Security Assessments

One complete assessment of your digital and physical security.

A locked door does not protect an exposed account, and strong passwords do not protect an unlocked network cabinet. Runtime Labs examines how premises, people, devices, accounts, suppliers, and everyday routines interact.

Business premises viewed as part of a combined cyber and physical assessment

Where It Helps

Areas We Connect

  • Physical access to IT systems, cabinets, ports, and sensitive information.
  • Staff, visitor, delivery, and supplier procedures.
  • Account, authentication, device, and remote-access security.
  • Backups, recovery responsibilities, and exposed equipment.
  • Camera, alarm, perimeter, and access-control coverage.
  • Gaps between physical and digital ownership.

Scope

What Is Included

01

Combined cyber and physical scope.

02

Account, device, network, backup, and remote-access review.

03

Premises, access, visitor, camera, alarm, and routine review.

04

Cross-over analysis between physical and digital controls.

05

Photographs and diagrams where useful.

06

Findings review and optional implementation planning.

Expected Outcome

What You Can Expect

  • One combined findings report.
  • Separate cyber and physical risk priorities.
  • Cross-over vulnerabilities that isolated reviews can miss.
  • Immediate actions and a longer-term improvement roadmap.
  • Optional support to implement and verify agreed improvements.

Four-Step Delivery

How It Works

  1. 1 Scope We agree the locations, systems, permissions, concerns, and firm boundaries.
  2. 2 Assess We gather evidence across the agreed physical and technical areas.
  3. 3 Prioritise Findings are ranked by practical risk, effort, and business impact.
  4. 4 Review We explain the report, answer questions, and agree sensible next actions.

Evidence

Practical Work and Equipment

Identity Meets Access
Identity Meets Access Cards, user accounts, doors, and departure processes need consistent ownership.
Exposed Infrastructure
Exposed Infrastructure Physical access and unclear connections can undermine otherwise strong digital controls.
Detection Coverage
Detection Coverage Camera, alarm, network, and account controls are assessed as one operating system.

Trust and Boundaries

Important Details

  • All activity is authorised, bounded, confidential, and designed around business continuity.
  • Intrusive technical or physical testing requires a separate written agreement.
  • The assessment is not automatically a certification, formal audit, or guarantee against incidents.

Commercials

Pricing Approach

Combined assessments typically start from approximately £1,500. The final scope reflects premises, users, systems, permitted techniques, reporting depth, travel, and follow-up work.

Questions

Frequently Asked Questions

Why combine the assessments?

The combined view exposes gaps where physical and digital responsibilities meet.

Is this a formal penetration test?

Not automatically. Intrusive testing is optional and requires a separate written scope.

Can we begin with one location?

Yes. The scope can focus on the highest-priority site and expand from the evidence found.

Next Step

Talk to Runtime Labs about Cyber + Physical Combined.

Share the situation, the outcome you need, and any useful photographs or error details.