top of page

April 2026 - Minaz Jivraj My Take: Beyond Cameras and Locks: Building a Resilient, Layered Security Ecosystem for Today’s Schools

  • Apr 8
  • 8 min read

For much of my career, school security conversations followed a familiar and deeply flawed pattern. After a high-profile incident, districts scrambled to purchase the latest technology; metal detectors, cameras, panic buttons, believing the right device could prevent the next tragedy. Months later, the urgency faded, systems went unmaintained, training lapsed, and the illusion of safety quietly replaced real preparedness.

The reality is uncomfortable but unavoidable: there is no single technology, policy, or response plan capable of protecting a school community on its own. Schools are living systems; complex, dynamic, and deeply human. Effective security must reflect that complexity.


A layered approach to school security technology recognizes a simple truth learned through decades of incidents, audits, and after-action reviews: failure is inevitable somewhere in the system. The question is whether the system collapses, or compensates.


Layered security is not about fear or fortification. It is about resilience, foresight, and duty of care. Done correctly, it strengthens safety while preserving the openness and trust that define healthy learning environments.


Why Layering Matters: Lessons Written in Hard Experience

In every serious school incident, I have studied, multiple failures, not one, were present. A door propped open. A radio that didn’t work indoors. Cell phones with no signal. A staff member unsure whether they had authority to act. A camera/s failing to record. A network outage during an emergency.


Layered security accepts three fundamental realities:

  1. Risk constantly evolves - threats change faster than procurement cycles.

  2. Humans are part of the system - for better and worse.

  3. Redundancy saves lives - when one layer fails, another must engage.

This philosophy mirrors high-reliability industries such as aviation, nuclear power, and healthcare, where catastrophic failure is prevented not by perfection, but by overlapping safeguards.

Schools deserve the same rigor.


The Foundation: Culture, Governance, and Human Intent


Culture Is the First Layer - Whether You Plan It or Not

Technology does not create safety; people do. The strongest security systems in the world fail instantly in cultures where:

  • Staff are afraid to report concerns

  • Policies are unclear or inconsistently enforced

  • Training is treated as a checkbox

  • Safety is viewed as someone else’s job

 

Conversely, I have seen modestly equipped schools perform extraordinarily well during crises because staff understood expectations, trusted leadership, and acted decisively.

A culture of safety is built intentionally through:

  • Visible leadership commitment

  • Clear behavioral expectations

  • Repeated, realistic training

  • Psychological safety for decision-making

 

Culture is not soft; it is operational.

 

Governance: The Most Overlooked Control

One of the most common findings in school security audits is fragmented ownership. Cameras belong to IT. Doors, locks and windows belong to facilities. Radios belong to site operations. Emergency decisions belong to no one, or everyone.

Layered security requires clear governance:

  • A designated district-level safety authority

  • Defined system ownership and maintenance responsibility

  • Documented decision authority during incidents

  • Routine reporting to executive leadership and boards

 

Without governance, systems decay quietly until they fail publicly.

 

Risk-Based Planning: Moving Beyond Emotional Purchasing

After every major incident, vendors flood the market with solutions promising prevention. While innovation matters, reactionary purchasing is one of the greatest risks to long-term safety.

Effective districts/boards begin with comprehensive risk assessments that evaluate:

  • Physical infrastructure

  • Operational workflows

  • Human behavior patterns

  • Historical incidents and near misses

  • Community-specific threats

Risk assessments do not dictate spending; they prioritize it. They answer the most important question leaders face: Where will limited resources reduce the most risk?

 

The Layers of School Security Technology

1. District/Board and Digital Infrastructure Layer

Cybersecurity is now inseparable from physical safety. In recent years, ransomware attacks have disabled access control systems, emergency communications, and student information platforms during active school hours.

Key components include:

  • Network segmentation for safety systems

  • Identity and access management

  • Redundant communication pathways

  • Data protection for safety platforms

A school without digital resilience is operationally blind during crisis.

 

2. Campus and Perimeter Layer

Perimeters are not about turning schools into fortresses. They are about early detection and controlled access.

Effective perimeter strategies combine:

  • Thoughtful site design and natural surveillance

  • Visitor management systems

  • Exterior lighting and cameras

  • Clearly defined entry points

The goal is not to stop every threat at the fence, but to slow, detect, and respond.

 

3. Building Layer

Most school incidents involve unauthorized or unmonitored access to buildings. This layer remains foundational.

Critical elements include:

  • Electronic access control with auditing

  • Integrated video and intrusion alarms

  • Public address and mass notification systems

  • Visibility in common areas

Access control systems are only as strong as daily behavior. One unlocked door negates thousands of dollars in technology.

 

4. Emergency Communications: A System, not a Button

Emergency communication failures are among the most frequent contributors to chaos during incidents. Schools often assume systems will work under stress; until they don’t.

Effective communication systems account for:

  • Power and network failure

  • Audible coverage gaps

  • Redundant delivery methods

  • Human activation under stress

Communication is not about speed alone; it is about clarity, confirmation, and reach.

 

5. Classroom and Interior Layer

The classroom is where safety becomes personal. This layer must empower, not trap occupants.

Key considerations:

  • Code-compliant lockable doors

  • Interior communication methods

  • Safe space design that allows flexibility

  • Clear procedures aligned with training

Security features that staff do not trust or understand will not be used effectively.

 

Integration and Interoperability: Where Systems Become Strategy

Siloed systems slow response and increase cognitive load during emergencies. Integrated platforms allow staff to see, hear, and act from a common operational picture.

Interoperability should include:

  • Access control, video, and alarms

  • Communication platforms

  • Coordination with first responders

  • Alignment with emergency operations centers

Integration is not about convenience; it is about decision speed under pressure.


Training, Pilots, and Continuous Improvement

Security systems should be piloted, stress-tested, and refined before full deployment. Pilots reveal:

  • Workflow conflicts

  • Training gaps

  • Human usability issues

  • Impact on learning environments

Security is never “done.” It must be inspected, rehearsed, and challenged to remain effective.

 

Inspection, Compliance, and the Reality of Drift

One of the most dangerous assumptions in school safety is that documentation equals functionality. Systems degrade through practical drift when inspections become routine and verification becomes assumed.

Effective districts:

  • Physically test life safety systems

  • Validate third-party inspections

  • Track maintenance and failure trends

  • Treat compliance as a minimum; not a guarantee

Liability does not disappear because a checklist was signed.

 

Sustainability: Planning Beyond the Financial Cycle

Short-term funding surges can create long-term liabilities if systems cannot be maintained. Sustainable planning accounts for:

  • Staffing and training costs

  • Maintenance and lifecycle replacement

  • Vendor support longevity

  • Operational ownership

Security that cannot be sustained is security that will eventually fail.

 

What a Layered Approach Is, and Is Not

A layered security framework is:

  • Not a product checklist

  • Not a one-size-fits-all solution

  • Not a mandate for expensive technology

It is a disciplined approach that aligns risk, governance, people, and technology into a coherent system.

 

Case Examples: When Layers Hold, and When They Fail

For over nearly three decades, my understanding of layered security has been shaped less by theory and more by post-incident reality. After-action reports, court records, reviews, and operational debriefs consistently reveal the same pattern: outcomes are determined not by the presence of a single technology, but by how multiple layers interacted, or failed to interact, under stress. The following examples illustrate that principle in real-world terms.


Case Example 1: Access Control Without Culture - A Door That Undid the System


Context: In a suburban high school with modern access control, cameras, and visitor management, an unauthorized individual gained entry during the school day through a side door that had been intentionally propped open for convenience.


What Worked:

  • Electronic access control on primary entrances

  • Exterior and interior video coverage

  • Established emergency procedures


What Failed:

  • Human behavior undermined the perimeter layer

  • No active supervision of secondary entrances

  • Cultural tolerance for bypassing controls


Lesson Learned: This incident did not occur because technology was absent. It occurred because human behavior was not treated as an intentional security layer. No amount of investment can compensate for norms that allow staff or students to defeat controls “just this once.”


Layered Insight: Physical security measures must be reinforced by training, accountability, and leadership modeling. Culture is either a force multiplier, or a vulnerability.

 

Case Example 2: Emergency Communications That Couldn’t Carry the Message


Context:During an active incident at a large secondary campus, administrators attempted to initiate a lockdown announcement. Portions of the building never received the message due to aging speakers, ambient noise, and network latency.


What Worked:

  • Incident command structure was established

  • Law enforcement response was timely

  • Staff attempted to follow protocol


What Failed:

  • Public address system coverage gaps

  • No redundant classroom-level communication

  • Overreliance on a single delivery method


Lesson Learned:Emergency communication had been treated as a device, not a system. The assumption that “the announcement will go out” had never been validated under real-world conditions.


Layered Insight:Effective communication requires redundancy across voice, visual, and digital channels, supported by regular testing and drills. Silence; intentional or not, creates confusion and increases risk.

 

Case Example 3: Integration That Reduced Response Time


Context:A mid-sized school district integrated access control, video surveillance, and panic notification into a single operational platform shared with local law enforcement.


What Worked:

  • Immediate situational awareness for responders

  • Real-time access to camera feeds

  • Faster verification of threat location


Outcome:Law enforcement was able to identify and isolate the threat area within minutes, reducing unnecessary building-wide disruption and accelerating resolution.


Lesson Learned:Integration reduced cognitive load and decision latency at the exact moment clarity mattered most.


Layered Insight:Interoperability does not replace training or judgment, but it amplifies both during time-compressed decision-making.

 

Case Example 4: Cyber Failure as a Physical Safety Event


Context:A large urban school district experienced a ransomware attack that disabled network-dependent systems, including access control dashboards, emergency communications, and digital visitor logs.


What Worked:

  • Manual procedures were available, but rarely practiced

  • Facilities staff could physically unlock doors


What Failed:

  • No network segmentation for life safety systems

  • Staff unfamiliarity with offline procedures

  • Delayed situational awareness during disruption


Lesson Learned: Cyber incidents are no longer an “IT problems.” They are operational safety events with direct physical implications and Cyber resilience must be treated as part of the district safety infrastructure, with offline contingencies trained and rehearsed like fire drills.

 

Case Example 5: Training as the Deciding Factor


Context:In two comparable districts with similar technology investments, staff responses to identical threat indicators differed dramatically.

  • District A had bi-annual, scenario-based training focused on judgment and decision-making.

  • District B relied on written procedures and infrequent drills.


Outcome:

  • District A staff recognized indicators earlier, escalated concerns, and prevented further escalation.

  • District B experienced delayed reporting and confusion over authority.


Lesson Learned:Technology did not determine the outcome; training did.


Layered Insight:Training is not a supporting activity; it is a primary control layer. Systems are only as effective as the people expected to activate them under stress.

 

Case Example 6: Practical Drift and the Illusion of Readiness


Context:During a routine inspection following a non-critical incident, a district discovered that several cameras listed as “operational” had not recorded video for months due to storage failures.


What Worked:

  • Documentation was complete

  • Compliance reports were current


What Failed:

  • Physical verification had not occurred

  • Maintenance alerts were not monitored

  • Assumptions replaced inspection


Lesson Learned:Compliance does not equal capability. Practical drift had quietly degraded the system.


Layered Insight:Layered security requires observable validation, not assumed functionality. Systems must be tested in conditions that mirror real use.

 

What These Cases Reveal Collectively

Across different geographies, threat types, and system designs, the same truths emerge:

  • Single points of failure are inevitable

  • Human behavior must be designed into the system

  • Redundancy saves time; and sometimes lives

  • Governance determines whether layers endure or erode

Layered security is not theoretical. It is visible in what holds together, and what unravels, when schools are placed under stress.

 

Conclusion: Preparedness as an Expression of Care

Layered school security is not about fear. It is about responsibility.

 

It reflects a district’s commitment to:

  • Protecting students and staff

  • Supporting informed decision-making

  • Preserving learning environments

  • Demonstrating duty of care

 

When schools invest in layered, well-governed, human-centered security systems, they do more than prevent harm; they build trust.

And in my experience, trust is the most powerful protective factor a school can have.


References

 


Minaz Jivraj MSc., C.P.P., C.F.E., C.F.E.I., C.C.F.I.-C., I.C.P.S., C.C.T.P.

Disclaimer:The information provided in this blog/article is for general informational purposes only and reflects the personal opinions of the author. It is not intended as legal advice and should not be relied upon as such. While every effort has been made to ensure the accuracy of the content, the author makes no representations or warranties about its completeness or suitability for any particular purpose. Readers are encouraged to seek professional legal advice specific to their situation.

 

 
 

Recent Posts

See All

MRJ Security Consultants: Protecting Tomorrow's Leaders Today with consulting, training and security services.

Quick Links

© Copyright 2025 MRJ  Security Consultants - All Rights Reserved

bottom of page