All insights
Security & Risk Management

Converged Security: Why an Integrated Approach to Physical, Cyber and Personnel Risk Is Now Essential

The traditional separation between physical security, cyber security, and personnel security has become a strategic liability. This article examines why converged security operating models are now essential for organisations facing hybrid threats and how UK security leaders are restructuring their functions in 2026.

Oakwood Risk & Resilience10 min read

For most of the past two decades, security functions in UK organisations have operated as parallel disciplines. Physical security teams managed access control, guarding contracts and CCTV. Cyber security teams managed firewalls, identity and incident response. Personnel security sat somewhere between human resources and corporate security, dealing with vetting, insider risk and leaver processes. Each team had its own budget, its own reporting line and, often, its own definition of what counted as a threat.

By 2026 that model has stopped working. The threats organisations now face do not respect the internal boundaries security teams have drawn around their disciplines. A compromised contractor uses physical access to plant a device that exfiltrates data over weeks. A disgruntled employee combines knowledge of building security with credentials harvested from a phishing campaign. A hostile reconnaissance team uses open source information and social media to identify vulnerabilities that no single team would ever spot in isolation. Converged security is the operating model that responds to this reality, and the organisations that have adopted it are noticeably more resilient than those that have not.

What converged security actually means

Convergence is widely talked about and frequently misunderstood. It is not simply a matter of putting the head of physical security and the chief information security officer in the same monthly meeting. That arrangement is necessary but nowhere near sufficient. True convergence means that the organisation has a single security risk picture, a shared set of standards, integrated incident response processes and clear accountability for the spaces between traditional disciplines.

In practical terms this involves three changes. The first is structural, with a single accountable executive responsible for the totality of security risk reporting to the board. The second is procedural, with shared risk assessments, joint investigations and integrated exercising. The third is cultural, with security professionals trained to think across disciplines rather than defending the boundaries of their specialism.

Why the case for convergence has hardened

Several developments have pushed convergence from a desirable state to an operational necessity. The Terrorism Protection of Premises Act 2025, often referred to as Martyn's Law, requires responsible persons to consider how physical security measures interact with operational procedures and staff training. We have written about how organisations should be preparing for the Terrorism Protection of Premises Act in 2026, and the legislation makes little sense unless physical, personnel and information security are treated as a single system.

The growth in insider risk has also reshaped the conversation. Modern insider threats almost always cross disciplinary lines. The trusted insider with privileged system access who removes commercially sensitive information uses physical means, digital means and social means in combination. Treating any of those vectors in isolation produces the kind of fragmented response that allows incidents to escalate. Our analysis of building a strong security culture across your organisation makes the same point from a different angle.

Regulatory pressure is the third driver. The financial services sector has been moving towards integrated operational resilience for several years, and we have explored the lessons in our piece on the first year of DORA and what it taught us about operational resilience. What financial regulators have made explicit, sector specific guidance across critical national infrastructure has made implicit. Boards are increasingly being asked to demonstrate that they understand security risk in the round, not as a series of isolated technical concerns.

What converged operating models look like in practice

The organisations that have made convergence work share a small number of design choices. They appoint a single senior security executive, sometimes called a chief security officer, with accountability for physical, personnel, information and travel security. That executive is supported by specialists in each discipline, but the specialists report into a unified function rather than parallel hierarchies.

They also invest in a shared security operations capability. This does not necessarily mean a single physical control room, but it does mean that physical and digital alerts feed into a common analytical function, and that incidents are triaged against a unified risk picture. Threat intelligence is consumed once and distributed across disciplines rather than being procured separately by each team.

Joint exercising is another consistent feature. The organisations that have moved furthest run scenarios that deliberately cross disciplinary boundaries. A simulated insider event might begin with a personnel concern, escalate to a physical access incident and culminate in a data exfiltration scenario. Designing and facilitating these exercises is challenging, which is why many organisations bring in external support. Our testing and exercises practice supports complex multi-disciplinary work for security leaders.

Common barriers and how to overcome them

Convergence is not free, and the obstacles are usually organisational rather than technical. Existing security leaders may resist losing direct reporting relationships. Procurement teams may struggle with contracts that have been let against a fragmented model. Human resources may be reluctant to share information that traditionally sat outside the security function. None of these barriers is insurmountable, but each requires deliberate change management.

The most successful approach we have seen begins with a unified security strategy approved at board level. That strategy creates the mandate for structural change and provides cover for the difficult decisions that follow. From there, organisations typically restructure governance first, then operations, then technology. Trying to start with technology rarely works because the underlying organisational issues continue to undermine the new tooling.

Skills development is the final piece. Security professionals trained in a single discipline often need significant support to operate effectively across boundaries. Our CSRM® Certified Security Risk Manager certification is designed for exactly this transition, equipping practitioners to operate at a strategic level across the full breadth of security risk. For those whose primary focus is protective security, the Certified Terrorism and Protective Security Practitioner certification provides the equivalent grounding in counter terrorism and protective security disciplines.

What boards should be asking

Boards do not need to become security experts, but they do need to ask the right questions. Three questions are particularly useful in 2026. First, who in the organisation has a single, integrated view of security risk, and how is that view communicated upwards. Second, when an incident occurs that crosses physical, personnel and information security boundaries, who is in charge and how was that decision made before the incident occurred. Third, when did the organisation last exercise a scenario that deliberately tested those boundaries.

If those questions cannot be answered cleanly, the organisation is not yet operating a converged security model, regardless of what the organisation chart says. The next step is usually a structured assessment of the current security operating model against the threats the organisation actually faces, followed by a phased roadmap towards genuine integration. Our security and resilience consulting practice supports organisations through exactly this kind of work, and many engagements begin with a short diagnostic that establishes a baseline before any structural changes are proposed.

The strategic argument for convergence has been made many times over the past decade. What has changed in 2026 is that the cost of not converging has become impossible to ignore. The threats are integrated. The regulatory expectations are integrated. The technology is integrated. Security functions that remain fragmented will continue to be outpaced by adversaries who have never recognised the artificial boundaries that fragmentation creates.

Talk to us

Want to discuss how this applies to your organisation?

Speak with us