Skip to content
SCHUHEN Consulting SCHUHEN Consulting
Security concepts

Building Security Concepts: Five Points Where They Usually Fail

Five weak points we keep finding when reviewing existing security concepts: threats lifted from a template, protection objectives that cannot be verified, measures that ignore how the building runs, missing reporting chains, and concepts never updated.

Security concepts · · Christian Schuhen

Ask around your organisation where the security concept is kept. In most cases exactly one person knows, and that person is currently on leave. The document exists, it cost money once, and nobody has opened it since the authority signed it off.

That is not a reproach. Security concepts are almost always written under pressure, because a licensing authority has asked, because an insurer has made it a condition, because a tender requires it, or because something has happened and suddenly everyone is looking. Under those circumstances you get a document that exists. Whether it holds only becomes apparent when something goes wrong.

When we review existing concepts, we keep finding the same five weak points. All of them are well known, and none of them costs much to avoid. You just have to look in time.

First: what we are talking about here

The term is imprecise, and that causes recurring misunderstandings. In this article, a security concept means a building-specific concept for protecting people, buildings, operating assets and processes against physical threats: assault, burglary, vandalism, sabotage, unauthorised access.

It does not mean the event security concept that governs crowd flows, stewarding and evacuation, nor fire safety, which follows its own body of rules, nor information security. All three form interfaces, and proper coordination with them is part of the job. What they cannot do is replace the building concept, and the same holds in reverse.

When a security concept is required

There is no general statutory duty in Germany to hold a security concept for every building. The individual triggers are all the more specific for it.

Assembly venues. Section 43 of the model regulation on assembly venues (Muster-Versammlungsstättenverordnung) requires a security concept where the nature of the event calls for one. Above 5,000 visitor places it is mandatory, and it must be agreed with the competent security and public order authorities. The federal states have largely adopted this; for the detail it pays to check the version in force in the relevant state.

Occupational safety. Section 5 of the Occupational Safety and Health Act (Arbeitsschutzgesetz) obliges every employer to carry out a risk assessment. A document titled "security concept" does not follow from this as a matter of law. In practical terms, however, wherever staff work alone, deal with a public prone to conflict, or work outside core hours, it comes down to the same questions: what threat exists, what state is to be achieved, what measure gets you there.

Critical infrastructure. The KRITIS umbrella act (KRITIS-Dachgesetz) has been in force since 17 March 2026. Unlike the NIS2 implementation act, which covers the digital side, it addresses the physical resilience of critical installations: protection against sabotage, natural events and infrastructure failure. Whether an organisation falls within its scope depends on sector, installation classification, thresholds and supplementary regulations, and has to be assessed case by case. For those who are covered, this is a trigger that is not open to negotiation.

Insurers and clients. Both require concepts contractually, without any statute behind it. In tenders for security services, a concept is now more often part of the requirements than not.

Whether an obligation applies in your case is a legal assessment, and we do not make it. What we can assess is whether the concept you have serves its purpose.

1. The threats come from a template, not from the building

This is the most common failure and the most consequential one. A concept begins with a risk analysis, and if that analysis is lifted from a specimen document, everything built on it stands on sand.

You can spot it in the wording. "There is a general risk of burglary." "Vandalism cannot be ruled out." Sentences that apply to every building in Germany and therefore say nothing about any of them. Where someone has actually walked the site, it reads differently: which entrance is unobserved at night, which area is overlooked from the neighbouring property, where deliveries arrive in a way that means a door is regularly wedged open.

A second problem comes on top, and it is discussed less often. Two specialists will rate the same situation differently. If one classifies a burglary risk as "medium" and the other as "high" without both sharing a view of what those words mean, the assessment is not reproducible.

The only remedy is a scale that is written out for every level. Each threat factor needs a sentence describing what level 2 means for that specific factor and what level 3 means. This does not eliminate the spread, but it shrinks it considerably, and above all it becomes possible later to trace what a figure was meant to signify. That is why we work with SCVeridit, our own survey tool, in which a justification is also recorded for every value. It appears in the report alongside the rating, so the reader can follow the reasoning and disagree with it.

There is one further rule that looks unremarkable on paper and matters a great deal in practice: a factor that has not been assessed does not count as "no risk". It drops out of the calculation. Anyone who honestly states that they cannot judge something does not thereby push the result artificially downwards. In templates where zeros appear everywhere because nobody looked, that is exactly what happens, and the overall picture ends up systematically too favourable.

2. The protection objectives cannot be verified

"The safety of employees is to be ensured." Words to that effect appear in many concepts, and it is the kind of sentence nobody can object to, because it asserts nothing.

A protection objective has to be worded so that in a year's time you can establish whether it was met. "In the citizens' service centre, during opening hours, it is ensured that a member of staff facing a conflict receives support within 60 seconds." That can be verified. You can test it, you can fail it, and you can talk about it.

Anyone who considers this hair-splitting underestimates the consequences. From verifiable protection objectives, measures follow almost by themselves. From vague ones, nothing follows, which is why such concepts regularly end up with a list of measures bearing no discernible relationship to the objectives above it.

3. The measures do not fit the way the building runs

An access control system that blocks deliveries will be circumvented within two weeks. An escalation route that runs through a telephone number nobody answers at night is not an escalation route. An instruction not to leave the reception desk during a conflict does not help if only one person is on duty and the toilet is at the far end of the corridor.

Measures like these arise when a concept is written at a desk. They are not technically wrong. They are simply incompatible with how the building actually operates, and operations always win.

The same applies to the technical side. Across fourteen categories, we record not whether an installation is present but whether it is effective for the particular protection objective. That reference to the objective is what matters. A camera without a monitored connection contributes nothing to immediate intervention, because nobody is watching while something happens. For subsequent investigation it may serve perfectly well. Where the concept states that it serves to avert danger, that is protection on paper only. An intruder alarm that goes unarmed out of convenience, and an access door permanently wedged open, belong in the same category: they settle the paperwork without reducing the risk they were entered against.

4. The reporting chain is missing

Almost every concept describes what is to be done. Considerably fewer describe who does it. And hardly any answers the question that comes up first in an emergency: who makes the call?

In an exercise this becomes apparent within minutes. Everyone knows the building has to be cleared, but nobody knows whether the evacuation is triggered by the control room, the caretaker or the department head, or whether the security service has authority of its own. Five people reach for the telephone and each calls someone different.

Alarm and emergency planning therefore belongs in the load-bearing part of the concept and not in an annex: reporting routes, responsibilities, deputising arrangements, the interaction with the fire and ambulance services. And it includes running the whole thing through at least once, even though experience suggests there is never a good date for it.

5. Written once, never updated

A security concept describes a building at a particular moment. Buildings change: an area is repurposed, opening hours shift, a department moves, footfall increases. After three years the concept describes a building that no longer exists in that form.

The real problem is not the inaccuracy. It is that an outdated concept is harder to spot than none at all. It is there, it looks complete, and nobody asks about the date.

What carries a concept before a supervisory authority or an insurer is, first of all, a traceable method, a defensible finding and a documented sign-off. To keep that visible over the years, we treat an update not as a correction but as a new version linked to the previous one. The old report remains readable unchanged, five years on and even after master data has long since altered, and a checksum proves that it has not been touched since it was issued. Anyone consulting the files after an incident then finds the version that applied at the time, not the one that looks better today.

What follows from this

If you have an existing concept, three places are worth a look. Does the threat section contain anything that applies only to your building? Can the protection objectives be verified? And does it say who makes the call in an emergency?

If one of those three questions goes unanswered, there is no cause for alarm. It is a good moment to open the document again, ideally before somebody else does.

© 2026 SCHUHEN Consulting GmbH. All rights reserved.