Physical security is one of the key elements in Security besides the human and technology part. The three elements basically linked together in an equal manner where hackers always try to find an entry access in one of the elements. A organization which have for example a state of the art firewall with IPS and IDS functionality and is fully patched and hardened is very difficult to defeat by an attacker. But what if the organization has no strong physical security system implemented where an attacker easily could walk into the building and connect a malicious device in one of the network sockets that is in an unprotected area.  A strong Physical Access Control Systems (PACS) becomes very relevant in this case for enterprise organizations.

But having a strong physical security doesn’t prevent hackers to try to gain unauthorized access to the facility by manipulating the system vulnerabilities and cause damage. This blog shows some examples and crucial dangers for PACS from an attacker perspective.

The following attack scenarios can be used by an attacker: