top of page
Search

Physical Security Measures for Critical Infrastructure: A Layered Approach

Writer: Paul Davies
Paul Davies
Sep 8
7 min read

Critical infrastructure often depends on assets, systems and services spread across more than one building, boundary or operational location. Essential functions may rely on control systems, communications, utilities, suppliers and specialist personnel working together.


That interdependence creates a difficult security problem. A strong perimeter cannot compensate for uncontrolled maintenance access. CCTV provides limited value when alarms cannot be verified quickly. A secure control room may still become unavailable if its power, cooling or communications can be disrupted elsewhere.


Effective physical security measures for critical infrastructure must therefore operate as a coordinated system. Each layer should address a defined threat, support an operational action and have a clearly accountable owner.


Scope note: This article discusses general physical security principles for critical and essential infrastructure. Formal Critical National Infrastructure designation, regulatory duties and acceptable measures vary by sector, operator and site.


Begin with the Essential Function

Security planning should start with the function that must continue, not with a list of products already available.


The UK Government’s Resilience Action Plan highlights the interdependence of critical services and the potential for disruption in one part of the system to cause wider consequences.


Before selecting barriers, surveillance or access-control technology, establish:

  • Which services and processes must remain available

  • Which people, facilities and systems support them

  • What dependencies could cause indirect failure

  • How long an interruption could be tolerated

  • Which operations must be restored first

  • What minimum service level must be maintained


This process often reveals that the most visible asset is not necessarily the only one requiring protection.


A well-protected control room, for example, may still depend on exposed communications cabling, an accessible backup generator or cooling equipment positioned elsewhere on the site.


Our guide to critical national infrastructure resilience considers how physical, cyber, personnel and operational risks can overlap across essential services.


Map the Likely Attack Timeline

A layered security system should interrupt the sequence an attacker would need to complete.


That sequence might include reconnaissance, approaching the site, crossing the perimeter, moving through operational areas and reaching a critical asset.


The NPSA protective security methodology organises protection around five connected functions:

Protective function

What it should achieve

Deter

Make an attempted attack less attractive or more difficult to plan

Detect

Identify suspicious activity or a breach early enough to act

Delay

Slow progress towards the protected asset

Mitigate

Reduce the operational, safety or public impact

Respond

Enable an effective intervention and recovery action

For each control, document:

  1. The threat it addresses

  2. Its expected detection, control or delay contribution

  3. The action required when it activates

  4. The person or team responsible

  5. How its effectiveness will be tested


Controls without a defined operational requirement are difficult to test, maintain or justify.


Build Protection from the Critical Asset Outwards

Beginning at the essential function reduces the risk of creating a perimeter-heavy design while leaving the most important assets insufficiently protected.


Protect the Critical Asset Directly

The innermost layer may contain a control room, communications node, switching facility, data hall, pumping system, hazardous process or backup-power installation.


Possible asset-level measures include:

  • Secure rooms, cages and equipment enclosures

  • Separate credentials for critical areas

  • Local intrusion and tamper detection

  • Protection of control panels and shutdown systems

  • Locked cabinets for sensitive equipment or records

  • Restrictions on tools, portable media and maintenance access

  • Resilient power, cooling and communications arrangements

  • Assessment of whether primary and backup capabilities share the same vulnerabilities


Access to general operational areas should remain separate from access to assets whose loss would create serious consequences.


This is especially important at sites where contractors, engineers or delivery personnel require legitimate access to parts of the facility but do not need to enter critical operational spaces.


Control Movement Within the Site

Crossing the perimeter should not provide unrestricted movement.

Internal zoning can separate public, operational, restricted and critical areas. Permissions should reflect the person’s role, working hours and the purpose of the visit.


Measures may include:

  • Role-based access rights

  • Separate routes for staff, visitors, contractors and deliveries

  • Time-limited permissions for temporary work

  • Escort requirements in restricted areas

  • Key, card and credential management

  • Controls against tailgating

  • CCTV at transitions between zones

  • Scheduled reviews of access permissions


Maintenance routes, loading areas and plant access deserve particular attention because frequent legitimate use can create pressure for informal exceptions or workarounds.


Permissions should also reflect time and context. Access that is reasonable during a fully staffed shift may create unnecessary exposure overnight or during reduced operations.


Treat the Building Envelope as a Complete Boundary

Doors, glazing, walls, roofs, vents and service penetrations can all form part of an attack route.


A robust doorset may contribute little if the surrounding wall, ceiling void or adjacent window offers an easier entry point. Frames, fixings and supporting construction must therefore be considered alongside the product.


The NPSA’s guidance on protection from forced entry recommends selecting protective measures against the relevant attacker, tool capability and required resistance.


Building-level controls may include:

  • Security-rated doors, shutters and glazing

  • Protected roof access and external ladders

  • Detection on vulnerable openings

  • Secure loading-bay arrangements

  • Reinforced ducts, vents and service penetrations

  • Controlled emergency and maintenance entrances

  • Locks and hardware compatible with safe egress


Security requirements must be coordinated with fire safety, accessibility, maintenance and emergency response.


Controls that conflict with essential operations may encourage informal workarounds, so security measures should be developed with operational and safety stakeholders.


Design the Perimeter for Detection, Control and Delay

A perimeter should define controlled space, channel authorised access and support early detection.


Its design should consider terrain, neighbouring properties, public access, drainage routes, utilities and vehicle approaches.


Depending on the risk, physical security measures may include:

  • Fences, walls and secure gates

  • Pedestrian and vehicle checkpoints

  • Hostile vehicle mitigation

  • Perimeter intrusion detection

  • CCTV positioned for alarm verification

  • Security lighting

  • Protection of culverts, ducts and service corridors

  • Guarding and patrol routes

  • Clear zones around vulnerable boundaries


The full perimeter should be examined rather than only the most visible frontage. A rear service gate, waterside edge, adjoining roof or shared utility route may offer a less controlled approach.


Consider Activity Outside the Formal Boundary

Hostile planning may begin before someone enters the site.


Teams should understand the organisation’s reporting thresholds for repeated or unusual activity around sensitive areas, while avoiding assumptions based solely on lawful behaviour or a person’s appearance.


Potential indicators requiring proportionate assessment may include repeated attempts to understand access routines, unexplained interest in restricted infrastructure or unusual activity that forms part of a wider pattern.


Publicly available information should also be reviewed. Site plans, contractor documentation, staff posts and photographs may unintentionally reveal entrances, routines or critical equipment.


Link Every Alarm to a Response

Every alarm requires a defined verification, escalation and response path.


For each alert, establish:

  1. Who receives it

  2. How its location and cause are verified

  3. Who can authorise escalation

  4. Which responder is expected

  5. How long intervention is likely to take

  6. What happens if the primary response is unavailable


Required barrier delay should be assessed against the time needed to detect, verify, escalate and deliver an effective response.


Those assumptions should reflect nights, weekends, remote locations and competing incidents, not only ideal daytime conditions.


Exercises should test decision-making and coordination rather than simply confirming that an alarm activates. Operators require accurate maps, usable camera views, current contact details and clear instructions for different scenarios.


Address Cyber-Physical Security Dependencies

Modern physical protection increasingly depends on networks, software, remote administration and digital credentials.


Access control, surveillance, perimeter detection and building-management systems may share infrastructure or exchange data with operational technology.


NPSA’s guidance on network-connected security technologies advises organisations to understand the cyber, data and remote-access risks associated with connected physical security systems.


At minimum, establish:

  • Which security systems connect to a network

  • Who administers them

  • How privileged access is controlled

  • How software and firmware changes are managed

  • Whether event logs are retained and reviewed

  • What happens if communications are lost

  • Which manual procedures remain available during an outage


Our article on security convergence explores why physical, cyber and operational teams require shared governance and clearly defined responsibilities.


Ownership may be distributed, but accountability for connected systems and incident escalation must remain explicit.


Test the Interfaces Between Measures

Individual products may operate correctly while the wider protective system fails.

Assurance should focus on the interfaces between barriers, technology, procedures and people.

Assurance question

What should be checked

Can alarms be located and verified quickly?

Camera views, alarm maps, operator procedures and test records

Do permissions reflect current roles?

Joiner, mover, leaver and contractor reviews

Does barrier delay support the response plan?

Attack-path analysis and timed exercises

Are backup systems exposed to shared failures?

Physical location, utility routes and communications dependencies

Can responders reach the incident safely?

Routes, keys, permissions and communications

Can operations continue during technology failure?

Manual fallbacks and loss-of-system exercises

Examples that warrant further investigation include:

  • Cameras that cannot verify the alarmed area

  • Credentials remaining active after a role or contract ends

  • Strong doors installed within weaker surrounding construction

  • Primary and backup systems sharing the same vulnerable utilities

  • Contractors using informal routes around access controls

  • Connected security systems without a clear technical owner

  • Response procedures that have not been exercised


The assessment should be repeated after building alterations, operational changes, security incidents, new technology or material changes in the threat.


Reviewing Layered Protection Across a Critical Site

Our published physical security project experience includes project management for a multi-site utilities CNI programme and independent scrutiny of physical security design specifications.


Our Physical Security Assessment reviews how infrastructure, access controls, procedures and behaviours work together. Depending on the agreed scope, this may include fencing, doors, glazing, locks, lighting, CCTV, barriers, pedestrian and vehicle access, visitor management and incident readiness.


Findings are prioritised based on the organisation’s risk profile, potential business impact, and the feasibility of remedial action.


The assessment does not remove all risk or replace specialist engineering, product certification, sector regulation or statutory assurance. It provides an independent basis for identifying gaps and prioritising proportionate improvements.


If you need to review whether your current security layers protect the functions that matter most, visit our Physical Security Assessment service page to see how we can assess your existing arrangements, identify vulnerabilities and prioritise practical improvements.


Test Whether Each Layer Addresses a Defined Risk

Effective physical security measures for critical infrastructure do not depend on installing the maximum number of controls.


They depend on understanding the critical function, mapping credible attack routes and connecting deterrence, detection, delay, mitigation and response.


The security plan should link each measure to a threat, an operational action and an accountable owner. Barriers should support realistic response times, alarms should lead to defined decisions and backup systems should be checked for shared vulnerabilities.


When protection is designed and tested in this way, organisations can direct investment towards the highest-priority vulnerabilities rather than adding isolated measures that provide little additional assurance.


 
 
 

Comments


Si4 Security Logo

​

Enquiries

Thanks for submitting!

ADDRESS

Si4 Security Ltd

Cardiff House
Cardiff Road
Vale of Glamorgan
CF63 2AW

PHONE

01446 501630

EMAIL

  • LinkedIn
Company Registration 16074137
bottom of page