Why modern business risk sits in the seam between buildings, people, devices, networks, and vendors.
|
Author Greg “Dutch” Holland-Merten, MSc, MSyI Reviewed by HMH Converged Risk Team |
Best for Leadership teams, family offices, dealerships, law firms, healthcare groups, industrial sites, retailers, and businesses using connected cameras, access control, vendors, cloud tools, or smart building systems. |
Key takeaway:Modern risk lives in the seam between cyber systems and physical spaces. Assessing one without the other leaves blind spots.
Where Cyber and Physical Risk Collide.
For years, businesses treated cyber and physical security as separate disciplines.
Cyber sat with IT. Physical sat with facilities, security, operations, or whoever had the keys. Each team had its own tools, vendors, language, budget, and reporting line.
That separation is increasingly outdated.
Modern buildings, vehicles, cameras, access control systems, alarms, elevators, visitor platforms, HVAC systems, payment terminals, cloud dashboards, and mobile devices all create overlap between physical and digital risk.
The attacker does not care which department owns the weakness.
They care whether it works.
Converged risk is not theory.
Converged risk is what happens when a digital weakness creates physical exposure, or when a physical weakness creates digital exposure.
A poorly secured network camera may provide surveillance of staff routines. A shared door code may allow access to a communications room. A contractor badge may create both site access and network access. A stolen laptop may become a data breach. An exposed building management system may affect operations. A compromised email account may be used to manipulate a physical movement, delivery, payment, or access request.
None of that is theoretical. It is how business actually works now.
Recent infrastructure incidents show the direction of travel.
In July 2026, Reuters reported that more than 30 Minnesota community water systems were targeted in a coordinated cyberattack. The investigation was ongoing, but officials described shared timing, access methods, and targeted infrastructure characteristics seen in coordinated critical-infrastructure incidents.
Years earlier, the Colonial Pipeline cyber incident showed how a network disruption could become a fuel supply and public confidence issue. The Department of Energy documented the whole-of-government response needed to help restore operations and mitigate physical-world impacts.
The lesson is straightforward: connected systems create connected consequences.
A cyber event can become a physical operations event very quickly.
The everyday version of the problem.
Most businesses are not running pipelines or water systems. That does not mean converged risk does not apply.
For a dealership, it may be payment systems, service bay access, cameras, key control, vendor portals, and customer data.
For a law firm, it may be case files, visitor access, conference room devices, cloud storage, laptops, and after-hours office access.
For a jeweler, it may be CCTV, alarms, safes, access control, staff routines, customer records, and high-value inventory movement.
For a family office, it may be travel calendars, home automation, staff access, vehicles, residences, digital accounts, and third-party vendors.
For an industrial site, it may be OT systems, building controls, contractors, remote support tools, and physical access to equipment.
Different industries. Same principle. The seam matters.
Where the seam usually sits
- CCTV systems connected to corporate networks
- NVRs and DVRs with default or weak credentials
- Cloud-managed access control platforms
- Shared door codes and badge access
- Visitor management systems holding personal data
- Building management systems with remote access
- Alarm systems controlled through vendor portals
- Contractors with physical and digital access
- Unsecured network closets and telecom rooms
- Poorly controlled mobile devices
- Email accounts used for movement, payment, or access approval
- Staff routines visible through public or digital channels
This is where traditional assessments often miss the point. The cyber team may not look at the door. The physical team may not look at the network. The vendor may only look at its own device. Nobody tests the relationship between them.
The vendor problem
Vendors are one of the biggest converged risk factors.
A vendor may install cameras, manage access control, service alarms, maintain HVAC, support IT, manage cloud applications, handle payroll, maintain vehicles, or support executive residences.
Each vendor may have a narrow job. The business still owns the total risk.
The questions are simple: who has access, what do they access, how is that access approved, how is it monitored, when is it removed, and what happens if the vendor is compromised?
Vendor convenience is often useful. It can also create a very tidy path into the business if nobody is watching the whole picture.
A converged assessment looks at attack paths
A converged risk assessment should not be a cyber assessment stapled to a physical assessment.
It should identify practical attack paths across people, places, devices, networks, and process.
For example:
- Can someone access a network closet without challenge?
- Could a camera system provide useful reconnaissance?
- Can a vendor remotely access a physical security platform?
- Can a compromised email account authorize a physical action?
- Are executive movements exposed through digital calendars or staff communications?
- Are visitor systems protecting the data they collect?
- Are smart building systems segmented from business systems?
- Do staff understand how cyber and physical incidents can connect?
- Would the incident response plan include both IT and site security?
This is the value of a converged review. It does not respect artificial department lines, because risk does not respect them either.
What leadership usually misses
Leadership often thinks in categories: cyber, physical, operations, legal, facilities, executive protection, insurance, vendors.
That makes sense on an org chart. It does not always make sense in an incident.
A single event may involve all of them.
A stolen device may trigger data exposure, legal review, client notification, access credential reset, physical site concerns, insurance notification, and reputational risk.
A compromised vendor portal may affect building access, surveillance systems, maintenance routes, or alarm response.
A physical intrusion may become a cyber incident if the target is a laptop, server room, badge system, or executive office.
The business does not need more silos. It needs a common operating picture.
Leadership questions to ask this week
- Which physical security systems are connected to our network or cloud platforms?
- Who owns those systems internally?
- Which vendors have remote access?
- Are physical security devices patched and monitored?
- Are camera systems, access control, and alarms segmented from business systems?
- Who can access telecom rooms, network closets, and server areas?
- Are door codes, keys, and badges reviewed regularly?
- Can digital compromise authorize physical action?
- Can physical access create digital compromise?
- Does our incident response plan include physical security and operations?
- Do cyber, physical, facilities, and leadership teams ever review risk together?
- Have we ever tested a cross-domain incident?
If the answer is no, the business may be managing yesterday’s risk model.
What good looks like
A good converged risk programme is not complicated for the sake of it.
It should create clear ownership, shared reporting, tested assumptions, sensible segmentation, controlled vendor access, staff awareness, and a practical incident response model that includes both digital and physical consequences.
Good looks like:
- Cyber and physical systems mapped together
- Critical assets identified by business impact
- Vendor access reviewed and controlled
- Physical access to technical areas restricted
- Security devices patched and segmented
- Staff trained to report cross-domain concerns
- Incident plans tested across departments
- Findings prioritised by operational impact
- Leadership briefed in plain English
It is not about building a bunker. It is about understanding where one failure could create another.
The HMH view
Converged risk is where HMH is different.
We do not look only at the firewall. We do not look only at the gate. We look at the seam between the two.
That is where modern exposure lives: between cyber systems, physical spaces, human routines, vendor access, and leadership assumptions.
At HMH Consulting, we assess converged risk through practical fieldwork, technical testing, process review, and operational judgement. The aim is not to make the business paranoid. The aim is to remove blind spots before someone else uses them.
No buzzwords. No over-engineered theory. No pretending cyber and physical risk live in separate worlds.
They do not.
If your business uses connected cameras, access control, cloud platforms, remote vendors, smart building systems, executive travel, sensitive data, or high-value assets, it is already operating in a converged risk environment.
The only question is whether anyone has assessed it properly.
Book a cyber risk review with HMH Consulting.
Discreet outreach. No obligation