The layered physical security model
Physical security is most effective when designed as concentric layers — each layer providing both its own deterrent and detection function and depth against threats that penetrate the outer layer. The outer layer is the site perimeter: fencing, walls, vehicle barriers, and external lighting that define the boundary and make unauthorised access visible. The second layer is the building shell: hardened doors, windows, and access points that resist forced entry and delay an intruder long enough for detection and response.
The third layer is internal access control: segregating sensitive areas within the building (server rooms, cash handling, executive floors) from general access areas, and controlling movement between them through card access, PIN systems, or manned checkpoints. The innermost layer is the immediate protection of the highest-value assets: safes, armoured cabinets, locked server racks.
Human security resources — manned guards, mobile patrols, reception security — sit across all layers: they deter through visible presence, detect through observation and alarm response, and respond to breaches that the physical and electronic layers have not prevented. The proportionate balance between electronic and human security depends on the premises type, the assets being protected, and the realistic threat profile.
