Soft target threat analysis
Audits for companies
Security audit of the company and workplace
Perimeter, reception, people, evacuation, cyber continuity. We will convert the weak points to measure.
An audit must end with a decision, not a PDF document in a drawer
A regular security agency will often sell the service. We first show the management exactly where the risk arises, what has the biggest impact and what makes sense to pay first.
The audit connects the object, people, documentation and crisis mode. The output is built so that the director, mayor, board and operations manager can work with it.
Object
entrances, routes, zones and points of first contact
Documentation
crisis plan, GDPR, camera mode and responsibilities
Risk
probability, impact, priority and budget of measures
Map of weak points
First, the place where the risk arises is walked. Only then is a recommendation made.
What is most at risk?
What to fix first
What to defend with the budget
1-3 days
On-site visit
20-50 pages
Structured output
5 areas
Perimeter · People · IT · Crisis · Operations
100 %
Confidentiality (NDA)
We audit where error is not permissible
We audit using the same methodology public institution, company headquarters, retail and production premises.
Workplace audit + staff training
Safety assessment of operation
Company security starts at the operational edge
Practical impact
Reception, entrances, parking and people must work as one mode.
Workplace audit will connect physical security, reception, visitor regime, evacuation and crisis management. We don't just deal with the building, but how people actually move in traffic.
- 01
Headquarters and HQ
Corporation: Reception, visitor areas, executive team, access.
- 02
Stores and OC
Retail: Attendance, de-escalation, evacuation, security.
- 03
Hotels, gastronomy, events
Hospitality: Guests, staff, events, mass incident.
- 04
Production premises
Industry: Perimeter, inputs, operation, OT/SCADA continuity.
Not just a security agency. System security of the company
Competition is protected by agency. You can have audit, building management, people training and crisis communication in one system.
01
Auditors from URNA, SOG and the 601st Group — not theory
We assess workplace weaknesses through the eyes of an attacker, not according to a checklist.
02
Accredited institution, compliance with ČSN 73 4400 and methodology MV ČR
Accreditation MV ČR, ČSN 73 4400 and soft target protection methodology.
03
References where error is not allowed
Czech Radio, National Theatre, Ombudsman, Academy of Sciences of the Czech Republic.
04
Audit + follow-up training from one hand
We convert recommendations straight into reception, security and management training.
What does a workplace audit cover?
Perimeter and entry control
Who and where to the premises and building
Reception and visiting regime
The first point of contact and its weaknesses
Cameras, EMS and access control
Electronic protection and its coverage
Evacuation and escape routes
Routes, collection points, coordination with IZS
Employee readiness
De-escalation, lockdown, crisis communication
Crisis management and continuity
Mass incident and traffic recovery
Continuity with IT / OT
Physical and cyber security together
Documentation and annual review
Status vs. ČSN 73 4400 and methodology MV ČR
How the audit takes place
- 01
Input risk analysis
Study of security documentation, crisis plans, previous incidents and links to the insurance company. Interview with management and security manager.
- 02
Physical assessment
Audit of the perimeter, entrances, reception, CCTV, access control, parking, collection zones and evacuation routes — according to ČSN 73 4400 principles.
- 03
People and procedures
Evaluation of the readiness of security, reception, key employees and management. Model situation of de-escalation and crisis communication.
- 04
Output for management
Structured audit with prioritized recommendations, cost estimate and follow-up training plan. Usable for risk management and insurance companies.
Workplace audit, shot by shot
The perimeter, reception, access systems and evacuation routes — that's what a traffic inspection looks like.
Frequently asked questions
What is a company security audit and what do we get as an output?
The company's security audit is an independent assessment of the physical security of the workplace — the perimeter, entrances, reception, cameras, evacuation routes and employee readiness. The output is a structured document (usually 20-50 pages) with prioritized recommendations, a cost estimate and a follow-up training plan. The assessment is based on the ČSN 73 4400 standard and the MV ČR methodology for the protection of soft targets.
Who is the workplace audit intended for?
For employers and company management across fields: corporate headquarters and HQ, retail and business centers, hotels, gastro and event operations as well as production and industrial premises. It is typically ordered by a security manager, operations director or executive who needs a verifiable risk assessment for management and the insurance company.
How much does a company security audit cost?
The price is determined individually according to the scope — the number of locations, the size of the area and the depth of the assessment. We offer everything from a short inspection of one building to a comprehensive audit of multiple operations. After a non-binding inquiry, we will return a specific scope and price proposal under NDA.
How long does the audit take?
The on-site visit usually takes 1-3 days depending on the number and size of the objects. We will typically process the written output within 10 working days of the last visit.
Is a company security audit mandatory?
There is no comprehensive statutory audit obligation for ordinary companies, but obligations arise from health and safety, fire protection and, for selected operations, from the protection of soft targets or cyber security (NIS2 / NÚKIB). The audit is primarily a prevention tool: it reduces the risk of an incident and serves as a basis for management and the insurance company.
Who conducts the audit and what are their qualifications?
The audit is led by former members of the URNA Police of the Czech Republic, the SOG of the Czech Army and the 601st Special Forces Group with experience from foreign missions. GBH Academy is an accredited educational institution with MV ČR accreditation; references include Czech Radio, the National Theatre, the Public Defender of Rights and the Academy of Sciences of the Czech Republic.
Does the audit follow up employee training?
Yes, we recommend it. The audit identifies weaknesses; follow-up accredited reception and security training, de-escalation and crisis communication for management will translate recommendations into people's real preparedness.
What next
An audit identifies weaknesses. Follow-up training will remove them
Reception, security, management. Accredited training builds on audit findings.
Related audits and training
Physical security audit for your business
Send segment, number of sites and priority. We will return the scope and price under NDA.
- Dlouhá 730/35, 110 00 Prague 1
- info@gbhdefence.com
- +420 252 548 480



