The attacker may rely on courtesy, distraction, crowding, or an open door rather than defeating the credential system directly. It is a physical-access form of social engineering, although not every unauthorized follow-through involves deliberate manipulation.
The person entering may pose as staff, a visitor, a contractor, or delivery personnel, or may simply blend into a group. Organizations use “tailgating” and “piggybacking” inconsistently, sometimes distinguishing entry without the authorized person’s knowledge from entry with their assistance.
Key points
Preventive controlsRequire individual authorization at controlled entrances, manage visitors and escorts, review door and sensor design, monitor exceptions, and make it easy for staff to contact security without confrontation.
If entry is suspectedNotify the designated security team, provide time and location details, preserve access and video records, and follow local incident procedures rather than physically intervening.
Authorized assessment onlyAny physical-access test needs explicit written authorization, defined scope, safety and stop conditions, and coordination with responsible personnel; unapproved attempts can create danger, disrupt operations, and invalidate the assessment.
Important limitationA shared doorway event does not by itself prove malicious intent, and anti-tailgating measures must preserve emergency egress, accessibility, privacy, and personal safety while applying policy consistently.