Dozens of systems sit between the physical program and the cyber program. Each one is somebody's equipment and nobody's responsibility.
Most security spending over the last decade went to the network, on the assumption that attackers had gone there too. Utilities are reporting the opposite.
Attackers did not move online. They added a second option.
Harden one path and you have defended one path.Physical security controls who gets into a space. Cybersecurity controls who gets into your information. Most comparisons stop there.
The difference that matters shows up afterward. Most network intrusions can be undone. You rotate credentials, restore systems, and notify the people you are required to notify. A failure at a substation, a loading dock, or a front desk can end with equipment that takes eight months to replace, or with someone in the hospital. You cannot reset a transformer.
An attacker takes the cheaper path. One of them gets patched every month and audited every year. The other gets a fire inspection. That is usually enough to decide it.
Protects people, buildings, and equipment. When it fails, it fails in a specific place, at a specific time, to a specific person. Getting back to normal means ordering parts and waiting.
Protects data, networks, and systems. When it fails it can fail everywhere at once, and often nobody notices for months. Getting back to normal means restores and disclosure letters.
Ukraine's grid has been under attack since 2022 by an opponent that had already taken it down with cyberattacks twice, in 2015 and 2016. So the capability was there and the target was familiar.
The Congressional Research Service looked at what actually did the damage. Cyberattacks caused short interruptions. Physical attacks brought the grid close to collapse in late 2022. Almost all of the strikes went after transmission substations and large power transformers, which are the pieces that take longest to replace.3
Four years, both options open, and the damage came from missiles.
Each is a physical control running on the network, or a network control defeated by someone walking in.
Badge readers are network devices. A compromised controller opens doors.
Video systems are among the most common unpatched devices on a corporate LAN.
The strongest network controls assume nobody walks in and pulls a drive.
HVAC, elevators, and fire panels sit on networks and control physical conditions.
A held door defeats identity controls. The attack begins in the lobby.
Third parties receive badges and credentials, frequently with no joint review.
These conversations usually stop at cameras and badge readers. The list runs longer, and most of what follows has never been assigned to anybody.
A fire alarm releases door locks by code. Anyone who can trigger one opens a controlled building, and the override is a design requirement.
Older 125 kHz credentials can be read and duplicated with cheap hardware. Many sites still run them a decade after better options shipped.
Cloud sign-in systems hold photos, scanned ID, and a record of who met whom. The vendor is rarely reviewed.
The door depends on an internet link and a vendor's uptime. Decide in advance what a connectivity failure does.
In leased space the building owner runs the cameras and access control. You hold no admin rights and no logs, and your incident response assumes both.
Master keys, cabinets, and the spare a retiring supervisor kept. The oldest access control in the building, and the least audited.
Drives, badge printers, and phones leave the site through a process nobody owns. Chain of custody is where the two domains meet.
Plate readers record when each employee arrives and leaves. Pattern-of-life data on your own staff, in a networked appliance.
Inbound goods pass the perimeter with the least screening of any route into the building.
A drone over your site crosses no fence, presents no badge, and touches no network. It carries a camera into airspace your lease does not cover. Your access control system has nothing to say about it and your firewall has nothing to inspect.
This is not rare anymore. Drone incursions over US military installations went from 230 in one year to about 420 the next, up 82 percent.5 Copenhagen Airport suspended flights for close to four hours in September 2025 after repeated sightings in controlled airspace, an event the Danish prime minister called the most serious attack on the country's critical infrastructure to date.6
Ask who owns airspace on your risk register. The usual answer is nobody.
CVE-2017-7921 is an authentication bypass in a widely deployed line of IP cameras. It scores 9.8 of 10. An attacker who reaches the device skips the login entirely, views live video, pulls recordings, and uses the camera as a foothold into the network behind it.9
It was disclosed in 2017. In March 2026, CISA added it to the Known Exploited Vulnerabilities catalog after confirming active exploitation, and set a binding federal remediation deadline of March 26, 2026.9
That is nine years, with a fix available for almost all of it.
Nobody owned it.
A patch with no owner never gets applied.IT assumes facilities handles the door. Facilities assumes IT handles the device on the door. Both report green. The badge controller runs firmware from 2019 and a vendor account from a finished contract still works.
Outside parties make it worse. Breaches involving a third party doubled from 15 percent to 30 percent in a single year, and 22 percent of the ones that exploited a flaw went after edge hardware like firewalls and remote access gateways.7 Vendors carry badges. That hardware sits in a closet. Both land in the seam.
You can pass both audits and still be open.
The seam sits outside both scopes.When Verizon looked at insider misuse in 2026, the top motive was convenience, at 60 percent. Money came second at 33 percent. The usual case is somebody emailing a file to a personal account to finish the work at home.8
The same thing happens in the building. The propped loading door. The held elevator. The shared badge. The keypad code written on the door frame. None of these people are hostile. Each one is working around something that makes the job harder.
So here is the rule worth carrying. Any control that fights the daily work will be defeated by the people it was bought to protect, usually within a month, and usually by someone just trying to get through the day.
A comparison between the security you have and the security your risks call for. Three steps, one ranked list.
Write down every control you have, including the shared systems neither side lists. Put a name against each one. If nobody owns it, that goes on the list.
Run realistic paths end to end. An intruder at the loading dock. A badge that outlived a contract. A drone over the yard on a Sunday.
Score every gap on what it would cost and how likely it is, then put them in order. Physical and digital findings go on the same list.
Two lists mean two sets of priorities. A serious physical gap loses to a middling digital one when two people rank them against two budgets. One list makes leadership choose in the open.
Most advice on this subject tells you to merge reporting lines. That takes years and it is usually somebody else's decision. WorldSafe works asset by asset, which you can start this quarter without reorganizing anything.
WorldSafe inventories the controls, walks the scenarios, and hands back a ranked list with names against it. Two weeks for one building.
A WorldSafe practitioner walks your site at its busiest hour and scores what they find. Written findings in 5 business days, with a summary your board can read.
WorldSafe comes back, re-scores, runs the exercises, and stays on call between visits. One annual fee you can budget.
Ask all five in the same meeting and write down who answers. If one person cannot cover all of them, you have found the gap.
More on gap analysis, and on running one integrated program.