// HIGH SECURITY DESIGN · HANS STUDY · ONTARIO, CANADA
High security design
In most buildings a door failure is an inconvenience. In some, it is the incident. Once failure has consequences beyond annoyance, almost every ordinary design assumption has to be re-examined, and most security designers have never had to do that.
I design and review security systems for environments where the stakes are real: borders, detention and custody, defence supply chain, utilities and water, courts, transit, and critical infrastructure. The work is the same disciplines as any other system, held to a standard where being mostly right is not a passing grade.
What changes at this level
- The insider is in the threat model. Designing against someone with legitimate credentials, physical access and knowledge of the system changes supervision, audit, dual control and what a single person can do alone.
- Failure modes are designed, not inherited. What the system does on power loss, network loss, controller loss and server loss is decided deliberately per subsystem rather than defaulting to whatever the product does.
- Interlocks and sequencing. Mantraps, sally ports, vehicle traps and airlocks where two openings must never be unsecured together, and the logic has to hold even when a component is faulty.
- Duress is a first-class function, not a feature enabled later. Silent alarm paths, what they trigger, who receives them, and whether the path itself can be cut.
- Anti-passback and occupancy where knowing who is inside is an operational requirement rather than a report.
- Evidence quality. Recording that will still be usable months later in a proceeding, with retention and integrity to match.
Redundancy that survives a real event
Most redundancy is designed against component failure and tested on a quiet Tuesday. High consequence environments fail during events, when several things go wrong together and somebody is under pressure.
- Power, including generator transfer behaviour and what the system does during the gap.
- Network paths that do not share a conduit, a room, or a single upstream device.
- Server and database availability sized for rebuild time, not just failover.
- Degraded modes that are defined and practised rather than discovered.
- Whether the operator can still do their job when half the system is unavailable.
Standards, authorities and the paperwork
These environments come with obligations: authorities having jurisdiction, sector standards, security clearance and screening requirements, procurement rules, and in defence supply chain work the CMMC and CPCSC regimes. The design has to satisfy them and be documented well enough to demonstrate it, which is often more work than the technical design itself.
Where this work has been done
- Border crossing, security with traffic control and message-sign infrastructure.
- International airport, multi-terminal video estate stabilised and upgraded.
- Water utility, brought off end-of-life infrastructure.
- Defence manufacturing, taken to NIST SP 800-171 readiness.
- Traffic operations, upgraded behind a live operations centre.
Design it for the day it matters
These systems are judged once, during an incident or an inspection, and the design decisions that matter were made years earlier by someone who either did or did not think about it.
Independent of every manufacturer involved. See the independence policy.