Back to BlogZero Trust

The IT/OT Divide: Why Your Physical Security Network is a Different Beast

TTSS Group LLC· Cory Franek July 24, 2026 8 min read
The IT/OT Divide: Why Your Physical Security Network is a Different Beast

In the modern federal and enterprise landscape, there is a dangerous assumption masquerading as efficiency: the belief that because a physical security device—like an IP camera, an automated gate controller, or a biometric reader—connects via an RJ-45 cable, it is effectively an "IT asset."

A federal contractor spent $4.7 million upgrading the physical security infrastructure at a DoD facility — new IP cameras, biometric readers, automated vehicle barriers, the works. Eight months later, a penetration test revealed that every one of those cameras was sitting on the same flat network segment as the facility's personnel database. The pen tester walked in through a camera. Nobody had noticed.

That is not a hypothetical. Variations of that scenario show up in federal security audits with uncomfortable regularity. The problem is not the hardware. The problem is a classification error that starts in procurement and ends up in your network architecture.

Why Calling an IP Camera an "IT Asset" Is a Setup for Failure

When a physical security device connects via an RJ-45 cable, someone in IT looks at it and sees a network endpoint. That instinct is understandable. It is also wrong in ways that matter operationally.

Information Technology and Operational Technology are built around different priorities, different lifecycle assumptions, and different failure tolerances. Treating one as a subset of the other does not simplify your environment — it creates blind spots that attackers actively look for.

Here is what the distinction actually looks like in practice:

  • IT prioritizes Confidentiality, Integrity, then Availability (CIA). A server can be taken offline for patching. A workstation can be rebooted. Downtime is an inconvenience measured in lost productivity and SLA penalties.
  • OT prioritizes Availability, Integrity, then Confidentiality (AIC). A door lock that fails to release during a fire evacuation is not an inconvenience — it is a life-safety failure. A camera feed that drops during an active intrusion has failed its only job.
  • IT runs on standardized, frequently updated operating systems. Windows, Linux, macOS — these get patched on a regular cycle. Remote deployment of updates is expected and engineered into the platform.
  • OT runs on embedded firmware, often proprietary, with lifecycles measured in decades. An access control panel installed in 2014 may be running firmware that the manufacturer no longer supports, on hardware that cannot tolerate the kind of aggressive patching schedule IT considers routine.

When IT applies standard hardening protocols to OT devices — aggressive timeout policies, forced reboots, automatic update cycles — it often breaks device functionality entirely. When IT ignores those same devices because they seem like simple peripherals, the devices sit unmonitored on the network indefinitely. Both outcomes are problems. Neither outcome is acceptable in a federal facility handling CUI under NIST SP 800-171 or operating under a DoD Authority to Operate.

The device that controls who gets through your perimeter should never be managed with the same assumptions you apply to a shared printer.

How Attackers Actually Use Your Physical Security Infrastructure Against You

Lateral movement is the mechanic that makes the IT/OT classification error dangerous at scale. Understanding it removes any remaining ambiguity about why network segmentation for physical security is not optional.

The IBM Cost of a Data Breach Report 2023 documented that the average time for an attacker to move laterally from an initial point of compromise to a high-value target inside a network is shrinking year over year. The access path does not have to start at a hardened server. It can start at a $300 IP camera with a default admin password and a firmware version from 2019.

Here is the mechanics of a realistic attack sequence against a flat-network physical security deployment:

  1. Attacker identifies an internet-facing or externally reachable IP camera through Shodan or a similar reconnaissance tool. This takes minutes.
  2. Camera is running outdated firmware with a known CVE. Attacker exploits it and gains shell access to the device.
  3. The camera sits on the same network segment as the facility's personnel management system, because the integrator used a flat architecture to simplify installation and reduce their labor hours.
  4. Attacker uses the camera's local network trust relationships to probe adjacent systems. Because the camera is a "trusted" internal device, traffic from it raises no flags in monitoring tools configured to watch for external threats.
  5. Within hours, the attacker has access to personnel files, visitor logs, or worse — the access control database that defines who can enter which areas of the facility.

The camera did not fail to record video. It was working exactly as designed. The failure was architectural. And it was predictable.

Large commodity integrators frequently push unified hardware packages built on flat network architectures. The sales pitch is simplicity — one network, one management console, faster installation. What they are actually selling is their own labor efficiency, transferred to you as long-term liability. A segmented architecture costs more to install. It costs significantly less when you are not reporting a breach to your Contracting Officer's Representative.

What Zero Trust Actually Requires for Physical Security Networks

The federal government's push toward Zero Trust Architecture under Executive Order 14028 and the subsequent OMB Memorandum M-22-09 is frequently discussed in the context of IT systems — identity management, cloud access, software-defined perimeters. Physical security infrastructure does not get enough attention in that conversation, and it should.

Zero Trust, applied correctly to OT environments, means the following in concrete terms:

  • Network segmentation by function and risk classification. Your IP camera network should not be able to communicate with your personnel database under any normal operating condition. VLAN architecture with strict inter-VLAN routing rules is the baseline. Micro-segmentation is the standard you should be targeting.
  • Device identity verification, not just network location trust. The fact that a device is plugged into a port inside your building does not make it trustworthy. 802.1X port authentication, certificate-based device identity, and NAC (Network Access Control) policies should gate what any physical security device can talk to on your network.
  • Continuous monitoring with OT-specific baselines. A camera that starts generating unusual outbound traffic at 2 AM is behaving anomalously. Your monitoring tools need to know what normal looks like for OT devices specifically — not just flag events that would be unusual for a workstation.
  • Firmware and patch management tracked separately from IT assets. OT devices need their own patch tracking workflow that accounts for manufacturer support status, firmware compatibility testing, and the operational impact of update windows. Shoving them into your standard IT patch management tool is not an equivalent process.
  • Defined change management for physical security configurations. Any change to an access control policy, camera field of view, or door schedule should go through a documented change management process. In a federal facility, this is not bureaucracy — it is the audit trail that keeps you out of trouble when something goes wrong.

CISA's guidance on OT security, published in their 2023 Cybersecurity Advisory series on internet-exposed OT systems, specifically calls out physical security devices — cameras, access control systems, building automation controllers — as high-priority targets that require network isolation and active monitoring. This is not theoretical guidance from people who have never seen a server room. It is response documentation from active incident investigations.

The Procurement Decision That Determines Your Security Posture

Most of the architectural problems described above are locked in before a single cable is pulled. They are decided in the design and procurement phase, when the agency or facility manager is evaluating bids and the integrator is building their proposal.

A flat network architecture is cheaper to propose and faster to install. A properly segmented OT network — with dedicated VLANs, NAC enforcement, firewall rules between security device segments and enterprise IT, and documented inter-system communication policies — takes more engineering hours and costs more upfront. On a competitive bid, the flat-network proposal wins on price. The segmented proposal wins on security.

Procurement officers and facility managers evaluating physical security integration bids should be asking these specific questions:

  • How will physical security devices be segmented from enterprise IT systems, and what is the technical mechanism — VLAN, physical separation, firewall policy?
  • What is the patch and firmware management plan for each hardware category, including devices with limited manufacturer support?
  • How will device authentication be handled — are default credentials changed at commissioning, and is there a documented process for credential management throughout the device lifecycle?
  • What monitoring will be in place for OT-specific anomalous behavior, and who is responsible for response?
  • Does the proposed architecture align with NIST SP 800-82 (Guide to OT Security) and the facility's existing ATO conditions?

If an integrator cannot answer those questions specifically, or answers them with generalities about "enterprise-grade security," that is information worth having before contract award.

Cheap integration is not a savings. It is a deferred cost with interest, paid in incident response, audit findings, and re-procurement.

The Bottom Line

Physical security devices are not IT assets that happen to open doors and record video. They are OT systems with distinct operational priorities, long hardware lifecycles, proprietary firmware, and direct consequences when they fail or are compromised. Managing them under IT assumptions — or ignoring them entirely because they seem like simple peripherals — leaves exploitable gaps in your network that meet none of the requirements under Zero Trust, NIST SP 800-171, or CMMC if you are operating in a DoD environment.

The one thing to do right now: pull up your current network diagram and find out where your IP cameras, access control panels, and biometric readers sit relative to your personnel and operational data systems. If the answer is "same segment" or "I'm not sure," that is where your security review needs to start — before your next penetration test finds it for you.

#PhysicalSecurity #CyberPhysicalSecurity #NDAA889 #LateralMovement #PhantomSecurity #ZeroTrust #FederalSecurity #FacilitySecurity #SecurityIntegration #CriticalInfrastructure
T

TSS Group LLC

Cory Franek

Technology Steward

Share this article

Ready to Strengthen Your Security Posture?

Request a no-obligation assessment for your facility. Our SDVOSB team delivers integrated physical and cyber security solutions.

Request Assessment