Editorial Library

Articles

Certanet publishes quotation-ready analysis on secure construction, industrial consequence, physical security, electromagnetic resilience and the standards needed to certify the built environment.

Industrial consequence and facility certification

Current industrial incidents show why chemical storage, occupied-space protection, responder access, control-room survivability and electromagnetic resilience belong in the built-environment certification conversation.

Are Chemical Tanks a Process-Safety Problem or a Building-Code Problem?
Industrial Risk

Are Chemical Tanks a Process-Safety Problem or a Building-Code Problem?

Both, and the second is usually neglected. Process safety governs the tank; the built environment receives the consequence. Occupied spaces, control rooms and egress paths near high-volume storage need siting, standoff and envelope decisions that process-safety programs were never designed to make.

How Close Should Occupied Spaces Be to Industrial Tanks?
Consequence Planning

How Close Should Occupied Spaces Be to Industrial Tanks?

Close enough only if standoff, envelope and egress are designed for a credible release. Proximity is a built-environment decision that determines who is exposed when a tank fails, and it is frequently inherited from site history rather than analysis.

Why Do Industrial Sites Need Certified Standoff Zones?
Industrial Siting

Why Do Industrial Sites Need Certified Standoff Zones?

Because standoff is the cheapest protection available and the easiest to lose. Distance between a hazard and occupied space reduces required hardening, but it is often assumed rather than documented, then eroded by later construction, storage or parking decisions.

Should Blast, Fragmentation and Chemical Release Be Designed Together?
Multi-Hazard Design

Should Blast, Fragmentation and Chemical Release Be Designed Together?

Yes. Industrial events rarely arrive as one hazard. A tank failure can combine pressure, debris, caustic release, fire exposure, utility loss and blocked access at once. Analyzing each separately leaves the interfaces between them unprotected, which is where most real failures occur.

What Survivability Standard Should a Control Room Meet?
Control Room Protection

What Survivability Standard Should a Control Room Meet?

One tied to how long the facility must keep operating and who must stay inside to run it. Control rooms concentrate people, decisions and dependencies, yet are often built to office criteria. Survivability means the room and its utilities function after the event, not merely that occupants evacuate.

Will Insurers Require Industrial Hardening Before Codes Do?
Insurance Risk

Will Insurers Require Industrial Hardening Before Codes Do?

Probably. Insurance responds to loss experience faster than code cycles allow, and it can price risk facility by facility. Owners are more likely to encounter hardening expectations through underwriting terms and renewal conditions than through a code amendment.

Where Is the Weakest Link in Industrial Security?
Weakest-Link Engineering

Where Is the Weakest Link in Industrial Security?

Usually at the interfaces. Walls, doors, glazing, penetrations, roof access and utility entries are each specified separately, then meet at joints nobody owns. Protection is set by the weakest continuous path, not by the strongest assembly in the specification.

Does Electromagnetic Resilience Belong in Industrial Safety Planning?
Electromagnetic Resilience

Does Electromagnetic Resilience Belong in Industrial Safety Planning?

Yes. Instrumentation, controls and communications are safety systems, and they fail under interference, loss of signal or power quality events. Treating electromagnetic exposure as an IT concern leaves the physical protection of those rooms, cable routes and antenna paths unassigned to anyone on the project.

Can Civilian Facilities Use UFC-Style Planning Without Overbuilding?
Standards Development

Can Civilian Facilities Use UFC-Style Planning Without Overbuilding?

Yes, by adopting the method rather than the criteria. Define the asset, state the hazard or threat, assign a consequence level, then set required protection and document accepted residual risk. That structure scales down to civilian industry without turning a plant into a military installation.

How Do You Certify a High-Consequence Industrial Facility?
Checklist

How Do You Certify a High-Consequence Industrial Facility?

By forcing specific answers before design closes: what must be protected, what threat or hazard is credible, what performance each assembly must deliver, and who accepts the residual risk. Certification is a documented decision trail, not a label applied after construction.

What Does Facility Certification Prove After an Incident?
Post-Incident Review

What Does Facility Certification Prove After an Incident?

That decisions were deliberate. A documented threat basis, assigned performance criteria and recorded acceptance of residual risk show a defensible standard of care. Without that record, an owner is left arguing intent after the fact, to investigators and insurers alike.

Foundation library

Core Certanet arguments on updated codes, UFC-level thinking, weakest-link engineering, insurance and risk governance.

Why Isn't Physical Security Part of the Building Code?
Building Codes

Why Isn't Physical Security Part of the Building Code?

Because codes were written for accident and disaster, not intent. Fire, egress, structure and energy all have performance criteria; deliberate attack, forced entry and electromagnetic disruption largely do not. Compliance certifies a minimum, not a threat-informed design, so owners must decide when minimum code is not enough.

Should Civilian Critical Infrastructure Adopt UFC-Level Thinking?
UFC Modernization

Should Civilian Critical Infrastructure Adopt UFC-Level Thinking?

The discipline, yes; the criteria, selectively. UFC's value is its sequence: establish a threat basis, assign a level of protection, then design and document against it. Civilian facilities can adopt that order of operations without defense-grade construction budgets.

Is Electromagnetic Security a Building Design Problem?
Electromagnetic Security

Is Electromagnetic Security a Building Design Problem?

Largely, yes. Shielding effectiveness, cable routing, room placement, penetrations and grounding are architectural and engineering decisions made early in design. Once walls are closed and pathways are set, electromagnetic performance becomes expensive to change and is rarely revisited for the life of the building.

What Does NSM-22 Mean for Infrastructure Owners?
Critical Infrastructure Policy

What Does NSM-22 Mean for Infrastructure Owners?

It reframes resilience as an ongoing obligation rather than a compliance event, emphasizing risk management across sectors and the systems society depends on. For owners it strengthens the expectation that physical and cyber-physical protection be assessed and documented.

What Is Weakest-Link Engineering for a Security Envelope?
Engineering Principles

What Is Weakest-Link Engineering for a Security Envelope?

Evaluating the envelope as a continuous system rather than a set of rated products. Delay is governed by the easiest path through it, so glazing, doors, penetrations, roof and utility entries must be assessed together, at the value of the weakest continuous route.

How Do You Apply Risk Management to Built-Environment Security?
Risk Management

How Do You Apply Risk Management to Built-Environment Security?

By converting threat, vulnerability and consequence into design requirements. Identify what must continue operating, the credible threats to it, the weak links in its envelope and utilities, and the consequence of failure, then translate the result into specified performance.

How Does Physical Security Affect Insurance Underwriting?
Insurance and Liability

How Does Physical Security Affect Insurance Underwriting?

Increasingly, through documentation. Underwriters price uncertainty, so a stated threat basis, tested assemblies and a recorded residual-risk decision give them something concrete to evaluate. Facilities that cannot describe their protective design invite conservative assumptions about it, and those assumptions arrive priced.

Why Does Secure Construction Need Published Standards?
Standards Development

Why Does Secure Construction Need Published Standards?

Because without them, comparison is impossible. Published criteria let owners evaluate competing assemblies, let designers specify by performance, and let insurers assess facilities consistently. Proprietary claims and fragmented checklists shift the risk of interpretation onto whoever signs the drawings.

What Should Come Before Security Technology in a Facility Design?
Practical Security

What Should Come Before Security Technology in a Facility Design?

Siting, layout, standoff, envelope and access sequence. Cameras and sensors report what is already happening; physical arrangement decides what can happen at all. Technology added to a weak configuration produces evidence of a breach rather than resistance to one.

Do Building Codes Require Ballistic or Forced-Entry Protection?
Protective Construction

Do Building Codes Require Ballistic or Forced-Entry Protection?

Generally no. Both are treated as specialty upgrades rather than code requirements, which leaves high-consequence facilities without a defined standard. The practical metric is access delay: how long an assembly resists a stated tool and threat level long enough for detection and response to matter.

Why Are Equipment Rooms a Cyber-Physical Risk?
Cyber-Physical Security

Why Are Equipment Rooms a Cyber-Physical Risk?

Because network security assumes the hardware is unreachable. Switches, controllers, power and communications terminate in rooms that are often protected only by an office-grade door. Physical access to that equipment bypasses most of the controls layered above it.

How Should Procurement Documents Specify Security Performance?
Specifications

How Should Procurement Documents Specify Security Performance?

In measurable terms: threat level, tool set, delay time, tested standard and acceptance evidence. Language such as bullet resistant or hardened has no defined meaning in a contract. Procurement is where a security intent either becomes enforceable or quietly disappears.

How Will Building Codes Address Security in the Future?
Future Standards

How Will Building Codes Address Security in the Future?

Most likely through risk-triggered requirements rather than universal mandates. High-consequence occupancies would carry a defined threat basis and measurable protection criteria, while ordinary buildings stay unchanged. Insurance terms and procurement language will probably impose that discipline well before code adoption catches up.