Ask most people what makes a facility secure, and they will describe cameras, fences, and guards. Ask a physical protection specialist, and they will describe a system that performs three specific functions well: detection, delay, and response — and, critically, performs them in the right order and the right timing relative to one another.

The Three Functions

Detection is the function of sensing that an adversary is attempting unauthorised access — through intrusion detection sensors, video analytics, access control anomalies, or personnel observation — and correctly assessing that detection as a real event requiring response, not a nuisance alarm to be dismissed.

Delay is the function of slowing an adversary's progress toward their objective once detected — through barriers, locks, distance, and other physical or procedural obstacles — for long enough that a response force can arrive before the adversary completes their task.

Response is the function of interrupting the adversary before they achieve their objective, whether that means a guard force, law enforcement, or another designated response capability arriving and acting in time.

Why Timing Is the Whole Game

The critical insight — and the one most often missed by facilities that simply add more cameras — is that these three functions only work as a system, not as independent investments. A facility can have excellent detection and still be insecure, if delay is too short for any response to arrive in time. It can have formidable barriers and still be insecure, if there's no detection early enough to trigger a response before the barriers are breached anyway.

The standard this gets measured against is simple to state and hard to satisfy: detection must occur, and the remaining delay after detection must exceed the response force's travel time, with margin. If that inequality doesn't hold — for any path an adversary could realistically take to the target — the system has a gap, regardless of how sophisticated any individual layer looks on paper.

Why "More Cameras" Is Rarely the Right Answer

Facilities under budget pressure often default to adding detection technology, because it's visible, procurable, and easy to justify in a board presentation. But additional detection only helps if the existing delay-to-response-time balance was actually the weak link. In many real assessments, the gap is somewhere else entirely — a response force with an unrealistic travel time to a remote area, a delay barrier that looks imposing but can be defeated quickly with common tools, or a detection system with such a high nuisance-alarm rate that operators have learned, culturally, to under-react to it.

This is why a proper vulnerability assessment evaluates the system holistically — mapping the specific paths an adversary could take to a target, and testing the detection-delay-response balance along each path, rather than reviewing each technology layer in isolation.

A protection system is a chain of timed events, not a list of equipment. It is only as strong as its slowest response relative to its shortest delay.

GTS's physical security and vulnerability assessment practice is built around exactly this analysis — identifying where a facility's detection-delay-response balance is strongest, where it is weakest, and which investments actually close the gap rather than simply adding visible but low-impact technology.