Skip to content
HireSecurityNow.com
Corporate Security: Building a Program for Offices & Campuses (2026)
Guards & Services

Corporate Security: Building a Program for Offices & Campuses (2026)

Updated: July 18, 2026
29 min read

Phillip Zobel

May 4, 2026 · Updated July 18, 2026 · 29 min read· Fact-checked

In this guide

Corporate security isn't a guard at a desk — it's a layered program of access control, reception, monitoring, and officers. Here's how to build one, whether to outsource, and what it actually costs.

For an office tower, a corporate campus, or a multi-site company, security isn't a single guard at a desk — it's an integrated program that layers electronic access control, professional reception, camera monitoring, and a guard force into one coherent posture. Done well, it protects people, property, and information while staying nearly invisible to the employees and visitors who move through the building every day. Corporate security also carries a legal weight that a parking-lot patrol does not: an employer has a duty to provide a workplace free of recognized hazards, and a poorly run program is not just a loss risk but a liability exposure. This guide covers what a corporate security program actually includes, how to size it to your building and risk, the build-or-buy decision, the workplace-violence obligations behind it, and what it all costs.

Quick answer

A corporate program combines access control and reception, CCTV monitoring, a guard force (fixed posts plus patrol), and — at larger organizations — a security operations center that ties it together, usually priced as a managed monthly program. Unarmed guard bill rates run about $22–$35/hr; armed posts run about $30–$48/hr; and dedicated executive-protection details are priced separately at roughly $75–$150/hr. A single continuous 24/7 post costs roughly $193,000–$420,000 a year (about 8,760 hours × the bill rate — the low end unarmed, the high end armed), and a full building needs several posts. Outsourcing bundles labor, insurance, and management into one rate; in-house gives more control but adds overhead; many large firms run a hybrid. Underneath it all sits a legal duty of care — OSHA's General Duty Clause, and in California a specific workplace-violence-prevention mandate under SB 553.

What corporate and office security actually covers

The phrase "corporate security" hides a lot of distinct functions. In a real program each of these is a defined post or responsibility, not a vague expectation of the guard on shift:

  • Lobby reception and concierge-security — the front-desk officer is the face of the building. This post blends hospitality and security: greeting employees and guests, directing traffic, watching the entrance, and enforcing the badge and visitor policy without making the lobby feel like a checkpoint. In Class A office buildings this role is often explicitly staffed as "concierge security," and officer presentation, communication, and judgment matter as much as vigilance.
  • Access control and badging — issuing, provisioning, and de-provisioning credentials; managing the badge database; and enforcing which credential opens which door. When an employee is terminated, the badge is killed the same day; when a badge is lost, it's deactivated and reissued with a clean audit trail.
  • Visitor management — pre-registering guests, verifying identity, issuing temporary passes, notifying hosts, and logging every arrival and departure. Done well it's both a security control and a good first impression.
  • After-hours and multi-tenant coverage — nights, weekends, and holidays, when the building is nearly empty and a single officer may be the only person on site. In a multi-tenant tower the security program often serves the landlord and common areas, while individual tenants layer their own suite-level coverage on top — a coordination problem that has to be settled in the contract.
  • Loading dock, mailroom, and threat screening — the back of the house is where most unscreened people and packages enter. Dock officers control vendor and delivery access, and mailroom screening (visual inspection, and at higher-risk organizations X-ray or a dedicated screening protocol) intercepts suspicious packages before they reach an executive floor.
  • Executive-floor and principal protection — C-suite floors, boardrooms, and executive residences or travel may warrant tighter access, dedicated officers, or coordination with an executive-protection detail. This is where corporate security shades into personal protection and where an armed posture is most often justified.
  • Emergency and incident response — documented procedures for medical events, evacuation, active-threat and workplace-violence situations, severe weather, and bomb threats, with officers trained and drilled to execute them. This is the operational heart of the program, and it gets its own section below.

The best programs integrate these so the officer at the lobby, the access-control system, and the camera network operate as one — not three disconnected pieces staffed by people who don't talk to each other.

The incident-response playbook: what "trained and drilled" actually means

Every corporate security proposal promises "emergency response." Almost none of them show you what that response looks like minute-to-minute. Yet the incident playbook is precisely where a program either discharges its duty of care or exposes the employer. A serious buyer should ask to see written procedures for each of the four scenarios below, and should expect officers to have rehearsed them — not merely read them.

Active threat: run, hide, fight — and the officer's job in between

The federal framework for an active-shooter or active-threat event is Run–Hide–Fight (CISA/FBI): evacuate if there is a safe path, deny entry and shelter if there is not, and disrupt the attacker only as a last resort. Most corporate officers are unarmed, and their role in an active-threat event is not to engage — it is to compress the timeline. That means: recognizing the threat and calling 911 immediately with a precise location, initiating lockdown of access-controlled doors, making the mass-notification announcement, guiding people to exits or shelter, and meeting responding law enforcement at a pre-designated point to hand off floor plans, camera access, and a headcount. The single biggest force-multiplier a guard program adds here is seconds — earlier detection and faster notification — not confrontation.

Medical and AED response

Sudden cardiac arrest is survivable only in a narrow window; survival falls roughly 10% for every minute without defibrillation. A corporate officer trained in CPR/AED and Stop the Bleed is often the fastest responder in the building — on scene before EMS clears the lobby. Post orders should specify AED locations, who retrieves the nearest bleeding-control kit, how to stage and escort EMS to the patient, and how to control the scene so a crowd doesn't obstruct care.

Evacuation and shelter-in-place

Fire, gas leak, and severe-weather events require officers who know the primary and secondary egress routes, the assembly points, and the accountability method (who confirms the floor is clear, who counts heads at the muster point, who accounts for mobility-impaired occupants). Shelter-in-place — for an exterior hazardous-materials release or a tornado warning — is the inverse skill: move people in and away from glass, and account for them there.

Bomb threat and suspicious package

The recognized standard is the DHS/ATF bomb-threat checklist: keep the caller talking, capture caller ID and background sound, note exact wording, and escalate to management and law enforcement — the decision to evacuate is a leadership call informed by the threat's specificity, not a reflex. For a suspicious package, the rule is the opposite of curiosity: do not touch, open, or move it; clear the area; and isolate it while professionals respond.

What a real post order looks like

The article-length version of "we train our officers" is a post order — the written, site-specific instruction sheet at each post. The presence or absence of good post orders is the single most reliable sign of a professional versus an amateur program. Here is a short excerpt of what a competent lobby-officer post order actually reads like:

POST 1 — MAIN LOBBY · Fire Alarm Activation
1. Do NOT silence or reset the panel. Confirm the alarm zone on the annunciator and note the location.
2. Announce evacuation over the PA using the approved script. Unlock stairwell and egress doors via the access-control override.
3. Direct occupants to Stairs A/B; keep elevators out of service. Assist mobility-impaired occupants to the Area of Refuge and report their location to the fire department.
4. Meet responding apparatus at the Elm St. entrance; hand the responding officer the floor plan, panel key, and current occupancy count.
5. Do NOT permit re-entry until the fire department gives an all-clear. Log time of alarm, notification, and all-clear in the DAR.

POST 1 — MAIN LOBBY · Aggressive or Threatening Visitor
1. Stay behind the reception line; do not escalate. Use a calm, low voice; do not touch the visitor.
2. Discreetly signal the GSOC/dispatch via the duress button. State the visitor's description and demand.
3. If the visitor attempts to pass the barrier toward secured floors, initiate lockdown of the elevator lobby and call 911.
4. Do not pursue. Preserve camera footage of the encounter and complete an incident report before end of shift.

When you evaluate a provider, ask to see a redacted post order from a comparable account. Vague answers here predict vague performance at 3 a.m.

The GSOC: the brain of a larger program

Once an organization runs more than a handful of sites, the coordinating layer becomes a Global (or Security) Operations Center — a GSOC. A GSOC is a staffed room (or a virtual, remotely-staffed equivalent) that monitors alarms, camera feeds, and access-control events across the enterprise; watches travel-risk and threat intelligence for employees and facilities; dispatches officers and coordinates with local law enforcement; and serves as the single point of contact during an incident.

For a single office, a GSOC is overkill — the lobby officer and a modest camera system suffice. For a multi-building campus or a company with dozens of sites, the GSOC is what turns scattered posts into one program: it standardizes response, keeps a centralized record, and means an alarm at 3 a.m. reaches a trained operator instead of ringing into an empty room. Many mid-size companies buy GSOC-style monitoring as a service from their guard provider rather than building one in-house, which keeps 24/7 coverage affordable without staffing a room around the clock.

Workplace-violence prevention and the duty of care

Corporate security is not only a loss-prevention function — it's how an employer meets a legal obligation to keep its workforce safe. Under the federal Occupational Safety and Health Act, the General Duty Clause (Section 5(a)(1)) requires employers to provide a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." OSHA has repeatedly applied this clause to workplace violence: where the hazard is recognized and feasible controls exist, an employer that fails to act can be cited. There is no single federal workplace-violence standard, so OSHA leans on the General Duty Clause plus published guidance, which points employers toward a written prevention program, threat assessment, reporting channels, training, and physical-security controls — exactly the things a corporate security program provides.

The four types of workplace violence — and the control each one calls for

The analytical backbone practitioners use — the same typology Cal/OSHA's SB 553 codifies — comes from NIOSH, which sorts workplace violence into four types by the attacker's relationship to the business. The type dictates the control, which is why a serious program is designed around this table rather than a generic "we have a guard" answer:

TypeWho the attacker isCorporate control that fits
Type I — Criminal intentA stranger with no legitimate relationship to the business (robbery, trespass, terrorism)Access control, lobby screening, cash/asset hardening, exterior lighting, CCTV, visible guard presence
Type II — Customer / clientA customer, client, patient, or visitor who turns violent while receiving serviceReception buffering, duress alarms, de-escalation-trained officers, controlled interview rooms, clear escalation paths
Type III — Worker-on-workerA current or former employee attacking a coworker (includes terminations gone wrong)Threat-assessment team, termination-security protocol, badge de-provisioning, behavioral-reporting channel
Type IV — Personal relationshipA domestic or personal-relationship aggressor targeting an employee at workPhoto/flag at reception, escort to vehicle, restraining-order coordination, no-badge-for-outsiders enforcement

Most corporate incidents are Type II and Type III, and the two most dangerous moments in any office's calendar are a hostile termination (Type III) and a domestic situation that follows an employee to work (Type IV) — both of which a well-briefed guard force and a threat-assessment process are specifically built to manage.

California SB 553 and what a prevention plan must contain

California has gone furthest. Senate Bill 553 (Labor Code §6401.9), enforceable since July 1, 2024, requires most California employers to establish, implement, and maintain a written Workplace Violence Prevention Plan (WVPP). It applies to any location in California — there is no exemption for out-of-state headquarters — with narrow carve-outs (fewer than 10 employees at a non-public site, teleworkers, and separately regulated health-care and corrections settings). Even outside California, building your program to this structure is defensible practice, because it maps cleanly onto the federal General Duty Clause expectation.

A compliant WVPP must contain, at minimum:

  • Responsible persons — named job titles or departments accountable for implementing and maintaining the plan.
  • Employee involvement — procedures for how non-supervisory employees help develop, review, and improve the plan.
  • Hazard identification, evaluation, and correction — how you find workplace-violence hazards, assess them, and fix them promptly.
  • Incident response and reporting — how the employer receives and responds to reports and investigates incidents, with an explicit anti-retaliation guarantee for anyone who reports.
  • Coordination with other employers at a shared site (directly relevant to multi-tenant towers).
  • A Violent Incident Log — documenting every incident, including threats and weapon involvement, regardless of injury, with personal identifiers omitted.
  • Training — initial training when the plan is established, then annually, plus additional training whenever a new hazard is identified or the plan changes after an incident.
  • Recordkeeping — hazard, incident, and Violent Incident Log records kept for five years (training records for one year), available to employees within 15 days of request.

The stakes are concrete, not abstract. Because SB 553 is enforced through Cal/OSHA's citation authority, a failure can draw a penalty of up to $25,000 for a serious violation and up to $162,851 for a willful or repeat violation (2025 citation maximums, adjusted annually for inflation) — before any civil liability from an actual incident. That is what converts "liability exposure" from a talking point into a budget line. A guard provider experienced in corporate work should be able to speak fluently to how its post orders, incident reporting, and training feed these obligations rather than treating them as your problem alone. A statewide general-industry standard is due to be adopted no later than December 31, 2026, which will formalize these requirements further.

Protecting information, not just doors: the physical–logical convergence

The intro promised a program that protects people, property, and information — and for a corporate audience the information dimension is where physical security quietly earns or loses its keep. Most data breaches are digital, but the physical layer is the one your guard force actually controls, and it is a real attack surface: the terminated employee who badges back in over the weekend to copy files, the "IT vendor" who tailgates into a wiring closet, the printout left face-up on a shared printer, the visitor who photographs a whiteboard full of roadmap. Physical security and information security have converged, and a mature program treats a data center door and a database credential as two locks on the same asset.

The controls a guard program contributes to information protection are concrete:

  • Insider-threat coordination — tying badge de-provisioning to the HR termination workflow so a departing employee's physical access dies at the same moment their network access does, and flagging after-hours or off-pattern access to sensitive areas.
  • Data-center and sensitive-area access — mantrap or dual-authentication entry, a strict escorted-visitor rule, and an audit trail for every entry to rooms holding servers, R&D, or regulated records.
  • Clean-desk and clear-screen enforcement — the officer's after-hours walk-through is where a clean-desk policy actually gets checked: unlocked drawers, unsecured laptops, documents at the printer, whiteboards not erased.
  • Vendor and delivery vetting at the dock — verifying that the person in the IT or facilities uniform is expected and logged, the analog equivalent of not clicking an unverified link.

For a corporate buyer, "can your officers support our information-security policy, not just our doors?" is a legitimate and revealing question — and a provider that has never thought about clean-desk walk-throughs or termination-driven badge kills is telling you how deep its program really goes.

Layered, tiered coverage by building size and risk — with realistic budgets

There is no single "corporate security package." The right program scales with the building's size, tenancy, and risk profile. The table below sketches how coverage typically tiers up, and pairs each tier with a realistic annual program-cost band. The bands assume unarmed guard bill rates of about $22–$35/hr, use consistent 8,760-hours-a-year math for any continuous 24/7 post, and rise at the top tier where armed posts ($30–$48/hr) and dedicated management enter. Treat them as 2026 planning estimates, not quotes.

Site profileTypical coverage modelGuard footprintApprox. annual program cost
Small single-tenant office (<100 staff, low risk)Business-hours lobby officer + access control + basic CCTV1 unarmed post, ~40–50 hrs/week~$50,000–$95,000
Mid-size office / low-rise (100–500 staff)Extended-hours lobby + roving patrol + visitor management + monitored CCTV2–3 unarmed posts, some after-hours coverage~$150,000–$350,000
Class A tower / multi-tenant24/7 lobby concierge-security + dock officer + patrol + integrated access & camera monitoringSeveral posts across shifts, supervisor~$500,000–$1,100,000
Corporate campus / HQLayered posts, roving vehicle patrol, GSOC-style monitoring, emergency-response teamMulti-post 24/7 with on-site management~$1.2M–$3M+
High-threat / high-value (data, executives, targeted)All of the above plus screening, executive-floor control, and selective armed postsArmed + unarmed mix, dedicated leadership~$2M–$5M+

The organizing principle is defense in depth: a public lobby, then badged employee floors, then hardened sensitive areas (data centers, executive suites, R&D), each a layer an intruder would have to defeat in turn. You spend the most protection where the loss would hurt the most, not uniformly across the whole footprint.

What a corporate program costs, and how the math works

Corporate security is priced as a bill rate — the hourly figure that covers the officer's wage plus the provider's overhead (payroll taxes, workers' comp, general liability insurance, uniforms, supervision, recruiting, and margin). The guard's take-home wage is only part of it: officers typically earn $16–$25/hr, while the outsourced bill rate for unarmed corporate posts runs about $22–$35/hr in most metros. Armed posts run higher, roughly $30–$48/hr, reflecting licensing, firearms qualification, and insurance. Dedicated executive-protection details are a different service entirely and are priced separately at about $75–$150/hr (or $15,000–$35,000/month for a sustained detail) — do not confuse an armed corporate guard post with close protection.

The math that surprises buyers is the cost of continuous coverage. A single post staffed around the clock is not one person — it's roughly 4.2 full-time officers once you account for shifts, breaks, PTO, and turnover — but you pay for it as 8,760 hours a year at the bill rate:

  • One unarmed 24/7 post: 8,760 hrs × $22–$35 ≈ $193,000–$307,000 a year.
  • One armed 24/7 post: 8,760 hrs × $30–$48 ≈ $263,000–$420,000 a year.
  • Business-hours only (say 50 hrs/week, ~2,600 hrs/yr): roughly $57,000–$91,000 a year for one unarmed post.

A real building rarely needs just one post, which is why the tier table above lands where it does. Layer in technology — CCTV systems run about $1,000–$5,000 installed for a 4–10 camera setup ($150–$500 per camera), with professional monitoring at $30–$200/month — and a GSOC-style service, and you have the full program cost. The takeaway: continuous coverage is expensive because time is the cost driver, so spend it where the risk is, and use technology plus targeted human presence to avoid staffing a guard on every empty corridor.

Build, buy, or blend

Most companies outsource the guard force to a contract security provider, which bundles labor, insurance, management, and scheduling into one bill rate and shifts the HR burden (hiring, backfilling call-outs, workers' comp) onto the vendor. Some large organizations run an in-house proprietary force for tighter control, culture fit, and lower turnover on sensitive posts — at the cost of carrying that overhead directly. Many run a hybrid: proprietary security leadership and executive-protection staff, with an outsourced officer force for the bulk of the posts. The right answer depends on how sensitive your sites are, how much control you need over officer selection and training, and whether security is core enough to your risk profile to justify owning it.

Tailgating: the free attack that beats a $50,000 access system

The most common breach of a corporate building isn't a hacked badge reader — it's tailgating: someone simply following an authorized employee through a door held open out of politeness. No technology stops it, because the door opened legitimately; the intruder just walked in behind. This is why access control and a human presence are complementary, not redundant.

Defeating tailgating takes design and behavior a card reader can't provide: a staffed reception or turnstile at the main entrance, anti-tailgating hardware (mantraps or optical turnstiles) at sensitive points, a visible-badge policy so strangers stand out, and — most importantly — officers and employees trained not to hold secure doors for people they don't recognize. The lesson generalizes: expensive access technology only works when a security culture and, at key points, a guard back it up. A reader with no one watching the door it protects is half a control.

Technology and guard-force convergence

For most corporate sites, access control is the backbone the rest of the program hangs on, and cameras are its memory — but neither is self-executing. A modern access system uses badges or mobile credentials to govern who can enter which areas and when, logging every event so a lost badge is killed instantly and an investigation has a clear trail. Video surveillance, increasingly with AI analytics that flag a forced door, a loitering figure, or a person in a restricted zone, covers entrances, common areas, and sensitive spaces.

The trend in corporate security is convergence: the guard force, the access-control system, and the camera network operating as a single, integrated posture rather than three silos. A camera that flags an event is only useful if an officer sees the alert and responds; a forced-door alarm means nothing if no one is watching the panel it lights up. The officer's real job in a mature program is to operate and enforce the technology — staffing reception, handling exceptions, responding to alarms and credential misuse — which is exactly why the ability of a provider to integrate its people with your systems is a top selection criterion. A badge reader with no one watching the door it guards is a receipt, not a control.

Security program maturity: the four stages

Most companies never decide their security posture — they inherit it, one incident at a time. Naming the stage you are actually in is the fastest way to see what is missing and what the next dollar should buy. Almost every corporate program we see maps onto one of four stages.

StageWhat it looks likeTypical gapNext investment
1 — ReactiveA guard was added after an incident. Coverage is whatever the vendor proposed. No written instructions, no incident data.Nobody inside the company owns security.Written post orders and an incident log — both cost almost nothing.
2 — DefinedPost orders exist, badges are issued, cameras record. Someone in facilities or HR owns the vendor relationship.No threat-assessment process, no drills, badge lists never audited against the HR roster.A termination-security protocol, a behavioral-reporting channel, and a quarterly access audit.
3 — ManagedThe program is measured: fill rate, response times and incident trends are reviewed monthly. Drills are run. The vendor is scored against an SLA.Security still operates in a silo, disconnected from HR, IT and legal.A cross-functional threat-assessment team and physical–logical convergence with IT.
4 — OptimizedStaffing is risk-based and re-based as risk changes. Monitoring is centralized. Insurance, legal and security posture are aligned, and budget is defended with data.Complacency, and controls that were designed for a threat picture that has since moved.Tabletop and red-team testing, plus an independent program audit on a set cadence.

The cheapest jump is stage 2 to stage 3. It is almost entirely documentation and measurement — writing down what officers are supposed to do, logging what actually happened, and reviewing both once a month. It costs a fraction of adding a post, and it is what turns a guard into a program.

Contract vs. in-house: modeling the true cost of both

The build-or-buy discussion above is the strategic version of this question. Here is the arithmetic, because the comparison people usually run — vendor bill rate against an employee's hourly wage — is not a comparison at all.

Start with coverage, not headcount. A single post staffed around the clock is 168 hours a week, or 8,736 hours a year. At a 40-hour week that is 4.2 full-time equivalents on paper — but no real schedule runs at 4.2. Vacation, sick time, training days, holidays and turnover mean in-house programs typically budget roughly 4.5 to 5 FTEs per 24/7 post to avoid paying permanent overtime to cover the gaps.

Then add the burden. An in-house officer costs far more than their wage: payroll taxes, workers' compensation (a comparatively expensive class code, more so for armed posts), health benefits, paid time off, uniforms and equipment, background screening, state licensing, and paid training hours. As a planning range, employers commonly model fully loaded labor at roughly 1.25–1.45× base wage before any supervisor, scheduler or manager is layered on top; your real multiplier depends on your benefits package and your state's comp rates, so build it from your own numbers. For the wage side, check current occupational wage data for security guards in your specific metro rather than a national average — guard pay varies enormously between markets, which is exactly why bill rates do too.

A contract bill rate — the roughly $22–$35 unarmed and $30–$48 armed range quoted earlier — already contains all of that, plus the vendor's recruiting pipeline, scheduling infrastructure, field supervision, insurance and margin. So the honest comparison is:

  • In-house: (base wage × burden multiplier × FTEs required for the coverage) + supervision + recruiting + management time + your own liability.
  • Contract: (bill rate × hours) + the internal management time you still spend overseeing the vendor.

Run honestly, the two often land closer than expected on a single post — and in-house tends to win only at scale, where you can spread a supervisor and a scheduler across many posts. What usually decides it is not the spread but these four factors:

  • Sensitivity of the post. Executive floors, R&D space, trading floors and data rooms are where companies most often go proprietary — you control selection, vetting and tenure directly.
  • Number of sites. One building rarely justifies in-house overhead. A regional portfolio might.
  • Who absorbs volatility. Call-outs, no-shows and sudden coverage requests are the vendor's problem under a contract and your problem in-house. This is worth real money.
  • Liability transfer. A contract lets you push a defined share of risk onto an insured third party through indemnification and insurance requirements. An in-house officer's conduct is yours, full stop.

Most organizations end up blending: proprietary leadership and sensitive posts, contracted officers for volume. For a fuller treatment of the tradeoff, see our guide to in-house vs. contract security, and if you are weighing a regional specialist against a national brand, local vs. national security companies covers that decision.

KPIs and SLAs: what to hold a vendor to after the contract is signed

The RFP question bank below gets you a good provider. A scorecard is what keeps them good in year two, when the account manager who sold you has moved on. Put these in the contract with a defined remedy attached, and review them monthly in a documented meeting.

MetricHow to define itReasonable target
Post fill rateShare of scheduled hours filled by an officer who is licensed, trained and oriented to your site97%+, with a billing credit when missed
Unfamiliar-officer rateShare of shifts covered by someone who has not worked your site beforeLow single digits; spikes predict incidents
Officer turnover on your accountAnnual share of assigned officers replacedBelow the vendor's own book average — make them quote the number
Time to fill a permanent vacancyDays from vacancy to a trained, site-oriented replacement5–10 business days
Supervisor site inspectionsDocumented visits per month, including at least one outside business hours2–4 per month, with written findings
Incident report timeliness and qualityShare of reports submitted complete within 24 hours95%+
Training and orientation complianceShare of assigned officers current on state requirements and site orientation100%, evidenced on request
After-hours escalationTime to reach a live decision-maker at the vendor outside business hoursUnder 15 minutes

The incident-report metric is the one clients most often treat as paperwork and most often regret. A complete, timestamped, contemporaneous report is not administration — it is the evidence you will rely on if an incident becomes a claim two years later. A vendor whose reports arrive late and vague is quietly transferring risk back to you.

Insurance and negligent-security exposure

A corporate security program has a second audience you rarely think about: a plaintiff's attorney reconstructing your decisions after something goes wrong. Premises-liability claims — commonly called negligent security — argue that a property owner or employer knew or should have known of a foreseeable risk of criminal harm and failed to take reasonable measures against it.

These standards are state law, and they differ. How foreseeability is established — prior similar incidents on the property, a totality-of-the-circumstances test, or a balancing approach — varies by jurisdiction, and several states have narrowed or reshaped these claims by statute in recent years. Nothing here is legal advice. Have counsel assess your posture against the specific states you operate in.

Across jurisdictions, four things tend to matter in these cases:

  • What you knew. Incident logs, police calls-for-service history, tenant or employee complaints. The same log that shows you were on notice also shows that you responded — but only if you recorded the response.
  • What you promised. Marketing that advertises "24-hour security," or a lease or employee handbook describing patrols, creates an expectation you can be measured against. Never publish a control you do not actually run.
  • Whether the control worked as designed. The camera that was not recording, the exterior light that had been out for weeks, the door that was routinely propped. Maintenance records are security records.
  • Whether you closed your own findings. An unaddressed recommendation from your own risk assessment is the single most damaging document a program can produce.

On the insurance side, verify these before a vendor's officers ever set foot on your property, and re-verify at each renewal:

  • Commercial general liability at limits sized to your risk — and confirm that assault and battery is not excluded or quietly sub-limited. This exclusion is common in guard-industry policies and it removes coverage from precisely the scenario you bought security for.
  • Workers' compensation with employer's liability. This is what keeps an injured officer's claim from arriving at your door.
  • Additional insured status for your entity, plus a waiver of subrogation — with the actual endorsement forms attached. A certificate of insurance alone confers no rights; the endorsement is the coverage.
  • Professional liability (E&O) where the vendor performs monitoring, screening, consulting or investigative work.
  • Auto liability if officers drive on or around your property.

Our guide to reading a security vendor's certificate of insurance walks through the document line by line, and negligent security liability covers the claim itself in more depth.

How to vet a corporate security provider: the RFP question bank

The difference between providers on this page is rarely price — the bill rates cluster. It's execution: fill rate, turnover, post-order quality, and how fluently they speak your compliance obligations. Use the question bank below in your RFP or vendor interview. Weak or evasive answers are as informative as strong ones.

  • Integration capability: "Show us how your officers would operate our specific access-control and camera platforms. What systems have your teams run before?" A provider that only offers a warm body is a different — and lesser — product than one that operates your technology.
  • Fill-rate SLA: "What is your guaranteed post-fill rate, and what's the credit if you miss it?" Ask for the target as a number (mature providers commit to ~97%+). An unfilled post is an open door.
  • Turnover on comparable accounts: "What's your annual officer turnover on accounts like ours, and what do you do to keep it below the industry average?" Contract-security turnover is notoriously high; a provider that can't quote a figure isn't measuring it.
  • SB 553 / duty-of-care fluency: "How do your post orders, incident reports, and training feed our Workplace Violence Prevention Plan and Violent Incident Log?" (Even outside California, a provider that understands this framework is operating at a higher level.)
  • Sample post orders: "Provide a redacted post order from a comparable account, including your fire-alarm and aggressive-visitor procedures." This is the single most revealing document you can request.
  • Emergency-response depth: "Walk us through your officers' active-threat, medical/AED, evacuation, and bomb-threat procedures, and how often they drill them."
  • Supervision and escalation: "Who supervises the account, how often are posts inspected, and what is the after-hours escalation path to a live human?"
  • Insurance and licensing: "Provide proof of general liability and workers'-comp coverage and confirm every officer's state guard license (and firearms qualification for armed posts)."

Turn this into a scorecard. Score each provider 1–5 on integration, fill-rate SLA, turnover, compliance fluency, and post-order quality, and weight them for your risk profile. The lowest bid that scores a 2 on fill rate and can't produce a post order is not the cheap option — it's the expensive one, on the day it fails.

When you are ready to price the program, compare licensed providers on our corporate security services directory, which lists companies by market with their state license status shown. If your requirement is a staffed lobby or floor post rather than a full program, the broader security guard services directory is the better starting point, and access control providers covers the badging and door-hardware side — and our access control buyer’s guide walks through credential types, cloud versus on-premise, and the life-safety rules that constrain every door decision.

Start from your market:

Related reading, roughly in the order most buyers need it:

Frequently asked questions

How much does corporate or office security cost in 2026?+
Outsourced unarmed corporate guard posts bill at roughly $22–$35 an hour in most metros; armed posts run about $30–$48 an hour. Because a single post covered around the clock is about 8,760 hours a year, one continuous unarmed 24/7 post costs roughly $193,000–$307,000 annually, and one armed 24/7 post about $263,000–$420,000. A business-hours-only lobby post (about 50 hours a week) runs roughly $57,000–$91,000 a year. Most buildings need several posts, so realistic full-program budgets range from about $50,000 for a small single-tenant office up to $2–5 million-plus for a high-threat campus. These are 2026 planning estimates, not quotes.
What's the difference between an armed corporate guard and executive protection?+
They're distinct services at different price points. An armed corporate post — a guard stationed at a lobby, dock, or executive floor who carries a firearm — bills at roughly $30–$48/hr, reflecting licensing, firearms qualification, and added insurance. Executive protection (close protection) is dedicated personal security for a principal, often involving advance work, travel, and a detail; it's priced separately at about $75–$150 an hour, or $15,000–$35,000 a month for a sustained detail. Don't budget close protection at guard-post rates, or vice versa.
What does California SB 553 require, and does it apply to out-of-state companies?+
SB 553 (Labor Code §6401.9, effective July 1, 2024) requires most employers with any location in California to maintain a written Workplace Violence Prevention Plan, keep a Violent Incident Log documenting every incident, train employees initially and annually, investigate incidents, and retain most records for five years. There is no exemption for companies headquartered elsewhere — if you have a California site, you comply. Because it's enforced through Cal/OSHA, violations can draw penalties up to $25,000 for a serious violation and up to $162,851 for a willful or repeat one (2025 maximums, adjusted annually), on top of any liability from an actual incident.
What are the four types of workplace violence, and why do they matter for office security?+
NIOSH — the framework SB 553 codifies — sorts workplace violence by the attacker's relationship to the business: Type I is criminal intent by a stranger (robbery, trespass); Type II is a customer or client who turns violent while receiving service; Type III is worker-on-worker (including terminations gone wrong); and Type IV is a personal-relationship aggressor following an employee to work. The type dictates the control — access control and screening for Type I, duress alarms and de-escalation for Type II, a threat-assessment team and termination protocol for Type III, and reception flagging and escorts for Type IV — which is why a serious program is designed around this typology rather than a generic guard presence.
How do I tell a professional corporate security provider from an amateur one?+
Ask for a redacted post order from a comparable account — the written, site-specific instructions at each post, including fire-alarm and aggressive-visitor procedures. Good post orders are the single most reliable sign of a professional program; their absence is a red flag. Then pin down the numbers: a guaranteed post-fill-rate SLA (mature providers commit to ~97%+), officer turnover on similar accounts, ability to operate your specific access-control and camera systems, and fluency in how their reporting feeds your workplace-violence obligations. The bill rates cluster; execution is where providers separate.

Share this guide

Need to hire a security company?

Get free quotes from licensed security companies in your area.

Get free quotes