← Case studies
Global technology occupierPre-acquisition threat and vulnerability assessment

The building that didn't get signed.

A threat and vulnerability assessment that ended in a recommendation to walk away, and a client who did.

1
Building recommended against, and not taken
What was unchecked

A building had cleared the commercial process and was moving toward signature. The security position had been described in the vendor's own documentation and had not been independently examined against the standard the occupier actually applies.

What we examined

Line by line, back to source.

01

The physical security position of the site, on site, against the occupier's own standard

02

What could realistically be remediated after occupation, and at what cost

03

The residual risk that would remain even after everything remediable had been done

What we found

The gap between the building's position and the required standard could not be closed to an acceptable level after occupation.

The remediation cost that would have been carried post-signature had not been priced into the deal.

The recommendation was not to remediate. It was not to take the building.

What changed

The client walked away. The value of that finding is not a saving that appears on a report; it is a liability that was never taken on. Independent review is worth most when it says no.