Corporate security isn't a guard at a desk — it's a layered program of access control, reception, monitoring, and officers. Here's how to build one, whether to outsource, and what it actually costs.
For an office tower, a corporate campus, or a multi-site company, security isn't a single guard at a desk — it's an integrated program that layers electronic access control, professional reception, camera monitoring, and a guard force into one coherent posture. Done well, it protects people, property, and information while staying nearly invisible to the employees and visitors who move through the building every day. Corporate security also carries a legal weight that a parking-lot patrol does not: an employer has a duty to provide a workplace free of recognized hazards, and a poorly run program is not just a loss risk but a liability exposure. This guide covers what a corporate security program actually includes, how to size it to your building and risk, the build-or-buy decision, the workplace-violence obligations behind it, and what it all costs.
Quick answer
A corporate program combines access control and reception, CCTV monitoring, a guard force (fixed posts plus patrol), and — at larger organizations — a security operations center that ties it together, usually priced as a managed monthly program. Unarmed guard bill rates run about $22–$35/hr; armed posts run about $30–$48/hr; and dedicated executive-protection details are priced separately at roughly $75–$150/hr. A single continuous 24/7 post costs roughly $193,000–$420,000 a year (about 8,760 hours × the bill rate — the low end unarmed, the high end armed), and a full building needs several posts. Outsourcing bundles labor, insurance, and management into one rate; in-house gives more control but adds overhead; many large firms run a hybrid. Underneath it all sits a legal duty of care — OSHA's General Duty Clause, and in California a specific workplace-violence-prevention mandate under SB 553.
What corporate and office security actually covers
The phrase "corporate security" hides a lot of distinct functions. In a real program each of these is a defined post or responsibility, not a vague expectation of the guard on shift:
- Lobby reception and concierge-security — the front-desk officer is the face of the building. This post blends hospitality and security: greeting employees and guests, directing traffic, watching the entrance, and enforcing the badge and visitor policy without making the lobby feel like a checkpoint. In Class A office buildings this role is often explicitly staffed as "concierge security," and officer presentation, communication, and judgment matter as much as vigilance.
- Access control and badging — issuing, provisioning, and de-provisioning credentials; managing the badge database; and enforcing which credential opens which door. When an employee is terminated, the badge is killed the same day; when a badge is lost, it's deactivated and reissued with a clean audit trail.
- Visitor management — pre-registering guests, verifying identity, issuing temporary passes, notifying hosts, and logging every arrival and departure. Done well it's both a security control and a good first impression.
- After-hours and multi-tenant coverage — nights, weekends, and holidays, when the building is nearly empty and a single officer may be the only person on site. In a multi-tenant tower the security program often serves the landlord and common areas, while individual tenants layer their own suite-level coverage on top — a coordination problem that has to be settled in the contract.
- Loading dock, mailroom, and threat screening — the back of the house is where most unscreened people and packages enter. Dock officers control vendor and delivery access, and mailroom screening (visual inspection, and at higher-risk organizations X-ray or a dedicated screening protocol) intercepts suspicious packages before they reach an executive floor.
- Executive-floor and principal protection — C-suite floors, boardrooms, and executive residences or travel may warrant tighter access, dedicated officers, or coordination with an executive-protection detail. This is where corporate security shades into personal protection and where an armed posture is most often justified.
- Emergency and incident response — documented procedures for medical events, evacuation, active-threat and workplace-violence situations, severe weather, and bomb threats, with officers trained and drilled to execute them. This is the operational heart of the program, and it gets its own section below.
The best programs integrate these so the officer at the lobby, the access-control system, and the camera network operate as one — not three disconnected pieces staffed by people who don't talk to each other.
The incident-response playbook: what "trained and drilled" actually means
Every corporate security proposal promises "emergency response." Almost none of them show you what that response looks like minute-to-minute. Yet the incident playbook is precisely where a program either discharges its duty of care or exposes the employer. A serious buyer should ask to see written procedures for each of the four scenarios below, and should expect officers to have rehearsed them — not merely read them.
Active threat: run, hide, fight — and the officer's job in between
The federal framework for an active-shooter or active-threat event is Run–Hide–Fight (CISA/FBI): evacuate if there is a safe path, deny entry and shelter if there is not, and disrupt the attacker only as a last resort. Most corporate officers are unarmed, and their role in an active-threat event is not to engage — it is to compress the timeline. That means: recognizing the threat and calling 911 immediately with a precise location, initiating lockdown of access-controlled doors, making the mass-notification announcement, guiding people to exits or shelter, and meeting responding law enforcement at a pre-designated point to hand off floor plans, camera access, and a headcount. The single biggest force-multiplier a guard program adds here is seconds — earlier detection and faster notification — not confrontation.
Medical and AED response
Sudden cardiac arrest is survivable only in a narrow window; survival falls roughly 10% for every minute without defibrillation. A corporate officer trained in CPR/AED and Stop the Bleed is often the fastest responder in the building — on scene before EMS clears the lobby. Post orders should specify AED locations, who retrieves the nearest bleeding-control kit, how to stage and escort EMS to the patient, and how to control the scene so a crowd doesn't obstruct care.
Evacuation and shelter-in-place
Fire, gas leak, and severe-weather events require officers who know the primary and secondary egress routes, the assembly points, and the accountability method (who confirms the floor is clear, who counts heads at the muster point, who accounts for mobility-impaired occupants). Shelter-in-place — for an exterior hazardous-materials release or a tornado warning — is the inverse skill: move people in and away from glass, and account for them there.
Bomb threat and suspicious package
The recognized standard is the DHS/ATF bomb-threat checklist: keep the caller talking, capture caller ID and background sound, note exact wording, and escalate to management and law enforcement — the decision to evacuate is a leadership call informed by the threat's specificity, not a reflex. For a suspicious package, the rule is the opposite of curiosity: do not touch, open, or move it; clear the area; and isolate it while professionals respond.
What a real post order looks like
The article-length version of "we train our officers" is a post order — the written, site-specific instruction sheet at each post. The presence or absence of good post orders is the single most reliable sign of a professional versus an amateur program. Here is a short excerpt of what a competent lobby-officer post order actually reads like:
POST 1 — MAIN LOBBY · Fire Alarm Activation
1. Do NOT silence or reset the panel. Confirm the alarm zone on the annunciator and note the location.
2. Announce evacuation over the PA using the approved script. Unlock stairwell and egress doors via the access-control override.
3. Direct occupants to Stairs A/B; keep elevators out of service. Assist mobility-impaired occupants to the Area of Refuge and report their location to the fire department.
4. Meet responding apparatus at the Elm St. entrance; hand the responding officer the floor plan, panel key, and current occupancy count.
5. Do NOT permit re-entry until the fire department gives an all-clear. Log time of alarm, notification, and all-clear in the DAR.
POST 1 — MAIN LOBBY · Aggressive or Threatening Visitor
1. Stay behind the reception line; do not escalate. Use a calm, low voice; do not touch the visitor.
2. Discreetly signal the GSOC/dispatch via the duress button. State the visitor's description and demand.
3. If the visitor attempts to pass the barrier toward secured floors, initiate lockdown of the elevator lobby and call 911.
4. Do not pursue. Preserve camera footage of the encounter and complete an incident report before end of shift.
When you evaluate a provider, ask to see a redacted post order from a comparable account. Vague answers here predict vague performance at 3 a.m.
The GSOC: the brain of a larger program
Once an organization runs more than a handful of sites, the coordinating layer becomes a Global (or Security) Operations Center — a GSOC. A GSOC is a staffed room (or a virtual, remotely-staffed equivalent) that monitors alarms, camera feeds, and access-control events across the enterprise; watches travel-risk and threat intelligence for employees and facilities; dispatches officers and coordinates with local law enforcement; and serves as the single point of contact during an incident.
For a single office, a GSOC is overkill — the lobby officer and a modest camera system suffice. For a multi-building campus or a company with dozens of sites, the GSOC is what turns scattered posts into one program: it standardizes response, keeps a centralized record, and means an alarm at 3 a.m. reaches a trained operator instead of ringing into an empty room. Many mid-size companies buy GSOC-style monitoring as a service from their guard provider rather than building one in-house, which keeps 24/7 coverage affordable without staffing a room around the clock.
Workplace-violence prevention and the duty of care
Corporate security is not only a loss-prevention function — it's how an employer meets a legal obligation to keep its workforce safe. Under the federal Occupational Safety and Health Act, the General Duty Clause (Section 5(a)(1)) requires employers to provide a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." OSHA has repeatedly applied this clause to workplace violence: where the hazard is recognized and feasible controls exist, an employer that fails to act can be cited. There is no single federal workplace-violence standard, so OSHA leans on the General Duty Clause plus published guidance, which points employers toward a written prevention program, threat assessment, reporting channels, training, and physical-security controls — exactly the things a corporate security program provides.
The four types of workplace violence — and the control each one calls for
The analytical backbone practitioners use — the same typology Cal/OSHA's SB 553 codifies — comes from NIOSH, which sorts workplace violence into four types by the attacker's relationship to the business. The type dictates the control, which is why a serious program is designed around this table rather than a generic "we have a guard" answer:
| Type | Who the attacker is | Corporate control that fits |
|---|---|---|
| Type I — Criminal intent | A stranger with no legitimate relationship to the business (robbery, trespass, terrorism) | Access control, lobby screening, cash/asset hardening, exterior lighting, CCTV, visible guard presence |
| Type II — Customer / client | A customer, client, patient, or visitor who turns violent while receiving service | Reception buffering, duress alarms, de-escalation-trained officers, controlled interview rooms, clear escalation paths |
| Type III — Worker-on-worker | A current or former employee attacking a coworker (includes terminations gone wrong) | Threat-assessment team, termination-security protocol, badge de-provisioning, behavioral-reporting channel |
| Type IV — Personal relationship | A domestic or personal-relationship aggressor targeting an employee at work | Photo/flag at reception, escort to vehicle, restraining-order coordination, no-badge-for-outsiders enforcement |
Most corporate incidents are Type II and Type III, and the two most dangerous moments in any office's calendar are a hostile termination (Type III) and a domestic situation that follows an employee to work (Type IV) — both of which a well-briefed guard force and a threat-assessment process are specifically built to manage.
California SB 553 and what a prevention plan must contain
California has gone furthest. Senate Bill 553 (Labor Code §6401.9), enforceable since July 1, 2024, requires most California employers to establish, implement, and maintain a written Workplace Violence Prevention Plan (WVPP). It applies to any location in California — there is no exemption for out-of-state headquarters — with narrow carve-outs (fewer than 10 employees at a non-public site, teleworkers, and separately regulated health-care and corrections settings). Even outside California, building your program to this structure is defensible practice, because it maps cleanly onto the federal General Duty Clause expectation.
A compliant WVPP must contain, at minimum:
- Responsible persons — named job titles or departments accountable for implementing and maintaining the plan.
- Employee involvement — procedures for how non-supervisory employees help develop, review, and improve the plan.
- Hazard identification, evaluation, and correction — how you find workplace-violence hazards, assess them, and fix them promptly.
- Incident response and reporting — how the employer receives and responds to reports and investigates incidents, with an explicit anti-retaliation guarantee for anyone who reports.
- Coordination with other employers at a shared site (directly relevant to multi-tenant towers).
- A Violent Incident Log — documenting every incident, including threats and weapon involvement, regardless of injury, with personal identifiers omitted.
- Training — initial training when the plan is established, then annually, plus additional training whenever a new hazard is identified or the plan changes after an incident.
- Recordkeeping — hazard, incident, and Violent Incident Log records kept for five years (training records for one year), available to employees within 15 days of request.
The stakes are concrete, not abstract. Because SB 553 is enforced through Cal/OSHA's citation authority, a failure can draw a penalty of up to $25,000 for a serious violation and up to $162,851 for a willful or repeat violation (2025 citation maximums, adjusted annually for inflation) — before any civil liability from an actual incident. That is what converts "liability exposure" from a talking point into a budget line. A guard provider experienced in corporate work should be able to speak fluently to how its post orders, incident reporting, and training feed these obligations rather than treating them as your problem alone. A statewide general-industry standard is due to be adopted no later than December 31, 2026, which will formalize these requirements further.
Protecting information, not just doors: the physical–logical convergence
The intro promised a program that protects people, property, and information — and for a corporate audience the information dimension is where physical security quietly earns or loses its keep. Most data breaches are digital, but the physical layer is the one your guard force actually controls, and it is a real attack surface: the terminated employee who badges back in over the weekend to copy files, the "IT vendor" who tailgates into a wiring closet, the printout left face-up on a shared printer, the visitor who photographs a whiteboard full of roadmap. Physical security and information security have converged, and a mature program treats a data center door and a database credential as two locks on the same asset.
The controls a guard program contributes to information protection are concrete:
- Insider-threat coordination — tying badge de-provisioning to the HR termination workflow so a departing employee's physical access dies at the same moment their network access does, and flagging after-hours or off-pattern access to sensitive areas.
- Data-center and sensitive-area access — mantrap or dual-authentication entry, a strict escorted-visitor rule, and an audit trail for every entry to rooms holding servers, R&D, or regulated records.
- Clean-desk and clear-screen enforcement — the officer's after-hours walk-through is where a clean-desk policy actually gets checked: unlocked drawers, unsecured laptops, documents at the printer, whiteboards not erased.
- Vendor and delivery vetting at the dock — verifying that the person in the IT or facilities uniform is expected and logged, the analog equivalent of not clicking an unverified link.
For a corporate buyer, "can your officers support our information-security policy, not just our doors?" is a legitimate and revealing question — and a provider that has never thought about clean-desk walk-throughs or termination-driven badge kills is telling you how deep its program really goes.
Layered, tiered coverage by building size and risk — with realistic budgets
There is no single "corporate security package." The right program scales with the building's size, tenancy, and risk profile. The table below sketches how coverage typically tiers up, and pairs each tier with a realistic annual program-cost band. The bands assume unarmed guard bill rates of about $22–$35/hr, use consistent 8,760-hours-a-year math for any continuous 24/7 post, and rise at the top tier where armed posts ($30–$48/hr) and dedicated management enter. Treat them as 2026 planning estimates, not quotes.
| Site profile | Typical coverage model | Guard footprint | Approx. annual program cost |
|---|---|---|---|
| Small single-tenant office (<100 staff, low risk) | Business-hours lobby officer + access control + basic CCTV | 1 unarmed post, ~40–50 hrs/week | ~$50,000–$95,000 |
| Mid-size office / low-rise (100–500 staff) | Extended-hours lobby + roving patrol + visitor management + monitored CCTV | 2–3 unarmed posts, some after-hours coverage | ~$150,000–$350,000 |
| Class A tower / multi-tenant | 24/7 lobby concierge-security + dock officer + patrol + integrated access & camera monitoring | Several posts across shifts, supervisor | ~$500,000–$1,100,000 |
| Corporate campus / HQ | Layered posts, roving vehicle patrol, GSOC-style monitoring, emergency-response team | Multi-post 24/7 with on-site management | ~$1.2M–$3M+ |
| High-threat / high-value (data, executives, targeted) | All of the above plus screening, executive-floor control, and selective armed posts | Armed + unarmed mix, dedicated leadership | ~$2M–$5M+ |
The organizing principle is defense in depth: a public lobby, then badged employee floors, then hardened sensitive areas (data centers, executive suites, R&D), each a layer an intruder would have to defeat in turn. You spend the most protection where the loss would hurt the most, not uniformly across the whole footprint.
What a corporate program costs, and how the math works
Corporate security is priced as a bill rate — the hourly figure that covers the officer's wage plus the provider's overhead (payroll taxes, workers' comp, general liability insurance, uniforms, supervision, recruiting, and margin). The guard's take-home wage is only part of it: officers typically earn $16–$25/hr, while the outsourced bill rate for unarmed corporate posts runs about $22–$35/hr in most metros. Armed posts run higher, roughly $30–$48/hr, reflecting licensing, firearms qualification, and insurance. Dedicated executive-protection details are a different service entirely and are priced separately at about $75–$150/hr (or $15,000–$35,000/month for a sustained detail) — do not confuse an armed corporate guard post with close protection.
The math that surprises buyers is the cost of continuous coverage. A single post staffed around the clock is not one person — it's roughly 4.2 full-time officers once you account for shifts, breaks, PTO, and turnover — but you pay for it as 8,760 hours a year at the bill rate:
- One unarmed 24/7 post: 8,760 hrs × $22–$35 ≈ $193,000–$307,000 a year.
- One armed 24/7 post: 8,760 hrs × $30–$48 ≈ $263,000–$420,000 a year.
- Business-hours only (say 50 hrs/week, ~2,600 hrs/yr): roughly $57,000–$91,000 a year for one unarmed post.
A real building rarely needs just one post, which is why the tier table above lands where it does. Layer in technology — CCTV systems run about $1,000–$5,000 installed for a 4–10 camera setup ($150–$500 per camera), with professional monitoring at $30–$200/month — and a GSOC-style service, and you have the full program cost. The takeaway: continuous coverage is expensive because time is the cost driver, so spend it where the risk is, and use technology plus targeted human presence to avoid staffing a guard on every empty corridor.
Build, buy, or blend
Most companies outsource the guard force to a contract security provider, which bundles labor, insurance, management, and scheduling into one bill rate and shifts the HR burden (hiring, backfilling call-outs, workers' comp) onto the vendor. Some large organizations run an in-house proprietary force for tighter control, culture fit, and lower turnover on sensitive posts — at the cost of carrying that overhead directly. Many run a hybrid: proprietary security leadership and executive-protection staff, with an outsourced officer force for the bulk of the posts. The right answer depends on how sensitive your sites are, how much control you need over officer selection and training, and whether security is core enough to your risk profile to justify owning it.
Tailgating: the free attack that beats a $50,000 access system
The most common breach of a corporate building isn't a hacked badge reader — it's tailgating: someone simply following an authorized employee through a door held open out of politeness. No technology stops it, because the door opened legitimately; the intruder just walked in behind. This is why access control and a human presence are complementary, not redundant.
Defeating tailgating takes design and behavior a card reader can't provide: a staffed reception or turnstile at the main entrance, anti-tailgating hardware (mantraps or optical turnstiles) at sensitive points, a visible-badge policy so strangers stand out, and — most importantly — officers and employees trained not to hold secure doors for people they don't recognize. The lesson generalizes: expensive access technology only works when a security culture and, at key points, a guard back it up. A reader with no one watching the door it protects is half a control.
Technology and guard-force convergence
For most corporate sites, access control is the backbone the rest of the program hangs on, and cameras are its memory — but neither is self-executing. A modern access system uses badges or mobile credentials to govern who can enter which areas and when, logging every event so a lost badge is killed instantly and an investigation has a clear trail. Video surveillance, increasingly with AI analytics that flag a forced door, a loitering figure, or a person in a restricted zone, covers entrances, common areas, and sensitive spaces.
The trend in corporate security is convergence: the guard force, the access-control system, and the camera network operating as a single, integrated posture rather than three silos. A camera that flags an event is only useful if an officer sees the alert and responds; a forced-door alarm means nothing if no one is watching the panel it lights up. The officer's real job in a mature program is to operate and enforce the technology — staffing reception, handling exceptions, responding to alarms and credential misuse — which is exactly why the ability of a provider to integrate its people with your systems is a top selection criterion. A badge reader with no one watching the door it guards is a receipt, not a control.
Security program maturity: the four stages
Most companies never decide their security posture — they inherit it, one incident at a time. Naming the stage you are actually in is the fastest way to see what is missing and what the next dollar should buy. Almost every corporate program we see maps onto one of four stages.
| Stage | What it looks like | Typical gap | Next investment |
|---|---|---|---|
| 1 — Reactive | A guard was added after an incident. Coverage is whatever the vendor proposed. No written instructions, no incident data. | Nobody inside the company owns security. | Written post orders and an incident log — both cost almost nothing. |
| 2 — Defined | Post orders exist, badges are issued, cameras record. Someone in facilities or HR owns the vendor relationship. | No threat-assessment process, no drills, badge lists never audited against the HR roster. | A termination-security protocol, a behavioral-reporting channel, and a quarterly access audit. |
| 3 — Managed | The program is measured: fill rate, response times and incident trends are reviewed monthly. Drills are run. The vendor is scored against an SLA. | Security still operates in a silo, disconnected from HR, IT and legal. | A cross-functional threat-assessment team and physical–logical convergence with IT. |
| 4 — Optimized | Staffing is risk-based and re-based as risk changes. Monitoring is centralized. Insurance, legal and security posture are aligned, and budget is defended with data. | Complacency, and controls that were designed for a threat picture that has since moved. | Tabletop and red-team testing, plus an independent program audit on a set cadence. |
The cheapest jump is stage 2 to stage 3. It is almost entirely documentation and measurement — writing down what officers are supposed to do, logging what actually happened, and reviewing both once a month. It costs a fraction of adding a post, and it is what turns a guard into a program.
Contract vs. in-house: modeling the true cost of both
The build-or-buy discussion above is the strategic version of this question. Here is the arithmetic, because the comparison people usually run — vendor bill rate against an employee's hourly wage — is not a comparison at all.
Start with coverage, not headcount. A single post staffed around the clock is 168 hours a week, or 8,736 hours a year. At a 40-hour week that is 4.2 full-time equivalents on paper — but no real schedule runs at 4.2. Vacation, sick time, training days, holidays and turnover mean in-house programs typically budget roughly 4.5 to 5 FTEs per 24/7 post to avoid paying permanent overtime to cover the gaps.
Then add the burden. An in-house officer costs far more than their wage: payroll taxes, workers' compensation (a comparatively expensive class code, more so for armed posts), health benefits, paid time off, uniforms and equipment, background screening, state licensing, and paid training hours. As a planning range, employers commonly model fully loaded labor at roughly 1.25–1.45× base wage before any supervisor, scheduler or manager is layered on top; your real multiplier depends on your benefits package and your state's comp rates, so build it from your own numbers. For the wage side, check current occupational wage data for security guards in your specific metro rather than a national average — guard pay varies enormously between markets, which is exactly why bill rates do too.
A contract bill rate — the roughly $22–$35 unarmed and $30–$48 armed range quoted earlier — already contains all of that, plus the vendor's recruiting pipeline, scheduling infrastructure, field supervision, insurance and margin. So the honest comparison is:
- In-house: (base wage × burden multiplier × FTEs required for the coverage) + supervision + recruiting + management time + your own liability.
- Contract: (bill rate × hours) + the internal management time you still spend overseeing the vendor.
Run honestly, the two often land closer than expected on a single post — and in-house tends to win only at scale, where you can spread a supervisor and a scheduler across many posts. What usually decides it is not the spread but these four factors:
- Sensitivity of the post. Executive floors, R&D space, trading floors and data rooms are where companies most often go proprietary — you control selection, vetting and tenure directly.
- Number of sites. One building rarely justifies in-house overhead. A regional portfolio might.
- Who absorbs volatility. Call-outs, no-shows and sudden coverage requests are the vendor's problem under a contract and your problem in-house. This is worth real money.
- Liability transfer. A contract lets you push a defined share of risk onto an insured third party through indemnification and insurance requirements. An in-house officer's conduct is yours, full stop.
Most organizations end up blending: proprietary leadership and sensitive posts, contracted officers for volume. For a fuller treatment of the tradeoff, see our guide to in-house vs. contract security, and if you are weighing a regional specialist against a national brand, local vs. national security companies covers that decision.
KPIs and SLAs: what to hold a vendor to after the contract is signed
The RFP question bank below gets you a good provider. A scorecard is what keeps them good in year two, when the account manager who sold you has moved on. Put these in the contract with a defined remedy attached, and review them monthly in a documented meeting.
| Metric | How to define it | Reasonable target |
|---|---|---|
| Post fill rate | Share of scheduled hours filled by an officer who is licensed, trained and oriented to your site | 97%+, with a billing credit when missed |
| Unfamiliar-officer rate | Share of shifts covered by someone who has not worked your site before | Low single digits; spikes predict incidents |
| Officer turnover on your account | Annual share of assigned officers replaced | Below the vendor's own book average — make them quote the number |
| Time to fill a permanent vacancy | Days from vacancy to a trained, site-oriented replacement | 5–10 business days |
| Supervisor site inspections | Documented visits per month, including at least one outside business hours | 2–4 per month, with written findings |
| Incident report timeliness and quality | Share of reports submitted complete within 24 hours | 95%+ |
| Training and orientation compliance | Share of assigned officers current on state requirements and site orientation | 100%, evidenced on request |
| After-hours escalation | Time to reach a live decision-maker at the vendor outside business hours | Under 15 minutes |
The incident-report metric is the one clients most often treat as paperwork and most often regret. A complete, timestamped, contemporaneous report is not administration — it is the evidence you will rely on if an incident becomes a claim two years later. A vendor whose reports arrive late and vague is quietly transferring risk back to you.
Insurance and negligent-security exposure
A corporate security program has a second audience you rarely think about: a plaintiff's attorney reconstructing your decisions after something goes wrong. Premises-liability claims — commonly called negligent security — argue that a property owner or employer knew or should have known of a foreseeable risk of criminal harm and failed to take reasonable measures against it.
These standards are state law, and they differ. How foreseeability is established — prior similar incidents on the property, a totality-of-the-circumstances test, or a balancing approach — varies by jurisdiction, and several states have narrowed or reshaped these claims by statute in recent years. Nothing here is legal advice. Have counsel assess your posture against the specific states you operate in.
Across jurisdictions, four things tend to matter in these cases:
- What you knew. Incident logs, police calls-for-service history, tenant or employee complaints. The same log that shows you were on notice also shows that you responded — but only if you recorded the response.
- What you promised. Marketing that advertises "24-hour security," or a lease or employee handbook describing patrols, creates an expectation you can be measured against. Never publish a control you do not actually run.
- Whether the control worked as designed. The camera that was not recording, the exterior light that had been out for weeks, the door that was routinely propped. Maintenance records are security records.
- Whether you closed your own findings. An unaddressed recommendation from your own risk assessment is the single most damaging document a program can produce.
On the insurance side, verify these before a vendor's officers ever set foot on your property, and re-verify at each renewal:
- Commercial general liability at limits sized to your risk — and confirm that assault and battery is not excluded or quietly sub-limited. This exclusion is common in guard-industry policies and it removes coverage from precisely the scenario you bought security for.
- Workers' compensation with employer's liability. This is what keeps an injured officer's claim from arriving at your door.
- Additional insured status for your entity, plus a waiver of subrogation — with the actual endorsement forms attached. A certificate of insurance alone confers no rights; the endorsement is the coverage.
- Professional liability (E&O) where the vendor performs monitoring, screening, consulting or investigative work.
- Auto liability if officers drive on or around your property.
Our guide to reading a security vendor's certificate of insurance walks through the document line by line, and negligent security liability covers the claim itself in more depth.
How to vet a corporate security provider: the RFP question bank
The difference between providers on this page is rarely price — the bill rates cluster. It's execution: fill rate, turnover, post-order quality, and how fluently they speak your compliance obligations. Use the question bank below in your RFP or vendor interview. Weak or evasive answers are as informative as strong ones.
- Integration capability: "Show us how your officers would operate our specific access-control and camera platforms. What systems have your teams run before?" A provider that only offers a warm body is a different — and lesser — product than one that operates your technology.
- Fill-rate SLA: "What is your guaranteed post-fill rate, and what's the credit if you miss it?" Ask for the target as a number (mature providers commit to ~97%+). An unfilled post is an open door.
- Turnover on comparable accounts: "What's your annual officer turnover on accounts like ours, and what do you do to keep it below the industry average?" Contract-security turnover is notoriously high; a provider that can't quote a figure isn't measuring it.
- SB 553 / duty-of-care fluency: "How do your post orders, incident reports, and training feed our Workplace Violence Prevention Plan and Violent Incident Log?" (Even outside California, a provider that understands this framework is operating at a higher level.)
- Sample post orders: "Provide a redacted post order from a comparable account, including your fire-alarm and aggressive-visitor procedures." This is the single most revealing document you can request.
- Emergency-response depth: "Walk us through your officers' active-threat, medical/AED, evacuation, and bomb-threat procedures, and how often they drill them."
- Supervision and escalation: "Who supervises the account, how often are posts inspected, and what is the after-hours escalation path to a live human?"
- Insurance and licensing: "Provide proof of general liability and workers'-comp coverage and confirm every officer's state guard license (and firearms qualification for armed posts)."
Turn this into a scorecard. Score each provider 1–5 on integration, fill-rate SLA, turnover, compliance fluency, and post-order quality, and weight them for your risk profile. The lowest bid that scores a 2 on fill rate and can't produce a post order is not the cheap option — it's the expensive one, on the day it fails.
Where to go next: providers, cities and related guides
When you are ready to price the program, compare licensed providers on our corporate security services directory, which lists companies by market with their state license status shown. If your requirement is a staffed lobby or floor post rather than a full program, the broader security guard services directory is the better starting point, and access control providers covers the badging and door-hardware side — and our access control buyer’s guide walks through credential types, cloud versus on-premise, and the life-safety rules that constrain every door decision.
Start from your market:
- Corporate security companies in New York City — the deepest market for multi-tenant tower and GSOC-style programs.
- Corporate security companies in Chicago.
- Corporate security companies in San Francisco — tech-campus and R&D-heavy requirements.
- All licensed security companies in Los Angeles, or licensed security companies in Washington, D.C. if your posture is driven by federal or government-adjacent tenants.
Related reading, roughly in the order most buyers need it:
- How to hire a security guard company — the end-to-end process, from scoping to contract.
- Security post orders explained — the document that decides whether your officers actually do the job you scoped.
- California SB 553 workplace violence prevention — the plan, log and training obligations in detail, and why the framework is worth adopting even outside California.
- In-house vs. contract security — the build-or-buy decision with the full cost model.
- Negligent security liability — how these claims are built and what documentation defends them.
- Executive protection cost — for when the requirement moves from the building to a person.
- Data center security — if your program covers a facility with its own compliance regime.
- How much does security cost — the full bill-rate breakdown behind every figure on this page.
Frequently asked questions
How much does corporate or office security cost in 2026?+
What's the difference between an armed corporate guard and executive protection?+
What does California SB 553 require, and does it apply to out-of-state companies?+
What are the four types of workplace violence, and why do they matter for office security?+
How do I tell a professional corporate security provider from an amateur one?+
Share this guide
Sources
- Cal/OSHA — SB 553 Workplace Violence Prevention requirements and required plan elements
- California DIR — 2025 Cal/OSHA civil penalty amounts ($25,000 serious; $162,851 willful/repeat)
- NIOSH / CDC — Types of Workplace Violence (four-type typology)
- OSHA — Workplace Violence overview and General Duty Clause enforcement guidance
- U.S. Bureau of Labor Statistics — Occupational Outlook Handbook: Security Guards and Gambling Surveillance Officers (wage and employment data)
- ASIS International — security industry standards and guidelines (program design and risk assessment)



