
A perimeter breach at an unmanned pumping station or an unmonitored gate at a tank farm rarely makes headlines until it becomes an incident. Physical Security Vulnerability Assessment services identify these gaps before an intruder, saboteur, or opportunist does. iFluids Engineering delivers combined Physical Security Assessment (PSA) and Security Vulnerability Assessment (SVA) studies for oil and gas, petrochemical, and energy facilities across GCC, India, and Southeast Asia.
A PSA evaluates the physical protection measures already in place: fencing, CCTV coverage, access control, intrusion detection, and lighting. An SVA goes further. It quantifies the likelihood and consequence of specific threat scenarios against critical assets, ranking vulnerabilities so that capital and manpower are directed at the risks that matter most. Together, PSA and SVA give facility owners a defensible, standards-aligned basis for security investment decisions.
Our engineers do not arrive with a generic checklist. Every assessment starts with the facility’s own documentation: scope of work, general arrangement drawings, existing security philosophy, and current system layouts. From there, we build a vulnerability picture specific to that site, not a template borrowed from an unrelated industry. The result is a report that operations, security, and management teams can act on immediately, not a binder that sits on a shelf.
What is a Physical Security Assessment (PSA) and Security Vulnerability Assessment (SVA)
iFluids Engineering delivers combined PSA and SVA studies that evaluate existing physical protection systems and quantify threat-based vulnerabilities for oil and gas and critical infrastructure facilities. Our assessments benchmark findings against ISO 31000 and API SP 780, producing a ranked action register client security teams can implement directly.
A Physical Security Assessment is a structured review of a facility’s existing protective measures against its stated security philosophy. It asks a narrow question: does what is installed match what was intended? A Security Vulnerability Assessment asks a broader question: given the threats a facility actually faces, where are the gaps that matter, and in what order should they be closed?
The distinction matters because a facility can have excellent equipment and still carry serious risk. A CCTV system with full coverage but a blind spot at the one gate used for emergency vehicle access is a PSA pass and an SVA failure. Our combined approach catches both categories of finding, which is why we run them as a single integrated study rather than two separate engagements.
For process facilities specifically, the security review has to account for what a breach could trigger downstream: unauthorized access to a control room, tampering with a custody transfer skid, or interference with an emergency shutdown system. A generic corporate security consultant evaluating retail or office premises does not carry this context. Our engineers do, because process safety and security assessment sit under the same technical discipline at iFluids.

Our PSA/SVA Methodology

iFluids Engineering executes a document-led, site-verified methodology for every Physical Security Vulnerability Assessment, combining desk review of existing facility data with structured field verification against ISO 31000 risk criteria. The result is a vulnerability register mapped directly to facility layout and existing security infrastructure.
We start by reviewing facility documentation before a single engineer sets foot on site. This is the review that separates a rigorous assessment from a walkthrough with a clipboard.
Our standard document intake covers:
| Category | Documents Reviewed |
| Project Basis | Scope of Work (SOW), Facility General Arrangement (GA) / Plot Plan |
| Governance | Existing Security Philosophy or Security Management Plan (client document) |
| Existing Systems | CCTV layout, Access Control System layout, Intrusion Detection System layout, Perimeter Fence and Gate layout, Security Lighting layout |
| Facility Data | Building layouts and floor plans, Vehicle Entry/Exit and Traffic Flow plan |
| Procedures | Visitor management, Access control, Guard patrol procedures, Emergency response procedures |
| Planning | Site Emergency Response Plan, Applicable client security standards and specifications |
| Assets | List of critical buildings and infrastructure |
| Operations | Guard force deployment, Patrol arrangements, Security control room operations |
Once the desk review is complete, our team follows a structured field methodology:
- Conduct a document gap analysis against the facility’s stated security philosophy
- Perform a physical walkthrough of the perimeter, access points, and critical asset zones
- Verify CCTV coverage, access control function, and intrusion detection response against layout drawings
- Interview guard force and security control room personnel on procedures in practice, not procedures on paper
- Score each identified vulnerability for likelihood and consequence using an ISO 31000-aligned risk matrix
- Rank findings into a prioritized action register with recommended remediation and indicative timelines
This sequence means every finding in the final PSA/SVA report traces back to a specific document, drawing, or observation. Nothing is asserted without evidence.
Recognized for excellence.
PROJECTS DELIVERED ACROSS THE GLOBE
Industries and Facilities We serve

iFluids Engineering conducts Physical Security Vulnerability Assessments for onshore and offshore oil and gas facilities, petrochemical plants, and energy infrastructure across GCC, India, and Southeast Asia. Our PSA/SVA scope covers refineries, gas processing trains, pipelines, tank farms, and unmanned or remotely operated facilities.
Every facility type carries a different threat profile, and our PSA/SVA scope adjusts accordingly. A refinery with continuous manned operations has a different vulnerability set than an unmanned wellhead or a remote pipeline valve station with only periodic patrol coverage. Offshore platforms introduce access-control questions that an onshore perimeter fence assessment never has to address.
Across GCC, India, and Southeast Asia, we have delivered Physical Security Vulnerability Assessment engagements ranging from single-site tank farms to multi-facility pipeline networks spanning several hundred kilometres. The common thread across every PSA/SVA engagement is the same combined discipline: document review, field verification, and a prioritized, standards-referenced vulnerability register at the end.
Regulatory and Standards Compliance
iFluids Engineering benchmarks every Physical Security Vulnerability Assessment against ISO 31000 risk management principles, API SP 780 security risk assessment methodology, and applicable client and regional security specifications. This dual-standard PSA/SVA approach gives facility owners a defensible, standards-traceable basis for security capital decisions.
ISO 31000 provides the risk assessment framework our engineers apply to score likelihood and consequence for each identified vulnerability. It is not a security-specific standard, but its structured risk criteria give an SVA the same rigor process safety studies already carry at most O&G facilities, which makes it easier for security findings to sit alongside HAZOP and SIL documentation in a client’s risk register.
API SP 780 sets out a security vulnerability assessment methodology developed specifically for the petroleum and petrochemical industry, and forms the technical backbone of every PSA/SVA we deliver. It addresses asset criticality ranking, threat characterization, and countermeasure evaluation in terms an operations team already recognizes from process hazard analysis work. Where a client operates under a named regional or corporate security standard, our assessment is scoped against that specification directly, in addition to the frameworks above. This dual-track approach, international standard plus client-specific requirement, is what keeps our findings acceptable to both corporate security and regional regulatory reviewers

Why Engineering Teams Choose iFluids
iFluids Engineering brings process safety and engineering discipline to every physical security vulnerability assessment, a combination generic security consultancies do not offer. Our teams read a P&ID and a CCTV layout with the same technical fluency, which means our PSA/SVA findings connect security gaps to operational risk, not just perimeter risk.
Most consultancies offering physical security vulnerability assessment services in GCC, India, and Southeast Asia come from a corporate, retail, or aviation security background. They can assess a fence line. They are less equipped to explain why a blind spot near a custody transfer skid carries a different consequence than a blind spot near an office car park. iFluids engineers work from the same technical base used in our process safety and design consulting services, so a PSA/SVA finding is written in language a plant manager and a process safety engineer both recognize immediately.
We are ISO 9001, ISO 14001, ISO 27001, and ISO 45001 certified, and hold KOC and ADNOC accreditation. Our teams have delivered engineering and safety studies across GCC, India, and Southeast Asia since 2015, with offices in Qatar, Oman, Abu Dhabi, and Malaysia supporting direct site access for field verification work.
Deliverables and Outcomes
Every Physical Security Vulnerability Assessment we deliver produces a document-referenced vulnerability register, a ranked action register with remediation timelines, and a final report aligned to ISO 31000 and API SP 780 methodology. Clients receive findings they can hand directly to security, operations, and corporate risk teams without further translation.
Standard PSA/SVA deliverables include a facility vulnerability register mapping each finding to its supporting document or field observation, a prioritized action register ranked by likelihood and consequence, and a final PSA/SVA report suitable for both internal risk governance and, where applicable, regulatory submission. Where a client requests it, we also provide a summary briefing for site leadership covering the top-priority findings and recommended near-term actions. Clients consistently tell us the value is in the traceability. Every recommendation in the action register points back to a specific gap between the security philosophy document and what our team verified in the field, which makes budget approval for remediation work considerably easier to secure internally.
Ready to Discuss Your Project
If your facility has not had a physical security vulnerability assessment in the last two to three years, or your existing security philosophy document has never been checked against what is actually installed and operating, this is the starting point. iFluids Engineering has delivered process safety and engineering studies across GCC, India, and Southeast Asia since 2015, and our PSA/SVA teams apply the same document-led, standards-referenced rigor to every security engagement.
We scope every PSA/SVA against your facility’s own documentation first, so the proposal you receive reflects your site, not a generic template. Our teams are based in Qatar, Oman, Abu Dhabi, and Malaysia, with direct access for field verification across the region. To discuss the scope of your facility’s security review, contact iFluids Engineering. For a look at how our engineering-led approach translates into delivered outcomes, see our process safety project case studies
Frequently Asked Questions
A Physical Security Assessment (PSA) reviews whether existing security systems match the facility’s stated security philosophy. A Security Vulnerability Assessment (SVA) ranks risk by likelihood and consequence against specific threat scenarios. iFluids delivers combined physical security vulnerability assessment services that run both as one integrated study, so equipment gaps and risk-based gaps are captured together
iFluids benchmarks assessments against ISO 31000 risk management principles and API SP 780, the petroleum industry’s dedicated security vulnerability assessment methodology. Client-specific security standards and regional regulatory requirements are scoped in addition, giving the final report a dual-track, defensible basis for security investment decisions
Typical intake for a Physical Security Vulnerability Assessment includes the scope of work, facility general arrangement or plot plan, existing security philosophy document, current CCTV, access control, intrusion detection, fencing and lighting layouts, security procedures, and the site emergency response plan. Our team reviews all available documentation before any field verification begins.
Duration depends on facility size, number of critical assets, and document availability. A single-site facility with organized documentation typically requires two to four weeks from document review through final report delivery. Multi-facility or pipeline network assessments take longer and are scoped individually during the proposal stage
The report includes a document-referenced vulnerability register, a prioritized action register ranked by likelihood and consequence, and remediation timelines aligned to ISO 31000 and API SP 780 methodology. A summary briefing for site leadership is available on request, covering the highest-priority findings first.
Our physical security assessment teams work from the same engineering base as our process safety and design consulting groups. This means findings are written in language operations and process safety teams already recognize, rather than generic corporate security terminology unfamiliar to a plant environment.