OT & Industrial Systems Security

Physical and Cyber Convergence in Critical Facilities

Back to program
Physical and Cyber Convergence in Critical Facilities
In a critical facility, physical security and cybersecurity are not two separate programs that happen to share a building -- they are two halves of the same protection problem, and treating them independently creates gaps that a determined adversary (or a careless insider) will find. Physical access to a control room, a substation, or an equipment cabinet often bypasses network-layer security entirely: a person with physical access to a PLC can connect a programming cable directly to it, completely outside any firewall, VPN, or network monitoring that the security team spent months designing. This is why badge access logs, cabinet locks, and physical access review for control system spaces deserve the same rigor as network access review -- they are, functionally, the same control category. Building management systems (BMS), physical access control systems (PACS), and video surveillance are themselves increasingly networked, IP-based systems with their own cybersecurity exposure -- a compromised badge reader system or camera network is not just a physical security failure, it is a foothold onto a network that may have further reach into operational systems than anyone realized when it was installed. Converged security governance -- where physical security, facilities, and cybersecurity teams share visibility into access events, incidents, and risk decisions -- consistently catches scenarios that neither team would catch alone: an after-hours badge entry combined with an unusual engineering workstation login, for example, is a much stronger signal together than either event is in isolation.
Reading 6 minutes
Lesson Reflection