In most South African organisations, two teams own security and they barely speak.
One sits in a control room. Cameras, access control, guarding, alarms, perimeter. It reports to operations or facilities. The other sits in IT. Firewalls, identity, endpoints, logs. It reports to the CIO.
They have separate budgets, separate suppliers, separate incident processes and separate definitions of an event. Someone attacking the business uses both doors, in one operation, and does not care which team owns which.
The split is historical, not logical
The division made sense when a camera was analogue and a firewall was a box in a rack. Physical security was a guarding contract. Information security was a technology function. Different skills, different worlds.
Then cameras moved onto the corporate network. Access control moved onto a database with a web front end. Alarm panels got IP connections. Video analytics started running on GPUs in a data centre. The physical estate became an IT estate with a different name.
The organisational chart did not follow. In many companies the control room network is still managed by a supplier the IT team has never met, on a VLAN nobody has audited in three years.
Ask your CIO who patches the access control server. Then ask your head of security the same question. Compare the two answers.
Where the gap costs money
Four failures show up again and again.
Unowned devices on the network
Cameras, controllers, intercoms and recorders with default credentials, firmware from four years ago and no owner in the asset register. They are the easiest entry point in most estates, and they sit inside the perimeter by design.
Two incident logs, no shared timeline
The control room records a badge event at 02:14. The SOC records an authentication anomaly at 02:17. Neither correlates the two, because the systems never talk and the teams never meet. The pattern only appears in the post-incident report months later.
Duplicated identity
An employee leaves. HR closes the network account the same week. The physical access card stays live for months because it lives in a different system with a different process. Every organisation I have worked with has found this when they finally checked.
Wasted spend
Two teams buy overlapping analytics, storage and monitoring, each unaware of the other's contract. Consolidation regularly recovers real money, which is usually what finally gets executive attention.
What convergence actually means
Convergence does not mean one person runs guards and firewalls. The skills stay specialised. What changes is the layer above.
- One risk register covering physical and digital threats, scored the same way.
- One asset register. If it has an IP address, IT knows about it, whoever bought it.
- One identity source of truth feeding both network access and door access, with one joiner, mover and leaver process.
- One incident timeline. Physical events and security events land in the same platform, timestamped from the same clock.
- One executive accountable for the combined picture, with both teams reporting into that view.
Start with identity and the asset register. Those two deliver the most risk reduction for the least political effort, and they build the case for the rest.
The South African angle
This matters more here than in most markets. South African organisations carry a heavier physical security load than their European counterparts. Guarding, perimeter protection, control rooms and video analytics are normal operating cost, not an unusual expense.
That gives local teams unusual depth. Very few countries have as much practical experience running large video estates, integrating analytics at scale and staffing 24-hour control rooms. The expertise is genuinely world class.
It is also underused, because it sits in a silo that reports to facilities and rarely reaches the board with the language of risk. Converging the two functions is how that expertise gets valued properly.
Where to start on Monday
- Scan the network for devices the IT asset register does not know about. Expect a bad afternoon.
- Pull the list of active access cards and reconcile it against the current payroll.
- Put the head of physical security and the head of information security in one weekly meeting with one agenda.
- Write one incident definition both teams sign.
None of that needs a procurement cycle. All of it makes the next real incident shorter.
