CLUSTER · CITADEL + SENTRY
Converged Security: Why Physical and Cyber Can’t Stay Separate
Physical security and IT security have operated as separate departments for decades — separate budgets, separate vendors, separate incident logs. The systems they protect no longer respect that boundary. Access panels run on the network. Cameras are computers. This is the case for treating converged security as a real discipline, backed by documented incidents, plus a framework for assessing where your organization actually stands.
QUICK ANSWER
The 50-Word Answer
Converged security means physical security (badges, cameras, alarms) and cybersecurity (network, identity, endpoints) share one incident response process, one identity model spanning badge and login, and one body of audit evidence — because the systems already share one attack surface. Documented breaches at a casino, a national retailer, and a camera vendor show what happens when they don’t.
FOUNDATIONS
What Is Converged Security, Really?
Converged security is the practice of operating physical security systems and cybersecurity systems as one accountable function instead of two coordinating ones. It is not the same thing as buying IP cameras or a cloud-managed badge reader. Almost every organization has already done that. Convergence is an organizational and operational change, not a purchasing decision: it means the team responsible for a badge anomaly at 2 a.m. is the same team — or is directly and automatically informed by the same system — that is responsible for a concurrent VPN login anomaly.
The argument for treating this as a distinct discipline rests on a simple technical fact: physical security equipment is now IT infrastructure. Access control panels are network-connected computers running embedded operating systems, communicating over standard protocols, and reachable from anywhere the network reaches. Cameras stream, store, and process video through cloud platforms with their own authentication, their own software supply chain, and their own vulnerability history. An alarm panel is a networked device with an administrative interface. None of this was true twenty years ago, when physical security equipment was closed-loop and analog. It is true of nearly every commercial deployment today.
Two teams sitting near each other, or exchanging an occasional email, is not convergence. Convergence is measurable: a shared identity record, a shared incident queue, and a shared body of evidence for auditors. Absent those three things, an organization has two security programs that happen to occupy the same building — and, as the incidents below show, the seam between them is exactly where attackers look.
THE ORIGIN OF THE GAP
Why the Divide Exists
The organizational split is older than the technology that erased its logic. Physical security historically grew out of facilities and operations: guards, locks, and badge systems purchased and managed by the same function that handled the parking lot and the HVAC contract, with a risk model built around theft, liability, and life safety, and an audit regime built around fire codes and insurance requirements. IT security grew out of data processing, later formalized into a CISO function reporting through the CIO or general counsel, with a risk model built around the confidentiality and availability of data, and an audit regime built around data protection statutes.
Neither function was designed to monitor the other’s telemetry, and neither budget line was built to fund a shared platform. Facilities buys a camera system from a systems integrator who installs cameras for a living and has never run a penetration test. IT buys a firewall from a managed security provider who has never configured an access control panel. As badge readers, cameras, and alarm panels became IP-connected over the last decade, the technical boundary between the two domains collapsed. The organizational boundary — the reporting lines, the vendor relationships, the separate incident logs — did not move with it. Nobody was assigned to own the seam, so the seam became the exposure.
DOCUMENTED EVIDENCE
When the Divide Becomes the Breach
This is not a hypothetical risk. Three well-documented incidents, spanning three different industries and a decade of history, show what happens at the exact seam between physical and cyber security.
A casino, a fish tank, and a facilities purchase (2018)
Darktrace CEO Nicole Eagan disclosed publicly that attackers compromised a North American casino through an internet-connected thermometer monitoring an aquarium in the lobby. The thermometer — a facilities purchase, not an IT purchase — gave attackers a network foothold. From there they moved laterally to the casino’s high-roller database and exfiltrated it back out through the same device (reported by Business Insider and covered widely, including by The Hacker News). No firewall was breached in the conventional sense; a device nobody in IT security had ever reviewed was simply on the same network as the data.
Target, its HVAC vendor, and 40 million card numbers (2013–2014)
Brian Krebs first reported that attackers gained their initial foothold in Target’s network using credentials stolen from Fazio Mechanical Services, a Pennsylvania refrigeration and HVAC contractor, via a phishing email. Fazio’s network access to Target was limited to electronic billing, contract submission, and project management — it did not control building systems directly. That narrow, facilities-vendor connection was enough: attackers used it as a beachhead to move laterally to point-of-sale systems, ultimately exposing roughly 40 million payment card numbers and 70 million customer records. The lesson is not that HVAC systems are dangerous; it is that any physical-facilities vendor relationship is a cyber trust relationship, whether or not the two departments that manage it ever compare notes.
Verkada: 150,000 cameras, one support server (2020–2021)
Cloud camera vendor Verkada suffered two breaches between December 2020 and March 2021. Attackers first planted botnet malware on a legacy firmware build server after a misconfiguration was never reversed; months later, a separate hacking group exploited Verkada’s customer-support server to obtain super-admin credentials, gaining live access to feeds from more than 150,000 cameras inside hospitals, jails, schools, and corporate sites. The Federal Trade Commission brought an enforcement action against Verkada in 2024, requiring a $2.95 million penalty and a mandated security program. The product was purely physical security — cameras — but the liability, the breach mechanics, and the regulatory response were entirely those of a cybersecurity incident.
The common thread across all three: none required a sophisticated attacker. Each exploited an organizational blind spot at the precise seam between a system classified as “physical” and a monitoring function classified as “cyber” — a seam that exists only because two departments never built a shared way of watching it.
WHAT CHANGES
What Actually Changes When You Converge
Three concrete operational changes separate a converged program from two departments that merely coexist.
One incident response process
A badge anomaly and a login anomaly become the same category of event, triaged by one on-call rotation inside one escalation path — not two separate tickets in two separate systems, discovered days apart by two teams that were never introduced.
One identity model spanning badge and login
A single identity record governs both physical access and network access, so terminating an employee revokes the badge and the account in one action instead of two, and physical access patterns can be checked against login patterns for the indicators that matter — a badge used at two distant readers within a travel-impossible window, or a login from a country where the same credential’s badge never left the building.
One body of audit evidence
Regulated frameworks increasingly examine both domains in the same audit — the HIPAA Security Rule’s facility access controls, CMMC 2.0’s Physical Protection (PE) domain, and SOC 2’s physical security criteria all sit alongside the cybersecurity controls in the same assessment. A converged program produces one evidence set from one system. A siloed program produces two, assembled by two departments that do not know what the other collected, in the week before the audit.
DIAGNOSTIC
A Framework for Assessing Your Convergence Maturity
Four levels, each with a concrete test question you can answer today without a consultant in the room.
| Level | What It Looks Like | The Test Question |
|---|---|---|
| 0 — Siloed | Physical security and IT security report through different executives, use different incident-tracking systems, and have never jointly reviewed an incident. | Can your CISO name who monitors your badge system after hours? |
| 1 — Aware | Both teams know the other exists and share information after an incident forces a conversation. There is no standing process — coordination happens by phone call, not by system design. | The last time an employee was terminated, were their badge and network access revoked in one action or by two separate tickets filed by two separate teams? |
| 2 — Coordinated | Formal handoff points exist — a badge anomaly generates a ticket IT security reviews, or vice versa — but the underlying systems remain separate and correlation is manual. | If a badge reader logs an after-hours entry to your server room, does anything automatically check that room’s network activity in the same window — or does someone have to think to ask? |
| 3 — Converged | Physical and cyber telemetry live in one data model, incidents are triaged by one team under one escalation path, and one identity source governs both badge and login. | Could you produce, inside an hour, a single report showing every door opened and every login attempted by one employee over the last 90 days? |
Most organizations sit at Level 0 or Level 1 not because the technology to converge is unavailable, but because the org chart drawn decades ago has never been redrawn. Moving from Level 1 to Level 2 typically requires no new headcount — only a defined handoff process between two teams that already exist. Moving to Level 3 requires a shared data model and, in practice, a single accountable operator for both domains.
GO DEEPER
Where to Go Next
This page is the hub. The resources below go deeper on the operating layers, the specific system risks, and a real deployment.
Portfolio
CITADEL: The Physical Security Operating Layer
Access control, video, visitor management, and alarm monitoring, correlated with SENTRY through FusionWatch.
Portfolio
SENTRY: Enterprise Cybersecurity Operations
24/7 monitoring, threat detection, and incident response — the cyber half of the converged incident queue.
Insight
Physical-Cyber Convergence in Access Control Systems
How behavioral baselining and anomaly detection turn badge readers into a real-time threat signal.
Insight
Why Your Cameras Need Cybersecurity
The specific vulnerabilities in IP cameras and access control systems, and the four-phase plan to close them.
Case Study
University Secures Campus with Integrated Physical + Cyber Security
Convergence Level 3 in practice, at a real campus with real access points and real regulatory exposure.
FAQ
Frequently Asked Questions
What is converged security?
Converged security is the practice of operating physical security (badges, cameras, alarms, visitor management) and cybersecurity (network, identity, endpoint, cloud) as one accountable function — sharing one incident response process, one identity model spanning badge and login, and one body of audit evidence — rather than as two departments that coordinate occasionally.
Is converged security just a marketing term?
No. It describes a specific technical reality: access control panels, cameras, and alarm systems are network-connected computing infrastructure, and documented breaches (the 2018 casino fish-tank thermometer hack, the 2013–2014 Target/Fazio Mechanical breach, and the 2021 Verkada camera breach) show what happens when the organizations managing them treat physical and cyber security as unrelated domains.
Why have physical security and IT security stayed separate for so long?
The split predates the technology. Physical security grew out of facilities and operations with a risk model built around theft and life safety; IT security grew out of data processing with a risk model built around data confidentiality. Different reporting lines, different vendors, different audit regimes. As physical security equipment became IP-connected, the technical boundary between the two domains collapsed, but the organizational boundary did not move with it.
How do I know what convergence maturity level my organization is at?
Use the four-level framework on this page. The fastest indicator: when an employee is terminated, is their badge access and their network access revoked in one action by one system, or in two separate tickets filed by two separate teams? One action indicates at least Level 2 maturity; two separate, uncoordinated tickets indicate Level 0 or Level 1.
Does converged security require replacing our physical security vendor?
Not necessarily. Moving from Level 1 to Level 2 maturity typically requires a defined handoff process between existing teams, not new equipment. Moving to Level 3 — one data model, one identity source, one accountable operator — is an operating-model change more than a hardware change, though it often does involve consolidating vendor relationships that have accumulated over years.
Where does your organization sit on the framework?
Armorstack runs converged security assessments across CITADEL and SENTRY for Wisconsin mid-market organizations — mapping your current maturity level, identifying the seam risk in your environment, and scoping the path to Level 3. No obligation, deliverable is yours to keep.