5 min read

Physical Access Has Become Digital Identity

Employee badges, visitor passes and contractor credentials are no longer just physical access tools. They have become security identities that require the same governance, lifecycle management and oversight as digital accounts.
Physical Access Has Become Digital Identity
Foto E. Mehler 2025

Part 6 of the series 

The Building Is Now Part of the Attack Surface


By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.


Identity has always been one of cybersecurity’s most valuable assets.

Today, it has also become one of facility management’s most critical responsibilities.

For decades, physical access and digital identity evolved along separate paths.

One was managed by keys, locks and security guards.

The other by user accounts, passwords and directory services.

That distinction no longer exists.

Modern buildings no longer ask only who may enter.

They ask:

  • Who are you?
  • Which identity are you using?
  • Which areas may you access?
  • At what time?
  • Under which conditions?
  • With which device?
  • Based on which business role?
  • Who approved your access?
  • Who can revoke it?

Those are not merely facility questions.

They are identity governance questions.

From Keys to Identities

Mechanical keys represented possession.

Digital credentials represent identity.

An employee badge today is no longer simply a piece of plastic.

It is a digital identity token.

It may interact with:

  • Active Directory,
  • Microsoft Entra ID,
  • HR systems,
  • visitor management,
  • parking systems,
  • elevators,
  • secure rooms,
  • printing systems,
  • vending,
  • time recording,
  • authentication platforms.

A single identity increasingly governs both digital and physical privileges.

Compromising one may compromise the other.

The Illusion of Separate Security

Many organisations still separate responsibilities.

Facility Management manages badges.

Corporate Security defines access policies.

HR manages employment status.

IT manages identities.

The CISO governs cyber risk.

Individually, every function performs well.

Collectively, they often fail.

Consider a common scenario.

An employee leaves the organisation.

The network account is disabled immediately.

The building badge remains active for another week.

The contractor account remains active for another month.

The parking credential remains valid.

The visitor application still contains privileged access.

No individual team failed.

Governance failed.

Physical Access Is Privileged Access

Cybersecurity invests enormous effort in protecting privileged accounts.

Yet many organisations still underestimate privileged physical access.

Who can enter:

  • data centres,
  • network rooms,
  • communication cabinets,
  • building automation rooms,
  • security control centres,
  • executive offices,
  • archive facilities,
  • crisis management rooms,
  • backup storage?

The answer should concern every CISO.

Physical access often bypasses digital controls entirely.

No firewall prevents someone with authorised physical access from connecting an unauthorised device.

No endpoint protection prevents someone from accessing exposed infrastructure inside an unlocked technical room.

Identity governance therefore begins long before login.

Every Badge Is an Account

One useful perspective changes executive thinking immediately.

Treat every physical credential exactly like a digital account.

It should therefore have:

  • an owner,
  • a defined purpose,
  • documented approval,
  • lifecycle management,
  • periodic review,
  • rapid revocation,
  • auditability.

Suddenly, familiar cybersecurity principles become directly applicable to physical security.

The Forgotten Lifecycle

Identity governance is fundamentally about lifecycle management.

Creation.

Modification.

Suspension.

Removal.

The same applies to physical access.

Questions include:

  • Who requests building access?
  • Who approves it?
  • Is temporary access automatically revoked?
  • Are contractor badges reviewed?
  • How are lost credentials handled?
  • Are emergency badges monitored?
  • Who validates visitor permissions?
  • Which access rights survive organisational change?

Every forgotten badge represents forgotten privilege.

Visitors Have Become Digital Users

Visitor management has changed dramatically.

Reception books have disappeared.

Visitors now interact with:

  • online registration,
  • QR codes,
  • cloud platforms,
  • identity verification,
  • mobile credentials,
  • digital invitations,
  • self-service kiosks.

These platforms process:

  • names,
  • contact details,
  • photographs,
  • visit history,
  • host information,
  • building locations,
  • access permissions.

Visitor management is no longer merely an administrative function.

It is an identity service.

Like every identity service, it deserves security governance.

Contractors Blur Organisational Boundaries

Contractors create one of the largest identity challenges.

They require:

  • physical access,
  • network access,
  • remote maintenance,
  • temporary privileges,
  • after-hours availability,
  • recurring visits.

Many organisations manage contractor identities manually.

Spreadsheets.

Emails.

Paper forms.

Local badge databases.

Disconnected systems.

The result is predictable.

Nobody possesses a complete picture of who can access what.

Identity Synchronisation

Modern buildings increasingly synchronise identities automatically.

HR updates employment status.

Identity platforms update user accounts.

Access-control systems receive new permissions.

Parking systems activate credentials.

Meeting-room systems allocate privileges.

Automation improves efficiency.

It also introduces dependency.

A single synchronisation error can unintentionally grant—or revoke—physical access across multiple locations.

Identity governance therefore extends beyond IT.

It becomes enterprise governance.

Identity Data Is Sensitive Information

Physical access systems collect more information than many organisations realise.

Examples include:

  • movement history,
  • building occupancy,
  • access attempts,
  • arrival times,
  • departure times,
  • location patterns,
  • contractor activity,
  • visitor behaviour.

Combined with HR data, these records create highly sensitive organisational intelligence.

Who meets whom.

Which facilities are occupied.

Which secure areas receive unusual activity.

Who entered critical infrastructure.

Protecting these datasets is not only a cybersecurity issue.

It is also a matter of privacy, trust and legal compliance.

Identity Without Monitoring

Many organisations successfully issue badges.

Far fewer continuously analyse their usage.

Questions worth asking include:

  • Why is a contractor accessing the building at midnight?
  • Why is a badge active simultaneously at different locations?
  • Why are repeated access denials occurring?
  • Why does an employee suddenly access technical rooms never previously visited?
  • Why is a terminated identity still generating physical events?

Identity governance does not end when access is granted.

It begins there.

The Convergence of IAM and Physical Security

Identity and Access Management has traditionally focused on digital systems.

That boundary is disappearing.

Future IAM programmes will increasingly govern:

  • digital identities,
  • physical identities,
  • machine identities,
  • building credentials,
  • contractor identities,
  • service identities,
  • visitor identities.

The organisation should not ask whether physical access belongs inside IAM.

It should ask why it was ever excluded.

Zero Trust Reaches the Building

Zero Trust is often summarised as:

“Never trust. Always verify.”

Buildings have traditionally followed the opposite philosophy.

Once a person entered the building, trust increased.

Modern security requires continuous verification.

Identity.

Role.

Purpose.

Time.

Location.

Privilege.

Business need.

Physical security is becoming contextual security.

What Mature Organisations Do Differently

Organisations with mature governance:

  • integrate physical and digital identity lifecycles,
  • automate access revocation,
  • review contractor privileges regularly,
  • classify technical areas as privileged environments,
  • monitor abnormal physical-access behaviour,
  • integrate access events with the SOC,
  • include physical identities in governance reporting,
  • align Facility Management, HR, Corporate Security and IAM.

Most importantly, they stop treating badges as administrative objects.

They recognise them as security identities.

Conclusion

Cybersecurity has spent years protecting digital identities.

Physical security has spent decades protecting buildings.

Today those two disciplines are converging.

The question is no longer whether someone can enter a building.

The question is what that identity allows them to do—both physically and digitally.

Because in modern organisations, physical access is no longer simply access to a building.

It is access to information.

To infrastructure.

To operations.

To trust.

And every trusted identity—whether digital or physical—has become part of the enterprise attack surface.


Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.

For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.