Join our Newsletter — 33% off our NHI Course

Why can touchless access controls create new security gaps if they are deployed too broadly?

Touchless controls reduce contact, but some options weaken authentication or leave the opening itself uncontrolled. Hand wave devices and hold open devices can let people pass without proving identity. Automated operators can also increase tailgating risk by keeping the door open longer. The key issue is misalignment between hygiene goals and access assurance, which can create a different kind of exposure.

When touchless access becomes a security problem

Touchless controls are designed to reduce physical contact and speed throughput, but they change the assurance model. Some implementations favour convenience over proof of identity, while others widen the time or space in which a door remains available to pass through. The result is not just a cleaner entry point, but a control that can be easier to misuse if it is deployed everywhere without matching the site’s actual risk.

That mismatch matters because access control is not only about opening a door, it is about ensuring the right person gets through at the right time. If a touchless option weakens the authentication step, the control becomes a proximity aid rather than an access decision, which is a very different security outcome.

Where the gap is introduced

The main gap is that some touchless mechanisms reduce friction by reducing verification. A hand-wave sensor can be easier to trigger than a deliberate badge or credential presentation, and a hold-open operator can let multiple people pass on a single action. In both cases, the control may preserve convenience while lowering the confidence that each passage was individually authorised.

There is also an environmental effect: door-opening automation can extend the open interval and make tailgating easier. That means the control weakness is not only in the reader or trigger itself, but in the way the opening behaves once activated. When deployment is too broad, an access method built for low-contact scenarios can quietly become the default path into spaces that needed stronger assurance.

How to think about deployment scope

Touchless access works best when it is treated as a targeted control choice, not a universal replacement for stronger entry assurance. Areas with higher sensitivity, higher traffic variance, or greater concern about unauthorised entry need controls that still force a clear, individualised access decision. In lower-risk areas, reduced-contact operation may be acceptable if the door behavior still prevents easy pass-through by the wrong person.

That means the important question is not whether the technology is touchless, but whether it preserves the same security intent as the control it replaces. If the answer is no, the deployment scope is too broad. The safest designs preserve the distinction between convenience at the point of contact and assurance at the point of entry.

Risk and Threat Considerations

When touchless controls are overused, the main risk is unauthorised entry through weakened identity assurance or through opportunistic pass-through behind an authorised user. The more the control prioritises friction reduction, the more attractive it becomes as a bypass path for someone who does not need to defeat the system so much as exploit its operating mode.

Failure mechanism: The control reduces the need for deliberate user action or keeps the opening available long enough that entry no longer depends on a distinct, individual authorisation event. That creates a gap between the stated access policy and the way the doorway actually behaves in practice.

Impact: Tailgating, shared passage, and unverified entry become easier, which can undermine zoning, visitor separation, and protection of restricted areas. In the wrong location, a convenience control can become a persistent access weakness rather than a hygienic improvement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Touchless entry can weaken user authentication at controlled doors.
AC-3 — Access Enforcement Broad touchless deployment can fail to enforce who may pass through and when.
Recommendation — Require deliberate authentication before door access is granted. Enforce entry policy so convenience features do not bypass authorization.
CIS Controls v8 CIS-6 — Access Control Management The issue is overbroad access behavior and weak control of physical entry paths.
Recommendation — Scope access methods to the least permissive option that still meets the use case.
ISO/IEC 27001:2022 A.5.15 — Access control Touchless controls affect how physical and logical access decisions are applied.
A.7.2 — Physical entry The gap arises at the controlled opening and how people move through it.
Recommendation — Define and apply access-control rules that match the sensitivity of each area. Set physical entry controls so doors cannot be used as uncontrolled pass-throughs.

Practitioner Guidance

What to verify: Confirm that the touchless method still requires a deliberate access decision and does not silently downgrade authentication strength. If the mechanism can be triggered casually or keeps the door open long enough for follow-on entry, treat that as a security design issue rather than a usability preference.

Decision rule: Use touchless access where reducing contact is the primary goal and the security impact of unauthorised pass-through is modest. Use tighter entry controls where a single uncontrolled passage would materially change risk, and avoid deploying a convenience-first mechanism as the default everywhere.

Practitioner takeaway: Touchless access is safe only when the convenience gain does not erase the security decision at the doorway; if it does, the organisation has improved hygiene while weakening entry assurance.