European diplomatic mission — multi-system security
Complete overhaul of access control, video surveillance and backup power for a chancery in service.
- Reference
- KP-2022-014
- Sector
- International organisations
- Country
- Mali
- Year
- 2022
- Duration
- 9 months

Two domains, a single crossing point, schematic
- 01Security domain
- A network of its own for the security equipment. It shares neither addressing, nor switches, nor rights with the rest.
- 02Single gateway
- The only crossing point between the two domains, and a logged one. A second undeclared crossing voids the whole separation.
- 03Office domain
- Workstations and everyday services. It sees what the gateway allows, and nothing beyond it.
- 04Recording A
- The first recording rack. It sits in a room separate from the second, not in the same cabinet.
- 05Recording B
- A copy held away from the first. Two racks in one room protect against failure only, never against an incident.
- 06Generator set
- Replacement source for the whole site, including uses that have nothing to do with security.
- 07Automatic transfer
- Automatic switching. Without it, the replacement source depends on someone being on site.
- 08UPS on security
- A reserve placed on the security loads alone, sized on the generator start-up window.
01
The context
Three systems installed ten years apart by three different suppliers coexisted without common supervision. Video recordings were kept on an isolated workstation, access rights had not been reviewed in four years, and a network outage was enough to interrupt the logging of movements. The site could not stop during the works.
02
The mission
Bring the three systems under a single architecture, with common supervision, a rebuilt rights policy and backup power sized on the security loads — with no interruption to the chancery's activity.
03
The architecture
Two separate network domains, one for security and one for office systems, joined by a single logged gateway. Recording duplicated across two racks in separate locations. UPS on the security loads, a generator for the whole site, automatic source transfer.
04
Delivery
Four phases, each reversible until its partial acceptance was pronounced. Cutovers were carried out outside opening hours, with a temporary arrangement kept in parallel until each phase was validated. Access rights were rebuilt with the site's security manager, position by position.
05
Results
One detection and response chain, one on-call rota, one point of contact. Access rights are reviewed under a quarterly procedure agreed with the client, and backup power is load-tested monthly.
06
What we take from it
Taking over a heterogeneous estate costs less than adding to it, provided the decision comes before the first replacement device is bought. After that point, each new device adds one more interface to handle.
Results
- 3
- Systems merged
- 0
- Service interruptions
- 9
- Months on site
Technologies
- Milestone
- ZKTeco
- OPNsense
- Zabbix
- Socomec
Solutions concerned
Why some clients are not named here
We design security systems and information systems for organisations whose public exposure is an operational risk. The discretion we apply to their projects is the discretion we will apply to yours. Identities, architectures and contractual documents are shared with an identified organisation as part of a pre-qualification.