A fire door at the back of a Midlands warehouse had stopped closing properly, its manager reported recently. The engineer dispatched to assess it had a bigger concern than the fault itself: weeks had gone by and nobody had picked it up. A dropped hinge had left a gap. Staff had jammed the door open to let air in more than once. And the alarm sensor on that entry point had not been tested once in the three years since the system was fitted.

No harm followed, as it happened. Nobody broke in, nothing was taken and there was no report to write. But a flaw like this hands opportunists an easy job, and it turns up at far more premises than owners tend to think.

The Home Office’s Commercial Victimisation Survey puts it bluntly: nearly a third of firms across the UK will be hit by some type of crime this year. The survey casts a wide net, taking in everything from customers stealing stock to staff being assaulted. Burglary and vandalism, precisely what decent security is meant to stop, remain a substantial slice: each year 8% of firms are burgled or face an attempted break-in, and vandalism hits a further 8%. The ONS, tallying the twelve months to March 2025, recorded 78,707 burglaries of non-domestic premises, and that is England and Wales on their own. That is no minor figure by any measure, and the risk is lopsided. Some sites make far softer targets than others, and the gap usually comes from a cluster of physical and procedural lapses that creep in over time, rather than a single obvious collapse.

Specialists surveying commercial sites, from a single shopfront to a warehouse estate spread across several buildings, report the same five red flags cropping up repeatedly across jobs of every size. Individually, none looks serious. Combined, they show exactly how exposed a site is.

1. CCTV That Misses the Weak Spots

Cameras are standard kit at most firms these days. Far fewer have them trained on the routes a burglar would really use to get in.

Surveyors see the same story over and over: a commercial CCTV system put in years ago and bolted onto in stages as the premises changed, leaving extensions, stores or chunks of car park outside its view. Installers keep finding old analogue kit too grainy to make out faces or number plates from a sensible distance, recorders that wipe footage after a few days, and cameras fixed on the car park gate while the loading bay round the side goes uncovered.

The remedy is seldom as blunt as “install more cameras.” Sometimes shifting two existing units kills a blind spot. Sometimes it means swapping an elderly DVR for IP-based NVR recording that keeps footage longer, can be viewed remotely and sends motion alerts. The test is whether coverage tracks the building’s real weak points, not where brackets went up a decade ago.

2. Gloomy, Uneven Lighting Outside

It is cheap to put right and routinely ignored. Hedges grown over a dusk-to-dawn sensor. A motion floodlight dead for months, never reported because the site is empty after dark. Lamps fitted when the building opened and never rethought as the planting spread or new wings were added.

Bad lighting hurts more than visual patrols. It cuts straight into CCTV performance, because a decent camera still struggles in the gloom without enough light or infrared matched to the range. Give engineers five minutes on the perimeter after dark and they learn a surprising amount, more than most people expect: which areas are truly lit, which are badly aimed and which have slipped into darkness unseen.

3. Alarms Nobody Has Checked or Serviced

Installers find so many intruder alarms more than a year past their last service that they rarely mention it now. A system goes in, gets commissioned, then is largely forgotten unless, or until, a false alarm forces the issue.

Two things are at stake. First, sensors wear. PIR detectors drift out of calibration, backup batteries pass their useful life, and dual-technology detectors combining microwave and infrared need periodic recalibration to work properly. Second, and often bigger, is compliance. Current national policy grants a police response to any system serviced in line with BS EN 50131 and linked to a receiving centre carrying NSI or SSAIB approval. Let servicing slide, notch up a few false alarms, and that priority can be pulled completely, leaving only a keyholder or a private response firm to turn up.

Regular servicing is not paperwork for its own sake. It is how the system stays fit for the purpose it was bought to serve.

4. Keys, Codes and Fobs Nobody Tracks

Owners are most often caught out here, because it rarely registers as a security risk until someone lays it out. Master keys unchanged through wave after wave of leavers. Alarm codes shared across a team years ago and never reset. Fobs issued to ex-staff that still open doors.

Consultants regularly arrive at sites where the manager has no idea how many working keys or codes are still out there. That is no slight on the manager. It is what years of staff churn produce when no access control system is recording every entry and exit with a time stamp.

A modern setup, using cards, fobs or biometrics, offers two advantages no shared key can match. It restricts who gets in, where and at what hours, and it leaves an audit trail. When trouble hits, that log can separate a precise account of events from guesswork.

5. An Alarm Sounds, and Nobody Comes

An alarm ringing out endlessly with no one answering is, in practice, as good as no alarm at all. Engineers still come across standalone intruder alarms that report to no monitoring station and rely on noise alone to scare off a burglar or alert someone walking past.

Hooking the system up to one of the alarm receiving centres, and keeping the keyholder list current, closes that gap. When a signal lands, the ARC checks whether the alert is genuine, works through keyholders in the correct order and, if the system qualifies, asks police to attend. Without that link, response comes down to chance: whether the siren reaches anyone’s ears, whether that listener knows who to phone, and whether the contact picks up.

Keyholder lists need their own check too. Engineers routinely find dead numbers, people who have left the firm, or a call order that bears no relation to who can actually get there at short notice.

Joining the Dots

Alone, none of the five is a disaster. A dim floodlight or a keyholder list nobody reviews won’t bring a firm down on its own. Yet they rarely show up singly. Poorly lit sites often run old CCTV that was never improved to match. Firms slack about cancelling old fobs are usually slack about alarm servicing too. The risks compound.

A full site survey is not about spotting one headline flaw. Its value lies in seeing the pattern running through all five areas and understanding how they feed into each other. A warehouse with top-notch CCTV but an unmonitored alarm still has a serious hole. A shop with a well-kept alarm but camera blind spots is still open to opportunist theft the alarm will never register.

Owners who find one weakness on this list, or two, at their own site have an obvious next move: get a qualified specialist to walk the premises properly, instead of letting an incident force the question. The Midlands warehouse manager was lucky. The gap turned up before anyone used it. Not every firm gets that break by chance, and with commercial burglary running at current levels, luck is no plan to bank on.