When Physical Security Becomes a Cyber Problem: The Convergence You Cannot Ignore

The clean separation between physical security and IT security is gone. It was already blurring a decade ago when IP cameras started connecting to corporate networks. By 2026, the integration is complete — and most organizations are managing it poorly.

The Attack Surface Nobody’s Owning

Access control systems, IP cameras, building management systems, badge readers, intercoms, visitor management kiosks — every one of these is now a network endpoint. Each has firmware that can contain vulnerabilities. Each communicates over the network. Many run on the same internal network as workstations and servers.

The consequences are bidirectional:

Physical breach enables cyber access. An attacker who tailgates into a server room doesn’t need to exploit a vulnerability — they plug in a USB device, use a KVM extender, or physically compromise hardware. An attacker who gains access to a wiring closet can tap network infrastructure directly. Physical access to a network jack in an unsecured conference room is, in many environments, equivalent to VPN access.

Cyber breach enables physical access. A compromised building management system can unlock doors. A compromised access control server can delete badge permissions, add attacker-controlled credentials, or suppress alarms. In documented incidents, attackers have used network access to disable physical security systems before a follow-on physical intrusion.

The Mirai botnet and its successors demonstrated this practically: millions of IP cameras were recruited into DDoS infrastructure because they ran outdated firmware with default credentials. Your parking structure cameras and lobby intercoms are on your network and are maintained by nobody on your security team.

The Legacy Proximity Card Problem

Most commercial buildings still use legacy 125kHz proximity cards (HID Prox, EM4100) for access control. These are trivially cloneable with cheap, pocket-sized hardware. The Proxmark3 can read and write these cards from several inches away. Long-range readers can capture badge data at several feet.

The attack is simple: stand near a target’s bag or pocket, read their badge, write the data to a blank card, and use the cloned badge to access facilities. The cloning takes seconds. The hardware is commercially available and legal to own.

The correct replacement is SEOS or mobile credential systems using Bluetooth Low Energy or NFC with cryptographic authentication. These cards and credentials cannot be passively cloned because the authentication involves a cryptographic challenge-response rather than broadcasting a static ID. The access control market has moved to these standards; many organizations haven’t followed.

Network Architecture for Physical Security Systems

Physical security systems should not share a network segment with IT systems. This is a basic segmentation principle that many organizations violate because it was convenient when the cameras were installed.

Correct architecture:

  • Physical security devices on a dedicated VLAN with no route to corporate systems
  • Physical security management servers isolated from general IT infrastructure
  • Outbound internet access for physical security devices restricted to specific, required destinations only
  • All traffic from physical security systems logged and monitored

This doesn’t solve the problem of a compromised physical security management server being used as a pivot, but it limits lateral movement significantly.

The Organizational Problem

Physical security and IT security typically report to different organizational chains — facilities and IT respectively. Unified threat assessment requires that these functions communicate, share threat intelligence, and coordinate incident response. Most organizations have no process for this.

The minimum viable coordination: a joint vulnerability assessment of physical security infrastructure at least annually, a shared incident response procedure for incidents that span both domains, and IT review of new physical security deployments before they’re connected to any network.

The adversary doesn’t recognize the org chart boundary between physical and cyber. Neither can an effective defense.

Upgrade Your Access Control: NFC and Bluetooth smart locks on Amazon — replace cloneable proximity cards with cryptographically secure access credentials.