Name what you are actually buying
“Security company” covers products that have almost nothing in common. A person standing at a gate, a monitored alarm on a phone line, a camera install with a maintenance contract, and a consulting engagement that produces a report are all sold under the same two words. Before you compare a single price, write down what you are protecting, what you are actually afraid of, and what “handled properly” would look like at three in the morning on a Sunday. That paragraph is the most valuable document in the whole procurement, and almost nobody writes it.
Most disappointing security contracts in Lebanon are not signed with bad companies. They are signed without a specification. Two quotes for “one guard, twenty-four hours” can describe entirely different services: whether relief for leave and sickness is included, who supervises the officer and how often, what gets written down, who answers the phone at two in the morning, and what the officer is permitted to decide alone. When none of that is on paper, price is the only field the two quotes share — so price decides, by default, and you find out what you bought several months later.
One page is enough. Site and hours. What the officer must control and what they may never decide alone. Who they call, in what order, and how quickly you personally expect to be told. What you want to be able to read the next morning. Take that identical page to every provider on your list. The differences in how they respond to it — which ones ask sharper questions, which ones quietly reduce the scope, which ones price the awkward parts — become the real comparison. If the exercise reveals that you do not yet know your own exposure well enough to write the page, that is what a proper security risk assessment is for, and it is cheaper than a mis-specified year of guarding.
Licensing: the first check, and the one most buyers skip
Security services can be subject to authorisations that change over time and may depend on the provider, proposed personnel, equipment, and assignment. Ask each provider to identify in writing the current requirements applying to your service, the issuing authority, the available evidence, its scope and validity. Confirm the answer with the competent authority before deployment.
Put the answer in the contract, not only in meeting notes. The clause should identify which authorisations apply, what evidence is held, its validity, who verifies it, and how you will be notified if the status changes. Ask your insurer whether the proposed service creates documentary conditions. Regulations and policies change, so verify them directly rather than relying on any website, including this one.
Without a specification, price is the only field two quotes share — which is exactly why an unspecified contract is always won on price.
ISO 9001:2015 — what the certificate proves, and what it does not
ISO 9001:2015 is a quality-management standard. Holding it means an organisation has documented its processes, follows them, checks itself against them, and submits to an external audit on a cycle. That is a genuinely useful signal — it is the difference between a company that has a procedure and a company that has a habit. What it does not mean is that the guards are good, that response is fast, that the price is fair, or that the service will suit your site. It is a statement about management discipline, not about outcomes at your gate.
Treat the bare phrase “ISO certified” as marketing, because that is all it is. A certificate has four things worth reading: which standard, which certificate number, which certification body issued it, and when it expires. Ask for all four. Then ask for the fifth, which is the one that actually matters and the one almost nobody requests — the scope statement. The scope is the sentence on the certificate that says which activities the certification covers, and it can legitimately be narrow. A certificate whose scope covers head-office administration tells you nothing about how a night shift is run.
Used properly, the certificate is a lever rather than a badge. If the scope genuinely covers the delivery of guarding services, then somewhere in that company there is a written, dated, owned procedure for the things you care about. So use it: pick one procedure relevant to your site — how an incident report is escalated, how an absent officer is replaced, how a complaint is closed — and ask to see it. An organisation with a real management system will produce it on the spot and will not find the request strange. One that treats the certificate as wall decoration will offer to “send something over” and then send a brochure.
Vetting: who is going to be standing at your door
The officer at your entrance will hold keys, learn access codes, and be trusted by residents, staff, and visitors within a fortnight. Vetting is the only process standing between that position of trust and a person nobody checked. Ask what is verified before assignment: identity documents, criminal-record checks where obtainable, previous employment actually contacted rather than merely listed, references genuinely called, and fitness for the physical demands of the post.
The useful question is never “do you vet your staff?” — every company on earth answers yes. Ask instead for a redacted example of a real officer file, and ask what disqualifies a candidate. A company with a genuine standard names its disqualifiers immediately and without consulting anyone, because those criteria are used weekly. A company without one will describe a philosophy and never reach a specific.
Then ask the question that separates a policy from a practice: are any of the officers who will serve your site subcontracted from another company? Subcontracting is not automatically wrong — cover has to come from somewhere on a bad week — but undisclosed subcontracting is, because it silently transfers your vetting standard, your insurance position, and your liability chain to a company you never assessed and cannot name.
Training, and the difference between a course and a competence
Training is what separates a trained officer from a warm body in a uniform, and it arrives in three layers that buyers routinely collapse into one: basic instruction (the legal limits of the role, the boundaries around use of force, report writing, fire and first-aid awareness, conduct with the public), site induction, and refresher training — which exists because everything in the first two decays.
Site induction is both the layer most often skipped and the one whose absence you will feel first. An officer who is excellent in general terms but does not know which stairwell door is alarmed, which delivery is expected on Tuesday morning, or which of the four gates is never to be opened after dark is not yet effective at your site — however good their certificate. Ask how many hours of induction each officer receives before their first unsupervised shift, who delivers it, and who signs it off.
Then ask for evidence rather than assurance: a dated training record for the specific officers assigned to you, an induction sign-off sheet for your site, and a refresher calendar with real dates on it. And ask one question that providers rarely expect — does the training explicitly cover what an officer may not do? A security officer is not a police officer. They deter, observe, control access, document, and escalate; they do not investigate, detain at will, or settle disputes by force. An officer who has never been told where that line sits is a liability waiting to be triggered, and the training record is where you find out whether anyone told them. This is covered in detail in our guide to security guard training and licensing in Lebanon.
Supervision and reporting: how you will know what actually happened
Everything above decays without supervision, on a predictable schedule — roughly six months into a posting, when familiarity has set in. Ask who supervises your officers, how many other sites that supervisor carries, how often they physically attend yours, at what hours, and whether each visit is timestamped. A supervisor who only ever appears in daylight is not supervising your night shift, whatever the contract says.
Reporting is the only window you have onto a service you are not present to watch. Ask for a redacted sample of a real daily report and a real incident report from an existing site — not a blank template. Read them the way an auditor would: are entries timed, legible, and specific; do they name what was observed, what was done, and by whom; is there any evidence of a decision rather than a note. A daily report reading “all normal” for thirty consecutive days is not a record of a quiet month, it is a signature collected thirty times.
Finally, put a time on it. At 2:47 in the morning something happens on your site: who does the officer call first, who calls you, and how long before you know? Ask for the name and the number, and ask who answers that number at 2:47. “The office” is not an answer unless someone is in the office. Providers who run a genuine out-of-hours process describe it as a sequence with names; providers who do not will describe an intention, and you will discover the difference on the night it matters. The supervision and accountability guide sets out how to audit this after you have signed.
Insurance, liability, and the exclusions worth reading twice
There are two distinct exposures in a guarding contract and they need separate answers. The first is harm caused by something an officer did — a wrongful detention, an injury during an intervention, damage to property. The second is loss you suffered because an officer failed to do something they were contracted to do. Ask which insurances the company carries, for what limits, and ask for the certificate itself. A line in a proposal saying “fully insured” is a claim, not a policy.
Then read the exclusions, which is where policies actually live. Several are common enough to check by name: cover restricted to officers who hold a current licence; cover excluding subcontracted personnel; cover excluding certain site categories or activities; and notification clauses requiring that an incident be reported to the insurer within a defined period. That last one quietly transfers a duty to you — if the provider does not notify in time, the exclusion bites, and you find out during the claim rather than during the negotiation.
Price structure: how to read a rate that is not really a rate
An hourly or monthly figure for “a guard” is not a comparable number until you know what sits inside it. Ask explicitly whether the rate includes relief cover for annual leave and sick days, overtime, public holidays, uniform and equipment, the supervision described earlier, the reporting you were shown, and transport where the site demands it. Then ask what triggers a surcharge, and ask for the surcharge schedule in writing. Most quotes that look unusually competitive are not cheaper; they are quoting a narrower thing.
The single most revealing pricing question has nothing to do with money. Ask what happens when an officer does not arrive for a shift. A provider whose staffing is real will describe a named process and a reserve, will tell you how quickly the gap is filled, and will confirm whether an uncovered hour is credited back to you. A provider whose staffing is thin will say that this does not happen. It happens everywhere; the only variable is whether it is tracked.
A rate well below the local market always resolves into something, and the list is short: unlicensed officers, no relief cover, no supervision, no insurance, or wages low enough to guarantee that nobody stays long enough to learn your site. None of those is free. You pay for each of them later, at a worse moment and usually at a higher figure, which is the subject of a separate piece on the real cost of cheap security. The right target is not the lowest quote or the highest; it is the quote whose contents you can name.
Red flags, and the checklist to take to every provider
A short list of answers should end a conversation rather than continue it. Refusing to put licensing in writing. Claiming certification without naming the standard, number, or scope. Being unable to produce a redacted report from any existing site. No named supervisor, or a supervisor who is also the salesperson. No written process for an absent officer. Guaranteeing an outcome — “no incidents” — that no security company on earth can guarantee. And reluctance to let you meet the officers before they are posted.
The strongest single test costs nothing: ask the same operational question of two different people at the company, a week apart — the sales contact and the operations manager, for instance. A real process produces the same answer twice, because both are describing something that exists. Improvisation produces two answers, and the gap between them is the gap between the proposal and the operation.
Take the checklist below to every provider you meet, and score them on it rather than on the meeting. It is deliberately written so that no company is advantaged by it, including ours — reluctance to be checked is itself the finding. When you are ready to compare specifications rather than prices, our professional security guarding page sets out how the service is structured, and the security consulting page covers the cases where the specification itself is the work.
- What to ask for
- A contract clause on officer licensing
- What a weak answer sounds like
- “All our staff are licensed, of course.”
- What to ask for
- Certificate number and scope statement
- What a weak answer sounds like
- “We are ISO certified.”
- What to ask for
- A redacted daily report from a live site
- What a weak answer sounds like
- A blank template, or “that is confidential”
- What to ask for
- Supervisor name, site load, and night visit records
- What a weak answer sounds like
- “Supervision is included in the price.”
- What to ask for
- The written absence and replacement process
- What a weak answer sounds like
- “That does not happen with us.”
- What to ask for
- Insurance certificate and the exclusions list
- What a weak answer sounds like
- “We are fully insured.”
- What to ask for
- A named escalation sequence with out-of-hours cover
- What a weak answer sounds like
- “Just call the office.”
Practical checklist
- Applicable authorisations: identified, evidenced, current, and recorded in the contract.
- Personnel evidence: scope and validity checked for the proposed assignment, with change notification agreed.
- ISO 9001:2015: certificate number, issuing body, expiry date — and the scope statement read.
- Vetting: named disqualifying criteria, a redacted sample officer file, and disclosure of any subcontracting.
- Training: dated records for your officers, an induction sign-off for your site, a refresher calendar.
- Supervision: named supervisor, sites carried, visit frequency, night attendance, timestamped visits.
- Reporting: a redacted real daily report and incident report — not a blank template.
- Escalation: the 2:47am sequence, with names, numbers, and who answers at that hour.
- Insurance: certificate seen, exclusions read — licensing, subcontractors, notification periods — and your own insurer asked what it requires.
- Price: what the rate includes, the surcharge schedule in writing, and whether uncovered hours are credited back.
- Contract: scope document attached, notice period, exit terms, mutual indemnity clause.
Related services
See today's conditions across Lebanon on the CIS Lebanon Security Index™.
Ready to talk about protecting your site, your people, or your operation?
Browse all services