Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Tailgating
Cyber Security

Tailgating

← Back to Glossary
By NHI Mgmt Group Updated September 16, 2026 Domain: Cyber Security

Tailgating is a physical security tactic in which an attacker gains entry by following an authorised person into a restricted area. The intruder relies on appearance, social pressure, or distraction to create the impression of legitimacy. In identity and security programmes, it shows how access control failures can begin outside digital systems.

Expanded Definition

Tailgating is a physical access-control failure, not a digital authentication event. It occurs when an unauthorised person enters a restricted area by closely following someone who is authorised, often by exploiting courtesy, urgency, distraction, or assumptions about who belongs.

In security programmes, the term is often used alongside “piggybacking,” though usage varies. Some teams reserve piggybacking for entry with the holder’s consent, while tailgating implies unapproved entry without consent. In practice, the boundary matters because the risk is the same: the perimeter control depends on people enforcing access rules, not just badges, doors, or readers.

Tailgating usually exposes a weak point in layered controls. A door badge may confirm one person’s access, but it does not automatically validate the person behind them. That gap is why physical security, visitor management, and awareness training are all part of the control surface around restricted spaces. For a broader control baseline, NIST SP 800-53 Rev 5 Security and Privacy Controls remains a useful reference for access control and audit expectations.

Examples and Use Cases

Tailgating appears in everyday security environments where entry is controlled by badges, turnstiles, guards, or door access systems.

  • An attacker waits near a secure office entrance and slips in behind an employee holding the door open.
  • A person carrying boxes or coffee uses the inconvenience of the moment to avoid challenge from staff inside a badge-controlled area.
  • A visitor follows a group through a reception barrier before anyone checks whether they are escorted or approved.
  • In a datacentre or lab, tailgating can bypass the first line of defence even when the access system itself is working correctly.

The common pattern is social, not technical. The control failure happens because authorised occupants assume the next person has already been checked, or because challenging them feels awkward. That makes tailgating a useful test of whether a site’s physical controls are actually being enforced rather than merely documented.

It is also a reminder that access decisions are contextual. A badge reader can only verify the credential presented at the door; it cannot on its own verify whether the doorway should admit a second person, so human challenge behaviour remains part of the control design.

Security Implications

When tailgating succeeds, the attacker gains the same physical foothold as a legitimate entrant, which can make the incident far more serious than a simple entry violation. Once inside, the intruder may access workstations, printed material, meeting rooms, network ports, or sensitive assets that were assumed to be protected by the building boundary.

The main security implication is that physical access often becomes an enabler for broader compromise. A short breach at the door can lead to theft, device tampering, shoulder-surfing, rogue device placement, or direct contact with internal systems. In environments with weak segmentation, one missed challenge can undermine multiple downstream controls.

Failure mechanism: the attacker exploits social compliance, urgency, or inconvenience to bypass the assumption that badge possession equals authorised entry. The control breaks when staff do not verify that each entrant is separately approved.

Impact: unauthorised physical presence, increased chance of data exposure, and a higher likelihood that other safeguards, including device, workstation, or network controls, will be attacked from inside the perimeter.

Practitioners should watch for repeated “courtesy-based” exceptions, because those habits usually indicate that the physical access policy is weaker in execution than it appears on paper.

Security, Operational and Governance Implications

Tailgating matters because it reveals how access governance fails when the environment relies on social norms instead of enforceable barriers. Even strong technical security can be weakened if someone can enter a controlled area and interact directly with assets, users, or infrastructure.

Operationally, the issue is usually not the door itself but the discipline around it. Reception procedures, escort rules, challenge culture, and monitoring all determine whether a restricted area is genuinely restricted. In many organisations, the hardest part is not detecting a tailgating attempt, but making employees comfortable enough to stop and question it.

From a governance perspective, tailgating is a boundary-control problem. It shows whether physical security ownership is clear, whether exceptions are logged, and whether people understand their responsibility to challenge unknown entrants. That makes the term relevant to audit, site operations, and incident readiness, not just facilities policy.

A practical lesson is that physical access control should be measured by behaviour as much as by hardware. If staff routinely hold doors open, the control may be present but not effective.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlTailgating bypasses facility access control and undermines authenticated entry boundaries.
PR.PT — Protective TechnologyPhysical barriers and monitoring are protective technologies that deter or detect unauthorised entry.
DE.CM — Continuous MonitoringMonitoring entry points helps detect repeated bypass patterns and weak enforcement of physical controls.
Recommendation — Enforce access checks and challenge procedures at physical entry points. Use barriers, turnstiles and monitoring to limit unverified entry. Monitor entrances for recurring unescorted access and policy exceptions.
CIS Controls v814 — Security Awareness and Skills TrainingTailgating is often enabled by social pressure and courtesy, which training is meant to reduce.
Recommendation — Train staff to challenge unknown entrants and report suspicious access attempts.
NIST SP 800-63Digital Identity GuidelinesPhysical access assumptions often mirror identity verification failures that should be handled separately from door entry.
Recommendation — Apply strong identity proofing to prevent downstream misuse after physical access.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org