PHYSICAL SECURITY · ASSESSMENT

Physical Security Systems Assessment and Architecture Review

Physical security systems are the first line of defence. They protect your assets, your people and your facilities from unauthorised physical access, and they stand between an adversary and the point at which physical access becomes network access.

They are also, today, ICT systems. They are rarely governed like ICT systems, and that gap is where the risk sits.

01

Physical access is a pathway to your network

An adversary who gains physical access to a site is not limited to what they can carry out of it. Physical presence is a position from which to pivot, into comms rooms, into ports, into workstations, and from there into the corporate network and the logical systems it holds.

The physical security estate is what prevents that. It is the outer boundary of your network perimeter, enforced at a door, a fence, a gate and a camera rather than at a firewall. It deserves to be resourced accordingly, and generally it is not.

02

The legacy that created the gap

Physical security systems were once genuinely separate from ICT. They were standalone, they were not networked, and they held nothing an attacker on the network could reach. Treating them as building systems rather than information systems was appropriate.

The landscape has changed dramatically. These are now network based systems. They rely on servers, databases and applications, their controllers and field devices sit on the network, and their operator workstations are ordinary computers.

The inherited assumption has not changed with them. They are still widely treated as low priority and low risk, largely because the people governing them do not have visibility of how the systems actually work. That combination, high consequence and low attention, is precisely where vulnerabilities accumulate.

03

Parallel network or corporate network

Where these systems sit on the network shapes the risk, and both arrangements have consequences.

On a separate, parallel network, physical security systems tend to be forgotten. They are out of sight of the ICT team, so they are not patched, not scanned, not monitored, and not reviewed. The separation offers some protection, and it is frequently used as a reason to ignore the system entirely. In practice these environments are often the least maintained systems in the organisation.

On the corporate network, the exposure is different. The system is now reachable, and it carries the same risk profile as any other corporate system, which means it requires the same controls. The advantage is visibility. Once these systems appear on the corporate network, they appear in the ICT team's field of view, and this is exactly why departments and vendors are now asking for them to be uplifted.

Neither position is inherently correct. What matters is that the decision is deliberate, and that the controls match the position.

04

The gap we fill

There is a gap between the ICT team and the integrator, and it is not anyone's fault.

Integrators are operational specialists. They install and maintain systems that work reliably, and they do that job well. Securing the platform, positioning it correctly on the network and protecting the information it holds are different disciplines, outside what they are engaged to deliver.

The ICT team has the security capability, but does not usually regard the physical security estate as its own, and rarely has the depth of knowledge in these specific platforms to assess them properly.

Our consultants have extensive experience in physical security systems. We identify the gaps the integrator has left, and translate them into an ICT and cyber security roadmap the organisation can actually follow, so that these systems are uplifted, and the information they hold is secured.

05

Systems we assess

Electronic access control systems (EACS), including Gallagher, Lenel and Inner Range

Security alarm systems

Video management systems (VMS), including Milestone, Geutebrück and Avigilon

Electronic key management systems

Perimeter detection systems

Intercom systems

The supporting ICT infrastructure on which all of the above depend

06

What we deliver

Security assessments.

Independent assessment of the deployed system, its configuration, its platform and its network position.

Gap analysis.

A clear picture of the difference between where the system is and where it needs to be, prioritised so it can be acted on.

Architecture review.

Assessment of the architecture as it stands, including segmentation, remote access, identity, storage and resilience.

Design review.

Review of proposed designs before they are built, which is considerably cheaper than remediating them afterwards.

Assessments are conducted against the Australian Government Information Security Manual, ACSC guidance and the manufacturer's published hardening guidance, and where relevant the Protective Security Policy Framework.

08

How we work

Independent. We do not sell, install or maintain physical security systems, and we hold no commercial relationship with any platform vendor.

Specialist. Our consultants work in this space specifically. This is not general ICT security applied loosely to an unfamiliar system.

Practical. These are live operational systems. A control applied without understanding the system will disrupt the site, and a control that disrupts the site gets reversed.

09

Who this is for

Government agencies, Defence organisations, government suppliers and critical infrastructure operators, particularly where a site holds sensitive or classified information.