Security Risk Assessment for Multi-Tenant Commercial Buildings


0
Modern office lobby with turnstiles, elevators, and a red access-control line.
Shared access points shape building security

A building can have excellent locks, smart cameras and a staffed reception, yet still leave a straightforward route for the wrong person to enter. In shared premises, the weak point is often the handover between landlord, tenant, contractor and security team.

A security risk assessment gives those parties a shared view of the building’s critical assets and overall security posture. It clarifies where responsibility begins and ends, and what happens when normal routines fail. It should cover people, premises, data and building systems, not just one of them.

The starting point is simple: a security risk assessment should reflect how people actually use the building, including after hours.

A security risk assessment is a shared building exercise

A single-occupier site has one set of priorities and one management structure. Multi-tenant buildings rarely work that way. A landlord may control reception, lifts, the car park and loading bay, whilst tenants control their suites, staff records, visitors and sensitive equipment.

That division matters. An unattended delivery entrance may be a landlord issue, but a contractor gaining access through it can affect every occupier. A compromised access-control account may sit with an IT supplier, yet allow entry to common areas. The assessment is therefore a shared risk management process, with ownership and approval authority documented.

Security, privacy and fire safety have different duties

These areas overlap, but physical security, information security, privacy and fire safety have separate duties. Security measures can support safe evacuation, but access arrangements must never obstruct fire-safety duties. CCTV can help investigate an incident, but it must also meet data-protection requirements.

For camera systems, recording retention, viewing permissions and signage all contribute to proportionate regulatory compliance. For UK organisations, the ICO’s video-surveillance guidance for organisations is a sensible reference point, but it isn’t a complete legal checklist.

The assessment needs clear boundaries

Start by recording who owns each risk and who can approve a control. That includes the building owner, managing agent, facilities team, security provider, tenant contacts, IT suppliers, cleaning contractors and emergency services liaison.

A vague division of responsibility is not a control. It is usually where the problem begins.

Map the building before rating the risk

An assessment built around a generic checklist misses the details that make a shared building vulnerable. Walk the site at opening time, during the working day and after normal trading hours. The building changes character across those periods.

Two professionals review a building plan beside a model with red-marked risk points.

Separate shared, tenant and restricted areas

Create an asset inventory covering critical assets, public, shared, tenant-controlled and restricted spaces. Include reception, post rooms, corridors, lifts, stairwells, toilets, car parks, bike stores, roof access, vacant units, loading bays, plant rooms and comms cupboards.

Mark the routes between them. A visitor should not be able to move from a public lobby to a service corridor merely by following someone through a door. The same applies to delivery drivers, cleaners and contractors working outside office hours.

The NPSA’s security planning guidance supports a proportionate site security plan. Proportionate does not mean decorative. It means controls match the asset, threat and likely consequence.

Include connected building systems

A proper security risk assessment also covers the systems that run the site: access cards, intercoms, visitor-management tools, CCTV, building-management systems, gate controls, smart locks and remote maintenance connections. Together, they expand the building’s attack surface.

List who administers each system, where data is held, who can add or delete users, and what happens if the supplier cannot be reached. Consider cloud security, particularly for supplier-hosted visitor, access or maintenance platforms. A plant room door controlled by an app is still a physical-security issue, even when the fault sits in a cloud service.

Zero trust principles help verify identity, authorisation and device or supplier access, rather than assuming a connected account is trustworthy. Recording ownership, permissions, data location and fallback arrangements supports continuous risk assessment.

Identify realistic threats and weak points

The useful question in a practical vulnerability assessment isn’t “what could happen in theory?” It’s “how could someone exploit this location, at this time, using the access available to them?”

Look beyond forced entry

Many incidents don’t begin with a broken lock. They begin with someone being held a door open, an unchallenged visitor, a lost fob that remains active, a delivery left in the wrong place or a contractor using an expired pass.

Consider theft, violence, vandalism, unauthorised occupation, arson, sabotage, protest activity, fraud, data breach and disruption. Physical access can also expose devices, credentials and network points, linking security incidents to cyber risk.

Then consider the threat actors who might cause it: opportunistic offenders, organised criminals, former contractors or someone seeking entry to a particular tenant. Include insider threats, such as disgruntled staff or people with legitimate access.

Test ordinary routines under pressure

Observe what happens when reception is busy, a lift is out of service, a fire alarm sounds or a tenant hosts an evening event. Check whether guards and reception staff know which tenants have after-hours access, who can authorise a visitor and when escalation is required. These observations should feed continuous risk assessment, rather than being treated as a one-off exercise.

The most revealing control test is often a routine exception: a delivery at 21:00, a lost pass at 07:00, or a contractor who says they were expected.

Treat visitors and contractors with a proportionate zero trust approach. Verify identity, authorisation, purpose and expiry rather than relying on familiarity or a verbal assurance.

Tenant privacy matters here. Building management may need confirmation that a visitor is expected, without receiving details of a tenant’s business, staff movements or client meetings. These findings help prioritise practical mitigation strategies while limiting tenant information to what building management genuinely needs.

Rate likelihood, impact and ownership

Risk ratings don’t need false precision. They need a consistent method that lets decision-makers compare concerns and decide what happens next.

Use a simple qualitative rating

Agree what low, medium and high mean before the assessment starts. Use the table to compare likelihood and impact consistently. Likelihood should consider opportunity, existing controls, incident history and the ease of avoiding detection. Impact should include harm to people, disruption, loss, reputational damage, tenant confidence and regulatory exposure.

RatingLikelihood or impact descriptionUsual response
LowUnlikely or limited effect on one areaRecord and review through normal management
MediumCredible scenario with material disruptionAssign an owner and set a treatment date
HighPlausible exposure with serious harm or major disruptionAct promptly, then test the revised control

A high impact doesn’t automatically mean a high overall risk. A locked roof plant room may have serious consequences but limited opportunity for access. The assessment should show that distinction plainly.

Write a risk statement that can be acted on

A risk register is where observations become decisions. Use it to select proportionate risk mitigation, with each action linked to an owner and treatment date. Avoid entries such as “loading bay insecure”. State the cause, event and consequence.

Risk statementExisting controlsAction ownerTreatmentTreatment date
An unauthorised person could enter through the loading bay during evening deliveries, leading to access to shared corridors and tenant property.Door release, delivery log, CCTV coverageManaging agentReview delivery protocol, access permissions and out-of-hours supervision as mitigation strategiesTo be agreed by the managing agent

Where reliable figures exist, financial loss estimates can support board reporting. They shouldn’t replace judgement. The immediate priority may be preventing harm, protecting a tenant’s confidential material or keeping essential building services available.

The NIST guide for conducting risk assessments frames assessment around threat and vulnerability, alongside impact. That remains a practical structure for commercial property, even though the cited publication isn’t property-specific.

Put layered controls around shared access

No single control solves a multi-tenant problem. Effective security controls address different parts of the risk. Cameras do not stop tailgating. A guard cannot correct poor access control or permission processes. A locked door is only useful if it closes, latches and is not routinely wedged open.

Office lobby with a reception desk, visitor kiosk, turnstile, and service gate.

Match controls to the actual route of entry

A layered approach may include staffed reception, visitor pre-registration, access cards with expiry dates, door alarms, secure key cabinets, lighting, patrols, intercom verification and monitored CCTV. These mitigation strategies should reflect the building’s operating hours, tenant profile and routes of entry.

For example, a building with late-working legal or financial tenants may need stricter visitor procedures than a daytime-only office block. A mixed-use property may need separate routes for residents, retail deliveries and office staff.

Test controls and incident response

Test a sample of access cards, emergency contacts, CCTV retrieval, door-release functions and contractor sign-in records. Check cloud security dependencies in visitor-management, access or monitoring platforms, including account offboarding and supplier availability. For remote administration and privileged access, apply zero trust by verifying identity, authorisation and need rather than assuming trust from a supplier relationship.

A response procedure should say who calls police or emergency services, who meets them on site, how tenants are notified, and who preserves footage or protects access logs. Keep personal information limited to what the role requires.

Keep the assessment current, not filed away

Buildings change more often than risk registers suggest. A new tenant, empty floor, refurbishment, change in security provider or updated access platform can alter the exposure overnight and weaken the building’s security posture.

Review after a meaningful change

Set review points after incidents, near misses, repeated false alarms, tenancy changes, major works and changes to building use. Scheduled management reviews still matter, but they should not be the only trigger.

A continuous risk assessment can include reviewing forced-door alerts, access exceptions, patrol findings, supplier changes and recurring visitor issues. Supplier reviews should check former accounts, excessive privileges and trusted third parties for insider threats, using zero trust verification for privileged or remote access.

Use recognised guidance without treating it as a template

NIST SP 800-30 offers a disciplined assessment method. The NIST Cybersecurity Framework 2.0 can help where building systems, tenant networks and supplier access create cyber risk.

A cyber security risk assessment can cover connected systems, hosted access, cloud security and maintenance services, but it complements rather than replaces the physical assessment. NPSA guidance is useful for physical-security planning, while ICO guidance applies where surveillance processes personal data. Information security arrangements should connect tenant networks, building systems and personal or operational data.

Requirements vary by location, building type, occupancy and industry, so legal, fire-safety and data-protection advice may be needed for the individual site. The review should then update practical mitigation strategies as conditions change.

Key Takeaways

  • Map every shared route, restricted space and connected building system before selecting controls.
  • Give each risk a named owner, a treatment action and a review point.
  • Rate likelihood and impact consistently, without pretending every risk can be reduced to a perfect number.
  • Treat tenant privacy, fire safety, cyber security and physical security as connected issues with separate duties.
  • Revisit the assessment when building use, tenancy, contractors or access arrangements change, and update the relevant mitigation strategies.

Frequently asked questions

Who should lead the assessment?

The property owner or managing agent should normally appoint a lead with authority to bring the right people together. That may be a security director, facilities manager or external security professional.

Tenant representatives, IT leads, reception teams and key contractors should contribute evidence. They should not be asked to take responsibility for risks outside their control.

How often should a security risk assessment be reviewed?

There is no single timetable that suits every site. Carry out a full review at a sensible planned interval, then revisit relevant risks after an incident, major works, a tenant change, a new system or a change to opening hours.

A live risk register is more useful than a polished annual document that no one checks.

Is CCTV enough for common areas?

No. CCTV may deter some behaviour and support investigation, but it does not decide who enters, challenge an unauthorised person or secure an open service door.

Treat it as one of several security controls, alongside access control, clear operating procedures and trained personnel. Recording footage without a clear purpose, access rules and retention arrangements creates a separate privacy issue.

A safer building is one with clear ownership

The strongest security risk assessment isn’t the one with the longest spreadsheet. It’s the one that shows real entry routes, assigns responsibility and produces controls people can operate properly.

Shared buildings need shared awareness, with firm boundaries around who does what. When responsibilities are documented and controls are tested, they form the basis for effective mitigation strategies and more reliable routine security.


Like it? Share with your friends!

0

What's Your Reaction?

hate hate
0
hate
confused confused
0
confused
fail fail
0
fail
fun fun
0
fun
geeky geeky
0
geeky
love love
0
love
lol lol
0
lol
omg omg
0
omg
win win
0
win

0 Comments

Your email address will not be published. Required fields are marked *

Cookie Consent with Real Cookie Banner