Start with a threat and vulnerability assessment
Before specifying any security system, commission a written threat and vulnerability assessment (TVA) for the building. A TVA identifies who might want to access the building without authorisation and why, what they would do once inside, which physical and procedural weaknesses they would exploit, and which countermeasures would reduce both likelihood and impact.
A TVA for a logistics warehouse looks entirely different from one for a pharmaceutical R&D facility or a law firm with commercially sensitive client files. The threat actors, the assets at risk, and the countermeasure priorities differ completely. Skipping the TVA and going straight to a product specification is how organisations end up with expensive CCTV systems that nobody monitors and access control on the wrong doors.
The four layers of building security
Effective building security layers outward from the most critical asset to the outermost perimeter. Layer one is access control: who can enter which zone under what conditions — card, biometric, escort policy, visitor management. Layer two is electronic surveillance: CCTV with retention and monitoring, intrusion detection (motion, door/window, glass-break), and alarm systems. Layer three is manned guarding: a licensed officer at a fixed post or on patrol, providing real-time human judgment that no system replaces. Layer four is technical counter-surveillance (TSCM): periodic sweeps of sensitive areas (boardrooms, server rooms, executive offices) for listening devices, GPS trackers, and covert cameras.
The layers interact. A CCTV system without a guard to respond to an alert is a recording system, not a security system. A manned post without access control generates paperwork, not data. A board meeting in an unswept room with the right visitors present is a security event regardless of how many cameras are on the building exterior.
Access control — the most under-specified layer
Most Dutch commercial buildings are more vulnerable through access control failures than through physical breaches. Tailgating, propped doors, unescorted visitors, and shared access cards are among the most common vectors for unauthorised entry. Access control policy — who has credentials, how they are issued and revoked, and what the escort policy is for visitors and contractors — matters as much as the hardware.
For new buildings or building reconfigurations, the standard recommendation is to map access zones first: public-access zones (lobby, café), restricted zones (office floors, meeting rooms), and high-security zones (server room, boardroom, finance, HR). Assign the minimum necessary access to each credential level and audit the list quarterly. Most organisations discover on audit that departed staff, contractors, and service providers still hold active credentials.
TSCM — why new buildings need a sweep before occupation
A building security plan that does not include TSCM is incomplete for any organisation that handles commercially sensitive, legally privileged, or strategically valuable information. Technical surveillance devices (listening bugs, covert cameras, GPS trackers on vehicles) can be placed during construction, fit-out, cleaning, maintenance, or visitor access. They do not require a physical breach after occupation.
The most cost-effective TSCM intervention is a baseline sweep before first occupation, when the building is clean and any device found is clearly a pre-occupation plant. For high-value buildings — headquarters, legal offices, financial trading floors, diplomatic missions — a sweep before first occupation, then scheduled recurring sweeps, is the standard. Mission Support's TSCM team operates across the Netherlands with full RF spectrum, NLJD, and physical search capability.
Frequently asked
Do I need a security guard or can CCTV alone secure my building?
CCTV records events; a manned guard responds to them. For low-risk sites, CCTV with an alarm response contract may be proportionate. For sites where real-time access control decisions are needed, where incidents require immediate physical response, or where there is a known threat, a manned guard post is necessary. A security consultant can advise on the right balance after a site assessment.
When should I commission a TSCM sweep for a new building?
Before first occupation if the building handles commercially sensitive, legally privileged, or strategically valuable information. The baseline sweep before occupation is the most cost-effective — any device found is clearly a pre-occupation plant. Recurring sweeps (quarterly, bi-annually, or event-triggered) maintain the baseline.
How long does a building security assessment take?
A physical site assessment for a single-occupancy commercial building typically takes half a day to a full day, depending on floor area and complexity. The written TVA report follows within 5–10 business days. The assessment is the input to the security specification — skipping it produces an incorrectly specified system.
