# What is Tailgating?

> A tailgating attack is an attempt to enter a controlled physical area by following an authorized person through an access point without presenting independent authorization.

- Canonical URL: https://yellowcube.eu/glossary/tailgating/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The attacker may rely on courtesy, distraction, crowding, or an open door rather than defeating the credential system directly. It is a physical-access form of social engineering, although not every unauthorized follow-through involves deliberate manipulation.

The person entering may pose as staff, a visitor, a contractor, or delivery personnel, or may simply blend into a group. Organizations use “tailgating” and “piggybacking” inconsistently, sometimes distinguishing entry without the authorized person’s knowledge from entry with their assistance.

### Key points

- **Preventive controls:** Require individual authorization at controlled entrances, manage visitors and escorts, review door and sensor design, monitor exceptions, and make it easy for staff to contact security without confrontation.
- **If entry is suspected:** Notify the designated security team, provide time and location details, preserve access and video records, and follow local incident procedures rather than physically intervening.
- **Authorized assessment only:** Any physical-access test needs explicit written authorization, defined scope, safety and stop conditions, and coordination with responsible personnel; unapproved attempts can create danger, disrupt operations, and invalidate the assessment.
- **Important limitation:** A shared doorway event does not by itself prove malicious intent, and anti-tailgating measures must preserve emergency egress, accessibility, privacy, and personal safety while applying policy consistently.

### Related terms

[Social engineering](<https://yellowcube.eu/glossary/social-engineering/>) · [Access control](<https://yellowcube.eu/glossary/access-control/>) · [Security awareness training](<https://yellowcube.eu/glossary/security-awareness-training/>) · [Insider threat](<https://yellowcube.eu/glossary/insider-threat/>) · [Identity and access management (IAM)](<https://yellowcube.eu/glossary/identity-and-access-management/>)

### Sources

[NIST SP 800-171 Rev. 3](https://csrc.nist.gov/pubs/sp/800/171/r3/final) · [UK National Protective Security Authority: Perimeters and checkpoints](https://www.npsa.gov.uk/building-protection/video-surveillance-access-control-detection-control-rooms/perimeters-checkpoints)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

