Tailgating in cyber security is a physical social engineering attack where an unauthorized person follows an authorized employee through a secure entry point to reach a restricted area without valid credentials. It exploits human courtesy rather than technology, and it is often the first move in a larger data breach.
Most companies pour their security budget into firewalls, email filters, and endpoint software, then leave the front door propped open, literally. Tailgating is one of the oldest tricks in social engineering, and it still works because holding a door for the person behind you feels polite, not dangerous. Once an attacker is inside your building, every digital defense you paid for can be bypassed from a network jack, an unlocked workstation, or a server room. This guide explains what tailgating is, how the attack unfolds, how it differs from piggybacking, and the layered controls that actually stop it.

Tailgating is usually opportunistic and low-tech. The attacker does not need to crack a password or defeat a lock. They need one authorized person to open a door and one moment of hesitation to walk in behind them. Because the intrusion looks ordinary, it rarely triggers an alarm at the moment it happens.
A typical tailgating attack follows a predictable pattern:
The attack exploits a hard truth about access control: a badge reader authenticates a credential, not a person. It confirms that someone with a valid badge opened the door. It has no idea a second person came through on the same swipe. This is the same human-manipulation logic behind email-based scams, only carried out in the physical world. If you want a deeper look at the digital side of social engineering, see our guide to phishing email warning signs to watch for.
Source: CISA guidance on social engineering attacks | NIST Computer Security Resource Center glossary
These two terms are used interchangeably, but security teams draw a clear line between them, and the difference is consent. In tailgating, the authorized employee does not know the intruder followed them in. In piggybacking, the employee knows and lets them through, usually after being talked into it with a believable story.
| Factor | Tailgating | Piggybacking |
|---|---|---|
| Employee awareness | Unaware the intruder followed | Aware and grants access |
| Consent | None | Given, often after manipulation |
| Typical method | Slipping through before the door shuts | “Can you hold that? My hands are full.” |
| Common cover | Blending into a crowd or rush | Posing as a delivery or vendor with a request |
The practical takeaway is the same for both: the fix is not a better lock, it is a workforce that verifies before it admits. Whether the intruder sneaks in or is waved in, one employee choosing to confirm identity ends the attack.
Source: NIST glossary definition of piggybacking
Badge readers control the credential, not the doorway. A single valid swipe can let two, three, or five people through one open door, and the system logs it as one authorized entry. Access control hardware is necessary, but on its own it creates a false sense of security. Without anti-tailgating design and an alert workforce, your badge log will show a clean record of the exact door an intruder walked through.
It is tempting to treat tailgating as a minor lobby nuisance. In reality, it removes the perimeter that most of your cyber defenses assume is intact. An attacker inside your walls is a trusted insider as far as your network is concerned, and the financial stakes of what follows are steep.
Once physical access is achieved, a tailgater can steal hardware, read confidential paperwork left on desks, connect a device to an open ethernet port to move laterally across the network, or install malware directly on an unattended workstation. Each of those actions turns a quiet walk through a door into a full-scale incident. This is exactly why physical and digital security cannot be managed as separate programs, and why a formal review of where those gaps sit is worthwhile. Our overview of what a cybersecurity risk assessment covers walks through how those exposures get identified before an attacker finds them.
Source: Verizon Data Breach Investigations Report | IBM Cost of a Data Breach Report
Attackers rehearse a small set of reliable disguises and situations. Recognizing them is the first line of defense, because a tactic you can name is a tactic you can challenge.
Carrying boxes, a clipboard, or food creates instant plausibility and an implied reason to have both hands full, which nudges a helpful employee to hold the door.
A hi-vis vest, tool bag, or lanyard signals “I belong here.” Few people stop to ask a person who looks like they are there to fix something.
Walking fast, on the phone, coffee in hand, right behind a real employee at a busy entrance. The crowd and the pace discourage anyone from questioning them.
Side doors and smoking areas are propped open or opened casually, and they are often out of camera view and away from reception.
These physical pretexts mirror the psychological tricks used in digital attacks. Seeing a real-world example makes the pattern click, and the same lesson applies to real phishing email examples that use the same false urgency and false authority.
Source: CISA on recognizing social engineering pretexts
No single control stops tailgating. Effective prevention layers physical design, technology, and behavior so that if one layer is bypassed, another catches the intruder.
Turnstiles, security mantraps (an interlocking two-door vestibule that admits one person at a time), and anti-passback rules make it physically hard for a second person to follow through. High-security areas such as server rooms deserve the strongest hardware.
Cameras at every entry point deter attempts and provide the evidence needed to investigate one. Video analytics can flag two people entering on a single credential in real time. Purpose-built business camera and surveillance installation covers the entrances that badge logs never see.
Sign-in systems, printed visitor badges, and escort requirements ensure every non-employee is accounted for and visibly identified. A guest who cannot produce a badge becomes easy to spot.
The most important layer is human. Train employees to challenge anyone without a visible badge politely, to never hold a secured door for someone they do not recognize, and to report tailgating attempts without fear of seeming rude. Building that habit is part of the broader effort covered in mastering cybersecurity basics across your team.
Most small and midsize businesses do not have the in-house staff to design and monitor all four layers at once. A managed security partner assesses your entry points, deploys the right controls, and keeps an eye on them so a propped side door never becomes tomorrow’s breach.
Protect Your Business From Social Engineering Attacks
Explore Fully Managed IT and Security Support
Source: CISA physical security resources

Virtual desktop infrastructure (VDI) is technology that hosts full desktop operating systems on centralized servers in…
Social engineering is the use of psychological manipulation to trick people into revealing confidential information, granting…
Smishing (SMS phishing) is a social engineering attack that uses text messages to trick you into…
QoS (Quality of Service) is a set of network technologies that prioritize important traffic, such as…