Physical Security Measures for Critical Infrastructure: A Layered Approach

Critical infrastructure often depends on assets, systems and services spread across more than one building, boundary or operational location. Essential functions may rely on control systems, communications, utilities, suppliers and specialist personnel working together.
That interdependence creates a difficult security problem. A strong perimeter cannot compensate for uncontrolled maintenance access. CCTV provides limited value when alarms cannot be verified quickly. A secure control room may still become unavailable if its power, cooling or communications can be disrupted elsewhere.
Effective physical security measures for critical infrastructure must therefore operate as a coordinated system. Each layer should address a defined threat, support an operational action and have a clearly accountable owner.
Scope note: This article discusses general physical security principles for critical and essential infrastructure. Formal Critical National Infrastructure designation, regulatory duties and acceptable measures vary by sector, operator and site.
Begin with the Essential Function
Security planning should start with the function that must continue, not with a list of products already available.
The UK Government’s Resilience Action Plan highlights the interdependence of critical services and the potential for disruption in one part of the system to cause wider consequences.
Before selecting barriers, surveillance or access-control technology, establish:
Which services and processes must remain available
Which people, facilities and systems support them
What dependencies could cause indirect failure
How long an interruption could be tolerated
Which operations must be restored first
What minimum service level must be maintained
This process often reveals that the most visible asset is not necessarily the only one requiring protection.
A well-protected control room, for example, may still depend on exposed communications cabling, an accessible backup generator or cooling equipment positioned elsewhere on the site.
Our guide to critical national infrastructure resilience considers how physical, cyber, personnel and operational risks can overlap across essential services.
Map the Likely Attack Timeline
A layered security system should interrupt the sequence an attacker would need to complete.
That sequence might include reconnaissance, approaching the site, crossing the perimeter, moving through operational areas and reaching a critical asset.
The NPSA protective security methodology organises protection around five connected functions:
Protective function | What it should achieve |
Deter | Make an attempted attack less attractive or more difficult to plan |
Detect | Identify suspicious activity or a breach early enough to act |
Delay | Slow progress towards the protected asset |
Mitigate | Reduce the operational, safety or public impact |
Respond | Enable an effective intervention and recovery action |
For each control, document:
The threat it addresses
Its expected detection, control or delay contribution
The action required when it activates
The person or team responsible
How its effectiveness will be tested
Controls without a defined operational requirement are difficult to test, maintain or justify.
Build Protection from the Critical Asset Outwards
Beginning at the essential function reduces the risk of creating a perimeter-heavy design while leaving the most important assets insufficiently protected.
Protect the Critical Asset Directly
The innermost layer may contain a control room, communications node, switching facility, data hall, pumping system, hazardous process or backup-power installation.
Possible asset-level measures include:
Secure rooms, cages and equipment enclosures
Separate credentials for critical areas
Local intrusion and tamper detection
Protection of control panels and shutdown systems
Locked cabinets for sensitive equipment or records
Restrictions on tools, portable media and maintenance access
Resilient power, cooling and communications arrangements
Assessment of whether primary and backup capabilities share the same vulnerabilities
Access to general operational areas should remain separate from access to assets whose loss would create serious consequences.
This is especially important at sites where contractors, engineers or delivery personnel require legitimate access to parts of the facility but do not need to enter critical operational spaces.
Control Movement Within the Site
Crossing the perimeter should not provide unrestricted movement.
Internal zoning can separate public, operational, restricted and critical areas. Permissions should reflect the person’s role, working hours and the purpose of the visit.
Measures may include:
Role-based access rights
Separate routes for staff, visitors, contractors and deliveries
Time-limited permissions for temporary work
Escort requirements in restricted areas
Key, card and credential management
Controls against tailgating
CCTV at transitions between zones
Scheduled reviews of access permissions
Maintenance routes, loading areas and plant access deserve particular attention because frequent legitimate use can create pressure for informal exceptions or workarounds.
Permissions should also reflect time and context. Access that is reasonable during a fully staffed shift may create unnecessary exposure overnight or during reduced operations.
Treat the Building Envelope as a Complete Boundary
Doors, glazing, walls, roofs, vents and service penetrations can all form part of an attack route.
A robust doorset may contribute little if the surrounding wall, ceiling void or adjacent window offers an easier entry point. Frames, fixings and supporting construction must therefore be considered alongside the product.
The NPSA’s guidance on protection from forced entry recommends selecting protective measures against the relevant attacker, tool capability and required resistance.
Building-level controls may include:
Security-rated doors, shutters and glazing
Protected roof access and external ladders
Detection on vulnerable openings
Secure loading-bay arrangements
Reinforced ducts, vents and service penetrations
Controlled emergency and maintenance entrances
Locks and hardware compatible with safe egress
Security requirements must be coordinated with fire safety, accessibility, maintenance and emergency response.
Controls that conflict with essential operations may encourage informal workarounds, so security measures should be developed with operational and safety stakeholders.
Design the Perimeter for Detection, Control and Delay
A perimeter should define controlled space, channel authorised access and support early detection.
Its design should consider terrain, neighbouring properties, public access, drainage routes, utilities and vehicle approaches.
Depending on the risk, physical security measures may include:
Fences, walls and secure gates
Pedestrian and vehicle checkpoints
Hostile vehicle mitigation
Perimeter intrusion detection
CCTV positioned for alarm verification
Security lighting
Protection of culverts, ducts and service corridors
Guarding and patrol routes
Clear zones around vulnerable boundaries
The full perimeter should be examined rather than only the most visible frontage. A rear service gate, waterside edge, adjoining roof or shared utility route may offer a less controlled approach.
Consider Activity Outside the Formal Boundary
Hostile planning may begin before someone enters the site.
Teams should understand the organisation’s reporting thresholds for repeated or unusual activity around sensitive areas, while avoiding assumptions based solely on lawful behaviour or a person’s appearance.
Potential indicators requiring proportionate assessment may include repeated attempts to understand access routines, unexplained interest in restricted infrastructure or unusual activity that forms part of a wider pattern.
Publicly available information should also be reviewed. Site plans, contractor documentation, staff posts and photographs may unintentionally reveal entrances, routines or critical equipment.
Link Every Alarm to a Response
Every alarm requires a defined verification, escalation and response path.
For each alert, establish:
Who receives it
How its location and cause are verified
Who can authorise escalation
Which responder is expected
How long intervention is likely to take
What happens if the primary response is unavailable
Required barrier delay should be assessed against the time needed to detect, verify, escalate and deliver an effective response.
Those assumptions should reflect nights, weekends, remote locations and competing incidents, not only ideal daytime conditions.
Exercises should test decision-making and coordination rather than simply confirming that an alarm activates. Operators require accurate maps, usable camera views, current contact details and clear instructions for different scenarios.
Address Cyber-Physical Security Dependencies
Modern physical protection increasingly depends on networks, software, remote administration and digital credentials.
Access control, surveillance, perimeter detection and building-management systems may share infrastructure or exchange data with operational technology.
NPSA’s guidance on network-connected security technologies advises organisations to understand the cyber, data and remote-access risks associated with connected physical security systems.
At minimum, establish:
Which security systems connect to a network
Who administers them
How privileged access is controlled
How software and firmware changes are managed
Whether event logs are retained and reviewed
What happens if communications are lost
Which manual procedures remain available during an outage
Our article on security convergence explores why physical, cyber and operational teams require shared governance and clearly defined responsibilities.
Ownership may be distributed, but accountability for connected systems and incident escalation must remain explicit.
Test the Interfaces Between Measures
Individual products may operate correctly while the wider protective system fails.
Assurance should focus on the interfaces between barriers, technology, procedures and people.
Assurance question | What should be checked |
Can alarms be located and verified quickly? | Camera views, alarm maps, operator procedures and test records |
Do permissions reflect current roles? | Joiner, mover, leaver and contractor reviews |
Does barrier delay support the response plan? | Attack-path analysis and timed exercises |
Are backup systems exposed to shared failures? | Physical location, utility routes and communications dependencies |
Can responders reach the incident safely? | Routes, keys, permissions and communications |
Can operations continue during technology failure? | Manual fallbacks and loss-of-system exercises |
Examples that warrant further investigation include:
Cameras that cannot verify the alarmed area
Credentials remaining active after a role or contract ends
Strong doors installed within weaker surrounding construction
Primary and backup systems sharing the same vulnerable utilities
Contractors using informal routes around access controls
Connected security systems without a clear technical owner
Response procedures that have not been exercised
The assessment should be repeated after building alterations, operational changes, security incidents, new technology or material changes in the threat.
Reviewing Layered Protection Across a Critical Site
Our published physical security project experience includes project management for a multi-site utilities CNI programme and independent scrutiny of physical security design specifications.
Our Physical Security Assessment reviews how infrastructure, access controls, procedures and behaviours work together. Depending on the agreed scope, this may include fencing, doors, glazing, locks, lighting, CCTV, barriers, pedestrian and vehicle access, visitor management and incident readiness.
Findings are prioritised based on the organisation’s risk profile, potential business impact, and the feasibility of remedial action.
The assessment does not remove all risk or replace specialist engineering, product certification, sector regulation or statutory assurance. It provides an independent basis for identifying gaps and prioritising proportionate improvements.
If you need to review whether your current security layers protect the functions that matter most, visit our Physical Security Assessment service page to see how we can assess your existing arrangements, identify vulnerabilities and prioritise practical improvements.
Test Whether Each Layer Addresses a Defined Risk
Effective physical security measures for critical infrastructure do not depend on installing the maximum number of controls.
They depend on understanding the critical function, mapping credible attack routes and connecting deterrence, detection, delay, mitigation and response.
The security plan should link each measure to a threat, an operational action and an accountable owner. Barriers should support realistic response times, alarms should lead to defined decisions and backup systems should be checked for shared vulnerabilities.
When protection is designed and tested in this way, organisations can direct investment towards the highest-priority vulnerabilities rather than adding isolated measures that provide little additional assurance.




Comments