top of page

Office Security Is Not an IT Decision.It Is a Fit-Out Decision — and Most Companies Make It Too Late.

  • Writer: UODC Architects Marketing
    UODC Architects Marketing
  • 12 minutes ago
  • 9 min read

Access control, CCTV, data room design, and visitor management are consistently treated as technology procurements. They are not. They are physical infrastructure decisions that must be made before the walls are closed. Once construction is finished, retrofitting them costs two to three times more and works half as well.


Here is how physical security typically gets handled in a corporate fit-out in Metro Manila.


The design team draws the floor plan. The contractor builds it. Three weeks before handover, the IT team asks where the CCTV cameras go. The contractor runs surface conduit along finished ceilings because there is nowhere else to put the cable. Access control panels are mounted on walls that were never designed to accommodate them. The server room has a keypad lock but no independent HVAC because nobody thought to specify one. The reception desk has no visitor log system because visitor management was not in anyone’s brief.


Every one of those problems was created at the briefing stage, not at the installation stage. And every one of them is more expensive to fix after the office opens than it would have been to design correctly from the start.


My position is straightforward: physical security is not a technology purchase that happens after the office is built. It is a design requirement that shapes the floor plan, the electrical specification, the partition layout, and the structural provisions before a single wall goes up. Every company that treats it otherwise is paying a premium to retrofit what should have been standard.

This article explains what physical security actually requires from a fit-out, where the most common gaps appear, and how to brief your design team so that security is built in rather than bolted on.






₱2M

The maximum fine under the Philippine Data Privacy Act of 2012 (RA 10173) for failure to implement adequate physical security measures to protect personal data. Criminal penalties include 2 to 7 years’ imprisonment. Inadequate physical security is not just an operational risk. It is a legal one — and your office fit-out is where compliance begins.

Section 1

Why physical security is a fit-out decision, not a technology decision


Physical security systems — access control, CCTV, intrusion detection, and data room protection — are hardware and software. But their effectiveness depends entirely on the physical environment they are installed in.


An access control system requires power, data cabling, and a door frame that can accommodate an electromagnetic lock. CCTV requires cable routes, power points at camera positions, and a location for the network video recorder. A secure server room requires dedicated power, independent precision cooling, and walls that extend to the structural slab above — not just to the suspended ceiling. None of these can be provided efficiently after the fit-out is complete.

The most expensive security upgrades I have seen in Metro Manila offices were not caused by new threats or changing requirements. They were caused by a fit-out that was completed without a security brief, and a security team that arrived six months later to find walls they could not cable through, ceilings they could not access, and rooms that were never designed to be secure. The retrofit cost more than the original fit-out of those areas would have.

The solution is not complicated. It requires one thing: the security brief must be written and handed to the design team before the floor plan is finalised. Not after. Before.


Section 2

The five physical security zones every corporate office needs to plan for

Not every office has the same security requirements. But every office has areas that need different levels of protection — and the fit-out must be designed to support each one. Here is how to think about the zones and what each one demands from the construction.


PUBLIC RECEPTION AND VISITOR ZONE

Who needs this:  All companies. This is the first physical security boundary of your office.

Fit-out must include:  Visitor management station with power and data for a reception system. Clear sightlines from reception desk to all entry points. Controlled access door between reception and the office proper: this door must be specified at design stage with the correct frame, power provision, and access control rough-in. CCTV coverage of the entry and the waiting area.

Most common mistake:  The controlled door is ordered as a standard door and the access control is added later. The frame cannot accommodate the lock. The door is replaced at three times the original cost.

GENERAL STAFF AND OPEN-PLAN WORK AREA

Who needs this:  All companies. This zone covers the majority of the floor area.

Fit-out must include:  Camera positions that provide coverage of main walkways and exit routes, with cable routes planned before ceilings are closed. Sufficient power points at CCTV locations. Perimeter alarm contacts on all windows if the floor is accessible from outside. Panic button provisions in reception, HR, and finance areas.

Most common mistake:  CCTV cable is surface-run after ceilings are completed, producing visible conduit on finished soffits. This cannot be fixed without opening the ceiling.


CONFIDENTIAL AND RESTRICTED AREAS

Who needs this:  Legal, HR, finance, C-suite, compliance, and any team handling sensitive personal data.

Fit-out must include:  Solid-core doors with acoustic ratings — not standard hollow-core commercial doors. Access control readers with power and data cabling roughed in before wall finishes. No shared wall penetrations with adjacent unrestricted areas. Walls that extend to the structural slab above — not just to the suspended ceiling — to prevent access over the partition.

Most common mistake:  Partitions are built to ceiling tile height. Anyone who lifts a ceiling tile in the adjacent space has unrestricted access to the restricted area above partition height. This is a physical security failure built into the construction.

SERVER ROOM AND IT INFRASTRUCTURE ROOM

Who needs this:  Every company with on-premise IT infrastructure, servers, or network equipment.

Fit-out must include:  Independent power supply with UPS protection. Precision cooling unit independent of the building HVAC — the room must be cooled when the rest of the building is not. Access control with audit trail capability: the system must log who entered and when, not just allow entry. Raised access floor for cable management. Fire suppression appropriate for electronic equipment — not a standard sprinkler head. Walls and door rated for the fire compartmentation required by the building code.

Most common mistake:  A keypad lock is specified instead of an access control system with audit logging. The company cannot demonstrate who accessed the server room during a data breach investigation. This is a compliance failure, not just a security failure.

MEETING ROOMS USED FOR SENSITIVE CLIENT OR COMMERCIAL DISCUSSIONS

Who needs this:  Professional services, legal, financial advisory, healthcare, and any client-facing company handling confidential information in meetings.

Fit-out must include:  Acoustic partition performance of at least Rw 45–50 dB — conversations should not be audible in adjacent spaces. No shared HVAC ducts with adjacent rooms without acoustic lining — sound travels through ductwork. Solid-core doors with door seals. No windows visible from public corridors without opaque film or blinds.

Most common mistake:  Standard drywall partitions are specified for client rooms without acoustic performance requirements. Confidential conversations are audible in the corridor and in adjacent workstations. This is a client relationship risk as much as a security risk.



Section 3

The four mistakes that create the most expensive security retrofits


These are not edge cases. They happen on the majority of Metro Manila corporate fit-outs where security was not part of the design brief.


1    Ceilings closed before CCTV cable routes are finalised

Once the suspended ceiling is complete, running cable to camera positions requires opening sections of the finished ceiling, routing conduit through inaccessible voids, and reinstating the finish. The cost of one camera position retrofitted into a finished ceiling can exceed the cost of cabling for ten positions during construction. The fix: camera positions and cable routes must be agreed and roughed-in before the ceiling grid is installed. This requires the security consultant and the fit-out designer to be in the same room at the same time, at the right stage of design.


  2    Access control doors specified without correct frame and power provisions

An access control door is not a standard door with a reader attached. It requires a door frame rated for the lock mechanism being used, a power supply routed to the frame, a data connection to the access control panel, and in some cases a door closer and a request-to-exit sensor. All of these must be specified before the door is ordered and the wall is built. Retrofitting power to a door frame in a finished wall means opening the wall, chasing conduit, and reinstating the finish. The cost is four to six times the original provision cost.


  3    Server room without independent cooling

The most dangerous and most common server room failure in Philippine offices is cooling that depends on the building’s central HVAC. When the building HVAC shuts down at 6pm on a Friday, the server room temperature rises through the weekend. By Monday morning, equipment has failed or shut down automatically. A precision cooling unit for the server room costs ₱150,000 to ₱400,000 depending on size and specification. The cost of server failure, data loss, and business interruption is orders of magnitude higher. Specify the precision cooling unit in the MEP brief. Do not share the server room with the general HVAC zone.


  4    No physical separation between public and staff areas

The most fundamental physical security control in any office is a controlled boundary between the public-facing reception and the staff working area. In too many Metro Manila fit-outs, this boundary is either absent or is a glass door with a keypad that was added after construction because nobody thought to specify it in the brief. A controlled entry point requires architectural planning: the door position affects sightlines from reception, the door type affects the access control specification, and the wall configuration affects how cleanly the system works. Plan it at the brief stage or explain later why a visitor walked unchallenged into your finance team’s area.


Section 4

What a security brief looks like and when to write it


A security brief is a one to two page document written by your security or IT team and handed to your design-build team before the floor plan is finalised. It does not need to specify brands or systems. It needs to specify requirements.


✓  Define your security zones.  Which areas are public, which are staff-only, and which are restricted? Mark them on a sketch of the floor if possible. This tells the designer where controlled doors, acoustic partitions, and elevated wall specifications are needed.


✓  State your CCTV requirements.  How many camera positions do you need and where? What areas must be covered? Where will the network video recorder be housed? This allows the designer to plan cable routes before the ceiling is specified.


✓  Specify your access control requirements.  Which doors need card readers, keypads, or biometric readers? Do you need an audit log of entries? How many concurrent access levels do you need to manage? This tells the electrical engineer what power provisions to include at each controlled door.


✓  Describe your server room requirements.  How large is the IT infrastructure? What is the heat load from the equipment? Does the room need independent cooling, raised flooring, and fire suppression beyond the standard specification? This tells the MEP engineer what to design before the walls are built.


✓  Name the compliance standard you are working to.  If your company is subject to the Data Privacy Act (RA 10173), ISO 27001, or a client-imposed security standard, name it in the brief. Your design team needs to know what the physical environment is required to support before they can design it correctly.

THE TIMING IS EVERYTHING

The security brief must be in the hands of the design team before the floor plan is approved. Not before construction. Before the floor plan. A floor plan that is approved without a security brief has already locked in decisions about door positions, partition heights, room configurations, and ceiling voids that will be expensive to undo. The brief takes a few hours to write. The retrofit costs months and millions.

Section 5

A direct note on the Data Privacy Act


Republic Act 10173 — the Data Privacy Act of 2012 — requires every organisation that processes personal data to implement organisational, physical, and technical security measures appropriate to the nature of the data and the risks involved.


Physical security measures under the DPA include: controlled access to areas where personal data is processed or stored, CCTV in relevant areas, secure storage for physical records, and policies governing who can access data processing areas.

Most companies in the Philippines have a Data Protection Officer. Very few of them were consulted during the office fit-out brief. The result is a compliance posture that looks complete on paper — policies, DPO appointment, privacy notices — and has a physical environment that contradicts it entirely: open access to HR records, no controlled boundary around the server room, and a reception area where visitors can see staff computer screens from the waiting chairs. Compliance is not just a document exercise. It is a physical design exercise. And it starts at the fit-out brief.

The penalty for inadequate physical security measures under RA 10173 runs from ₱500,000 to ₱2,000,000 and includes criminal liability. That is not a fine that a policy document will protect you from if the physical environment of your office demonstrably failed to protect personal data. The NPC will ask what physical measures were in place. Your fit-out is part of the answer.


If the National Privacy Commission walked into your office today and asked to see your physical security measures for protecting personal data — would your fit-out pass that inspection, or would the gaps be visible before they reached the server room?


TALK TO UODC ARCHITECTS

We integrate physical security requirements into the fit-out brief from day one — access control, CCTV routing, secure room design, and DPA-compliant physical measures built into the design, not added after construction.

Book a Free Consultation → www.uodc-architects.com/book-an-appointment


 
 
 

Recent Posts

See All

Comments


bottom of page