top of page

Security Technology Assessment & Gap Analysis

A Security Technology Assessment gives organizations an objective, current-state view of their existing systems: how they're configured, where they diverge from industry’s best practices, and what risk that divergence introduces.


Insite's assessments are conducted independently of any product, platform, or integrator relationship, so findings reflect the client's actual risk exposure. Each assessment provides an in-depth gap analysis of existing vulnerabilities and recommendations to resolve them.

Designing Secure, Scalable & Standardised Security Technology Environments

What a Security Technology Assessment Delivers

Our assessments are organized around the two central pillars of effective security technology: physical access control and video surveillance, along with how well each function is integrated with each other and with the broader business. Together, these systems help protect assets, safeguard personnel, and maintain a secure and compliant workspace.

Depending on portfolio size and system access, Insite combines platform review, on-site verification, a review of existing documentation, and structured discussions with facilities, IT, and security stakeholders. Each system component is evaluated against a defined best-practice standard. Each vulnerability discovered is documented, and every finding is paired with a specific, actionable recommendation.

Our Gap Analysis covers

01

Access Control System Evaluation

Insite evaluates access control hardware and software down to the reader and panel level across every in-scope location. This includes determining if:

  • Readers and panels are multi-system compatible, configured to Open Supervised Device Protocol (OSDP), and firmware is up to date
     

  • Whether the environment runs on a single, cloud-hosted platform or a patchwork of systems
     

  • Access control systems are supervised, credentials are provisioned and deprovisioned as necessary, and card data is encrypted and secure

02
 
Configuration, Permissions & Credential Review

Beyond what hardware exists, Insite examines how the system is configured and administered. This includes:

  • Review of administrator accounts and permission structures against the principle of least privilege, including identifying dormant accounts that retain elevated access
     

  • Identification of generic or shared credentials that undermine access history, and confirmation that former employees are automatically deprovisioned
     

  • Evaluation of credential and card format standardization across sites, including whether formats are encrypted and secure

03 

Video Surveillance Evaluation

Camera hardware and video management platforms are assessed with the same rigor applied to access control. This includes assessing:

  • Compatibility with open video standards and confirmation that firmware is current across every location
     

  • Verification that devices in use are National Defense Authorization Act (NDAA) compliant to eliminate the regulatory and procurement risk associated with equipment from prohibited manufacturers
     

  • Confirmation that cameras are mapped to their corresponding access-controlled doors

04 

IT Infrastructure & Network Dependency Assessment

Security technology increasingly relies on enterprise IT infrastructure. Insite reviews:

  • Network architecture, addressing schemes, and segmentation supporting security system traffic, including whether devices sit on an isolated VLAN
     

  • Dependencies on identity management, directory services, and single sign-on integration
     

  • Backup power and business continuity provisions for critical access points

05 

Benchmarking Against Industry Standards

Findings are measured against recognized industry best practices and enterprise security standards, giving leadership a clear reference point for how the organization's environment compares to peer organizations and where it falls short.

06 

Prioritized Remediation 

The assessment concludes with a sequenced implementation plan that dictates corrective actions by risk, cost, and operational impact.

 

Insite typically divides recommendations into immediate solutions, a coordinated mid-term phase, and longer-term iterative design work, giving stakeholders an organized  structure for budgeting and phased execution rather than a single, undifferentiated list of findings.

Case Study: Insite In Action
 

A global professional services firm operating roughly a dozen offices across North America, Europe, and Asia-Pacific engaged Insite to assess its security technology environment after a period of rapid office expansion left no single team with full visibility into how access control and video surveillance were being managed from site to site.

Insite's subject matter experts conducted a remote review of the firm's primary access control and video management platforms, supplemented by document review and structured discussions with facilities, IT, and security stakeholders. The review found that roughly a third of the firm's offices were still operating on legacy, discontinued, or otherwise disconnected systems outside the firm's primary cloud platform, with two different integrators on record and no consistent naming standard for doors, cameras, or credentials across sites.

On the video side, camera firmware had gone unpatched for over a year at most sites, cameras were not mapped to corresponding points of access, and one regional office was found to be running camera hardware later confirmed to be subject to U.S. federal procurement restrictions. No formal process existed for triaging system alerts, so alarms were generated but rarely reviewed by anyone with the authority to act on them.

Insite delivered a prioritized roadmap sequenced into three phases.

  • Phase I included firmware updates, standardizing security technology protocols and procedures, camera-to-door association, and notification configuration for the highest-risk doors.
     

  • Phase II planned to migrate remaining sites to a single primary platform, auditing administrator accounts down to a least-privilege standard, consolidating integrators, and replacing restricted camera hardware over the course of 6 months.
     

  • Through 12 months, Phase III introduced an iterative process to formalize a written security technology standard and migrate to a single, encrypted credential format.
     

The result was a single, coordinated security technology standard that replaced years of fragmented, site-by-site decision-making, giving the organization one consistent way of operating across every location.

Frequently Asked Questions

 

How long does a security technology assessment take?

Timelines vary based on portfolio size and the number of in-scope locations. A single-site or small-portfolio assessment can typically be completed in a matter of weeks, while enterprise-wide, multi-region engagements are scoped and sequenced across the sites that carry the greatest risk exposure first.

Does Insite need on-site access to conduct an assessment?

Not always. Many assessments begin with a remote review of the platform administration console, supported by a document review and stakeholder interviews, which allows Insite to evaluate configuration, permissions, and policy gaps without disrupting operations. On-site verification is layered in where physical conditions, such as device health, wiring, or hardware model, need to be confirmed in person.

Does the assessment recommend specific products or vendors?

No. The assessment is intentionally vendor-agnostic. It documents the current state and benchmarks against best practice; the process of selecting specific software, hardware, and systems is addressed separately during the design phase.

What happens after the assessment is complete?

Findings are delivered as a prioritized remediation process that sequences corrective action by risk and cost. From there, most organizations move into system design or platform modernization work, depending on whether legacy systems are being replaced or a net-new standard is being established.

Does this assessment evaluate cybersecurity?

The assessment reviews IT infrastructure dependencies relevant to physical security systems, including network architecture and identity integration. It is not a substitute for a dedicated cybersecurity audit, though findings are shared with a client's IT and information security stakeholders as part of the process.

Start With a Security Technology Assessment

Gain a clear, independent understanding of your current environment, identify material gaps, and define a structured path to a unified security technology standard.

bottom of page