How to check an assessor has real security expertise
Verify a security assessor's expertise before hiring. Check PSIRA registration, qualifications, insurance, past client references and ask specific methodology.
You've just had a break-in, or a near-miss, and you need someone to tell you what went wrong and how to fix it. Or maybe you're opening a new site and want a professional eye before anything goes sideways. Either way, the assessor you call will walk through your property, talk to your staff, and tell you where threats sit. That advice will shape real spending decisions. So before you hand over that job, you need to know whether this person actually knows what they're talking about.
The problem is that "security consultant" sits on a shelf with no lock. Anyone can print business cards. You need concrete checks—things you can verify, documentation you can hold, and references you can call—to separate genuine expertise from confident guessing.
Registration and formal credentials
Start by asking for their PSIRA registration number. The Private Security Industry Regulatory Authority licences security consultants and risk assessors in South Africa; if they hold a valid accreditation, they'll know it and won't flinch at being asked. Ask them to show you the registration or give you the number to cross-check against PSIRA's online database yourself. Don't accept vague answers or promises to "send it later."
Beyond PSIRA, look for qualifications specific to vulnerability assessment or penetration testing. Some assessors hold certifications like GIAC (Global Information Assurance Certification), CEH (Certified Ethical Hacker), or similar frameworks if their work crosses into IT security. If they work mostly on physical threats—access points, lighting, perimeter weaknesses—ask what their training has been in. Legitimate professionals can name the courses or programmes they've completed and, if you push, explain what they covered.
Also check whether they hold current professional liability insurance. This isn't just bureaucracy; it means they've been vetted by an insurer and it signals they take accountability seriously. Ask for proof or the name of their insurer so you can verify it's active.
Real-world proof and references
Now move to what they've actually done. Ask for case studies or references from three to five previous clients in your industry or sector. Don't settle for names alone; get permission to contact them and ask specific questions: Did the assessor spend enough time on-site? Did the report pinpoint threats they hadn't considered? Did recommendations end up being useful and implementable, or academic fluff? Did they follow up to clarify findings?
When you speak to a reference, avoid yes-or-no questions. Instead ask: "What were the biggest vulnerabilities they picked up?" and "Did those align with problems you'd suspected?" A genuine assessor will have spotted issues that aren't obvious at first glance—weak points in staff protocols, gaps in camera coverage that only show up under certain light, choke points where multiple access routes funnel into one space. References should confirm this kind of specificity.
Also ask previous clients how the assessor handled questions during the process. A thorough professional will explain their methodology as they work, not vanish and reappear with a report. They should be able to walk you through why they flagged a particular risk and what data or observation it rests on.
What to ask them directly
During your first conversation, ask them to describe how they'd approach your space. A credible assessor won't hand you a standard formula; they'll ask you questions first—about your current threats, your existing controls, your business type, your biggest worry. Then they'll outline how they'd tailor their work to those specifics.
Also ask what their report will look like. Will it prioritise risks by likelihood and impact? Will recommendations come with rough effort or cost guidance? Will they offer a follow-up session to discuss findings? Professional assessors set these expectations upfront and won't be offended by the question.
Finally, ask how long they've been doing this work and what their own background is. Former police, military, facility management, or loss prevention roles are common and credible. Someone who's been doing it for under two years might still be competent, but paired with weak references or vague credentials, it's a yellow flag.
A solid assessor will welcome every one of these checks. They know their track record and qualifications speak, and they understand you'd be reckless to hire anyone without verifying them. On Strove, you can browse verified security consultants, read what past clients say about their thoroughness, and compare their credentials before you even make a call.
Common questions
- What's the difference between a PSIRA-registered assessor and someone without registration?
- PSIRA (Private Security Industry Regulatory Authority) licences security consultants and risk assessors in South Africa. Registration means they've met baseline standards and their accreditation is publicly verifiable. Someone without it may still have skills, but you have no regulatory backstop and no easy way to check their standing if something goes wrong.
- What should I ask references about an assessor?
- Ask whether the assessor spent adequate time on-site, identified specific vulnerabilities the reference hadn't spotted, and delivered recommendations that were actually useful and implementable. Avoid yes-or-no questions; push for examples of what they found and how well it matched real risks.
- Is professional liability insurance a must?
- It's a strong indicator of legitimacy. An insurer won't cover someone without checking their credentials and track record, so active insurance suggests accountability. Always ask for proof or confirmation that they hold a current policy.
- Can I trust an assessor who's been in the field for only a year or two?
- Not by itself. Newer assessors can be sharp, but pair any short tenure with strong references, clear PSIRA registration, and specific credentials. If references and qualifications are also weak, move on.
Find a verified provider on Strove
Compare vetted vulnerability assessments providers, check their credentials, and book or request a quote — all in one place.
Find a Business