Skip to main content
Corporate Due Diligence

Security and Operational Resilience

Building security and operational resilience protect people, assets and operations. Understanding what to evaluate helps organisations ensure their buildings support safe and reliable operations.

International office , factory , data-centre , hospital Operation
Good Practice Security Manager, FM Team Pending

What Building Security Means

Building security encompasses the physical measures, technology, procedures, and personnel that protect a building's occupants, assets, and operations from unauthorised access, theft, vandalism, and hostile acts. For commercial buildings — especially those housing MNCs or financial institutions — security is not just about guards and CCTV; it is a layered system designed around deter, detect, delay, and respond.

Security Layers (Defence in Depth)

LayerComponentsPurpose
1. PerimeterBoundary wall/fence, vehicle barriers, lighting, CCTVDeter and detect at property boundary
2. Building exteriorEntry control, reception, visitor management, facade hardeningControl who enters the building
3. Internal zonesAccess control (card/biometric), floor segmentation, secure areasRestrict access to authorised zones
4. High-security areasServer rooms, cash areas, executive floors — enhanced controlsProtect highest-value assets
5. ResponseGuard force, alarm response, police liaison, incident proceduresRespond to detected threats

Key Security Metrics

ParameterGood PracticeRed Flag
CCTV coverageAll entry/exit points, parking, perimeter, lobby, lift lobbies, critical areasCameras non-functional, gaps in coverage, no recording
CCTV retention≥ 30 days recording storage< 7 days or no recording
Access controlCard/biometric at all entry points, audit trailNo access control, shared access cards, no audit log
Visitor managementID verification, host notification, badge, escort in secure areasUncontrolled visitor access
Guard forceTrained, licensed, supervised, with defined patrol routesUntrained, sleeping, no patrol evidence
Lighting≥ 50 lux at entry points, ≥ 20 lux in parking areas (IESNA)Dark areas around perimeter or parking
Incident response timeGuard response ≤ 3 minutes to any alarmNo defined response protocol
Security audit frequencyAnnual comprehensive security assessmentNever audited

MNC Security Requirements (Typical)

  • Access control — electronic access on all entry points with audit trail. No shared cards. Card deactivation within 24 hours of termination.
  • CCTV — HD cameras at all entry/exit, lobby, parking, critical areas. 30-day retention minimum. Remote monitoring capability.
  • Vehicle screening — vehicle barriers (bollards or boom gates) preventing unauthorized vehicle approach. Under-vehicle inspection for high-threat locations.
  • Mail/delivery screening — dedicated loading bay, X-ray for mail/parcels in high-threat environments.
  • Blast protection — standoff distance ≥ 25 m from uncontrolled vehicle access for high-risk tenants (banks, embassies).
  • Security Operations Centre (SOC) — 24/7 monitoring of CCTV, access control, alarms for large facilities.

Bangladesh Security Context

  • Threat landscape: Petty theft, burglary, and unauthorised access are the primary commercial building security concerns. Political violence and terrorism are lower-probability but have occurred (Holey Artisan Bakery attack, 2016).
  • Guard force: Security guards are widely used but often poorly trained and underpaid. Engage licensed security companies (ANSAR/VDP affiliated or private licensed firms). Insist on training records.
  • MNC requirements: Banks, embassies, and MNC headquarters in Dhaka typically employ professional security firms, electronic access control, CCTV with remote monitoring, and vehicle barriers.
  • Residential-commercial mix: Many Dhaka commercial buildings are in residential areas with limited perimeter security. This creates specific challenges for access control and vehicle management.

Operational Resilience

Operational resilience goes beyond security to encompass the building's ability to maintain operations through disruptions:

  • Redundancy — dual power feeds, dual ISPs, backup cooling for server rooms, redundant fire pumps.
  • Monitoring — BMS, security systems, fire systems all monitored 24/7 with alarm escalation procedures.
  • Maintenance — PPM completion ≥ 95% ensures systems don't fail when needed most.
  • Supplier resilience — critical service contracts (generator maintenance, lift maintenance, security) with SLAs and backup providers.
  • Documentation — SOPs for all critical building operations, emergency procedures, escalation contacts.

References & Sources

  1. ASIS International — Physical Security Standards
  2. CPNI — Centre for the Protection of National Infrastructure
  3. ISO 22301 — Business Continuity
  4. IESNA — Illuminating Engineering Society (Lighting Standards)
  5. ISO 31000 — Risk Management

Insights & Guidance

  • Building security follows defence in depth: perimeter → building exterior → internal zones → high-security areas → response.
  • CCTV must cover all entry/exit points with ≥ 30 days recording retention.
  • Electronic access control with audit trail on all entry points — no shared cards.
  • Guard response time ≤ 3 minutes to any alarm.
  • Operational resilience = redundancy + monitoring + maintenance + supplier resilience + documentation.
  • Bangladesh: engage licensed security companies; insist on training records and supervision.

Security incidents disrupt operations, damage assets, harm people, and destroy organisational reputation. For MNCs and financial institutions in Bangladesh, security is a regulatory requirement (central bank guidelines for banks) and a corporate governance obligation. The Holey Artisan Bakery attack (2016) demonstrated that security threats in Bangladesh can be severe and unpredictable — buildings must be prepared.

  • Unauthorised access — intruders access building due to uncontrolled entry, leading to theft, data breach, or harm.
  • CCTV failure — incident occurs but no footage available for investigation.
  • Guard failure — untrained guard fails to detect threat or respond appropriately.
  • Access control bypass — tailgating, shared cards, or broken readers allow unauthorised entry.
  • Insider threat — employee or contractor misuses access. No audit trail to detect or investigate.
  • Vehicle attack — no barriers prevent vehicle approach to building entrance.

  • Security risk assessment — site-specific, reviewed annually
  • Security operating procedures — post orders, patrol schedules, incident response
  • Guard training records — initial and refresher training
  • CCTV system specification — camera locations, recording capacity, retention policy
  • Access control system report — active cards, access levels, recent audit
  • Incident log — all security incidents recorded with response and follow-up
  • Annual security audit report

  • Perimeter — walls, fencing, gates, lighting, vehicle barriers.
  • Main entrance — reception, visitor registration, access control, guard presence.
  • CCTV cameras — present, positioned correctly, indicator lights on.
  • Access control — readers at all entry points, anti-tailgate measures.
  • Guard alertness — observing, patrolling, or sleeping/distracted?
  • Loading area — controlled access, separate from main entry?
  • Lighting — adequate at entry points, parking, and perimeter?

  • Who provides the security service? Are they licensed?
  • What training do guards receive? How often is it refreshed?
  • How many CCTV cameras are installed? What is the recording retention period?
  • Is there electronic access control? Is there an audit trail?
  • What is the guard response time to an alarm? Has it been tested?
  • Has a security risk assessment been conducted for this building?
  • How are visitors managed? Is there an escort policy for restricted areas?
  • Are there vehicle barriers at the building perimeter?

  • Security risk assessment — qualified security consultant (ASIS CPP or equivalent).
  • CCTV and access control design — security systems integrator.
  • Threat assessment — for high-risk tenants (banks, embassies), specialist threat and vulnerability assessment.
  • Guard force evaluation — independent audit of security provider performance.
Was this page helpful?
|

Related Articles

Vendor and Contractor Due Diligence for Buildings

How to evaluate, select, and manage building service contractors and vendors, covering prequalification, contract structures, performance monitoring, and compliance requirements.

Service Charge Analysis for Commercial Buildings

How to evaluate, benchmark, and negotiate service charges in commercial leases, covering what should be included, common disputes, and best practice transparency standards.

Space Management and Utilisation: Measuring How Buildings Are Actually Used

How to measure and manage space utilisation in commercial buildings including measurement methods, occupancy sensors, utilisation benchmarks, cost per occupied seat, and how space data drives real estate decisions.

Disclaimer: This article provides educational information and preliminary guidance. It does not constitute professional engineering advice, structural certification, fire-safety approval, legal advice or statutory approval. Building conditions vary by jurisdiction, design, construction and operation. Qualified professionals and relevant authorities should be engaged where required.

Stay informed

Building safety, compliance and operational readiness updates — direct to your inbox.

We respect your privacy. Unsubscribe at any time.