Score what happens after detection.

Incident handling has six stages. Most enterprise security programs are fully built through stage two and improvised after that. Answer 24 questions in about three minutes and see exactly where the gap opens in yours.

Coverage isn't the same thing as capability.

Security programs get measured on inputs: cameras deployed, guard hours purchased, sites covered. Those numbers go up every year while the outcome that matters stays flat, because more detection with the same response capacity produces more evidence, not fewer incidents. The scorecard measures the other direction. It asks what your program does in the first 30 seconds, who gets reached and how fast, whether deterrence happens without a person deciding to trigger it, and whether an incident can close without someone writing a report at the end of a shift.

Almost nobody is fast enough
Only 13 percent of security professionals say their detection and response speed needs no meaningful improvement. ASIS International, 2025.
Speed predicts everything else
93 percent of those satisfied with their response time rate their program effective, against 33 percent of those who want it faster.
The gap sits downstream
Detection is near-universal in enterprise programs. What happens after it is where results diverge, and where this scorecard looks.

Rate your program, one stage at a time.

Answer honestly rather than aspirationally. The value is in the gap it exposes, and a flattering result is worth nothing in a budget review. Nobody sees your answers unless you ask for a review.

Detect and verify
Step 1 of 5
Detect and verify
Deter
Escalate and respond
Resolve and document
Your score
Detect and verify

Stages one and two. Almost every enterprise program scores well here, so treat this section as your baseline, not your achievement.

How much of your perimeter and critical outdoor area runs AI-driven detection?

Camera coverage and detection coverage are not the same thing.

Cameras record, no analytics running
Analytics on a handful of key cameras
Most exterior cameras run analytics
AI-driven detection across the perimeter and every critical zone
After hours, who confirms whether an alarm is real?

Verification is the step that decides whether anything else happens.

Nobody until footage gets reviewed later
An on-site guard walks over when available
A third-party monitoring center reviews the video
The system verifies automatically and only passes on confirmed events
How long between an event occurring and someone knowing it's genuine?

Measure from the detection timestamp, not from when the report was filed.

Hours, or the next business day
More than 15 minutes
Two to 15 minutes
Under 30 seconds
What does your nuisance alarm volume look like?

Alert fatigue is the quiet reason real events get missed.

High. Most alerts are noise and operators have learned to ignore them
We don't measure it
Reduced, but still a daily burden on the team
Filtered automatically. Operators only see verified events
Can your system reliably separate people, vehicles, animals, and weather?

Classification is what makes automated escalation safe to turn on.

No classification, motion only
Basic person and vehicle detection on some cameras
Solid classification across most of the estate
Full classification including objects, PPE, weapons, and plates where needed
If the network or cloud connection drops, does detection keep working?

Cloud-only architectures go blind exactly when someone cuts the line.

Everything stops until connectivity returns
Recording continues locally but nothing is analyzed
Detection continues at the edge, alerting resumes when the link is back
Detection and on-site deterrence both continue at the edge
Deter

Stage three is where most programs fall off. Detection tells you something happened. Deterrence is the first moment your program changes the outcome instead of documenting it.

In the first 30 seconds after a confirmed detection, what happens on site?

Not what gets logged. What the intruder experiences.

Nothing. The event is recorded for later review
An operator may notice and radio someone
Lights or a siren trigger on a schedule or a rule
Targeted voice, light, and audio deterrence fires automatically at the event location
Can your system speak to an intruder without a human on the line?

Voice is the single most effective non-physical deterrent in the field.

No audio capability outdoors
Prerecorded messages a person has to trigger
Live talk-down when an operator is available
AI-driven voice-down that starts automatically and escalates its message
Is deterrence automatic, or does it wait for a person to act?

Every human step in the chain is a delay you can measure.

Entirely dependent on a person deciding to act
A person triggers it from a console when staffed
Automatic for a narrow set of rules
Automatic across the SOP, with human override available
Do you have deterrence where incidents actually happen?

Perimeters, lots, gates, docks, and laydown areas, not just lobbies.

Deterrence only at staffed entrances
One or two fixed locations
Most known hot spots covered
Every identified hot spot, including temporary and remote sites
Do you know how many incidents end at deterrence without escalating?

This is the number that proves your program prevents rather than records.

We have no way to measure that
We could reconstruct it manually from reports
We track it roughly
We report it as a standing metric
Does deterrence escalate as a subject ignores it?

A single siren teaches people that nothing follows the siren.

No deterrence to escalate
One fixed response, always the same
Manual escalation if someone is watching
Automatic escalation through warning tiers based on subject behavior
Escalate and respond

Stage four. This is where a verified event either becomes a coordinated response or becomes a phone tree. Most programs discover their real gap in this section.

When an event needs escalation, how do the right people get reached?

Count the manual steps between confirmation and notification.

Someone starts calling down a printed list
An operator calls or radios one contact at a time
Automated alerts go out, follow-up is manual
The system contacts every stakeholder in parallel per the SOP and tracks who responded
Does escalation follow a documented, site-specific procedure automatically?

A binder on a shelf is not an executable procedure.

No documented escalation procedure
Documented, but executed from memory under pressure
Documented and mostly followed, with manual steps
Encoded in the system and executed automatically per site
Do responders arrive knowing what they're walking into?

Live context is the difference between a response and a surprise.

They get an address and nothing else
A verbal description relayed by phone
A still image or short clip
Live video, subject description, and location, updated as the scene changes
What happens to an event outside staffed hours?

Most serious incidents happen when the fewest people are watching.

It waits until morning
An on-call person may or may not pick up
A monitoring center handles it on contract terms
Handled identically to staffed hours, automatically
Can you measure time from detection to responder arrival?

If you can't measure it, you can't defend it or improve it.

No, we'd be guessing
Only by reconstructing it after a serious incident
For some incident types
Automatically timestamped for every incident
How much of your escalation depends on one person being available?

Single points of failure show up on the worst night, not an average one.

Almost all of it
A small group, and coverage gets thin
Redundancy exists but is informal
None. The workflow runs regardless of who is on shift
Resolve and document

Stages five and six. An incident isn't finished when the intruder leaves. It's finished when it's closed, documented, and usable as evidence. Ninety percent of organizations write after-action reports, and most write them by hand.

Who writes the incident record?

Manual reporting is a real, recurring labor cost that rarely appears in a security budget.

Often nobody, unless it was serious
A guard or manager writes it up at end of shift
A person completes a structured template
The system generates the record automatically and a person reviews it
How long does an incident record take to produce?

Multiply this by your annual incident count.

Hours, and it happens days later
Thirty to 60 minutes of someone's time
Ten to 30 minutes
It's ready within minutes with no manual assembly
Does the record include video, timeline, actions taken, and outcome together?

Scattered evidence is what makes an incident hard to defend later.

Written narrative only
Narrative plus clips someone has to locate
Most elements, assembled manually
A single audit-ready record with everything attached
How quickly can you produce evidence for legal, insurance, or law enforcement?

Retrieval speed is what your organization actually experiences as security's value.

Days, and it may not exist
A day or two of hunting
A few hours
Minutes, retrievable by anyone authorized
Do incident records feed back into how the program is run?

More than half of security teams use after-action reports to justify further investment.

They're filed and never revisited
Reviewed after major incidents only
Reviewed periodically for patterns
They drive redeployment, training, and budget decisions on a standing cycle
Can you report security outcomes to leadership without building a deck by hand?

Reporting effort is the reason security metrics go stale between board meetings.

Every report is assembled from scratch
We reuse a template and fill it manually
Some metrics pull automatically
Outcome reporting is generated on demand
Your score is ready.

Tell us where to send the nine-page report. Your score appears as soon as you submit, and the report follows by email within a minute.

Name
Please enter your name.
Work email
Please use your work email address.
Company
Please enter your company.
Role
Please select your role.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use this to send your report and to route a review request if you ask for one. No call happens unless you request it.

0
of 72
Alert-Driven

Your band summary appears here.

Detect and verify
0/18
Weakest stage
Deter
0/18
Weakest stage
Escalate and respond
0/18
Weakest stage
Resolve and document
0/18
Weakest stage

Your report is on its way by email. Nothing else happens unless you book a review.

Back
0 of 6 answered
Continue

What's in the nine pages.

The on-screen score is the summary. The report is the working document: your answers, what each gap costs, and a page you can attach to a budget request without rewriting it. It's an assessment, not a sales deck.

Your scored breakdown

All six stages, scored and ranked, with your two weakest called out and explained in plain terms.

Benchmark context

How your result reads against published ASIS International research, so it lands as an industry pattern rather than a local failure.

The cost of each gap

What an open stage costs in exposure hours, manual labor, and incidents that close without resolution.

What closing it looks like

Capability mapped to stage, with a real incident walkthrough timestamped from detection to resolution.

A budget-request summary

A one-page fill-in you can attach to an internal request without rewriting any of it. More than half of security teams already use incident reporting this way.

Questions to ask any vendor

The three questions that separate a system that alerts from a system that resolves. Ask them of anyone, including us.

Four bands. Most enterprise programs land in the second.

Bands describe capability, not effort. A well-run program with disciplined people and good cameras still lands in Alert-Driven, because the band measures how much of the workflow runs without someone deciding to run it.

0 to 24

Evidence-Based

The program reliably establishes what happened. Almost everything after detection depends on who is available and how quickly they notice.

25 to 42

Alert-Driven

Detection is strong and alerts fire correctly. What happens next still waits on a person seeing the alert and deciding what to do about it.

Most common band
43 to 59

Response-Capable

Escalation is documented and largely automatic. Deterrence and documentation still carry manual steps that slow the close.

60 to 72

Autonomous

Detection, deterrence, escalation, and documentation run as one workflow. People handle judgment calls rather than routine steps.

Thirty minutes, no deck.

You bring your score and a site layout. We walk the two weakest stages and show what closing them looks like with your existing solutions, and our autonomous capabilities, including SARA Agentic AI running the workflow from detection to resolution.

Questions about the scorecard.

What happens with your answers, what the report contains, and how this relates to the models security teams already use.

Will someone call me after I take this?
Not unless you ask. The report goes to your email and the review is a button you press, not a follow-up you receive. Most people take the scorecard, read the report, and never hear from us, which is the arrangement we intended.
The scoring model is published on this page and no question references a product. Most of the 24 questions are about process rather than technology, and the report names your two weakest stages whether or not we sell anything that closes them. One page of nine covers what our capabilities do, and it's clearly marked.
No. Every question is answerable from working knowledge of how your program runs day to day. If you find yourself guessing on a question, that gap is usually a finding in itself, and the report treats it that way.
Those models describe perimeter design and they end at denial. This scorecard measures what happens after the perimeter is crossed: whether response, escalation, and closure depend on a person being available to run them. Related question, different stage of the problem.