Have you previously witnessed or learnt of a house-breaking incident? Once inside, what really does the perpetrator look for?

Physical security has often been entrusted with the guards protecting company premises while limiting the entry of ineligible guests, but today it has proved to go beyond the entry check-points to more sophisticated levels involving internal collusion and social engineering ploys. Whereas physical security can be easily overlooked by an organization, it is one of the attack dimensions that can highly expose employees and organizational assets to cybersecurity breaches.

In any event, a physical object can be stolen, damaged, or destroyed. The physical security attacks thus range from gaining unauthorized access to a facility, cutting a fibre-optic backbone, breaking into secure spaces and/or stealing equipment, removing RAM and other components from a PC, and recovery of improperly disposed of sensitive information among many other mischievous practices.

KCCA broken into, computers stolen
“Kampala Capital City Authority (KCCA) offices were deemed to have broken into twice within a space of 10 days,” reported Amos and Damalie of Daily Monitor Uganda. This came to light through a June 23rd letter authored by a whistleblower.

The whistleblower said unknown people broke into the office of the directorate of engineering and technical services and took off with an unidentified number of computers. “Exhibits were later recovered by detectives inside City Hall main building in an emergency tunnel/duct which connects the vandalised office to the toilets with discs which contain data missing,” the letter reads in part.

After Mr Lukwago read the letter in the council meeting, councillors wondered how the offices could be broken into with a fully-fledged police department in place to ensure the safety of the property. The council also learnt that the KCCA headquarters did not have CCTV cameras. Mr Richard Lule, the KCCA director of human resource, admitted before the council that certain offices in the technical wing had previously been broken into and some documents got stolen. He added that the claims in the said letter were true and police at CID were already investigating the matter.

Best practices to embrace
With regard to the truth of the matter, we need to be well equipped with these tips of guarding against physical security attacks:

  1. Secure access to buildings and rooms such as the server room and data centre by using tight locks or access cards coupled with a surveillance system.
  2. Disable external access such as USB ports, and grant access where only necessary.
  3. Audit services, users, and administrators to verify compliance with security policies.
  4. Secure any backup media.