Überwachungskameras an einem Mast vor der Fassade eines großen modernen Gebäudes

Building Security: The Three Pillars of an Integrated Security Strategy

27.08.2026 | 6 min read

Building security is usually thought about one product at a time: a stronger door, a camera system, electronic access control, a guarding contract. Each of those can be a sensible investment. None of them, on its own, adds up to a security plan that holds.

A camera may register an event. It does not trigger the right response. Access control enforces permissions in the system, but loses much of its value once those permissions stop being kept current. And a hardened building envelope only protects so far if sensitive areas are not properly separated from one another in the first place.

Effective building security does not come from installing as many controls as possible. It comes from making them work together against a defined set of risks.

A well-established model distinguishes three pillars: mechanical or structural security, electronic or technical security, and organisational security. The categories are useful because they structure different protective functions. But the aim is not to build each pillar out as far as it will go. The aim is to derive a security architecture from your protection requirements and your risks — one in which every control has a traceable job to do.

So building security does not start with the question of which technology to buy. It starts with a different question: what has to be protected, against which threats, and with what consequence if it fails?

What Is Building Security?

Building security covers the structural, technical, organisational and personnel controls that protect people, buildings, plant, information and business processes against physical threats.

That can include:

  • structural burglary resistance and hardening,
  • access control and permission management,
  • video surveillance,
  • intruder alarm and detection systems,
  • perimeter security,
  • fire protection,
  • key and visitor management,
  • security control rooms and intervention,
  • organisational security processes,
  • training, exercises and personnel security controls.

Which of these you actually need cannot be answered in the abstract. An administrative site has different protection requirements than a production plant, a research campus or a data centre. Even inside one building, reception, office floors, plant rooms and high-sensitivity zones can sit at very different levels.

Building security is therefore less a fixed catalogue of controls than a capability: the ability to keep physical risk at a site under control.

A Building Security System Is More Than the Sum of Its Parts

The weak point in security estates that have grown over time is rarely missing technology. It is the seams between the controls.

Typical examples:

  • Electronic access control works, but permissions for leavers are not withdrawn consistently.
  • Cameras cover a security-relevant area, but nobody has defined who assesses an alarm.
  • An intruder alarm detects an event, while escalation and intervention processes are not aligned to the response time actually required.
  • A hardened door restricts access, while side entrances and plant routes into the same area were never assessed to the same standard.
  • A guarding provider is in place, but responsibilities between the security function, facility management and IT are unclear.

In every one of these cases the individual control works exactly as specified. The security problem sits in the system.

This is why building security should not be planned component by component. The useful question is not:

Which camera or which access control system do we need?

It is:

Which event must we detect or prevent, how quickly must it be detected, who assesses it, and what response has to be possible afterwards?

That shift moves planning away from products and towards protective functions and processes.

The Three Pillars of Building Security

The three-pillar model is a practical way to structure security controls. It is not a normative classification and should not be read as a rigid hierarchy. Depending on your protection requirements, individual functions carry different weight.

1. Mechanical and Structural Security: Resistance and Separation

Mechanical and structural security creates physical barriers and defines spatial boundaries.

This includes:

  • the building envelope,
  • doors and windows,
  • locks and locking systems,
  • walls and partition elements,
  • gates and vehicle barriers,
  • fencing and other perimeter security elements,
  • protection of sensitive rooms,
  • structural fire protection.

Its core function is to prevent or delay unauthorised entry and to separate security areas from one another.

For burglar-resistant components — doors, windows, curtain walling, grilles and shutters — the current DIN EN 1627:2021-11 sets out requirements and a classification of burglar resistance. The standard rates defined properties of construction products. It does not prescribe a universal resistance class for every type of building. Which class is appropriate for a given site follows from protection requirements, the expected attack scenario, the position of the component and the security plan as a whole.

That exposes a basic principle: strength in one place does not compensate for weakness in another.

A high-specification door achieves little if the same security area can be reached through a less protected route. Mechanical security has to be assessed along possible attack paths and across security zones — not just at component level.

2. Electronic Security: Detect, Control, Alert

Electronic security extends structural protection with detection, identification, monitoring, control and alerting.

Typical systems:

  • electronic access control,
  • intruder and hold-up alarm systems,
  • video surveillance and video analytics,
  • perimeter detection,
  • fire detection,
  • danger management and security management systems.

Electronic systems primarily produce information and options for action. Their actual protective effect comes from the process behind them.

A camera can capture a person. That information only becomes security-relevant once six things are settled:

  1. Which event are we trying to detect?
  2. Is the alarm assessed automatically or by an operator?
  3. How is a relevant event prioritised?
  4. Who receives the alarm?
  5. What response follows?
  6. Within what time must that response be possible?

The same applies to access control. The technical decision to grant or deny entry is only one part of the process. Permission assignment, periodic recertification of rights, handling of exceptions, lost credentials and the withdrawal of rights nobody needs any more matter just as much. This is well understood in environments where access management is the primary control.

With biometric access control, too, the method alone does not determine security. System architecture, attack resistance, operation and organisational integration count for at least as much.

Specific rule sets exist for individual security applications. For intruder alarm systems, VdS 2311:2025-06 – Einbruchmeldeanlagen, Planung und Einbau sets out requirements for the planning and installation of VdS-compliant systems. Guidance of that kind always belongs to its defined scope. It does not provide a general classification framework for building security as a whole.

3. Organisational and Personnel Security: Turning Technology Into a Process

The organisational pillar largely decides whether structural and technical controls actually do their job day to day.

This includes:

  • roles and responsibilities,
  • permission models,
  • key and badge administration,
  • visitor and contractor processes,
  • alarm and escalation routes,
  • guarding and intervention,
  • maintenance and functional testing,
  • documentation,
  • training and awareness,
  • exercises and emergency organisation.

Personnel controls can be treated as a category of their own. In the three-pillar model they are usually counted as part of organisational and operational delivery. What matters is their function in the security process, not where they are filed.

This is where weaknesses show up most often in practice. A well-engineered access control system only stays effective if permissions are issued traceably and reviewed on a schedule. An alarm system needs named responsibilities. And a security control room needs more than technology: qualified operators, clear escalation routes and decision processes that hold up under pressure. Managed security services exist precisely because this operational layer is hard to sustain in-house.

Organisation is what turns individual controls into an estate you can actually run.

Protection Requirements Connect the Three Pillars

The three pillars still do not tell you which controls you need.

That decision starts with protection requirements.

First, work out:

  • Which people, assets, information or processes need the highest protection?
  • What would the consequences of a security incident be?
  • Which threats are realistic for this site?
  • Which existing controls already reduce those risks?
  • Where do relevant gaps remain?
  • Which residual risks can be accepted?

Only then can you judge which structural, technical, organisational or personnel controls make a proportionate contribution.

This avoids two common failure modes.

Under-specification: individual controls are not sufficient against the threats identified, or leave gaps that are too large.

Over-specification: technology and processes become more complex and more expensive than the actual protection requirement justifies.

A risk-based building security strategy therefore does not chase maximum security. It aims at a level of protection that is proportionate and can be justified.

Layered Security Beats a Single Line of Defence

In demanding environments, building security is built in layers.

The idea is simple. If one layer is defeated or fails, others remain to detect, delay or respond.

Such an architecture can run from the outer site all the way to the most sensitive interior areas:

Perimeter → site access → building envelope → controlled building entrance → internal security zone → high-security area

Which layers you need depends on the site. Layered security in data centres shows the principle in its most developed form.

Perimeter security enables early detection of an approach. Access control then restricts entry to defined areas. Structural measures create resistance and separation. Video supports verification of events. Organisational processes make sure detected events are assessed and the right action is taken.

That reveals a defining feature of integrated building security: the controls do different jobs, and they complement each other.

Perimeter security, then, is not simply a fence. It is the first physical layer of a layered security architecture.

Connected Building Systems: Integration Creates Opportunity and New Dependencies

Modern security and building technology is increasingly networked. Access control, video, alarm and detection systems, building automation and security management can exchange data or be brought together in higher-level platforms — a development driven by building IoT and the wider smart building agenda.

The advantage is real: information from different systems can be assessed together.

A security-relevant event at the perimeter can be verified against camera images. An access transaction can supply context. In a security control room, several events can be assessed and prioritised as one picture. Building information modelling adds a further layer of spatial context to that.

But integration is not the same thing as better security.

More connectivity also creates:

  • technical dependencies,
  • additional interfaces,
  • potential single points of failure,
  • cyber attack surface,
  • more complex operating and permission models.

The goal should not be maximum connectivity. It should be integration you can control and defend.

Safety- and security-critical functions must not be blended into general building automation without thought. Requirements for availability, failover, fire and escape route functions or certified security systems can call for their own system boundaries. Getting those boundaries right is a core part of systems integration and engineering.

The BSI addresses these relationships in the IT-Grundschutz Compendium, among others in modules INF.1 General Building, INF.13 Technical Building Management and INF.14 Building Automation. INF.1 covers technical and non-technical security aspects in the planning and use of buildings. INF.13 addresses the secure operation of technical building equipment and the allocation of responsibilities, while INF.14 sets requirements for building automation systems.

These modules belong to the IT-Grundschutz methodology. They do not create a general legal obligation for every company or every critical infrastructure operator. Whether and how IT-Grundschutz applies depends on your organisational, regulatory and, where relevant, evidentiary context.

The current published edition of the IT-Grundschutz Compendium is still Edition 2023. The BSI published no new edition in 2025 and is developing the framework further in parallel under “IT-Grundschutz++”.

What a Building Security Plan Should Cover

A plan that holds is not produced by ticking off three pillars. It needs a traceable line from risk through to operation.

The steps usually run as follows.

1. Define Protection Objectives and Areas Worth Protecting

Start with which parts of the building need which level of protection. Reception, visitor zones, general office space, plant rooms, server rooms, goods-in and rooftop installations can all sit at different levels.

The decisive question is what the operational impact would be if each were compromised.

2. Assess Threats and Risks

Next, look at the relevant hazards.

Depending on the site, these can include:

  • unauthorised access,
  • burglary and theft,
  • sabotage,
  • insider actions,
  • vandalism,
  • fire,
  • water and natural events,
  • technical failures,
  • disruption of networked security and building systems.

Not every theoretically conceivable threat deserves the same attention. The assessment follows operating context, impact and the controls already in place.

3. Define Security Zones and Protective Functions

Areas that need protection should be separated from one another in a way that can be explained and defended.

This means deciding:

  • which areas are public or controlled,
  • who needs access,
  • which transitions are especially critical,
  • where events must be detected,
  • how much delay is required,
  • and what response times are necessary.

4. Derive Controls From the Risks

Only now do you select specific structural, technical, organisational and personnel controls.

The order stays clear:

Technology does not define the security plan. Protection requirements define which technology and which organisation are needed.

5. Plan Alerting and Intervention

Detection alone reduces no risk.

For every relevant event, settle:

  • who receives the alarm,
  • how it is assessed,
  • what escalation follows,
  • who can respond,
  • what response times are achievable,
  • and how external parties are brought in.

A 24/7 security control room and alarm monitoring connection is what makes those answers operational.

6. Set Out Operation and Responsibilities

Security controls change during live operation.

People move on, buildings are refitted, processes change and systems are extended. Permission management, maintenance, documentation, functional testing and responsibilities therefore belong in the security plan from day one.

7. Review Effectiveness Regularly

Every security plan encodes assumptions about protection requirements, threats and operating processes. When those conditions change, the plan should be reviewed too.

Our sResilience Health Check makes it visible whether existing controls still match your current protection requirements. Our Resilience Health Check is deliberately scoped as a current-state review within an agreed scope — it is not a substitute for a full risk and threat analysis.

How a deeper analysis and the development of a security plan work in practice is covered in our article on physical security strategies.

Regulation, Standards and Critical Infrastructure Security

Depending on your sector, your facilities and your corporate context, legal, normative or insurance-related requirements can apply to building security.

These can include:

  • requirements for critical infrastructure,
  • obligations connected with NIS2 or the German KRITIS Umbrella Act (KRITIS-Dachgesetz),
  • information security requirements with a physical security dimension,
  • standards for particular components or technical systems,
  • application-specific VdS guidelines,
  • sector-specific security requirements.

The important distinction is between legal obligation, normative requirement, recognised framework and professional recommendation.

Not every organisation has to apply the same standards. Nor does belonging to a building type or a sector automatically produce a particular catalogue of technical controls.

In critical infrastructure that distinction matters most. Regulatory classification follows specific facilities, services, thresholds and the applicable rule set — not a sector label.

Regulatory requirements do not replace a risk analysis. They set an additional frame within which a proportionate building security plan has to be developed.

What Building Security Means Across Different Site Types

Different building types tend to produce different risk profiles. That does not license a rigid security classification.

At an office or administrative site, visitor processes, internal permissions and the protection of sensitive business areas are often the priority — the core of most commercial building security programmes.

At production and logistics sites, perimeter security, delivery traffic, separation of operating areas and the availability of critical production processes carry more weight.

Research sites may additionally need to protect highly sensitive information, equipment or development results.

Data centres work with multiple security zones and graded access rights, because a physical incident has immediate consequences for business-critical IT infrastructure.

Here too, it is not the label on the building that determines which controls are appropriate. It is the specific risk.

That is why physical security has to be treated as a system: individual controls only deliver their protective effect inside a risk-led security architecture.

This is where we come in. e-shelter security plans, integrates and operates building security for data centres, critical infrastructure and multi-site organisations — from security technology through systems integration and installation to live operation from our 24/7 security control room. Structural, technical and organisational controls are not planned in isolation. They are brought together along your protection requirements.

Conclusion: Building Security Starts With Risk, Not Technology

Building security is not a component question.

Mechanical and structural measures create resistance and boundaries. Electronic systems detect, control and alert. Organisational and personnel measures make sure the technology is actually used effectively in operation.

The three pillars are therefore neither a catalogue of controls nor a fixed hierarchy. They are a model for bringing different protective functions together in a structured way.

The order is what counts:

Understand protection requirements. Assess risks. Define protective functions. Derive controls from them. Secure the interaction and the operation.

Only then do individual doors, cameras, sensors, access control systems and processes become an integrated security strategy for a building.

The quality of a building security system does not show in how much technology has been installed. It shows in whether every control makes a traceable contribution against real risk — and whether all of them still work together when something actually happens.

Want to know whether your building security still matches your protection requirements? Explore our solutions or talk to our experts; we support you from the first site walkthrough through to a completed security plan.

— More interesting articles