UK organisations invest considerable time and budget in protecting the perimeter. Access control, CCTV, guarding and visitor management all help determine who can enter a facility and under what circumstances.
But what happens after someone crosses that perimeter?
For employees, contractors, engineers and maintenance personnel, getting access is easily done.
Yet once an authorised individual is inside, visibility over their interaction with physical assets can become less consistent. That creates an important insider-risk consideration: trust is necessary, but not enough.
Human error and negligence account for roughly 55% of all insider incidents, though malicious actions have grown to represent about 32% of events.
It takes serious time and money to recover from these incidents.
The UK’s National Protective Security Authority (NPSA) provides a useful framework through its 10 Steps to Effective Insider Risk Assessment. The guidance encourages organisations to identify critical assets, understand threats, assess risk, document existing and additional mitigations, and continually monitor their effectiveness.
Independent assessment can also add value. External specialists can challenge established assumptions, examine processes from a different perspective and identify vulnerabilities that may be difficult to see from within the organisation.
Physical key management is one area worth putting under that lens.
Processes leave surprisingly fundamental questions difficult to answer:
Who took a key? Were they authorised to take it? When did they take it? And, during an investigation or audit, can you demonstrate the answers?
Intelligent key management can help close this accountability gap. As one component of a layered insider-risk strategy, PAAM Systems provides technology for securely storing and tracing physical keys, helping organisations ensure the right people have access to the right assets at the right time, while maintaining a traceable record of key activity.
Strong perimeter security remains essential. But for security managers, there is another question worth asking:
How effective are your controls once someone is already inside?







