Skip to content

Illustration by Security Management; iStock

Impossible Travel Detection: Closing an Insider Threat Gap

For decades, physical security has operated on the basic assumption that a credential belongs to one person, and that person can only be in one place at a time. This assumption is largely untested because the access infrastructure to do so simply didn’t exist. Most enterprise environments manage physical access control as a collection of disconnected, siloed systems, where the infrastructure can differ across corporate headquarters, regional offices, leased offices, data centers, and other facilities. But even in environments running a single cohesive system, the access transactions for authorized users are rarely examined for behavioral anomalies.

Most of this fragmentation has come about the way enterprise complexity usually does—through acquisitions, shifting real estate footprints, evolving IT stacks, and the natural sprawl of organic growth. Integration will always be addressed “later,” but in many organizations, later never comes. This results in access control environments that look modern on the surface but run on manual processes and systems that were never built to communicate with each other.

At the same time, physical access events are typically not compared and confirmed using the broader digital footprint employees leave across other systems. For example, the Wi-Fi network he or she joined, the cafeteria order placed, the travel booking made, and the secure print job released present a far more complete story about someone’s location, including when he or she is there.

This environment is ripe for insider threats, where the same credential can appear simultaneously across separate systems, with no simple way to connect those events and alert various teams that there might be a security incident at play. It’s pretty easy for such threats to slip through the cracks of manual processes and disconnected systems since a credentialed and trusted person moving through a building is already known to the organization. Impossible travel detection changes that dynamic because it relies on physics.

Existing cybersecurity tools can focus on identifying impossible travel, defined as two sign-ins originating from locations that are too far apart to log in within a realistic period of time.

In a common scenario—the impossible travel detection scenario—an authorized user accesses a secure server room with his or her credential. Within hours, the same credential is used for attempted access to a restricted floor in a facility hundreds of miles away. This is virtually impossible, based on the distance between locations. So a platform can register both events, determine that the travel time makes the sequence impossible, and trigger alerts or other actions. Security teams can quickly deactivate the credential, pull both events for review, and open an investigation to coordinate a response, if necessary.

For years, the cybersecurity sector has used impossible travel detection, flagging authentication events when it’s clear, for example, that accessing resources would require a user to physically cross vast distances, even continents, within minutes. This behavior is flagged by measuring the distance and time between sign-in attempts, with the user able to set a default top travel speed. The same logic applies directly to physical environments, where a credential moving across locations faster than any person could travel is one of the clearest behavioral signals a security team can act on.

Insider threat programs should be especially wary about this gap because detecting questionable physical access behavior across locations requires cross-system visibility, which siloed access control environments are seldom able to provide.

Similar anomalies include an employee accessing spaces outside his or her normal pattern, or a contractor moving through areas of a facility where he or she has no reason to be. These events can be more easily detected with a unified physical access layer or connected access network platform. These solutions bring together multiple access control systems and technologies for centralized visibility and management to help identify issues in real time.


This environment is ripe for insider threats, where the same credential can appear simultaneously across separate systems, with no way to connect those events and alert various teams that there might be a security incident at play.


Physical security finds itself at the same crossroads IT faced years ago, where the more practical path is adding the connective layer that existing systems have been missing. The organizations best positioned to manage insider threats are the ones that treat physical access data as a source of behavioral intelligence. These companies extend zero-trust principles across physical domains the same way they have already been applied to the digital world, putting the individual at the center of how access is governed.

A connected access network approach instead allows organizations to use a single platform to centralize management of every access point across their entire portfolio. Unifying access data in a technology-agnostic platform allows for real-time visibility into where someone is attempting to gain access. This way, security teams can easily identify and act in response to impossible travel scenarios.

One highly common issue this type of detection could address concerns delays in offboarding exiting employees, such that credentials are active even after an employee and employer have terminated their formal relationship. Incomplete offboarding is one of the most underestimated insider threat risks, with research pointing to 34 percent of former employees retaining access to systems or data after leaving an organization.

Mobile credentials have accelerated the shift toward more secure, centrally managed access. They give organizations a cleaner way to provision, track, and deactivate credentials across locations.

For insider threat programs that have struggled to connect physical access behavior across locations, a connected access network approach provides the infrastructure that has always been missing. It brings physical access systems, identity providers, and enterprise IT ecosystems into a single open layer, whereby governed access follows the user’s identity across buildings, doors, floors, and shared resources. Within that broader governance model, insider threat programs gain the impossible travel detection, cross-location visibility, and real-time response capability that siloed physical security environments have never been able to deliver, with mobile credentials becoming within a network built to deliver all of it.

 

Brandon Arcement is executive vice president and chairman, executive committee for SwiftConnect. He has more than 20 years of experience leading transformation in physical access, digital identity, and smart building technology. Before joining SwiftConnect, Arcement was a senior director of strategic application at HID, and previously worked for Johnson Controls. He earned a bachelor’s degree in mechanical engineering from the University of Texas at Austin.

 

arrow_upward