What two climbers on the Empire State Building can teach us about physical security.
Two people climbed the Empire State Building today. They made it all the way up the antenna — 1,454 feet above Manhattan — hung a banner, got engaged at the top, and were eventually talked down by NYPD. No injuries. Charges pending.
The internet is running with the love story. And it’s a good one. But if you work in security, the detail that should stop you cold isn’t the ring. It’s the sentence a witness on the observation deck gave to reporters:
“I just assumed they were allowed up there.”
A building employee said essentially the same thing. The gates were open. Bystanders watched two masked people scale a restricted structure — one that carries the broadcast signal for a huge share of New York’s TV and radio — and nobody intervened. Not because the security was picked or bypassed, but because everyone in the vicinity quietly assumed someone else had already handled it.
That’s the whole story. And it’s the most common failure mode in the entire field.
The exploit was social, not technical
We tend to picture a breach as something loud and clever: a picked lock, a cloned badge, a hacked reader. Real-world intrusions are almost never that interesting. Far more often, someone gets waved in.
The tools are mundane and devastatingly effective:
• A high-visibility vest and a clipboard. Look like maintenance and most people will hold the door for you.
• Tailgating. Walk in close behind someone with a badge. Challenging a stranger to a secured door feels rude, so people don’t.
• Confidence. Move like you belong, and the social cost of stopping you falls on whoever considers doing it — so nobody does.
None of these require breaking anything. They exploit a human default: we treat the appearance of belonging as proof of belonging. The climbers didn’t defeat a control. They walked through a gap that everyone could see and nobody owned.
Why this gap keeps winning
Diffusion of responsibility is the quiet engine here. When lots of people can see a problem, each individual assumes another will act — so no one does. Add a plausible cover story (a vest, a badge lanyard, a purposeful walk) and the bystander’s brain resolves the ambiguity in the intruder’s favor. It’s easier, more comfortable, and socially safer to assume authorization than to challenge it.
Organizations spend enormous budgets on the technical layer — access control systems, cameras, badge readers — and comparatively little on the layer that actually gets tested in an intrusion: whether a real human being will stop a stranger and ask a hard question. A camera that records an unchallenged intruder is just a very expensive way to document your own breach.
The IT and physical security seam
This is precisely the seam where I focus at Calibre Security Group: the place where IT security and physical security meet — and where each side assumes the other has it covered.
The same “someone else must have handled it” logic that let two climbers reach a restricted antenna is what lets an attacker tailgate into a badge-controlled server room, plug into an open network port in an unattended conference room, or drop a rogue device behind a reception desk. The digital and physical threat models are not separate problems. They’re the same problem viewed from two angles, and the vulnerabilities live in the space between the teams that own them.
“I assumed they were allowed” is not a security policy. But it’s the policy a lot of organizations are running by default, whether they’ve written it down or not.
The uncomfortable question
So here’s the one worth sitting with: if someone confident, wearing the right vest, walked toward your restricted areas right now — would anyone stop them? Or would everyone assume someone else already had?
Could someone walk into your restricted areas just by looking the part? Let’s find out before someone else does.
