C://SECURE36Physical Security
The door is part of
the attack surface.
Physical security covers access control, alarms, and visitor management: who can enter which spaces, when, and with what record. It is for organisations with server rooms, sensitive areas, or after-hours access to manage.
THE PROBLEM
Strong digital controls are worth less than they look if the server room is unlocked and the alarm code has not changed in years.
The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.
Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.
- 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
- 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
- 03Only handled when it breaksAttention arrives after the disruption rather than before it.
WHAT YOU GET
What the engagement covers
Scoped before it starts, so you know what is included and what is not.
- 01
Access control
Card or mobile credentials issued by role and revoked centrally the moment someone leaves, rather than collected back at a farewell if anyone remembers.
- 02
Sensitive areas
Server rooms and comms cupboards restricted separately and logged, because that is where an afternoon of unsupervised access does the most damage.
- 03
Visitor management
A record of who was on site and when, which is unremarkable until the day you need it.
- 04
Integration
Physical access tied to the same identity system as digital access, so one offboarding process governs both.
HOW WE WORK
Baseline, remediate, monitor, evidence
Four stages with a written output at each one. You always know which stage you are in and what comes next.
- 01Week 1
Baseline
What is configured today, measured against a recognised standard, with gaps ranked by real-world risk rather than vendor score.
- 02Weeks 2 – 6
Remediate
Gaps closed in the order that buys the most safety fastest, with each change recorded.
- 03Ongoing
Monitor
Tuned to your environment so alerts mean something, and every alert has a named owner.
- 04Quarterly
Evidence
A written report you can hand to an insurer, a customer, or your board without translating it first.
WHAT CHANGES
What you should expect
- Someone other than you owns it, with that written down.
- The current state is documented and stays documented.
- Cost is planned ahead rather than discovered at renewal.
- Decisions are made against evidence rather than assumption.
FAQ
Questions we get asked
01What is physical security?
Physical security covers access control, alarms, and visitor management: who can enter which spaces, when, and with what record. It is for organisations with server rooms, sensitive areas, or after-hours access to manage.
02Why would an IT company handle physical security?
Because the two have converged. Access control systems are now networked software with user accounts, permissions, and updates, and they are frequently the least maintained device on a business network. Tying door access to the same identity system as everything else also means one exit process removes both, which is the gap that keeps causing problems.
03What is wrong with keys and a shared alarm code?
They cannot be revoked and they cannot be audited. Keys are copied, codes are shared, and neither tells you who actually opened the door at eleven on a Sunday. Credentials that can be switched off individually and produce a log are a different proposition entirely, and after an incident the log is often the only thing that resolves the question.
04How secure does a server room actually need to be?
Secure enough that only the handful of people who need to be in there can get in, and that entries are logged. Physical access to hardware defeats most digital controls, because someone standing in front of a server can do things no remote attacker can. It also protects against the far more common problem, which is a well-meaning person unplugging something.
05Can access control work with the cards or phones we already use?
Usually. Modern systems support mobile credentials, so a phone becomes the pass, and can often read existing card formats. If you are replacing an older system it is worth checking whether the existing readers and cabling can be retained, because that is frequently the larger share of the cost.
06What should happen when someone leaves the business?
Their building access, their accounts, and their multi-factor device should all be revoked as part of one process, ideally triggered by the payroll exit rather than by anyone remembering. Where these are separate systems maintained by separate people, one of them is always missed, and it is usually the door.
07How much does physical security cost in New Zealand?
We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.
08How long does it take to get started with physical security?
A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.
09Can you deliver physical security alongside our existing IT team or provider?
Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.
10Do we have to move our whole IT contract to Atlas?
No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.
11Can you support us if we are not based in Auckland?
Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.
12Who will we be dealing with when something actually happens?
Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.
13What happens after it is in place?
You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.
Start with a conversation.
Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.
← All services