A CCTV installer can tell you where a camera will physically fit. What they usually can’t tell you is whether that’s actually the position the building needs covered, or just the position that was easiest to run cable to. Security by design starts from the opposite direction: work out what the site actually needs to see, control, and protect, then hand that brief to the people who do the drawings.
What Security by Design Actually Means
Security by design is the practice of assessing a development’s security needs early, at concept or masterplan stage, and prescribing where coverage, access control, and lighting need to sit, based on how the building or space will actually be used.
It’s worth being precise about what that involves, because it’s easy to assume it means drawing cable runs or specifying equipment. It doesn’t. A security by design assessment identifies entry points, sightlines, vehicle access, and after-hours risk, and produces a clear brief: what needs coverage, where, and why. What it hands over is a set of requirements, not a set of drawings.
That distinction is deliberate. An electrical consultant or security systems designer is the right party to turn a brief into cable schedules, equipment specifications, and installable drawings. Security by design sits before that step, making sure the brief they’re working from is actually based on risk, not on whatever’s fastest to specify.
What the Assessment Looks Like in Practice
A security by design review works through a site or a set of plans systematically, looking at the same handful of things every time.
Entry points. Every point where someone can enter the building or site, pedestrian and vehicle, formal and informal, gets assessed for what level of access control and surveillance it actually warrants. Not every entry needs the same treatment, a staff-only service door carries a different risk profile to a public lobby.
Lobby and reception coverage. The first point of contact for a building is also usually the highest-value point for surveillance and access control, since it’s where legitimate visitors, deliveries, and anyone with less legitimate intent all pass through the same space.
Vehicle access and carparks. Vehicle entry points, boom gates, and carpark areas carry their own risk profile, including, for higher-risk or crowded sites, whether hostile vehicle mitigation needs to be considered at the design stage rather than retrofitted later.
Service corridors and loading docks. Frequently overlooked in early design because they’re not public-facing, these are consistently where access control gaps end up being found once a building is occupied.
After-hours risk zones. How the building’s risk profile changes when staffing drops and public activity stops. A space that feels secure at midday with people everywhere can be a very different proposition at 11pm.
The output of that review is a written brief: what needs CCTV coverage and why, where access control needs to sit and at what level, where lighting needs to support surveillance, and which of these are genuinely a priority versus nice-to-have. That brief becomes the input for whoever is doing the actual systems design and documentation, not a replacement for their work.
What This Deliberately Isn’t
To be clear about the boundary: this isn’t electrical design, and it isn’t systems documentation. No cable schedules, no equipment model numbers, no installable drawings. That’s a distinct discipline, done by an electrical consultant or a security systems designer, and a security by design brief is written to be their input, not a competing document that duplicates or second-guesses their work.
This matters for two reasons. First, it means the advice stays independent, there’s no incentive to specify a particular system or brand because no system is being specified at all, only the risk-based requirement. Second, it means bringing a security by design review onto a project doesn’t threaten anyone already on the team. An architect keeps designing the building. An electrical consultant keeps producing the drawings. The security by design brief just makes sure both of them are working from a requirement that’s actually grounded in risk.
Why This Needs to Happen Early
Under WA’s Safer Places by Design CPTED framework, the second step in the process is informing the brief, establishing the security requirement before design development begins, not after. That sequencing exists for a reason. Once a floor plan is locked, moving a lobby sightline or repositioning a vehicle entry point becomes a redesign, not a footnote. Getting the brief right at concept stage is the difference between a security requirement that shapes the design and one that gets bolted on afterward at higher cost and lower effectiveness.
This is also where CPTED principles and a security by design brief overlap directly. Access control, surveillance, and territorial definition are core CPTED principles, and a security by design review is often the mechanism that turns those principles into a specific, site-based requirement rather than a general design philosophy.
How It Fits Into a Project Team
A security by design review sits alongside the architect and the electrical or security systems designer, not in place of either. In practice, that usually looks like an early-stage site or plan review, a written brief delivered back to the project team, and availability to answer questions as design development progresses and the brief needs to be applied to an actual layout.
This is deliberately easy to bring onto a project that already has its design team assembled. It doesn’t require displacing an existing electrical consultant or security systems designer, and it doesn’t compete with the DA-stage CPTED reporting that a project might separately need for planning approval, the two serve different purposes at different points in a project.
Who This Suits
Security by design reviews suit developers, architects, and project managers working on new builds at concept or masterplan stage, particularly multi-residential, mixed-use, civic, and commercial developments where the cost of getting entry points, lobby coverage, and vehicle access wrong is measured in both budget and outcome. It’s equally relevant for councils and government agencies delivering new public infrastructure, where a defensible, risk-based brief supports both good design and governance requirements.
Why Choose Smartsec Security Solutions
Smartsec Security Solutions is a Perth-based, independent security consultancy. We don’t design, sell, or install security systems, so a security by design brief reflects what the site actually needs, not what’s easiest to specify or supply.
Our assessments are grounded in ISO 31000:2018 risk methodology and WA’s Safer Places by Design CPTED framework, delivered by an SRMCP-credentialled, WA-licensed Security Risk Consultant with nearly two decades of experience across public and private sector projects in WA.
Let’s Talk
If you’re at concept or masterplan stage on a new development and want the security brief right before the drawings are locked in, contact Smartsec Security Solutions to arrange a scoping conversation.


