You will get a physical security risk assessment - threat, vulnerability and risk log


Project details
Most risk assessments sold online are a spreadsheet of generic risks with colours applied. That does not survive a question from an insurer, a board or an auditor.
This is built the way the profession builds them. I start from what you are actually protecting and what losing it would cost. I build a credible threat picture for your sector, location and operating pattern. I test your existing measures against each scenario and record where they fail. Only then is anything scored - and every score carries the reasoning that produced it, so it can be defended or challenged.
You receive an asset and criticality register, a threat assessment, a vulnerability assessment, and a scored risk log on a 5x5 matrix. Standard and Advanced add a treatment plan sequenced by risk reduction against cost, so you know what to fund first. Advanced adds a residual risk statement for sign-off.
20+ years in corporate security, Lieutenant Colonel, PFSO certified, 13 published books. Arabic and English.
My lane: physical, organisational and personnel security risk. Not cyber - no ISO 27001 certification work, SOC 2, or penetration testing.
This is built the way the profession builds them. I start from what you are actually protecting and what losing it would cost. I build a credible threat picture for your sector, location and operating pattern. I test your existing measures against each scenario and record where they fail. Only then is anything scored - and every score carries the reasoning that produced it, so it can be defended or challenged.
You receive an asset and criticality register, a threat assessment, a vulnerability assessment, and a scored risk log on a 5x5 matrix. Standard and Advanced add a treatment plan sequenced by risk reduction against cost, so you know what to fund first. Advanced adds a residual risk statement for sign-off.
20+ years in corporate security, Lieutenant Colonel, PFSO certified, 13 published books. Arabic and English.
My lane: physical, organisational and personnel security risk. Not cyber - no ISO 27001 certification work, SOC 2, or penetration testing.
Project Type
Business ConsultingWhat's included
| Service Tiers |
Starter
$400
|
Standard
$850
|
Advanced
$1,600
|
|---|---|---|---|
| Delivery Time | 7 days | 10 days | 14 days |
Number of Revisions | 1 | 2 | 2 |
Frequently asked questions
About Mostafa
Corporate Security & Business Continuity Consultant, ISO 22301, Author
Hurghada, Egypt - 6:44 am local time
My background: law enforcement (Lieutenant Colonel), UN field operations, U.S. Embassy fraud investigations, and corporate security leadership for a destination-scale hospitality and real estate developer — 25,000 residents, 18 hotels, 500+ guard force, 2,000+ cameras.
What I deliver on Upwork:
• Security Policy Pack — five cross-referenced policies (physical security, access control, CCTV, visitors & contractors, incident reporting), audit-ready
• SMB Business Continuity Plan — focused BIA, recovery objectives your operation can actually meet, activation structure — ISO 22301-aligned without enterprise bloat
• ISO 22301 Gap Analysis — clause-by-clause (4–10), scored findings, 30/60/90 remediation roadmap
Why clients pick me:
• The templates I use on your engagement are the ones I published — nothing improvised
• A rare combination in one consultant: physical security, investigations, and business continuity
• Bilingual Arabic/English — deliverables at native standard in either language, across MENA/GCC and beyond
• Fixed prices, defined deliverables, one full revision round; timelines run from receipt of your inputs
My lane is the organizational, physical, and continuity side that keeps operations running — not cyber (ISO 27001 / SOC 2 / pentesting).
Send your requirement and I’ll tell you within one business day whether it’s a fit, what it costs, and how long it takes.
Steps for completing your project
After purchasing the project, send requirements so Mostafa can start the project.
Delivery time starts when Mostafa receives requirements from you.
Mostafa works on your project following the steps below.
Revisions may occur after the delivery date.
Intake and threat picture
I establish what you are actually protecting and what losing it costs, then build a credible threat profile for your sector, location and operating pattern.
Vulnerability assessment and scoring
Your existing measures are tested against each credible scenario and where they fail is recorded. Only then is anything scored, and every score carries its reasoning.

