Physical Information Security Improves Protection by Controlling Access

FC Barker talks about physical information security and why trust can be dangerous.

FC Barker runs a cybersecurity and pen testing company, where they try to break into other companies to test how good their security really is. But he doesn’t just use his ethical hacking skills to test their digital security measures. He also tests physical security – breaking into physical locations and using a combination of traditional breaking-in skills and social engineering to see how a company’s physical information security stacks up.


See Exploiting Trust (Part 2) with FC Barker for a complete transcript of the Easy Prey podcast episode.

FC, better known by his hacker alias Freakyclown, has been a cybersecurity pro for over three decades. His career has included working as a pen tester, sysadmin, and head of physical security. His last job was head of cyber research at Raytheon; he left that job to start Cygenta, a cybersecurity company, with his wife. Though the company started as primarily cybersecurity, he started taking notes on physical information security issues he saw while doing his other work. One client appreciated these notes so much that they asked him to do just a physical security assessment at their other location. From there, testing physical as well as digital security became another service Cygenta offered.

This is the second part of a two-part series with FC. Read the first part, where FC discusses the tactics he uses and what they reveal about common security weaknesses, here.

It’s Still the Simple Problems

The biggest physical information security issue FC saw in the early days was companies relying on poorly-placed CCTV cameras. The most ridiculous ones were low enough that someone could easily move them. And nobody was looking at the feeds. That’s still common, actually. It’s very rare for a company to have someone staring at the monitors because there’s generally so many of them.

Another issue was people just shouting private information across the room. FC wrote a book, How I Rob Banks, that shares a lot of stories from his time doing physical and digital information security testing. One of the stories in the book is about a woman who shouts a building door code to a coworker down the street while FC was trying to break in. That’s a big security problem!

It’s really the simple, foundational things that are still major issues for security. That’s true both for physical and digital security. In that sense, not a lot has changed, security-wise, in the last thirty years.

It’s the simple foundational security [issues] that we see even today … not much has changed in the last 30 years.

FC Barker

Security is Inconvenient

Just like in cybersecurity, one of the difficulties in physical information security is that it’s inconvenient. The more measures you put in place that prevent people from doing their jobs efficiently, the more problems you’re going to have. People will find ways around them. It’s not necessarily malicious. But people want to get on with their jobs. If you block sending external emails on the company’s Office 365 and someone really needs to do that, they’ll just start using Gmail. If people see the security measures as a roadblock to doing their jobs, they’re going to find ways around it.

The more you put things in place that prevent people from doing their job, the more issues you’re going to find …. People will find ways around it.

FC Barker

In one instance, FC was working with a government defense company. They used a sneakernet system – instead of digitally transferring files, they put them on hardware storage devices and physically walked them from one place to another. It was an air gap system, and one of the few FC has seen that worked really well. He was in there late one night, talking to one of the people working on the project, and asked him to send him some stuff. He handed FC a USB key on a keyring that also had his car and house keys. It turned out that he was taking this USB full of extremely sensitive information home every night because it was convenient to have it on his key ring. That’s not good physical information security.

A Combination of Reasons

There are multiple reasons why people are so quick to circumvent security procedures. One of them is that people just aren’t thinking about security. The other is that sometimes security measures are so cumbersome that they interfere with doing their job. If you put in something that doesn’t work or is too onerous, they’ll find a way around it. Most of the time it isn’t malicious. People aren’t intentionally trying to compromise their company’s digital or physical information security. They’re just trying to do their job.

People will find a way around it. … 99% of the time it’s not malicious. They’re just trying to do their job.

FC Barker

Think about the common advice of not clicking links in emails. If someone clicks a malicious link and it infects your entire network, you had a technical failure that let the threat get that far. The person clicking the link didn’t do anything wrong. Part of their job is clicking links in emails. We’re telling people not to do things because it’s a security risk, but there are lots of other solutions you can put in place to mitigate risks.

Company culture has a huge impact, too. This wasn’t FC’s experience, but he heard the story: A physical information security tester came into a company that was proud of their physical security because everybody followed the rules. So she put a sign on a door saying, “Don’t lock this door under any circumstances.” People left the door unlocked, and that’s how she got into the building.

One of the biggest impacts I think you can have on any company is the culture.

FC Barker

People Are Helpful (and That Can Be a Risk)

It’s human nature to be helpful. We’re trying to help each other and do our jobs. But that can lead to physical security issues. FC been doing physical information security testing for over twenty-five years. He’s broken into thousands of buildings, including banks, government buildings, and military sites, with a 100% success rate. And he has millions of stories of people helping him get access to something when he wasn’t supposed to get it. The biggest factor in his success is someone helping because they want to be nice. Almost every one of his stories includes someone helping him when they shouldn’t have.

There’s a story that he tells in his book where he stole fourteen PCs. He found them stacked up when he got into the building. They were supposed to be decommissioned. He decided to take a few. As he was struggling through a door, someone held the door for him. Then he used the PC he was carrying to wedge open another door and went back for a second one. At that point, people saw what he was doing. So a small group of people working near that area helped him take all fourteen PCs down the elevator and into his car.

Even something as simple and human as holding a door open for someone can be a physical information security risk.

It’s amazing how many people have assisted FC as he broke into various places. Being helpful is human nature. But it’s really bad for security.

Don’t help people, don’t trust people.

FC Barker

Resisting Physical Information Security Testing

FC has encountered quite a few situations where people didn’t want him to come in and test their security. It tends to be more common with physical information security testing than with the digital side. In one situation, an ex-police officer in charge of the physical security team got in his face threatening to take him down and call the police. But the CEO was adamant that the test happen, so it went ahead anyway. It was fascinating how he reacted – there’s a chapter about it in FC’s book just called “The Very Angry Man.”

There have only been two instances where a job as gone wrong, and neither of them were FC’s fault. They were failures of other people involved. He wrote about both in the book, but in one, he was hired to break into a series of high street banks and one manager was very upset about it. He told all his banks that FC was coming in. So when FC came in and gave his story, he was sent to the waiting room. He felt immediately that something had gone wrong. About fifteen minutes later, the police show up. FC had to explain that he was there to rob the bank, but for a good reason. That manager ended up getting in trouble, since there’s only so many times you can call the police out on false pretenses before they stop showing up. He got in more trouble than he would have if FC had just successfully broken in.

Testing the C-Suite

On the other side, FC has seen lots of cases where someone below the C-suite who has some autonomy brings them in to “test up” and see how the C-suite reacts. This has resulted in some funny stories.

In one, FC was asked to test the physical information security and general physical security of an investment bank. This bank had a lot of gold in a vault. FC joked that his final goal should be to break into the vault. Vaults are always in the basement, because gold is heavy. So towards the end of the test, FC went down there. He found the vault open and stole a gold bar.

Later on, he gets called into the boardroom. They have a big, expensive mahogany table with the C-suite sitting at one end. They didn’t believe that he’d broken into the bank. So FC pulled out the gold bar, which he’d wrapped in a jacket. But it fell out and took a huge chunk out of the expensive mahogany table. FC had never feared for his life so much. But after a brief silence, the executives erupted. They didn’t know the test was happening and didn’t know anyone could get into the vault. The stress of that took away from the table damage. FC never got charged for it, and he hopes that gouge is still there as a reminder.

Most people are pretty good after these tests. They see the value of them, whether they’re physical or digital. FC things the “very angry man” was the only person who didn’t end up coming around in the end. To be fair, he did bait him a little. And he ended up getting fired a few weeks later for something else. But generally, most people see the value eventually.

Physical Information Security Testing and Law Enforcement

Different types of testing require different amounts of preparation. If FC is just trying to get into a building to grab a file, it might only take fifteen minutes of prep. Especially now, when you can get on Google Maps and see what you need in advance, it’s faster. In the past, he would have to travel there in advance to do recon, which takes longer. But the prep usually involves coordinating with local police. There’s a chance someone might call them, and he doesn’t want to have to explain that they told him to break in.

The first bank FC broke into was a huge investment bank in London. They’d invested £1 million in security and wanted to test it. It was 3AM the night before the planned break-in. It was raining and dark and FC was tired. He’d never broken into a bank before, and this massive building looked like Fort Knox. He was trying to map it from the outside. If you look at a building, you can identify which windows are stairwells, bathrooms, offices, etc., and you can build a mental picture.

He was in the process of doing this when he heard a cough behind him, and someone says, “Excuse me, mate, what are you up to?” FC was lost in thought, and responded without turning around, “Trying to work out how to break into this bank.” The person behind him gasped. He turned around and discovered to police officers behind him. It was an interesting night. They learned some stuff, and so did FC, and it took hours out of his recon. Sometimes the police do get involved, so it’s easier to head that off in advance.

Improve Your Physical Information Security

The easiest thing you can do to improve your physical information security and general physical security is awareness. Look at your house and your friends’ houses for how you would break in. We’ve all done this when we’ve forgotten our keys. Think like an attacker – those are the things to look at.

FC likes the quote, “Locks only keep honest people out.” It’s the truth. It doesn’t matter how many awesome locks you have on your door. Real criminals aren’t going to take the time to pick the lock. They’re going to break a window or jimmy the door off its hinges.

Doesn’t matter how many awesome locks you’ve got on your front door, real criminals aren’t going to be picking a lock.

FC Barker

Understanding how criminals look at a property or a situation is the biggest thing. Take an attacker’s view of everything, and have some situational awareness. This is also a great way to avoid pickpockets. If you’re wearing headphones and staring at your phone, you’re a target. If you have your hands in your pockets and are looking around, you’re not a good target.

One of the coolest things you can do is go to Rome, sit at a fountain, and watch the pickpockets at work. After twenty minutes or so you’ll spot them, and they’re world-class. The victims they chose are people who are distracted, tourists, and people looking at maps or their phones or taking photos. These are all things criminals look for in targets. Just having that awareness of how and why you would attack something is a good start.

The Value of Cameras

Despite their common issues, cameras are still useful for physical information security, even when they’re generally not being watched. Cameras are great at going back in time. It’s extremely unlikely that you’re going to see something happening on the cameras in the moment and be able to prevent it. But they’re great for looking at after an incident to see if you caught it. Home defense cameras especially are very good now – the more cameras, the better. You can get Google Nest, ADT, Ring, and all sorts of cameras that turn on with motion, record things, and send it to the cloud.

Cameras are very useful in a home environment. The more cameras the better.

FC Barker

For a home, you want to place cameras in corners. Choose places where, ideally, someone couldn’t get close to it and move it or knock it down without getting caught on the camera. Put exterior cameras on corners where they can cover most areas of approach. That’s not just paths, either – if there’s a wall that someone could jump over, that’s a potential area of approach. Exterior cameras should always be outside of the height of reach. Even if people can approach it, they should need a ladder to move it.

For internal cameras, you want them at a height where they can capture a face, not just the top of a head. Remember, they aren’t preventative. They’re coming in after the action. It’s unlikely that police are going to come in and do fingerprinting and DNA testing to find out who stole your iPod. So you want the camera image to be identifiable enough to find the person.

Don’t be a Target

FC never talks about his home defense system. You don’t want even your friends and neighbors to know what you’ve got. Anything you have that’s valuable, don’t tell people about it. The less you talk about it, the better. It will keep you from being a target.

This isn’t victim-blaming here. It’s never your fault if you’re the victim of a crime. But at the same time, there are things you can do to improve your physical security and reduce your likelihood of being a victim. Just like if you’re walking somewhere at night, it’s better to choose the lighted open area instead of the dark back alley. If you get mugged, it’s not your fault. But there’s also something you could have done to prevent it. Be aware of where bad stuff happens and do what you can to avoid it.

Learn more about Cygenta at cygentasecurity.com. They do pen testing and security testing, speaking, and assess company culture and made recommendations for changes. They only work on things that are interesting, so if you want to work with them, reach out and see if they’re interested. Find Cygenta also on all the platforms, including X/Twitter @cygentahq, LinkedIn, YouTube, and Instagram @cygentahq. Connect with FC directly at freakyclown.com or his wife at drjessicabarker.com.