Physical Security Meets Cybersecurity: One Team for Both

Your cameras, door controllers, and building systems joined the network years ago, and most org charts still haven't caught up to the fact that physical security and cybersecurity aren't two jobs anymore. Running them as one program is the fastest security upgrade most organizations can make, and here's why.

How Physical Security Became an IT Problem

Access control systems, video surveillance, elevators, HVAC, and building automation all moved onto the IP network, one upgrade cycle at a time. The global count of connected devices passed 21 billion this year and keeps climbing. Every camera is a Linux computer, and every door controller is a small server with keys to the building.

The threat data treats them that way. In Microsoft's analysis of ransomware incidents, over 90% of attacks that reached the encryption stage used unmanaged devices as the entry point or the encryption path. The cameras and controllers nobody patches are the textbook unmanaged device. And the Internet's record-setting DDoS attacks have been powered by exactly this class of hardware for a decade: a 5.6 terabit-per-second attack in late 2024 came from a botnet of roughly 13,000 hijacked devices, most of them cameras and similar equipment.

This isn't a new risk, either. The 2013 Target breach that exposed 40 million payment cards started with credentials stolen from an HVAC contractor with network access. Building systems have been a door into the enterprise for a long time. The difference now is that there are more of them, and the teams responsible for them rarely talk.

The Convergence Numbers

21.1B
Connected IoT devices worldwide
90%+
Ransomware reaching encryption via unmanaged devices
60%+
Organizations with converged security functions
$4.99M
Average cost of a data breach

What Two Silos Cost You

When physical security reports to facilities and cybersecurity reports to IT, three failure modes repeat across mid-market organizations.

Nobody owns the patching. Camera firmware updates aren't in the SOC's remit and aren't in the security integrator's contract. So they don't happen. An unpatched camera with default credentials on a flat network is a foothold waiting for a scanner.

Nobody owns the segmentation. The camera VLAN, the door controller subnet, and the badge system's server shouldn't share a path with payroll. When neither team owns the network policy, the flat network wins because it's the path of least resistance.

Nobody connects the incidents. A door controller that starts sending traffic to an unknown address looks like a nuisance to the security tech and invisible to the SOC. Attackers exploit exactly this gap: the 2019 Threat Landscape for Smart Buildings research found malware on more than a third of the computers running building automation systems across 40,000 monitored buildings. Those detections sat somewhere between two teams.

With the average breach now costing close to $5 million, and more in the U.S., the cheapest control you can add is an org chart that connects the two halves of the attack surface.

What One Team Looks Like

The convergence trend is already majority behavior: by 2022, over 60% of organizations had at least partially merged physical and cyber security functions, up from about a quarter in 2019, and 86% of converged organizations told ASIS Foundation researchers it strengthened their security overall. Mid-market organizations converged faster than enterprises, partly because one leader can actually see both domains.

If you're building toward that model, the working parts look like this:

One architecture. Cameras and controllers get segmented network zones, zero-trust access policy, and the same monitoring discipline as any other device touching the network.

One policy. Device hardening standards, password policy, firmware cadence, and procurement rules, so a new camera can't join the network as a liability by default.

One risk picture. Door controllers, badge systems, and cameras live in the same risk register as firewalls and endpoints. A physical event with a cyber dimension (a door forced open at 3am paired with unusual badge activity) gets one investigation, not two notes in two systems.

One response plan. When a camera is compromised, it's an IT incident that happens to involve hardware in a hallway. Both teams practice it together, before it happens.

Five Questions to Ask This Quarter

  • Who patches your cameras, and can they prove the last date it happened?
  • Who owns the network policy for the camera VLAN and door controllers?
  • Has your SOC ever seen a log from a badge system or a camera?
  • Do your security integrator and IT security vendor have each other's phone numbers?
  • If a door controller was compromised tomorrow, who would investigate it, and would they know?

If these questions have no owners, your attack surface has a seam down the middle, and seams are where breaches live.

Run It as One Program

Gage staff have spent decades on both sides of this line: installing and servicing the cameras, access control, and structured cabling that make up physical security, and running the network and cyber defense they live on. That's one team, one architecture, and no seam for an attacker to live in.

Call (254) 772-3400 or email info@gagetech.com to talk about closing the gap between your two security teams.

Sources and Citations
  • IoT Analytics, 21.1 billion connected IoT devices iot-analytics.com
  • Microsoft Digital Defense Report 2024, 90%+ of ransomware via unmanaged devices microsoft.com
  • Cloudflare Q4 2024 DDoS report, 5.6 Tbps attack from ~13K IoT devices blog.cloudflare.com
  • U.S. Senate Commerce Committee, Target Kill Chain analysis (HVAC contractor entry) commerce.senate.gov
  • Kaspersky ICS CERT, smart building threat landscape ics-cert.kaspersky.com
  • ASIS Foundation convergence research (24% in 2019, 60%+ by 2022, 86% report stronger security) asisonline.org
  • IBM Cost of a Data Breach Report 2026, $4.99M global average ibm.com

Contact us for
a consultation.

Ask Gage AI