Security patrols
Security KPIs: what to measure, and how to know the figures are true
Security KPIs (key performance indicators) are measurable figures, each with an agreed definition and target, that show whether a security program or a guard services contract is delivering what was promised.
They are how a client and a security company agree whether the contract is working. A handful of well-defined KPIs show whether every post was covered by a licensed, trained officer, whether patrols and checks happened, and whether problems were reported and dealt with. Badly chosen ones produce a green monthly report and a lobby nobody was watching. This guide covers which KPIs to use, how to define and verify them, and how to report them.
01
What security KPIs are, and which rules touch them
A key performance indicator (KPI) is a measurable figure that shows whether a service is meeting the standard both sides agreed. In a security services contract the KPIs usually sit in the contract or its service level schedule, each with a definition, a target, a measurement period and a source of evidence, and they are reviewed at a regular meeting between the client's facility or security manager and the security company's account manager. The term is also used in cybersecurity, where KPIs track how quickly threats to an organization's systems are detected and dealt with; this guide deals with physical security and guard services, though the method is the same.
No federal or state law sets KPIs for a private guard contract in an ordinary commercial building. What the law does set is the ground the KPIs stand on: state licensing and training rules for officers, OSHA recordkeeping for injuries, and, in some states, specific records such as California's violent incident log. The performance measures themselves are a matter of contract.
Federal contracting shows the method most clearly. Under the Federal Acquisition Regulation, section 37.601 (FAC 2026-01), performance-based contracts for services must include a performance work statement, measurable performance standards "in terms of quality, timeliness, quantity, etc.", and performance incentives where appropriate, which must correspond to those standards. FAR 46.401 says a quality assurance surveillance plan (QASP) should be prepared alongside the statement of work and should specify all work requiring surveillance and the method of surveillance, and FAR 37.604 lets the government either write the QASP itself or ask bidders to propose one.
A private client does not have to follow the FAR, but the pattern is worth borrowing: say what the work is, say how each part will be measured, and say how the client will check the measurement. A set of security KPIs without the third part is a set of numbers the provider reports about itself.
02
The security KPIs worth measuring
Most guard contracts need between five and ten KPIs. The ones worth considering on almost any site are these:
- Post coverage: contracted post hours actually staffed, and the number of posts left unfilled or filled late in the period. Every other measure depends on this one.
- Patrol and checkpoint completion: scheduled patrols and checkpoint checks completed against those planned in the post orders, for example the 0200 perimeter round or the hourly check of a stairwell door.
- Response time: how quickly an officer attends an alarm, a call from a tenant or a request from the console, measured by priority.
- Incident reporting: incidents written up within the agreed time, with the required fields complete, and escalated to the client when the contract says they must be.
- Supervisor post inspections: inspections completed against those planned, and the share of inspected posts where the officer knew the post orders, had the right equipment and was where the post orders say.
- Licensing and training compliance: officers on post with a current state license or registration and training completed by its deadline, including site-specific training before first standing a post.
- Hazards and maintenance faults reported: issues found on patrol, such as a propped fire door, a light out in the parking garage or a leak, and how many were passed to the right person and closed.
- Complaints and repeat failures: complaints from the client or tenants, and how many concern a problem already raised.
- Officer safety: injuries to officers on the contract, and near misses, with how each was followed up.
Some measures are tempting but belong elsewhere. Crime counts on the property depend on far more than the officers on duty, and a target to reduce them can push officers toward not reporting. Officer turnover matters, because a new officer who has not learned the post is a weaker post, but it is the security company's workforce measure; the client usually tracks its effect through post inspection results and training compliance instead. Cost per post hour is a procurement measure, not a measure of performance.
Special posts add their own measures. A screening post might be tested with planned test items; a control room might be measured on alarm acknowledgment times; a security supervisor running a mobile patrol route might be measured on sites visited against the schedule. The principle is the same: pick the few measures that show whether this site was protected as agreed.
03
Defining each KPI and setting the target
Every KPI needs a written definition both sides agree before the contract starts. For each one, set out:
- What is measured, precisely. "Patrols completed" needs to say what counts as a patrol, which checkpoints it must include, and whether a round started 40 minutes late still counts.
- The source of the data: the scheduling system, checkpoint records, the daily activity report, incident reports, training files, the client's own complaint log.
- Who measures it, and how the client verifies it. This is the QASP question: joint inspections, spot checks, a sample of reports read each month.
- The period: weekly, monthly or quarterly.
- The target, and the level below which it counts as a failure.
- What happens on a failure: a corrective action plan, a meeting, or a service credit if the contract has them. FAR 37.601 ties incentives to the stated standards, which is a sound rule in private contracts too.
Set targets from a baseline. The first month of a new contract, or the last three months of an existing one, shows what the site actually achieves. A target of 100% on anything measured by inspection will be missed, and a contract that fails a KPI every month stops taking it seriously. A target nobody ever misses is not measuring anything.
Be careful with targets on incidents. A KPI that rewards fewer incident reports rewards officers for writing fewer of them. Measure the timeliness and completeness of reports, not their number, and treat a rise in reported hazards as officers doing their job until the evidence says otherwise.
Weight the KPIs to the site. A hospital emergency department cares about response time and workplace violence; a distribution center cares about gate and dock checks; an office tower cares about the lobby and after-hours access. Timings should be realistic for the ground covered. The Interagency Security Committee's Armed Contract Security Officers in Federal Facilities, in its appendix on estimating staffing, for example, expects a patrol and response post to patrol at about 1.5 miles per hour, including stops at set points; that is a planning assumption, not a target, but it is a useful check on a patrol schedule that could not physically be walked.
04
Licensing, training and safety: the compliance KPIs
Licensing and training are the easiest KPIs to define, because the law sets the deadlines, and among the most often wrong in practice, because nobody checks the files until something goes wrong. The rules are set by each state, so the KPI must follow the state the site is in. Two examples:
- California. Under Business and Professions Code section 7583.6 (as amended by SB 652, effective January 1, 2026), a guard must complete a course in the power to arrest and the appropriate use of force before registration is issued, then "not less than 32 hours of training in security officer skills within six months", 16 of them within 30 days, and must "annually complete eight hours" of review or practice of security officer skills.
- New York. The Department of State's security guard training requirements set an 8-hour pre-assignment course, 16 hours of on-the-job training within 90 days of employment, and an 8-hour annual in-service course each calendar year the registration is held.
A useful compliance KPI counts officers who stood a post in the period with their license current and every training deadline met, against all officers who stood a post. Missed deadlines are a finding in themselves, whatever the percentage.
For armed officers at federal facilities, the Interagency Security Committee's Armed Contract Security Officers in Federal Facilities (2019 edition) says agencies "shall have a system to validate" that officers meet the contract's qualification and training requirements, that officers should qualify with firearms every six months and receive annual refresher training, and that officers newly assigned to a post should be familiar with its post orders before standing it. Private clients can adopt the same three measures for armed posts, alongside whatever their state requires.
Officer safety is measured the way the Bureau of Labor Statistics guide to computing incidence rates sets out: the number of OSHA recordable injuries and illnesses multiplied by 200,000, divided by the hours actually worked, the 200,000 standing for 100 employees working 40 hours a week for 50 weeks. The security company is usually the employer that records its officers' injuries, so the client asks for the rate on the contract rather than keeping it.

05
Reporting security KPIs, and checking the figures
Security KPIs are usually reported monthly, in a short report reviewed with the account manager, with a quarterly review of trends and the contract as a whole. A useful monthly security report shows:
- each KPI against its target, with a simple red, yellow or green status;
- the trend over several months;
- the reasons behind any failure, and the corrective action taken;
- open issues found on patrol, who owns them and how long they have been open;
- anything that keeps recurring, and what is being done about it.
Monthly is too slow on its own. A patrol missed on the 3rd and reported on the 30th has already been forgotten by everyone except whoever found the door unlocked. Many clients also want a daily or weekly view of what was due, what was done and what is still open.
Then check the figures. The federal experience is a warning. In March 2025 the Government Accountability Office reported on the Federal Protective Service's oversight of its contract guards (GAO-25-108085): in 27 covert tests, guards detected the prohibited item (a baton, pepper spray or a multi-purpose tool with a knife) in only 14, and a Post Tracking System deployed in 2018 was, six years later, "beset with problems" and not meeting its purpose, so paper remained the official record and the agency could not verify in real time that posts were staffed by qualified guards. If an agency with a dedicated oversight program struggles to know its posts are covered, a private client relying on a provider's monthly spreadsheet should assume it needs checks of its own.
Practical checks a client can make without a large program:
- Joint post inspections, at irregular times including nights and weekends, recording what was found.
- A monthly sample of incident reports and daily activity reports, read against what the client knows happened.
- Spot checks of training files for a few named officers, against the state's deadlines.
- Planned tests where the contract allows them, such as an unannounced visitor at the front desk, agreed in advance with the security company.
06
Where the record fails, and where SiteClara fits
Of all security KPIs, patrol and checkpoint completion is the one most often built on the weakest evidence. The figure in the monthly report is usually taken from daily activity reports and supervisors' notes. "0200 patrol completed, all secure" reads the same whether the officer tried every door or wrote it at the console, a missed round is rarely written down as missed, and a light out on a parking level noted at 3 a.m. stays in the report unless someone passes it on.
SiteClara records the routine part of the shift where it happens. A printed QR poster, with an optional NFC tag behind it, goes at each checkpoint the post orders name: a stairwell door, a loading dock, a roof access, a parking level. The officer scans the code or taps the tag on their own phone, with no app to install, sees the checks due at that point and marks each one done, or says what stopped them. The time and the named officer are recorded as it happens, with a photo when one is asked for. A problem found on the round is reported there and goes onto the team's list of jobs until someone closes it.
The supervisor sees what was due, done and missed, and records the reason a check was missed. Each day they review the totals and photos, add a note and approve a report that goes to nominated management or client contacts at 8 a.m. the next morning, showing what was reported, what was completed, what is still open and how the scheduled checks went, for example 11 of 12 completed. That gives the checkpoint completion and open-issue KPIs a daily source recorded at the time, rather than reconstructed for the monthly meeting.
07
Questions people ask
What is a KPI in security?
A key performance indicator is, in the words of NIST's Measurement Guide for Information Security, Volume 1 (SP 800-55 Vol. 1, December 2024), "a metric of progress toward intended results". The same guide defines metrics as "measures and assessment results designed to track progress, facilitate decision-making, and improve performance with respect to a set target", and says KPIs and key risk indicators "are examples of metrics, though not all metrics fall into these categories." A figure that is only counted, with no target and no decision hanging on it, is data rather than a KPI.
What is a good security KPI example?
One tied to a target, drawn from a record both sides trust, and checked by the client. The Federal Acquisition Regulation, section 37.601 asks for "measurable performance standards (i.e., in terms of quality, timeliness, quantity, etc.)" and "the method of assessing contractor performance against performance standards". On a guard contract that gives, for example, scheduled checkpoint checks completed against those planned (quantity), incident reports submitted within the agreed time (timeliness), and the share of supervisor post inspections where the officer knew the post orders (quality).
What are cybersecurity KPIs?
They measure how an organization's information security program is performing. NIST's Measurement Guide for Information Security, Volume 1 lists indicators such as mean time to detect, which "tracks the average amount of time that a problem exists before it is found", mean time to recovery and the false positive rate, and program-level metrics "such as the number of security incidents in a year or the cost per incident". It also warns: "Poorly selected quantitative metrics can undermine the overall quality of reporting and erode confidence in the work product." Cybersecurity KPIs usually sit with the information security team; the physical security KPIs in this guide sit with facilities and the guard contract.
08
Further reading, and a list to take away
The FAR's rules on performance-based acquisition and quality assurance surveillance plans are the clearest public model of defining and checking a service's performance. The Interagency Security Committee's Armed Contract Security Officers in Federal Facilities sets out training, qualification and staffing practice for armed posts. GAO's report GAO-25-108085 shows what goes wrong when guard oversight depends on data nobody can rely on. For licensing and training, read your own state's rules; California's are in Business and Professions Code section 7583.6 and New York's on the Department of State's training page.
Before you agree or review a set of security KPIs, check that:
- there are between five and ten, and each one matters to this site;
- post coverage and patrol completion are measured, not only incidents and complaints;
- each KPI has a written definition, data source, owner, period and target;
- the contract says how the client will verify the figures;
- no KPI rewards officers for reporting less;
- licensing and training are measured against the deadlines in the site's own state;
- hazards found on patrol are tracked until they are closed;
- there is a daily or weekly view of delivery as well as the monthly report;
- the KPIs are reviewed at least once a year, and whenever the post orders change.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Federal Acquisition Regulation, section 37.601 acquisition.gov
- FAR 46.401 acquisition.gov
- FAR 37.604 acquisition.gov
- Business and Professions Code section 7583.6 leginfo.legislature.ca.gov
- Security guard training requirements dos.ny.gov
- Armed Contract Security Officers in Federal Facilities cisa.gov
- Computing incidence rates bls.gov
- Workplace violence page osha.gov
- Labor Code section 6401.9 leginfo.legislature.ca.gov
- GAO-25-108085 gao.gov
- Measurement Guide for Information Security, Volume 1 csrc.nist.gov



