Tailgating is the oldest trick in physical social engineering: someone without a badge just follows an employee through a locked door, and 2026 breach reports keep showing it still works. This guide gives you the exact training sequence to stop it, from entry-point audits to unannounced drills your staff won't see coming.
TL;DR
- Train staff tailgating physical security starts with a no-exception badge policy, not a poster campaign.
- Reception and frontline staff need scripted challenges before anyone else in the building does.
- Unannounced tailgating drills expose gaps that awareness training alone misses.
- Fold tailgating scenarios into new-hire onboarding so the habit forms on day one, not after an incident.
- Repeat tailgating incidents need an escalation path, the same way repeat phishing clicks do.
Why this matters
Tailgating bypasses every digital control a company has. It doesn't matter how strong the phishing filters are if a stranger in a delivery vest walks straight into the server room behind someone carrying coffee.
Most security awareness training in 2026 still focuses almost entirely on email and phishing, which leaves a physical gap attackers know how to use. The same instinct that makes staff click a fake invoice link, wanting to be helpful, not wanting to seem rude, is what makes them hold a door for someone they don't recognise. Training staff to recognise cyber security threats has to include the physical version of social engineering, not just the inbox version.
ISO 27001:2022 Annex A control 7.2 covers physical entry controls directly, and any audit against that standard in 2026 will ask for evidence of staff training on it, not just a badge reader on the front door.
What you'll need
- A floor plan or access list showing every door, loading dock, and shared entry point
- Badge or fob access logs from the last 90 days
- Reception and frontline staff available for a 30-minute briefing
- A short (2-3 minute) scripted challenge phrase staff can use without confrontation
- A reporting channel that doesn't require naming a colleague to flag a concern
- Time for at least two unannounced drills across a quarter
The steps
1. Map every entry point in the building
This tells you where tailgating is actually possible, not where you assume it is. Most offices have three or four "soft" entry points beyond the front door: loading docks, fire exits propped for smoke breaks, and shared lobbies with other tenants.
Walk the building once with a checklist and note which doors lock automatically and which ones staff prop open out of habit. Expect to find at least one door that's been propped for months without anyone flagging it. Common mistake: auditing only the main entrance and skipping the loading dock, which is where most real-world tailgating happens.
2. Enforce a strict badge-only access policy
A badge policy only works if there are zero exceptions, including for the CEO. Once one person is allowed through without scanning, the policy is dead within a week.
Set the rule in writing: every person, every door, every time, badge scans first. Give reception the authority to stop anyone, including senior staff, who tries to bypass it. Expected outcome: badge log volume should match headcount within 5-10% once the policy sticks. Common mistake: rolling this out without telling senior leadership first, so the first person management has to correct is a director.
3. Train frontline and reception staff first
Reception and security staff face tailgating attempts before anyone else does, so they need the scripted response before the rest of the company. A single confident phrase, something like "I can't let you through without a badge, let me call your host," stops most attempts cold.
Run this as a 20-minute session, not an email. Role-play the exact phrase twice so it's automatic under pressure. Common mistake: training reception on policy but not on the actual words to say, which leaves them freezing when someone pushes back.
4. Run unannounced tailgating drills
Drills show you what staff actually do, not what they say they'd do in a survey. Have someone from outside the immediate team, or a contractor from a different site, attempt to follow an employee through a secure door without a badge.
Run the first drill within 30 days of the policy rollout and a second one 60-90 days later to check retention. Log every successful and failed attempt by door, not by individual name. Common mistake: only drilling the front door when the loading dock is the weaker point identified in step one.
5. Build a no-blame reporting channel
Staff need a way to flag "someone followed me in and I didn't check" without feeling like they're reporting a colleague to HR. If reporting feels punitive, it stops within weeks.
Use the same principle already applied to phishing reporting: fast, anonymous where possible, and followed up with a thank-you, not a warning. Expected outcome: report volume should rise after a drill, which means people are paying attention, not that the problem is getting worse. Common mistake: routing tailgating reports through a manager instead of a dedicated security inbox, which slows the response and discourages future reports.
6. Fold tailgating scenarios into onboarding
New hires are the highest-risk group because they don't yet recognise who belongs in the building. Building tailgating awareness into new employee onboarding training means the habit forms before bad habits do.
Add a 10-minute physical security module to week one, covering the badge policy and the challenge script from step three. Expected outcome: new hires should be able to name the reporting channel by the end of week one. Common mistake: covering physical security only in a digital onboarding module that nobody reads past slide two.
7. Track and escalate repeat incidents
One tailgating slip is a training gap. Three from the same person in a quarter is a pattern that needs a direct conversation, the same way repeat phishing clickers get escalated rather than re-sent the same training video.
Log incidents by individual over a rolling 90-day window and set a threshold, two or more, that triggers a one-on-one refresher instead of another group email. Common mistake: treating every incident the same regardless of frequency, which teaches high-risk staff that nothing actually changes.
Fold physical security into staff training
See how a security awareness platform tracks both digital and physical training in one place.
Troubleshooting
Staff say challenging a stranger feels rude. Give them a scripted phrase and frame it as helping the visitor find their host, not accusing anyone. Rehearsed politeness removes the awkwardness that makes people freeze.
Visitors slip through the loading dock. Add a physical log or buzzer at the dock and assign one staff member per shift as the point of contact. Unmonitored docks are the most common gap found in step one's audit.
Contractors piggyback in vans during deliveries. Issue short-term contractor badges instead of relying on staff recognition. A badge that expires at the end of the job closes this gap without slowing deliveries down.
Drills feel like entrapment to staff. Announce that drills happen quarterly, without naming dates, and frame results as team-level, not individual, unless the escalation threshold in step seven is hit.
Reporting stays flat even after a drill. Check whether the reporting channel is actually anonymous and fast. If people have to open a ticket and wait two days, they'll stop bothering after the second try.
Tools and resources
- Floor plan or building access map (existing facilities documentation)
- Badge or fob access logs, pulled monthly
- A short physical security module added to onboarding, see new employee onboarding training
- Gamified security awareness training formats to keep tailgating scenarios from feeling like a lecture
- A no-blame reporting inbox, separate from general HR channels
What to do next
Tailgating incidents alone won't tell you whether the training actually changed behaviour. Pair drill results with a broader look at how to measure security culture beyond click-rate metrics, since physical security habits move on a slower timeline than email habits do.
FAQ
What is tailgating in physical security?
Tailgating is when someone without authorised access follows an employee through a secure door, relying on politeness rather than breaking in. It's the physical equivalent of phishing and it's covered under ISO 27001:2022 Annex A control 7.2 for physical entry.
How do you train staff to prevent tailgating?
Train staff tailgating physical security by giving them a scripted challenge phrase, enforcing a no-exception badge policy, and running unannounced drills at least twice a year. Frontline and reception staff need this training before the rest of the company.
Is tailgating a bigger risk than phishing in 2026?
Phishing still accounts for more reported incidents, but tailgating bypasses every digital control a company has, including firewalls and email filters. Both need dedicated training rather than treating physical security as an afterthought.
How often should tailgating drills run?
Run the first drill within 30 days of rolling out a badge policy and a second one 60 to 90 days later to check retention. Quarterly drills after that keep the habit from fading.
What should staff say when challenging a tailgater?
A simple, rehearsed line works best: 'I can't let you through without a badge, let me call your host.' Scripting the phrase in advance removes the hesitation that lets tailgating succeed.
Does new employee onboarding need a physical security module?
Yes, new hires are the highest-risk group because they don't yet recognise who belongs in the building. A 10-minute physical security module in week one closes that gap before bad habits form.
How do you report a tailgating incident without blaming a colleague?
Use a dedicated, anonymous-where-possible reporting channel separate from general HR, the same model used for phishing reports. Report volume should rise after a drill, which signals attention, not a worsening problem.
What happens with repeat tailgating incidents?
Two or more incidents from the same person within a 90-day window should trigger a direct one-on-one refresher rather than another group training email. Treating every incident the same regardless of frequency teaches high-risk staff that nothing changes.
One last thing
The loading dock, not the front door, is where most tailgating audits in 2026 find the actual gap, because everyone locks down the entrance staff see every day and forgets the one they don't.