// HIGH SECURITY DESIGN · HANS STUDY · ONTARIO, CANADA

High security design

In most buildings a door failure is an inconvenience. In some, it is the incident. Once failure has consequences beyond annoyance, almost every ordinary design assumption has to be re-examined, and most security designers have never had to do that.

I design and review security systems for environments where the stakes are real: borders, detention and custody, defence supply chain, utilities and water, courts, transit, and critical infrastructure. The work is the same disciplines as any other system, held to a standard where being mostly right is not a passing grade.

What changes at this level

  • The insider is in the threat model. Designing against someone with legitimate credentials, physical access and knowledge of the system changes supervision, audit, dual control and what a single person can do alone.
  • Failure modes are designed, not inherited. What the system does on power loss, network loss, controller loss and server loss is decided deliberately per subsystem rather than defaulting to whatever the product does.
  • Interlocks and sequencing. Mantraps, sally ports, vehicle traps and airlocks where two openings must never be unsecured together, and the logic has to hold even when a component is faulty.
  • Duress is a first-class function, not a feature enabled later. Silent alarm paths, what they trigger, who receives them, and whether the path itself can be cut.
  • Anti-passback and occupancy where knowing who is inside is an operational requirement rather than a report.
  • Evidence quality. Recording that will still be usable months later in a proceeding, with retention and integrity to match.

Redundancy that survives a real event

Most redundancy is designed against component failure and tested on a quiet Tuesday. High consequence environments fail during events, when several things go wrong together and somebody is under pressure.

  • Power, including generator transfer behaviour and what the system does during the gap.
  • Network paths that do not share a conduit, a room, or a single upstream device.
  • Server and database availability sized for rebuild time, not just failover.
  • Degraded modes that are defined and practised rather than discovered.
  • Whether the operator can still do their job when half the system is unavailable.

Standards, authorities and the paperwork

These environments come with obligations: authorities having jurisdiction, sector standards, security clearance and screening requirements, procurement rules, and in defence supply chain work the CMMC and CPCSC regimes. The design has to satisfy them and be documented well enough to demonstrate it, which is often more work than the technical design itself.

Where this work has been done

Design it for the day it matters

These systems are judged once, during an incident or an inspection, and the design decisions that matter were made years earlier by someone who either did or did not think about it.