What is Tailgating in Cyber Security: The Physical Threat UK Businesses Overlook
What is tailgating in cyber security? Here’s what I’ve noticed over years working with UK businesses: most think security only happens on computers. They spend thousands on firewalls but never think about who walks through their front door.
The UK Government Cyber Security Breaches Survey 2025 found that 43% of businesses experienced security breaches in the last year. While phishing gets all the attention, physical breaches like tailgating let attackers steal laptops, plug in devices, or access networks directly. That means nearly half of all companies dealt with problems that could have started with someone just walking in behind an employee.
I’ll show you six practical methods to stop tailgating attacks at your business. You’ll learn what actually works, why these attacks succeed, and simple steps to protect your building without breaking your budget.
What is Tailgating in Cyber Security – The Simple Truth
What is tailgating in cyber security? Think of it like this: imagine you’re carrying a box into your office building. Someone behind you says “thanks” as you hold the door open. They walk in. They might be legitimate. They might not be. That’s tailgating. My cyber security consultancy services often start with this simple vulnerability that most businesses completely miss.
Here’s what I tell businesses in Birmingham and Manchester every week. An attacker doesn’t need hacking skills. They just need to look like they belong. They carry a coffee cup. They wear smart clothes. They time their arrival for busy morning hours when multiple people enter at once.
Picture this common scenario: it’s 8:45am at a Solihull office building. Employees rush in before their 9am meeting. Someone in a hi-vis vest carrying a clipboard follows closely behind three workers. The badge reader beeps once. All four people enter. Nobody questions it. By 9:15am, that person has plugged a device into your network or copied files to a USB drive.
Key Point
The main thing to remember: Tailgating works because it exploits human nature, not technology. We’re taught to be polite and hold doors open.
This makes tailgating one of the most effective physical security breaches. No hacking skills needed. Just confidence and timing.
How Tailgating Attacks Work – What Actually Happens
Let me break this down into the methods attackers actually use. Understanding credential theft in cybersecurity helps, but tailgating is even simpler than stealing passwords.
Here’s what actually works for attackers:
- The Morning Rush Method: Arrive between 8:30-9:00am when employees stream in. People are distracted, checking phones, carrying coffee. Security is lowest.
- The Helpful Colleague: Carry something bulky like boxes or a laptop bag. Stand near the door. Someone will hold it open for you because you look busy.
- The Contractor Disguise: Wear a hi-vis vest or carry tools. Most employees assume contractors are legitimate and don’t challenge them.
- The Smoker’s Door: Wait near the smoking area or side entrance. These doors often have weaker security and fewer people watching.
Think about it this way. Your front door might have expensive badge readers and cameras. But your side entrance? The one employees use after lunch? Often just a basic lock with a handful of people coming and going. Attackers know this. They watch your building for a few days. They learn the patterns.
Once inside, malware protection best practices don’t matter if someone’s plugging infected USB drives directly into your computers. Physical access defeats most technical security.
Types of Tailgating Attacks
The reality for most businesses is they don’t know what to watch for. Here are the four main types I see:
| Attack Type | How It Works | What They’re After |
|---|---|---|
| Physical Tailgating | Following employee through door after they badge in | Access to building, offices, server rooms |
| Digital Tailgating | Using unlocked workstation or stolen laptop still logged in | Network access, files, credentials, email accounts |
| Piggybacking | Employee knowingly allows entry (being polite or pressured) | Same as physical tailgating but harder to detect |
| Backdoor Installation | Once inside, installing device for remote access later | Long-term network access without returning to building |
What I generally recommend is understanding the difference between tailgating and piggybacking. Tailgating happens when the employee doesn’t realise they’re helping an attacker. Piggybacking is when they knowingly let someone in. Both are dangerous.
Why Tailgating Attacks Succeed – Common Mistakes
I see the same mistakes over and over at UK businesses. Understanding user access control best practices helps with digital security, but physical security needs different thinking. Here are the big ones:
Watch Out For This
Most businesses do this wrong: They spend thousands on network security but have zero physical security policies. Employees don’t know if they should challenge strangers in the building.
Create a simple rule: every person must badge in separately. If someone asks you to hold the door, politely say “sorry, security policy” and let them use their own badge. No exceptions.
The good news is these problems are fixable without massive expense. You don’t need expensive turnstiles or security guards. You need clear policies and Cyber Essentials compliance that includes physical security awareness.
Here’s what tends to happen: someone spots a stranger in the office. They think “maybe they’re from another department” or “maybe they’re visiting someone”. They don’t want to seem rude by asking. The stranger walks around for 20 minutes. By then it’s too late.
What Attackers Do Once Inside
Let me share what I’ve seen happen when tailgating works. This is where it gets serious:
| Once Inside | Time Needed | Potential Damage | Detection Difficulty |
|---|---|---|---|
| Steal unlocked laptop | 2-3 minutes | Access to all files, emails, network credentials | Easy – noticed quickly when missing |
| Install USB keystroke logger | 10 seconds per computer | Captures every password typed | Very hard – tiny devices behind PC |
| Plug in rogue Wi-Fi device | 30 seconds | Creates backdoor into network | Hard – looks like normal equipment |
| Access unlocked workstation | 5-10 minutes | Install malware, steal data, send emails | Medium – depends on office layout |
| Take photos of whiteboards/documents | 1-2 minutes | Steal confidential plans, strategies, credentials | Very hard – looks like using phone |
According to the latest UK government data from 2025, ransomware attacks doubled compared to 2024, affecting approximately 19,000 organisations. Many of these started with physical access through tailgating. Once someone plants a device on your network, they can launch ransomware attacks remotely without ever returning to your building.
6 Methods to Stop Tailgating Attacks
Here’s how to protect your business without breaking your budget. Was someone legitimate or trying to tailgate? Here’s how to tell:
- Badge-in policy: Every person uses their own badge. No exceptions. No holding doors. Train staff that this isn’t rude, it’s security.
- Visitor procedures: All visitors sign in at reception. They get a visible visitor badge. They’re always escorted. No wandering alone.
- Challenge unknown people: If you see someone without a badge, politely ask “can I help you find someone?” This lets you verify they’re legitimate without being confrontational.
- Lock screens immediately: Set computers to lock after 2 minutes of inactivity. Use password-protected screensavers. Never leave workstations unlocked when you step away.
- Secure side doors: That door smokers use? The one staff prop open in summer? These need the same security as your main entrance.
- Security awareness training: Run scenarios with staff. Show them what tailgating looks like. Practice challenging strangers politely but firmly.
What Works Best
In my experience working with organisations: The single most effective method is empowering staff to challenge strangers. When employees know it’s okay to ask “do you need help?”, most tailgating attempts fail.
This approach works because attackers rely on people being too polite to challenge them. Remove that assumption and tailgating becomes very difficult.
The thing about cyber security is physical and digital protection work together. You can have perfect network defences, but if someone walks in and plugs a device into your network, those defences don’t help. Understanding zero trust security for small businesses means verifying everyone, every time, including at physical doors.
Tailgating Prevention Tools and Techniques
The reality for most businesses is they can’t afford security guards at every entrance. Modern technology helps. Here’s what tends to work for UK SMEs:
- Mantrap doors: Two doors with a space between. First door must close before second door opens. Only allows one person through at a time.
- Turnstiles: Physical barriers that require badge access. More expensive but very effective at stopping tailgating.
- CCTV monitoring: Cameras that count people entering versus badge swipes. Sends alerts when numbers don’t match.
- Smart building systems: Modern access control that logs every entry with photos. Creates audit trail of who entered when.
- Motion sensors in secure areas: Server rooms and sensitive areas get extra monitoring. Alerts security if someone enters without authorisation.
Picture this common scenario: a London tech firm installed basic door counters. The system counted badge swipes and actual people entering. Within the first week, they caught three tailgating attempts they’d never have spotted otherwise.
Protecting against supply chain attacks requires similar thinking about trust and verification at every entry point.
Cost-Effective Security Measures
| Method | Best For | Difficulty | Cost Range |
|---|---|---|---|
| Security awareness training | All business sizes | Easy | Low |
| Visitor management system | Businesses with regular visitors | Easy | Low to Medium |
| CCTV with alerts | Medium to large businesses | Medium | Medium |
| Turnstiles or mantraps | High-security environments | Hard | High |
| Security guard presence | Large businesses, high-risk locations | Easy | High (ongoing cost) |
Preventing Tailgating Attacks – Getting Started Today
Here’s my advice for getting this right without spending months on planning. Understanding vulnerability management means addressing both digital and physical security gaps:
- Write a clear policy: One page. Simple rules. Everyone badges in separately. No exceptions for senior staff or frequent visitors. Post it by every secure entrance.
- Train your reception team: They’re your first line of defence. They need to know how to handle visitors properly, issue visitor badges, and challenge people without badges.
- Run a test: Have someone unknown try to follow employees in. See what happens. This shows you where your real gaps are.
- Fix the easiest problems first: Side doors. Smoking areas. Delivery entrances. These are usually your weakest points and cheapest to improve.
- Monthly reminders: Send a quick email or mention it in team meetings. Keep physical security in people’s minds. Most attacks happen when awareness drops.
- Review quarterly: Check your visitor logs. Review CCTV footage. Look for patterns. Adjust your approach based on what you find.
Quick Win
Start here today: Walk around your building right now. Try all the doors. Which ones have weak security? Which ones are propped open? Make a list. Fix the worst one this week.
This 10-minute audit often reveals problems you’ve walked past for years without noticing.
Real-World Tailgating Examples
Let me share what I’ve seen in the field without naming names. A Birmingham professional services firm had excellent network security. Firewalls, encryption, regular security checks, the lot. They got breached anyway.
How? Someone in a Royal Mail uniform followed an employee through the side entrance at 2pm. They walked straight to the server room. The door wasn’t locked. They plugged in a small device that created a Wi-Fi network. They left after 3 minutes. Nobody noticed because they looked like they were delivering a parcel.
For the next two months, attackers accessed their network remotely through that device. They stole customer data. The company only discovered the breach when a customer complained about suspicious emails. The investigation found the device plugged into a switch in the server room.
Another example from Manchester. A retail company spent significant money on cyber security tools. They had regular testing. Everything looked secure. Then one evening, someone followed the cleaning crew in at 6pm. The cleaners didn’t challenge them because they assumed they were an employee working late.
That person spent 45 minutes in the office. They installed keystroke loggers on 15 computers. Over the next month, they captured login credentials for email, banking systems, and customer databases. The company only found out when they ran routine checks and discovered the devices.
The Future of Physical Security
What I generally recommend is preparing for what’s coming next. Physical and digital security are merging. The UK Government survey shows medium and large businesses face increasingly sophisticated attacks.
The latest research from 2025 shows that:
- Remote work increases risk: Fewer people in offices means strangers stand out less. Empty buildings are easier targets for physical breaches.
- AI-powered surveillance: New CCTV systems use AI to spot tailgating automatically. They alert security when someone follows too closely through doors.
- Biometric access control: More businesses use fingerprint or facial recognition. Harder to fake than badges. Makes tailgating more difficult.
- Integration with digital systems: Physical access logs now connect to cybersecurity tools. Alerts trigger if someone accesses building then network shows unusual activity.
The Cyber Essentials scheme now asks more questions about physical security. The government recognises that buildings are part of your security level, not separate from it.
Building Your Defence Strategy
The thing about cyber security is it’s not a one-time fix. Think of it like maintaining a car. Regular checks. Small adjustments. Staying alert to new problems.
Here’s what I tell businesses: start simple. Get the basics right first. Train your staff. Write clear policies. Test them regularly. Then add technology as budget allows.
The most expensive security system in the world won’t help if your employees hold doors open for strangers. The cheapest solution that works is better than the most sophisticated solution that nobody follows.
Most importantly, remember that tailgating succeeds because of human nature, not technical failures. We want to be helpful. We don’t want to seem rude. Attackers know this and exploit it ruthlessly.
Create a culture where challenging strangers is normal and expected. Make it clear that security isn’t about being unfriendly. It’s about protecting everyone who works there and the data you’re responsible for.
Understanding what is tailgating in cyber security helps you protect your business from one of the simplest but most effective attacks that bypass all your expensive technical defences.
Need Help With Physical Security?
I help UK businesses strengthen their security through practical guidance that combines physical and digital protection.
Learn more about my cyber security consultancy services and how we might work together to close security gaps at your organisation.
Common Questions
What is the difference between tailgating and piggybacking in cyber security?
Tailgating happens when someone follows you through a secure door without your knowledge. You don’t realise they’re there or you’re too distracted to notice. Piggybacking is when you knowingly allow someone to enter without their own credentials. This might be holding the door open for someone carrying boxes or letting a colleague in who forgot their badge. Both are security risks, but piggybacking is often harder to address because the authorised person made a conscious decision to allow entry. The solution for both is the same: require everyone to use their own access credentials every single time they enter.
How can small businesses prevent tailgating without expensive security systems?
You don’t need expensive turnstiles or security guards to stop tailgating. Start with clear policies that everyone must badge in separately. Train staff that it’s not rude to ask strangers for help or to direct them to reception. Install simple door sensors that alert when a door stays open too long. Use visitor sign-in systems that issue visible visitor badges. Create a culture where challenging unknown people is normal and expected. These measures work because tailgating relies on people not questioning strangers. When your team knows to challenge anyone without a badge politely but firmly, most tailgating attempts fail immediately. Focus on people and processes before spending on technology.
What should employees do if they suspect someone has tailgated into the building?
Approach them calmly and politely with “can I help you find someone?” or “do you need directions?” This lets you verify they’re legitimate without being confrontational. If they claim to be visiting someone, walk them to reception to sign in properly. If they can’t explain why they’re there or become defensive, inform security or management immediately. Never physically confront someone or put yourself at risk. Most genuine visitors will appreciate the help. Attackers often leave when challenged because they rely on not being noticed. The key is making it normal to ask these questions rather than assuming everyone belongs. Regular training helps employees feel confident doing this.
Does tailgating only affect large businesses with multiple offices?
Small businesses are actually at higher risk because they often have weaker physical security and fewer people watching who enters. A small office can still suffer serious damage from tailgating. Someone could steal laptops, access computers left unlocked, or install devices on your network. The principles are the same regardless of company size. You need visitor procedures, clear policies about holding doors open, and staff awareness of the risks. Small businesses often have an advantage because everyone knows each other, making strangers more obvious. Use this to your benefit by encouraging staff to greet everyone they see and politely question people they don’t recognise. Size doesn’t protect you from physical security threats.
How often should businesses review their physical security procedures?
Review your physical security quarterly at minimum. Check your visitor logs to see if procedures are being followed. Walk around the building looking for propped-open doors or bypassed security measures. Test your systems by having someone unknown attempt to enter. Pay extra attention when you move offices, change staff, or alter working patterns like allowing more remote work. These changes create gaps in security awareness. Also review immediately after any security incident, even minor ones. A quarterly schedule keeps physical security in people’s minds and helps you spot problems before they become serious breaches. Regular reviews show staff that security matters and encourages compliance with policies.
What are the signs that someone is attempting to tailgate?
Watch for people who hesitate before entering, looking to see if someone’s approaching the door. They often carry items like coffee cups or boxes to appear busy and legitimate. They time their approach carefully to arrive just as someone else badges in. Common tactics include pretending to search for a badge while standing very close to the door, engaging in friendly conversation to distract you, or dressing as delivery drivers or contractors. After hours, be extra suspicious of anyone following cleaning crews or maintenance workers. The key sign is someone who doesn’t use their own credentials but tries to enter immediately after you. Trust your instincts. If something feels off about a situation, it probably is. Better to politely check than assume everything’s fine.
Can cyber security tools detect physical tailgating attacks?
Modern security systems can help detect tailgating through integration between physical and digital tools. Access control systems that log every badge swipe can be compared with CCTV footage counting actual people entering. Smart building systems with weight sensors or advanced cameras can alert security when more people enter than badges swiped. Some newer systems use artificial intelligence to analyse CCTV footage and automatically flag potential tailgating. However, technology alone isn’t enough. The most effective approach combines these tools with strong policies and staff awareness. Think of technology as supporting your processes, not replacing them. Even the best systems need someone monitoring alerts and responding appropriately. Staff vigilance remains your primary defence against tailgating.