Physical Security & Social Engineering
Tailgating, badge cloning, pretexting, and dumpster diving — the foundational, often-overlooked layer of defense in depth that no firewall can substitute for.
Learning Objectives
- → Explain the role of physical security as a foundational layer of defense in depth
- → Identify common physical social engineering techniques
- → Describe physical access controls: mantraps, badge/RFID systems, CCTV, guards
- → Explain the clean desk policy and why it matters
- → Apply a basic physical security walkthrough checklist
Why Physical Security Still Matters
No firewall, encryption scheme, or Zero Trust architecture protects against someone who simply walks in the front door and plugs a device into an open network jack. Physical security is the foundational layer defense in depth is built on top of — a perfectly hardened server is trivially compromised if an attacker can just remove its hard drive.
Physical Social Engineering Techniques
| Technique | How it works |
|---|---|
| Tailgating | Following an authorized person through a secured door without badging in yourself |
| Badge cloning | Copying an RFID badge's credentials using a cheap, portable reader, often without the victim noticing |
| Pretexting | Fabricating a plausible scenario (delivery driver, IT support, new hire) to gain physical or informational access |
| Dumpster diving | Recovering sensitive information (documents, discarded hardware, sticky notes with passwords) from trash |
These techniques exploit the same human trust patterns as email phishing — social engineering conducted in person rather than over email or phone.
Physical Access Controls
| Control | Purpose |
|---|---|
| Badge/RFID systems | Restrict entry to authorized personnel, log who entered where and when |
| Mantrap | A small interlocking chamber allowing only one person through at a time, specifically designed to prevent tailgating |
| CCTV | Detective control — records activity for investigation, and can deter through visibility |
| Security guards | Combine deterrent, detective, and sometimes preventive functions (challenging unrecognized individuals) |
A mantrap is the direct physical-world equivalent of the Zero Trust principle covered earlier: even someone already inside the building doesn't automatically get to bypass the next control.
The Clean Desk Policy
A clean desk policy requires employees to secure sensitive documents, storage media, and login credentials whenever they leave their workstation unattended. It sounds low-tech, but a sticky note with a password on a monitor defeats every technical control protecting that account.
A Basic Physical Security Walkthrough Checklist
- Can someone follow an employee through a secured door without badging in? (tailgating test)
- Are server room / data center doors alarmed and access-logged?
- Are visitor badges clearly distinguishable from employee badges, and are visitors escorted?
- Is sensitive printed material shredded rather than placed in a regular trash bin?
- Are unattended workstations set to auto-lock after a short idle period?
- Are unused network jacks in public areas (lobbies, conference rooms) disabled?
Common Pitfalls
- Treating physical security as "the building's problem" rather than part of the overall security program
- Training staff on email phishing but never on in-person pretexting or tailgating
- Leaving decommissioned hardware (drives, printers with cached documents) unwiped in general trash
- Assuming a badge system alone prevents tailgating — badge systems only work if people actually badge in individually, which a mantrap enforces and open-door courtesy defeats
Tailgating exploits simple human courtesy — holding a secured door open for whoever is behind you.
What is tailgating in a physical security context?
A mantrap enforces one-person-at-a-time entry physically, not just through a policy that people can choose to ignore.
What specific tailgating-prevention purpose does a mantrap serve?
A visible password bypasses every technical control protecting the account it belongs to.
Why can a clean desk policy defeat otherwise-strong technical security controls if ignored?
💪 Exercises & Challenges
Physical Security & Social Engineering MCQ
Test your understanding of Physical Security & Social Engineering.
Conduct a Physical Security Walkthrough
Using the 6-item checklist from the lesson, conduct a walkthrough of your own home or workplace and document your findings for each item, noting at least 2 specific weaknesses found and a recommended
Identify the Physical Social Engineering Techniques
A physical penetration test finds: (1) a tester wearing a hi-vis vest and carrying a clipboard was able to follow an employee through a badge-secured door without ever badging in themselves, (2) disca