A national retail bank engaged us as armed-robbery exposure climbed across a branch network of more than 200 sites. Losses were rising, staff confidence was eroding, and the organisation lacked a single, defensible physical-security standard to hold its estate to. Our mandate was to bring proportion and consistency to how the network was protected, and to shorten the gap between an incident beginning and a coordinated response reaching it.
The challenge
Physical security had grown branch by branch over many years, which left protection uneven and difficult to assure. Two outlets a short distance apart could carry very different controls, and neither the security function nor branch managers could say with confidence where the real weaknesses sat. That inconsistency was driving losses and, just as corrosively, staff anxiety.
Response was the second weakness. Once an incident began, there was no centralised picture and no agreed doctrine for who acted, in what order, and to whom. Time that should have been spent containing a threat was instead lost to confusion, and the organisation had no reliable measure of how long its own response actually took.
Our approach
We began with an enterprise-wide risk assessment rather than a site-by-site audit, so that the bank could see its exposure as a portfolio and direct spend to where it mattered. The assessment graded branches against a common threat model and surfaced the small number of structural gaps that accounted for the majority of the risk across the estate.
From that evidence we re-engineered the physical security standard into a single, tiered specification that scaled with each branch's risk grade rather than applying one undifferentiated template. The standard was written to be auditable, so that compliance could be demonstrated to the board and to assurance partners, and proportionate, so that lower-risk sites were not burdened with controls they did not need.
We then stood up a centralised monitoring and response capability, giving the network the single operating picture and agreed response doctrine it had lacked. The workstreams were:
- An enterprise risk assessment grading every branch against a common threat model
- A re-engineered, tiered physical security standard aligned to each site's risk grade
- A centralised monitoring centre providing one operating picture across the estate
- A response doctrine setting out who acts, in what order, and through which channels
- An assurance framework so compliance with the standard could be evidenced to the board
The outcome
More than 200 branches were brought under the new standard and the centralised capability, giving the bank, for the first time, a consistent and demonstrable level of protection across its estate. With monitoring and response coordinated from a single centre, incident response time fell by 41 per cent.
The operational gains carried straight through to the balance sheet. Loss events declined by 28 per cent year on year, and the combination of clearer standards and faster, coordinated response did as much for staff confidence as it did for the numbers.
For the first time we can say, branch by branch, exactly how we are protected and how quickly we will respond. That is what changed the conversation with our board.
What made the uplift durable was that it was built on a standard the organisation could own and assure, not on a one-off intervention. Because protection was tiered to risk and response was governed by a clear doctrine, the bank can extend the model to new branches and hold the whole estate to the same proportionate, defensible benchmark.
