
Security Consulting & Risk Advisory
Independent assessment, honest findings and a sequenced plan you can actually fund — built by people who read a site the way an adversary would.
Know the risk before you spend against it.
Scope. Assess. Analyse. Report.
Consulting is where SHADO does the thinking before anyone does the spending. We read your environment the way a hostile party would, down to the distance between what the SOP says and what happens at three in the morning. What you get is a costed, prioritised roadmap — not a list of complaints.
Founded by a Military Intelligence veteran of the Indian Army. The methodology that shapes this work is drawn from that discipline: collect, corroborate, analyse, and only then recommend.
What consult actually delivers.
Seven capabilities, each with the work we do and the outputs you hold at the end of it. Open any one to read the detail.
Security Audits & Risk Assessments
A structured, on-site examination of how your site is actually secured — perimeter, entry control, manpower deployment, surveillance coverage, key and asset custody, and the supervision layer that holds it together. We observe across shifts rather than during a scheduled walkthrough, because risk lives in the hours nobody watches. Findings are rated by likelihood and consequence, not by how uncomfortable they are to raise.
What you receive
- Written audit report with photographic evidence and a rated risk register
- Threat and vulnerability matrix mapped to people, assets, information and continuity
- Prioritised corrective actions separated into immediate, short-term and capital items
- Management debrief with your security, facilities and HR leads
Vulnerability Assessments
A focused, adversarial look at a specific exposure — a boundary wall, a despatch bay, a night shift, a cash route, a server room, a new building under fit-out. We test the assumption rather than the paperwork: what a determined person could remove, reach or observe, and how long they would have before anyone noticed. Where appropriate and pre-authorised in writing, this includes discreet access and observation exercises.
What you receive
- Scenario-based exposure report covering intrusion, theft, sabotage and information loss
- Attack-path walkthrough showing how each weakness would realistically be exploited
- Detection and response timing analysis against each scenario
- Specific, buildable countermeasures with an owner against every item
Security Master Planning
A multi-year security architecture for a site, campus or portfolio — how manpower, technology, physical barriers and procedure combine into a single layered system instead of three separate purchases. We plan around your expansion, shift patterns and capital cycle so that each phase stands on its own and still fits the end state. This is the document that stops security spending from being reactive.
What you receive
- Layered security concept from outer perimeter to critical asset core
- Phased implementation plan with indicative budgets and dependencies
- Manpower-versus-technology balance analysis for each layer
- Drawings and zone maps marked with control points, coverage and response routes
SOP & Policy Development
Written procedure that a guard on his first night can follow correctly and a supervisor can be held to. We write post-specific SOPs — not a generic manual — covering entry and exit control, material gate passes, visitor and contractor handling, key control, patrol routes, escalation and incident reporting. Every procedure is drafted to be auditable, so compliance can be measured rather than assumed.
What you receive
- Post-wise standing orders and duty instructions in the language your team reads
- Access, visitor, material movement and key control policies
- Incident classification, escalation matrix and reporting formats
- Supervisor check sheets and a periodic compliance audit format
Access Control & Surveillance Planning
Design of who may go where, how that is enforced, and what is recorded when it is. We map identity and authorisation across employees, contractors, visitors, vehicles and material, then specify the camera, reader and barrier layout that supports it — placement, field of view, lighting, storage duration and, critically, who is expected to watch and act on what. Coverage without a viewing and response plan is only evidence after the fact.
What you receive
- Zone and authorisation matrix defining access rights by role and area
- Camera and reader layout plan with field-of-view, lighting and retention requirements
- Control room viewing, alarm response and footage retrieval protocols
- Functional specification you can tender to vendors without being led by them
Crisis & Emergency Preparedness
Preparation for the days that decide reputations — fire, medical emergency, bomb threat, labour unrest, intrusion, natural disaster or a serious workplace incident. We build the response structure, assign the roles, write the immediate-action drills and then rehearse them with your people until the sequence is instinctive. Plans are validated against your real site conditions, muster points and local emergency services.
What you receive
- Emergency response plan with an incident command structure and named roles
- Immediate-action drills and evacuation, muster and headcount procedures
- Crisis communication protocol covering internal, family and authority notification
- Table-top exercise and live mock-drill debriefs with corrective actions
Security Technology Advisory
Vendor-independent guidance on what to buy, what to skip and what you already own that is not being used. We translate operational requirements into technical specifications, review quotations on equivalent terms, and assess integration with your existing systems before commitment. Our advice is not tied to any manufacturer or system integrator, so the recommendation follows the risk, not the margin.
What you receive
- Requirement-led technical specification and bill of quantities
- Comparative vendor and quotation evaluation on a like-for-like basis
- Integration and lifecycle review covering storage, power, network and support
- Acceptance testing checklist to verify what was installed matches what was specified
How a consult engagement runs.
Four stages, agreed in writing before we begin, so you always know what is happening and what comes next.
Scope
We agree what is being protected, from whom, and what a failure would cost. Boundaries, timelines, access permissions and confidentiality terms are settled in writing before any fieldwork begins.
Assess
Fieldwork on your site across different shifts and conditions — observation, document review, and structured interviews with the people who actually run the gate, the stores and the control room.
Analyse
Findings are corroborated, tested against realistic threat scenarios and rated by likelihood and consequence, so that attention and budget go to the exposures that genuinely matter.
Report & Roadmap
A written report with evidence, a rated risk register and a phased, costed action plan — followed by a management debrief and, if you want it, support through implementation.
Built for the people who carry the risk.
If none of these describes your situation exactly, say so — the scoping conversation costs nothing and we would rather tell you early that you need something else.
Plant and facility leadership
Sites carrying material value, contractor traffic and shift operations, where losses are suspected but not yet measurable and the existing arrangement has never been independently examined.
Organisations before a major change
A new facility, an expansion, a shift to multi-shift working or a change of security provider — the moment when design decisions are cheapest to get right.
Boards and risk committees
Leadership that needs an independent, documented view of physical security exposure to support insurance, compliance, customer audits or capital approval.
The questions that come up first.
We already have a security agency on site. Will an audit just be a sales pitch for replacing them?
No. The audit is a separate engagement with its own deliverable, and it is frequently commissioned to strengthen an incumbent rather than remove one. Findings address the system — manning plan, procedure, supervision, technology and accountability — and where the fault lies with deployment or instructions rather than the provider, the report says so plainly.
How long does an assessment take, and how much will it disturb production?
A single mid-sized facility typically takes three to five days on site, spread across shifts, followed by about a week of analysis and drafting. Fieldwork is observational and interview-based, so nothing needs to stop. Where any intrusive test is proposed, it is scoped, authorised in writing and timed with you in advance.
Will the report be something I can take to my management for budget approval?
That is what it is written for. Each finding carries a risk rating, an evidence reference, a recommended action and an indicative cost band, separated into what can be fixed immediately at no cost, what needs a small operational spend, and what belongs in the capital plan.
Do you insist that we buy manpower or systems from you afterwards?
No. Consulting engagements are independent of our deployment work and of any equipment vendor. You are free to take the roadmap to any provider, and specifications are written so that you can tender them competitively.
Continue
Start with a conversation about consult.
Tell us the site, the concern and the timeline. We will tell you honestly whether this is the right discipline for the problem.
Security. Intelligence. Assurance. — Pan India Presence
