A cybersecurity consultancy has highlighted the growing threat posed by physical breaches as a method for gaining unauthorized access to corporate networks, underscoring that traditional cyber defenses may be insufficient without robust physical security.
Jamie Frost, head of a "black team" at the FTSE 250 firm NCC Group, specialises in testing organizational security by attempting to infiltrate offices, warehouses, laboratories, and data centers. His team mimics the tactics of hostile actors seeking to exploit physical vulnerabilities in order to access sensitive information or disrupt operations.
In one recent test, Frost described an incident where he was detained briefly during an infiltration exercise at a warehouse. Despite presenting evidence of limited phone use and cooperating with the security personnel, he was released with a warning after authorities concluded he posed no threat. Frost said this experience marked the closest he had come to being caught in more than a decade of conducting these simulated breaches.
Frost explained that his team's approach involves extensive reconnaissance, both online and on-site, to identify weaknesses. This includes observing employee arrival and departure times, dress codes, and the design of security badges and lanyards. By determining which team members are less likely to attract attention, and when the premises are least monitored, his team identifies opportune moments for entry.
Although many companies employ keycard security systems, Frost noted these measures are frequently vulnerable. His team has successfully acquired company lanyards through resale platforms. More notably, Frost demonstrated how a device costing approximately £200 can clone unencrypted access cards by coming within 12 inches of an employee carrying a keycard for a brief period. This method can replicate multiple cards, enabling unauthorized entry without detection.
Once inside, his team has been able to plant surveillance devices on laptops, access executive offices, and breach cabinets by using simple tools such as lock picks or improvised devices resembling coat hangers to manipulate door locks.
Frost has conducted penetration tests on a variety of facilities, including pharmaceutical research centers, warehouses, and critical data centers. He emphasized that gaining physical access significantly increases the potential for causing damage, as it allows attackers to bypass increasingly sophisticated cybersecurity controls.
The consultancy’s findings underline the importance for companies to strengthen physical security protocols alongside digital defenses to mitigate risks from combined cyber-physical attack vectors.
