Insights

Physical Security - Cybersecurity’s Older and Wiser Brother  

Author:

Richard Mason

When people discuss security, the conversation often shifts to digital threats. Ransomware, zero-day vulnerabilities, AI-driven attacks, and state-sponsored threat actors dominate headlines, budgets, and boardroom discussions. This focus is understandable, as organisations and the broader security industry increasingly prioritise defending networks, applications, and data against threats that originate from behind keyboards and screens.  

However, security is not solely a digital concept. Long before computers existed, people were protecting buildings, information, and each other using principles we now recognise as modern cybersecurity theory. For example, a locked door represents access control, while a guard checking identification is a form of authentication. Restricting access to specific rooms aligns with the principle of least privilege, and a building with multiple locked doors between the entrance and the server room exemplifies defence in depth. The physical security industry was applying ‘Zero Trust’ principles long before the term became popular; cybersecurity did not create these concepts but inherited them.  

There is often a natural inclination towards newer technologies, whether because they are exciting, funding-friendly, or simply easier to advocate for than basic security measures. Take the current race towards AI as an example. In contrast, fundamental safeguards, such as a guard checking IDs or a locked filing cabinet, can be easily overlooked, dismissed as trivial, or considered low risk. However, security fundamentals remain crucial, even if they may no longer feel exciting; they are what make advanced controls valuable in the first place. There is little benefit in hardening a network if someone can walk straight into the server room unchallenged.  

So, why do basic physical security practices often become an afterthought in the rush to defend against digital threats? This is a question I frequently reflect on during onsite client engagements, where I observe the same patterns. Security fundamentals are taught but not always enforced. Doors to restricted areas are propped open for convenience or simply because closing them feels impolite. Visitor passes exist, yet they often consist of nothing more than a lanyard with a paper tag reading “visitor,” allowing unfamiliar faces without one to go unchallenged. Laptops are sometimes left unlocked and unattended.  

Security does not occur solely within networks and computers; it also takes place in offices, data centres, and everyday interactions. 

AI doesn’t stop someone walking through the door 

The cyber security industry has always been attracted to the next big solution, and it sometimes feels as though vendors are racing to position AI as the answer to every security problem. Before AI, we saw the rise of cloud security, Zero Trust, EDR, and many other technologies that promised to solve the biggest challenges facing IT teams. 

Each of these technologies provide significant value. However, problems arise with the assumption that a new tool removes the need for good security fundamentals.  

An organisation can have the most advanced AI-powered security platform available, but it will not prevent: 

  • Someone tailgating an employee through a secure entrance 
  • A visitor accessing an area they should not be in 
  • An unattended laptop containing sensitive information being taken 
  • Confidential documents being left exposed 
  • Poor security decisions due to a lack of awareness  

These are not failures that require more advanced technology. They require better processes, stronger security culture, and people who understand their role in protecting organisational data and assets. 

The human element remains critical 

As a penetration tester, I spend a lot of time assessing how organisations can be compromised. Many client discussions naturally focus on vulnerabilities, misconfigurations, authentication and authorisation mechanisms, and defensive technologies. These are all important, however, it shouldn’t be forgotten that security is rarely defeated by technology alone. Often, attackers succeed because organisations fail to get the fundamentals right. 

Attackers look for the weakest point in the overall security chain. This could be a software vulnerability, misconfigured system or a weakness in the supply chain. Sometimes it is a human interaction or a physical opportunity. 

People are often described as an organisation’s biggest security weakness, which may be true in certain contexts. But this misses the point that people can also be one of the strongest security controls within an organisation. 

Employees who understand why security matters, are far more likely to question unusual behaviour, challenge unfamiliar individuals and report suspicious activity. The goal is not to create a culture of suspicion or encourage employees to view everyone as a potential threat. It should be to create a culture where security awareness is second nature. 

Physical security and cybersecurity work together 

Physical and cybersecurity should never be viewed as separate disciplines. They protect different aspects of the same organisation. Cybersecurity protects systems, networks, applications, and digital data. Physical security protects the environments, equipment, people and physical data. 

A security programme can have strong identity controls, advanced monitoring, and sophisticated threat detection, but if someone can gain unauthorised physical access to critical areas, many of those controls lose their effectiveness. This is why mature security programmes combine both approaches. 

Security cameras, access control systems, visitor management, security monitoring, vulnerability management, penetration testing and red teaming, as well as employee awareness all aim to contribute to the same goal, reducing risk. 

Physical security doesn’t need to be complicated 

Improving physical security does not always require expensive technology. Often, the biggest improvements come from reviewing basic processes and behaviours: 

  • Review who has access to sensitive areas 
  • Encourage employees to challenge unfamiliar individuals in an appropriate manner 
  • Ensure visitor procedures are consistently followed 
  • Include physical security in security awareness training 
  • Review how devices, documents, and sensitive information are handled 
  • Conduct regular physical security assessments alongside technical assessments

The same way organisations cannot rely on a single security tool to protect their network, they cannot rely on a single physical control to protect their environment. 

Don’t let the AI fog cloud the basics 

AI provides a significant opportunity to improve how security teams work and how organisations identify and protect against threats. But AI should be viewed as an enhancement, not a replacement for good security professionals and practices. Strong passwords, patch management, regular security testing, security awareness training and physical security controls still matter. 

The organisations that are the most resilient are not always the ones with the most advanced technology. They are the ones that understand security is a combination of technology, people, processes, and physical protections working together. It is important to remember that the strongest firewall in the world cannot protect an organisation if an attacker can walk through the front door. 

Put your physical security to the test 

Physical security is not old fashioned, it is the foundation. The technologies we use have changed, but the principles have not. Organisations should embrace AI, automation and modern cybersecurity practices. But they should do so while remembering that security has always been about understanding risk, controlling access and building layers of protection. 

The strongest security programmes do not choose between physical and cybersecurity. They recognise that both are essential. 

At Pentest, our physical social engineering and red teaming engagements are designed to test those fundamentals. We help organisations understand whether their physical controls, processes and people can stand up to real-world attack scenarios. If you would like to understand how resilient your organisation really is, we would love to talk. 

Looking for more than just a test provider?

Get in touch with our team and find out how our tailored services can provide you with the cybersecurity confidence you need.