The face of the moon was in shadow
Most access control at critical sites was designed to answer one question: is this person allowed in? That is the easy question, and answering it well does not make a site secure.
The harder questions arrive afterwards. Who was on site when the pump failed. Which contractor had access to the switch room in the fortnight before the outage. Whether the person who left through the north gate at 02:00 is the same person who entered through the main gate at 18:00. A system that cannot answer those has controlled entry without producing security.
What critical infrastructure actually changes
The phrase gets used loosely, so it is worth being specific about what makes a site different. Three things.
The consequence of failure extends past the operator. A breach at an office costs the business. A breach at a water treatment works, a substation or a fuel depot reaches people who never chose to take the risk, which is why these sites attract regulatory attention that ordinary commercial premises do not.
The threat is patient. Opportunistic theft is a nuisance. The serious risk at infrastructure sites is someone who is prepared to spend weeks understanding shift patterns, contractor rotations and which gate is unmanned at handover. Controls that defeat an opportunist barely inconvenience that person.
And the site is rarely one place. A generating station is a compound with an administrative block, a control room, a switchyard, a fuel store and a perimeter, and the population allowed into each differs. Treating it as a single access boundary (in or out) is the most common design failure and the hardest to retrofit.
Zones, not doors
The useful mental model is concentric. Public approach, controlled perimeter, operational area, critical area. Each boundary has its own population and its own evidence requirement.
| Zone | Who belongs | What the control has to produce |
|---|---|---|
| Approach | Anyone, including visitors and deliveries | Presence recorded. Vehicle and plate captured |
| Perimeter | Staff, cleared contractors, escorted visitors | Identity verified at entry and at exit |
| Operational | Staff on shift, contractors with a work order | Authorisation tied to a task and a time window |
| Critical | A named few, usually with a second person present | Individual attribution, retained and reviewable |
Most sites implement the perimeter and stop. The gap between perimeter and critical is where incidents actually happen, because it is where contractors, deliveries and maintenance crews operate, the population with legitimate access and the least oversight.
Contractors, which is where the exposure actually sits
The population with legitimate access and the least oversight is contractors, and at an infrastructure site it is usually the largest population on any given day. Maintenance crews, specialist engineers, cleaners, caterers, delivery drivers and the subcontractors they bring without telling anyone.
Three controls do most of the work here, and none of them is expensive.
- Access tied to a work order with a start and an end, so authorisation expires by default rather than by somebody remembering to revoke it
- A record of who a contractor actually is, held by the site rather than by the contracting company. Sites that cannot name the people who were on them are relying on a supplier's list they have never seen
- Exit recorded as strictly as entry. A site that knows who came in but not who left cannot answer the question that matters during an evacuation, and cannot detect the person who never went home
Retrofitting these is unglamorous work with a poor demo and a very good return. It is also the part most likely to be descoped when a project runs long, which is worth knowing before the project runs long.
Where surveillance is misunderstood
Cameras are usually bought for deterrence and justified for evidence, and they frequently deliver neither, for reasons that are known in advance and ignored anyway.
- Coverage is specified by camera count rather than by what has to be identifiable. A camera that proves someone was present is a different specification from one that proves who
- Retention is set by disk size rather than by how long an incident takes to surface. Infrastructure incidents are frequently discovered weeks later, by which time the footage has rolled
- Nobody is watching, and nobody was ever going to. Live monitoring is a staffing commitment, and a system sold on live monitoring but resourced for review is a review system with an expensive interface
- Lighting was never considered. A camera that produces unusable footage at night is unusable during the hours that matter
The honest position is that most surveillance at these sites is forensic rather than preventive. That is fine (forensic value is real value), but it should be designed for on purpose. Designing for prevention and delivering forensics is how organizations end up with footage nobody can use.
The integration that makes the difference
Access control and surveillance are usually procured separately, installed separately and operated separately, and the value sits in joining them.
A badge event with no corresponding camera event is worth investigating. So is a camera event with no badge. So is a badge used at a gate two minutes after the same badge was used at a gate fifteen minutes' walk away. None of those is detectable if the two systems keep separate records that a person has to reconcile by hand after something has already gone wrong.
The same applies to radio. Site security teams communicate over two-way radio, and the value of tying a radio call, a badge event and a camera view to the same timestamp is that an incident can be reconstructed rather than reconstructed from memory.
What to ask before you buy anything
- What question do we need this system to answer after an incident, and can it?
- Which population is actually the risk: outsiders, or authorised people doing unauthorised things?
- How long does it take us to notice something, and does our retention cover that period?
- Who reviews the records when nothing has happened? A system only checked after an incident is a system nobody knows is broken
- What happens when the power fails, and what happens when the network fails? These are the conditions during which sites are most vulnerable and most systems are least available
The last one is worth pressing on. Access control that fails open leaves the site unprotected; access control that fails closed can trap people inside a hazardous area. There is a right answer per door and it is a safety decision as much as a security one.
Doing it in stages
Nobody rebuilds a site's security in one project. The sequence that works is: fix the zone model on paper first, because it costs nothing and it determines everything after it; then bring identity and time attribution to the boundaries that matter most; then extend surveillance to those same boundaries at a specification that produces usable evidence; then integrate.
Doing it in the other order (cameras first, zones never) is how sites end up with sixty cameras, one gate and no idea who was in the switch room.


PLACEHOLDER
AGPO Certified 



