{"id":908,"date":"2013-09-20T23:21:43","date_gmt":"2013-09-20T22:21:43","guid":{"rendered":"http:\/\/www.halkynconsulting.co.uk\/a\/?p=908"},"modified":"2014-02-01T16:13:08","modified_gmt":"2014-02-01T16:13:08","slug":"physical-security-still-matters","status":"publish","type":"post","link":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/","title":{"rendered":"Physical Security &#8211; It still matters"},"content":{"rendered":"<figure id=\"attachment_910\" aria-describedby=\"caption-attachment-910\" style=\"width: 300px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.halkynconsulting.co.uk\/security\/contact-security-team\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"910\" data-permalink=\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/information-security-service-lg\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?fit=2304%2C1532&amp;ssl=1\" data-orig-size=\"2304,1532\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;3.5&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1269171653&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;50&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0.025&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"Physical security protects information\" data-image-description=\"&lt;p&gt;Good physical security protects your information.&lt;\/p&gt;\n\" data-image-caption=\"&lt;p&gt;Good physical security protects your information.&lt;\/p&gt;\n\" data-medium-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?fit=300%2C199&amp;ssl=1\" data-large-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?fit=1024%2C680&amp;ssl=1\" class=\"size-medium wp-image-910 \" alt=\"Good physical security protects your information.\" src=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_-300x199.jpg?resize=300%2C199\" width=\"300\" height=\"199\" srcset=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?resize=300%2C199&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?resize=1024%2C680&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?resize=120%2C80&amp;ssl=1 120w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" data-recalc-dims=\"1\" \/><\/a><figcaption id=\"caption-attachment-910\" class=\"wp-caption-text\">Good physical security protects your information.<\/figcaption><\/figure>\n<p>When it comes to security, there is an unfortunate tendency for organisations (large and small) to fall into the trap of treating their physical security as something separate or different from their information security needs. Despite physical security having a place in every international security standard (such as ISO 27001), ownership of physical risks often ends up being moved away from the &#8220;Information Security&#8221; specialists and bundled in with safety or facilities management.<\/p>\n<p>As we have said in the past, <a title=\"Security design \u2013 physical security measures\" href=\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/06\/security-design-physical-security-measures\/\" target=\"_blank\">physical security really does matter<\/a> to your organisation. If you don&#8217;t take it seriously, it doesn&#8217;t matter how much cybersecurity you have in place, you will suffer losses.<\/p>\n<p>There is an assumption that the big global banks are very much leaders when it comes to security and preventing criminals getting access to their money. Banks have led the way with development of anti-theft measures, counter-fraud, hacker prevention and much more. Most banks spend inordinate amounts of money building very robust networks with strong firewalls and access controls. This all makes sense, because when it comes to robbing money, most criminals dream of getting a big score from a big bank.<\/p>\n<p>With this sort of threat level, spending lots of money on security is actually very sensible for a bank. As you may imagine, they really do spend lots of money.<\/p>\n<p>This means that the recent news was a bit of a surprise. Not one, but two global banks were targeted by a reasonably unsophisticated type of attack which has been known about for over a decade and is countered by pretty basic physical security measures.<\/p>\n<figure id=\"attachment_917\" aria-describedby=\"caption-attachment-917\" style=\"width: 300px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.halkynconsulting.co.uk\/contact\/contact-security-team\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"917\" data-permalink=\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/000801_0257_0052_tsms\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/000801_0257_0052_tsms.jpg?fit=1000%2C1000&amp;ssl=1\" data-orig-size=\"1000,1000\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}\" data-image-title=\"Keyboards &#8211; protect them with physical security\" data-image-description=\"&lt;p&gt;Keyboards &#8211; protect them with physical security&lt;\/p&gt;\n\" data-image-caption=\"&lt;p&gt;Keyboards &#8211; protect them with physical security&lt;\/p&gt;\n\" data-medium-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/000801_0257_0052_tsms.jpg?fit=300%2C300&amp;ssl=1\" data-large-file=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/000801_0257_0052_tsms.jpg?fit=1000%2C1000&amp;ssl=1\" class=\"size-medium wp-image-917\" alt=\"Keyboards - protect them with physical security\" src=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/000801_0257_0052_tsms-300x300.jpg?resize=300%2C300\" width=\"300\" height=\"300\" srcset=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/000801_0257_0052_tsms.jpg?resize=300%2C300&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/000801_0257_0052_tsms.jpg?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/000801_0257_0052_tsms.jpg?resize=100%2C100&amp;ssl=1 100w, https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/000801_0257_0052_tsms.jpg?w=1000&amp;ssl=1 1000w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" data-recalc-dims=\"1\" \/><\/a><figcaption id=\"caption-attachment-917\" class=\"wp-caption-text\">Keyboards &#8211; protect them with physical security<\/figcaption><\/figure>\n<p>The first news broke around 13 September 2013 with reports that the <a title=\"Met Police - Police Central e-crime Unit\" href=\"http:\/\/content.met.police.uk\/Site\/pceu\" target=\"_blank\">Police Central e-crime Unit<\/a> (PCeU) had foiled a planned attack by a criminal group in London to pose as an engineer then plant a &#8220;KVM&#8221; switch in the Salford Quays branch. When this happened, the <a title=\"Arrests over 'cyber plot' to steal from Santander bank\" href=\"http:\/\/www.bbc.co.uk\/news\/uk-england-london-24077094\" target=\"_blank\">BBC News<\/a> reported a gang of 12 people had been arrested in connection with the planned attack.<\/p>\n<p>A week later (20 Sept 2013), a very similar news item appeared when eight men were arrested following the theft of \u00a31.3 million from Barclays Bank using an identical attack. <a title=\"Barclays Bank computer theft: Eight held over \u00a31.3m haul\" href=\"http:\/\/www.bbc.co.uk\/news\/uk-england-24172305\" target=\"_blank\">As reported, again by the BBC<\/a>, This time a fake engineer visited the Swiss Cottage branch of Barclays and attached a malicious KVM switch to a computer. This enabled the gang to get remote access and siphon out the money.<\/p>\n<p>While intelligence led policing seems to have saved Santander from any loss, Barclays was not so lucky. Even if they do recover most of the money, the harm has still been done. This is a very good example spending a fortune on technical security controls not mattering. If there is a physical security weakness, attackers will get in.<\/p>\n<p>(<em>Note: a KVM is a &#8220;keyboard, video, mouse&#8221; switch which is normally used to allow one person to control several devices. In these attacks the KVM appears to have been linked to a device controlled by the criminals allowing them to access the bank&#8217;s networks<\/em>)<\/p>\n<h2>Physical security protects assets &#8211; lessons learned<\/h2>\n<p>Although we may never know all the details, from the published reports there are some lessons for everyone here.<\/p>\n<p>The criminals appear to have been trying to exploit two weaknesses &#8211; lack of physical security sweeps and a relaxed approach to service engineers. The fact that two global banks appear to have suffered the same issues is especially interesting and may be a sign that this is prevalent across business sectors.<\/p>\n<p>First &#8211; how to combat the two main weaknesses that the criminals wanted to exploit:<\/p>\n<ol>\n<li>Physical security is important. If your organisation separates physical and IT security, you will have a weakness that a criminal will exploit. Don&#8217;t fall into this trap.<\/li>\n<li>Ensure your staff are security aware enough that they can spot when strange things appear on their machines or in the office.<\/li>\n<li>If you have security guards \/ officers on site, make sure they carry out regular physical security sweeps. This should include checking for documents left out, cabinets left unlocked and any strange devices attached to machines.<\/li>\n<li>Unless there is a business reason for it, lock down your computer ports. This wont prevent a KVM switch attack but it will prevent similar attacks on USB ports.<\/li>\n<li>Manage your service providers. If an engineer comes on-site in a sensitive area you should be supervising them. No engineer should ever get access without having their credentials checked and any unexpected engineer visits should be treated with extreme caution.<\/li>\n<\/ol>\n<p>Security, including physical security, is never perfect but if you can implement these five steps you will significantly reduce your risks.<\/p>\n<p>One extra issue worth considering &#8211; although there is no indication it is relevant to the two cases here &#8211; is the risk of an insider being involved. If the criminal gangs had managed to subvert an employee, then they wouldn&#8217;t have had to sneak in as an engineer and the attacks become significantly harder to detect.<\/p>\n<p>This is one reason why good background screening and employee after care is essential to your overall security posture. Without it, you are just creating a new opportunity for criminals to get access.<\/p>\n<h2>Physical Security &#8211; Information Security &#8211; Personnel Security &#8211; Security<\/h2>\n<p>The overarching lesson here is that security is security. Protecting your business, preventing theft, guarding your reputation, keeping your assets safe (and so on) is all part of the same mission.<\/p>\n<p>The more you fragment your security into different areas the more you increase the chance that a gap will appear which a criminal will exploit. You may not have the threat profile of a bank, but eventually criminals will notice your weakness and take advantage of it.<\/p>\n<p>In recent years there has been a tendency to split information security off to the IT Department, personnel security gets pushed to HR and physical security ends up with the facilities management team. This is a mistake.<\/p>\n<p>In an ideal world, your organisation will have a &#8220;security&#8221; department which covers all of this and has links to other departments as needed. Even if we don&#8217;t live in an ideal world, you need a centralised &#8220;Chief Security Officer&#8221; type role to join up the competing interests and make sure that all your security controls join up properly.<\/p>\n<p>Frequently this is called &#8220;Holistic&#8221; security and buzzword or not, it just makes sense.<\/p>\n<p>To finish, a quote from Alex Grant, Managing Director, Fraud Prevention, Barclays<\/p>\n<blockquote><p>Barclays has no higher priority than the protection and security of our customers against the actions of would-be fraudsters.<\/p><\/blockquote>\n<p>Well said. Every business should take a similar position, but remember &#8211; actions speak louder than words. <strong>If you value your security, do it properly<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to security, there is an unfortunate tendency for organisations (large and small) to fall into the trap of treating their physical security as something separate or different from their information security needs. Despite physical security having a place in every international security standard (such as ISO 27001), ownership of physical risks often [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":910,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[5,3],"tags":[102,76,10,30,6,54,7],"class_list":["post-908","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-securitynews","tag-banking","tag-breach","tag-crime","tag-financial","tag-infosec","tag-loss-prevention","tag-physsec","entry","has-media"],"jetpack_publicize_connections":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v19.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Physical Security - It still matters to your business, dont forget it!<\/title>\n<meta name=\"description\" content=\"Physical security is often overlooked while defending from cyber threats but as Barclays &amp; Santander have learned, this can be a mistake\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Physical Security - It still matters to your business, dont forget it!\" \/>\n<meta property=\"og:description\" content=\"Physical security is often overlooked while defending from cyber threats but as Barclays &amp; Santander have learned, this can be a mistake\" \/>\n<meta property=\"og:url\" content=\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/\" \/>\n<meta property=\"og:site_name\" content=\"Halkyn Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2013-09-20T22:21:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2014-02-01T16:13:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?fit=2304%2C1532&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"2304\" \/>\n\t<meta property=\"og:image:height\" content=\"1532\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Taz Wake - Halkyn Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/tazwake\" \/>\n<meta name=\"twitter:site\" content=\"@HalkynSecurity\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Taz Wake - Halkyn Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/#article\",\"isPartOf\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/\"},\"author\":{\"name\":\"Taz Wake - Halkyn Security\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/6eb0b544119827df120fb596772d25bc\"},\"headline\":\"Physical Security &#8211; It still matters\",\"datePublished\":\"2013-09-20T22:21:43+00:00\",\"dateModified\":\"2014-02-01T16:13:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/\"},\"wordCount\":1145,\"commentCount\":0,\"publisher\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\"},\"keywords\":[\"Banking\",\"Breach\",\"Crime\",\"Financial\",\"Information Security\",\"Loss Prevention\",\"Physical Security\"],\"articleSection\":[\"Security\",\"Security News\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/\",\"name\":\"Physical Security - It still matters to your business, dont forget it!\",\"isPartOf\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#website\"},\"datePublished\":\"2013-09-20T22:21:43+00:00\",\"dateModified\":\"2014-02-01T16:13:08+00:00\",\"description\":\"Physical security is often overlooked while defending from cyber threats but as Barclays & Santander have learned, this can be a mistake\",\"breadcrumb\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Halkyn Security\",\"item\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"http:\/\/www.halkynconsulting.co.uk\/a\/category\/security\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Physical Security &#8211; It still matters\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#website\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\",\"name\":\"Halkyn Security Blog\",\"description\":\"Specialist Security &amp; Risk Management Consultants\",\"publisher\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/www.halkynconsulting.co.uk\/a\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#organization\",\"name\":\"Halkyn Consulting\",\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1\",\"contentUrl\":\"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1\",\"width\":\"990\",\"height\":\"170\",\"caption\":\"Halkyn Consulting\"},\"image\":{\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/2329571\",\"https:\/\/twitter.com\/HalkynSecurity\"]},{\"@type\":\"Person\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/6eb0b544119827df120fb596772d25bc\",\"name\":\"Taz Wake - Halkyn Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6689803eeae3e16b54fab3a7a1dfd1a5ee70f3ca1a83e77278a1b1adfedc4260?s=96&d=retro&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6689803eeae3e16b54fab3a7a1dfd1a5ee70f3ca1a83e77278a1b1adfedc4260?s=96&d=retro&r=g\",\"caption\":\"Taz Wake - Halkyn Security\"},\"description\":\"Certified Information Systems Security Professional with over 19 years experience providing in-depth security risk management advice to government and private sector organisations. Experienced in assessing risks, and producing mitigation plans, worldwide in both peaceful areas and war zones. Additionally, direct experience carrying out investigations into security lapses, producing evidential standard reports and conducting detailed interviews to ascertain the details of the incident. Has a detailed understanding of the Security Policy Framework (SPF) and JSP440, as well as in depth expertise in producing cost-effective solutions in accordance with legislative and regulatory guidelines. Experienced in accrediting establishments and networks as well as project managing the development of secure, compliant, workable business processes.\",\"sameAs\":[\"http:\/\/www.halkynconsulting.co.uk\",\"https:\/\/twitter.com\/https:\/\/twitter.com\/tazwake\"],\"url\":\"http:\/\/www.halkynconsulting.co.uk\/a\/author\/tazwake\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Physical Security - It still matters to your business, dont forget it!","description":"Physical security is often overlooked while defending from cyber threats but as Barclays & Santander have learned, this can be a mistake","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/","og_locale":"en_GB","og_type":"article","og_title":"Physical Security - It still matters to your business, dont forget it!","og_description":"Physical security is often overlooked while defending from cyber threats but as Barclays & Santander have learned, this can be a mistake","og_url":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/","og_site_name":"Halkyn Security Blog","article_published_time":"2013-09-20T22:21:43+00:00","article_modified_time":"2014-02-01T16:13:08+00:00","og_image":[{"width":2304,"height":1532,"url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?fit=2304%2C1532&ssl=1","type":"image\/jpeg"}],"author":"Taz Wake - Halkyn Security","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/tazwake","twitter_site":"@HalkynSecurity","twitter_misc":{"Written by":"Taz Wake - Halkyn Security","Estimated reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/#article","isPartOf":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/"},"author":{"name":"Taz Wake - Halkyn Security","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/6eb0b544119827df120fb596772d25bc"},"headline":"Physical Security &#8211; It still matters","datePublished":"2013-09-20T22:21:43+00:00","dateModified":"2014-02-01T16:13:08+00:00","mainEntityOfPage":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/"},"wordCount":1145,"commentCount":0,"publisher":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization"},"keywords":["Banking","Breach","Crime","Financial","Information Security","Loss Prevention","Physical Security"],"articleSection":["Security","Security News"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/#respond"]}]},{"@type":"WebPage","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/","url":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/","name":"Physical Security - It still matters to your business, dont forget it!","isPartOf":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#website"},"datePublished":"2013-09-20T22:21:43+00:00","dateModified":"2014-02-01T16:13:08+00:00","description":"Physical security is often overlooked while defending from cyber threats but as Barclays & Santander have learned, this can be a mistake","breadcrumb":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/2013\/09\/physical-security-still-matters\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Halkyn Security","item":"http:\/\/www.halkynconsulting.co.uk\/a\/"},{"@type":"ListItem","position":2,"name":"Security","item":"http:\/\/www.halkynconsulting.co.uk\/a\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Physical Security &#8211; It still matters"}]},{"@type":"WebSite","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#website","url":"http:\/\/www.halkynconsulting.co.uk\/a\/","name":"Halkyn Security Blog","description":"Specialist Security &amp; Risk Management Consultants","publisher":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/www.halkynconsulting.co.uk\/a\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#organization","name":"Halkyn Consulting","url":"http:\/\/www.halkynconsulting.co.uk\/a\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2011\/07\/Untitled-1.png?fit=990%2C170&ssl=1","width":"990","height":"170","caption":"Halkyn Consulting"},"image":{"@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/2329571","https:\/\/twitter.com\/HalkynSecurity"]},{"@type":"Person","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/6eb0b544119827df120fb596772d25bc","name":"Taz Wake - Halkyn Security","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"http:\/\/www.halkynconsulting.co.uk\/a\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6689803eeae3e16b54fab3a7a1dfd1a5ee70f3ca1a83e77278a1b1adfedc4260?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6689803eeae3e16b54fab3a7a1dfd1a5ee70f3ca1a83e77278a1b1adfedc4260?s=96&d=retro&r=g","caption":"Taz Wake - Halkyn Security"},"description":"Certified Information Systems Security Professional with over 19 years experience providing in-depth security risk management advice to government and private sector organisations. Experienced in assessing risks, and producing mitigation plans, worldwide in both peaceful areas and war zones. Additionally, direct experience carrying out investigations into security lapses, producing evidential standard reports and conducting detailed interviews to ascertain the details of the incident. Has a detailed understanding of the Security Policy Framework (SPF) and JSP440, as well as in depth expertise in producing cost-effective solutions in accordance with legislative and regulatory guidelines. Experienced in accrediting establishments and networks as well as project managing the development of secure, compliant, workable business processes.","sameAs":["http:\/\/www.halkynconsulting.co.uk","https:\/\/twitter.com\/https:\/\/twitter.com\/tazwake"],"url":"http:\/\/www.halkynconsulting.co.uk\/a\/author\/tazwake\/"}]}},"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.halkynconsulting.co.uk\/a\/wp-content\/uploads\/2013\/09\/information-security-service.lg_.jpg?fit=2304%2C1532&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9yHvD-eE","jetpack_likes_enabled":true,"_links":{"self":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/908","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/comments?post=908"}],"version-history":[{"count":15,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/908\/revisions"}],"predecessor-version":[{"id":1044,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/posts\/908\/revisions\/1044"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/media\/910"}],"wp:attachment":[{"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/media?parent=908"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/categories?post=908"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.halkynconsulting.co.uk\/a\/wp-json\/wp\/v2\/tags?post=908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}