
A construction security risk assessment identifies what needs protecting on your site and ranks the threats against it, so you spend money and manpower on the exposures that actually matter. It follows five steps: scope the site, identify the threats, prioritise them by likelihood and consequence, mitigate with the right controls, and review on a set schedule.
Start today by walking the perimeter and listing every high value asset before you touch a checklist. That single walk tells you more about your real exposure than any generic template.
- Define the scope: boundaries, access points, high value zones
- Identify threats: theft, unauthorised access, vandalism, arson
- Prioritise using a likelihood/consequence matrix
- Mitigate with controls matched to the hierarchy of control
- Review on a fixed cadence and after triggering events
The Model Code of Practice for construction work sets out this exact process, and Abcosecurity’s own assessment templates follow the same structure so you can start filling one in immediately.
Key Takeaways
A construction security risk assessment works when it follows a fixed cycle, scope, identify, score, mitigate, review, and produces a written risk register that drives every control decision.
| Point | Details |
|---|---|
| Start with the site map | Walk the perimeter and mark access points and high value assets before scoring anything. |
| Separate life safety from asset risk | Unauthorised public access is a distinct, often higher priority risk than theft. |
| Use a simple matrix | Score likelihood and consequence to rank threats before choosing controls. |
| Follow the hierarchy of control | Eliminate or isolate hazards first, then engineer, then rely on procedures and patrols. |
| Abcosecurity supports the full cycle | Its templates and construction security services help build, implement, and monitor the assessment. |
Where to check the official guidance
- Model Code of Practice — Construction Work
- SafeWork NSW site security checklist
- Abcosecurity’s construction site security guide
Table of Contents
- How do you run a construction security risk assessment step by step?
- What are the biggest security risks on a construction site?
- Which security controls should you use and in what order?
- What documentation do WHS inspectors and insurers expect?
- What most site managers get wrong about security planning
- Get a security risk assessment built for your site
- Sources
- FAQ
How do you run a construction security risk assessment step by step?
Every assessment starts with scope, not a spreadsheet. Walk the site with a printed plan or a tablet and mark the perimeter line, every gate and pedestrian access point, delivery zones, and where the expensive gear sits, plant, generators, copper, timber packs, anything a thief could move in under ten minutes. Photograph weak points as you go. This single walkthrough usually reveals more than any desk-based review, because site conditions change week to week and plans on paper rarely match what is actually built.
Threat identification comes next, and it splits into two lanes that get confused too often. One lane is asset protection: theft, vandalism, arson. The other is life safety: unauthorised people, particularly children, wandering into an active site. WorkSafe WA’s guidance on unauthorised access treats the second lane as the more urgent one, because a member of the public who climbs through a gap in the hoarding does not know which excavation is live and which is backfilled.
- Scope the site — map the perimeter, access points, and asset locations on a current site plan
- Identify threats — separate life safety risks (public access, children, trespassers) from asset risks (theft, vandalism, arson)
- Score each threat — rate likelihood (rare to almost certain) and consequence (minor to catastrophic) to build a ranked list
- Mitigate top risks first — assign controls to the highest scoring items before spending on lower priority ones
- Document and review — record decisions in a register and set a date to revisit it
Scoring is where most site managers either overcomplicate things or skip it entirely. You do not need a statistician. Rate likelihood on a simple scale, rare, possible, likely, almost certain, and do the same for consequence, minor, moderate, major, severe. Multiply or plot the two on a grid and you get a ranked risk register, which is the single most useful document to come out of this process.
Three outputs should exist by the end of this stage:
- A marked site map showing perimeter, gates, cameras, lighting, and asset storage
- A risk register listing each threat, its score, and the proposed control
- A mitigation plan assigning who does what and by when
A site in its early civil works phase, for instance, might score “unauthorised access via unfenced boundary” as almost certain and major, given open excavations and no hoarding yet. That single line item in the register then drives the very first fencing order, before framing even starts. Abcosecurity’s security risk assessment checklist is built around this same scope, identify, score, mitigate sequence, so you can drop your site map and register straight into it rather than starting from a blank page.
What are the biggest security risks on a construction site?
Five categories account for most incidents: theft of materials and plant, vandalism, unauthorised access, climbing hazards on cranes and scaffolds, and arson. Which ones matter most on your site depends heavily on context, not just category.
A site next to a primary school carries a different risk profile to one on an industrial estate three kilometres from the nearest house. Proximity to schools, parks, or foot traffic raises the likelihood of unauthorised entry, and WorkSafe WA flags this as a genuine life safety concern, not just a nuisance. Remote or semi rural sites, by contrast, tend to see more equipment theft because response times for police or patrols are longer and there are fewer eyes on the property overnight.
Timing matters as much as location. Periods with reduced visibility such as night shifts, long weekend shutdowns, and major delivery windows are regularly recognized as high risk times, since asset value on site tends to be at its peak and unguarded plant deliveries present tempting targets.
Run these through a 5×5 matrix and the priorities usually sort themselves fast:
- Unfenced perimeter near a school, early civil phase: almost certain likelihood, major consequence, treat as top priority
- Overnight theft of hand tools from a locked container, established site: possible likelihood, moderate consequence, mid priority
- Arson risk to combustible waste piles, isolated site: unlikely likelihood, severe consequence, mid to high priority depending on fire season
- Scaffold climbing by local youths, urban infill site: likely likelihood, moderate to major consequence, high priority
Anything that lands in the “likely or almost certain” band combined with “major or severe” consequence goes to the top of your mitigation list, full stop. Everything else gets scheduled, not ignored.
Which security controls should you use and in what order?
Security decisions follow the same hierarchy of control used for safety hazards: eliminate the risk first, then substitute or isolate it, then engineer it out, then rely on administrative procedures, and only lean on personal vigilance or PPE-level measures last. Applied to security, that looks like removing high value assets from site overnight where practical, isolating hazardous zones with dedicated barriers, engineering out access with fencing and lighting, backing that with procedures, and using patrols or guards to cover what physical controls cannot.
Physical controls come first because they work without anyone needing to remember a procedure.
- Hoarding and fencing — chain mesh or solid hoarding at a height and standard that resists casual climbing, checked regularly for gaps or storm damage
- Gate control — a single controlled entry point wherever the site layout allows it, rather than multiple gates nobody is watching
- Secure storage — lockable containers for tools and small plant, bunded and away from the perimeter line
- Hazard isolation — dedicated barriers and signage around excavations or live scaffolds when full perimeter fencing is not practical, a common situation on staged builds
SafeWork NSW’s site security checklist covers exactly this ground, right down to checking gate locks and isolating utilities before a long weekend shutdown.
Operational controls sit underneath the physical layer. Delivery protocols, so a driver cannot simply wander the site looking for someone to sign for a load, key control registers, and a sign in process for subcontractors all reduce the number of people who can access an area without someone noticing.
Technology adds reach where physical controls run out. Lighting on entry points and asset storage areas is cheap and genuinely effective. CCTV works best when cameras cover choke points, gates and container doors, rather than being scattered for general coverage. Mobile surveillance units and monitored alarms extend cover to sites without permanent power or during phases when a fixed camera network is not yet installed. None of these are a substitute for a locked gate; they are there to detect and respond to whatever gets through.
Pro Tip: Cameras deter more effectively when the signage is visible from outside the fence line, not just inside it. A sign a trespasser sees before they climb is worth more than the footage you review after they have already left with your gear.
Patrols or a professional construction security service earn their cost on sites with high value plant, extended shutdown periods, or a history of incidents, where the register clearly shows administrative controls alone are not closing the gap.
What documentation do WHS inspectors and insurers expect?
Regulators and insurers both want evidence of a considered process, not proof you bought a camera. Regulation 298 of the WHS framework requires the person managing the workplace to secure it from unauthorised access so far as reasonably practicable, and to show that assessment in writing.
Keep these records current and accessible:
- Site map marking perimeter, access points, cameras and lighting
- Risk register with likelihood and consequence scores for each threat
- Mitigation plan naming who is responsible for each control and by when
- Incident log recording every breach, near miss, or theft, however minor
- Monitoring and maintenance records for cameras, alarms and fencing
- SWMS for any high risk construction work intersecting with security measures, such as scaffold access controls
Insurers reviewing a claim after a theft or break in almost always ask for the risk register and incident log before anything else. A folder with these six items, updated rather than filed and forgotten, does more for a claim than a single expensive gadget ever will.
When should you reassess site security?
Reassess weekly during high activity phases, such as early civil works or major fit out, and at every project milestone change, slab pour, frame complete, services fit off. Between those points, five triggers demand an immediate reassessment regardless of the calendar: a major delivery, a change of subcontractor with site access, any incident or near miss, a severe weather event, and an extended shutdown such as a holiday period.
- Weekly checks during high tempo phases
- Milestone reviews at each major phase change
- Immediate reassessment after any of the five triggers above
- Site manager authorises the reassessment and controls
- Notify the project supervisor and update the risk register within 24 hours
ABCO templates you can use right now
Abcosecurity publishes three resources built directly around this process. The security risk assessment checklist gives you a structured place to drop your site map, asset list, and scoring. The ‘7 Steps to Build a Construction Site Security Plan’ walks through mitigation planning stage by stage. The ‘Security Risk Assessment Template 2026’ extends both into a full register with review dates built in. Abcosecurity’s guidance draws on more than 15 years in the security industry and alignment with ISO 9001 and ISO 30000 standards, which is why the templates map so closely to what regulators actually ask to see.
What most site managers get wrong about security planning
The biggest mistake is treating a construction security risk assessment as a one off document filed after the site establishment meeting, never revisited until something goes missing. That approach misreads what the regulation actually asks for. The Model Code of Practice describes risk assessment as a cycle, identify, control, review, not a form you tick once.
Conventional advice also over indexes on cameras and under indexes on the boring administrative layer, delivery protocols, key registers, sign in sheets. Technology gets attention because it is visible and easy to sell. But a site with excellent CCTV and no delivery protocol still has a driver wandering the yard looking for someone to sign for a load, and that is exactly the kind of gap a thief or an unauthorised visitor exploits.
If there is one thing worth prioritising above the rest, it is the risk register itself. Not the fencing, not the alarm system, the written, scored, dated register that shows you thought about likelihood and consequence before you spent a dollar on controls. Everything else, patrols, cameras, lighting, should trace back to a line item in that document. Sites that skip straight to buying equipment without that register tend to overspend on the wrong things and underspend on the boring controls that actually close the biggest gaps.
Get a security risk assessment built for your site
Reading a checklist gets you started; having a licensed team walk the perimeter with you gets the gaps closed. Abcosecurity runs full construction security risk assessments backed by 24/7 monitoring, mobile patrols, and CCTV installation, so the controls your register calls for actually get installed and maintained rather than sitting on a to do list.
That matters most on sites juggling multiple subcontractors and shifting phases, where a site manager rarely has spare hours to chase fencing contractors and camera installers separately. Abcosecurity’s construction site security management service handles the register, the controls, and the ongoing monitoring as one package, aligned to ISO 9001 and ISO 30000 standards. If your last assessment is more than a few months old, or you are moving into a new project phase, request a site walkthrough and get your risk register and mitigation plan reviewed by a licensed team.
Sources
- Model Code of Practice — Construction work (Safe Work Australia)
- Site security checklist (SafeWork NSW)
FAQ
What are the five steps of a security risk assessment?
The five steps are scoping the site, identifying threats, scoring likelihood and consequence, applying mitigation controls, and reviewing the plan on a set schedule or after a trigger event.
How do you do a construction risk assessment?
Walk the site to map the perimeter and assets, list threats separating life safety from asset risks, score each on a matrix, assign controls following the hierarchy of control, and document everything in a risk register.
What is the 20/20 rule in construction?
There is no established “20/20 rule” tied to construction security risk assessments in current WHS guidance; definitions of this term vary by trade and jurisdiction, so treat any specific claim about it with caution.
What should a security risk assessment include?
It should include a site map, a scored risk register, a mitigation plan assigning responsibility, an incident log, and a review date, matching what Model Code of Practice guidance expects site managers to demonstrate.
How often should a construction site reassess its security?
Weekly during high activity phases, at every major project milestone, and immediately after triggers like major deliveries, contractor changes, incidents, or severe weather.







