Your scored breakdown
All six stages, scored and ranked, with your two weakest called out and explained in plain terms.
Incident handling has six stages. Most enterprise security programs are fully built through stage two and improvised after that. Answer 24 questions in about three minutes and see exactly where the gap opens in yours.
Security programs get measured on inputs: cameras deployed, guard hours purchased, sites covered. Those numbers go up every year while the outcome that matters stays flat, because more detection with the same response capacity produces more evidence, not fewer incidents. The scorecard measures the other direction. It asks what your program does in the first 30 seconds, who gets reached and how fast, whether deterrence happens without a person deciding to trigger it, and whether an incident can close without someone writing a report at the end of a shift.
Answer honestly rather than aspirationally. The value is in the gap it exposes, and a flattering result is worth nothing in a budget review. Nobody sees your answers unless you ask for a review.
Stages one and two. Almost every enterprise program scores well here, so treat this section as your baseline, not your achievement.
Camera coverage and detection coverage are not the same thing.
Verification is the step that decides whether anything else happens.
Measure from the detection timestamp, not from when the report was filed.
Alert fatigue is the quiet reason real events get missed.
Classification is what makes automated escalation safe to turn on.
Cloud-only architectures go blind exactly when someone cuts the line.
Stage three is where most programs fall off. Detection tells you something happened. Deterrence is the first moment your program changes the outcome instead of documenting it.
Not what gets logged. What the intruder experiences.
Voice is the single most effective non-physical deterrent in the field.
Every human step in the chain is a delay you can measure.
Perimeters, lots, gates, docks, and laydown areas, not just lobbies.
This is the number that proves your program prevents rather than records.
A single siren teaches people that nothing follows the siren.
Stage four. This is where a verified event either becomes a coordinated response or becomes a phone tree. Most programs discover their real gap in this section.
Count the manual steps between confirmation and notification.
A binder on a shelf is not an executable procedure.
Live context is the difference between a response and a surprise.
Most serious incidents happen when the fewest people are watching.
If you can't measure it, you can't defend it or improve it.
Single points of failure show up on the worst night, not an average one.
Stages five and six. An incident isn't finished when the intruder leaves. It's finished when it's closed, documented, and usable as evidence. Ninety percent of organizations write after-action reports, and most write them by hand.
Manual reporting is a real, recurring labor cost that rarely appears in a security budget.
Multiply this by your annual incident count.
Scattered evidence is what makes an incident hard to defend later.
Retrieval speed is what your organization actually experiences as security's value.
More than half of security teams use after-action reports to justify further investment.
Reporting effort is the reason security metrics go stale between board meetings.
Tell us where to send the nine-page report. Your score appears as soon as you submit, and the report follows by email within a minute.
We use this to send your report and to route a review request if you ask for one. No call happens unless you request it.
Your band summary appears here.
Your report is on its way by email. Nothing else happens unless you book a review.
The on-screen score is the summary. The report is the working document: your answers, what each gap costs, and a page you can attach to a budget request without rewriting it. It's an assessment, not a sales deck.
All six stages, scored and ranked, with your two weakest called out and explained in plain terms.
How your result reads against published ASIS International research, so it lands as an industry pattern rather than a local failure.
What an open stage costs in exposure hours, manual labor, and incidents that close without resolution.
Capability mapped to stage, with a real incident walkthrough timestamped from detection to resolution.
A one-page fill-in you can attach to an internal request without rewriting any of it. More than half of security teams already use incident reporting this way.
The three questions that separate a system that alerts from a system that resolves. Ask them of anyone, including us.
Bands describe capability, not effort. A well-run program with disciplined people and good cameras still lands in Alert-Driven, because the band measures how much of the workflow runs without someone deciding to run it.
The program reliably establishes what happened. Almost everything after detection depends on who is available and how quickly they notice.
Detection is strong and alerts fire correctly. What happens next still waits on a person seeing the alert and deciding what to do about it.
Escalation is documented and largely automatic. Deterrence and documentation still carry manual steps that slow the close.
Detection, deterrence, escalation, and documentation run as one workflow. People handle judgment calls rather than routine steps.
You bring your score and a site layout. We walk the two weakest stages and show what closing them looks like with your existing solutions, and our autonomous capabilities, including SARA Agentic AI running the workflow from detection to resolution.
What happens with your answers, what the report contains, and how this relates to the models security teams already use.
Last updated: July 2026
Benchmark figures on this page come from Security Incident Management in 2025, published by ASIS International and sponsored by VOLT, a company unaffiliated with RAD. The study was fielded in September 2024 with 618 respondents and 433 completed responses, giving a margin of error of roughly 5 percent at 95 percent confidence. The scoring model, band thresholds, and stage weightings are RAD's own and are published in full on this page. Scores are self-reported and are not an audit, a certification, or a substitute for a site assessment.