Commercial real estate multi-tenant office buildings face a wide range of potential threats—from everyday criminal activity like theft and vandalism to more serious concerns such as workplace violence, civil unrest, cyber-enabled access breaches, or even targeted attacks due to specific tenants or social justice issues and concerns. For property management representatives, understanding and conducting basic threat assessments is a core responsibility tied to tenant safety, asset protection, liability reduction, and business continuity.
A threat assessment is not about predicting the future or creating fear; it is a structured process used to identify, evaluate, and manage risks before they escalate into incidents. In a multi-tenant environment, the complexity increases due to the number of occupants, varying tenant security cultures, shared infrastructure, and public access points.
This article provides an overview of the fundamentals of threat assessments as they apply to commercial multi-tenant office buildings. It is designed to give property managers a working knowledge they can apply immediately, whether coordinating with security vendors, responding to tenant concerns, or planning building improvements.
At its core, a threat assessment is a systematic evaluation of potential hazards that could negatively impact people, property, or operations. These hazards may be intentional (crime or violence) or unintentional (poor/ineffective access control, inadequate lighting, or lack of emergency procedures).
For property management, a threat assessment helps answer these key questions:
Eliminating all risk is impossible but reducing risk to a reasonable or manageable level is possible.
Multi-tenant buildings present unique challenges compared to single-tenant assets. Shared access points, such as lobbies, elevators, stairwells, and parking facilities, are used by multiple tenants, employees, visitors, and members of the public. Tenant operations can also vary, with differing hours, visitor volumes, and risk profiles. Public-facing elements, including retail spaces, food services, or ground-floor amenities, can create additional considerations, while property managers may have limited control over internal tenant security practices.
A well-executed threat assessment enables property managers to proactively address vulnerabilities and support tenant confidence, and possibly retention. It can also help reduce liability exposure by demonstrating due diligence and create well-informed capital planning decisions for security upgrades.
Criminal Activity
Criminal activity can include theft and burglary, vandalism and property damage, vehicle break-ins, and trespassing and loitering. These are often the most frequent threats and can escalate if not addressed.
Workplace Violence and Personal Safety
Workplace violence and personal safety concerns may involve disgruntled tenant employees or terminated contractors, domestic violence spillover into the workplace, harassment or stalking incidents involving tenants, or aggressive or unstable individuals entering common areas. While rare, these threats carry significant safety, reputational, and legal consequences.
Unauthorized Access
Unauthorized access can occur through tailgating through secure checkpoints or doors, lost or shared access credentials, or delivery and vendor access vulnerabilities. Unauthorized access is often a root cause of more serious incidents.
External and Environmental Threats
External and environmental threats may include protests or demonstrations near the property, nearby construction affecting visibility or access, high-crime surrounding areas, and natural hazards that impact security, such as power outages or storms. These factors may be outside direct control but still affect risk levels.
Technology and Infrastructure Risks
Technology and infrastructure risks can include malfunctioning access control systems, inconsistent camera coverage or blind spots, alarm systems that are misunderstood or ignored, and poor integration between building systems. Technology is a force multiplier when properly managed, or a weakness when neglected.
A basic threat assessment for a multi-tenant office building typically includes the following elements.
Property and Site Overview
Start with a clear understanding of the building and its environment, including the location and surrounding neighborhood, building size, height, and layout, number of tenants and occupants, operating hours and peak traffic times, and proximity to public transportation or high-traffic areas.
This context frames every other decision.
Access Control Evaluation
Access control is the foundation of building security. An evaluation should consider how many public, semi-public, and restricted entry points exist and whether doors, turnstiles, or gates are functioning as intended. It should also examine how credentials are issued, tracked, and revoked, whether visitors are consistently managed and documented, and whether loading docks and service entrances are controlled.
In multi-tenant buildings, inconsistent enforcement of access rules is a common vulnerability.
Physical Security Features
Evaluate the condition and placement of physical deterrents and protective measures, including lighting levels in lobbies, garages, stairwells, and exterior walkways; visibility and camera coverage of critical areas; clear signage directing visitors and deliveries; and barriers or architectural features that guide movement (CPTED).
Effective design reduces opportunities for concealment and confusion. The principles of Crime Prevention through Environmental Design (CPTED) are proven effective and should always be considered, especially in any property renovations.
Security Personnel and Procedures
Whether security is in-house or contracted, procedures matter as much as presence. Assess staffing levels and coverage times, training standards and turnover, clarity of post orders and escalation protocols, communication methods with property management, and incident documentation and reporting practices.
Without clear guidance, security staff can become reactive instead of preventative.
Tenant Interface and Communication
In a multi-tenant environment, security is a shared responsibility. Property managers should evaluate how tenants report security concerns, how building rules and emergency procedures are communicated, whether tenant onboarding includes any security orientation, and how sensitive information is shared appropriately during incidents.
Effective communication reduces confusion and panic during real events.
Emergency Preparedness and Response
Threat assessments must account for incidents that can escalate quickly. Review emergency action plans for different scenarios, evacuation and shelter-in-place procedures, medical response capabilities (AEDs, trained staff), coordination with local law enforcement and fire departments, and the frequency of drills or tabletop exercises.
Plans that exist only on paper often fail in real-life scenarios. Annual tabletop exercises are a recommended best practice, and quick, “five-minute drills” several times a year are also great.
Property managers do not have to be security experts to lead an effective assessment. If you work with a security provider, leveraging that relationship to support a threat assessment makes sense. This should be a collaborative effort since the service provider is responsible for policy execution but the property owner/manager has legal obligations under the Duty of Care statute (O.C.G.A. 51-3-1).
A practical approach includes:
Threat assessments should be living processes, not one-time exercises.
Identifying risks is only valuable if documented and followed by reasonable action. Mitigation strategies may include policy changes, such as visitor management and access rules; low-cost physical improvements, such as lighting and signage; technology upgrades, such as cameras and access control software; training enhancements for staff and tenants; and adjustments to security post coverage or patrol patterns.
Not every solution requires major capital investment. Many effective improvements involve minor adjustments and holding responsible parties accountable.
Once threats are identified, property managers should evaluate each one through a consistent lens: likelihood, potential impact, existing controls, gaps, and realistic mitigation options. A simple high, medium, or low rating can be sufficient for most properties, provided the rationale is documented and reviewed regularly. The purpose is to prioritize action, not to create unnecessary complexity.
The following considerations build on the common threat categories identified earlier and translate them into practical risk management actions for multi-tenant office buildings.
Criminal Activity
Risk assessment considerations: Evaluate incident history, neighborhood crime trends, vulnerable exterior areas, parking facilities, after-hours activity, and locations where theft, vandalism, trespassing, or loitering have occurred. Likelihood may be higher where lighting is poor, visibility is limited, tenant traffic is inconsistent, or prior incidents have gone unresolved. Impact should consider tenant confidence, property damage, insurance claims, business disruption, and reputational effects.
Mitigation considerations: Strengthen lighting in parking areas, loading docks, stairwells, and exterior walkways; maintain visible camera coverage in common areas; adjust patrol routes based on incident patterns; promptly repair doors, gates, fencing, and locks; and coordinate with local law enforcement on recurring issues. Always document every corrective action taken and maintain a log of these actions. Being able to prove that the property has addressed known issues could help reduce or avoid liability exposure in the future.
Workplace Violence and Personal Safety
Risk assessment considerations: Assess how the building identifies and responds to WPV threats or personal safety concerns. These events are often low frequency but high consequence. Do your tenants know how to notify property management about credible concerns without disclosing unnecessary confidential information?
Mitigation considerations: Establish clear escalation procedures for threats, restraining orders, terminations, and concerning behavior reported to property management. Provide security staff with practical post orders for responding to distressed or aggressive individuals. Conduct periodic tabletop exercises for incidents involving lockdown, shelter-in-place, evacuation, or law enforcement response so all departments are aware of their role and how to respond.
Unauthorized Access
Risk assessment considerations: Review how individuals enter the building, move through common areas, access tenant floors, and use loading docks, garages, service corridors, and after-hours entrances. Indicators of elevated risk include tailgating, shared credentials, delayed credential deactivation, inconsistent visitor screening, uncontrolled vendor access, and limited elevator or stairwell controls. Impact should consider whether unauthorized access could lead to theft, violence, data exposure, tenant disruption, or a loss of confidence in building management.
Mitigation considerations: Require prompt deactivation of lost cards and departing employee access; reinforce visitor check-in standards; audit door alarms and access logs; and consider layered access controls for higher-risk tenants or floors. Vendor and delivery procedures should clearly define where vendors may enter, how they are verified, and whether escorts are required for sensitive areas.
External and Environmental Threats
Risk assessment considerations: Evaluate risks that originate outside the property but affect operations, including protests, civil unrest, seasonal severe weather, the impact of power outages, and crime patterns around the property. Consider location, recent events, building visibility, tenant profile, nearby government or public facilities, and seasonal weather patterns. Impact should include tenant access, building operations, emergency response, life safety, and business continuity.
Mitigation considerations: Monitor reliable public safety and weather sources; maintain relationships with local law enforcement, fire officials, and neighboring properties; verify backup power and emergency lighting; establish communication templates for disruptions; and review shelter-in-place or evacuation procedures for different scenarios.
Technology and Infrastructure Risks
Risk assessment considerations: Assess whether access control, cameras, alarms, intercoms, radios, emergency notification tools, and building systems are functioning as intended and understood by staff. Common vulnerabilities include camera blind spots, outdated user permissions, unreliable door hardware, ignored alarms, inconsistent maintenance, and lack of integration between systems. Impact can be significant because technology failures often weaken multiple security layers at once.
Mitigation considerations: Establish preventive maintenance schedules; test critical systems routinely; document camera coverage and known blind spots; audit system permissions; train staff on alarm interpretation and escalation; and ensure service providers respond within defined timeframes. For networked building systems, property managers should coordinate with qualified technology or cybersecurity professionals to ensure vendor access, passwords, remote management, and software updates are controlled appropriately.
Using a Risk Matrix to Prioritize Mitigation
A basic risk matrix helps convert observations into decisions. For each risk, assign a likelihood rating and an impact rating, then identify the current control, the gap, the recommended mitigation, the responsible party, and the target completion date. High-likelihood and high-impact risks should receive immediate attention; low-likelihood but high-impact risks should still be addressed through emergency planning, communication, and response readiness.

Mitigation should also be assigned to an owner. Some actions belong to property management, such as policy updates, vendor oversight, capital planning, and tenant communications. Others may require security contractors, engineers, technology vendors, tenant representatives, or public safety partners. Assigning ownership prevents recommendations from becoming unresolved observations.
High-priority items may require weekly follow-up until resolved, while moderate items can be tracked monthly and lower-risk items included in routine property inspections. Any significant change—new tenant mix, major construction, recurring incidents, public safety advisories, or system upgrades—should trigger a reassessment of the affected risks.
The following example illustrates how a property management team might document risks for a mid-sized, multi-tenant office building with a public lobby, attached parking garage, loading dock, and after-hours tenant access. The ratings are illustrative and should be adjusted based on actual incident history, tenant profile, location, and building conditions.
Sample rating scale: Likelihood and impact are rated High, Medium, or Low. Overall priority is based on the combined effect of likelihood, impact, current controls, and urgency. High-priority risks require prompt action and management follow-up; medium-priority risks require assigned corrective actions and tracking; low-priority risks should be monitored through routine inspections and periodic reassessment.
This type of completed assessment should be reviewed in management meetings until each corrective action is closed. Once actions are completed, the property team should reassess the likelihood, impact, and priority to determine whether the residual risk is acceptable or whether additional mitigation is needed.

From a liability and governance standpoint, documentation matters.
Property managers should maintain threat assessment reports, incident logs and response records, maintenance and inspection records for security systems, training and communication documentation, and records of any repairs or remediation actions completed.
These records demonstrate reasonable care and professionalism and that the property takes its “Duty of Care” seriously.
Threat assessments are a foundational tool for managing safety and risk in multi-tenant office buildings. They allow property management representatives to move beyond reactive security measures and toward informed, proactive decision-making.
By understanding common threat categories, assessing core security components, engaging tenants, and translating findings into practical actions, property managers can significantly reduce risk while enhancing tenant confidence and asset value.
In an environment where expectations for safety continue to rise, a well-executed threat assessment is not just a security function—it is a core part of effective property management.
To stay up to date on news and resources such as this and other topics of importance to the real estate industry, subscribe to the free CRE Insight Journal Newsletter using this link.
Comments are closed.