1 · Identify
Define what is being protected
List the collection assets, supporting information, keys and credentials, likely access routes, people with legitimate access and the most credible theft scenarios.
A prevention review is the disciplined examination of whether a collector's security arrangements actually protect the collection. It is not an inventory of locks, alarms, cameras and safes. It asks whether credible theft routes have been understood, whether controls work together, whether people use them correctly and whether detection leads to a safe and timely response.
Collections change faster than security assumptions. Values rise, objects move, access is granted, systems age, subscriptions lapse, online exposure accumulates and routines become informal. Review and improvement are therefore the mechanism that prevents yesterday's sensible decisions from becoming tomorrow's vulnerabilities.
A collector has not finished security because an installation has been completed. Effective prevention is a repeating risk-management cycle in which each review feeds the next assessment. The controls should remain proportionate to the collection, appropriate to the property and sustainable for the people who must operate them.
1 · Identify
List the collection assets, supporting information, keys and credentials, likely access routes, people with legitimate access and the most credible theft scenarios.
2 · Assess
Consider financial loss, replacement difficulty, provenance, research importance, completeness, emotional significance, recovery prospects and the speed with which theft could occur.
3 · Treat
Remove the vulnerability, add deterrence, detection or delay, improve response, transfer some risk through insurance, or knowingly accept the residual risk.
4 · Record
Record what was agreed, who owns the action, when it is due, how completion will be tested and what remains unresolved.
5 · Review
Test performance, verify that the original risk is still relevant, identify new weaknesses and return to a fresh assessment rather than closing the subject permanently.
A stable, modest collection may justify a formal annual review, supported by more frequent checks of alarms, cameras, locks, credentials, backups and inventory. Higher value, highly portable, frequently traded or publicly visible collections require a shorter review interval.
Major acquisition, sale, authentication, grading, new category, set completion or substantial market-value movement.
Relocation, building work, altered room use, new doors or windows, changed access routes or new outbuildings.
New household member, tenant, cleaner, carer, employee, contractor or the departure of someone with access.
Lost, duplicated, photographed, shared or unreturned keys, codes, fobs or account access.
False alarm, recording failure, suspicious enquiry, attempted entry, unexplained missing object or repeated near miss.
Local burglary activity, insurance renewal, long absence, bereavement, incapacity planning or any theft.
A weak review asks whether the collection room is secure. A strong review follows the entire sequence by which an unauthorised person could learn about the collection, approach the property, gain access, select an object, remove it, escape and sell it. That boundary extends beyond the display cabinet or safe.
Security investment becomes distorted when collectors begin by choosing equipment. The first task is to define what requires protection and why. Four asset classes should be considered because theft can remove both the object and the collector's ability to identify, value, prove or recover it.
Physical assets
Rare items, complete sets, prototypes, signed pieces, authenticated examples, packaging, inserts and small portable objects whose loss would reduce completeness or value.
Information assets
Inventories, photographs, values, storage locations, authentication reports, purchase records, ownership details and insurance schedules.
Access assets
Building keys, safe keys, alarm fobs, gate remotes, codes, cloud accounts, camera credentials and recovery methods.
Evidential assets
Serial numbers, measurements, distinguishing marks, condition records, provenance chains, receipts, object fingerprints and high-resolution identification images.
Purchase price, current market value, replacement value, agreed insurance value, liquidation value, historical significance, personal irreplaceability and criminal attractiveness are not interchangeable. A modest-looking object can be highly portable and easily sold; an object with limited market value can still carry unique research, family or provenance significance.
Reviews organised only around product categories such as locks, alarms and cameras tend to test components in isolation. Scenario review tests the entire chain from knowledge to resale and identifies where that chain can be broken.
Scenario chain
Knowledge → Approach → Access → Search → Selection → Removal → Escape → Resale
Opportunistic
An offender exploits a weak door, window, garage or rear approach and takes obvious, portable objects before anyone responds.
Targeted
The offender knows or strongly suspects that desirable objects are present and arrives with suitable tools, transport or specialist knowledge.
Legitimate access
A visitor, contractor, household member, cleaner, employee or acquaintance removes an object while lawfully inside.
Gradual loss
Items disappear one at a time, allowing theft to be mistaken for misplacement, loan, sale or cataloguing error.
Deception
A genuine item is replaced, components are swapped, or an offender gains access by impersonating a buyer, courier, tradesperson or official.
Transaction
The object is taken during viewing, transport, valuation, grading, repair, exhibition, handover or temporary storage.
Strong arrangements use layers with different purposes. No single layer should be treated as a complete solution, and no single failure should expose the whole collection.
Deter
Boundaries, maintained lighting, alarm indicators, secure openings, signs of occupancy and disciplined information control can make attack appear difficult or unrewarding.
Detect
Contacts, motion detection, cabinet sensors, cameras, access logs, inventory discrepancies, neighbour observation and monitored alarms reveal that something is wrong.
Delay
Resistant doors, internal zoning, anchored safes, locked rooms, secure cabinets and distributed storage slow access and removal.
Respond
Alerts need a known recipient, verification method, escalation path, safe attendance plan, police contact procedure and evidence-preservation response.
Inspect front, side and rear access, gates, climbing aids, vegetation, alleyways, roofs, garages, sheds, lighting, camera blind spots and places where an intruder could work unseen. High solid barriers can restrict access but may also provide privacy after they are crossed. The aim is controlled approach without creating concealment.
Review every plausible opening, including rarely used doors, garage-to-house doors, patio doors, rooflights, basement windows, loft hatches, communal corridors and routes exposed during building work. Examine the construction, frame, hinges, glazing, fixings, lock suitability and whether users actually engage the available security.
Crossing the external boundary should not make the entire collection immediately accessible. A locked collection room, secure cabinets, a separately protected high-value section, controlled documentation storage and restricted contractor access can create useful internal layers.
Review question
Can a visitor move from the entrance to the collection unobserved?
Review question
Does one compromised key or code expose everything?
Review question
Is the strongest container inside the weakest room?
Review question
Can a safe or cabinet be removed intact?
Review question
Are valuable objects left out after photography or cataloguing?
Review question
Do display arrangements advertise the target and its location?
Assess tested burglary resistance, insurer acceptance, anchoring, substrate, location, code or key control, capacity, fire and water characteristics and the conservation suitability of the internal environment.
Frequent failures include unanchored light safes, weak fixings, nearby override keys, unchanged default codes, excessive sharing, neglected batteries and the concentration of every important object and its records in one predictable place.
Examine detector coverage, entry routes, collection-room and container protection, communications, monitoring, power, backup, tamper resistance, setting habits, user codes, response contacts, maintenance and false-alarm history.
Test failure states: broadband down, mobile signal interrupted, mains power lost, collector overseas, phone silent, app logged out, backup contact unavailable or visible hub disabled.
Judge the usable result rather than the camera count. Check identification quality, entry and exit coverage, night lighting, angle, obstruction, timestamps, retention, recorder resilience, cloud status, account security, alert usefulness and export.
A camera view may be intended to detect an event, observe behaviour or identify a person or vehicle. One broad view rarely performs all three tasks well.
Many failures arise from uncontrolled authority rather than defective locks. Create an access register covering building and collection-room keys, safe keys, alarm codes, fobs, remotes, camera accounts, smart-lock access, recovery codes and emergency sets. Record who holds each credential, why it is needed, which areas it opens, when it was issued, when it was last confirmed and when it must be returned or revoked.
Physical security reduces the probability of theft. Inventory control reduces the time before theft is discovered. A useful reconciliation confirms that the object exists, is in the recorded location, is the same object, remains complete, has not been substituted and retains the recorded condition.
The review should test whether the collector could prepare a credible police report, insurer claim and market alert immediately. Copies of photographs, serial numbers, distinguishing marks, receipts, provenance, valuations, authentication records and insurer schedules should survive a theft of the object, the local computer and the paperwork stored beside it.
Public information can become an offender's reconnaissance file. Review current and historic social posts, room tours, livestreams, sales listings, auction images, geotags, reflections, exterior details, visible keys, alarm panels, packaging and travel disclosures. Separate fragments can be combined to reveal location, layout, value and absence.
Does the image reveal the address, neighbourhood or approach?
Does it show doors, windows, safes, alarms or collection-room layout?
Does it reveal where the highest-value objects are kept?
Does metadata contain location or device information?
Does the posting time reveal that the collector is away?
Can older posts be combined with current information?
Invoices, shipping labels, auction packaging, safe and alarm instructions, old inventories, valuation drafts and branded storage cartons can reveal acquisitions, dealer relationships, collection categories and household routines. Destroy sensitive paperwork, remove labels and avoid presenting major acquisitions to the street through conspicuous packaging waste.
A visual review cannot establish whether the system works. Safe and lawful testing should reproduce realistic operating conditions and foreseeable failures without attempting dangerous forced-entry simulation or defeating life-safety systems.
Lock each door and confirm the mechanism has actually engaged.
Trigger each alarm zone and verify delivery to every intended recipient.
Test communications during broadband or mains-power failure.
Retrieve footage from a specified date and export a shareable clip.
Check night-time image quality at likely approach points.
Confirm safe anchoring and spare-key custody.
Conduct a sample inventory audit and investigate discrepancies.
Restore an inventory backup and verify account-recovery methods.
Contact the emergency keyholder and rehearse alert escalation.
Review what happens when the collector is unavailable or overseas.
“CCTV installed” proves only presence. An effective-control statement describes the routes covered, usable night-time image quality, alert path, retention period, communications resilience and the date on which footage was successfully exported. Apply the same discipline to every important control.
| Dimension | Review question |
|---|---|
| Presence | Does the control exist? |
| Coverage | Does it protect the relevant asset and route? |
| Quality | Is it appropriately specified and installed? |
| Operation | Is it normally used correctly? |
| Reliability | Does it work during foreseeable failures? |
| Integration | Does it support the other security layers? |
| Response | Does activation produce timely action? |
| Evidence | Can performance be demonstrated? |
| Sustainability | Can it be maintained in practice? |
| Residual risk | What remains possible despite it? |
Hardware without procedure
Strong locks provide little benefit if a rear door is routinely left open or collection-room keys remain unattended.
Technology without maintenance
Cameras may be recording nothing, storage may be full, timestamps may be wrong, subscriptions may have lapsed or batteries may be depleted.
Alarm without response
An alert sent only to a collector who is abroad, asleep or offline is not an effective response arrangement.
Inventory without reconciliation
A catalogue cannot reveal theft if nobody checks that the recorded object remains present, complete and in the correct location.
Safe without anchoring
A light safe placed in furniture or fixed to a weak substrate may simply help an offender remove the most concentrated part of the collection.
Security without conservation
Unsuitable airtight storage, compression, off-gassing materials, damp locations or invasive marking can protect against theft while harming the object.
A door found unlocked, a contractor entering the wrong room, a failed recording, an unexpected code use, an object in the wrong location or a suspicious question is free evidence about a possible theft route. Treating near misses as harmless prevents the system from learning before a real loss.
•What happened and when?
•Who was present or had access?
•Which control should have prevented it?
•Why did that control fail?
•What immediate action was taken?
•What long-term corrective action is required?
•Who owns the action?
•What is the deadline and test of completion?
Not every weakness can be corrected at once. Priority should reflect likelihood, consequence, number of assets exposed, speed of theft, absence of detection, ease of correction, insurer requirements and whether one improvement reduces several risks.
Immediate
Recover compromised keys, revoke codes, repair insecure openings, restore failed monitoring, remove public absence information, secure exposed high-value items and back up ownership evidence.
Near term
Upgrade vulnerable locks, improve zoning, anchor suitable storage, add missing detection, formalise key control, improve inventory photography and establish response contacts.
Strategic
Reconfigure storage, replace fragmented systems, commission a professional survey, move exceptional material to specialist storage or revise estate and incapacity arrangements.
Record the weakness, affected assets, current control, supporting evidence, proposed treatment, priority, owner, target date, estimated cost, completion status, test performed, residual risk and next review date. Purchase is not completion.
Avoid superficial measures such as camera count or money spent. Useful indicators connect to performance, resilience and recovery. Metrics should guide judgement rather than become targets that reward poor-quality completion.
Percentage of high-priority objects with current identification photographs.
Percentage with adequate ownership and provenance evidence.
Time required to detect a missing high-risk object.
Number of unassigned, shared or unconfirmed keys and credentials.
Percentage of alarm zones successfully tested.
CCTV retrieval and export success rate.
Time from alert activation to acknowledgement and escalation.
Number and age of unresolved critical weaknesses.
Percentage of improvement actions completed and tested by deadline.
Frequency of inventory discrepancies and recurring false alarms.
Insurance does not prevent theft, but policy terms may dictate lock standards, alarm use, safe specifications, valuation intervals, transit conditions, unoccupied-property rules and notification duties. Confirm material changes with the insurer rather than assuming that a security upgrade automatically satisfies the policy.
Professional input becomes proportionate when collection value or significance is substantial, a targeted threat is suspected, premises are unusual, several people or staff have access, systems are complex, major building changes are proposed, insurer requirements are technical or theft has already occurred.
Police crime-prevention officers, accredited locksmiths, recognised alarm or CCTV installers and competent security consultants.
Specialist insurers, valuers, auction or market specialists and advisers familiar with the collection category.
Conservators, collection-care specialists and structural engineers where storage, anchoring or environmental conditions are involved.
Legal or data-protection advisers where surveillance, shared premises, employment, privacy or public-space capture creates obligations.
Myth
Nobody knows what my collection is worth.
Reality
A knowledgeable visitor, buyer, online follower or specialist offender may recognise value that ordinary people overlook.
Myth
The alarm prevents burglary.
Reality
An alarm primarily detects activity. Effective prevention also requires resistance, delay, communication and response.
Myth
CCTV means the offender will be identified.
Reality
Poor position, lighting, image scale, retention or export capability can leave footage evidentially weak.
Myth
The items are insured, so the risk is managed.
Reality
Insurance cannot restore unique provenance, rebuild a complete set or remove the personal and research consequences of theft.
Myth
Only strangers pose a risk.
Reality
Legitimate access, uncontrolled credentials, social engineering and excessive information sharing are credible theft routes.
Myth
A review is only needed after a major change.
Reality
Batteries fail, values rise, subscriptions lapse, vegetation grows, people leave and routines decay even when no formal change is declared.
Build the recurring operational checks that support the wider prevention review.
Return to the full theft-prevention framework and its related collector guidance.
Continue into the actions required when prevention fails or a loss is suspected.
Examine how access, visibility, handling and routine can make theft easier or harder.
Strengthen the daily management of keys, codes, visitors and authorised access.
Apply proportionate controls when legitimate visitors need access to the property.
Understand how review records, access logs and usable CCTV support investigation after a loss.