← Cybersecurity & OT Security Studio
Concept Explainer · Physical Security

Fail-Safe vs. Fail-Secure

Why a door's "failure mode" is a real design decision, not an accident — and why the same building routinely uses both.

Every electronically controlled door has to answer one question that has nothing to do with normal operation: what should it do when power, the network link, or the access control panel itself is lost? There are exactly two possible defaults, and picking between them is a deliberate tradeoff between two things that are both, in the abstract, "security" — keeping people safe, and keeping an area protected. Which one wins during a failure isn't a matter of opinion. On many doors, it's dictated by fire and building code. On others, it's a conscious risk decision made by whoever designed the access control system.

The Setup

Two failure modes, two different things protected

Fail-safe means that when power or control signal is lost, the locking mechanism defaults to unlocked. An electronic door lock wired fail-safe releases the moment power drops — during a fire, a general power outage, or a control-panel failure — so people inside can get out even though the access control system driving it is dead. It prioritizes life safety over access security at the exact moment things are going wrong. Fail-secure (also called fail-locked) is the opposite default: on loss of power or control, the mechanism stays locked. A door wired fail-secure can't be opened just by cutting its power, so it prioritizes asset and area protection over convenient egress during that same failure. Neither behavior is a bug — both are the mechanism doing exactly what it was engineered to do.

Same event, two designed-in outcomes

Power lost
FAIL-SAFEfire / power lossdoor releases — occupants evacuateprotects: people, during a fireFAIL-SECUREdoor stays shutpower cutentry attempt blockedprotects: the asset, from a power-cut attack
Fail-safe: on power loss
Unlocks
Typically required on designated egress paths — main exits, stairwell doors — so a dead system never traps occupants during a fire.
Fail-secure: on power loss
Stays locked
Used on non-egress, high-value interior spaces where cutting power to unlock a door must never be a viable attack.

One building, both failure modes — chosen door by door

Realistic layout
SERVER ROOMFAIL-SECUREstays locked on power loss(asset protection)open office floorMAIN EGRESS DOORFAIL-SAFEunlocks on power loss(life safety / code-required)both doors wired through the same access control system — the failure mode is set per door, not site-wide
Main egress door
Fail-safe
Chosen because it's a designated means of egress — trapping occupants here during a fire is a code violation, not a security win.
Server room door
Fail-secure
Chosen because it's not an egress path and holds high-value assets — a power cut must not be a way in.
Why this works

The failure mode isn't a security setting. On many doors, it's a code requirement — and it's decided door by door, not site-wide.

Building and fire codes (NFPA 101 Life Safety Code, the International Building Code, and the local fire marshal's interpretation of them) typically mandate fail-safe operation on designated means of egress — the doors people are legally supposed to be able to exit through — specifically because a locked exit during a fire is one of the deadliest and most preventable failure modes a building can have. Those doors are usually also wired to release automatically on fire-alarm activation, independent of the access control system. High-security, non-egress spaces run the opposite calculation: if the door only protects an asset rather than a person's escape route, letting an attacker unlock it for free by pulling a breaker or cutting a cable is the greater risk, so it's specified fail-secure. A real facility routinely does both— main exits and stairwell doors fail-safe, a server room or vault fail-secure — all wired through the same access control platform, with the failure mode set per door hardware and per door's actual risk profile, not chosen once for the whole building.

Common misconception
"A secure building should have all its doors fail-secure — locked on power loss is obviously 'more secure.'"

This is false, and on a primary egress route it's a real, serious life-safety code violation risk. Fires are one of the most common causes of building power loss — and a fail-secure door on a designated fire-exit route means occupants can be physically trapped inside during exactly the event they most need to escape. That's precisely why fire and life-safety codes typically mandate fail-safe operation on egress doors, regardless of how security-conscious the rest of the facility is. "More secure" framing only applies to non-egress, asset-protection doors — a server room, a vault, an evidence room — never to a route someone is depending on to get out. Confusing the two isn't a stricter security posture; on an exit door, it's a code violation waiting to become a fatality.

Related Reading
Identity & Access Management (IAM): MFA, RBAC & Least Privilege
Read it →
Maglocks vs. Electric Strikes — Why Hardware Choice Dictates Failure Mode
Coming soon

Fail-Safe vs. Fail-Secure — Concept Explainer

Explains the two possible failure modes for an electronically controlled door — fail-safe (unlocks on power/control loss, prioritizing life safety) and fail-secure (stays locked on power/control loss, prioritizing asset protection) — and why real facilities deliberately mix both across a single building rather than picking one policy site-wide.

Why This Is Commonly Misunderstood

It's tempting to treat "locked" as the universally safer default and assume a well-secured facility should keep every door fail-secure. That reasoning ignores that a door's failure mode has to answer two competing questions at once: does it protect the people who need to get through it, or the asset/area behind it? On a designated exit route, those two goals point in opposite directions during a power loss, and life safety wins by code, not by preference.

How Codes Decide It For You

Fire and building codes — NFPA 101 (Life Safety Code), the International Building Code, and the local Authority Having Jurisdiction's interpretation of them — typically mandate fail-safe operation on designated means of egress: main exits, stairwell doors, and other paths occupants are required to be able to use to leave the building. Those doors are usually also tied into the fire alarm system so they release on alarm activation independent of the access control platform itself. Non-egress doors protecting high-value or sensitive areas — server rooms, vaults, evidence rooms, some detention spaces — are not egress paths, so the code pressure reverses: they're frequently specified fail-secure so that cutting power can't be used as a way to force entry.

Why the Same Building Uses Both

Because the decision is made door by door based on that door's actual risk profile, not once for the whole site. A hospital, office building, or industrial facility will typically run every designated exit fail-safe while running specific interior high-value rooms fail-secure — all wired through the same access control panel, with the failure mode set per door hardware (an electric strike can usually be configured either way; a magnetic lock is inherently fail-safe by nature, since removing power removes the magnetic holding force) and per local code requirement for that specific opening.

Frequently asked questions

Is fail-safe or fail-secure "more secure" overall?

Neither, in the abstract — it depends entirely on what that specific door is protecting. Fail-safe protects the people who need to exit through it during a failure; fail-secure protects the asset or area behind it from a power-cut attack. The right choice is a per-door risk decision, and on egress paths it's usually not a choice at all — code dictates fail-safe.

Do fire codes require fail-safe operation on exit doors?

Generally, yes. Designated means of egress — main exits, stairwell doors, other legally required exit paths — are typically required by life-safety and building codes (e.g., NFPA 101, the IBC, and local AHJ interpretation) to unlock on power loss and on fire alarm activation, because trapping occupants behind a locked door during a fire is one of the failure modes those codes exist to prevent.

Can one building legitimately use both fail-safe and fail-secure doors?

Yes, and it's the normal case in practice, not an exception. A single access control system commonly drives fail-safe hardware on egress doors and fail-secure hardware on non-egress, high-security interior doors like a server room or vault, with the failure mode configured independently for each opening.

Does a magnetic lock behave differently from an electric strike here?

Yes. Electromagnetic locks (maglocks) are inherently fail-safe — removing power removes the magnetic holding force, so they release with no other wiring required. Electric strikes can be manufactured and wired as either fail-safe or fail-secure, which is why the specific strike model and wiring matter when a door's required failure mode is being specified.

Does "fail-secure" mean the door is always locked and unusable during normal operation?

No. Fail-secure only describes what happens on loss of power or control signal. Under normal operation, a fail-secure door still unlocks for valid credentials exactly like any other access-controlled door, and it must still be openable from the inside via request-to-exit hardware or panic hardware as required by code — fail-secure is not a substitute for meeting egress requirements.

🎓

Try our Cybersecurity Studio

More calculators, simulators, and guides for this discipline.

Related tools & guides

Identity & Access Management (IAM) GuideIndustrial Cybersecurity ReferenceNIST CSF 2.0 Assessment Tool