Skip to main content

CNiC Solutions

Unauthorized person following an employee through a badge-secured office door in a tailgating attack

Most companies pour their security budget into firewalls, email filters, and endpoint software, then leave the front door propped open, literally. Tailgating is one of the oldest tricks in social engineering, and it still works because holding a door for the person behind you feels polite, not dangerous. Once an attacker is inside your building, every digital defense you paid for can be bypassed from a network jack, an unlocked workstation, or a server room. This guide explains what tailgating is, how the attack unfolds, how it differs from piggybacking, and the layered controls that actually stop it.

Key Takeaways

  • Tailgating is a physical attack, but a cyber threat. Physical entry is the gateway to data theft, malware, and network access.
  • It exploits people, not software. Attackers rely on politeness, distraction, and the reluctance to confront a stranger.
  • The human element drives most breaches. Verizon found a person was a factor in 68% of breaches in its 2024 report.
  • Badges alone are not enough. A reader only checks the person who scans, not the person who slips in behind them.
  • Prevention is layered: access control, surveillance, visitor management, and a culture where employees challenge unfamiliar faces.

What’s in This Guide

 

 

Four-step diagram showing how a tailgating attack works from reconnaissance to network access
The four stages of a typical tailgating attack, from casing the entrance to gaining network access.

 

 

How a Tailgating Attack Works

Tailgating is usually opportunistic and low-tech. The attacker does not need to crack a password or defeat a lock. They need one authorized person to open a door and one moment of hesitation to walk in behind them. Because the intrusion looks ordinary, it rarely triggers an alarm at the moment it happens.

A typical tailgating attack follows a predictable pattern:

  1. Reconnaissance. The attacker studies entry points, shift changes, smoking areas, and delivery schedules to find the busiest, least-supervised door.
  2. The approach. They arrive dressed to blend in, as a delivery driver, a contractor in a hi-vis vest, or an employee balancing a coffee and a laptop bag.
  3. The follow. When an employee badges in, the attacker slips through the same door before it closes, often with a nod or a rushed “thanks.”
  4. The objective. Once inside, they plug into an open network port, photograph sensitive documents, access an unlocked device, or drop a rogue device that phones home to them.

The attack exploits a hard truth about access control: a badge reader authenticates a credential, not a person. It confirms that someone with a valid badge opened the door. It has no idea a second person came through on the same swipe. This is the same human-manipulation logic behind email-based scams, only carried out in the physical world. If you want a deeper look at the digital side of social engineering, see our guide to phishing email warning signs to watch for.

Source: CISA guidance on social engineering attacks | NIST Computer Security Resource Center glossary

Tailgating vs. Piggybacking

These two terms are used interchangeably, but security teams draw a clear line between them, and the difference is consent. In tailgating, the authorized employee does not know the intruder followed them in. In piggybacking, the employee knows and lets them through, usually after being talked into it with a believable story.

Factor Tailgating Piggybacking
Employee awareness Unaware the intruder followed Aware and grants access
Consent None Given, often after manipulation
Typical method Slipping through before the door shuts “Can you hold that? My hands are full.”
Common cover Blending into a crowd or rush Posing as a delivery or vendor with a request

The practical takeaway is the same for both: the fix is not a better lock, it is a workforce that verifies before it admits. Whether the intruder sneaks in or is waved in, one employee choosing to confirm identity ends the attack.

Source: NIST glossary definition of piggybacking

Myth: “Our badge system already stops tailgating.”

Badge readers control the credential, not the doorway. A single valid swipe can let two, three, or five people through one open door, and the system logs it as one authorized entry. Access control hardware is necessary, but on its own it creates a false sense of security. Without anti-tailgating design and an alert workforce, your badge log will show a clean record of the exact door an intruder walked through.

Why Tailgating Matters for Your Business

It is tempting to treat tailgating as a minor lobby nuisance. In reality, it removes the perimeter that most of your cyber defenses assume is intact. An attacker inside your walls is a trusted insider as far as your network is concerned, and the financial stakes of what follows are steep.

68%
of breaches involved a human element in Verizon’s 2024 report, the category tailgating exploits
$4.88M
global average cost of a data breach in 2024, per IBM

Once physical access is achieved, a tailgater can steal hardware, read confidential paperwork left on desks, connect a device to an open ethernet port to move laterally across the network, or install malware directly on an unattended workstation. Each of those actions turns a quiet walk through a door into a full-scale incident. This is exactly why physical and digital security cannot be managed as separate programs, and why a formal review of where those gaps sit is worthwhile. Our overview of what a cybersecurity risk assessment covers walks through how those exposures get identified before an attacker finds them.

Source: Verizon Data Breach Investigations Report | IBM Cost of a Data Breach Report

 

CNiC Solutions — Cybersecurity

 

Common Tailgating Tactics

Attackers rehearse a small set of reliable disguises and situations. Recognizing them is the first line of defense, because a tactic you can name is a tactic you can challenge.

The delivery or courier

Carrying boxes, a clipboard, or food creates instant plausibility and an implied reason to have both hands full, which nudges a helpful employee to hold the door.

The contractor or maintenance worker

A hi-vis vest, tool bag, or lanyard signals “I belong here.” Few people stop to ask a person who looks like they are there to fix something.

The rushed employee

Walking fast, on the phone, coffee in hand, right behind a real employee at a busy entrance. The crowd and the pace discourage anyone from questioning them.

The friendly smoker or break-area entrance

Side doors and smoking areas are propped open or opened casually, and they are often out of camera view and away from reception.

These physical pretexts mirror the psychological tricks used in digital attacks. Seeing a real-world example makes the pattern click, and the same lesson applies to real phishing email examples that use the same false urgency and false authority.

Source: CISA on recognizing social engineering pretexts

How to Prevent Tailgating

No single control stops tailgating. Effective prevention layers physical design, technology, and behavior so that if one layer is bypassed, another catches the intruder.

1. Physical access controls

Turnstiles, security mantraps (an interlocking two-door vestibule that admits one person at a time), and anti-passback rules make it physically hard for a second person to follow through. High-security areas such as server rooms deserve the strongest hardware.

2. Surveillance and monitoring

Cameras at every entry point deter attempts and provide the evidence needed to investigate one. Video analytics can flag two people entering on a single credential in real time. Purpose-built business camera and surveillance installation covers the entrances that badge logs never see.

3. Visitor management

Sign-in systems, printed visitor badges, and escort requirements ensure every non-employee is accounted for and visibly identified. A guest who cannot produce a badge becomes easy to spot.

4. Security awareness culture

The most important layer is human. Train employees to challenge anyone without a visible badge politely, to never hold a secured door for someone they do not recognize, and to report tailgating attempts without fear of seeming rude. Building that habit is part of the broader effort covered in mastering cybersecurity basics across your team.

Most small and midsize businesses do not have the in-house staff to design and monitor all four layers at once. A managed security partner assesses your entry points, deploys the right controls, and keeps an eye on them so a propped side door never becomes tomorrow’s breach.

Protect Your Business From Social Engineering Attacks

Explore Fully Managed IT and Security Support

Source: CISA physical security resources

 

 

Infographic showing four layers of tailgating prevention: access control, surveillance, visitor management, awareness
Effective tailgating prevention layers physical controls, surveillance, visitor management, and an alert workforce.

 

 

Common Questions About Tailgating

What is tailgating in cyber security?

Tailgating is a physical social engineering attack in which an unauthorized person follows an authorized employee through a secured entrance to reach a restricted area without valid credentials.

What is the difference between tailgating and piggybacking?

In tailgating the intruder slips in without the authorized person’s knowledge. In piggybacking the authorized person is aware and consents, usually after being manipulated with a plausible excuse.

Is tailgating a cyber attack if no computer is hacked?

Yes. It is a cyber security threat because physical entry is usually the first step toward stealing data, planting malware, or accessing systems from inside the trusted network.

How can businesses prevent tailgating attacks?

Combine access control such as turnstiles or mantraps, video surveillance, visitor management, and a culture where employees challenge anyone without a visible badge.

Who is most at risk from tailgating?

Organizations with high foot traffic, shared entrances, delivery activity, or hybrid staff are most exposed, because unfamiliar faces are common and less likely to be questioned.

Sources

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog