What Building Security Means
Building security encompasses the physical measures, technology, procedures, and personnel that protect a building's occupants, assets, and operations from unauthorised access, theft, vandalism, and hostile acts. For commercial buildings — especially those housing MNCs or financial institutions — security is not just about guards and CCTV; it is a layered system designed around deter, detect, delay, and respond.
Security Layers (Defence in Depth)
| Layer | Components | Purpose |
|---|---|---|
| 1. Perimeter | Boundary wall/fence, vehicle barriers, lighting, CCTV | Deter and detect at property boundary |
| 2. Building exterior | Entry control, reception, visitor management, facade hardening | Control who enters the building |
| 3. Internal zones | Access control (card/biometric), floor segmentation, secure areas | Restrict access to authorised zones |
| 4. High-security areas | Server rooms, cash areas, executive floors — enhanced controls | Protect highest-value assets |
| 5. Response | Guard force, alarm response, police liaison, incident procedures | Respond to detected threats |
Key Security Metrics
| Parameter | Good Practice | Red Flag |
|---|---|---|
| CCTV coverage | All entry/exit points, parking, perimeter, lobby, lift lobbies, critical areas | Cameras non-functional, gaps in coverage, no recording |
| CCTV retention | ≥ 30 days recording storage | < 7 days or no recording |
| Access control | Card/biometric at all entry points, audit trail | No access control, shared access cards, no audit log |
| Visitor management | ID verification, host notification, badge, escort in secure areas | Uncontrolled visitor access |
| Guard force | Trained, licensed, supervised, with defined patrol routes | Untrained, sleeping, no patrol evidence |
| Lighting | ≥ 50 lux at entry points, ≥ 20 lux in parking areas (IESNA) | Dark areas around perimeter or parking |
| Incident response time | Guard response ≤ 3 minutes to any alarm | No defined response protocol |
| Security audit frequency | Annual comprehensive security assessment | Never audited |
MNC Security Requirements (Typical)
- Access control — electronic access on all entry points with audit trail. No shared cards. Card deactivation within 24 hours of termination.
- CCTV — HD cameras at all entry/exit, lobby, parking, critical areas. 30-day retention minimum. Remote monitoring capability.
- Vehicle screening — vehicle barriers (bollards or boom gates) preventing unauthorized vehicle approach. Under-vehicle inspection for high-threat locations.
- Mail/delivery screening — dedicated loading bay, X-ray for mail/parcels in high-threat environments.
- Blast protection — standoff distance ≥ 25 m from uncontrolled vehicle access for high-risk tenants (banks, embassies).
- Security Operations Centre (SOC) — 24/7 monitoring of CCTV, access control, alarms for large facilities.
Bangladesh Security Context
- Threat landscape: Petty theft, burglary, and unauthorised access are the primary commercial building security concerns. Political violence and terrorism are lower-probability but have occurred (Holey Artisan Bakery attack, 2016).
- Guard force: Security guards are widely used but often poorly trained and underpaid. Engage licensed security companies (ANSAR/VDP affiliated or private licensed firms). Insist on training records.
- MNC requirements: Banks, embassies, and MNC headquarters in Dhaka typically employ professional security firms, electronic access control, CCTV with remote monitoring, and vehicle barriers.
- Residential-commercial mix: Many Dhaka commercial buildings are in residential areas with limited perimeter security. This creates specific challenges for access control and vehicle management.
Operational Resilience
Operational resilience goes beyond security to encompass the building's ability to maintain operations through disruptions:
- Redundancy — dual power feeds, dual ISPs, backup cooling for server rooms, redundant fire pumps.
- Monitoring — BMS, security systems, fire systems all monitored 24/7 with alarm escalation procedures.
- Maintenance — PPM completion ≥ 95% ensures systems don't fail when needed most.
- Supplier resilience — critical service contracts (generator maintenance, lift maintenance, security) with SLAs and backup providers.
- Documentation — SOPs for all critical building operations, emergency procedures, escalation contacts.
References & Sources
Insights & Guidance
- Building security follows defence in depth: perimeter → building exterior → internal zones → high-security areas → response.
- CCTV must cover all entry/exit points with ≥ 30 days recording retention.
- Electronic access control with audit trail on all entry points — no shared cards.
- Guard response time ≤ 3 minutes to any alarm.
- Operational resilience = redundancy + monitoring + maintenance + supplier resilience + documentation.
- Bangladesh: engage licensed security companies; insist on training records and supervision.
Security incidents disrupt operations, damage assets, harm people, and destroy organisational reputation. For MNCs and financial institutions in Bangladesh, security is a regulatory requirement (central bank guidelines for banks) and a corporate governance obligation. The Holey Artisan Bakery attack (2016) demonstrated that security threats in Bangladesh can be severe and unpredictable — buildings must be prepared.
- Unauthorised access — intruders access building due to uncontrolled entry, leading to theft, data breach, or harm.
- CCTV failure — incident occurs but no footage available for investigation.
- Guard failure — untrained guard fails to detect threat or respond appropriately.
- Access control bypass — tailgating, shared cards, or broken readers allow unauthorised entry.
- Insider threat — employee or contractor misuses access. No audit trail to detect or investigate.
- Vehicle attack — no barriers prevent vehicle approach to building entrance.
- Security risk assessment — site-specific, reviewed annually
- Security operating procedures — post orders, patrol schedules, incident response
- Guard training records — initial and refresher training
- CCTV system specification — camera locations, recording capacity, retention policy
- Access control system report — active cards, access levels, recent audit
- Incident log — all security incidents recorded with response and follow-up
- Annual security audit report
- Perimeter — walls, fencing, gates, lighting, vehicle barriers.
- Main entrance — reception, visitor registration, access control, guard presence.
- CCTV cameras — present, positioned correctly, indicator lights on.
- Access control — readers at all entry points, anti-tailgate measures.
- Guard alertness — observing, patrolling, or sleeping/distracted?
- Loading area — controlled access, separate from main entry?
- Lighting — adequate at entry points, parking, and perimeter?
- Who provides the security service? Are they licensed?
- What training do guards receive? How often is it refreshed?
- How many CCTV cameras are installed? What is the recording retention period?
- Is there electronic access control? Is there an audit trail?
- What is the guard response time to an alarm? Has it been tested?
- Has a security risk assessment been conducted for this building?
- How are visitors managed? Is there an escort policy for restricted areas?
- Are there vehicle barriers at the building perimeter?
- Security risk assessment — qualified security consultant (ASIS CPP or equivalent).
- CCTV and access control design — security systems integrator.
- Threat assessment — for high-risk tenants (banks, embassies), specialist threat and vulnerability assessment.
- Guard force evaluation — independent audit of security provider performance.