Physical security

Perimeter and deterrence

Fences define a boundary, deter, and delay intruders to buy response time. Best for large perimeters. Bollards are sturdy steel or concrete posts against vehicle threats specifically.

Physical brute force takes four shapes: forcible entry (counter with hardened doors and deadbolts), tampering with devices (counter with redundancy), confronting guards (conflict and self-defense training), vehicle ramming (bollards and reinforced barriers).

Surveillance

Four components: video, security guards, lighting, sensors.

Cameras do motion detection, night vision, facial recognition, and PTZ (pan-tilt-zoom to follow an intrusion). Put them at data centers, telecom closets, entrances and exits, and record everything.

The sensor types: infrared (body heat), pressure (weight on a mat), microwave (pulse reflection off movement), ultrasonic (wave reflection).

The bypass methods to know: visual obstruction (paint, tape, objects), blinding with light bursts, acoustic jamming, EMI jamming, and plain physical tampering (cutting wires).

Entry control

An access control vestibule is a double-door where only one opens at a time. It stops piggybacking and tailgating.

The difference: piggybacking has the authorized person’s consent (social engineering); tailgating does not (sneaking through behind them).

Badges use RFID, NFC, or magnetic strips, often with a guard for deterrence, ID checks, and response.

Locks and biometrics

The lock progression: traditional padlocks (weak), then basic locks (pickable), then electronic (PIN, wireless NFC/BT/RFID, biometrics). Cipher locks (numbered push-buttons) guard high-security rooms like server rooms.

Biometric error rates: FAR (false acceptance, lets the wrong person in), FRR (false rejection, blocks the right person), and CER (the crossover error rate, the balance point where FAR = FRR; lower CER means a better system). Raising sensitivity lowers FAR but raises FRR.

Badge cloning

Copying RFID or NFC data to a blank card: scan, extract credentials, write to the new card, use it.

The defenses: encryption on the card system, MFA, updated protocols, user education, shielded sleeves, log auditing.