Skip to content

Physical Access Facilitation

Physical access facilitation influences people or physical-security processes to admit a person, permit movement, expose an asset or enable interaction with a controlled environment. The attacker may be physically present, act through another person, or use a remote request to influence an onsite access decision.

Physical access may be the immediate objective or may enable later theft, reconnaissance, technical access, disruption or information exposure. A plausible role, badge, uniform, delivery, work order, sponsor name, or familiar routine can make presence appear expected without establishing the person’s authority or access scope.

Physical access facilitation can be assessed by asking:

  • What space, asset, device, infrastructure, or movement is being requested?
  • Who is making or executing the physical access decision?
  • Are the sponsor, purpose, identity, scope, escort, and custody requirements established?
  • What later technical, operational, or information risk could follow?

Physical Access Facilitation includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.


Physical access facilitation activity may involve one or more of the following behaviours:

Identity and role presentation

  • presenting as a legitimate onsite role, contractor, courier, supplier, technician, cleaner, inspector, visitor, student, parent, or staff member
  • using badges, uniforms, high-visibility clothing, tools, carts, clipboards, delivery items, work orders, or branded material to appear expected
  • claiming sponsorship, approval, appointment, urgency, maintenance need, delivery requirement, or operational responsibility
  • using familiar names, departments, suppliers, sites, classrooms, rooms, or facilities language to reduce scrutiny

Access and movement behaviour

  • following authorised individuals through controlled doors
  • asking someone to hold a door, badge them in, escort them, or “just let them through”
  • bypassing reception, sign-in, sponsor validation, escort requirements, or visitor badge procedures
  • moving through office, school, facility, plant, loading dock, records, comms, or restricted areas without a clear operational purpose
  • attempting to access printers, unattended desks, whiteboards, meeting rooms, classrooms, storage areas, network cabinets, comms rooms, or equipment rooms

Asset, device, and infrastructure behaviour

  • requesting release, pickup, replacement, redirection, or handover of laptops, phones, access cards, badges, keys, documents, tokens, storage media, or networking equipment
  • interacting with unattended workstations, printers, scanners, meeting-room devices, kiosks, or shared endpoints
  • connecting unknown devices to network ports, USB ports, wireless networks, or exposed infrastructure
  • placing, collecting, or encouraging use of USBs, cables, QR codes, access cards, power banks, or other physical artefacts
  • removing equipment, documents, drives, or media from site past exit controls, sometimes using a forged release, a borrowed trolley, or end-of-day and shift-change timing to avoid screening

Pressure and environmental signals

  • using politeness, helpfulness, embarrassment, authority, urgency, familiarity, or operational pressure to reduce challenge
  • exploiting busy periods, school drop-off/pick-up, shift changes, deliveries, incidents, events, cleaning schedules, holidays, or after-hours conditions
  • applying social pressure when challenged, such as irritation, name-dropping, impatience, embarrassment, or “I’m here all the time” framing