Brian Sims
Editor

Security Perimeters: Tested Against Yesterday’s Threats

WHILE LPS 1175 is one of the most rigorous physical security standards in the world, asserts Richard Hilson, it only tests products against defined toolkits, but are those tools the most likely ones to be used by criminals?

As lithium-ion battery technology puts professional-grade cutting capabilities into the hands of criminals for under £200, the gap between what certification assures and what real-world security demands has never been wider.

When talk turns towards physical security tests, LPS 1175 is, without question, one of the toughest. Under Issue 8, a product is assessed against a two-part rating: a letter from A to H denotes the toolkit used, while a number from one to 20 denotes the delay (in minutes) that it must realise against an attacker using that toolkit. However, the overwhelming majority of products (95% of them, in fact) submitted for certification fail on the very first attempt.

The Loss Prevention Certification Board tests a specimen representing a specific product – such as a gate, a fence panel, a shutter or a grille – in a controlled laboratory against a defined toolkit for a defined period.

For those who are unfamiliar with LPS 1175, that scenario may not appear to factor-in how the product is to be installed or that it may be attacked by someone who has done their homework rather than just turned up ‘cold’.

Reality of the situation

The LPCB not only tests the product, but does so having full access to the manufacturer’s production drawings and installation instructions. These enable test engineers to not only verify the specimen’s construction and installation, but also to plan their attack test with full knowledge of the product and its potential vulnerabilities.

Perimeter fencing is one such example where the level of pre-testing insights meets rigorous assessment. The LPCB has access to details that define how the fence is configured to achieve the angles to be included within a perimeter, or to suit the topography on which it’s to be installed. In order to ensure that specifiers, installers and end users are aware of how a specific product has been evaluated, these details are included within issued certificates and within associated listings on RedBook Live (ie the database where LPCB certified products can be found).

Toolkits in the matrix  

Each toolkit listed in the LPS 1175 classification matrix is effectively a snapshot of what was available to criminals when the Loss Prevention Standard, or its most recent revision (in this case Issue 8), was published.

Issue 8 replaced Issue 7 in 2019. Issue 8 replaced Issue 7 in 2019. One reason it was updated was that some tools listed within had become unavailable (eg 7.2v drill). More importantly, the LPCB had identified the threat posed by portable battery-powered tools, including those supplied with higher voltage battery packs – 36V (introduced in Toolkit F) and 54V (introduced in Toolkit H).

Issue 8 also included changes to manual tools, including the addition of ratchet straps in toolkit B. Like any revision, LPS 1175 Issue 8 was implemented to ensure the standard reflected attacker capability and, therefore, the threat spectrum at that time. It also future-proofed the standard to ensure products certified to Issue 8 would remain relevant to the threat posed by commonly available tools for years to come. That remains the case to this day.

Police investigations into commercial burglaries are increasingly referencing portable angle grinders being used to break perimeter security. In January this year, Hampshire Police reported that offenders had used an angle grinder to force entry through fencing at a business premises in Eastleigh before stealing six micro excavators.

Likewise, Avon and Somerset Police now specifically warns construction businesses that the increased availability of battery-powered cordless angle grinders is contributing to more attempts by criminals to break through site security measures, among them locks and storage units.

This presents a challenge to those responsible for preparing and maintaining security standards. As criminal capability evolves, so must the standards which benchmark products’ resistance to them. The LPCB has achieved this with LPS 1175, but the same cannot be said for all standards. For example, EN 1627 continues to only reference the use of a 14.4V drill (RC4). Although it does reference other power tools for resistance classes RC5 and RC6, they are mains powered.

When was the last time you heard of a burglar plugging their angle grinder into a power socket mounted on the attack face of a gate and then cutting a hole in that gate?

Rising crime

BauWatch’s 2025 crime report found that two-thirds of construction and infrastructure professionals had seen crime rise on their sites, with small tools and power tools the most commonly stolen category, costing the industry close to £100 million per annum.

A product holding an LPS 1175 rating tells you that specific item, tested in isolation, met a specific level. The standard evaluates the product as a whole, including hardware and fixings, but that assessment stops at the edge of the tested unit. Everything else – ie specification, installation and how the layers interact – is down to whomever built the perimeter. To me, that suggests a brilliant product badly integrated is not going to make a brilliant perimeter.

Certification confirms that the product has the capability to deliver a specific level of protection when configured and installed (as defined on the certificate and associated documents listed on that certificate). However, the certification body’s assessment stops there. The latter cannot cater for what it cannot see.

On that basis, it remains vitally important that users complete a threat, vulnerability and risk assessment. They must select a security rating appropriate to the type and power of the tools that may be available to (and used by) intruders. Further, they have to ensure the product they specify and use is certified to that rating for a scope covering the sizes and configurations to be installed as well as the gradient and other important contextual factors. Otherwise, it will always be the case that a brilliant product badly integrated is not going to make a robust and trusted perimeter.

Delay, detection and response 

Certification is an integral process for ensuring the right security systems are invested in and, ultimately, provides a transparent and trusted way in which to assess performance against defined use cases.

However, as those practitioners operating in the security industry are well aware, certification doesn’t completely solve the whole problem. It’s the starting point for protecting people and assets, not the finish line. Delay is only one element of the equation alongside detection and response, while a perimeter is only as good as its weakest link. The latter could be centred on poor installation or improper maintenance.

A barrier delivering a ten-minute delay is worth little if nobody notices the attack until minute eight, and worth less still if the response takes 15 minutes to arrive. Experience shows that deterrence emanates from convincing an attacker that risk and effort outweigh the reward.

Where, then, does that leave the individual who’s specifying a perimeter security regime? They need to ask (and then answer) a different question. Not: ‘What rating does this product hold?’, but instead: ‘Will this perimeter, as specified and installed, actually stop or delay the attempted attack given the tools realistically available today?’

Richard Hilson is Director of Sales and Marketing at Parking Facilities Limited (PFL) Access Management (www.parkingfacilities.co.uk)

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up