The building that didn't get signed.
A threat and vulnerability assessment that ended in a recommendation to walk away, and a client who did.
A building had cleared the commercial process and was moving toward signature. The security position had been described in the vendor's own documentation and had not been independently examined against the standard the occupier actually applies.
Line by line, back to source.
The physical security position of the site, on site, against the occupier's own standard
What could realistically be remediated after occupation, and at what cost
The residual risk that would remain even after everything remediable had been done
The gap between the building's position and the required standard could not be closed to an acceptable level after occupation.
The remediation cost that would have been carried post-signature had not been priced into the deal.
The recommendation was not to remediate. It was not to take the building.
The client walked away. The value of that finding is not a saving that appears on a report; it is a liability that was never taken on. Independent review is worth most when it says no.
