Projects

European diplomatic mission — multi-system security

Complete overhaul of access control, video surveillance and backup power for a chancery in service.

Reference
KP-2022-014
Sector
International organisations
Country
Mali
Year
2022
Duration
9 months
Review of execution drawings on a secure building site — editorial context image, unrelated to the site of this project.

Two domains, a single crossing point, schematic

01Security domain
A network of its own for the security equipment. It shares neither addressing, nor switches, nor rights with the rest.
02Single gateway
The only crossing point between the two domains, and a logged one. A second undeclared crossing voids the whole separation.
03Office domain
Workstations and everyday services. It sees what the gateway allows, and nothing beyond it.
04Recording A
The first recording rack. It sits in a room separate from the second, not in the same cabinet.
05Recording B
A copy held away from the first. Two racks in one room protect against failure only, never against an incident.
06Generator set
Replacement source for the whole site, including uses that have nothing to do with security.
07Automatic transfer
Automatic switching. Without it, the replacement source depends on someone being on site.
08UPS on security
A reserve placed on the security loads alone, sized on the generator start-up window.
Schematic of the separation described above. No room, no drawing and no real equipment appears on it.A typical sizing figure, not measured on an installation. The autonomy shown is what a generator start-up calls for.
  1. 01

    The context

    Three systems installed ten years apart by three different suppliers coexisted without common supervision. Video recordings were kept on an isolated workstation, access rights had not been reviewed in four years, and a network outage was enough to interrupt the logging of movements. The site could not stop during the works.

  2. 02

    The mission

    Bring the three systems under a single architecture, with common supervision, a rebuilt rights policy and backup power sized on the security loads — with no interruption to the chancery's activity.

  3. 03

    The architecture

    Two separate network domains, one for security and one for office systems, joined by a single logged gateway. Recording duplicated across two racks in separate locations. UPS on the security loads, a generator for the whole site, automatic source transfer.

  4. 04

    Delivery

    Four phases, each reversible until its partial acceptance was pronounced. Cutovers were carried out outside opening hours, with a temporary arrangement kept in parallel until each phase was validated. Access rights were rebuilt with the site's security manager, position by position.

  5. 05

    Results

    One detection and response chain, one on-call rota, one point of contact. Access rights are reviewed under a quarterly procedure agreed with the client, and backup power is load-tested monthly.

  6. 06

    What we take from it

    Taking over a heterogeneous estate costs less than adding to it, provided the decision comes before the first replacement device is bought. After that point, each new device adds one more interface to handle.

Results

3
Systems merged
0
Service interruptions
9
Months on site

Technologies

  • Milestone
  • ZKTeco
  • OPNsense
  • Zabbix
  • Socomec

Why some clients are not named here

We design security systems and information systems for organisations whose public exposure is an operational risk. The discretion we apply to their projects is the discretion we will apply to yours. Identities, architectures and contractual documents are shared with an identified organisation as part of a pre-qualification.

Request pre-qualification

Consultations · Pre-qualifications · Partnerships

A comparable requirement?

Site constraints differ from one project to the next, but the questions to settle recur. An initial technical discussion establishes whether the comparison holds.