4.2 Natural Disasters, Accidental & Cyber-Physical Hazards
Key Takeaways
- Natural hazards—flood, wind, earthquake, wildfire, and extreme heat or cold—destroy protection systems and then open the site to adversaries
- Accidental hazards include hazardous-materials releases, vehicle impact into the lobby, utility failure, and construction openings left in the perimeter
- Attacks on access-control, video, and intrusion networks still leave physical security owning the cabinet, cable plant, and console
- Stolen credentials and unlocked intermediate-distribution-frame closets convert a digital payload into physical entry
- Writing a flood plan while ignoring an already-successful tailgating thief treats a high-likelihood adversarial pathway as less important than a polished binder
Natural Disasters, Accidental, and Cyber-Physical Hazards
Adversaries are not the only sources of harm. Domain 1 Task 3 groups natural disasters, accidental events, and cyber with crime and terrorism for a reason: the assessment has to estimate likelihood and severity for non-adversarial harm as well. A flood that drowns the access-control servers, a delivery truck that enters the lobby, and a stolen badge that opens every reader are all in the PSP threat-and-hazard picture. Physical security still owns the cabinet, the cable plant, and the console even when the payload is digital.
Exam focus: A hazard can destroy protection systems and then invite an adversary. Writing a flood plan while ignoring a tailgating thief is a classic miss.
Natural Hazards That Change Physical Security
Natural events do not have intent, but they have capability (energy), history (maps and past floods), and targeting (the site sits in a path). Treat them as hazards with likelihood and severity, then ask what they do to people, assets, and the security systems that were supposed to protect both.
Flood includes riverine overflow, coastal surge, flash flooding, and interior water from failed roofs or sprinklers. Water kills controllers, lock power, and video storage long before it reaches the executive floor. A warehouse built on a slab in a mapped floodplain has a history even if this particular tenant has never seen water. Likelihood comes from flood maps, drainage, and past interior leaks—not from whether the lobby looks dry today. Severity includes life safety, inventory, and the days of unsecured doors while electric locks fail open or fail locked depending on code and design. Know which openings fail in which direction; that is a physical-security question, not only a facilities question.
Wind—hurricane, tornado, straight-line—peels rooftop cameras, blows in glazed façades, and turns dumpsters into missiles. After a storm, fencing gaps and missing doors are invitations. History is local climatology and the last roof-camera replacement. Targeting is height, exposure, and cheap mounts. A "temporary" plywood period after glazing loss is a burglary and theft window, not a pause in the security program.
Earthquake is low-likelihood in many U.S. interiors and high-consequence where it is credible. Unrestrained battery plants, sliding racks, and jammed doors after a shake are physical-security and life-safety problems together. Do not import a coastal shake scenario onto a site with no credible seismic history just to look thorough. Do not ignore bracing in a zone where the building code already required it.
Wildfire is not only a rural-forest problem. Ember attack, smoke, and evacuation orders hit campuses at the wildland-urban interface and some industrial edges. Cameras looking at a tree line can be the first detection of fire—or the first things to melt. Access control must still let people out. A gate that cannot fail safe during evacuation is a hazard layered on a hazard.
Extreme heat and cold kill equipment quietly. Outdoor card readers, camera housings, lock electronics, and backup batteries have operating ranges. A Midwest winter that freezes a parking-control arm, or a Southwest summer that cooks an unventilated closet, produces the same operational result as sabotage: the system is down. Likelihood is climate, not crime. Severity is the period of uncontrolled access or failed detection.
| Natural hazard | Typical physical-security effect | Evidence you actually collect | Common miss |
|---|---|---|---|
| Flood | Powered locks and video servers drowned; debris on fences; mold in closets | Flood maps, drain history, floor elevations of security rooms | Security equipment on the lowest floor because that closet was empty |
| Wind | Camera loss, façade breach, fence failure | Wind region, roof-mount quality, glazing | Treating plywood as an acceptable overnight perimeter |
| Earthquake | Jammed doors, fallen racks, spilled battery acid | Seismic design category, restraint of security gear | Skipping bracing because the building is old |
| Wildfire | Evacuation versus shelter, melted devices, smoke-obscured video | Vegetation, access roads, prior evacuations | Magnetic locks that trap people during a fire-alarm storm |
| Extreme heat or cold | Reader and lock failure, condensation, battery collapse | Manufacturer ranges versus local climate | Indoor-rated gear in outdoor housings |
Accidental Hazards
Accidents have no adversary, but they still have likelihood, severity, and a habit of opening the site to criminals afterward.
Hazardous materials (HAZMAT) on site or next door: a chemical release can force shelter-in-place or evacuation, shut heating and cooling, and empty posts. Physical security must know what is stored, where, and how a release would change staffing and doors. A spill that sends everyone to the parking lot also sends the contents of the building toward anyone watching.
Vehicle crash into the lobby is an accidental pathway that can also be adversarial. A delivery van, a medical event at the wheel, or a confused driver can penetrate a glass storefront. Bollards, setbacks, and lobby layout are as much accident countermeasures as anti-ram features. History includes the curb cut, the slope toward the glass, and whether trucks already bounce the sidewalk. Severity includes people in the lobby, not only the pane.
Utility failure—power, water, heating and cooling, communications—turns electronic security into a battery-life problem. Know how long locks, cameras, and radios last on backup, and what the fail state is. A four-hour uninterruptible power supply on the video servers and a twenty-minute battery on the readers is a designed gap. After a regional outage, opportunistic burglary rises in many commercial districts; the accident and the adversary arrive together.
Construction error is a hazard you will see on live campuses: a fire-watch door left unsecured, a construction core that still operates after the project, a fence panel removed for a crane and never reinstalled, a camera covering a wall that was demolished. Intent is absent; capability to create an open path is high. History is the punch list you did not walk at dusk.
Cyber-Physical Hazards: The Payload Is Digital, the Cabinet Is Yours
PSP is not an information-security credential, but the knowledge statements include cyber as a threat and hazard type because modern access-control systems (ACS), video surveillance systems (VSS), and intrusion-detection systems (IDS) are networked. An attacker who never climbs a fence can still unlock doors, blind cameras, or suppress alarms. The physical security professional still owns three things.
The cabinet: controllers, network video recorders, switches, and power supplies in locked rooms. If the room is a janitor closet with a storeroom key, you do not have a cabinet. You have a box in a hallway.
The cable: copper and fiber paths, including the unlocked intermediate-distribution-frame closet that is "only IT." Anyone who can sit in that closet can span ports, unplug door controllers, or insert a device. Walk the closets. If twenty people hold the key, the closet is not a control.
The console: workstations in the security operations center, including unlocked sessions, shared passwords on a sticky note, and remote-access tools left enabled for a vendor. A stolen password that reaches the ACS is a physical-entry problem, not a ticket you can close by saying "cyber owns it."
Attacks on ACS, VSS, and IDS networks include default passwords left on cameras, unsegmented security virtual local-area networks sitting on guest wireless, remote-access tools left enabled, and ransomware that encrypts the video archive. The physical effect is immediate: doors may fail, video may disappear, alarms may go silent. Likelihood is high wherever those systems are treated as "just cameras" instead of as safety systems. Severity is the period of no detection and no delay.
Stolen credentials are a hybrid. A badge left on a café table, a cloned card, a phished password that reaches the ACS, or a shared contractor login all convert a digital secret into physical entry. The adversary may be external; the enabling condition is often an insider process failure—slow reporting of a missing badge, no escort for the vendor, no timeout on the console.
Trap: The Flood Binder and the Tailgating Thief
A river campus spent a year writing a flood annex: sandbag diagrams, generator elevations, a call tree, and a plan to relocate the security servers to the second floor after a watch stage. The binder was excellent. In the same year, lobby officers waved through anyone who smiled, the turnstiles stayed in bypass "because of flu-season lines," and shrinkage from the first-floor sample room climbed. The next loss event was not the river. It was a thief who tailgated through the lobby, walked into an unattended sample room, and rolled out a cart of prototype devices.
The trap is writing a flood plan and ignoring a tailgating thief. Natural-hazard planning is required where the maps say so. It does not excuse an unattended adversarial pathway that is already succeeding. Likelihood for tailgating at a busy lobby is often daily. Severity for prototype loss can exceed a wet carpet in the mailroom. Score both. Fund both in proportion to risk, not in proportion to which binder looks more professional.
A second version of the same trap: treating cyber-physical issues as "IT's job" and never walking the closets. Information-technology teams may patch servers. Physical security still specifies the lock, the camera on the closet door, the escort rule for vendors, and the console timeout. If the payload is digital and the door is open, you still own the door.
Worked Scenario: Hospital Campus
An urban hospital sits on a floodplain fringe, runs a busy emergency department, and has a pharmacy, a ground-floor intermediate-distribution-frame closet, and a loading dock that shares a driveway with an ambulance bay.
Natural: a 2019 interior flood from a failed domestic-water line drowned the ground-floor closet for six hours. Access control went to battery, then failed. Exterior doors on delayed-egress hardware behaved as designed for fire, which meant they also behaved as designed for anyone who wanted out with property. Wind last summer took two parking-garage cameras. Extreme heat this July produced condensation in outdoor readers at the staff lot.
Accidental: a patient-transport van clipped a bollard last year; the next vehicle could reach the emergency-department glass if the remaining posts stay decorative. A construction project on the west wing left a fence gap for a week. A HAZMAT incident at a nearby rail line could force shelter-in-place while the emergency department still receives walk-ins.
Cyber-physical: default passwords remained on several older cameras; the security network was not separated from clinical wireless; the closet that flooded was also unlocked so that "nurses could reset the badge printer." A traveler nurse's badge was missing for two shifts before anyone reported it.
A complete hazard picture for this campus is not "we have a flood plan." It is flood (history, elevation of the replacement closet), vehicle impact at the emergency department, construction openings, the unlocked cabinet, the credential process, and the thief or aggrieved visitor who will use any of those openings. Likelihood and severity get scored per event, not as one hospital-risk slogan. The chart below is a worked qualitative example for this campus, not a national ranking and not an official score you should memorize.
Ransomware encrypts the video archive, and an attacker is also able to sit in an unlocked ground-floor intermediate-distribution-frame closet. What does physical security still own?
A river campus has an excellent flood binder. Shrinkage from an unattended sample room is rising because lobby turnstiles stay in bypass and visitors tailgate. What is the assessment trap?
Outdoor card readers keep failing every July, and a delivery van recently jumped the curb toward the lobby glass. How should those two events be typed in the threat-and-hazard picture?