Physical Access Facilitation
Physical access facilitation influences people or physical-security processes to admit a person, permit movement, expose an asset or enable interaction with a controlled environment. The attacker may be physically present, act through another person, or use a remote request to influence an onsite access decision.
Physical access may be the immediate objective or may enable later theft, reconnaissance, technical access, disruption or information exposure. A plausible role, badge, uniform, delivery, work order, sponsor name, or familiar routine can make presence appear expected without establishing the person’s authority or access scope.
Physical access facilitation can be assessed by asking:
- What space, asset, device, infrastructure, or movement is being requested?
- Who is making or executing the physical access decision?
- Are the sponsor, purpose, identity, scope, escort, and custody requirements established?
- What later technical, operational, or information risk could follow?
Techniques
Section titled “Techniques”Physical Access Facilitation includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.
- SE-T014.001Tailgating & PiggybackingEntering a controlled area through another person’s authorised access, whether unnoticed or with that person’s assistance.
- SE-T014.002Badge, Uniform & Physical Identity MimicryUsing badges, uniforms, tools, equipment, or other visual identity cues to make a physical role appear legitimate.
- SE-T014.003Gatekeeper Access ManipulationInfluencing a person who controls or administers physical entry to admit, badge, escort, or otherwise grant access without the required verification or authorisation.
- SE-T014.004Asset & Device Access FacilitationInfluencing a person to permit temporary handling, proximity, viewing, or use of a device, document, token, key, badge, or other asset while it remains within the controlled environment.
- SE-T014.005Restricted Area ProbingMoving through or testing access to internal areas beyond the person’s authorised scope to identify where challenge, barriers, or stronger controls occur.
- SE-T014.006Environmental BlendingBlending into expected operational or physical environments to avoid scrutiny.
- SE-T014.007Physical Security Process ExploitationExploiting weak visitor management, access control, badge issuance, or exception procedures.
- SE-T014.008Network & Infrastructure Access FacilitationInfluencing a person or physical-access process to permit connection, placement, or interaction with network ports, communications equipment, access-control infrastructure, shared endpoints, or other technical systems.
- SE-T014.009Asset Egress & Release ManipulationInfluencing a person or process to hand over, sign out, redirect, collect, or remove an asset without the required identity, authority, destination, or custody checks.
Behavioural Indicators
Section titled “Behavioural Indicators”Physical access facilitation activity may involve one or more of the following behaviours:
Identity and role presentation
- presenting as a legitimate onsite role, contractor, courier, supplier, technician, cleaner, inspector, visitor, student, parent, or staff member
- using badges, uniforms, high-visibility clothing, tools, carts, clipboards, delivery items, work orders, or branded material to appear expected
- claiming sponsorship, approval, appointment, urgency, maintenance need, delivery requirement, or operational responsibility
- using familiar names, departments, suppliers, sites, classrooms, rooms, or facilities language to reduce scrutiny
Access and movement behaviour
- following authorised individuals through controlled doors
- asking someone to hold a door, badge them in, escort them, or “just let them through”
- bypassing reception, sign-in, sponsor validation, escort requirements, or visitor badge procedures
- moving through office, school, facility, plant, loading dock, records, comms, or restricted areas without a clear operational purpose
- attempting to access printers, unattended desks, whiteboards, meeting rooms, classrooms, storage areas, network cabinets, comms rooms, or equipment rooms
Asset, device, and infrastructure behaviour
- requesting release, pickup, replacement, redirection, or handover of laptops, phones, access cards, badges, keys, documents, tokens, storage media, or networking equipment
- interacting with unattended workstations, printers, scanners, meeting-room devices, kiosks, or shared endpoints
- connecting unknown devices to network ports, USB ports, wireless networks, or exposed infrastructure
- placing, collecting, or encouraging use of USBs, cables, QR codes, access cards, power banks, or other physical artefacts
- removing equipment, documents, drives, or media from site past exit controls, sometimes using a forged release, a borrowed trolley, or end-of-day and shift-change timing to avoid screening
Pressure and environmental signals
- using politeness, helpfulness, embarrassment, authority, urgency, familiarity, or operational pressure to reduce challenge
- exploiting busy periods, school drop-off/pick-up, shift changes, deliveries, incidents, events, cleaning schedules, holidays, or after-hours conditions
- applying social pressure when challenged, such as irritation, name-dropping, impatience, embarrassment, or “I’m here all the time” framing