Practice Area · Security · 04

Force Protection & InfoSec

A determined adversary studies the perimeter long before anyone notices they're watching.

The Problem

Sites with real exposure tend to be protected by arrangements that accumulated rather than were designed. A guard contract from one era, a camera system from another, post orders that describe a layout that has since changed. Each piece is defensible on its own. Together they leave seams.

The gaps are rarely at the fence. They are in the routine — the parts of daily operation that were never examined because they have always worked. A site under real exposure is studied over time, and what makes one predictable is usually an operational habit nobody thought to review.

Information security belongs in the same conversation. A perimeter is not defended on its own if the information describing how it runs is held loosely, and access granted from inside defeats both halves at once. We treat them as one problem because that is how they are used.

What We Deliver

  • Force protection assessments for compounds, facilities, and remote field sites
  • Perimeter and defensive posture planning: standoff distance, access control, and layered defense
  • Guard force planning, post orders, and reaction-force procedures
  • Operational security (OpSec) programs for sensitive sites and operations
  • Information security (InfoSec) policy design and implementation
  • Insider threat programs: detection, response, and prevention

Who We Serve

Energy operators, remote compounds and man-camps, and critical infrastructure sites with personnel and assets to protect, plus organizations with elevated risk profiles that need a genuinely defensible perimeter.

Why Acacia Lake

Our team brings military and force protection experience. We assess a site the way an adversary would: from the outside in, then close the gaps they'd exploit.

How An Engagement Runs

  1. 01

    Discovery

    We assess the site from the outside in, before we look at a single document. That order matters: it produces a picture of the site as it actually presents itself, rather than as the plan describes it.

  2. 02

    Diagnosis

    A written assessment of where the posture is weakest, ranked by consequence and by how quickly each gap can be closed. Physical, procedural, and informational findings are reported together, because in practice they are not separate problems.

  3. 03

    Execution

    We close the gaps: defensive posture and access control, post orders and reaction procedures, OpSec discipline where daily operation had become predictable, and InfoSec policy written to keep the site's own information properly held.

  4. 04

    Stewardship

    Postures decay as staffing turns over and routines drift back. We re-assess on a set cadence and stay available when the threat picture changes.

What You Receive

  • A written force protection assessment with each finding tied to the condition that produces it
  • Perimeter and defensive posture plans: standoff, layering, and access control
  • Guard force post orders and reaction-force procedures your contract can be held to
  • An OpSec program covering the operational habits and disclosures that warrant tightening
  • InfoSec policy written for the site, not lifted from a template
  • An insider threat program with detection, escalation, and response defined

Common Questions

Is this only for sites facing a specific, named threat?
No. Most of this work is done by operators with elevated general exposure — remote locations, valuable assets, personnel on site around the clock. A specific threat sharpens the timeline; it is not a prerequisite.
Do you provide guards?
We do not staff guard forces. We plan them: post orders, coverage, reaction procedures, and the standards your contracted provider should be held to. Keeping the assessment separate from the staffing contract is what keeps the assessment honest.
Why is InfoSec bundled with physical force protection?
Because they are not separate in practice. The information describing how a site runs is as sensitive as the site itself, and it is usually held far more loosely. Hardening the perimeter while leaving that unaddressed leaves the work half done.
Will your assessment disrupt site operations?
The external phase is non-intrusive by design and typically invisible to the site. The internal phase requires access and interviews, scheduled around your operations.
How is this different from your physical security practice?
Physical security designs the system — hardening, access control, surveillance architecture. Force protection is the posture and human procedure around it, for environments where exposure is treated as active rather than theoretical. The two are frequently scoped together.
Call (956) 477-1721Request a Consultation