In short: Port security in the UK is governed by the ISPS Code and the Port Security Regulations 2009, which require a port facility to control access, monitor its berths and restricted areas, supervise cargo handling and keep security communication readily available. On a large estate most of those duties now depend on cameras, remote gates and handheld devices, so the network that connects them is part of the security plan, and a private 5G network is one practical way to cover the parts of the quay that fibre never reached.
Key Takeaways
- The ISPS Code lists seven duties — access control, berth monitoring, restricted areas, cargo, ship's stores and security communication all appear in Part A section 14, and most of them now run over a network.
- Coverage gaps become security gaps — a camera on a lighting tower with no fibre, or a remote gate with a flaky link, is a blind spot the Port Facility Security Plan assumes is not there.
- Level 2 needs kit in hours — trailer cameras, extra checkpoints and body-worn video on a SIM-authenticated private network can be in place the same day the security level rises.
In a nutshell

A port's security plan is usually written by people who know the estate intimately: the Port Facility Security Officer, the harbour master, the head of operations, often a retired police officer or two. It describes where the fence runs, which gates are staffed, where the cameras point and who is allowed on the quay. What it rarely describes in any detail is the network those cameras and gates sit on, because for most of the last twenty years that network was a mix of fibre where it could be trenched, point-to-point microwave where it could not, and a two-way radio system that the security team shared with everyone else. This post looks at port security from that angle: what the ISPS Code requires of a UK port facility, which of those requirements now depend on connectivity, and where the connectivity tends to fail.
What does the ISPS Code require for port security?
The International Ship and Port Facility Security (ISPS) Code was adopted by the International Maritime Organization in December 2002, after the attacks of September 2001, and came into force on 1 July 2004 under chapter XI-2 of SOLAS. It applies to ships on international voyages and to the port facilities that serve them. In the UK it sits alongside EC Regulation 725/2004, retained after Brexit, and the Port Security Regulations 2009, which extend the regime from individual terminals to whole port areas and create the role of Port Security Authority. The Department for Transport's maritime security team is the regulator and carries out the inspections.
Each port facility must have a Port Facility Security Assessment, a Port Facility Security Plan and a named Port Facility Security Officer. Part A section 14 of the Code then sets out the security duties the facility must perform, and the list is worth reading in the original because it is so practical:
- ensuring the performance of all port facility security duties;
- controlling access to the port facility;
- monitoring the port facility, including the anchoring and berthing areas;
- monitoring restricted areas, to ensure only authorised persons have access;
- supervising the handling of cargo;
- supervising the handling of ship's stores;
- ensuring that security communication is readily available.
The Code also defines three security levels. Level 1 is the normal state; level 2 is heightened, applied for a period when there is an increased risk; level 3 is exceptional, applied when an incident is probable or imminent. For UK facilities the Department for Transport sets the level, and the plan must describe what additional measures the facility takes at each one. Part B of the Code expects drills at least every three months and a full exercise at least once each calendar year, with no more than 18 months between exercises.
Which port security duties now depend on the network?
Almost all of them, on a modern estate. Controlling access means ANPR at the vehicle gates, card readers and turnstiles at pedestrian gates, and a check of the person's pass against a live list of who is authorised today. Monitoring the berths and restricted areas means CCTV, increasingly with thermal cameras along the quay edge to catch someone approaching from the water, and video analytics that flag a person inside a fenced area. Supervising cargo means knowing which box went where, which overlaps with the terminal operating system. Security communication means radios, and increasingly handheld devices that can send a photograph of a damaged seal or a suspect vehicle back to the control room.
Each of those systems generates traffic that has to reach a control room, often several hundred metres or a couple of kilometres away. On a small berth that is a short run of fibre. On an estate such as Southampton, Immingham or Tilbury, with quays, storage areas and car terminals spread over several square kilometres, it is a long list of cable runs, ducts and wireless links, each installed at a different time for a different project.
The threats those systems watch for are specific. In February 2024 the National Crime Agency and Border Force announced the seizure of 5.7 tonnes of cocaine hidden in a shipment of bananas at Southampton, the largest class A seizure in UK history; the previous record, 3.7 tonnes, had also been found at Southampton, in 2022. The National Crime Agency has warned repeatedly that organised crime groups recruit port workers, which makes the access control and restricted-area monitoring duties as much about insiders as about strangers climbing a fence. Ro-ro ports on the short straits deal with people trying to board lorries in the marshalling areas. A fence slows these people down; a person watching a screen, or an analytics rule firing, is what catches them, and both depend on the video reaching the control room.
Why do port CCTV and access control fail on large estates?
In our experience, when a camera or gate goes dark the fault is usually in the link behind it, and we see three recurring patterns.
Firstly, the estate outgrows its cabling. Cameras get added to lighting towers, fences and temporary structures where no duct exists, and each is connected by whatever was affordable at the time: a point-to-point wireless bridge, a 4G router on a consumer SIM, a Wi-Fi mesh node. Each works on the day it is installed. Several years later, nobody is quite sure which camera is on which link, and a failed bridge shows up as a black tile in the control room that stays black for a week.
Secondly, steel moves. A container terminal's stacks change height and position every shift, and a wireless link that had line of sight on Monday may be blocked by a stack of five-high boxes on Thursday. Wi-Fi across a yard struggles for the same reason: coverage between the stacks is patchy and handover between access points is poor for anything mounted on a moving vehicle.
Thirdly, the public mobile network is shared. A security team relying on consumer 4G for remote gates or body-worn video is competing for capacity with ships' crews, hauliers and passengers, and at a ferry port on a busy summer Saturday that competition is real. It is also a network the port does not control, cannot prioritise, and cannot easily audit.
The consequence for the Port Facility Security Plan is uncomfortable. The plan assumes a camera covers a restricted area, or that a remote gate checks every pass against the live list; if the link behind either has failed, the duty is not being performed, and nobody may notice until the next drill or the next inspection.
How does private 5G support port security?
A private 5G network is a mobile network that the port owns or rents, running on spectrum it holds under an Ofcom Shared Access licence, usually in the 3.8 to 4.2 GHz band. A small number of radios on existing towers and buildings can cover a quay, a storage area and a gate complex, and every device on it authenticates with a SIM that the port issues and can revoke. For security use, four properties matter.
Radio placement follows a survey of the estate, including the container stacks, and a cellular network hands a moving device from one cell to the next without dropping the session, which is what a camera on a patrol vehicle or a body-worn camera on an officer walking the quay needs.
Security traffic can be separated and prioritised. Cameras, gates and security handhelds can sit on their own data network name, with their own quality-of-service rules, so a burst of terminal operating system traffic or a firmware download never pushes the video from the quay edge out of the queue. The traffic breaks out locally, so the video stays on site and goes straight to the video management system in the control room.
Every device is known. A SIM-authenticated camera cannot be swapped for a laptop plugged into the same socket, and a lost handheld can be cut off from the network in seconds. For a regulator asking how the port knows its security systems have not been tampered with, that is a clearer answer than an open Wi-Fi SSID with a shared password.
The network also keeps running during a public network outage. A private network with its core on site keeps the cameras recording and the gates checking passes even when the public operators are congested or down, which matters for the "security communication is readily available" duty.
There are trade-offs. Uplink capacity on a 5G cell is finite; a cell sector configured for uplink-heavy traffic might carry somewhere between 100 and 200 Mbit/s of uplink, which is enough for a few dozen 1080p cameras at 4 to 6 Mbit/s each but far fewer 4K streams. Fixed cameras where fibre already exists should stay on fibre. The strongest case for 5G is the long tail: lighting towers, fence lines, remote gates, vehicles and people, which are exactly the places where the existing patchwork of links fails.
What happens when the security level rises?
This is where connectivity decides how quickly a port can respond. When the Department for Transport raises a port to security level 2, the plan will typically call for more patrols, fewer open access points, more checks on vehicles and cargo, and more monitoring of the waterside and restricted areas. Some of those measures are people; many are equipment. A trailer-mounted camera mast at a closed gate, a temporary vehicle checkpoint with ANPR and a pass reader, extra body-worn video for officers searching vehicles: all of it needs a network connection at a place where there was not one yesterday.
On a patchwork estate the answer is usually a consumer 4G router and hope. On a private 5G network the port pre-registers SIMs for a kit of redeployable cameras and checkpoint equipment, keeps them charged in a store, and puts them out when the level changes. The cameras appear in the video management system the moment they power up, on the same prioritised security network as the fixed ones. That same kit makes the quarterly drills more realistic, because the drill can include deploying it rather than assuming it.
The same logic applies to one-off pressures that are not a formal level change: a cruise call with several thousand passengers at a terminal usually used for cargo, a high-value cargo that the shipper wants watched, or a visiting naval vessel. Each needs extra coverage for days, not years.
Where should a port start?
Associated British Ports runs a private 5G network at the Port of Southampton, built with Verizon Business, and Belfast Harbour partnered with BT to build its own 5G network, so there are working examples on UK estates. A smaller facility can start with a narrower scope, and we suggest a sequence that follows the Port Facility Security Plan rather than the technology.
Start with the Port Facility Security Assessment and list every camera, gate and security device that is not on fibre, with its current link and its failure history. That list is usually longer than anyone expects, and it is the scope for a first phase. Then survey the estate for radio coverage, including the areas the plan calls for at level 2 but does not currently monitor. Finally, move the most failure-prone links first: remote gates and cameras on lighting towers along the quay edge, followed by the redeployable level 2 kit.
We would also talk to the Department for Transport's maritime security team early. The regulator is interested in whether the duties are performed and evidenced, and a network that logs which camera was online, and when, makes that evidence easier to produce at the next inspection. If you would like to walk through your own estate's plan, get in touch and we will start with the list of links your security plan depends on.
