would work if it did. We use current threat reporting plus what your site and your sector look like to somebody choosing a target.

  • Access control strategy

    We review and redesign access control: credentials, the visitor protocol and the list of people who still hold a badge and should not. That includes the systems behind the doors, the networked badge readers and the electronic locks.

  • Emergency response planning

    We write or review the plans for an active threat, a natural disaster and an evacuation, plus keeping the doors open through any of them. Then we run the plan against your floor plan and your staffing.

  • Protective measures consulting

    Cameras, barriers, lighting, guard staffing, detection technology. We do not sell any of it, so what we recommend is whatever cuts the most risk per dollar you have.

Where physical and cyber security converge

Most organizations now run their physical security over the network: badge readers on Active Directory, cameras sharing an IP network with administrative workstations, HVAC and power behind a building automation platform somebody can reach from home. That is easier to run, and it is also a way in.

Our assessments cover that ground. When we review an access control system we look at the hardware and at the network it sits on. Cameras get checked for isolation and patch level as well as placement. Emergency response plans get the scenarios that cross the line: a ransomware event that forces an evacuation decision, a forced door that starts a network incident.

Who this is for

  • County and state election offices
  • Government agencies and municipalities whose security program is old, informal or both
  • Private businesses protecting offices, data centers or plants
  • Nonprofits and advocacy groups facing an elevated threat
  • Public utilities and critical infrastructure carrying physical security compliance obligations
  • Anyone who just had an incident

Every consultant who works with Foundation Consultant Group served as a Cybersecurity Advisor with CISA, the federal field role for reducing cyber risk in state and local government and critical infrastructure.

  • Six states CISA Region 5: Illinois, Indiana, Michigan, Minnesota, Ohio and Wisconsin, where Spencer Wood served.
  • More than 20 years His record in enterprise, government and critical infrastructure.
  • Nationwide Where we take engagements now.

Leadership

Spencer Wood
Spencer Wood, Founder, CEO and Principal Consultant

Spencer Wood served as a Cybersecurity Advisor with CISA, supporting government agencies and election officials across a six-state region. His physical security work covers government offices, critical infrastructure and election facilities, much of it during federal service, and it looks at the networks running through the building at the same time. Before federal service he was interim State Chief Information Officer of Ohio and CIO for the Ohio Secretary of State, which is where he learned what it takes to run security for a large government environment. He holds the CISM.

Next step

If you can name the building and the date, we can scope the visit. You will see the cost before you commit to anything.

Get in Touch