Security KPIs: How to Measure Whether Your Provider is Performing

Most security contracts run for years without a formal performance framework. Incidents are logged, shift rotas are filled and the account manager attends an occasional review meeting. But the question of whether the security provision is actually performing – reducing risk, delivering consistently, responding appropriately – is rarely answered with data.

This matters because without measurement, you cannot distinguish between a security provider that is genuinely performing well and one that has simply not been tested. Here are the metrics that give you that distinction.

Response time standards

Response time is the most operationally significant KPI in physical security. It covers two scenarios: response to alarm activations (how quickly does a guard or patrol officer arrive on site after an alarm triggers?) and response to reported incidents (how quickly does the provider acknowledge and act on an incident reported by your staff?)

These should be specified in the contract SLA as hard commitments with defined consequences for breach. Typical standards: alarm response within 20-30 minutes for urban sites, up to 45 minutes for rural; incident acknowledgement within 15 minutes during staffed hours. If your current contract has no defined response time commitment, that is a gap worth addressing at the next review.

Guard retention rate

High guard turnover at a site is one of the most reliable indicators of a security provider under operational strain. Frequent changes in the guarding team mean guards who are unfamiliar with your site, your staff, your access requirements and your incident history. This creates vulnerability.

A guard retention rate of 80%+ at 12 months is a reasonable benchmark for a well- run security contract. Ask your provider what the retention rate is at your specific sites – not the company average. If they cannot tell you, that is itself an informative answer.

Training and licensing compliance

Every security guard assigned to your site should hold a current SIA licence. Beyond that baseline, role- specific training – first aid, conflict management, CCTV operation, access control – should be tracked and current. Ask your provider for a training compliance report covering the guards on your account. It should show: SIA licence status and expiry for each guard; role-specific training completed and dates; any training outstanding or overdue.

A provider that cannot produce this report on request does not have the management systems to track it systematically.

Incident report quality and turnaround

The quality and timeliness of incident reporting tells you a great deal about a provider’s operational rigour. A well- written incident report arrives within 24 hours of the incident, includes the facts (who, what, when, where and what action was taken), is written clearly enough to be used in an insurance or legal context and is filed consistently regardless of whether the incident was significant.

Ask to see sample incident reports – anonymised if needed – from your provider before you contract. If reporting quality at the proposal stage is poor, it will not improve in delivery.

Account review conduct and action log

Monthly or quarterly account reviews should be structured, minuted, and produce a documented action log with owners and deadlines. If your current security provider attends reviews but the outcomes disappear into verbal commitments, the review is serving the provider’s relationship management, not your operational oversight.

A performance- oriented provider will bring data to reviews: incident summary, response time performance, training compliance, guard retention, any open issues and their status. If the review is a conversation rather than a structured performance assessment, ask your provider to change the format.

Building KPIs into the contract from the outset

Performance measurement is significantly easier to enforce when it is written into the contract from day one. Retrofitting KPIs into a running contract is possible but requires negotiation. At renewal or re- tender, include a formal KPI framework in the SLA as a non- negotiable contractual requirement – not a nice- to-have.

Not sure how your current security provision measures up?

Request a security programme review from Magenta. We’ll assess your current provision against industry benchmarks and identify where performance gaps exist – no obligation, no hard sell. 

Book a Security Review

Magenta Security has held NSI Gold accreditation and BSIA membership for more than 25 years and ranks among the top 5% of SIA Approved Contractors in the UK. Established in 1995, the company directly employs its security officers and supports every contract through its 24/7 National Control Room, £10 million public liability cover and 100% money-back guarantee (subject to contractual terms and conditions).

Web based CCTV Remote Monitoring

New service - from as little as £1 per camera

Find out more
loading...