Last updated: April 29, 2026
A Hyderabad data centre operator passed every cyber audit. Then a “courier” walked into the facility carrying a fake delivery, tailgated through a side door behind a smoking employee, and spent 40 minutes in the server hall photographing rack labels and one open KVM session. The recording from the lobby camera arrived for review three days later. Physical security is the layer that crashes spectacularly when treated as facilities-team problem disconnected from cyber. This module covers physical security as a security-engineering discipline.
Why physical security is a cyber concern
Cyber controls assume an attacker is on the network. Physical access defeats most of them:
- Bootable USB on an unlocked workstation = local admin in 90 seconds
- Plugged-in HID device (Rubber Ducky / Bash Bunny) = keystroke injection with one user touch
- Network-tap on cable = mTLS-bypassing wire-tap if endpoints don’t enforce
- Camera over a screen = MFA token capture during operator session
- Server hall access = direct disk imaging, RAM dump (cold-boot attack), iLO/iDRAC capture
Physical breach often costs less than zero-day acquisition.
The defence layers
Perimeter
- Fencing, vehicle barriers (where applicable for facilities)
- External CCTV with overlapping fields-of-view; 90-day retention minimum
- Lighting — motion-activated for after-hours; break-in deterrent
Building entry
- Mantraps for high-security zones (data centres, SOC) — one door at a time
- Biometric + smart-card dual-factor for sensitive zones
- Tailgating prevention — turnstiles, monitored mantraps, anti-passback rules
- Visitor management — pre-registered, photo, badge, escort, audit-logged
Server hall / equipment areas
- Cabinet locks — managed via electronic locks with audit trail (Smartrac, dirak, Southco)
- Cabling under raised floor or in ceiling — prevents tap installation
- Camera coverage of every aisle, retained 90 days
- No personal devices — phones in lockers; only approved cameras / laptops
- Sign-in / sign-out for every visit; quarterly review
Workstation / desk security
- Auto-lock on idle (5 minutes max for sensitive roles, 15 for general)
- Cable lock for laptops in shared spaces
- Privacy screens for shoulder-surfing risk
- Clean-desk policy — sensitive documents in lockable drawers; bins disposed via shred
- USB-port disable / control via endpoint management for non-developers
The Hyderabad DC remediation
After the courier incident, the operator implemented:
- Mantrap-only entry to server hall with biometric + card; tailgating physically impossible
- Smoking area moved away from any entry door; all side doors alarmed-only, no badge use
- “Challenge unfamiliar visitors” baked into staff training — three-monthly refresher with measurable test (planted social-engineer attempts)
- Visitor management upgraded to photo-ID scanning, named-host approval, badge that auto-deactivates at end of visit
- Lobby camera review automated for tailgating events using video analytics — alerts within 60 seconds
Subsequent red-team physical assessment two quarters later: zero successful intrusion attempts. Cost of programme: ₹35 lakh in tech + ongoing training. Cost of the next incident: avoided.
Red-team physical penetration testing
Most Indian organisations skip physical pen-testing because it’s expensive and management-uncomfortable. Quality firms charge ₹5-15 lakh for a 5-day physical engagement covering:
- Reconnaissance — public records, social media, shift-pattern observation
- Pretexting — impersonation of vendor, courier, regulator, fire-safety inspector
- Tailgating attempts
- Lock-picking and badge-cloning if scoped
- Once inside, network-tap planting, USB drops, dumpster-diving
Sample finding from a 2024 engagement at an NBFC: tester walked into the back-office with a fake AC-maintenance work order, planted a Wi-Fi pineapple in a network closet, captured 47 employee credentials over two days, and was never challenged.
USB / removable media
- Block USB mass-storage by default; allow-list for approved devices via endpoint management (CrowdStrike, Microsoft Defender for Endpoint, Trellix)
- USB drop tests — leave 20 USBs in the parking lot with a calling-home file. Indian organisations consistently see 30-50% plug-in rate
- Charging-only USB cables in airports, hotels, public spaces — prevent juice-jacking
- For high-risk roles, USB ports physically disabled or filled with locking blockers
Indian compliance mapping
- RBI Cyber Framework — physical security of data centres mandatory; periodic review
- SEBI CSCRF — physical security explicit for Q-RE / MII facilities
- ISO 27001:2022 A.7 — physical and environmental controls (the entire chapter)
- UIDAI — Aadhaar data-centre physical security mandates: biometric mantraps, 90-day camera retention, segregated rack zones
- DPDP §8(5) — reasonable security safeguards include physical protection
Common gaps
- Smoking-area side doors propped open
- Cleaning crew with unsupervised after-hours access
- Vendor / contractor badges that don’t expire automatically
- Server-room cabinet keys held in unsecured drawers
- Visitor logs handwritten and never reviewed
- Loading docks where deliveries enter without screening
- CCTV recording but no review and no retention enforcement
Try this in your environment
- Walk to your office’s least-monitored entry. Could you tailgate? Time how long until challenged.
- Drop five labelled USB drives in your parking lot. Track plug-in attempts via the DNS-callback file.
- Audit visitor logs for the last quarter. How many “vendor” entries with no host-name? How many no-badge-return events?
- Review your CCTV — does it actually cover the chokepoints? When was footage last pulled and reviewed?
- Schedule a physical pen-test next budget cycle. Find out what an attacker actually can do.
Physical security is where good cyber defenders lose to mediocre social engineers. Cyber and physical have to be one programme — same threat model, same review cadence, same ownership. The Hyderabad courier didn’t need to bypass a single firewall.
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.