
Services
Nine capabilities across security, resilience, and governance. Engaged individually or as an ongoing advisory retainer.
Security
Understanding what you are actually carrying.
Physical security assessments
On-site walkthroughs documenting the security measures in place and where they fall short of the risk the organization carries. Findings are written up and prioritized by exposure, not by cost.
- Access control at entries, common areas, and after hours
- Camera coverage, placement, retention, and export capability
- Lighting levels and uniformity across parking, walkways, and entries
- Landscaping, sightlines, and territorial reinforcement
- Reception protocol, visitor management, and key control
- Guard service scope and post orders where applicable
CPTED and statutory compliance
Crime Prevention Through Environmental Design assessments, including compliance assessments for multifamily residential properties under Florida Statute 768.0706. The statute requires an assessment no more than three years old, performed by a law enforcement agency or a designated Florida CPTED Practitioner.
- CPTED assessment for any property type
- Florida Statute 768.0706 compliance assessments
- Written documentation of conditions against the statute
- Portfolio pricing for property management companies
- Remediation sequencing after the assessment
Security technology planning
Ownerโs representative services for camera, access control, and related infrastructure. G.I.S. does not sell, install, or service equipment and takes no vendor commissions, which means the recommendation is independent of whoever bids the work.
- Needs assessment and design basis before procurement
- Capital budgeting and phasing
- Technical requirements and specification development
- RFP drafting and bid evaluation
- Vendor selection support
- Implementation oversight and commissioning review
Contracted vendor review
An independent review of guard services, patrol, and monitoring already under contract, evaluating whether current spend matches actual performance and risk exposure. This is separate from technology and system selection, which is scoped under security technology planning.
Cross-border security advisory
Regional threat and travel risk advisory for organizations and executives operating in the Caribbean and Latin America, delivered in English and Spanish.

Resilience
Building what happens next.
Business continuity and emergency planning
Frameworks for how an organization keeps operating through a hurricane, an extended power loss, or an infrastructure failure, and how it reopens afterward. Built on FEMA ICS and NIMS methodology and applied emergency operations practice. Reviewed annually.
- Emergency operations planning
- Closure, release, and reentry authority defined in writing
- Continuity of operations for critical functions
- Vendor and dependency mapping
- Communications planning for staff, residents, and stakeholders
- Plan review scored against FEMA CPG 101 or NFPA 1600
Tabletop exercises
Facilitated discussion-based exercises so leadership makes the hard decisions before a real event rather than during one. Objectives are set in advance with the client and documented afterward.
- Scenario design matched to real exposure
- Facilitated sessions, on site or virtual
- Written after-action summary with improvement items
- Quarterly cadence available under retainer
Crisis response
A named point of contact who already knows your operation, available when something happens. Retainer clients have direct access rather than starting a relationship mid-incident.
- Direct advisory contact during an active disruption
- Coordination guidance with responding agencies
- Post-incident review and documentation
- Recommendations carried into the next plan revision
Governance
The framework behind the decisions.
Program and policy development
The written framework a client needs before an incident, and the training that makes it usable.
- Investigation protocols and case documentation standards
- Workplace violence prevention programs
- Threat assessment program design
- Incident reporting and escalation procedures
- Training for the staff who carry the programs out
Information security governance
Governance and physical protection of information assets.
- Information classification and handling policy
- Access control policy: how access is granted, reviewed, and revoked
- Physical protection of information: storage, disposal, clean desk
- Insider risk programs
- Support for client and vendor security questionnaires
Litigation support
Consulting services for defense counsel and corporate legal departments in premises liability and negligent security matters. Work is performed from records provided by counsel.
- Review of security measures in place at the time of an incident
- Prior incident history and foreseeability analysis
- Early case assessment on security adequacy
- Evaluation of CPTED assessments relied on under 768.0706
- Discovery guidance on security records
- Deposition question development for opposing experts
Insurance and risk transfer advisory
Connecting assessment findings to coverage decisions. G.I.S. coordinates with brokers and carriers on the underwriting-relevant documentation a risk transfer strategy depends on. G.I.S. does not sell or place insurance.
Engagement models
Project, retainer, or counsel.
Project
- A defined scope with a fixed fee
- An assessment, a plan, an exercise, or a technology program
- Written deliverable at completion
Retainer
- Fractional Director of Security and Resilience
- Named point of contact, ongoing oversight
- Coordinates vendors and subcontractors through implementation, not just the report
- Quarterly walkthroughs, exercises, and annual plan review
Counsel
- Engaged by defense counsel or legal departments
- Billed hourly against a replenishing retainer
- Work performed from records provided
