The Camera Was Offline for Three Weeks and Nobody Noticed

Physical security in most organisations sits quietly in the operations budget, usually owned by a Facilities team stretched across a dozen other priorities. It looks comprehensive on a floor plan. It functions reliably most days. And it fails in ways that nobody detects until something actually goes wrong.
The problem isn’t the technology. It’s that physical security isn’t one system. It’s an ecosystem of disconnected vendors, each responsible for their piece, none responsible for the whole.
Your CCTV vendor sells cameras. Your access control vendor sells doors and credentials. Your guarding firm sells headcount. Your video analytics platform sells alerts. Each one solves a problem they’ve defined in terms that favour their product. What falls through the cracks is the operational framework that makes them work together.
A CCTV camera goes offline. Who notices? The guard? The FM team? The vendor? The analytics platform, if it’s even configured to raise an alert for a camera outage? And while it’s down, what happens to the area it was covering? Is a guard redeployed to compensate? Is a temporary camera installed? Or does an unmonitored blind spot simply exist until someone gets around to raising a purchase order for the repair?
In most organisations, there aren’t clear answers to those questions. That’s why cameras can go offline for weeks without detection. Why access control doesn’t talk to visitor management. Why a security incident at 3 AM sits unreviewed until the next business day.
The gap isn’t between what you have and what you need. It’s between what you think is covered and what’s actually being monitored.
After all the investment in hardware and analytics, the guard at the front desk is doing most of the real work. The person who decides whether to challenge someone who tailgated through a door. Who escalates an alert or dismisses it. Who sets the tone for whether your security protocols are treated as real or performative. In most organisations, that person is employed by a contract firm primarily obligated to fill the shift, not to understand your specific risk profile or train to your environment’s standards.
This isn’t a criticism of security personnel. It’s a structural observation about where most organisations place the final layer of their security investment and how little intentional support that layer receives.
When companies review physical security, the standard approach is to invite vendors in. The CCTV firm presents. The access control provider brings case studies. The guarding company quotes headcount. Each one is positioning their solution to their definition of your problem. What most organisations need first is someone who isn’t selling anything.
A vendor-agnostic assessment asks different questions. Not “which system do you want?” but “what are you actually trying to protect, and what does failure look like?” Not “how many cameras should we install?” but “who will monitor them, when, and what are they trained to do?” Not “which vendor should we choose?” but “what gaps exist in your current framework, and which gaps matter most given your actual risk profile?”
That conversation, held before any vendor is briefed, changes everything that follows. Your technology choices solve your problem instead of the vendor’s sales target. Your guarding contract includes the right training obligations. The pieces of your security ecosystem are selected to work together rather than simply coexist.
Physical security is one of the few operational domains where what you think you have and what you actually have can remain radically different for years. The question worth asking isn’t whether your security systems are state-of-the-art. It’s whether they’re actually working the way you believe they are, and whether your blind spots are somewhere nobody’s looking.