WORLDSAFE
Guide
Physical security and cybersecurity

The seam nobody
owns.

Dozens of systems sit between the physical program and the cyber program. Each one is somebody's equipment and nobody's responsibility.

Written for
Security directors, IT leadership, and risk owners
Practice
Security Gap Analysis
Sources
E-ISAC, DOE, CRS, NORTHCOM, Verizon DBIR, CISA. Page 15
WORLDSAFE
Physical vs Cyber  ·  1
What changed

Physical attacks are climbing.

Most security spending over the last decade went to the network, on the assumption that attackers had gone there too. Utilities are reporting the opposite.

3,500+
physical security breaches logged by grid operators in 2025. Roughly 3 percent disrupted electricity delivery.
NERC E-ISAC year-end report 1
2x
physical security incidents in the Western Interconnection in 2024, rising from 107 to 220 in a single year.
DOE OE-417 reporting 2
13,000+
drone incursions detected at United States power generation sites during 2024.
Congressional testimony, July 2025 4

Attackers did not move online. They added a second option.

Harden one path and you have defended one path.
WorldSafe Physical vs Cyber2
WORLDSAFE
Physical vs Cyber  ·  2
The asymmetry

What a failure costs you afterward.

Physical security controls who gets into a space. Cybersecurity controls who gets into your information. Most comparisons stop there.

The difference that matters shows up afterward. Most network intrusions can be undone. You rotate credentials, restore systems, and notify the people you are required to notify. A failure at a substation, a loading dock, or a front desk can end with equipment that takes eight months to replace, or with someone in the hospital. You cannot reset a transformer.

Why the boundary matters

An attacker takes the cheaper path. One of them gets patched every month and audited every year. The other gets a fire inspection. That is usually enough to decide it.

Physical security

Protects people, buildings, and equipment. When it fails, it fails in a specific place, at a specific time, to a specific person. Getting back to normal means ordering parts and waiting.

Cybersecurity

Protects data, networks, and systems. When it fails it can fail everywhere at once, and often nobody notices for months. Getting back to normal means restores and disclosure letters.

WorldSafe Physical vs Cyber3
WORLDSAFE
Physical vs Cyber  ·  3
The case nobody cites in a security review

Russia had both options in Ukraine. It picked the substation.

Ukraine's grid has been under attack since 2022 by an opponent that had already taken it down with cyberattacks twice, in 2015 and 2016. So the capability was there and the target was familiar.

The Congressional Research Service looked at what actually did the damage. Cyberattacks caused short interruptions. Physical attacks brought the grid close to collapse in late 2022. Almost all of the strikes went after transmission substations and large power transformers, which are the pieces that take longest to replace.3

Four years, both options open, and the damage came from missiles.

What transfers to a commercial site
  • Find your long-lead item. Attackers aim at whatever takes longest to replace. Every site has one. Go find out what yours is and how long it would take.
  • Length matters more than frequency. A short outage gets absorbed. A twelve-month one changes the business.
  • Ask which one you have never tested. Most organizations can name their last penetration test and cannot name their last site assessment.
  • Check the register. Single points of physical failure rarely show up on a cyber risk register at all.
WorldSafe Physical vs Cyber4
WORLDSAFE
Physical vs Cyber  ·  4
Side by side

How the two programs differ.

Protects
People, facilities, equipment
Data, networks, systems
Attacker needs
Proximity, or a drone
A route to the network
Detection
Usually immediate and visible
Often delayed by weeks or months
Recovery
Procurement lead times
Restores and disclosure
Primary controls
Barriers, access control, lighting, staffing
Identity, segmentation, encryption, monitoring
Testing
Site assessment, penetration test, tabletop
Vulnerability scan, penetration test, red team
Typical owner
Facilities or corporate security
IT or a CISO organization
Budget pattern
Capital projects, often reactive
Recurring program spend
Regulatory driver
CIP-014, TSA guidelines, duty of care
Sector frameworks, privacy law, audit
Two owners, two scopes. WorldSafe works across both columns and takes the systems that belong to neither.
WorldSafe Physical vs Cyber5
WORLDSAFE
Physical vs Cyber  ·  5
Convergence

Six places the boundary disappears.

Each is a physical control running on the network, or a network control defeated by someone walking in.

1

Access control systems

Badge readers are network devices. A compromised controller opens doors.

2

Cameras on the network

Video systems are among the most common unpatched devices on a corporate LAN.

3

Server rooms

The strongest network controls assume nobody walks in and pulls a drive.

4

Building management

HVAC, elevators, and fire panels sit on networks and control physical conditions.

5

Tailgating

A held door defeats identity controls. The attack begins in the lobby.

6

Vendor access

Third parties receive badges and credentials, frequently with no joint review.

WorldSafe Physical vs Cyber6
WORLDSAFE
Physical vs Cyber  ·  6
Also unowned

Nine more that appear on neither register.

These conversations usually stop at cameras and badge readers. The list runs longer, and most of what follows has never been assigned to anybody.

Fire and life safety

A fire alarm releases door locks by code. Anyone who can trigger one opens a controlled building, and the override is a design requirement.

Legacy proximity cards

Older 125 kHz credentials can be read and duplicated with cheap hardware. Many sites still run them a decade after better options shipped.

Visitor management

Cloud sign-in systems hold photos, scanned ID, and a record of who met whom. The vendor is rarely reviewed.

Cloud-managed locks

The door depends on an internet link and a vendor's uptime. Decide in advance what a connectivity failure does.

Landlord-owned systems

In leased space the building owner runs the cameras and access control. You hold no admin rights and no logs, and your incident response assumes both.

Physical key management

Master keys, cabinets, and the spare a retiring supervisor kept. The oldest access control in the building, and the least audited.

Decommissioned hardware

Drives, badge printers, and phones leave the site through a process nobody owns. Chain of custody is where the two domains meet.

Parking and plate readers

Plate readers record when each employee arrives and leaves. Pattern-of-life data on your own staff, in a networked appliance.

Loading dock and mail

Inbound goods pass the perimeter with the least screening of any route into the building.

WorldSafe Physical vs Cyber7
WORLDSAFE
Physical vs Cyber  ·  7
The one that fits neither program

A physical intrusion that breaches no perimeter.

A drone over your site crosses no fence, presents no badge, and touches no network. It carries a camera into airspace your lease does not cover. Your access control system has nothing to say about it and your firewall has nothing to inspect.

This is not rare anymore. Drone incursions over US military installations went from 230 in one year to about 420 the next, up 82 percent.5 Copenhagen Airport suspended flights for close to four hours in September 2025 after repeated sightings in controlled airspace, an event the Danish prime minister called the most serious attack on the country's critical infrastructure to date.6

Ask who owns airspace on your risk register. The usual answer is nobody.

Why it lands in the seam
  • Not cyberIt uses no network, so it never shows up in a scan or in the monitoring tools.
  • Not perimeterIt defeats no barrier, so it never shows up in a site inspection either.
  • Not yoursFederal law limits who may track or stop one, so you cannot buy your way out of this.
  • DoableTrain staff to log sightings, give them one number to call, and move sensitive work out of open yards.
WorldSafe Physical vs Cyber8
WORLDSAFE
Physical vs Cyber  ·  8
Case: the nine-year camera

A 2017 flaw with a 2026 deadline.

CVE-2017-7921 is an authentication bypass in a widely deployed line of IP cameras. It scores 9.8 of 10. An attacker who reaches the device skips the login entirely, views live video, pulls recordings, and uses the camera as a foothold into the network behind it.9

It was disclosed in 2017. In March 2026, CISA added it to the Known Exploited Vulnerabilities catalog after confirming active exploitation, and set a binding federal remediation deadline of March 26, 2026.9

That is nine years, with a fix available for almost all of it.

Nobody owned it.

A patch with no owner never gets applied.
Why devices like this go unpatched
  • ProcurementCameras are bought as building equipment, so they never enter the IT asset inventory.
  • ProcessFirmware is downloaded manually from a vendor site. Many organizations never repeat that after install.10
  • ScaleRoughly half of IoT devices carry known vulnerabilities or default passwords.10
  • LifespanA camera gets bought for ten years of service. Its software gets supported for about three.
WorldSafe Physical vs Cyber9
WORLDSAFE
Physical vs Cyber  ·  9
The seam

Most exposure sits between the two programs.

IT assumes facilities handles the door. Facilities assumes IT handles the device on the door. Both report green. The badge controller runs firmware from 2019 and a vendor account from a finished contract still works.

Outside parties make it worse. Breaches involving a third party doubled from 15 percent to 30 percent in a single year, and 22 percent of the ones that exploited a flaw went after edge hardware like firewalls and remote access gateways.7 Vendors carry badges. That hardware sits in a closet. Both land in the seam.

You can pass both audits and still be open.

The seam sits outside both scopes.
What the seam looks like in practice
  • UnownedA badge controller nobody patches, because facilities buys it and IT does not inventory it.
  • UnreviewedContractor credentials that outlive the contract, physical and digital both.
  • UntestedA camera network reachable from the guest wifi, never scanned because it looks like building equipment.
  • UnrehearsedAn incident that starts at a door and becomes a data question, with two escalation paths and no shared one.
WorldSafe Physical vs Cyber10
WORLDSAFE
Physical vs Cyber  ·  10
The unifying finding

People take the easy route.

When Verizon looked at insider misuse in 2026, the top motive was convenience, at 60 percent. Money came second at 33 percent. The usual case is somebody emailing a file to a personal account to finish the work at home.8

The same thing happens in the building. The propped loading door. The held elevator. The shared badge. The keypad code written on the door frame. None of these people are hostile. Each one is working around something that makes the job harder.

So here is the rule worth carrying. Any control that fights the daily work will be defeated by the people it was bought to protect, usually within a month, and usually by someone just trying to get through the day.

What this changes about remediation
  • Audit the workaround. The gap is the distance between the written rule and the observed behavior.
  • Walk the building at its busiest hour. Controls hold at 9am on a Tuesday. They fail during a delivery window.
  • Treat a widespread bypass as a design defect. One person defeating a control is a coaching matter. Everyone defeating it is a specification error.
  • Fix the friction first. It costs less to remove the reason than to keep policing the rule.
WorldSafe Physical vs Cyber11
WORLDSAFE
Physical vs Cyber  ·  11
Method

What a security gap analysis does.

A comparison between the security you have and the security your risks call for. Three steps, one ranked list.

Map

Inventory the controls

Write down every control you have, including the shared systems neither side lists. Put a name against each one. If nobody owns it, that goes on the list.

Test

Walk the scenarios

Run realistic paths end to end. An intruder at the loading dock. A badge that outlived a contract. A drone over the yard on a Sunday.

Rank

Score by consequence

Score every gap on what it would cost and how likely it is, then put them in order. Physical and digital findings go on the same list.

Why one register matters

Two lists mean two sets of priorities. A serious physical gap loses to a middling digital one when two people rank them against two budgets. One list makes leadership choose in the open.

WorldSafe Physical vs Cyber12
WORLDSAFE
Physical vs Cyber  ·  12
WorldSafe's approach to converged security

Start where you already have authority.

Most advice on this subject tells you to merge reporting lines. That takes years and it is usually somebody else's decision. WorldSafe works asset by asset, which you can start this quarter without reorganizing anything.

  • Put a name on every shared system. Badge controllers, cameras, building management, elevator controls. The list is shorter than people expect. Anything without a name becomes a finding with a due date.
  • One list, one ranking. Physical and digital findings get scored the same way, so leadership can compare them directly.
  • Review vendors once, for both. A contractor's badge and login are one record. Issued together, revoked together, on the last day.
  • Rehearse the crossover. Run an exercise where the incident starts at a door and turns into a data problem. One escalation path, practiced.
  • No equipment to sell. WorldSafe sells no cameras, no access control, and no software, so a finding never shows up attached to a quote.
Engagements
Entry

Security Gap Analysis

WorldSafe inventories the controls, walks the scenarios, and hands back a ranked list with names against it. Two weeks for one building.

Core

Security Assessment

A WorldSafe practitioner walks your site at its busiest hour and scores what they find. Written findings in 5 business days, with a summary your board can read.

Ongoing

Resilience as a Service

WorldSafe comes back, re-scores, runs the exercises, and stays on call between visits. One annual fee you can budget.

WorldSafe Physical vs Cyber13
WORLDSAFE
Physical vs Cyber  ·  13
Where to start

Five questions for
this quarter.

Ask all five in the same meeting and write down who answers. If one person cannot cover all of them, you have found the gap.

More on gap analysis, and on running one integrated program.

  • Who owns the badge system, the device and the policy both
  • When was the camera network last scanned
  • What happens to a contractor's badge and login on the last day
  • Who would notice a drone over the yard on a Sunday
  • Which physical asset has the longest replacement lead time
Security failures are
leadership failures.
Security Assessment · Security Gap Analysis · Integrated Security Program · Resilience as a Serviceworldsafe.co  ·  +877-831-SAFE
WorldSafe Physical vs Cyber14
WORLDSAFE
Physical vs Cyber  ·  14
Sources

Where the numbers come from.

  1. NERC E-ISAC, 2025 end-of-year report. More than 3,500 physical security breaches in 2025, approximately 3 percent disrupting electricity delivery.
  2. US Department of Energy, OE-417 reporting. Western Interconnection physical security incidents rose from 107 in 2023 to 220 in 2024.
  3. Congressional Research Service, R48067. Attacks on Ukraine's Electric Grid. Physical attacks had greater strategic impact than cyberattacks. The majority of strikes targeted transmission substations and large power transformers.
  4. US House Committee on Homeland Security, testimony, July 2025. Over 13,000 drone incursions detected at US power generation sites in 2024, citing E&E News and Dedrone.
  5. US Northern Command, reported October 2025. 230 drone incursions over military installations between September 2023 and September 2024, rising approximately 82 percent to about 420 in the following period.
  1. Copenhagen Airport, September 22, 2025. Flights suspended for close to four hours after repeated drone sightings in controlled airspace.
  2. Verizon, 2025 Data Breach Investigations Report. Third-party involvement rose from 15 to 30 percent. 22 percent of exploitation breaches targeted edge devices.
  3. Verizon, 2026 Data Breach Investigations Report. Insider misuse motives: convenience 60 percent, financial gain 33 percent.
  4. CISA Known Exploited Vulnerabilities catalog, March 2026. CVE-2017-7921, authentication bypass, CVSS 9.8, disclosed 2017, federal remediation deadline March 26, 2026.
  5. Phosphorus device research, as reported 2026. Approximately 50 percent of IoT devices carry known vulnerabilities or default credentials.
WorldSafe Physical vs Cyber15