Score what happens after detection.

Incident handling has six stages. Most enterprise security programs are fully built through stage two and improvised after that. Answer 24 questions in about three minutes and see exactly where the gap opens in yours.

Coverage isn't the same thing as capability.

Security programs get measured on inputs: cameras deployed, guard hours purchased, sites covered. Those numbers go up every year while the outcome that matters stays flat, because more detection with the same response capacity produces more evidence, not fewer incidents. The scorecard measures the other direction. It asks what your program does in the first 30 seconds, who gets reached and how fast, whether deterrence happens without a person deciding to trigger it, and whether an incident can close without someone writing a report at the end of a shift.

Almost nobody is fast enough
Only 13 percent of security professionals say their detection and response speed needs no meaningful improvement. ASIS International, 2025.
Speed predicts everything else
93 percent of those satisfied with their response time rate their program effective, against 33 percent of those who want it faster.
The gap sits downstream
Detection is near-universal in enterprise programs. What happens after it is where results diverge, and where this scorecard looks.

Rate your program, one stage at a time.

Answer honestly rather than aspirationally. The value is in the gap it exposes, and a flattering result is worth nothing in a budget review. Nobody sees your answers unless you ask for a review.

Detect
Step 1 of 7
Detect
Verify
Deter
Escalate
Respond
Resolve
Your score
Detect

Stage one. Whether the system knows what it's looking at, rather than only that something moved. Most enterprise programs score well here, so treat this as your baseline.

How much of your perimeter and critical outdoor area runs AI-driven detection?

Camera coverage and detection coverage are not the same thing.

Cameras record, no analytics running
Analytics on a handful of key cameras
Most exterior cameras run analytics
AI-driven detection across the perimeter and every critical zone
Can your system reliably separate people, vehicles, animals, and weather?

Classification is what makes automated action safe to turn on.

No classification, motion only
Basic person and vehicle detection on some cameras
Solid classification across most of the estate
Full classification including objects, PPE, weapons, and plates where needed
What does your nuisance alarm volume look like?

Alert fatigue is the quiet reason real events get missed.

High. Most alerts are noise and operators have learned to ignore them
We don't measure it
Reduced, but still a daily burden on the team
Filtered automatically. Operators only see events worth seeing
If the network or cloud connection drops, does detection keep working?

Cloud-only architectures go blind exactly when someone cuts the line.

Everything stops until connectivity returns
Recording continues locally but nothing is analyzed
Detection continues at the edge, alerting resumes when the link is back
Detection and on-site deterrence both continue at the edge
Verify

Stage two. Whether an alert is real, and who decides. This is where most programs are still entirely manual, and where the gap usually opens.

After hours, who confirms whether an alarm is real?

Verification is the step that decides whether anything else happens.

Nobody until footage gets reviewed later
An on-site guard walks over when available
A third-party monitoring centre reviews the video
The system verifies automatically and only passes on confirmed events
How long between an event occurring and someone knowing it's genuine?

Measure from the detection timestamp, not from when the report was filed.

Hours, or the next business day
More than 15 minutes
Two to 15 minutes
Under 30 seconds
Does verification wait on a person being available to look?

Every human step in the chain is a delay you can measure.

Entirely. If nobody looks, nothing is verified
A person verifies when staffed, otherwise it waits
Automated for some event types, manual for the rest
Automated across event types, with human override available
When an event is verified, what comes with it?

Verification that produces no context just moves the problem downstream.

An alarm code and a timestamp
A still image
A clip, retrieved manually
Classification, live view, and location, assembled automatically
Deter

Stage three. The first moment your program changes the outcome instead of documenting it. Deterrence is almost always a subset of camera coverage, so answer for the sites that matter.

In the first 30 seconds after a confirmed detection, what happens on site?

Not what gets logged. What the intruder experiences.

Nothing. The event is recorded for later review
An operator may notice and radio someone
Lights or a siren trigger on a schedule or a rule
Targeted voice, light, and audio deterrence fires automatically at the event location
Can your system speak to an intruder without a human on the line?

Voice is the most effective non-physical deterrent in the field.

No audio capability outdoors
Prerecorded messages a person has to trigger
Live talk-down when an operator is available
AI-driven voice-down that starts automatically and escalates its message
Do you have deterrence where incidents happen?

Perimeters, lots, gates, docks, and laydown areas, not just lobbies.

Deterrence only at staffed entrances
One or two fixed locations
Most known hot spots covered
Every identified hot spot, including temporary and remote sites
Does deterrence escalate as a subject ignores it?

A single siren teaches people that nothing follows the siren.

No deterrence to escalate
One fixed response, always the same
Manual escalation if someone is watching
Automatic escalation through warning tiers based on subject behaviour
Escalate

Stage four. Getting a verified event to someone who can act on it. Without a mouse click, most programs stop here.

When an event needs escalation, how do the right people get reached?

Count the manual steps between confirmation and notification.

Someone starts calling down a printed list
An operator calls or radios one contact at a time
Automated alerts go out, follow-up is manual
The system contacts every stakeholder in parallel per the SOP and tracks who responded
Does escalation follow a documented, site-specific procedure automatically?

A binder on a shelf is not an executable procedure.

No documented escalation procedure
Documented, but executed from memory under pressure
Documented and mostly followed, with manual steps
Encoded in the system and executed automatically per site
What happens to an event outside staffed hours?

Most serious incidents happen when the fewest people are watching.

It waits until morning
An on-call person may or may not pick up
A monitoring centre handles it on contract terms
Handled identically to staffed hours, automatically
How much of your escalation depends on one person being available?

Single points of failure show up on the worst night, not an average one.

Almost all of it
A small group, and coverage gets thin
Redundancy exists but is informal
None. The workflow runs regardless of who is on shift
Respond

Stage five. Guards, police, or a monitoring centre dispatching on verified video. What responders know before they arrive decides how the incident ends.

When an incident needs a physical response, who goes?

The answer drives both your cost per incident and your arrival time.

Nobody until the next shift or the next morning
Whichever on-site staff happen to be available
A guard service or monitoring centre on contract
Dispatch decided on verified video, routed to the closest capable responder
Do responders arrive knowing what they're walking into?

Live context is the difference between a response and a surprise.

They get an address and nothing else
A verbal description relayed by phone
A still image or short clip
Live video, subject description, and location, updated as the scene changes
How often does a response turn out to be a false dispatch?

False dispatches burn budget, goodwill, and police response priority.

Often, and we've had police response deprioritized because of it
Regularly, and we absorb the cost
Occasionally. Video verification catches most of them first
Rarely. Nothing dispatches without verified video
Can you measure time from detection to responder arrival?

If you can't measure it, you can't defend it or improve it.

No, we'd be guessing
Only by reconstructing it after a serious incident
For some incident types
Automatically timestamped for every incident
Resolve and document

Stage six. An incident isn't finished when the subject leaves. It's finished when there's a defensible record, available immediately rather than written from memory at the end of a shift.

Who produces the incident record?

Manual reporting is a recurring labor cost that rarely appears in a security budget.

Often nobody, unless it was serious
A guard or manager writes it up at end of shift
A person completes a structured template
The system generates the record automatically and a person reviews it
When is the record available?

A record written from memory two days later is not evidence.

Days later, if at all
End of shift, from memory and notes
Same day, assembled manually
Within minutes of the incident closing
Does the record include video, timeline, actions taken, and outcome together?

Scattered evidence is what makes an incident hard to defend later.

Written narrative only
Narrative plus clips someone has to locate
Most elements, assembled manually
A single audit-ready record with everything attached
How quickly can you produce evidence for legal, insurance, or law enforcement?

Retrieval speed is what your organization experiences as security's value.

Days, and it may not exist
A day or two of hunting
A few hours
Minutes, retrievable by anyone authorized
Your score is ready.

Tell us who you are and your score appears on the next screen, broken out by stage.

Name
Please enter your name.
Work email
Please use your work email address.
Company
Please enter your company.
Role
Please select your role.
Monthly incident volume
Please select your monthly incident volume.
Something went wrong. Please try again.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use this to route a demo request if you ask for one. No call happens unless you request it.

0
of 72
Alert-Driven

Your band summary appears here.

Detect
0/12
Biggest gap
Verify
0/12
Biggest gap
Deter
0/12
Biggest gap
Escalate
0/12
Biggest gap
Respond
0/12
Biggest gap
Resolve and document
0/12
Biggest gap

Your score is yours to keep. Nothing else happens unless you ask.

Back
0 of 4 answered
Continue

What you get on screen.

Your result appears the moment you finish, scored stage by stage. It's an assessment, not a sales deck.

Your scored breakdown

All six stages scored out of 12, so you can see at a glance which parts of the chain run on their own and which wait on a person.

Benchmark context

How your result reads against published ASIS International research, so it lands as an industry pattern rather than a local failure.

Where you're strongest

The stage your program runs best, so the result reads as a plan to build on rather than a list of failures.

Where the chain breaks

Any stage still running on manual effort shows in yellow. The shape of the problem is obvious without reading a word.

A number you can take to a budget conversation

A score out of 72 and a named maturity band give you a defensible starting point for an internal case, not a vague sense that things could be better.

Questions to ask any vendor

The three questions that separate a system that alerts from a system that resolves. Ask them of anyone, including us.

Six bands. Most enterprise programs land in the middle.

Bands describe capability, not effort. A well-run program with disciplined people and good cameras still lands mid-scale, because the band measures how much of the workflow runs without someone deciding to run it.

0 to 12

Evidence-Based

Almost nothing runs without a person deciding to run it. The program produces a record after the fact, and little else happens on its own.

13 to 24

Detection-Led

A few steps are automated, usually in detection. Verification and everything downstream still run on manual effort.

25 to 36

Partially Automated

Parts of the workflow run on their own. The chain breaks wherever coverage or automation runs out.

Most common band
37 to 48

Response-Capable

Most of the chain holds without manual intervention. One or two stages still wait on a person being available.

49 to 60

Near-Autonomous

The workflow runs end to end with limited handoffs. A stage or two still needs attention.

61 to 72

Autonomous

Detection through resolution runs as one workflow. People handle judgment calls, not routine steps.

Thirty minutes, no deck.

You bring your score and a site layout. We walk the two weakest stages and show what closing them looks like with your existing solutions, and our autonomous capabilities, including SARA Agentic AI running the workflow from detection to resolution.

Questions about the scorecard.

What happens with your answers, what the report contains, and how this relates to the models security teams already use.

Will someone call me after I take this?
Not unless you ask. The report goes to your email and the review is a button you press, not a follow-up you receive. Most people take the scorecard, read the report, and never hear from us, which is the arrangement we intended.
The scoring model is published on this page and no question references a product. Most of the 24 questions are about process rather than technology, and the result names where you're strongest alongside your biggest gaps, whether or not we sell anything that closes them.
No. Every question is answerable from working knowledge of how your program runs day to day. If you find yourself guessing on a question, that gap is usually a finding in itself, and the report treats it that way.
Those models describe perimeter design and they end at denial. This scorecard measures what happens after the perimeter is crossed: whether response, escalation, and closure depend on a person being available to run them. Related question, different stage of the problem.