SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
    Hikvision 4MP ColorVu 3.0 Fixed PT Network Camera

    Hikvision 4MP ColorVu 3.0 Fixed PT Network Camera

    Hikvision DS-2CD1F47G3H-LIU/SX(4mm) 4 MP ColorVu 3.0 Fixed PT Network Camera

    Hikvision DS-2CD1F47G3H-LIU/SX(4mm) 4 MP ColorVu 3.0 Fixed PT Network Camera

    Dahua APOLLO 4G Solar Security System

    Dahua APOLLO 4G Solar Security System

    Morse Watchmans KeyWatcher Touch Key Control Modules

    Morse Watchmans KeyWatcher Touch Key Control Modules

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Colt SCION: First managed service network provider
    • F5 BIG-IP cloud-native solutions for 5G & AI
    • WFW adopts SwiftConnect for secure mobile access
    • Acoem acoustic threat updates enhance gunshot detection
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • What are the unique aspects of the critical infrastructure market?
    • AI and regulation are reshaping the future of building security
    • How is the role of biometrics changing in physical access control?
    • How are new technologies reshaping casino surveillance and security?
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
    Dahua AI traffic control revolutionises Atyrau mobility

    Dahua AI traffic control revolutionises Atyrau mobility

    Morse Watchmans enhances Lincoln's Inn security systems

    Morse Watchmans enhances Lincoln's Inn security systems

    Hikvision solution boosts Muçum flood preparedness

    Hikvision solution boosts Muçum flood preparedness

    Carrefour Brazil: Enhanced security with Dahua solutions

    Carrefour Brazil: Enhanced security with Dahua solutions

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Technology's role in securing banks and financial institutions
    Technology's role in securing banks and financial institutions
    PACK EXPO Chicago 2026

    PACK EXPO Chicago 2026

    OFSEC - Oman Fire, Safety & Security Expo 2026

    OFSEC - Oman Fire, Safety & Security Expo 2026

    Milipol Qatar 2026

    Milipol Qatar 2026

    DSEI Germany 2027

    DSEI Germany 2027

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Software House
    • ELATEC USA
    Other Resources
    • eMagazines
    • Videos
    Technology's role in securing banks and financial institutions

    Technology's role in securing banks and financial institutions

    Integrated systems enable critical and compliant security for transportation

    Integrated systems enable critical and compliant security for transportation

    Modernising physical access control

    Modernising physical access control

    Access. Intrusion. One estate.

    Access. Intrusion. One estate.

About us Advertise
  • Securing financial institutions
  • AI special report
  • Cyber security special report
  • 6
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Misguided trust leads to increase in security risks and potential attack from intruders

John Davies
John Davies
Contact company
Contact TDSi
icon Add as a preferred source Download PDF version
Quick Read
⌵
Summary is AI-generated, newsdesk-reviewed
  • Human error increases risks; stringent security policies prevent intruder attacks effectively.
  • Misguided trust exposes vulnerabilities, highlighting human nature's impact on security breaches.
  • Ethical hacking tests reveal crucial need for proven, not assumed, trust in organisations.
Taking the personal element out of security allows it to be more robust and to ensure trust is proven, rather than simply being assumed
Stringent security policies are necessary in an organisation to prevent incidents
of misplaced trust leading to an attack from intruders

Trust is a word closely associated with both physical and logical security, after all, knowing who to trust is a key part of any security policy. However, when trust is wrongly assumed it rapidly becomes a key problem and a significant weakness in the security regime.

Often the weak link is human nature itself. This means that to begin to guarantee effectiveness it’s vital to have the right policies in place and to ensure that staff follow them, however draconian they may seem to the people operating and being subjected to them.

Testing security in the real world

A good example of misguided trust was recently documented. A so-called ethical hacker was employed to test the security regime of a client company. The management deliberately kept the operation a secret from the security team and staff at the business, to assure the accuracy of the results. Initially the hacker tried to gain access through online channels, which proved to be well guarded and highly secure.

The next step was for the hacker to enter the business facilities personally. This is where psychology played its part, the perpetrator kept up a friendly appearance and politely asked the reception team if he could use the toilet facilities, whereby the person behind the desk happily allowed him access to a non-public area. Bear in mind this was a complete stranger with no security credentials who had walked in off the street!

Perhaps the most disturbing part of the story is what happened next - the hacker left two USB keys in the toilet area for staff or visitors to find. On each drive he had included a specially designed piece of software that would auto-run and execute once accessed via a computer, stealing login credentials from the user and covertly sending them to the hacker. This effectively offers open access to the most secure parts of the company’s network! Inevitably, somebody who found the drives tried them in their computer and the hacker was informed shortly afterwards.

 

When hacking a company online proves unsuccessful, hackers can instead get on the company’s network by simply walking into the building
One example of misguided trust saw a hacker leave a USB in a company building. When an unsuspecting employee used it, malware was added to the company computer

Human nature as a weakness to security policy

What the example above really highlights is just how much human nature can play its part in the way security is upheld (or broken) in the real world. The hacker explained that his other choice may have been to hand the USB keys in to the reception and simply to say he had found them in the restrooms – which would, in all likelihood, have resulted in a similar outcome.

It is debatable whether the staff were complacent or simply used misguided judgement on what appeared to be a harmless visitor, albeit an unexpected one. The fact the hacker didn’t appear to be personally involved with this potential threat perhaps lowered the guard of the reception and security team still further. Of course those individuals that recovered the USB keys weren’t in any way coerced into using them, but curiosity got the better of them and the fact the uploaded malware gave no indication it was present (literally just silently taking security data) meant the company could have suffered some serious problems had it been for real.

Misuse of authorised access

The consequences of misplaced trust in a secure environment can be severe, particularly with physical and logical security being so closely tied together now. It’s all well and good having impenetrable external IT security in place, but if this level of vigilance isn’t continued on the premises it can leave worrying vulnerabilities.

The example above shows how apparently good-natured assistance can be taken advantage of, but of course legitimate access can be misused by intruders in other ways too. The attacks on the Paris offices of Charlie Hebdo in January 2015 are a prime example of authorised access being hijacked, when an employee was threatened and forced to enter a code to help the terrorists gain entry and attack other members of staff.

Other examples include the ‘passback’ of security tokens between individuals (to gain multiple entry) and tailgating of unsuspecting members of staff as they enter secured areas. In a highly secure facility the protection measures need to anticipate these potential intrusion methods and provide solutions to combat them.

 

Rather than having to make a spontaneous judgement in an unfamiliar situation, staff will follow security procedure if it is clearly laid out
Tightened security policies can also prevent cases of people sharing access
credentials and tailgating – both of which can be serious access security risks

Security measures for countering intruder attacks

The most important lesson to be learned from all of these examples is that the culture of security within an organisation is vital - the entire team needs to be vigilant and involved.  This culture needs to be regularly assessed and, if needs be, revised to close any gaps or potential loopholes of vulnerability. It is also not good practice to purely rely upon the intuition of staff, security or otherwise. In the ethical hacker example, there was no reason for staff to be suspicious but that is exactly how the planned attack succeeded. 

This is where a stringent and water-tight security policy is so important. Rather than making a judgement, staff follow procedure and a stringent policy will tell them not to simply plug an unknown USB stick into a company device or network! Added to this, staff won’t feel the same pressure to be a ‘Good Samaritan’ to unknown visitors – policy is policy and nobody will feel guilt for denying access in these circumstances.

The layout of security measures within a business facility is also very important. The reception area should be inviting (as the name suggests) but it should also show a strong defence to those not authorised to enter. Access control systems also need to be resilient, with automated monitoring for signs of tailgating and people counters to alert the security team of any abnormalities. Equally, its good practice to ensure these measures extend inside the secure areas of the facility too, just in case intruders gain access through another entry point.

Making trust trustworthy

Despite the potential problems from wrongly assuming trust, it is still an essential element of all business transactions and excellent security recognises this. Taking the personal element out of security allows it to be more robust and to ensure trust is proven, rather than simply being assumed. Often the deadliest threats to security are the least obvious ones.

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Physical security
  • Security management
  • Security policy
  • Security access systems
  • Facility security
  • Cyber security
  • Data Security
  • Related links
  • TDSi CCTV cameras
  • TDSi Access control systems & kits
  • Articles by John Davies
  • Related categories
  • CCTV cameras
  • Access control systems & kits
  • Intruder alarm system control panels & accessories
Related white papers
Technology's role in securing banks and financial institutions

Technology's role in securing banks and financial institutions

Download
Security technologies promote real-time awareness in K-12 schools

Security technologies promote real-time awareness in K-12 schools

Download
An end user's guide to physical security for data centres

An end user's guide to physical security for data centres

Download
Related articles
How physical security consultants ensure cybersecurity for end users

How physical security consultants ensure cybersecurity for end users

How managed detection and response enhances cybersecurity management in organisations

How managed detection and response enhances cybersecurity management in organisations

Drawbacks of PenTests and ethical hacking for the security industry

Drawbacks of PenTests and ethical hacking for the security industry

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Cyber security
  4. News
  5. Expert commentary
About this page

Elevate security with expert insights: prevent intrusion, mitigate risks, and protect assets by tackling misplaced trust and security complacency.

See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2026, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Technology's role in securing banks and financial institutions
Technology's role in securing banks and financial institutions
Integrated systems enable critical and compliant security for transportation
Integrated systems enable critical and compliant security for transportation
Modernising physical access control
Modernising physical access control
Minimizing storage, maximizing focus
Minimizing storage, maximizing focus
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec