Hi, I’m Wajid Khan. I am trying to explain computer stuff in a simple and engaging manner, so that even non-techies can easily understand, and delivered to your inbox biweekly. Join me on an under-the-hood tech journey.
You locked your computer. You protected your password. You ignored the suspicious email. Then you held the secure door open for a stranger.
It’s 8:45 in the morning.
You’re arriving at the office with a coffee in one hand and your laptop bag over your shoulder.
You reach the entrance to a restricted area.
You tap your access card.
Beep.
The door unlocks.
Just as you’re walking through, you notice someone behind you.
They’re dressed professionally.
Laptop bag.
Phone in hand.
Company-looking ID card hanging somewhere around their neck.
They smile.
“Thanks. Could you hold that for me?”
You hold the door.
They follow you inside.
It feels like nothing.
A normal courtesy between two people arriving at work.
But here’s the question:
Did that person actually have permission to enter?
You don’t know.
They didn’t use an access card.
They didn’t authenticate themselves.
They entered because you authenticated for them.
And if that person was a social engineer, you’ve just experienced an attack called:
Tailgating.
What Is Tailgating?
Our cybersecurity training defines tailgating as a situation where a social engineer follows an authorized person into a restricted area.
The attacker doesn’t necessarily break a lock.
They don’t need to steal an access card.
They don’t have to defeat the building’s access-control technology.
They simply find someone who is authorized to enter.
Then they follow them.
That’s what makes tailgating such an interesting cybersecurity lesson.
The door may have worked perfectly.
The access card worked perfectly.
The electronic security system did exactly what it was designed to do.
But the person who opened the door unintentionally allowed someone else through.
The technology wasn’t necessarily defeated.
The human behavior was exploited.
Why Is This a Cybersecurity Problem?
You might be thinking:
“Isn’t this physical security rather than cybersecurity?”
The distinction isn’t always as clear as we imagine.
Our training warns that once a social engineer enters a restricted area, they may gain access to unlocked workstations and potentially infiltrate the organization’s network.
Think about that.
An unauthorized person gets through one physical door.
Now they’re walking through an environment containing:
Computers.
Workstations.
Internal systems.
Employees.
Potentially sensitive information.
The cyberattack may therefore begin without an email, malicious link or piece of malware.
Sometimes the first security control being attacked is literally:
The office door.
The Attacker Wants to Look Like They Belong
A successful tailgater probably doesn’t want to look suspicious.
Imagine someone approaching the secure entrance wearing a black hoodie and mask, looking around nervously and saying:
“Can you let me into your restricted network operations room?”
You’re probably going to ask questions.
That’s not how a social engineer wants the situation to feel.
Instead, they want to look ordinary.
Professional clothing.
Laptop bag.
Coffee cup.
Phone.
Confident body language.
Maybe an ID badge.
They may walk quickly, as though they’re late for a meeting.
The objective is to make your brain decide:
“They probably work here.”
And once your brain reaches that conclusion, politeness can take over.
“I Forgot My Badge”
Now imagine the person says:
“I forgot my badge upstairs. Can you let me through?”
That’s a believable story.
Employees forget things.
Access cards stop working.
People move between offices.
Nothing about the explanation sounds impossible.
But remember one of the most important lessons from our social-engineering article:
A believable story isn’t the same as verified authorization.
The attacker doesn’t need to tell you an impossible story.
They need to tell you a story that’s plausible enough that you stop questioning it.
Social Engineers Exploit Helpfulness
This is why tailgating belongs in our cybersecurity-awareness series.
The attack relies on the same human behaviors we’ve already discussed.
Trust.
Helpfulness.
Social pressure.
Authority.
Distraction.
Urgency.
Suppose the person behind you is carrying two large boxes.
You naturally hold the door.
That’s what considerate people do.
Now imagine they’re carrying those boxes because they know people are more likely to hold the door for someone whose hands are full.
The behavior hasn’t changed.
The intention behind the situation has.
The attacker is turning normal human courtesy into a way around an access control.
The Awkwardness Is Part of the Attack
There’s another reason tailgating can work.
Stopping someone at a door can feel uncomfortable.
Imagine saying:
“Sorry, I can’t let you come through with me.”
What if they really are an employee?
What if they’re senior to you?
What if they think you’re rude?
What if everyone else normally holds the door?
That tiny moment of social discomfort is useful to an attacker.
They want you thinking:
“I don’t want to make this awkward.”
instead of:
“Is this person authorized?”
Security procedures sometimes require us to tolerate a few seconds of awkwardness.
That’s okay.
An ID Badge Isn’t Always Proof
Suppose the person has something hanging around their neck that looks like an employee badge.
Does that settle the question?
Not necessarily.
The important issue isn’t whether someone looks like they belong.
It’s whether they are following your organization’s required access procedure.
Remember what we’ve learned throughout this series:
A familiar display name doesn’t prove an email is legitimate.
A familiar logo doesn’t prove a website is legitimate.
A familiar Wi-Fi name doesn’t prove a wireless network is legitimate.
And someone who looks like an employee isn’t automatically authorized to enter a restricted area.
The same principle keeps returning:
Appearance isn’t verification.
The Access Card Is There for a Reason
Imagine your organization spends money installing:
Electronic access-control systems.
Security doors.
Employee badges.
Restricted areas.
Logging systems.
Then every morning employees hold the secure door open for whoever happens to be walking behind them.
At that point, the expensive technology isn’t providing the protection it was intended to provide.
Access control works only when the access process is actually followed.
If every authorized person must authenticate individually, allowing someone to bypass that process defeats the purpose of the control.
What Could Someone Do Once They’re Inside?
Our source material gives us one particularly important example:
Access unlocked workstations.
Imagine an employee leaves their desk for a few minutes without properly securing their workstation.
An unauthorized person is already inside because someone allowed them through the door.
Now two small security failures have combined.
Failure 1:
Unauthorized physical access.
Failure 2:
Accessible workstation.
The attacker may now have an opportunity to interact with systems inside the organization.
This illustrates something important about cybersecurity:
Security incidents often depend on several small weaknesses connecting together.
Cybersecurity Is a Chain
Think about the attacks we’ve covered so far.
A phishing email leads to a malicious attachment.
The attachment installs malware.
The malware helps steal credentials.
The credentials provide system access.
Or:
A social engineer creates a convincing story.
The employee believes it.
The employee provides information.
The attacker uses that information for another attack.
Tailgating can follow the same pattern.
An employee opens a restricted door.
The attacker gets inside.
They encounter an unlocked workstation.
That workstation gives them an opportunity to access organizational systems.
One action creates the opportunity for the next.
Breaking any part of that chain can stop the attack.
Tailgating and Insider Threats Are Not the Same Thing
An insider threat can involve someone such as an employee, contractor or vendor who misuses existing access to the organization’s networks, systems or data.
Tailgating involves a social engineer finding a way to follow an authorized person into a restricted physical area.
One may involve misuse of legitimate internal access.
The other involves obtaining unauthorized physical access by exploiting someone who is authorized.
Different threats.
But they share an important characteristic:
The attacker ends up operating inside a boundary we expected to be secure.
“But I Know That Person”
Suppose you recognize the person behind you.
Does that mean you should ignore your organization’s access procedures?
Not necessarily.
Knowing someone and authorizing someone’s access are different things.
You may know a colleague without knowing whether they’re permitted to enter a particular restricted area.
Organizations create access controls because different people may have different levels of authorization.
The safest approach is not to invent your own rules.
Follow your organization’s access-control policy.
Don’t Turn Yourself Into Security Staff
Just as we discussed with insider threats, cybersecurity awareness doesn’t mean you should start personally investigating everyone around you.
You aren’t being asked to interrogate colleagues.
You don’t need to demand identification from everyone you see.
And you shouldn’t create confrontations.
The principle is much simpler:
Follow the organization’s established procedure for restricted areas.
If something doesn’t seem right, use the appropriate security or reporting channel.
Let the people responsible for physical security handle situations requiring further investigation.
Restricted Means Restricted
The word restricted matters.
A restricted area exists because access is intentionally controlled.
So ask yourself:
What makes someone authorized to enter this area?
Is it an access card?
A visitor badge?
Security approval?
An escort?
Some other organizational process?
Whatever your organization’s procedure is, follow it.
Don’t replace:
“This person has demonstrated authorization”
with:
“This person looks like they belong here.”
Those are not equivalent.
The Coffee-Cup Test
Here’s a simple scenario I want you to remember.
You’re entering a restricted office.
Behind you is someone holding:
A coffee.
A laptop.
A phone.
They look professional.
They smile and say:
“Thanks.”
Your brain may automatically interpret that as:
Employee.
But none of those things actually demonstrates authorization.
A coffee cup isn’t an access credential.
A laptop bag isn’t an access credential.
Professional clothing isn’t an access credential.
Confidence isn’t an access credential.
The organization’s approved access method is the access credential.
That distinction is the heart of tailgating awareness.
Physical Security Protects Digital Security
This is the bigger lesson.
Cybersecurity isn’t contained inside the computer.
Passwords matter.
Firewalls matter.
Malware protection matters.
Email filtering matters.
VPNs matter.
Access controls matter.
But physical access can influence digital security.
A restricted office may contain the very computers, networks and information all those other security technologies are designed to protect.
So when we protect the door, we’re not protecting only the room.
We’re helping protect everything accessible from inside that room.
A Few Seconds at the Door Can Matter
Tailgating happens in an extremely ordinary moment.
That’s what makes it easy to overlook.
You’re not sitting in front of a suspicious email wondering whether to click.
You’re walking through a door.
You’re thinking about your meeting.
You’re carrying coffee.
Someone is behind you.
And you make a decision almost automatically.
That’s where awareness helps.
It creates a small pause:
“This is a restricted entrance. Does everyone need to authenticate individually?”
If the answer is yes, follow the process.
Those few seconds may matter just as much as the few seconds we spend checking a suspicious email.
Security Culture Shows Up in Small Moments
Organizations often talk about building a strong security culture.
That can sound abstract.
But security culture appears in ordinary behavior.
It’s the employee who reports the suspicious phishing email.
The finance employee who verifies an unexpected bank-account change.
The person who uses an approved password manager instead of reusing credentials.
The traveler who verifies the correct public Wi-Fi network.
And the employee who follows access procedures even when holding the door would be easier.
Security culture isn’t built only through technology and policies.
It’s built through repeated everyday decisions.
The Door Is Part of the Security System
The next time you enter a restricted area, remember what that door represents.
It’s not simply an inconvenience between you and your desk.
It’s a security boundary.
The access card isn’t simply something you have to carry.
It’s part of the process that determines who should be allowed through that boundary.
And you are part of that process too.
So be helpful.
Be polite.
But don’t allow politeness to quietly override security procedures.
Because the attacker trying to reach your organization’s systems may never send you a phishing email.
They may never ask for your password.
They may never create malware.
They may simply walk behind you and say:
“Thanks for holding the door.”
Key Takeaway
Tailgating occurs when a social engineer follows an authorized person into a restricted area. Once inside, they may gain access to unlocked workstations and potentially the organization’s network. Follow your organization’s access procedures and don’t treat appearance, familiarity or politeness as proof of authorization.
Hi, I’m Wajid Khan. I am trying to explain computer stuff in a simple and engaging manner, so that even non-techies can easily understand, and delivered to your inbox biweekly.




