Security Convergence Is a Governance Problem, Not a Technical One
Reframing the Convergence Debate
Security convergence is often presented as a technical challenge.
Across industry discussions, the emphasis is clear. Integrate systems. Align platforms. Connect physical and cyber infrastructures. The assumption is that once systems are unified, convergence will naturally follow.
At face value, this seems logical.
But it is also fundamentally incomplete.
Because security convergence is not, at its core, a technical problem. It is a governance problem.
The Structural Reality of Security Functions
To understand why, it is necessary to look at how security functions are actually organised within modern organisations.
In most large enterprises, physical security is positioned within facilities management or corporate services. Cybersecurity operates within information technology. Risk management is often embedded at the enterprise level, while intelligence and investigative functions may sit within legal or compliance structures.
Each of these functions plays a legitimate and necessary role in managing organisational risk.
However, they do not operate within a unified professional system.
They exist in parallel.
Each function follows its own leadership model, reporting structure, and operational priorities. While their responsibilities overlap in practice, their governance structures remain separate.
This is where the problem begins.
The barrier to convergence is not the absence of technology. It is the absence of aligned governance.
Why Technology Alone Cannot Deliver Convergence
There is no question that technology has advanced the ability to integrate security systems.
Modern platforms enable shared visibility, data exchange, and real-time coordination across previously isolated functions. Surveillance systems can be linked to network monitoring tools. Access control systems can feed into broader intelligence frameworks.
These are important developments.
But they do not resolve the core issues.
Technology can facilitate the flow of information. It can support coordination. It can enhance situational awareness.
What it cannot do is answer fundamental governance questions:
Who holds decision-making authority?
Who is accountable for outcomes?
How are competing priorities resolved across functions?
These are not technical questions. They are questions of governance.
Without clear answers to these, integration risks creating complexity rather than coherence.
Governance Fragmentation as the Core ChallengeFigure 1: Governance Fragmentation in Security Convergence
Figure 1: Governance Fragmentation in Security Convergence
This condition can be understood as Governance Fragmentation.
A state in which security functions operate under separate authority structures, professional frameworks, and accountability models, despite addressing overlapping and interdependent risks.
In such environments, decision-making becomes misaligned. Priorities compete rather than converge. Responsibility becomes diffuse.
Technology does not eliminate this fragmentation. In many cases, it exposes it more clearly.
True convergence, therefore, cannot be achieved through systems alone. It requires structural alignment.
Extending the Security Knowledge Structure
Figure 2: Mardner Security Knowledge Structure Model (MSKSM)
This challenge becomes even more visible when viewed through the Mardner Security Knowledge Structure Model (MSKSM), which frames security knowledge across three interconnected levels: operational, analytical, and strategic.
At the operational level, integration is often achievable. Systems can be connected, processes aligned, and responses coordinated.
At the analytical level, information sharing can occur. Threat data, risk assessments, and intelligence outputs can be combined to improve understanding.
However, at the strategic level, where authority, governance, and decision-making reside, fragmentation persists.
This is where convergence ultimately fails.
Without alignment at the strategic level, integration at the operational and analytical levels remains partial and unstable.
The Complexity of the Multi-Actor Security Environment
The challenge of convergence extends beyond individual organisations.
Modern security environments are characterised by the interaction of multiple actors, including private security providers, law enforcement agencies, intelligence services, regulatory bodies, and corporate security functions. Each operates within distinct legal mandates, institutional frameworks, and operational priorities.
As Loader and Walker describe, this reflects a system of plural policing, where authority is distributed across multiple institutions rather than concentrated within a single structure.
In such environments, convergence is not simply a matter of linking systems.
It requires coordination across institutions.
This is inherently a governance challenge.
The Role of Professional Alignment
There is a further dimension that is often overlooked.
Professional fragmentation.
Different areas of security practice operate with different terminologies, analytical models, and conceptual definitions of risk. What constitutes “risk,” “threat,” or “vulnerability” may vary significantly between physical security, cybersecurity, intelligence, and risk management disciplines.
These differences create friction, even where technological systems are compatible.
Convergence, therefore, depends not only on integrated systems, but on shared professional frameworks.
This is where structured knowledge becomes critical.
The development of a coherent disciplinary foundation, often framed as Security Science, provides the basis upon which different domains can align conceptually, not just operationally.
What Meaningful Convergence Requires
Meaningful convergence is not achieved through integration alone.
It requires:
• clearly defined authority structures
• aligned governance frameworks
• shared professional knowledge systems
• consistent standards of competence and accountability
Technology supports these elements.
It does not replace them.
Conclusion: Convergence as an Institutional Design Problem
Security convergence will not be delivered by platforms, software, or system integration alone.
It will emerge through the deliberate design of governance structures that align authority, knowledge, and responsibility across the security ecosystem.
In increasingly complex threat environments, from cyber intrusion to infrastructure disruption and hybrid risk scenarios, the need for integrated security is clear.
But integration is not a technical outcome.
It is an institutional one.
And until governance is addressed as the central issue, convergence will remain incomplete.
References
Loader, I., & Walker, N. (2007). Civilizing Security. Cambridge University Press.
Gill, M. (2014). The Handbook of Security. Palgrave Macmillan.
Brooks, D. J., & Smith, C. L. (2013). Security Science: The Theory and Practice of Security. Butterworth-Heinemann.
Dupont, B. (2006). Security Networks. Policing & Society.