Is your access control system secure?

You may think you have sufficient security measures in place to combat the risk of theft, terrorism, or unlawful entry but you might want to think again.

As a ‘security-conscious' organisation you may well be using Electronic Access Control as a means of preventing anyone walking in at any time without your knowledge. However, you may be extremely surprised to learn just how easy it is for anyone wishing to enter your property unlawfully to do so by scanning and cloning the information on a member of your staff's electronic access control card, even from a distance away.

How is this Possible? Most large organisations nowadays utilise electronic access and identity security, enabling staff to enter and work within their facilities using electronic key cards or ID passes. This technology has long replaced physical keys in most instances because it is an effective, fully monitored and provides a recorded access system.

However as this system is founded on a wireless exchange between the Access/ID card and the ‘reader', it leaves a very significant loophole or weakness in your security system.

The access card carries a Radio Frequency Identification chip (known as RFID). This responds automatically to a signal sent out by the door reader once within range. The chip then gives out the encrypted access code, the door reader recognises the code and unlocks. Simple and effective.

However, you may not be aware that the Access/ID card carried by staff, visitors or contractors may give up its code to ANY reader operating on that radio frequency.

Therefore, while your buildings electronic ‘keys' are being carried, often visibly, by the holder, a third party with an easily concealed scanner could walk through a crowd, ride on public transport, a lift or escalator, or other crowded area and scan targeted RFID enabled Access cards and then write that scan to a blank card.

Alternatively, your NFC enabled smartphone could be subverted to scan your own RFID chipped cards or Passport and then distribute the stolen data wherever the criminal chooses! All without the data owner/card holder ever knowing it happened!

