Physical security
Perimeter and deterrence
Fences define a boundary, deter, and delay intruders to buy response time. Best for large perimeters. Bollards are sturdy steel or concrete posts against vehicle threats specifically.
Physical brute force takes four shapes: forcible entry (counter with hardened doors and deadbolts), tampering with devices (counter with redundancy), confronting guards (conflict and self-defense training), vehicle ramming (bollards and reinforced barriers).
Surveillance
Four components: video, security guards, lighting, sensors.
Cameras do motion detection, night vision, facial recognition, and PTZ (pan-tilt-zoom to follow an intrusion). Put them at data centers, telecom closets, entrances and exits, and record everything.
The sensor types: infrared (body heat), pressure (weight on a mat), microwave (pulse reflection off movement), ultrasonic (wave reflection).
The bypass methods to know: visual obstruction (paint, tape, objects), blinding with light bursts, acoustic jamming, EMI jamming, and plain physical tampering (cutting wires).
Entry control
An access control vestibule is a double-door where only one opens at a time. It stops piggybacking and tailgating.
The difference: piggybacking has the authorized person’s consent (social engineering); tailgating does not (sneaking through behind them).
Badges use RFID, NFC, or magnetic strips, often with a guard for deterrence, ID checks, and response.
Locks and biometrics
The lock progression: traditional padlocks (weak), then basic locks (pickable), then electronic (PIN, wireless NFC/BT/RFID, biometrics). Cipher locks (numbered push-buttons) guard high-security rooms like server rooms.
Biometric error rates: FAR (false acceptance, lets the wrong person in), FRR (false rejection, blocks the right person), and CER (the crossover error rate, the balance point where FAR = FRR; lower CER means a better system). Raising sensitivity lowers FAR but raises FRR.
Badge cloning
Copying RFID or NFC data to a blank card: scan, extract credentials, write to the new card, use it.
The defenses: encryption on the card system, MFA, updated protocols, user education, shielded sleeves, log auditing.