SecurityInformed.com
  • Products
    Video Surveillance
    • Surveillance cameras
    • Video Surveillance software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network Video Recorders (NVRs)
    • IP Dome cameras
    • Security camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Intercom Systems
    • Electronic lock systems
    • Access control cards/ tags/ fobs
    • Access control accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder alarm warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
    Dahua APOLLO 4G Solar Security System

    Dahua APOLLO 4G Solar Security System

    Morse Watchmans KeyWatcher Touch Key Control Modules

    Morse Watchmans KeyWatcher Touch Key Control Modules

    Hikvision AX PRO Wireless Alarm Keyfob

    Hikvision AX PRO Wireless Alarm Keyfob

    Delta Scientific Rapid Deployment Portable Barrier

    Delta Scientific Rapid Deployment Portable Barrier

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Cellebrite Expands Digital Forensics Community
    • Secutech Vietnam 2026: AI In Smart Building Tech
    • Cyble Partners With UAE On Threat Intelligence MOU
    • Godel Technologies Embraces AI For Mid-Market Growth
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • How Are New Technologies Reshaping Casino Surveillance And Security?
    • How Can Physical Security Technology Promote Better Executive Protection?
    • Responsible AI Adoption Starts With Governance
    • How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
    Enhancing Security At Lincoln's Inn With KeyWatcher

    Enhancing Security At Lincoln's Inn With KeyWatcher

    Enhance Hospitality Security With Key Control Systems

    Enhance Hospitality Security With Key Control Systems

    eCLIQ Enhances Security At Marin Hospital Of Hendaye

    eCLIQ Enhances Security At Marin Hospital Of Hendaye

    Alamo Colleges Boosts Safety With Alcatel-Lucent OmniSwitch Platform

    Alamo Colleges Boosts Safety With Alcatel-Lucent OmniSwitch Platform

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Technology's Role In Securing Banks And Financial Institutions
    Technology's Role In Securing Banks And Financial Institutions
    Securex Caspian 2026

    Securex Caspian 2026

    PACK EXPO Chicago 2026

    PACK EXPO Chicago 2026

    OFSEC - Oman Fire, Safety & Security Expo 2026

    OFSEC - Oman Fire, Safety & Security Expo 2026

    Milipol Qatar 2026

    Milipol Qatar 2026

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Software House
    • Eagle Eye Networks
    Other Resources
    • eMagazines
    • Videos
    Technology's Role In Securing Banks And Financial Institutions

    Technology's Role In Securing Banks And Financial Institutions

    Integrated Systems Enable Critical And Compliant Security For Transportation

    Integrated Systems Enable Critical And Compliant Security For Transportation

    Modernizing Physical Access Control

    Modernizing Physical Access Control

    Access. Intrusion. One Estate.

    Access. Intrusion. One Estate.

About us Advertise
  • Securing Financial Institutions
  • AI special report
  • Cybersecurity special report
  • 6
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Misguided Trust Leads To Increase In Security Risks And Potential Attack From Intruders

John Davies
John Davies
Contact company
Contact TDSi
icon Add as a preferred source Download PDF version
Quick Read
⌵
Summary is AI-generated, newsdesk-reviewed
  • Misguided trust in security protocols increases intruder attack risks in organizations.
  • Human nature and lack of rigorous policies weaken physical and logical security measures.
  • Implementing strict security measures prevents unauthorized access and curtails insider threats.
Taking the personal element out of security allows it to be more robust and to ensure trust is proven, rather than simply being assumed
Stringent security policies are necessary in an organization to prevent incidents
of misplaced trust leading to an attack from intruders

Trust is a word closely associated with both physical and logical security, after all, knowing who to trust is a key part of any security policy. However, when trust is wrongly assumed it rapidly becomes a key problem and a significant weakness in the security regime.

Often the weak link is human nature itself. This means that to begin to guarantee effectiveness it’s vital to have the right policies in place and to ensure that staff follow them, however draconian they may seem to the people operating and being subjected to them.

Testing Security In The Real World

A good example of misguided trust was recently documented. A so-called ethical hacker was employed to test the security regime of a client company. The management deliberately kept the operation a secret from the security team and staff at the business, to assure the accuracy of the results. Initially the hacker tried to gain access through online channels, which proved to be well guarded and highly secure.

The next step was for the hacker to enter the business facilities personally. This is where psychology played its part, the perpetrator kept up a friendly appearance and politely asked the reception team if he could use the toilet facilities, whereby the person behind the desk happily allowed him access to a non-public area. Bear in mind this was a complete stranger with no security credentials who had walked in off the street!

Perhaps the most disturbing part of the story is what happened next - the hacker left two USB keys in the toilet area for staff or visitors to find. On each drive he had included a specially designed piece of software that would auto-run and execute once accessed via a computer, stealing login credentials from the user and covertly sending them to the hacker. This effectively offers open access to the most secure parts of the company’s network! Inevitably, somebody who found the drives tried them in their computer and the hacker was informed shortly afterwards.

 

When hacking a company online proves unsuccessful, hackers can instead get on the company’s network by simply walking into the building
One example of misguided trust saw a hacker leave a USB in a company building. When an unsuspecting employee used it, malware was added to the company computer

Human Nature As A Weakness To Security Policy

What the example above really highlights is just how much human nature can play its part in the way security is upheld (or broken) in the real world. The hacker explained that his other choice may have been to hand the USB keys in to the reception and simply to say he had found them in the restrooms – which would, in all likelihood, have resulted in a similar outcome.

It is debatable whether the staff were complacent or simply used misguided judgment on what appeared to be a harmless visitor, albeit an unexpected one. The fact the hacker didn’t appear to be personally involved with this potential threat perhaps lowered the guard of the reception and security team still further. Of course those individuals that recovered the USB keys weren’t in any way coerced into using them, but curiosity got the better of them and the fact the uploaded malware gave no indication it was present (literally just silently taking security data) meant the company could have suffered some serious problems had it been for real.

Misuse Of Authorized Access

The consequences of misplaced trust in a secure environment can be severe, particularly with physical and logical security being so closely tied together now. It’s all well and good having impenetrable external IT security in place, but if this level of vigilance isn’t continued on the premises it can leave worrying vulnerabilities.

The example above shows how apparently good-natured assistance can be taken advantage of, but of course legitimate access can be misused by intruders in other ways too. The attacks on the Paris offices of Charlie Hebdo in January 2015 are a prime example of authorized access being hijacked, when an employee was threatened and forced to enter a code to help the terrorists gain entry and attack other members of staff.

Other examples include the ‘passback’ of security tokens between individuals (to gain multiple entry) and tailgating of unsuspecting members of staff as they enter secured areas. In a highly secure facility the protection measures need to anticipate these potential intrusion methods and provide solutions to combat them.

 

Rather than having to make a spontaneous judgement in an unfamiliar situation, staff will follow security procedure if it is clearly laid out
Tightened security policies can also prevent cases of people sharing access
credentials and tailgating – both of which can be serious access security risks

Security Measures For Countering Intruder Attacks

The most important lesson to be learned from all of these examples is that the culture of security within an organization is vital - the entire team needs to be vigilant and involved.  This culture needs to be regularly assessed and, if needs be, revised to close any gaps or potential loopholes of vulnerability. It is also not good practice to purely rely upon the intuition of staff, security or otherwise. In the ethical hacker example, there was no reason for staff to be suspicious but that is exactly how the planned attack succeeded. 

This is where a stringent and water-tight security policy is so important. Rather than making a judgment, staff follow procedure and a stringent policy will tell them not to simply plug an unknown USB stick into a company device or network! Added to this, staff won’t feel the same pressure to be a ‘Good Samaritan’ to unknown visitors – policy is policy and nobody will feel guilt for denying access in these circumstances.

The layout of security measures within a business facility is also very important. The reception area should be inviting (as the name suggests) but it should also show a strong defense to those not authorized to enter. Access control systems also need to be resilient, with automated monitoring for signs of tailgating and people counters to alert the security team of any abnormalities. Equally, its good practice to ensure these measures extend inside the secure areas of the facility too, just in case intruders gain access through another entry point.

Making Trust Trustworthy

Despite the potential problems from wrongly assuming trust, it is still an essential element of all business transactions and excellent security recognises this. Taking the personal element out of security allows it to be more robust and to ensure trust is proven, rather than simply being assumed. Often the deadliest threats to security are the least obvious ones.

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Physical security
  • Security management
  • Security policy
  • Security access systems
  • Facility security
  • Cyber security
  • Data Security
  • Related links
  • TDSi Access control systems & kits
  • TDSi Surveillance cameras
  • Articles by John Davies
  • Related categories
  • Surveillance cameras
  • Access control systems & kits
  • Intruder alarm system control panels & accessories
Related white papers
Technology's Role In Securing Banks And Financial Institutions

Technology's Role In Securing Banks And Financial Institutions

Download
Security Technologies Promote Real-Time Awareness In K-12 Schools

Security Technologies Promote Real-Time Awareness In K-12 Schools

Download
An End User's Guide To Physical Security For Data Centers

An End User's Guide To Physical Security For Data Centers

Download
Related articles
How Physical Security Consultants Ensure Cybersecurity For End Users

How Physical Security Consultants Ensure Cybersecurity For End Users

How Managed Detection And Response Enhances Cybersecurity Management In Organizations

How Managed Detection And Response Enhances Cybersecurity Management In Organizations

Drawbacks Of PenTests And Ethical Hacking For The Security Industry

Drawbacks Of PenTests And Ethical Hacking For The Security Industry

Follow us

Sections Products Video Surveillance Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cybersecurity special report RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Cyber security Counter terror Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy Californian Residents (CCPA)
  1. Home
  2. Topics
  3. Cyber security
  4. News
  5. Expert commentary
About this page

Boost security & reduce risks; uncover the illusion of safety and thwart potential attackers with smarter safety measures.

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SecurityInformed.com - Making The World A Safer Place
Copyright © Notting Hill Media Inc. 2000 - 2026, all rights reserved

Our other sites:
SourceSecurity.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Technology's Role In Securing Banks And Financial Institutions
Technology's Role In Securing Banks And Financial Institutions
Integrated Systems Enable Critical And Compliant Security For Transportation
Integrated Systems Enable Critical And Compliant Security For Transportation
Modernizing Physical Access Control
Modernizing Physical Access Control
Minimizing Storage, Maximizing Focus
Minimizing Storage, Maximizing Focus
Sign up now for full access to SecurityInformed.com content
Download Datasheet
Download PDF Version
Download SecurityInformed.com product tech spec