Security
Physical security services spanning access control systems (hard) and guarding/front-of-house-adjacent presence (soft) — genuinely resistant to a single category.
Security is the service most likely to be miscategorised, because the category question — is this a system or a person — has a different answer for every building.
Access control systems, CCTV infrastructure and intruder detection are hard, statutory-adjacent technical systems; guarding, front-of-house security presence and incident response are soft, people-delivered services. Most facilities need both, integrated, and forcing this service into either Hard or Soft alone misrepresents how it's actually specified and delivered.
Why this service exists
Security protects people, assets and continuity of operation simultaneously — one of the few FM services with a direct line to both life-safety and business-continuity outcomes.
What the service covers
- Access control system management.
- CCTV monitoring.
- Security guarding/patrol.
- Incident response.
- Security risk assessment.
Assets and objects
- Access-control infrastructure.
- CCTV systems.
- Perimeter and interior spaces.
- Security control room where present.
Who takes part
- Security managerRequired
Mandatory role.
- Licensed guarding staffRequired
Delivers patrol and response.
- Access-control/CCTV technical specialistSituational
Manages the systems.
- FM operations managerSituational
Coordinates with the FM organisation.
- Incident-response liaison with emergency servicesSituational
Escalates serious incidents.
What the service needs
- Security risk assessment.
- Threat/incident history.
- Access-control policy.
How delivery runs
- 01Maintain a current security risk assessment, reviewed against actual incident data, not just annually by default.
- 02Manage access-control systems and credentialing.
- 03Deliver guarding/patrol against a risk-informed deployment plan, not a flat headcount assumption.
- 04Respond to incidents per a defined escalation procedure.
- 05Review and adjust based on incident trends.
What is delivered
- Access logs.
- Incident reports.
- Patrol/monitoring records.
From output to outcome
Controlled access and documented incidents.
A secure environment for people and assets.
Genuinely inseparable from Business Continuity & Resilience, since a serious security incident is, by definition, a continuity event.
Where it gets tense
- Guarding levels set once at commissioning and never revisited against actual incident/risk trends.
- Access-control and guarding managed as entirely separate services with no integrated incident-response procedure between them.
Strategic, tactical, operational
Security risk assessment should feed directly into business continuity planning, not sit as a separate FM concern.
The hard/soft integration point (does the access-control system alert guarding staff automatically, or are they separate workflows) is where most practical security gaps actually occur.
Guarding staff licensing and training standards vary significantly by jurisdiction and should be verified, not assumed.
Performance indicators
- Incident response time
Core indicator.
- Access-control system uptime
Technical reliability.
- Security incident rate and severity trend
Risk trend over time.
Risks
- Licensing requirements for guarding staff (jurisdiction-specific).
- Data protection obligations for CCTV footage (GDPR/AVG-relevant).
- Duty-of-care liability for security incidents.
Statutory context
Guarding licensing obligations are jurisdiction-specific; GDPR/AVG applies to CCTV data regardless of jurisdiction within the EU.
Sourcing options
- Single service
Guarding commonly single-service outsourced to licensed security providers.
- Managing agent
Access-control/CCTV systems sometimes retained under separate technology-vendor contracts — worth naming this common split explicitly since it's where integration gaps concentrate.
Technology and data
- Access control systems.
- CCTV/video analytics.
- Integrated security management platforms.
Competencies required
- Licensed security management.
- Risk assessment.
- Incident command.
Common mistakes
- Treating access-control technology and guarding as unrelated procurement decisions rather than one integrated security capability.
- Under-reviewing guarding deployment against actual risk data.