Get a demo

Rated, Never Priced: The Physical Security Risk Assessment Banks Need

Your institution prices credit risk, market risk, and operational risk to the dollar. It holds capital against them and defends them to examiners and insurers in a shared language. Then the conversation turns to the branches, trading floors, and data centers, and the evidence becomes a five-point rating scale that calls almost everything medium.  

A physical security risk assessment sits at the center of that gap. Most banks have plenty of them, one per site, and still cannot say which location out of two hundred carries the most exposure right now. The problem is not the quality of any single assessment. It is that security is the one risk function still reporting in a different language than the rest of the institution. 

 

Why Your Branch Assessments Never Line Up

The reviews themselves are rarely the problem. A large bank usually has more physical security documentation than anyone reads: branch security surveys, guard post orders, partner-provider assessments filed after each acquisition, insurance schedules refreshed at renewal.  

A large bank usually has more physical security documentation than anyone reads.

 

The trouble is that no two of them were built to be read against each other. A downtown branch carries a survey scored on one firm's five-point scale. A regional operations center was hardened to a different standard and never formally reviewed after the retrofit. A trading floor inherited in a merger runs on controls nobody has revisited since. None of them answers the question the risk committee actually asks.

And it is a precise question: not whether a site is secure, but which of two hundred is carrying the most exposure this quarter, and whether the next dollar is going there or to the location that made the most noise. Credit risk answers that with a model. Physical security answers it with a folder and a judgment call, so the budget conversation stalls the moment it leaves security's own office.

 

Where a Bank's Exposure Actually Concentrates

When the allocation is wrong, the loss does not spread itself evenly across the footprint. It pools. Insider risk is the clearest case. The average organization now absorbs $17.4 million a year in insider-related cost, up from $16.2 million two years earlier, and in a bank the physical side of that exposure is unusually concrete. Vaults, cash rooms, trading floors, and data halls are where privileged access stops being a permission and becomes a loss.  

The street outside also carries its own concentration. Insured losses from strikes, riots, and civil commotion climbed from negligible levels a decade ago to more than $8 billion between 2020 and 2024, and a branch network is a street-level footprint. A handful of downtown branches, where unrest usually gathers, absorb far more of that exposure than the quieter sites around them, in property damage, closed sites, and the safety of the people inside them.

Neither loss spreads across the whole network. Each one concentrates in specific sites, which is the argument for comparison in one line: budget money spread evenly lands hardest where the risk is lightest. 

 

Why Physical Security Is the Last Risk Function Without a Number

The reason this lasted is not neglect. Corporate security is the last risk function in a bank to receive quantitative tooling, and the lag shows only because the comparators sit down the hall. Market and credit risk went on models decades ago. Operational risk holds capital against measured loss. Cyber crossed to dollar exposure years ago and now briefs the board that way. Physical security stayed on an ordinal scale, where a site is labeled high or medium with nothing to say what it ranks against.

Corporate security is the last risk function in a bank to receive quantitative tooling.

 

So spending drifts toward whatever is most vivid. A branch robbery last quarter pulls budget to that address. A regional head with a sharp deck and a good relationship wins the upgrade. Each call holds up in isolation, and the portfolio still slides away from where the exposure actually lives. Only a number reorders that list, and physical security has never had one to put a dollar behind. 

 

What a Number Your Risk Committee Can Defend Looks Like

Fixing it does not mean commissioning deeper surveys. It means measuring every site the same way, so the result is an ordered list rather than a pile of ratings. The method a bank would recognize: find what each site would lose with only its structure to protect it, credit its controls for the loss they prevent, and read the difference as the exposure that remains. Express it in the losses behind it: the safety response an incident forces, the legal exposure when duty of care cannot be shown, the reputational cost of an event at a branch the community banks at. Done to that depth, the assessment stops being a snapshot and becomes the baseline your later budget requests, control decisions, and board reports get measured against.

Built this way, the output survives the room it was made for. It says which sites carry the most exposure and what a dollar moved there buys, and every figure traces to its driver the way an examiner or model validation team expects. It also keeps the evidence a regulator or examiner would ask for, which controls exist at which sites and in what condition, in one record rather than a scatter of site files.

Holtium is the risk operating system for corporate security: the platform a security team runs its program on, with experts alongside when they are needed. It pulls a bank's branches, campuses, trading floors, and data centers into one place, prices the exposure that remains, and turns it into an executive risk report the board committee can read beside every other risk function. Budget stops following the loudest problem and starts following the evidence, and a physical security risk assessment stops being a document that ages in a drawer and becomes a standing measure the team updates and defends as sites open, close, and change hands. The same comparability gap runs through a manufacturer's plant network, differently dressed. In a bank it is sharper, because everyone else in the building already reports in dollars, and only one function still cannot.

 

Back to All Holtium Insights