Cybersecurity at the Physical Layer

Cybersecurity controls extend beyond firewalls and software. Comms-room access, patching, cable identification and documented network outlets all affect how easily an unauthorised device can reach the network. Physical controls should support, not replace, logical segmentation and security monitoring.

By Wayne Connors·Managing Director, ACCL·Published 9 July 2026·6 min read
BICSI member Fluke DSX test evidence 28+ years trading London, Kent and the South East
In brief
  • Physical security, logical segmentation and configuration control work together.
  • DSX certification verifies cabling performance and identity; VLAN configuration must be verified separately in the network environment.
  • Dedicated cabling or switching may be appropriate for higher-risk systems, but only after a proportionate risk assessment.

The threat that software cannot solve

Most cybersecurity conversations in commercial buildings focus on firewalls, endpoint protection, SIEM platforms and zero-trust architecture. These are all important. But there is a layer beneath all of them that is rarely discussed in a security context, and it is the layer that a determined attacker will look for first: the physical network.

If an attacker can physically connect to your network infrastructure, tapping a cable run in a ceiling void, plugging into an unsecured patch panel port, accessing a comms room that was left unlocked, the software security stack becomes significantly easier to circumvent. Physical layer security is not an alternative to software security. It is the foundation on which everything else sits.

Structured cabling design contributes to security by making physical connections controlled, traceable and easier to audit.

Physical layer security is not an alternative to software security. It is the foundation on which everything else sits.

How AI systems change the attack surface

The deployment of AI in commercial buildings substantially increases the physical attack surface. Every AI-powered device, a CCTV camera with on-board analytics, an occupancy sensor feeding a building management system, an AI-managed Wi-Fi access point, an edge compute node in a comms room, is a physical network endpoint. Each one is a potential entry point to the network if it is not physically secured and logically isolated.

The risk is not theoretical. A compromised IP camera on the same network segment as business workstations provides lateral movement opportunities. A malicious device plugged into an unmonitored patch panel port can capture traffic, inject packets, or establish a persistent foothold. An AI building management system connected to the corporate LAN creates a bridge between operational technology (OT) and IT networks that did not exist in older analogue building systems.

Physical separation, such as dedicated cabling or switching for a higher-risk system, can provide additional assurance where a risk assessment justifies it. It does not remove the need for secure configuration, access control, monitoring and patch management.

A VLAN is a logical boundary. Dedicated physical infrastructure can add another control, but it should be selected according to the data, threat model, operational impact and regulatory context rather than treated as a universal requirement for AI systems.

VLAN architecture and the cabling contractor’s role

Virtual LANs (VLANs) are the standard mechanism for segmenting a network logically, separating corporate data traffic from IoT devices, guest Wi-Fi from staff Wi-Fi, AI surveillance systems from general business systems. VLANs are effective and essential. But they are implemented in switch firmware, and switch firmware can be misconfigured, exploited, or bypassed by an attacker with physical access to the network.

The cabling contractor’s role in VLAN security is often overlooked. VLAN design only works if the physical cabling correctly routes each device to the right switch port, patch panel port and logical segment. A cabling error that connects a CCTV camera to the wrong patch panel row can inadvertently place it on the corporate network segment. A poorly documented comms room makes this kind of error invisible for months or years.

ACCL can align outlet, panel and cable identifiers with the agreed network design. TIA-606-style labelling and Fluke DSX certification provide an auditable record of cable identity and physical performance. VLAN and switch-port configuration must be verified separately through the switching or network-management environment.

Key point

Physical layer security is not an alternative to software security. It is the foundation on which everything else sits.

Physical separation for AI systems: when and how

For many commercial buildings, VLAN segmentation across shared cabling is appropriate when it is correctly designed, configured and monitored. Dedicated physical infrastructure may be considered where the consequence of compromise, operational requirements or assurance needs justify the additional cost.

  • AI-powered CCTV and access control systems in environments handling sensitive data, legal, financial, healthcare, government
  • Edge compute nodes running AI inference on business-critical processes
  • Building management systems controlling physical access, power distribution or environmental controls
  • Any network segment where a breach would have regulatory consequences, GDPR, FCA, NHS DSP Toolkit

Physical separation means dedicated cable runs, dedicated switch hardware, and in some cases dedicated comms room infrastructure. The cost is higher than a shared physical plant. The risk reduction is substantially higher still.

The comms room as a security perimeter

The comms room is the most physically sensitive space in a network infrastructure. All cable runs terminate here. All switches, patch panels and servers are here. Unrestricted physical access to the comms room is effectively unrestricted access to the network.

ACCL can coordinate access-controlled comms rooms and auditable entry systems where these controls form part of the agreed security design. The access-control platform should be selected to suit the client’s estate, governance and support arrangements.

Documentation as a security tool

A structured cabling installation without complete, accurate documentation is a security liability. Unknown cable runs, unlabelled ports and undocumented connections are the physical equivalent of shadow IT. An attacker who understands your building’s layout can exploit undocumented network access points that your IT team does not know exist.

Where included in the agreed scope, ACCL provides cable and port labelling, link certification and as-built documentation. These records support asset control and investigation, but they should be maintained alongside switch configurations, access logs and change records.

Standards and sources

Frequently asked questions

What is physical layer security in a commercial network?

Physical layer security refers to the measures taken to protect the physical cabling infrastructure, comms rooms and network access points from unauthorised access. It includes physically separate cable runs for sensitive network segments, access-controlled comms rooms, comprehensive cable documentation, and asset labelling that makes every network connection traceable and auditable. Physical layer security is the foundation on which software-based security measures, firewalls, VLANs, endpoint protection, operate.

Are VLANs sufficient to isolate AI systems from corporate networks?

VLANs are an established method of logical segmentation and are suitable for many environments when they are correctly configured, controlled and monitored. Dedicated cabling or switching can add assurance for higher-risk systems, but it is not automatically required because a system uses AI. The decision should follow the organisation’s risk assessment and security architecture.

Why does the cabling contractor matter for network security?

The cabling contractor controls how outlets, panels and pathways are installed, identified and documented. Good records make unauthorised or unexpected connections easier to detect. Cable certification verifies physical performance, while the IT team must separately control switch ports, VLANs, authentication and monitoring.

Should AI CCTV and access control systems be on a separate network?

CCTV and access-control systems should normally be segmented from general user traffic. This may be achieved with dedicated VLANs and security controls, or with physically separate infrastructure where the risk assessment requires stronger isolation. The appropriate design depends on the system, data, operational impact and client policy.

Find out if your infrastructure is ready

A scoped physical layer audit establishes what the existing infrastructure can support, what needs attention and what should be budgeted before dependent systems are specified.

0333 900 0101