Risk & Access

Security

Physical security services spanning access control systems (hard) and guarding/front-of-house-adjacent presence (soft) — genuinely resistant to a single category.

B — Soft / workplace & userHardStrategicTacticalOperationalStatutory exposure

Security is the service most likely to be miscategorised, because the category question — is this a system or a person — has a different answer for every building.

This service resists one group

Access control systems, CCTV infrastructure and intruder detection are hard, statutory-adjacent technical systems; guarding, front-of-house security presence and incident response are soft, people-delivered services. Most facilities need both, integrated, and forcing this service into either Hard or Soft alone misrepresents how it's actually specified and delivered.

Why this service exists

Security protects people, assets and continuity of operation simultaneously — one of the few FM services with a direct line to both life-safety and business-continuity outcomes.

What the service covers

  • Access control system management.
  • CCTV monitoring.
  • Security guarding/patrol.
  • Incident response.
  • Security risk assessment.

Assets and objects

  • Access-control infrastructure.
  • CCTV systems.
  • Perimeter and interior spaces.
  • Security control room where present.

Who takes part

  • Security managerRequired

    Mandatory role.

  • Licensed guarding staffRequired

    Delivers patrol and response.

  • Access-control/CCTV technical specialistSituational

    Manages the systems.

  • FM operations managerSituational

    Coordinates with the FM organisation.

  • Incident-response liaison with emergency servicesSituational

    Escalates serious incidents.

What the service needs

  • Security risk assessment.
  • Threat/incident history.
  • Access-control policy.

How delivery runs

  1. 01Maintain a current security risk assessment, reviewed against actual incident data, not just annually by default.
  2. 02Manage access-control systems and credentialing.
  3. 03Deliver guarding/patrol against a risk-informed deployment plan, not a flat headcount assumption.
  4. 04Respond to incidents per a defined escalation procedure.
  5. 05Review and adjust based on incident trends.

What is delivered

  • Access logs.
  • Incident reports.
  • Patrol/monitoring records.

From output to outcome

Output

Controlled access and documented incidents.

Outcome

A secure environment for people and assets.

Organisational effect

Genuinely inseparable from Business Continuity & Resilience, since a serious security incident is, by definition, a continuity event.

Where it gets tense

  • Guarding levels set once at commissioning and never revisited against actual incident/risk trends.
  • Access-control and guarding managed as entirely separate services with no integrated incident-response procedure between them.

Strategic, tactical, operational

Strategic

Security risk assessment should feed directly into business continuity planning, not sit as a separate FM concern.

Tactical

The hard/soft integration point (does the access-control system alert guarding staff automatically, or are they separate workflows) is where most practical security gaps actually occur.

Operational

Guarding staff licensing and training standards vary significantly by jurisdiction and should be verified, not assumed.

Performance indicators

  • Incident response time

    Core indicator.

  • Access-control system uptime

    Technical reliability.

  • Security incident rate and severity trend

    Risk trend over time.

Risks

  • Licensing requirements for guarding staff (jurisdiction-specific).
  • Data protection obligations for CCTV footage (GDPR/AVG-relevant).
  • Duty-of-care liability for security incidents.

Statutory context

Guarding licensing obligations are jurisdiction-specific; GDPR/AVG applies to CCTV data regardless of jurisdiction within the EU.

Sourcing options

  • Single service

    Guarding commonly single-service outsourced to licensed security providers.

  • Managing agent

    Access-control/CCTV systems sometimes retained under separate technology-vendor contracts — worth naming this common split explicitly since it's where integration gaps concentrate.

Technology and data

  • Access control systems.
  • CCTV/video analytics.
  • Integrated security management platforms.

Competencies required

  • Licensed security management.
  • Risk assessment.
  • Incident command.

Common mistakes

  • Treating access-control technology and guarding as unrelated procurement decisions rather than one integrated security capability.
  • Under-reviewing guarding deployment against actual risk data.

Connections

Knowledge domains
  • Security Management
  • Risk Management
  • Privacy
To index
Standards and guidance
  • National security-licensing regulation (jurisdiction-specific)
  • GDPR/AVG for CCTV data handling
To index

Adjacent services

Last reviewed: 2026-08-23

Classified using market terminology (hard / soft / enabling), nuanced against EN 15221-8:2025 and ISO 41011:2024.

Services Atlas