Gallagher Security System Assessments
Gallagher is one of the most widely deployed access control platforms across Australian Government, Defence and critical infrastructure environments. It is a capable and well engineered system. Whether it is secure in your environment depends entirely on how the platform, the application and the supporting infrastructure have been configured and maintained.
CCircle provides independent security assessments of Gallagher deployments, applying the same standards to your physical security system that you already apply to the rest of your ICT estate.
The landscape has changed
For a long time, physical security systems sat outside ICT. They were standalone, they were the responsibility of the security or facilities team, and they were not connected to anything that mattered from an information security perspective. Treating them differently to corporate IT made sense.
That is no longer the case. Almost every component of a modern physical security system is now networked, and in many organisations these systems sit on, or connect to, the corporate network. A Gallagher deployment today is a server, a database, an application, a fleet of networked controllers, and an operator workstation. It is an ICT system in everything but name.
What has not changed is the level of attention these systems receive. They are still frequently governed as building systems rather than as information systems, and so they are patched less, monitored less, hardened less and reviewed less than any corporate system of equivalent exposure. Not through negligence, but because the people responsible for them were never expected to be information security specialists.
Where the gap comes from
Gallagher systems are typically installed and maintained by integrators, and good integrators do their job well. But their trade is operational. Their objective is a system that is installed correctly, works reliably and lets the right people through the right doors. Securing the information the system holds, hardening the platform it runs on, and positioning it correctly on the network are different disciplines, and they sit outside what an integrator is engaged to deliver.
The result is a system that operates exactly as intended, and is not necessarily secure.
Where CCircle fits
We work in the physical security systems space specifically. Our consultants have in depth knowledge of these platforms, not general IT knowledge applied loosely to an unfamiliar system.
That matters, because a security control applied without understanding the system will break the operation. Access control is a live operational system. If a change locks out staff, disrupts a shift, or takes a site offline, it will be reversed, and the security improvement will be lost with it. Our objective is security controls that hold without becoming an obstacle to the way the site actually runs.
We assess against the manufacturer's own hardening guidance, alongside the Australian Government Information Security Manual and ACSC guidance, covering the platform, the application configuration and the supporting infrastructure.
What we assess
Command Centre.
The server, operating system and database. Patching and currency, hardening against the manufacturer's guidance, service accounts, operator roles and permissions, audit logging, and backup and recovery.
Controllers and field hardware.
Firmware currency, and the physical protection of the controllers themselves. A controller in an unsecured ceiling space or an open comms cupboard undermines every door it governs.
Readers and credentials.
Reader protocols, card technology, and how credentials are issued, reviewed and revoked. Legacy card technologies remain widespread in Australia and can be cloned with inexpensive, commonly available equipment.
Network position.
Where the controllers and Command Centre sit, whether the system is segmented from the corporate network, whether it is monitored, and what an attacker who reached that segment could actually do.
Configuration and operations.
Access groups and privilege creep, anti passback, door forced and door held alarm handling, integration with HR and visitor systems, and whether access rights are genuinely reviewed.
Alignment with Australian requirements.
Assessment against the ISM and ACSC guidance, and where relevant the Protective Security Policy Framework, including security zones and the physical controls expected at each level.
What we typically find
- Legacy card technologies still in service, cloneable with commodity hardware
- Command Centre servers running unsupported or unpatched operating systems
- Manufacturer hardening guidance available, but never applied
- Access control systems on flat, unsegmented networks alongside corporate systems
- Shared operator accounts, with no way to attribute an action to a person
- Access rights accumulated over years and never reviewed
- Departed personnel whose credentials were never revoked
- No tested backup of the Command Centre database
Individually these look minor. Together they usually mean the access control system is not doing the job the organisation believes it is doing.
Who this is for
Government agencies, Defence organisations, government suppliers and critical infrastructure operators running Gallagher, particularly where the same site also holds sensitive or classified information.
Talk to us
To discuss an independent assessment of your Gallagher deployment, call 1300 045 483 or email info@ccircle.com.au