At a Midlands warehouse, the manager lately raised a ticket about a back-of-house fire door that had stopped latching shut. When a security engineer attended, the ironmongery was not the main concern. The bigger issue was that the defect had sat unlogged for weeks. A dropped hinge had opened a gap along the frame, the door had been propped for ventilation on several shifts, and the alarm contact guarding that exit point had gone without a test since commissioning three years earlier.
No harm followed. Nobody got in, nothing was taken and no report needed filing. Still, a defect like this is precisely what hands an opportunist an easy job, and such faults turn up across commercial estates far more often than owners tend to think.
The Home Office’s Commercial Victimisation Survey puts the share of UK businesses facing some type of crime this year at nearly a third. That headline takes in a broad spread of offences, from shoplifting by customers to violence against staff, yet burglary and vandalism, the very risks a well-specified security package is meant to design out, remain a sizeable slice: over a typical year, 8% of firms log a burglary or a failed attempt at one, and a further 8% log vandalism. On top of that, ONS recorded 78,707 burglaries at non-domestic premises in England and Wales over the year to March 2025. That is a substantial caseload, and it does not fall evenly across the country’s building stock. Some buildings are simply softer targets, and what sets them apart is normally a cluster of fabric and process shortcomings that creep in over time, rather than one headline defect.
Surveyors who walk commercial sites, whether a lone retail unit or a warehouse estate of several blocks, report the same five red flags cropping up repeatedly. Each looks minor when read alone. Read together, they show how exposed a building truly is.
1. Cameras That Leave Key Areas Unwatched
Cameras feature on almost every asset register. Far less common is a layout that trains them on the places an intruder would really try to breach.
The same scenario recurs: a commercial CCTV system put in years ago and bolted onto piecemeal as the footprint changed, so extensions, stores and new parking zones never made it onto the coverage schedule. Contractors frequently come across legacy analogue kit whose picture quality cannot resolve a face or a number plate at a workable distance, recorders that hold only a few days of footage before wiping it, and cameras pointed towards the car park gate while the loading bay at the side sits outside every field of view.
The right fix is not necessarily to “install more cameras.” Occasionally it means relocating a pair of existing heads to cut out a blind spot, or retiring an ageing DVR in favour of an IP-based NVR with suitable retention, remote viewing and motion alerts. The test is whether coverage genuinely tracks the site’s actual risk points, not merely where brackets went up a decade ago.
2. Exterior Lighting That Is Dim or Uneven
Of all the items on a site snagging list, this is among the cheapest to put right and the most often skipped. Shrubs left unpruned mask a dusk-to-dawn sensor. A motion-sensing floodlight fails and stays dark for months, with no fault ever raised because nobody occupies the building out of hours. Luminaires specified at construction are never reassessed as the grounds matured or new wings were added.
Weak lighting is not merely a problem for anyone patrolling on foot. It directly erodes CCTV performance, because even a good-quality camera suffers in low light unless illumination or infrared support is sized for the distances involved. A five-minute perimeter walk after dark gives engineers a surprisingly full picture: which areas have adequate light, which are lit from a poor angle, and which have quietly failed without anyone logging it.
3. Alarms Missing Their Test and Service Visits
Finding an intruder alarm more than a year overdue for its maintenance visit is so ordinary that experienced engineers seldom mention it. Installations are handed over and commissioned, then drop off the planned maintenance schedule until a false activation forces them back onto someone’s radar.
Two things make this matter. The first is that sensors wear. PIR detectors lose their calibration over time, standby batteries run past their service life, and dual-technology detectors that mix infrared with microwave sensing need recalibration at intervals to keep working properly. The second, and frequently the more serious, is compliance. Current national policy allows police response for a system maintained to BS EN 50131 and monitored through an NSI or SSAIB approved alarm receiving centre. Let the service regime lapse, clock up several false alarms, and that response priority may be removed entirely, leaving only a keyholder, or a contracted third-party response, to fall back on.
Regular maintenance is not paperwork for its own sake. It is what keeps the system delivering the protection it was specified to provide.
4. Access Rights That Are Unchecked or Stale
This category catches owners out more than any other, since it rarely registers as a security risk until someone draws it up on paper. Master keys still unchanged after multiple rounds of leavers. Alarm codes shared across a department long ago and never reset. Fobs issued to staff who have since departed and never cancelled.
Consultants regularly arrive at buildings where the site lead honestly cannot confirm the number of people who still have a working key or code. That is no failing on the manager’s part. It is the predictable drift of years of joiners and leavers without a proper access control platform recording who came in, who went out and at what hour.
A modern access control installation, whether it runs on cards, fobs or biometrics, delivers two things no bundle of shared keys can: it confines each user to set hours and areas, and it generates an audit record. Should anything go wrong, that log is often what separates a clear account of events from guesswork.
5. Detection Left Disconnected From Any Response
An alarm that sounds on and on with nobody attending offers, in real terms, no more protection than no alarm at all. Some sites still run the intruder alarm as an isolated unit that reports to no monitoring station, trusting the siren alone to put off an intruder or catch a passer-by’s ear.
Monitored systems, tied to an alarm receiving centre and supported by a keyholder register that is kept current, close that gap. Once a signal comes in, the ARC can verify it, work through the keyholders in the agreed order and, where eligibility allows, call for police attendance. Absent that link, the speed of any response is left to chance: whether anybody picks up on the siren, whether they have a number to ring, and whether that contact can be reached.
The keyholder register deserves its own review too. Engineers frequently turn up lists carrying disconnected numbers, people who no longer work there, or a call-out sequence that does not match who can actually attend at short notice.
Seeing the Whole Picture
Individually, none of the five is a disaster. A floodlight running a little dim or a keyholder register nobody has audited will not, alone, finish a business. Trouble is, they rarely occur singly. Where exterior lighting is weak, the camera equipment is often dated too, with no upgrade ever made to offset the darkness. An organisation lax about cancelling old fobs is frequently just as lax about alarm maintenance. The risks stack up.
A proper site assessment earns its fee not by exposing one spectacular fault but by showing the pattern that runs through all five areas and how each feeds into the others. A warehouse with excellent cameras but an alarm that reports to nobody still has a serious hole. A shop unit whose alarm is serviced like clockwork, yet whose cameras leave blind spots, remains exposed to opportunist thieves who would never set that alarm off.
An owner who sees even one of these weaknesses, or perhaps two, in their own buildings should take an easy next step: commission a competent specialist to carry out a full site walk, rather than letting an incident settle the question. The warehouse manager in the opening story was lucky. The defect was picked up before anyone made use of it. Not every business will be so fortunate by accident, and given how prevalent commercial burglary is at present, leaving things to chance is no way to run a site.




