Mobile Security Patrols vs On-Site Guards: Which Does Your Business Need?

Choosing between mobile security patrols and on-site guards is one of the most common decisions Australian businesses face when building a security program. Both have clear strengths — the question is which fits your specific risk profile, site layout, and budget.

This guide explains how each model works, where each performs best, and the factors that should inform your decision.

What Is a Mobile Security Patrol?

A mobile security patrol is a licensed security officer who conducts regular vehicle-based inspections of your premises. Patrols can be scheduled at fixed intervals (such as every two hours overnight) or randomised to create unpredictability that deters criminal activity.

Mobile patrol officers typically cover multiple sites per shift. This makes them highly cost-effective for businesses that need consistent security presence but don’t require someone on-site around the clock.

Key characteristics of mobile patrol:

  • Vehicle-based, covering large areas or multiple sites per shift
  • Scheduled or randomised check-in times
  • Officers respond to alarms, check locks, and complete incident reports
  • Backed by 24/7 back-to-base monitoring
  • Lower per-site cost than dedicated static guarding

What Is On-Site (Static) Guarding?

On-site guarding places a dedicated security officer at your premises continuously. The officer manages access control, monitors CCTV, conducts patrols of the site, manages visitors, and responds immediately to any incident.

Static guarding is the highest level of physical security presence available. It eliminates response time — an officer is already on site when an incident occurs.

Key characteristics of on-site guarding:

  • Dedicated, continuous presence at a single location
  • Manages access control, visitor screening, and CCTV monitoring
  • Immediate on-site incident response
  • Can fulfil customer service and concierge functions
  • Higher cost per site than mobile patrol

Key Differences: Mobile Patrol vs Static Guarding

Factor Mobile Patrol Static Guarding
Coverage area Multiple sites per shift Single site
Response time Minutes (travel required) Immediate
Deterrence High visibility on arrival Constant visible presence
Cost Lower per site Higher per site
Best for Multiple properties, construction sites, retail precincts Hospitals, corporate buildings, data centres

When Should You Choose Mobile Security Patrols?

Mobile patrols are ideal when deterrence and rapid response matter more than continuous presence. The Australian Institute of Criminology has found that visible security patrols can reduce property crime incidents by up to 16% in targeted areas — even without a permanent on-site officer.

Mobile patrols are typically the right choice when:

  • You manage multiple properties — One patrol officer can cover 3–5 sites per shift, making mobile patrol far more cost-effective than deploying a static officer at each location.
  • Your risk is primarily after-hours — Research from NSW Police indicates the majority of commercial break-ins occur between 10pm and 6am, when a visible patrol presence provides strong deterrence at a fraction of the static guarding cost.
  • You have a large site perimeter — Construction sites, industrial yards, and large retail precincts benefit from vehicle patrols that can cover the full perimeter quickly.
  • You need alarm response — Mobile patrol officers can be the primary response to after-hours alarms, attending the site within minutes and liaising with police as required.

When Should You Choose On-Site Guarding?

Static guarding is the right choice when continuous physical presence is essential — either because of the nature of the environment, the value of the assets, or the requirement for immediate incident response.

On-site guarding is typically the right choice when:

  • You operate a high-risk environment — Hospitals, data centres, financial institutions, and government facilities typically require static guarding because the consequences of a security breach are severe and response time is critical.
  • You have a complex access control requirement — If managing who enters and exits your facility is a primary security function, a static officer can fulfil this in a way no mobile patrol can match.
  • Your facility operates 24/7 — Sites that never close — hospitals, hotels, transport hubs — require a security presence that mirrors their operating hours.
  • You need concurrent customer service — Concierge and gatehouse functions combine security with visitor management. This requires a dedicated, on-site officer.

Can You Combine Both?

Many organisations use both — particularly across multi-site portfolios where one or two locations warrant static guarding while others are adequately protected by regular patrol visits. Barrick Group regularly designs integrated programs that layer mobile patrols with static posts to achieve comprehensive coverage at a lower total cost than static guarding alone.

How to Decide: A Simple Framework

Ask three questions:

  1. What is the consequence of an undetected breach? If it is catastrophic (patient harm, data loss, significant asset damage), static guarding is likely required. If it is significant but manageable, patrols may suffice.
  2. Do you need immediate on-site response, or will a patrol response within 5–15 minutes be adequate? The answer depends on your risk profile and the nature of potential incidents.
  3. How many locations do you need to protect? If more than one, mobile patrol almost always delivers better coverage per dollar across the portfolio.

Speak to Barrick Group

Barrick Group provides both mobile security patrols and on-site guarding across New South Wales, backed by 24/7 back-to-base monitoring. Our team will assess your sites, risk profile, and budget to recommend the right model — or a combination of both.

Call us on 1300 102 201 or contact us online to discuss your requirements.

Australia’s Essential Eight Cybersecurity Framework: What Your Business Needs to Know

The Australian Signals Directorate’s Essential Eight is the most widely referenced cybersecurity framework for Australian businesses — and for good reason. The Australian Cyber Security Centre (ACSC) estimates that implementing the Essential Eight could prevent up to 85% of targeted cyber intrusions.

Despite this, many Australian businesses have not fully implemented it. Here is what the Essential Eight is, why it matters, and what each strategy requires.

What Is the Essential Eight?

The Essential Eight is a set of eight baseline cybersecurity mitigation strategies developed by the Australian Signals Directorate (ASD) and published by the Australian Cyber Security Centre (ACSC). It was originally designed for Australian government agencies but is now considered best practice for any organisation that holds sensitive data or operates critical systems.

The framework is structured around three objectives:

  • Prevent cyberattacks from occurring
  • Limit the extent of cyberattacks
  • Recover data and systems after a cyberattack

Each strategy is assessed at one of four maturity levels: Level 0 (not implemented) through Level 3 (fully implemented and actively tested).

Why the Essential Eight Matters for Your Business

The ACSC’s Annual Cyber Threat Report 2022–23 recorded over 94,000 cybercrime reports in Australia — an average of one every six minutes. Cybercrime is estimated to cost Australian businesses over $33 billion annually.

Small and medium businesses are not immune. The IBM Cost of a Data Breach Report 2024 found the average cost of a data breach to Australian organisations was approximately USD $3.35 million (approximately AUD $5.1 million). For smaller businesses without enterprise-grade defences, even a partial breach can be operationally devastating.

The Essential Eight does not eliminate all risk — no framework does. But independent analysis consistently shows that organisations at Maturity Level 2 or above experience significantly fewer successful intrusions and recover faster when incidents occur.

The Eight Strategies Explained

1. Application Control

Only approved applications can execute on your systems. Malicious software cannot run if it is not on the approved list. At Maturity Level 2, application control must be implemented on workstations and internet-facing servers.

2. Patch Applications

Software vulnerabilities are discovered constantly. Patching closes those vulnerabilities before attackers can exploit them. The Essential Eight requires patches for internet-facing services to be applied within two weeks of release (or 48 hours for critical vulnerabilities at Level 3).

3. Configure Microsoft Office Macro Settings

Malicious macros embedded in Microsoft Office documents are a primary vector for malware delivery via phishing emails. Restricting macros to signed, trusted sources eliminates this vector for most organisations.

4. User Application Hardening

Web browsers and common applications like Adobe Reader are frequently exploited. Hardening involves disabling unnecessary features (such as Flash, Java, and ads) and configuring applications to block common attack vectors.

5. Restrict Administrative Privileges

Admin accounts are the keys to your systems. Restricting who holds admin privileges — and ensuring those accounts are not used for everyday tasks like email and browsing — dramatically limits the damage an attacker can do if they compromise a standard user account.

6. Patch Operating Systems

Like application patching, operating system patching closes vulnerabilities in Windows, Linux, and macOS. At Maturity Level 2, patches must be applied within one month for non-critical systems and within two weeks for internet-facing systems.

7. Multi-Factor Authentication (MFA)

MFA requires users to verify their identity using two or more factors — typically a password and a one-time code sent to a mobile device or authenticator app. The ACSC considers MFA one of the single most effective controls against account compromise. At Level 2, MFA is required for all remote access, all administrative accounts, and third-party services that handle sensitive data.

8. Regular Backups

Ransomware is only effective if the victim cannot restore their data from a clean backup. Regular, tested, offline backups are the primary defence against ransomware extortion. Backups must be stored separately from production systems and tested regularly to confirm they can actually be restored.

Essential Eight Maturity Levels

Each strategy is assessed at Maturity Levels 0–3. The ACSC recommends all organisations target Maturity Level 2 as a minimum. Level 2 means the controls are implemented, applied consistently, and regularly tested — not just documented in a policy.

As of the ACSC’s 2023 assessment data, a significant proportion of Australian organisations — including government agencies — remain at Maturity Level 1 or below across several strategies, with MFA and application control being the most commonly incomplete.

Essential Eight and Corporate Risk Management

For directors and executives, the Essential Eight is increasingly relevant to personal liability obligations. The Australian Securities and Investments Commission (ASIC) has pursued directors of companies that experienced preventable cyber incidents, arguing that failure to implement basic cybersecurity controls may constitute a breach of directors’ duties under the Corporations Act 2001.

Implementing the Essential Eight — and documenting that implementation — is one of the clearest demonstrations of due diligence available to Australian business leadership.

How Barrick Group Supports Essential Eight Implementation

Barrick Group’s Information and Cyber Security practice supports organisations across the Essential Eight implementation journey — from gap assessment at your current maturity level through to implementation support, documentation, and ongoing managed monitoring.

Our Barrick365 Managed IT service embeds Essential Eight controls into day-to-day IT operations, ensuring patch management, MFA enforcement, backup verification, and privilege management are maintained continuously — not just at audit time.

Contact us on 1300 102 201 or online to discuss your current maturity level and what it would take to reach Level 2.

Security Licence Classes in Australia: Classes 1A to 1E Explained

Before you hire a security guard, bodyguard, or crowd controller in Australia, you need to understand the licensing system. Every licensed security professional in Australia holds a class-specific licence that determines what they are legally permitted to do.

This guide explains the Australian security licence class system, what each class covers, and what businesses need to know when engaging security personnel.

How Security Licensing Works in Australia

Security licensing is regulated at the state and territory level in Australia. Each jurisdiction has its own licensing body:

  • New South Wales: NSW Police Force — Security Licensing & Enforcement Directorate (SLED)
  • Victoria: Victoria Police — Licensing & Regulation Division
  • Queensland: Office of Fair Trading
  • South Australia: Consumer and Business Services
  • Western Australia: WA Police Force — Licensing Enforcement Division

While each state administers its own licences, the class structure is broadly consistent across Australia. Security officers must hold the appropriate licence class for every task they perform.

Security Licence Classes Explained

Class 1A — Unarmed Guard

Class 1A is the most common security licence in Australia. It covers:

  • Mobile security patrols (vehicle and foot)
  • Static guarding and on-site security
  • Back-to-base monitoring and alarm response
  • Access control and gatehouse operations
  • General loss prevention

Class 1A officers do not carry firearms. They may use other approved equipment (such as handcuffs or personal protective equipment) where authorised under their licence. The vast majority of commercial security personnel hold Class 1A.

Class 1B — Guard Dog Handler

Class 1B covers all Class 1A functions plus the use of a trained security dog. Guard dog deployments are common for:

  • Construction site security
  • Yard and depot protection
  • Industrial facilities
  • After-hours retail patrol

Officers holding Class 1B must also hold (or be obtaining) a Class 1A licence. The dog used must be trained to the relevant Australian Standard and registered.

Class 1C — Crowd Controller

Class 1C is specifically for crowd control at licensed venues and events. This includes:

  • Hotels, bars, and nightclubs
  • Concerts and music festivals
  • Sporting events
  • Any venue licensed to sell alcohol where crowd management is required

Crowd controllers have specific training in conflict resolution, use of force, and venue evacuation procedures. In NSW, operating as a crowd controller without a Class 1C licence (or under the supervision of a licensed officer) is a criminal offence.

Class 1D — Bodyguard

Class 1D covers close personal protection — commonly referred to as executive protection. This class is required for:

  • Personal protection of individuals and executives
  • Close protection during travel and events
  • Advance route planning and threat assessment

Bodyguards receive specialised training in protective security operations, first aid, and threat assessment. Many also hold relevant firearms licences.

Class 1E — Armed Guard

Class 1E covers the use of firearms in a security capacity. This is the most regulated class of security licence and covers:

  • Cash-in-transit operations
  • Armoured vehicle operations
  • High-value asset transport
  • Certain government and critical infrastructure roles

In addition to the security licence, Class 1E officers must hold separate firearms licences under their respective state’s Firearms Act. Police checks, medical requirements, and additional training requirements apply.

Master Licences: What Security Companies Must Hold

In addition to individual officer licences, security companies operating in Australia must hold a Master Licence (also called a Security Industry Licence or Business Licence, depending on the jurisdiction). This licence authorises the company to provide security services commercially.

When engaging a security company, always verify that they hold a current Master Licence. In NSW, Barrick Group holds Master Licence NSW M/L 000109659.

How to Verify a Security Licence

You can verify security licences through the relevant state licensing authority:

  • NSW: SLED Licence Verification at police.nsw.gov.au
  • VIC: Victoria Police licence check
  • QLD: Office of Fair Trading licence register

Businesses engaging security personnel are not liable for verifying individual officer licences at each engagement, but doing so for contracted companies is considered due diligence — particularly in higher-risk environments.

What Licence Classes Does Barrick Group Hold?

Barrick Group holds a NSW Master Licence and deploys officers credentialled across all relevant licence classes — Class 1A (unarmed guard), Class 1B (guard dog handler), Class 1C (crowd controller), and Class 1D (bodyguard/executive protection) — as required by each client engagement.

Our safety and security services are delivered exclusively by licensed professionals operating within the scope of their licence class and Barrick’s operational procedures.

If you have questions about security licensing requirements for your business or project, contact our team on 1300 102 201 or online.

CCTV Surveillance Laws in Australian Workplaces: What You Need to Know

CCTV surveillance is standard practice in Australian workplaces. But using it without understanding the legal framework can expose your business to significant liability — from privacy complaints to employment disputes and regulatory fines.

This guide covers the key legal obligations Australian businesses must understand before installing or operating CCTV in the workplace.

How Many Australian Businesses Use CCTV?

Workplace surveillance is widespread in Australia. According to research from the University of NSW’s Cybersecurity and Data Governance Research Network, the majority of Australian workplaces with more than 20 employees operate some form of CCTV or electronic surveillance. In retail, hospitality, and industrial settings, CCTV penetration approaches near-universal levels.

The growth of AI-enhanced video analytics and intelligent CCTV has expanded the functional capability of workplace surveillance systems significantly — making the legal framework more important to understand, not less.

The Key Legal Frameworks

The Privacy Act 1988 (Commonwealth)

The Privacy Act 1988, and specifically the Australian Privacy Principles (APPs) contained in Schedule 1, applies to organisations with an annual turnover of more than $3 million (and to certain smaller organisations in specific sectors).

APP 3 governs the collection of personal information. CCTV footage of identifiable individuals constitutes personal information. Under APP 3, you may only collect personal information that is reasonably necessary for your business functions or activities.

Key obligations under the Privacy Act for CCTV operators:

  • You must have a lawful reason to collect the surveillance footage
  • You must take reasonable steps to notify individuals that they are being recorded (typically via signage)
  • Footage must be stored securely and not disclosed to third parties without consent (except in limited circumstances, such as disclosure to police)
  • Individuals generally have the right to access footage of themselves
  • Footage must not be retained longer than is necessary for the purpose it was collected

NSW Workplace Surveillance Act 2005

In New South Wales, the Workplace Surveillance Act 2005 imposes specific requirements on employers conducting workplace surveillance — including CCTV.

Notice requirements: Employers must give employees at least 14 days’ written notice before installing a new CCTV system, unless the surveillance is covert. Covert surveillance requires a covert surveillance authority issued by a Magistrate — it is not available simply to satisfy employer curiosity or general suspicion.

Prohibited surveillance: The Act prohibits surveillance of employees in change rooms, toilets, or shower facilities. This prohibition is absolute — there are no exceptions.

Email and computer surveillance: The Act also governs electronic surveillance of employee email and computer usage. Separate notice requirements apply.

Penalties: Contravening the Workplace Surveillance Act can result in fines of up to $55,000 for corporations and $5,500 for individuals.

Other State and Territory Legislation

Other Australian states and territories have their own workplace surveillance laws:

  • Victoria: Surveillance Devices Act 1999
  • Queensland: Invasion of Privacy Act 1971
  • ACT: Workplace Privacy Act 2011
  • WA: Surveillance Devices Act 1998

If your organisation operates across multiple states, you must comply with the requirements of each jurisdiction.

CCTV Signage: What’s Required?

The most practical compliance requirement is adequate signage. Under the Privacy Act and most state workplace surveillance laws, you must notify individuals that CCTV is operating. The standard approach is to place clear, visible signs at all entry points to surveilled areas.

Effective CCTV signage should include:

  • A statement that CCTV is in operation
  • The name of the operating company or responsible party
  • Contact details for enquiries about the footage

Generic “CCTV in operation” signs without contact details may be insufficient under the Privacy Act’s notification requirements for organisations covered by the APPs.

How Long Can You Retain CCTV Footage?

There is no universal statutory retention period for CCTV footage in Australia — the obligation is that you must not retain footage longer than is necessary for the purpose it was collected.

In practice, industry standards vary:

  • Retail loss prevention: typically 30–90 days
  • Construction sites: typically for the duration of the project plus a short review period
  • Corporate facilities: typically 30–60 days
  • Government and regulated industries: may be subject to sector-specific requirements

If footage captures an incident that may lead to legal action, you should preserve it immediately and seek legal advice on retention obligations.

Using CCTV Evidence in Employment Disputes

CCTV footage is regularly used as evidence in unfair dismissal proceedings before the Fair Work Commission. However, footage obtained in breach of the Workplace Surveillance Act (such as covert surveillance without authority, or surveillance in prohibited areas) may be inadmissible or may expose your organisation to separate liability.

Before relying on CCTV footage in an employment matter, confirm that the system was installed and operated in compliance with the applicable legislation.

Intelligent CCTV and AI Analytics: Additional Considerations

Modern intelligent CCTV systems use AI-powered video analytics to perform functions beyond basic recording — including facial recognition, behaviour analysis, and crowd density measurement. These capabilities introduce additional privacy and ethical considerations under the Privacy Act.

Facial recognition in particular is subject to increasing regulatory scrutiny. The Office of the Australian Information Commissioner (OAIC) has published guidance indicating that biometric surveillance data constitutes sensitive information under the Privacy Act — attracting higher obligations than standard CCTV footage.

How Barrick Group Can Help

Barrick Group’s technology solutions practice designs and implements CCTV and intelligent video surveillance systems with compliance built in — from signage standards through to data retention policies and access controls.

Our team can review your current CCTV setup to identify compliance gaps, recommend appropriate system configurations, and ensure your surveillance operations meet the requirements of the Privacy Act and applicable state legislation.

Contact us on 1300 102 201 or online to discuss your workplace surveillance requirements.

How to Plan Security for a Major Event in Australia: A Complete Guide

Major events carry unique security challenges that don’t exist in a fixed commercial environment. Crowd dynamics, temporary infrastructure, unfamiliar attendees, multiple access points, and tight timelines create a security environment that rewards preparation and punishes improvisation.

Whether you’re planning a corporate function, sporting event, concert, or public gathering, this guide outlines the key steps to effective major event security planning in Australia.

Why Event Security Demands a Different Approach

According to the Australian Institute of Criminology, large gatherings of people consistently create elevated risks for assault, theft, crowd crush, and anti-social behaviour — even at well-organised events. The Crowd Management Standard (AS 3745) and Work Health and Safety legislation impose legal obligations on event organisers that require documented, risk-based planning.

In NSW, major events held on public land or in licensed venues are subject to requirements from multiple regulators — NSW Police, local councils, the Independent Liquor & Gaming Authority (ILGA), and venue-specific licensing conditions. Security planning must satisfy all of these, not just the most obvious.

Step 1: Define the Event Profile

Security requirements vary dramatically based on event type, audience profile, and location. Before you can build a security plan, you need to define:

  • Expected attendance: The number of attendees determines the minimum required number of security personnel under event licensing conditions.
  • Audience profile: A corporate awards night has different risk factors than an outdoor music festival or a sporting finals event.
  • Venue type: Temporary outdoor venues, licensed hotels, arenas, and public parks each carry different access control challenges and regulatory requirements.
  • Alcohol and licensing status: Events serving alcohol require licensed crowd controllers (Class 1C) under state licensing laws.
  • VIP or high-profile attendees: The presence of executives, politicians, or celebrities may require close personal protection (Class 1D) in addition to standard crowd management.

Step 2: Conduct a Security Risk Assessment

A formal Security Risk Assessment (SRA) is the foundation of any event security plan. It should identify:

  • All threats relevant to the event type and location (including terrorism, crowd crush, medical emergencies, and theft)
  • Vulnerable points in the venue perimeter and access control system
  • Emergency evacuation routes and assembly points
  • Interactions with neighbouring venues or public spaces

The SRA must be documented. For licensed venues in NSW, insurers and liquor licensing authorities regularly request evidence of a completed risk assessment as a condition of approving an event.

Step 3: Design the Security Deployment Plan

Based on the risk assessment, design a deployment plan that addresses:

  • Entry and exit control: How many entry points will operate, what screening will be applied (bag checks, wanding, ID verification), and what the process is for managing prohibited items.
  • Officer positions and patrols: Fixed posts, roving officers, undercover personnel, and vehicle-based rapid response positions should all be documented in a site map.
  • Crowd management zones: High-density areas such as stages, bar queues, and exits require dedicated crowd management resources.
  • Command and communication structure: A clear chain of command and communication protocol (radio channels, code words, escalation procedures) must be established before the event begins.
  • Emergency response protocols: Documented procedures for medical emergencies, evacuation, crowd crush response, and police liaison.

Step 4: Brief All Security Personnel

A pre-event briefing is not optional. Every officer deployed to your event should receive:

  • Site maps, entry/exit points, and prohibited zones
  • Specific responsibilities and patrol routes
  • Emergency procedures and evacuation assembly points
  • Communication protocols and escalation contacts
  • Known risks specific to the event

Officers who arrive at a major event without a briefing are a liability, not an asset. Barrick Group’s event security teams receive event-specific operational briefings before every deployment.

Step 5: Coordinate with Police and Emergency Services

For events above a threshold size (typically 1,000 attendees or more in NSW, though this varies by venue type), formal coordination with NSW Police is required. This includes:

  • Notifying the local police area command of the event
  • Providing the security deployment plan and emergency contacts
  • Establishing a designated police liaison contact within your security team

NSW Ambulance and Fire and Rescue NSW should also be notified for events with large expected attendance or elevated risk profiles. Their liaison can identify additional access or resource requirements early.

Step 6: Post-Event Review

A post-event security review is essential for continuous improvement — and is increasingly required by insurers for repeat events. The review should document:

  • Total incidents reported and how each was resolved
  • Any gaps in the deployment plan that were identified during the event
  • Feedback from security personnel and event staff
  • Recommendations for changes to the security plan at the next event

Staffing Requirements: How Many Security Officers Does My Event Need?

There is no single formula for event security staffing. State licensing authorities, venue licences, and event-specific risk factors all influence the required number of officers.

As a general guide used by the Australian Security Industry Association Limited (ASIAL):

  • Crowd controllers: typically 1 per 100 patrons for lower-risk events; 1 per 50 for higher-risk events
  • Entry screening officers: typically 1 per entry lane, with lanes sized for approximately 200 patrons per hour
  • Rapid response: at least 1 dedicated response officer per 500 patrons

These are indicative figures only. Your security provider should conduct a site-specific assessment and produce a staffing recommendation backed by a formal risk assessment.

Plan Your Event Security with Barrick Group

Barrick Group has provided major events security for a wide range of events across New South Wales — from corporate functions to large public gatherings. Our team delivers comprehensive security planning, licensed crowd management, access control, emergency response coordination, and post-event review.

Contact us on 1300 102 201 or online to discuss your event security requirements. Early planning allows us to provide the most comprehensive coverage at the best possible deployment efficiency.