Choosing help to audit after a break-in or incident
Find a security auditor for post-incident assessment. Learn what separates investigators from salespeople and how to check their independence and experience.
After a break-in or incident, you need to know what went wrong and how to stop it happening again. A security audit in this context isn't a routine check—it's a forensic one. You're not shopping for a standard assessment; you're looking for someone who can trace what happened, identify the specific vulnerabilities that were exploited, and tell you which fixes actually matter. The difference between a generic auditor and one suited to post-incident work is substantial, and it shapes every other choice you'll make.
Experience reading the crime, not just the building
Post-incident audits require a different mindset than preventive ones. The auditor needs to think like the person who got in. They should ask: How did they gain entry? What stopped them from being detected? Which alarm zones failed, or were they never triggered? Why didn't CCTV deter or record them? These aren't abstract questions—they're about your specific incident.
When you're vetting candidates, ask them directly about break-ins or thefts they've audited before. Not how many, but what they actually found. A credible auditor will describe the sequence of events, the point of compromise, and what the client was doing wrong at that exact moment. They should be comfortable saying things like "the door sensor wasn't working, but they wouldn't have known that until they tested it" or "the guard was following a predictable patrol pattern." If someone speaks only in generic terms about "best practice," they're not the right fit.
Ask whether they've worked with insurers or the police after incidents. Insurance assessors and investigators develop a practical eye for what actually fails, not just what theory says should work. Similarly, if they've helped businesses recover after a crime, they understand the gap between what looks secure and what is.
You should also clarify whether they'll examine the incident itself. Do they want the police report, CCTV footage, access logs, guard records? Will they walk through the building with you and reconstruct the event? If they skip this step and jump straight to "here's what you need," they're guessing, not auditing.
Independence from the sales pitch
After a break-in, you're vulnerable to being sold expensive solutions. An auditor who owns a CCTV installation business or a gate company has a financial interest in recommending their products, and that clouds judgment. This doesn't mean they're dishonest—it means their incentives are split.
The cleanest approach is to find an auditor who doesn't sell security hardware or installation. They should make their money from the audit itself, not from what you buy afterward. Ask directly: "Do you or your company install systems, sell equipment, or take commission from suppliers?" If yes, ask them to confirm in writing that they'll disclose this in their report and explain why certain recommendations serve your interests, not theirs.
You can cross-check independence by asking whether they'll review quotations from installers on your behalf, or advise you on which supplier to approach. An independent auditor is usually willing to do this because they have no vendor relationship. If they refuse or push you toward "partners," that's a signal.
One practical test: after they deliver their audit, can you take their recommendations to three different security companies and get competitive quotes? If the audit is genuinely independent, the answer should be yes. If it's written in a way that only one supplier can fulfill it, you've probably paid for a sales document.
What to compare when you're shortlisting
Get two or three auditors to quote, but don't compare price alone. Ask each one to outline their method in writing—how they'll investigate the incident, what they'll inspect, and how long it'll take. The breadth of their scope matters more than the cost.
Also ask for references from clients who had break-ins or thefts, not just routine audits. Speak to them about whether the auditor's findings matched reality, whether the recommendations actually reduced their risk, and whether they felt the auditor understood their specific problem.
When you're ready to move forward, look for auditors on Strove who specialise in incident response and can show you their track record. A verified profile will flag their qualifications, past work, and client reviews—all of which help you spot someone who thinks like an investigator rather than a salesman.
Common questions
- What's the difference between a post-incident audit and a routine security audit?
- A post-incident audit investigates what went wrong during a specific crime or break-in—it reconstructs the event and identifies which vulnerabilities were exploited. A routine audit checks general security standards and compliance. After an incident, you need someone who thinks forensically and can trace the attacker's path through your premises.
- How do I know if an auditor is independent or selling me their own products?
- Ask them directly whether they or their company install systems, sell equipment, or receive commission from suppliers. Request a written statement of independence in their report. Independent auditors make money from the audit fee alone, not from what you buy afterward. Test this by taking their recommendations to competing installers for quotes—if multiple suppliers can fulfill them, independence is likely genuine.
- What questions should I ask a candidate auditor about their experience?
- Ask them to describe break-ins or thefts they've audited before, including how entry was gained and what failed. Inquire whether they've worked with insurers, investigators, or police after crimes. Check if they'll examine your incident report, review CCTV footage, and reconstruct the event during the audit. Generic answers about best practice are a red flag.
- Should I get multiple quotes for a post-incident audit?
- Yes—get two or three quotes and compare their scope and method, not just price. Ask each auditor to outline how they'll investigate your specific incident and what they'll inspect. Request references from clients who had break-ins, not just routine checks, so you can verify whether their recommendations matched reality and reduced actual risk.
Find a verified provider on Strove
Compare vetted security audits providers, check their credentials, and book or request a quote — all in one place.
Find a Business