Electronic Access Control System Security Assessments
An electronic access control system decides who may enter your building, your data centre, your comms rooms and your secure areas. It is the control most organisations rely on most heavily, and examine least.
CCircle provides independent security assessments of electronic access control systems (EACS), covering the platform, the credentials, the network position and the governance that surrounds them.
The first line of defence
Physical access to a network is one of the most valuable things an adversary can obtain. Standing next to a port, inside a comms room, or beside a server changes what is possible. A great many controls that hold firmly against a remote attacker mean considerably less to someone who is physically present.
The electronic access control system is what stands between an adversary and that position. It is the first barrier, and in practical terms it is the outer boundary of your network perimeter, enforced at a door rather than a firewall.
That is worth stating plainly, because these systems are rarely resourced as though they carry that responsibility.
Access control is an identity system
Most organisations think of access control as hardware. Readers, doors, controllers, cards.
It is more useful to think of it as an identity system. It holds a population of identities, assigns each of them a set of entitlements, and enforces those entitlements thousands of times a day. That is exactly what an identity and access management system does in the ICT environment, and organisations govern their ICT identity systems carefully.
The physical equivalent is very rarely governed to the same standard. The same organisation that reviews privileged accounts quarterly, enforces multi factor authentication and revokes logical access the day someone leaves will frequently have no idea who currently holds physical access to its most sensitive rooms.
Access governance is where the risk accumulates
Access rights are granted quickly, because someone needs to get through a door today. They are almost never removed.
Over years, this produces a predictable outcome. Long serving staff accumulate access to areas they no longer have any reason to enter. People who changed roles keep the access from their old role and gain the access for the new one. Contractors retain access long after the contract ended. Cards issued to departed staff are never returned or revoked, and nobody can say with confidence which cards are currently active.
We assess the entire lifecycle. How access is requested, who approves it, whether approval is meaningful, whether it is reviewed, and whether it is genuinely revoked when a person leaves or changes role.
Credentials
The credential is the thing an attacker actually wants. We assess the card technology in use, the reader protocols, and how credentials are issued, managed and destroyed.
Legacy credential technologies remain widespread across Australia, including on sites that hold sensitive information, and many can be copied with inexpensive and commonly available equipment. A secure platform, correctly hardened and properly segmented, provides limited protection if the credential presented at the reader can be cloned in a corridor.
Integration is where systems quietly expand
Access control systems are rarely standalone. They integrate with HR systems, visitor management, building management, lifts, video, and increasingly with corporate identity platforms.
Every integration is a connection, a set of credentials, and a trust relationship. Each one expands the boundary of the system, and integrations are frequently commissioned once and never reviewed. We assess what your access control system is connected to, what those connections are permitted to do, and whether the trust placed in them is warranted.
What we assess
The platform.
Servers, operating systems and databases. Patching and currency, hardening against the manufacturer's published guidance, service accounts, operator roles, and audit logging.
Controllers and field devices.
Firmware currency, configuration, and the physical protection of the devices themselves.
Credentials and readers.
Card technology, reader protocols, and the issue, review and revocation of credentials.
Access governance.
Approval, review, revocation, privilege creep, and whether access reflects current need.
Identity and authentication.
Operator accounts, shared logins, multi factor authentication, and whether an action in the system can be attributed to a person.
Network position.
Segmentation from the corporate network, monitoring, remote access, and what an attacker who reached that segment could do next.
Integrations.
HR, visitor management, building systems, video, and corporate identity platforms.
Alignment with Australian requirements.
Assessment against the ISM and ACSC guidance, and where relevant the Protective Security Policy Framework, including security zones and the physical controls expected at each level.
What we typically find
The pattern here closely mirrors what we see in video systems, for the same underlying reason. These are networked ICT systems that continue to be governed as building systems.
- Environments that are flat, with no segmentation between the access control system and the wider network
- Remote sites connected without appropriate encryption, and connections established with weak or unsuitable configurations
- Controllers and end devices that are not updated, and not reviewed on any regular cycle
- Servers and operator workstations that are not patched regularly
- Manufacturer hardening guidance published, but never applied
- No visibility for the customer into the cyber security risk posture of their own access control system, and therefore no way to make an informed decision about it
- Access rights accumulated over years, with no review and no revocation process
- Shared operator accounts, so no action can be attributed to a person
- No multi factor authentication on the management platform
- Legacy credential technology still in service on sensitive sites
The final point is often the most consequential. An organisation cannot govern a risk it cannot see, and in most cases nobody has ever presented them with a clear picture of the security posture of this system.
Where CCircle fits
Our consultants work in the physical security systems space specifically, and understand these platforms in depth.
That depth matters, because access control is a live operational system. A control applied without understanding it will disrupt the site, and a control that disrupts the site gets reversed. Our objective is a system that is genuinely secure and still allows the organisation to operate.
Systems we work with
We are independent of the manufacturers. We do not sell, install or maintain access control systems, and we have no commercial relationship with any platform vendor.
We work across the systems in common use in Australian Government, Defence and critical infrastructure environments, including Gallagher, Lenel and Inner Range, ensuring deployments align with the manufacturer's published hardening guidance and that adequate cyber security controls are actually implemented, alongside the ISM and ACSC guidance.
Who this is for
Government agencies, Defence organisations, government suppliers and critical infrastructure operators, particularly where the site holds sensitive or classified information and physical access is a control the organisation is genuinely relying on.
Talk to us
To discuss an independent assessment of your access control environment, call 1300 045 483 or email info@ccircle.com.au