RFPs and Lead Qualification
Identifying viable engagement opportunities and avoiding problematic projects from the start
Physical security testing engagements begin long before any facility is assessed. The process starts with identifying viable opportunities and filtering out problematic projects, which forms the foundation of a sustainable security testing practice. Effective lead qualification prevents wasted effort on proposals that will never succeed and protects practitioners from engagements that carry unacceptable risk. Understanding how to evaluate Requests for Proposals and qualify leads is essential knowledge for any security professional, and mastering this skill early in your career will save countless hours and prevent serious problems down the road.
Understanding Requests for Proposals
An RFP, or Request for Proposal, is a formal document through which organizations solicit detailed proposals for physical security testing services. Think of an RFP as an invitation to bid on work. Organizations use this document to describe what they need tested, outline their objectives and constraints, and communicate budget expectations. They typically send the RFP to multiple security firms and ask each one to submit a proposal explaining how they would approach the work, what it would cost, and how long it would take. This competitive process allows organizations to compare approaches and select the firm that best fits their needs.
RFPs are commonly used in enterprise and government settings, where formal procurement processes govern vendor selection. Smaller organizations may use informal requests through emails or phone calls, but the underlying concept remains the same: the organization is asking prospective security firms to propose how they would approach the requested work. Your response to an RFP is your proposal, which is a detailed plan explaining your approach, methodology, timeline, and pricing. Good RFPs provide enough information to write meaningful proposals because they clearly articulate what the organization needs, while bad RFPs are vague and make accurate proposal writing difficult, often leading to mismatched expectations later in the engagement.
Recognizing Quality Opportunities
When evaluating an RFP, certain characteristics signal a quality opportunity worth pursuing. These green flags indicate that an organization is serious about security testing and prepared to support a successful engagement.
Clear scope definition is perhaps the most important indicator. The RFP specifies exact facilities to test, precise objectives the organization wants to achieve, and explicit constraints on your work. You know what buildings and floors are in scope, you understand whether they want employee awareness testing or physical barrier validation, and the timeline expectations are explicit. This clarity enables you to create accurate proposals that address actual needs rather than guessing at what the client might want.
Realistic budget allocation signals organizational maturity. When an organization understands that comprehensive testing costs money and has budgeted accordingly, it shows they are serious about security testing and prepared to invest appropriately. Budget that matches the scope of work indicates a client who values what you do, while a mismatch between ambitious scope and minimal budget suggests problems ahead.
Authorized requesters make engagements legitimate. The RFP should come from someone with genuine authority to commission security testing, typically the Chief Security Officer, Director of Physical Security, or a similar executive role. You need to verify they have authority to grant facility access and authorize testing activities, because working with unauthorized requesters creates legal exposure regardless of their good intentions.
Reasonable timeline expectations show the organization understands that professional work requires preparation. They allow adequate time for planning, coordination, execution, and reporting rather than demanding immediate starts that would compromise quality and safety.
When you see these green flags together, you have found an opportunity worth pursuing with confidence.
Warning Signs of Problematic Engagements
Just as certain characteristics signal quality opportunities, warning signs indicate potentially problematic engagements that deserve serious scrutiny. These red flags should trigger careful evaluation, and multiple red flags together often justify declining the opportunity entirely.
Vague requirements make proposals impossible to write accurately. When the RFP says things like “test everything” or “assess all security” without providing specifics, there are no defined facilities, no clear objectives, and no explicit constraints. You cannot accurately estimate time, resources, or costs without knowing what you are actually being asked to do. More importantly, vague requirements create scope disputes later because they indicate the client does not actually know what they want.
Unrealistic budgets signal misaligned expectations. When clients want comprehensive multi-facility testing but have allocated minimal budget, they are expecting days of work for hours of pay. This indicates either that they do not understand what security testing involves or that they do not value it appropriately. These situations frequently become payment disputes when invoices arrive.
Rushed timelines create safety and quality problems. When a client needs testing immediately, perhaps starting next week or even tomorrow, there is no time for proper planning, coordination, or preparation. Important details get missed, and thorough work becomes impossible. Rushed timelines also indicate poor organizational planning that often manifests in other ways during the engagement.
Questionable authority creates legal exposure. When the person making the request lacks authority to commission security testing or grant facility access, authorization problems will arise during testing. Perhaps it is a middle manager without executive backing, or IT requesting physical testing beyond their departmental authority. Working with unauthorized requesters puts you at legal risk if other stakeholders object.
Any of these red flags warrants serious concern on its own, and multiple red flags together mean you should walk away no matter how attractive other aspects might appear.
Qualifying Leads Through Strategic Questions
Before investing significant time in detailed proposals, ask qualifying questions that reveal whether opportunities are worth pursuing. These questions should be asked during initial conversations, allowing you to screen opportunities early and focus your energy on viable engagements:
- What specific facilities need testing? Get exact addresses, building names, and locations. Vague answers at this stage are red flags suggesting the client has not thought through what they actually need.
- What are your security objectives? What do they want to learn from testing? What concerns are driving this request? Understanding their objectives helps you determine whether you can deliver meaningful value.
- What is your budget range? Does their budget align with their scope expectations? The budget tells you whether they are serious and whether the work is financially viable.
- What is your timeline? When do they need testing completed and results delivered? Is the timeline realistic given what they are asking for?
- Who has authorization authority? Can the requester actually authorize testing and grant facility access? This helps you avoid investing proposal time only to discover they cannot approve the engagement.
- Have you done this before? First-time clients need more education about what testing involves. Experienced clients typically have more realistic expectations.
- What are your success criteria? How will they measure whether testing was valuable? Clients without success criteria often become dissatisfied regardless of your work quality.
These questions reveal the true nature of opportunities quickly, helping you focus your energy on engagements that are likely to succeed.
Key Takeaways
- RFPs start formal engagements by defining project parameters upfront. They function as invitations to propose your approach, and your proposal explains your methodology, timeline, and pricing in response to what the client has requested.
- Green flags indicate quality opportunities: clear scope, realistic budget, proper authority, and reasonable timelines. When you see these signals together, you have found an engagement worth pursuing.
- Red flags mean trouble ahead: vague requirements, unrealistic budget, rushed timelines, and questionable authority. Any single red flag warrants concern, and multiple red flags mean you should walk away.
- Seven qualifying questions help verify viability before investing time in detailed proposals. Ask them during initial conversations to screen opportunities early.
Effective lead qualification prevents wasting time on problematic projects and helps you focus on viable engagements that lead to successful outcomes for both you and your clients.