Ask most organisations about their security programme and the conversation turns immediately to firewalls, endpoint agents and phishing simulations. Yet every organisation still occupies physical space: offices, workshops, data rooms, loading bays. Physical security is where defence in depth actually begins, and it is often the layer that has had the least attention in the last decade. At Halkyn Consulting, we work across both disciplines. And the pattern is consistent: businesses with mature cyber controls frequently have physical protection that has not been reviewed since the office was fitted out.
What layered physical security means
Good physical security is not one strong barrier. It is a series of layers, each buying time and information, arranged from the site boundary inwards:
- Outer layer – the site perimeter: fences, walls, gates, landscaping, lighting and clear sight lines. Its job is to define the boundary, deter casual intrusion and channel people through controlled entry points.
- Middle layer – the building envelope: doors, windows, locks, shutters and the building fabric itself. This layer delays a determined intruder and generates alarms.
- Inner layers – protected rooms and containers: server rooms, stores, safes and cabinets holding the assets that actually matter.
Each layer should contribute to one or more of four functions: deter, detect, delay and respond. A fence deters and delays. A motion sensor detects. A monitored alarm triggers response. The design question is always the same: will the intruder be detected early enough, and delayed long enough, for the response to arrive before they reach the asset? If the answer is no, the individual products on the shopping list are irrelevant.
The mistakes we see most often
Three failures come up repeatedly in site reviews:
- Detection without response. Cameras record incidents beautifully for the insurance claim, but nobody is watching, and nobody attends. CCTV without a response plan is evidence collection, not security.
- Hard shell, soft centre. Impressive front-door controls, while the door at the rear is propped open with a fire extinguisher and the server room key hangs in an unlocked cupboard.
- Controls that decay. Physical measures degrade quietly: hedges grow over lighting, staff turnover erodes challenge culture, and door closers fail. Without periodic review, a good design becomes a paper design.
The supporting cast: lighting, detection and surveillance
Around the layers sit the systems that make them work.
- Security lighting is the cheapest deterrent available, but only when it is designed rather than bolted on: it should light the ground and the approach routes evenly, avoid glare that blinds cameras and observers, and actually be maintained – a dark corner behind a failed lamp is worse than honest darkness, because everyone assumes it is covered.
- Intrusion detection converts delay into warning: door contacts, motion sensors and glass-break detectors are only as useful as the monitoring and response arrangements behind them, so decide before you buy who receives the alarm at 3 a.m. and what they are expected to do about it.
- Video surveillance needs a defined purpose for every camera – detect a person at the fence, observe the yard, or identify a face at the door are different jobs needing different placement, resolution and lighting. Retention, storage and signage also carry legal obligations in the UK, so the system needs an owner, not just an installer.
All of these systems share one characteristic: they fail silently. Test them. Walk-test the sensors quarterly, review who holds keyholder duties, check the cameras actually cover what the design assumed, and treat the annual maintenance visit as a minimum rather than an assurance.
Physical security supports every other control
Your cyber defences assume the physical layer holds. Server rooms, network cabinets, backup media and the workstations your staff log into are all physical assets. An attacker who can walk to a network point does not need to defeat your firewall, and a stolen laptop bypasses years of patching discipline in thirty seconds. This is why standards from bodies such as the NPSA and the NCSC treat physical and personnel security as inseparable from information security. People are part of the same system: controls only work when staff understand them, which is why we put such emphasis on training your staff and on having a rehearsed incident response process that covers physical incidents as well as digital ones.
Where to start
You do not need a blank cheque. Start with three questions: What are we actually protecting? How would someone realistically get to it? How would we know, and what would we do about it? Walk your own site the way an intruder would – out of hours, from the back, without your badge. The findings usually fund themselves.
Halkyn Consulting provides independent physical security reviews alongside our cyber services. So if you would like a professional eye over your site, get in touch.
Discover more from Halkyn Security Blog
Subscribe to get the latest posts sent to your email.