SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Hikvision attains ISO 37301 Certification for Compliance Management System
    • SentriGuard's role in sustainable security solutions
    • Axis joins CISA Secure by design for cybersecurity
    • Xtract One's SmartGateway enhances Nova Scotia security
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • What are emerging applications for physical security in transportation?
    • What is the most overlooked factor when installing security systems?
    • Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity
    • How should security adapt to the unique aspects of healthcare?
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Alamo enhances security with Alcatel-Lucent solutions

    Alamo enhances security with Alcatel-Lucent solutions

    The University of Dundee implements HID for modern access control

    The University of Dundee implements HID for modern access control

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    SBB upgrades surveillance with Hanwha Vision cameras

    SBB upgrades surveillance with Hanwha Vision cameras

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    Technology Summit International 2025

    Technology Summit International 2025

    G2E Philippines 2025

    G2E Philippines 2025

    IFSEC India 2025

    IFSEC India 2025

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Eagle Eye Networks
    • Hanwha Vision America
    Other Resources
    • eMagazines
    • Videos
    Aligning physical and cyber defence for total protection

    Aligning physical and cyber defence for total protection

    Understanding AI-powered video analytics

    Understanding AI-powered video analytics

    Modernizing access control

    Modernizing access control

    Enhancing physical access control using a self-service model

    Enhancing physical access control using a self-service model

About us Advertise
  • AI-powered video analytics
  • AI special report
  • Cyber security special report
  • 6
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Check out our special report on casino security

Get it now!

Misguided trust leads to increase in security risks and potential attack from intruders

John Davies
John Davies
Contact company
Contact TDSi
icon Add as a preferred source Download PDF version
Quick Read
⌵
Summary is AI-generated, newsdesk-reviewed
  • Human error increases risks; stringent security policies prevent intruder attacks effectively.
  • Misguided trust exposes vulnerabilities, highlighting human nature's impact on security breaches.
  • Ethical hacking tests reveal crucial need for proven, not assumed, trust in organisations.
Taking the personal element out of security allows it to be more robust and to ensure trust is proven, rather than simply being assumed
Stringent security policies are necessary in an organisation to prevent incidents
of misplaced trust leading to an attack from intruders

Trust is a word closely associated with both physical and logical security, after all, knowing who to trust is a key part of any security policy. However, when trust is wrongly assumed it rapidly becomes a key problem and a significant weakness in the security regime.

Often the weak link is human nature itself. This means that to begin to guarantee effectiveness it’s vital to have the right policies in place and to ensure that staff follow them, however draconian they may seem to the people operating and being subjected to them.

Testing security in the real world

A good example of misguided trust was recently documented. A so-called ethical hacker was employed to test the security regime of a client company. The management deliberately kept the operation a secret from the security team and staff at the business, to assure the accuracy of the results. Initially the hacker tried to gain access through online channels, which proved to be well guarded and highly secure.

The next step was for the hacker to enter the business facilities personally. This is where psychology played its part, the perpetrator kept up a friendly appearance and politely asked the reception team if he could use the toilet facilities, whereby the person behind the desk happily allowed him access to a non-public area. Bear in mind this was a complete stranger with no security credentials who had walked in off the street!

Perhaps the most disturbing part of the story is what happened next - the hacker left two USB keys in the toilet area for staff or visitors to find. On each drive he had included a specially designed piece of software that would auto-run and execute once accessed via a computer, stealing login credentials from the user and covertly sending them to the hacker. This effectively offers open access to the most secure parts of the company’s network! Inevitably, somebody who found the drives tried them in their computer and the hacker was informed shortly afterwards.

 

When hacking a company online proves unsuccessful, hackers can instead get on the company’s network by simply walking into the building
One example of misguided trust saw a hacker leave a USB in a company building. When an unsuspecting employee used it, malware was added to the company computer

Human nature as a weakness to security policy

What the example above really highlights is just how much human nature can play its part in the way security is upheld (or broken) in the real world. The hacker explained that his other choice may have been to hand the USB keys in to the reception and simply to say he had found them in the restrooms – which would, in all likelihood, have resulted in a similar outcome.

It is debatable whether the staff were complacent or simply used misguided judgement on what appeared to be a harmless visitor, albeit an unexpected one. The fact the hacker didn’t appear to be personally involved with this potential threat perhaps lowered the guard of the reception and security team still further. Of course those individuals that recovered the USB keys weren’t in any way coerced into using them, but curiosity got the better of them and the fact the uploaded malware gave no indication it was present (literally just silently taking security data) meant the company could have suffered some serious problems had it been for real.

Misuse of authorised access

The consequences of misplaced trust in a secure environment can be severe, particularly with physical and logical security being so closely tied together now. It’s all well and good having impenetrable external IT security in place, but if this level of vigilance isn’t continued on the premises it can leave worrying vulnerabilities.

The example above shows how apparently good-natured assistance can be taken advantage of, but of course legitimate access can be misused by intruders in other ways too. The attacks on the Paris offices of Charlie Hebdo in January 2015 are a prime example of authorised access being hijacked, when an employee was threatened and forced to enter a code to help the terrorists gain entry and attack other members of staff.

Other examples include the ‘passback’ of security tokens between individuals (to gain multiple entry) and tailgating of unsuspecting members of staff as they enter secured areas. In a highly secure facility the protection measures need to anticipate these potential intrusion methods and provide solutions to combat them.

 

Rather than having to make a spontaneous judgement in an unfamiliar situation, staff will follow security procedure if it is clearly laid out
Tightened security policies can also prevent cases of people sharing access
credentials and tailgating – both of which can be serious access security risks

Security measures for countering intruder attacks

The most important lesson to be learned from all of these examples is that the culture of security within an organisation is vital - the entire team needs to be vigilant and involved.  This culture needs to be regularly assessed and, if needs be, revised to close any gaps or potential loopholes of vulnerability. It is also not good practice to purely rely upon the intuition of staff, security or otherwise. In the ethical hacker example, there was no reason for staff to be suspicious but that is exactly how the planned attack succeeded. 

This is where a stringent and water-tight security policy is so important. Rather than making a judgement, staff follow procedure and a stringent policy will tell them not to simply plug an unknown USB stick into a company device or network! Added to this, staff won’t feel the same pressure to be a ‘Good Samaritan’ to unknown visitors – policy is policy and nobody will feel guilt for denying access in these circumstances.

The layout of security measures within a business facility is also very important. The reception area should be inviting (as the name suggests) but it should also show a strong defence to those not authorised to enter. Access control systems also need to be resilient, with automated monitoring for signs of tailgating and people counters to alert the security team of any abnormalities. Equally, its good practice to ensure these measures extend inside the secure areas of the facility too, just in case intruders gain access through another entry point.

Making trust trustworthy

Despite the potential problems from wrongly assuming trust, it is still an essential element of all business transactions and excellent security recognises this. Taking the personal element out of security allows it to be more robust and to ensure trust is proven, rather than simply being assumed. Often the deadliest threats to security are the least obvious ones.

Learn why leading casinos are upgrading to smarter, faster, and more compliant systems

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Physical security
  • Security management
  • Security policy
  • Security access systems
  • Facility security
  • Cyber security
  • Data Security
  • Related links
  • TDSi Access control systems & kits
  • TDSi CCTV cameras
  • Articles by John Davies
  • Related categories
  • Access control systems & kits
  • Intruder alarm system control panels & accessories
  • CCTV cameras
Related white papers
Aligning physical and cyber defence for total protection

Aligning physical and cyber defence for total protection

Download
Combining security and networking technologies for a unified solution

Combining security and networking technologies for a unified solution

Download
System design considerations to optimize physical access control

System design considerations to optimize physical access control

Download
Related articles
How physical security consultants ensure cybersecurity for end users

How physical security consultants ensure cybersecurity for end users

How managed detection and response enhances cybersecurity management in organisations

How managed detection and response enhances cybersecurity management in organisations

Drawbacks of PenTests and ethical hacking for the security industry

Drawbacks of PenTests and ethical hacking for the security industry

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Cyber security
  4. News
  5. Expert commentary
About this page

Elevate security with expert insights: prevent intrusion, mitigate risks, and protect assets by tackling misplaced trust and security complacency.

See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2025, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Understanding AI-powered video analytics
Understanding AI-powered video analytics
Security and surveillance technologies for the casino market
Security and surveillance technologies for the casino market
Modernizing access control
Modernizing access control
Addressing Cybersecurity Vulnerabilities in the Physical World
Addressing Cybersecurity Vulnerabilities in the Physical World
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec