Your Biggest Security Threat May Already Have an Access Card
This article examines insider security risk and explains why authorised access can become a vulnerability when employee, contractor and service-provider permissions are not regularly reviewed. Eller Security discusses the role of access control, surveillance, guarding, risk assessment and investigations in identifying unusual activity and managing physical security as an integrated business function. The article highlights why South African businesses should continuously review who has access to their premises, what areas they can enter and whether those permissions remain necessary.

Most businesses spend a great deal of time thinking about how to stop unauthorised people from entering their premises. There are guards at entrances, cameras around buildings, alarms, visitor registers and increasingly sophisticated access control systems. All of these measures are important, but they can also create a dangerous sense of comfort because one of the more difficult security risks to manage is not necessarily the person trying to get in. It can be the person who is already authorised to be there.
Think about how many people can legitimately move through a commercial property during an ordinary working week. There are employees, contractors, cleaners, maintenance teams, delivery personnel, temporary workers and service providers. Some need access every day, some only occasionally, and others may need access to one part of the building but not another. Over time, people change roles, contracts end, employees leave and suppliers replace staff. Unless access permissions are being managed with the same discipline used to issue them in the first place, a business can very quickly lose sight of who can go where and why.
This is why access control should never be treated simply as a system for opening and closing doors. Modern systems can use cards, fingerprints, facial recognition, passwords and QR codes to control movement and provide a record of when people enter particular areas. The technology is useful, but it cannot compensate for poor security management. If someone has access to an area they no longer need to enter, the fact that the system correctly recognises their fingerprint does not make that access less of a risk.
The same applies to familiar faces. A security officer may see the same contractor arriving every week and naturally become accustomed to that person. An employee who has worked in a building for years may attract very little attention when moving through it. That familiarity is part of normal working life, but from a security perspective it is precisely why procedures matter. Security cannot depend entirely on whether somebody looks as though they belong there.
Businesses should therefore be reviewing access as an ongoing security responsibility rather than something dealt with when a person joins the organisation. Who currently has access to the premises? Which areas can they enter? Do they still require that level of access? How quickly are permissions changed when somebody moves departments or leaves? How is contractor access managed? What happens to temporary credentials? And, importantly, would the organisation recognise unusual activity from somebody whose credentials remain perfectly valid?
This is also where access control has to work with the wider security operation. A record showing that an authorised employee entered a restricted area at an unusual time may mean very little on its own. Surveillance can provide context. A trained security officer may notice behaviour that a system will not recognise as unusual. Where an incident has occurred, access records can also become important information during an investigation. The value comes from bringing those different pieces of security information together rather than expecting one system to provide all the answers.
None of this means businesses should begin treating their employees or contractors as suspects. It means recognising a basic reality of physical security: authorisation does not remove risk. A good security environment protects the organisation from external threats while maintaining sensible control over the access that has already been granted internally.
For many businesses, the next security vulnerability may therefore not require somebody to climb a fence, force a door or defeat an alarm. It may simply require someone whose access was never properly reviewed to use the credentials they already have.
Contact the Author
Want to reach out to the author?
Login to contact author