T
echnology permeates every aspect of our lives, creating hybrid risk across physical, personnel, and cyber domains. NPSA asks security professionals to assess whether existing models of responsibility still reflect the environment they protect.
Beyond the Perimeter: Protective security in a
It's a sunny Tuesday morning. I wake up and my smart watch tells me I’ve been sleeping better recently, probably since I started scrolling less on social media before bed. I’m visiting a new client today, so over breakfast I programme the route into the car from my phone and switch on the air conditioning. Before I leave, I ask the home assistant to add some essentials to the family shopping list, which notifies my partner.
Throughout the day my phone tells me that I missed a delivery and that a neighbour left a message at the front door. After a long day at work, I'm looking forward to watching the new crime drama my streaming platform recommended.
We now routinely communicate with appliances, vehicles, home security, entertainment systems, and other connected technologies that permeate every aspect of our lives. In parallel, the physical environments we protect depend on similar advances. Offices automatically adjust heating, lighting, and other facilities based on sensor data, and in industry, older equipment is being fitted or replaced with new digital systems.
Connected technologies can both strengthen and threaten security and privacy. More everyday services are delivered through online accounts, effectively trading convenience and personalisation for a rich digital footprint, as online data ecosystems build detailed profiles of users doing the weekly shop, hailing a taxi home, or planning their next holiday. Similarly, connected workplaces can expose sensitive insights about sites or processes from aggregated data, unintentionally creating valuable hostile reconnaissance tools.
Traditional security models, structures, and roles have diverged from operational reality as connectivity has shaped environments. Hybrid threats pose
complex risk across physical, personnel, and cyber domains. Controls that were once bounded, visible, and locally enforced are now deeply intertwined with digital data, infrastructure, and governance that sit outside the conventional perimeter. Across commercial estates and office buildings, factories, public spaces, and critical infrastructure, networked technologies increasingly underpin how physical spaces function and how people interact with them.
NPSA’s work across physical and personnel security consistently highlights the growing influence of connectivity and data-driven processes. This is both in the environments we seek to protect, and the measures we use to protect them.
Organisations rely more heavily on connected platforms, remote operations, and dispersed infrastructure to deliver access control, hostile vehicle mitigation, weapons detection, visual surveillance, building management systems, and personnel functions. Physical security specialists must recognise how inextricably interdependent their fields are with technology, and vice versa; if not directly, then through people, whose behaviours are increasingly driven by interaction with personal devices and the digital systems around them.
A system outside your control
In this connected environment, every device interaction generates data that often travels far beyond the immediate system. Individual components, though simple in isolation, both influence and respond to a vast and opaque digital ecosystem. This ecosystem ignores organisational and geographic perimeters; it spans personal devices, corporate systems, and public infrastructure, linking entities across trust boundaries that operate under different security standards and legal obligations.
7 © CITY SECURITY MAGAZINE – SUMMER 2026
For protective security professionals, this misalignment between technical reality and organisational control represents a growing challenge. Security outcomes increasingly depend on systems and actors outside their visibility and authority. In some cases, service providers route or process data in jurisdictions where external authorities can legally compel access, often without the system owner’s knowledge or consent. As a result, organisations may depend on, or be exposed to, parts of a connected ecosystem they neither control nor fully understand.
The mission to secure our people, information, and physical assets brings together issues spanning protective security disciplines. This complexity challenges traditional notions of perimeter security, and demands an approach that accounts for the distributed, dynamic, and interdependent nature of modern connected ecosystems.
Security beyond convergence
The threat of access to data and control over systems in connected physical environments isn’t new; these dynamics are often discussed under the banners of ‘convergence’ and ‘cyber-physical’ systems. What continues to evolve, however, is the scale and richness of information generated, the range of capabilities embedded into everyday environments, and the degree to which human behaviour is influenced by technology. As functionality and integration increase, so too does the potential value of these systems to hostile actors. ‘Convergence’ is a starting point; implications for security extend beyond to fundamental questions of dependency, authority and accountability.
www.citysecuritymagazine.com
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36