A building has a front door. A perimeter has a line, and the person crossing it picks the time and the place. They pick the weakest point on that line. If detection depends on a radio link, that weakest point is not always a gap in the fence. It is a notch in coverage.
No cellular product prevents deliberate radio denial, so this piece deals with detection instead. Site survey, physical hardening, response procedures, the choice of detection technology, and the alarm transmission category your installation needs all remain yours. So do risk documentation, incident response planning, Cyber Resilience Act conformity assessment, and vulnerability reporting.
A building is a point. You survey one location, confirm signal at the panel, and you are done. A perimeter is a line that runs for kilometres, and coverage has to hold along the whole of it. The average signal across a site tells you nothing useful. The weakest 50 metres is the number that matters, because that is the stretch an intruder will find.
Perimeter devices also sit where infrastructure runs out. The boundary of a substation, a reservoir, a rail corridor, or a port is the point past which there is no mains power, no fixed line, and no cabinet to put anything in.
And perimeter equipment is the first thing an intruder meets. Cameras inside a building are encountered after entry. A fence sensor is encountered before it. Anything an attacker wants to defeat, they reach first.
Jammers cannot lawfully be placed on the EU market under the Radio Equipment Directive, 2014/53/EU, and their use is prohibited in every member state. What varies is whether import, advertising, and mere possession are separately offences. They are in circulation regardless, and they already appear in vehicle and cargo theft, where the point is to stop a tracker reporting while the load moves. The same logic transfers to a perimeter sensor without modification.
Radio denial is a physics problem. No cellular product prevents it, from any provider, and anyone specifying connectivity for a perimeter should start from that assumption instead of looking for a product that claims otherwise.
Which is why the alarm industry never tried to solve it that way. EN 50136-1 carries a clause headed denial of service, and what it specifies is not an unjammable path. It specifies how fast you have to notice the path is gone. Prevention was never the control. Detection time was.
That reframes what to ask of a connectivity layer, and it is worth being precise about where multi-network access helps. European operators hold separate licences, but within the same handful of frequency ranges: 700, 800, 900, 1800, 2100, and 2600 MHz. A commodity jammer is specified by frequency range rather than by operator, and a typical unit covers that whole span in parallel. Reaching 4 networks does not help when all 4 sit inside the block being filled.
So multi-network access is not a defence against deliberate jamming. It is the answer to the failure a perimeter meets regularly: a coverage notch, an operator outage, a congested cell. A device tied to one operator treats every one of those as a dead sensor. There is a second, larger reason it matters, and it comes from the availability figures further down this page.
Reselection after a lost network is not instant, and on NB-IoT it is slow, because there is no connected-mode handover and recovery depends on idle-mode cell reselection and a band scan. Design the supervision interval around that instead of assuming it away.
If you want to tell a jammed site apart from one that has dropped for ordinary reasons, that capability sits in the modem, not in the SIM. There is precedent for expecting it: EN 50131-5-3 requires wireless interconnections within an alarm system to detect radio interference. Worth knowing what the module in your device already reports.
EN 50136-1:2012+A1:2018 is the European standard for alarm transmission systems, the path carrying an alarm from a protected site to an alarm receiving centre. It categorises those systems by path and performance: SP1 to SP6 for single-path systems, DP1 to DP4 for dual-path. It classifies each category on 4 axes, and most connectivity content only ever mentions one of them.
The longest permitted delay between the transmission path failing and that failure being reported. Table 3 sets it out. For single path it runs from 32 days at SP1, through 25 hours at SP2, 30 minutes at SP3, 3 minutes at SP4, and 90 seconds at SP5, down to 20 seconds at SP6. Dual-path categories run from 25 hours at DP1 down to 90 seconds at DP4 on the primary path, with separate limits for the alternative path.
The same table sets a figure for failure of all paths at the same time. For single-path categories that figure matches the path figure, because there is only one path to lose. So for a cellular perimeter running single path, the SP number is the number that matters when the site goes dark.
Worth noting while you are in Table 3: dual path is not automatically faster. DP1 allows 25 hours on the primary path, slower than SP3 at 30 minutes, and the all-paths-failed figures for DP2, DP3, and DP4 are 31 minutes, 4 minutes, and 3 minutes, each longer than the primary path figure for the same category.
This is the axis that decides whether a cellular path holds a category in most deployments, and it is the one nobody writes about. The weekly availability targets are 97% at SP4, 99% at SP5, and 99.8% at SP6. On the dual-path side they are 99% at DP2 and 99.8% at DP3 and DP4. Convert 99.8% and you get 20 minutes of non-operational time in a 7-day period.
SP1, SP2, SP3, and DP1 carry no availability requirement at all, which is why the standard only requires an alarm transmission service provider from SP4 upwards.
Twenty minutes a week is the number that bites a fence line in fringe coverage, not the 20-second reporting time. And this is where multi-network access earns its place properly. It does nothing for reporting time. It acts directly on the outages, congestion, and coverage notches that consume weekly availability.
A separate classification covering how long an alarm message takes to get from the transmitter to the receiving centre. Relevant here because waking a sleeping device adds to it.
Requirements that vary by category, with information security measures mandatory from SP4 and DP3 upwards. Cryptographic techniques are not optional. Clause 6.8.1 requires them, requires symmetric keys of no less than 128 bits and hash outputs of no less than 128 bits, and requires regular automatic key changes using machine-generated random keys. That last requirement rules out the static shared key a good deal of field equipment still ships with.
Read those back and the assumption behind them is plain. Substitution security exists because signals get replaced. Reporting times measured in seconds exist because the industry decided a long time ago that not hearing from a site is itself information.
So the question for a cellular perimeter is not whether the sensor is online. It is which transmission category the installation achieves on all 4 axes, and whether you have the evidence to prove it.
That answer does not come from a connectivity vendor. The risk assessment sets the security grade under EN 50131-1, and Table 10 of that standard gives the minimum ATS category for the grade and notification option chosen. Grade 2 lands on SP2, SP3, DP1, or DP2. Grade 3 lands on SP3, SP4, DP2, or DP3. SP5 and SP6 appear only at Grade 4. An insurer or national scheme pushes it higher. Your designer and your certification body settle it between them.
What the connectivity layer decides is narrower and still worth having: how much of that weekly availability budget you spend, how quickly you learn the path is gone, and whether that reaches your alarm platform and not a portal.
A multi-network SIM does not turn one cellular link into 2 paths in the terms EN 50136 uses. One radio, one antenna, one point of failure.
EN 50136-1 does not name a required technology for the second path. What it does require, for every dual-path category, is a separate alternative network interface at both ends and an alternative receiving centre transceiver. And the availability arithmetic behind the dual-path categories assumes the 2 paths fail independently. 2 radios in one enclosure sharing an antenna and a jammed band are not independent. Whether your national scheme accepts them is a question for your certification body, and in most schemes 2 paths sharing a radio front end will not be treated as diverse.
This is the trade-off most perimeter connectivity content skips, and it decides the design.
Solar and battery power at the boundary push you towards low-power wide-area network bearers such as LTE-M and NB-IoT, and towards power saving mode and long extended discontinuous reception cycles.
Be precise about what sleep does and does not break. A sleeping sensor still raises an alarm quickly, because power saving mode does not stop a device transmitting when its own detector fires. It wakes on its own trigger and sends. What sleep breaks is downlink reachability and the frequent supervision exchange the reporting time depends on, and it stretches transmission time, because waking, re-establishing the radio connection, updating the tracking area, and sending takes seconds on LTE-M and tens of seconds on NB-IoT.
So an installation certified to a short reporting time is effectively always on, and always on is a power budget, which is mains or a much larger solar array.
Most real perimeters end up with 2 device classes, not one. Low-rate detection nodes on LTE-M or NB-IoT, sleeping between reports, sized for battery life. And always-on alarm transmission and verification video on LTE, sized for the reporting time and the availability figure the category requires. Decide which class each device belongs to before you choose a bearer, because the bearer decision is the one you cannot revisit without a van.
For most perimeter work the binding category is SP4 or DP3, at 3 minutes reporting time and 97% or 99.8% availability. That is demanding for a sleeping device and achievable for an always-on one.
Worth saying plainly: NB-IoT will not carry verification video, and LTE-M carries it marginally at best. Anything doing visual verification belongs in the always-on class.
If loss of path is reported in 3 minutes, an attacker has 3 minutes of quiet before the operator treats the absence as an incident. If it is reported at the next billing reconciliation, they have a day.
A word on what the network does and does not know, because this gets stated wrongly. When a device uses power saving mode, the core negotiated the timers. It knows the device is asleep, knows when it is due back, and buffers downlink traffic against a known reachability window. A jammed device looks different, because it misses the periodic tracking area update the core was expecting. The 2 cases are distinguishable.
What confuses them is the dashboard. Most connectivity platforms show only recent data activity and never surface the negotiated sleep window, so a scheduled sleep and an unscheduled silence render identically. If you intend to use session state as a security signal, the platform has to tell those apart.
The IXT CMP, IXT's connectivity management platform, updates connectivity status, session data, and network events in near real-time, with an API so the same signal reaches your alarm platform instead of sitting in a portal somebody has to remember to open. Its rules engine acts on connectivity drops directly. Set the threshold and a lost session raises an alert or triggers an action, without anyone watching a dashboard at 02:00. The same engine acts on changes to the International Mobile Equipment Identity, which is the connectivity-layer answer to a SIM being pulled out of a sensor and put into something else.
Underneath it, IXT runs its own mobile core, built for IoT from the ground up and not virtualised on shared infrastructure, reaching 600+ mobile networks across 190+ countries. That is what makes multi-network reach and the routing controls below possible in the first place.
There are 2 limits worth stating plainly.
CMP is not a certified alarm transmission system. The transmission category of your installation is a property of the alarm equipment and the path design, not of the SIM.
And a connectivity session view is not a supervision poll between the alarm transmitter and the receiving centre. A device in power saving mode keeps its session and its IP address but sends nothing and answers nothing, so on a usage-driven view it looks silent while working perfectly. Use CMP as a second, independent signal about the path. Do not use it as a substitute for the supervision your transmission category requires.
| Requirement | Why perimeter work differs | What to specify |
|---|---|---|
| Coverage along a line, not at a point | The weakest stretch defines the perimeter | Multi-network access, subject to roaming agreements in that market, and a survey that walks the boundary instead of sampling the gate |
| Weekly availability inside the category budget | SP6 allows 20 minutes of downtime a week | Several reachable operator networks per site, on a core that controls routing directly |
| Fast detection of a lost path | Silence is either a fault or an intrusion in progress | Near real-time status by API, rules that fire on a dropped session, and a platform that separates scheduled sleep from unscheduled silence |
| Bandwidth at the moment of an alarm | Verification clips are bursty and unpredictable | LTE Cat-1 or above for live visual verification, or edge buffering and clip upload to keep LTE-M viable, plus a shared data pool with alerting |
| Long battery life on detection nodes | Solar and battery at the boundary | LTE-M or NB-IoT, confirmed available in the specific markets, on devices that do not need fast reporting |
| Traffic that does not cross the public internet | Detection data is sensitive by nature | IXT SecureNet private APN routing directly to your systems |
| Containment when one node is compromised | A sensor controller is a foothold, not a target | IXT Zero Trust policy-based segmentation and traffic mapping across IXT-connected devices |
| Controlled vendor access | Detection controllers get serviced by their manufacturer | Privileged Remote Access: brokered, time-limited, recorded sessions scoped to one device |
Perimeter detection produces alarms that need confirming, and every detection technology has its own nuisance sources. Fence-mounted sensors respond to wind, rain and hail, loose fabric, and vibration from nearby road or rail. Buried cable is far less wind-sensitive but not immune, because trees inside the detection volume transmit root movement into the soil, and it also responds to burrowing animals, saturated ground, freeze-thaw changing the coupling, and vehicles passing close by. Microwave barriers are troubled by standing water and snow in the beam and by vegetation growing into it. Active infrared beams suffer in fog, snow, and blowing dust. Radar picks up wind-moved vegetation, birds, and small animals as well as rain clutter and multipath. Thermal analytics degrade in fog, lose contrast under strong solar loading, and fail hardest at thermal crossover, around dawn, dusk, and immediately after rain, when target and background sit at similar apparent temperature. Taut wire is the low-nuisance option and gets specified for exactly that reason.
Every one of these is a trade between probability of detection and nuisance alarm rate, and the usual way to hold both is 2 dissimilar technologies with confirmation logic between them.
Confirmation is not only video. Sequential confirmation from 2 independent detectors and audio verification both qualify, and both cost a fraction of the bandwidth, which matters on a perimeter where 2 dissimilar sensors already cover the same stretch. Where visual verification is specified, it means retrieving a short clip spanning the moment the sensor fired, from the seconds before it as well as after, because the frames that answer the question come first. That is a bounded clip upload at an unpredictable moment, on a site that spends most of its life reporting almost nothing.
Per-SIM data allowances handle that badly. A fence-mounted sensor beside a treeline in a windy autumn generates far more activations, and far more verification traffic, than the same sensor beside a car park. Under per-SIM caps, the sensor that has had the busiest month runs out of allowance first, so the noisiest part of your perimeter is the part that goes quiet.
A shared pool across the fleet removes that specific failure, because the busy sensor draws on headroom the quiet ones are not using. The trade-off is worth naming out loud: an exhausted pool affects every SIM on it. On a security perimeter that means sizing the pool above the worst month you have recorded rather than the average one, and wiring the pool threshold alerts into the same monitoring as the sensors. There is more on how pooling works in How shared data pools cut global IoT costs.
Perimeter detection generates a map of your boundary: where sensors sit, which stretches activate, and what the site looks like at the moment of an alarm. That is the material an attacker would like to have before choosing a crossing point.
The SIM identifies the device to the network. IXT SecureNet routes its traffic through a private APN and dedicated tunnels straight into your systems or cloud environment, so it never touches the public internet.
A private APN isolates traffic. It does not encrypt it, does not authenticate the session, and unless device-to-device traffic is explicitly blocked it leaves compromised equipment able to address its neighbours. Isolation is not segmentation.
IXT Zero Trust validates every session through Zscaler ZTNA, and IXT has been Zscaler's named partner for Zscaler Cellular since July 2025. Illumio maps the traffic and applies policy-based segmentation across IXT-connected devices. A compromised sensor controller reaches its own management platform, and for most deployments nothing else. Zero Trust is IXT's standard security offering. SecureNet on its own is the lighter option for deployments that choose not to take it.
Vendor access lands here too. Perimeter intrusion detection system (PIDS) controllers, radar units, and thermal cameras get serviced by the companies that made them, and a VPN gives each of those companies a route onto the network carrying your perimeter data. Privileged Remote Access replaces that with a browser session scoped to one device, time-limited and recorded, with no client on the controller and none on the engineer's machine. The App Connector initiates the outbound connection from inside your environment, so nothing at the perimeter has to listen for an inbound one. We covered the mechanics in The devices you installed to watch the site are among the riskiest on the network.
Perimeter sites in energy, transport, water, and digital infrastructure sit inside sectors NIS2 covers. NIS2 places personal liability at board and C-suite level, and Zero Trust is one of the technical measures that demonstrates control.
IXT Zero Trust addresses NIS2 Article 21(2) technical controls: access control, network segmentation, incident detection, supply chain access, audit trail, and continuous authentication. Incident detection is the one connecting most directly to everything above, knowing that a device stopped reporting, when it stopped, and what happened on it beforehand. What stays with you is the risk documentation, the incident response plan, staff training, and supplier governance. No connectivity product certifies NIS2 compliance. The full mapping is in IXT Zero Trust and EU compliance: NIS2 and the Cyber Resilience Act.
A fair objection: if the nearest responder is a 40-minute drive from an unmanned substation, what does a 3-minute reporting time get you?
It buys 3 things. A timestamped, attributable event instead of an unexplained gap discovered at the next service visit. A receiving centre that starts a decision instead of a reconstruction. And the record that NIS2 incident detection and every post-incident review will ask for, showing what stopped reporting and when.
It changes what the person driving knows before they arrive, and whether anyone is driving at all.
Substations, reservoirs, and treatment works are unmanned, distributed, and inside NIS2 sectors. Boundaries are long and response is a drive away, which puts the weight on detection quality and on knowing quickly.
Boundaries run for kilometres across varied terrain, cross operator coverage boundaries, and in border regions cross national ones. Coverage along the line is the whole problem. Permanent roaming rules make a cross-border corridor a connectivity question as much as a security one, and IXT supports local IMSI options in key markets to reduce permanent roaming risk.
Companies building fence sensors, radar units, and thermal towers ship into markets across Europe and beyond and cannot negotiate a carrier agreement in each one. One SIM reaching 600+ networks in 190+ countries on a single contract removes an installation step and a support call. IXT also supports manufacturers preparing for the Cyber Resilience Act, though conformity assessment and vulnerability reporting stay with the manufacturer.
A building is a single location surveyed once. A perimeter is a line running for kilometres, and coverage has to hold along all of it because an intruder selects the weakest stretch. Perimeter devices also sit where mains power and fixed lines run out, which forces solar or battery operation and constrains which cellular bearers are usable.
Radio denial works against any cellular device, which is why EN 50136 specifies how fast a lost path must be reported instead of assuming the path holds. Detection time, not prevention, has always been the control. Commodity jammers are specified by frequency range rather than by operator and cover the whole span European networks sit in, so multi-network access is not a defence against deliberate jamming. It is the answer to the coverage notches and operator outages that consume a category's weekly availability budget.
EN 50136-1:2012+A1:2018 is the European standard for alarm transmission systems, the path carrying alarms from a protected site to an alarm receiving centre. It defines SP1 to SP6 for single path and DP1 to DP4 for dual path, and classifies each on reporting time, availability, transmission time, and security. Table 3 sets maximum reporting times: single path runs from 32 days at SP1 to 20 seconds at SP6, with SP4 at 3 minutes and SP5 at 90 seconds. Weekly availability targets are 97% at SP4, 99% at SP5 and DP2, and 99.8% at SP6, DP3, and DP4.
It follows from the security grade. The risk assessment sets the grade under EN 50131-1, and Table 10 of that standard gives the minimum ATS category for the grade and notification option chosen. Grade 2 lands on SP2, SP3, DP1, or DP2. Grade 3 lands on SP3, SP4, DP2, or DP3. SP5 and SP6 appear only at Grade 4. Insurers and national schemes push the requirement higher, and your designer and certification body settle it between them.
No. One radio and one antenna is a single path no matter how many operator networks the SIM reaches. EN 50136 does not name a required technology for a second path, but every dual-path category requires a separate alternative network interface at both ends and an alternative receiving centre transceiver, and the availability arithmetic assumes the 2 paths fail independently. 2 radios sharing an antenna and a jammed band do not.
Not while it sleeps, though the reason is narrower than it sounds. Power saving mode does not stop a device transmitting when its own detector fires, so an alarm still gets out. What sleep breaks is downlink reachability and the frequent supervision exchange the reporting time depends on, and it stretches transmission time. Most perimeters split into sleeping detection nodes and always-on alarm transmission for that reason.
Yes. The core negotiated the power saving mode timers, knows when the device is due back, and buffers downlink traffic against a known reachability window. A jammed device misses the periodic tracking area update the core was expecting. What obscures the difference is the dashboard, because most connectivity platforms show only recent data activity and never surface the negotiated sleep window. If you plan to use session state as a security signal, check that the platform separates the 2.
Perimeter sensors generate unpredictable bursts of verification traffic, and activation rates vary along a boundary depending on vegetation, weather, and wildlife. Under per-SIM allowances the busiest stretch exhausts its data first, so the noisiest part of the perimeter goes quiet exactly when it is producing the most alarms. A shared pool lets busy devices draw on the headroom of quiet ones, with the caveat that an exhausted pool affects every SIM on it, so size it above the worst month you have recorded and alert on the threshold.
If you run perimeter detection across unmanned sites in a sector NIS2 covers, 2 things are worth settling before anything else: the coverage survey walked along the boundary, and the weekly availability your transmission category demands.
The cheapest way to test both is to put SIMs at the weakest stretch you already know about and watch what the platform and the API report as you walk a device out of coverage. Request trial SIMs and try it.