Navigating tailgating threats, legal risks and the imperative for modernisation, by Kasia Hanson, Vice President, Strategic Partnerships, Alcatraz.
Modern businesses are brimming with cloud apps, corporate networks, building management platforms and physical entry points.
That has raised the bar for what modern access control looks like, with increasingly sophisticated systems being deployed to monitor and protect premises.
AI is dramatically reshaping how organisations approach security modernisation.
Advanced analytics, machine learning and real-time monitoring tools enable proactive detection of anomalies and potential breaches in both physical and cyber environments. AI-driven access management systems can rapidly authenticate identities, flag suspicious behaviors and adapt to emerging threat patterns.
This transformation has led to improvements in incident response times, risk mitigation and operational efficiency, creating a more resilient security posture across industries.
Tailgating: A leading threat
Ironically, one of the most common ways intruders get in is still one of the most straightforward: Tailgating.
Bad actors simply walk through a supposedly secure entrance by closely following someone who belongs there. In one study, more than 60% of security leaders reported experiencing a tailgating breach in the past six months.
On one level, it’s mind-blowing that we’re still talking about such a low-tech risk in the era of AI-powered cyber-attacks. But tailgating persists because it is rooted in human behavior and exploits the realities of daily work.
People are distracted, assume that someone who looks the part probably belongs or they think that security is someone else’s responsibility.
Busy lobbies, multi-tenant floors and delivery-heavy operations create ideal conditions for someone to slip in unnoticed.
But many organisations also do their security no favours through their reliance on legacy systems like badge readers that only validate credentials rather than identity.
In these cases, tailgating becomes a predictable failure, not a rare exception. Organisations of all sizes need to modernise their approach to security.
The risks from tailgating
It’s easy to dismiss tailgating as a minor infraction until you map out risks it enables.
Unauthorised physical entry can lead to: Theft of equipment or even violent incidents; access to restricted areas such as executive floors, labs and operations rooms; cybersecurity breaches through access to network endpoints or server rooms.
The direct costs of a tailgating incident are familiar.
Investigation time, operational disruption, replacement of stolen assets and remediation. But the consequences spill out much further in the form of reputational damage, regulatory scrutiny and even litigation.
An open door for lawsuits
Tailgating creates legal risk because it is a known threat. The legal doctrine of “foreseeability” means that organisations must take proactive steps to prevent known risks or they may be held liable for resulting harm.
Courts expect organisations to demonstrate due diligence in protecting employees, customers and assets. As a result, outdated access control systems expose organisations to significant legal risk.
Failure to implement reasonable security measures, such as anti-tailgating technologies, visitor management protocols and regular system updates, can lead to allegations of negligence in the aftermath of a security breach.
Settlements in legal cases involving foreseeable security breaches can reach millions of dollars (Law.com). There are many cases where companies have faced costly lawsuits after violent entry events.
Often, plaintiffs contend that management ignored industry best practices, failed to maintain access logs or allowed security lapses to persist, thereby creating conditions for preventable tragedies.
These cases reinforce the necessity of modernising access control systems and regularly training staff on security protocols.
Deepfakes: A growing risk
Complicating things further is the rise of deepfakes. These AI-generated synthetic images and videos present a new risk to access control systems.
More basic visual verification tech has been fooled by photographs held up to a camera.
Reports of deepfake incidents targeting businesses and public figures are increasing, prompting security teams to strengthen detection and response strategies.
Smarter systems now incorporate measures such as liveness detection, which make it much harder for scammers to spoof their way in.
Security teams are increasingly adopting these systems as the threat of deepfakes grows – but organisations will need to stay informed about emerging deepfake tactics and continually update their posture to counter them.
A modern approach to access control
AI is driving a convergence of physical and cybersecurity. That will fundamentally change how organisations manage access.
The lines between physical and digital security are increasingly indistinct as a breach in one domain can compromise the other.
For instance, a tailgating event may facilitate unauthorised network access if the intruder gets access to IT infrastructure.
This convergence creates new opportunities for holistic security, but it also introduces unique challenges.
Security teams must adapt to managing hybrid threats, ensuring that access control systems protect both tangible assets and sensitive data.
Modern identity and access management solutions integrate biometric verification, behavioural analytics and real-time threat intelligence to monitor and control entry points.
The integration of AI tools is essential for correlating physical events with cyber-risks, enabling faster and more accurate responses to incidents.
Modernisation approaches for access control
Combatting the growing range of risks requires a multi-layered approach to identity and access modernisation.
This involves both technology upgrades and process improvements that enhance detection and response capabilities. These include:
- Unifying physical and digital access control – integrate physical and cybersecurity access management systems to establish a singular, cohesive threat-management framework
- Leveraging AI for enhanced security intelligence – implement AI-driven analytics to improve threat detection and response capabilities
- Ensuring continuous policy and technology modernisation – institute a regular review and update cycle for all access policies and underlying technologies to maintain a proactive stance against evolving threats
- Cultivating a security-conscious organisational culture – promote enterprise-wide security awareness, ensuring all personnel understand their roles and responsibilities
There are specific steps to take to combat the ever-present threat of tailgating.
These include: Deploying biometric access control with anti-tailgating technologies to detect and prevent unauthorised entry attempts; in particularly high-risk areas, implementing multifactor authentication – combining facial authentication with a mobile access credential reduces the likelihood of credential misuse; enhancing visitor management by adding biometrics to pre-registration processes.
The imperative for access control modernisation
A modern approach to security must go beyond entry points and provide a holistic view of risks in the digital and physical worlds. Organisations must integrate building entry systems with cybersecurity access management to create a single, cohesive framework for managing identity and threats.
Within that foundation, they can leverage AI-driven analytics to anticipate and prioritise risks as they evolve. And, to keep defences from drifting out of date, access policies and the technologies that enforce them should be reviewed and modernised regularly.
Tailgating remains one of the most persistent access control failures. But, AI-powered technologies are creating the possibility of eliminating it as a substantial risk for the first time in history.
As security professionals, we need to be willing to adopt these technologies and build the processes that will enable them to function effectively. By prioritising access control modernisation, security leaders can protect their people, assets and reputation in an era of unprecedented threat complexity.
