Search this phrase and most of what comes back is written for IT departments — firewalls, penetration testing, network vulnerabilities. If you manage a building, a campus, or a business in Los Angeles and you’re asking this question, you’re almost certainly not asking about your network. You’re asking about your building, your people, and your exposure — and that’s a different discipline with its own definition, its own methodology, and its own answer.
Quick Answer
A security risk and vulnerability assessment is a structured evaluation of a facility or organization that identifies specific weaknesses (vulnerabilities), the threats that could exploit them, and the likely consequences if they did — combined into an overall risk picture with prioritized recommendations. In physical security, it covers access control, perimeter design, personnel practices, emergency planning, and the surrounding environment, not network or data security.
Risk vs. Vulnerability: The Difference That Actually Matters
These two words get used interchangeably, but they mean different things, and the difference is the entire point of the assessment:
- A vulnerability is a specific weakness — an unmonitored side door, a gap in perimeter lighting, an access control policy that isn’t enforced.
- A threat is a source or hazard that could exploit that weakness — anything from an opportunistic intruder to a disgruntled former employee to a natural hazard like an earthquake.
- Risk is what you get when you combine them with consequence: how likely is this threat to exploit this vulnerability, and how bad would the outcome be if it did?
A building can have vulnerabilities with very little associated risk — a rarely used, out-of-the-way door with no valuable contents nearby — and a smaller vulnerability that carries serious risk because of what it protects. A proper assessment doesn’t just list weaknesses. It weighs them against real threats and consequences, so you know which ones actually deserve attention first.
What a Physical Security Risk & Vulnerability Assessment Actually Examines
A thorough assessment looks across the full environment, not just the perimeter fence:
- Access control — how entry is managed, credentialed, and enforced across every point, not just the main entrance
- Surveillance and technology — camera coverage, placement, blind spots, and whether footage is actually monitored
- Personnel deployment — where security staff are positioned and whether that matches where the actual risk is concentrated
- Perimeter and barriers — fencing, vehicle standoff distance, and physical boundaries between public and controlled space
- Threat assessment — a look at who or what could realistically pose a risk to this specific facility, not a generic list
- Communications — how staff report and respond to a developing situation, and whether that process actually works in practice
- Life safety and fire suppression — systems and protocols that keep people safe during an emergency, physical security or otherwise
- Emergency plans and drills — whether a plan exists in writing and whether anyone has actually practiced it
- Environmental conditions — lighting, sightlines, landscaping, and anything about the physical surroundings that affects risk
This is the same framework — scaled to the environment — that I used conducting the independent Risk and Vulnerability Assessment of the Pennsylvania Governor’s Residence following the April 2025 security breach and arson attack there. The categories don’t change much between a governor’s residence and a commercial office building; what changes is which of them carries the most weight for that specific property.
Why Cybersecurity Content Keeps Showing Up When You Search This
It’s worth naming the problem directly: “risk assessment” and “vulnerability assessment” are also standard cybersecurity terms, and there’s far more content published about IT risk assessments than physical ones. If you’re a facilities manager, property owner, or business leader asking this question, that content isn’t wrong — it’s just answering a different question. Some organizations genuinely need both a physical assessment and a cybersecurity assessment, run by different specialists with different expertise. Neither substitutes for the other.
How Often Should a Business Get One?
At minimum, annually. Beyond that baseline, a new assessment is warranted after:
- A change in location, layout, or a new lease
- A security incident, even a minor one
- A merger, acquisition, or change in leadership
- A meaningful increase in the company’s or its leadership’s public visibility
- Any material change to the surrounding area — new construction, a change in neighboring tenants, or a shift in the local risk environment
This overlaps with the broader question of when a company should bring in outside security expertise at all — a risk and vulnerability assessment is often the specific engagement that answer points toward.
Who Should Perform One
An independent, third-party assessment carries advantages an internal review generally can’t match: objectivity from people who aren’t used to the property’s daily quirks, broader pattern recognition from having assessed many different environments, and credibility with boards, insurers, and legal counsel that an internal review often doesn’t carry the same way. We cover this distinction in more depth in our piece on choosing between internal security staff and an outside consultant.
A Related Question: How Is This Different From a Security Audit?
These terms get used loosely, including on our own site, so it’s worth being precise. A security audit — see our corporate office security audit guide — typically checks specific items against a defined standard: is this door locked, is this camera working, is this policy being followed. A risk and vulnerability assessment goes further: it evaluates those findings against actual threats and consequences to produce a prioritized risk picture, not just a list of items to fix. In practice, a good assessment often includes an audit as one of its components, but the reverse isn’t always true.
Los Angeles-Specific Factors That Change the Assessment
Los Angeles isn’t a generic backdrop for this kind of work — several things about the city genuinely change what an assessment needs to weigh:
- High-rise density in Downtown LA. Buildings like the US Bank Tower and the Wilshire Grand present vertical evacuation challenges, floor-by-floor access control questions, and elevator lockdown procedures that a single-story suburban facility simply doesn’t face.
- Multi-tenant campuses in Century City and West LA. Shared perimeter responsibility between property management and individual tenants is a common gap — everyone assumes someone else owns a given control point.
- Entertainment and studio properties in Burbank, Culver City, and Hollywood. These sites carry unique access control needs tied to protecting productions, sets, and high-profile talent, layered on top of standard commercial security.
- High-value retail corridors like Beverly Hills and the Grove carry a different threat and consequence profile than a typical office building, driven by both merchandise value and brand exposure.
- Seismic risk. Los Angeles’s earthquake exposure means a genuine facility risk assessment has to account for structural and life-safety factors that a similar assessment in a lower-seismic region wouldn’t weigh as heavily.
- Documented history of civil disturbance in certain commercial corridors. A serious risk assessment accounts for this as a known factor in the surrounding environment, the same way it would account for any other documented local risk pattern.
- Media and public visibility. Los Angeles’s concentration of entertainment and media companies means both corporate facilities and executives — see our note on executive protection considerations — often carry more public exposure than a comparable business elsewhere.
Our broader piece on security risk assessments for Los Angeles businesses covers more on how this plays out for organizations in the region, and companies planning events with high-profile attendees may also find our piece on VIP and executive security at Orange County company events useful, since the LA and OC markets share many of the same visibility-driven risk factors.
Frequently Asked Questions
1. What is a security risk and vulnerability assessment?
It’s a structured evaluation that identifies specific weaknesses in a facility or organization, the threats that could exploit them, and the likely consequences, producing a prioritized set of findings rather than a generic checklist.
2. What’s the difference between risk and vulnerability in physical security?
A vulnerability is a specific weakness; risk is what results when that vulnerability is combined with a realistic threat and a meaningful consequence. A facility can have vulnerabilities that carry little actual risk, and smaller ones that carry significant risk depending on what they expose.
3. Is a security risk assessment the same as a cybersecurity risk assessment?
No. They share terminology but are entirely different disciplines — one addresses physical facilities, people, and environment; the other addresses networks and data. Many organizations need both, performed by different specialists.
4. What does a physical security risk and vulnerability assessment typically examine?
Access control, surveillance and technology, personnel deployment, perimeter and barriers, threat assessment, communications, life safety systems, emergency planning, and the surrounding environmental conditions.
5. How often should a business in Los Angeles get a security risk assessment?
At minimum annually, and again after any significant change — a new location, an incident, a leadership change, or increased public visibility.
6. Who should conduct a security risk and vulnerability assessment?
An independent third party generally provides more objectivity and broader pattern recognition than an internal team, and typically carries more weight with boards, insurers, and legal counsel.
7. What’s the difference between a security audit and a risk and vulnerability assessment?
An audit checks specific items against a standard; a risk and vulnerability assessment evaluates those findings against real threats and consequences to produce a prioritized risk picture. An assessment often includes an audit as one component.
8. Do earthquake and seismic risk factor into a security risk assessment?
For Los Angeles properties, yes — structural and life-safety considerations tied to seismic risk are a genuine factor in a thorough facility assessment, distinct from but related to physical security planning.
9. Does company size determine whether a business needs this kind of assessment?
Not primarily. Risk is driven more by a facility’s location, visibility, and specific vulnerabilities than by company size alone — a smaller, high-visibility business can carry more risk than a larger, lower-profile one.
10. How do I get a security risk and vulnerability assessment for my Los Angeles property?
Book a consultation to discuss your specific property and situation — scope is determined by what your assessment actually needs to cover, not a fixed package.
If you searched this question expecting a firewall diagram and got one, you were looking for something else entirely. A physical security risk and vulnerability assessment is about your building, your people, and your surroundings — and in a city with the density, visibility, and seismic exposure of Los Angeles, it’s worth getting a genuinely thorough one rather than a generic checklist.
For more information on what an assessment would involve for your Los Angeles property, book a consultation with Jeffrey Miller Consulting, or learn more about our Risk & Vulnerability Assessment services directly.

