All posts

Physical security is IT security: bringing IAM, the SOC, and the zone model together

OT technician at security dashboards in a factory – Physical security is IT security

Most security strategies start at the login and stop at the front door. Access control, video surveillance, and the server room are considered facility management, not part of IT security. That is a fallacy: nearly every serious attack has a human and often also a physical touchpoint somewhere. Anyone who excludes this layer is defending their network with an open flank. Bringing IAM, the SOC and the zone model together closes exactly this gap.

Where physical and digital attacks interlock

The transitions are more fluid than separate responsibilities would suggest. An unauthorized person who slips through the gate behind someone with a badge (tailgating) suddenly stands in front of freely accessible network equipment. A rigged USB device or a mini computer planted at the switch provides persistent access. Backup media lying openly on a shelf are a complete copy of your data. And the site badge of a contractor who left long ago often still opens doors months later.

• Tailgating and following others through secured areas
• Tampering with freely accessible network and server hardware
• Smuggled-in foreign devices (USB, rogue devices)
• Unprotected backup media and storage devices
• Still-valid badges and accounts of departed personnel

Defense in depth starts at the door

The principle of layered defense has long been established in IT, but it does not end at the firewall. Every additional physical layer raises the effort for attackers and the likelihood that an attempt gets noticed. What matters is that IT security, facility management, and external specialists work on a shared architecture with clearly assigned roles, instead of operating side by side. Physical and logical controls have to speak the same language.

IAM: one identity model for door and login

The biggest lever lies in controlling physical entry and digital access through the same identity. When a person is onboarded, transferred, or leaves the company (joiner-mover-leaver), building access and system rights should change automatically and in sync. An offboarding that deactivates the Active Directory account but forgets the site badge is only half done. Role-based assignment following the least-privilege principle, for doors as for applications, ensures that people only get to where they belong.

SOC: analyzing physical and logical events together

The connection becomes truly valuable when a security operations center correlates both event streams. Only in combination do anomalies emerge that remain inconspicuous on their own: a system login without anyone having entered the building beforehand. Simultaneous entries by the same identity at two sites. Access outside usual hours. Repeatedly failed badge attempts at a sensitive door. Such patterns are strong early indicators, but only if entry and login data come together in the same analysis.

The zone model: four layers, graduated controls

A proven organizing model divides premises into four security zones with increasing requirements:

• Zone 1 (public): reception and visitor areas, identity check at the entrance.
• Zone 2 (internal): employees only, personalized access and logging.
• Zone 3 (sensitive): only for explicitly authorized persons, multi-stage or biometric control.
• Zone 4 (high security): server room and core, multi-factor entry, minimal set of people, complete recording.

The appeal lies in the consistency: the deeper a zone, the stricter the control, and the tighter the coupling to the digital authorization.

Compliance turns this into an obligation

What is good practice is increasingly becoming a requirement. NIS-2 raises the baseline cybersecurity requirements across Europe and explicitly includes physical security. The BSI IT-Grundschutz, the KRITIS requirements for critical infrastructure, and TISAX (especially in the automotive and supplier industry) demand essentially the same thing: systematic risk assessment, documented entry and access controls, and audit readiness at all times. Documenting physical and digital controls separately produces gaps that stand out in an audit.

Consider data protection from the start

Entry logs, video recordings, and biometric characteristics are personal data, some of it particularly sensitive. A sound architecture defines clear purposes, limits retention periods, restricts access to what is necessary, and informs employees and visitors transparently. The proportionality principle is a quality marker here: taking it seriously delivers security and GDPR compliance together.

Our view at KAEMI

Physical security is not a facility-management cost item but part of a resilient, auditable security governance, especially in hybrid environments where edge and on-premises systems remain your responsibility. We think about entry and access identity-centrically: Zero Trust principles, network microsegmentation, and SASE/SSE ensure that one breached door does not open the entire network. Aligned with your requirements, we connect the physical with the digital layer, from the zone logic to event correlation in the SOC. Get in touch if you want to bring both worlds together into one architecture.

Want to stop lateral movement before an incident spreads?

KAEMI designs, implements and manages Zero Trust segmentation down to the workload — from the dependency map to the managed service.