Tailgating — following an authorised person through a controlled door without badgeing — remains one of the simplest ways into an office, warehouse or secure facility. Training staff to prevent it is a behaviour design problem: give people a clear challenge script, rehearse it under social pressure, and back it with process so politeness does not override policy.
Key takeaways
- Teach a short verbal challenge script staff can use without escalating conflict.
- Rehearse door, lift and loading-dock scenarios; slides alone do not build muscle memory.
- Cover contractors, cleaners and visitors in the same programme as permanent staff.
- Pair physical drills with digital awareness — attackers often combine both.
- Measure challenge attempts and near-miss reports, not only course completion.
Why this matters
Physical access controls only work when humans enforce them. A turnstile, mantrap or locked door fails the moment someone holds it open for a stranger with a clipboard, a delivery badge or a friendly smile. CISA describes social engineering as attackers using human interaction to obtain or compromise information — and the same pattern applies at the door: an unassuming person claims to be a new hire, a vendor or a researcher, then rides in on trust.
CISA’s physical-security guidance for devices also stresses locked areas, limited access and not leaving equipment unattended. The same discipline applies to people flow. Once someone is past reception, lateral movement — to a meeting room, a print station or an unattended laptop — becomes far easier. Training is how you make badge policy stick across shifts and sites.
Who this is for
This guide is for facilities, security and people leaders in offices, warehouses, clinics, campuses and multi-tenant buildings. If staff badge through controlled doors or escort visitors, the steps below apply.
What you will need
- A written access and visitor policy with a one-line challenge expectation
- A short Ideal Script staff will actually say (see step 2)
- Manager cover for a 30-day pilot on one floor or site
- A way to log near-misses and successful challenges without blame
- Optional: short modules in your security awareness training catalogue and phishing simulations for the digital half of the attack
- Four weeks for design, pilot and first tune-up
The steps
1. Write the rule in one sentence
State the non-negotiable: every person must badge their own entry; holding a door for an unknown person is not allowed; visitors go via reception or a booked escort. Put it on the induction pack and the wall by the main door.
Expected outcome: a one-sentence rule managers can repeat in stand-ups.
Common mistake: a three-page policy nobody has opened since fit-out.
2. Design a challenge script people can say out loud
Give staff words that stay polite and firm. Example: “I need you to badge in at reception — I cannot swipe you through.” Practise tone. The goal is a repeatable line, not a confrontation course.
Expected outcome: a script on a wallet card and in the LMS module.
Common mistake: telling people to “challenge strangers” with no words to use.
3. Map the failure points on your floor plate
Walk the site: main lobby, side doors, car park fire exits, loading dock, multi-tenant lifts, smoker’s courtyard returns. Note where people naturally hold doors. Those spots become drill locations.
Expected outcome: a one-page map of high-risk doors.
Common mistake: training only on the glamorous front entrance.
4. Run short scenario drills, not only e-learning
Use five-minute stand-up drills: hold-the-door request, fake delivery, “I forgot my badge,” visitor without escort. Rotate who plays the outsider. Follow with a two-minute debrief. E-learning alone rarely survives real social pressure.
Expected outcome: every team on the pilot floor completes at least one live drill in 30 days.
Common mistake: a yearly video with a smiling actor and no floor practice.
5. Include contractors, cleaners and temporary badges
Many breaches involve people who are not on the permanent payroll. Enrol short-tenure badges in the same physical module before or on first issue. Brief cleaning and facilities partners in writing.
Expected outcome: contractor induction checklist includes the challenge script.
Common mistake: training only corporate email accounts.
6. Make reporting safe and useful
Create a no-blame channel (form, chat alias or facilities ticket) for “I was tailgated” and “I challenged someone.” Review weekly. Fix broken closers and sticky locks that force people to prop doors.
Expected outcome: near-miss log with at least a handful of entries in month one — silence usually means fear, not perfection.
Common mistake: punishing the person who reports a successful tailgate.
7. Pair physical drills with digital awareness
Attackers who walk in may also phish reception for a visitor list or the help desk for a temporary account. Keep phishing simulations and short security awareness training running in parallel, and show combined risk in human risk reporting.
Expected outcome: one monthly view that includes both door near-misses and phish report rates.
Common mistake: treating facilities security and cyber awareness as unrelated programmes.
Troubleshooting
Staff say challenging feels rude. Role-play with managers first so leaders model the script. Politeness to attackers is not a corporate value.
Doors are propped for air flow or deliveries. Fix the environment — air, dock process, temporary holds — before blaming people.
Multi-tenant lifts dump strangers on your floor. Add a secondary badge line or reception intercept; train floor wardens on lift lobby challenges.
Executives expect exceptions. Get sponsor language that the rule applies to everyone, including leaders walking in with guests.
No one logs near-misses. Start with anonymous options and celebrate one good catch in the all-hands.
Tools and resources
- One-sentence access rule and wallet-card script
- Floor map of high-risk doors
- Short physical-security module in your awareness catalogue
- Near-miss form and weekly 15-minute review
- CISA guidance on social engineering and physical security of devices
- ACSC Essential Eight as complementary technical hygiene for Australian environments
What to do next
Once the pilot floor holds the script, expand site by site and fold tailgating into contractor onboarding. Connect the programme to how to reduce business email compromise risk with staff training and human risk reporting so physical and digital social engineering share one scorecard.
FAQ
What is tailgating in physical security?
Tailgating is when an unauthorised person follows an authorised person through a controlled entry point without presenting their own credentials. It is a social engineering technique that exploits politeness and haste.
How do you train staff to stop tailgating?
Give a clear one-sentence rule, a spoken challenge script, short live drills at real doors, contractor coverage, and a no-blame way to report near-misses. E-learning alone is not enough.
What should staff say when someone asks to be let through?
A simple line works: “I need you to badge in at reception — I cannot swipe you through.” Practise it until it feels normal.
Should cleaners and contractors get the same training?
Yes for the physical and visitor modules. Temporary badges are a common weak point when only permanent staff are trained.
How often should tailgating drills run?
At hire, then at least two live drills per year per site, with a short refresh after any incident or fit-out change.
Does tailgating training replace access control hardware?
No. Hardware and logs still matter. Training is how you stop authorised humans from defeating those controls for strangers.
What if someone has already tailgated in?
Do not badge them deeper. Escort them to reception or security, report the event, and review CCTV or badge logs. Speed beats blame.
One last thing
The friendliest person at the door is sometimes the test. If your training never gives staff a practised line for refusing a door-hold, every lock on the floor is waiting on luck.