Tailgating and Piggybacking: The 2026 Threat Intelligence Briefing on the Access-Control Blind Spot, the NIST Vestibule Standard, and the Badge-to-Body Reconciliation Layer
Home / Intelligence / Tailgating and Piggybacking: The 2026 Threat...
Threat Intelligence

Tailgating and Piggybacking: The 2026 Threat Intelligence Briefing on the Access-Control Blind Spot, the NIST Vestibule Standard, and the Badge-to-Body Reconciliation Layer

How tailgating and piggybacking defeat the credential layer, what NIST PE-3(8) already requires, and the AI badge-to-body reconciliation layer that turns an unaccounted-for entry into a real-time alert.

Published June 2026
Read Time 14 min read
Stream Threat Intelligence
~9%
of successful breaches since 2020 involved a physical security compromise (IBM 2025)
71%
of security professionals call a tailgating breach likely to very likely (Boon Edam survey)
241 days
mean time to identify and contain a breach in 2025 (IBM 2025)

Tailgating is the most preventable breach in physical security and the hardest one for a badge reader to see. Three numbers frame why the credential layer keeps failing at the door.

~9%of successful breaches since 2020 involved a physical security compromise, per the IBM 2025 Cost of a Data Breach Report
71%of security professionals call a tailgating breach likely to very likely at their facility (Boon Edam survey of 188 end users)
241 daysmean time to identify and contain a breach in 2025, the window an unaccounted-for entry hides inside (IBM 2025)

Every access control system makes the same quiet assumption: one credential, one person. A badge taps, a door unlocks, one authorized individual walks through. Tailgating breaks that assumption at the exact moment it matters, when a second person follows through the same open door without ever presenting a credential. The reader logged one entry. Two people are now inside. The system has no record of the second, no way to revoke their access, and no way to tell anyone they are there.

This briefing is a threat-intelligence analysis of tailgating and piggybacking as a physical-access failure mode: how the credential layer is structurally blind to it, what the federal control frameworks already say about it, why the conventional countermeasures do not scale, and where AI video analytics close the gap between the door event and the human record. It is written for security directors, facility operators, and risk leaders who already own access control and cameras, and who need to understand why owning both has not solved the problem at the door. The throughline is the one IntelliSee applies across every detection modality: real-time analysis on the cameras a facility already runs.

Real IntelliSee trespassing detection output showing a bounding box on a person crossing a monitored perimeter zone, confidence score visible
LIVE CAM-07 · CONTROLLED ENTRY
Actual IntelliSee detection output. A person identified crossing a monitored access zone, bounded and scored by the platform's computer vision model. This is the visual layer a badge reader cannot supply: the door logs a credential event, while the camera records who actually moved through the threshold. No facial recognition. No stored video. The detection routes to security dispatch in real time so an unaccounted-for entry becomes an alert within seconds rather than a forensic discovery weeks later.

What tailgating and piggybacking actually are, and why the distinction matters operationally

Tailgating and piggybacking are two versions of the same outcome with different mechanics, and the difference decides which countermeasures work. Tailgating occurs when an unauthorized person follows an authorized individual through a controlled entry without that person's knowledge or cooperation, slipping through before the door closes. Piggybacking is the cooperative version: the authorized person holds the door, waves the follower through, or otherwise consents to the entry, usually out of courtesy. The U.S. Cybersecurity and Infrastructure Security Agency classifies piggybacking through a secure entrance point as a negligent insider-threat behavior, a category CISA defines as insiders who are familiar with security policy but choose to ignore it.

The operational consequence of the distinction is straightforward. A technical control that physically enforces single-person passage, an interlocking vestibule, stops both. An awareness control, signage and training, only addresses piggybacking, because tailgating depends on the authorized person never noticing. Most facilities deploy awareness controls and then act surprised when the breach rate does not move. They have addressed the polite version of the problem and left the stealth version untouched.

The reason both versions matter to a threat analyst is the same reason CISA flags it: the entry creates an unattributed presence. When an organization cannot account for who is inside its facility, it has lost the ability to control what those individuals can access, move, photograph, or remove. The breach is not the open door. The breach is the gap in the record that follows from it, the same structural blindness IntelliSee analyzes in its insider threat and former-employee violence briefing, where the threat actor is precisely the person the access system was never designed to flag.

Why the credential layer is structurally blind to the second person

Access control was designed to answer one question: is this credential authorized for this door at this time. It answers that question well. It was never designed to answer a second question, how many people walked through after the door opened, and most installed systems have no sensor capable of answering it.

Consider what a standard card reader and electric strike actually perceive. The reader detects a valid credential. The controller energizes the strike. The door opens. From that point until the door closes and relatches, the system is blind. It does not count bodies. It does not distinguish one person from three. The door position sensor, where one exists, reports only open or closed. The access log will record a single authorized entry no matter how many people passed through, which means the record itself is wrong, not incomplete but affirmatively misleading. An investigator pulling that log after an incident sees one entry and has no signal that anything is amiss.

This is why tailgating is so durable as a failure mode. It does not defeat the credential. It operates in the interval the credential layer cannot see, the seconds between unlock and relatch. Every other access control improvement, stronger credentials, multi-factor authentication at the door, anti-passback rules, hardens the credential check itself. None of them address the interval. A facility can deploy the most sophisticated badge system on the market and remain completely exposed to the person who simply walks in behind someone who used one.

The Anti-Passback Illusion

Why a logical control cannot close a physical gap

Anti-passback is the access control feature most often cited as a tailgating defense. It prevents a credential from being used to enter twice without an intervening exit, which stops a cardholder from badging in and then passing the card back out a window to a second person. It is a real control against credential sharing. It does nothing about tailgating, because the tailgater never touches a credential at all. Anti-passback governs the logical use of a badge; tailgating happens in the physical space the badge logic never observes. Treating the two as interchangeable is one of the most common reasons a security program believes it has solved a problem it has not touched.

What the control frameworks already require, and the gap between the standard and the door

Tailgating is not an emerging or speculative threat in the standards literature. It is named explicitly in the federal control catalog. NIST Special Publication 800-53 Revision 5 includes control PE-3(8), Access Control Vestibules, whose supporting guidance states that vestibules are designed to prevent unauthorized individuals from following authorized individuals into facilities with controlled access, an activity it names directly as piggybacking or tailgating that results in unauthorized access. The control statement instructs organizations to employ access control vestibules at organization-defined locations, and the supplemental guidance describes interlocking door controllers used to limit the number of individuals entering at a controlled point.

The framework, in other words, already treats tailgating as a recognized hazard with a defined engineering countermeasure. The gap is not in the standard. It is in the distance between what the standard specifies and what a facility can physically build at every door. A vestibule, often called a mantrap, is two interlocking doors with a containment space between them; the outer door must close and lock before the inner door will unlock, and occupancy sensing holds both doors if more than one person is detected inside. It is the most effective physical countermeasure that exists, and at a sensitive perimeter it is the right answer.

It is also expensive, slow, and architecturally invasive. A vestibule consumes floor space, throttles throughput to one person per cycle, and cannot be retrofitted into most existing doorways without construction. A hospital cannot put a mantrap on every ward door. A corporate campus cannot vestibule every stairwell and loading entrance. The control that the framework recommends is viable at the handful of highest-consequence portals and impractical at the dozens or hundreds of secondary doors where tailgating actually happens most often. This is the structural tension at the center of the tailgating problem: the strongest countermeasure does not scale, and the scalable countermeasures are weak.

The countermeasure gap: why the scalable defenses do not hold

Between the unaffordable strong control and the open door sits a tier of countermeasures that facilities actually deploy at scale. Each one addresses part of the problem and leaves a characteristic gap. Understanding those gaps is the analytic core of the tailgating threat surface.

Tailgating Countermeasures and Their Characteristic Failure Mode

CountermeasureWhat It DoesWhere It Fails
Awareness and signageAsks cardholders not to hold doors and to challenge unknown followersAddresses cooperative piggybacking only. Cannot stop stealth tailgating, and challenge culture erodes within weeks of a campaign ending
Anti-passback rulesBlocks reuse of a credential without an intervening exitGoverns credential logic, not physical passage. The tailgater never presents a credential, so the rule never engages
Door position and held-open alarmsAlerts when a door stays open past a thresholdA tailgater passes through in the normal open-and-close cycle, well under any held-open threshold. No alarm fires
Optical turnstilesMechanically resist a second body at speed lanes in lobbiesDefeated by close-following and jump-overs, and impractical at side doors, loading docks, and stairwells where most tailgating occurs
Access control vestibule (mantrap)Physically enforces single-person passage with interlocking doors per NIST PE-3(8)The strongest control, but costly, throughput-limiting, and not retrofittable at scale across secondary doors
AI video analyticsCounts people through the door and correlates the count to the access event in real timeDepends on camera placement and field of view; a layer over the gap rather than a physical barrier, but scales across every door a camera already covers

Read down the failure-mode column and a pattern emerges. The cheap controls fail because they rely on human attention or address the wrong mechanism. The strong control fails because it cannot scale. Every option in the middle leaves the same residual exposure: a door that a camera can see but that no system is actively counting people through. That residual is exactly the surface AI video analytics is built to cover, not by replacing the door hardware but by adding the count the access log was never able to record.

How AI video analytics closes the door-to-record gap

The tailgating problem reduces to a single missing data point: the access log records one entry, and no system records how many people that one unlock actually admitted. AI video analytics supplies that missing number by analyzing the camera feed the facility already runs at the door, counting the people who cross the threshold during an entry event, and correlating that count against the access control system's record of credentials presented.

The mechanism is detection, not recognition. A computer vision model trained to detect and track people identifies each individual crossing a defined zone at the doorway and counts them. When the count of people through the door exceeds the count of credentials presented in the same window, the system has detected a discrepancy: more bodies than badges. That discrepancy is the tailgating event, and it can be flagged as an alert in real time rather than reconstructed from footage after an investigation begins. Crucially, this is object-level and motion-level analysis. It detects that a person crossed the threshold; it does not compute who that person is. There is no facial recognition, no biometric template, no identity match, the same privacy-by-design architecture IntelliSee applies across its platform and documents in its multi-camera tracking technology briefing, where subjects are followed across a camera network by appearance and motion rather than by face.

Badge-to-Body Reconciliation

How AI turns one unlock into a verified head count

What happens at a controlled door the moment a credential is presented and a second person follows.

T + 0s
Credential Presented

Card reader logs one authorized entry. Door strike releases. Access log expects one person through.

T + <1s
Threshold Watched

Existing camera covering the door captures the entry zone. No new hardware at the edge.

T + ~2s
People Counted

CV model detects and counts each person crossing the doorway zone. Two bodies tracked through one unlock.

T + ~3s
Discrepancy Flagged

Bodies through door exceed credentials presented. The mismatch is the tailgating event.

T + <30s
Alert Dispatched

Security console notified with door, time, and clip context for live verification and response.

Two design properties make this an operationally useful control rather than a noise generator. First, the analysis runs against the camera infrastructure a facility already owns, so it extends to every door a camera covers without per-door hardware. Second, because it produces a real-time alert tied to a specific door and time, it converts tailgating from a forensic finding into a live event a responder can act on while the unaccounted-for person is still near the entry. The 241-day mean breach dwell time that IBM reports is, in part, a function of breaches no one detected at the point of entry. A door-level discrepancy alert attacks that dwell time at its source.

The tailgating threat surface across facility types

Tailgating is not uniform. The motive, the consequence, and the right detection posture change with the environment. A threat analyst evaluating exposure should map the surface to the facility rather than treating tailgating as a single generic risk.

Data Centers and Critical Infrastructure

The highest-consequence environment. A single unauthorized entry into a server hall can mean physical access to hardware, theft, or sabotage, and the IBM data shows physical compromise is a real and costly breach vector. These facilities typically justify vestibules at the primary perimeter, but loading docks, mechanical rooms, and inter-suite doors remain tailgating exposure points where camera-based counting is the practical layer. See the data center sector playbook for the full threat model.

Healthcare Facilities

Infant-care units, behavioral health wards, pharmacy and controlled-substance storage, and clinical corridors all gate on access control that staff routinely hold open for colleagues carrying equipment or pushing beds. Courtesy piggybacking is endemic and clinically rational, which makes awareness controls especially weak here. Door-level counting that does not compute patient or staff identity fits the privacy constraints of the environment.

Corporate and Commercial Real Estate

Lobby turnstiles handle the front door; the exposure migrates to stairwells, parking-level entries, and freight elevators. Social engineering, the follower carrying coffee or a delivery box who counts on courtesy, targets exactly the doors with no turnstile. The mismatch alert is the only scalable record of who actually entered beyond the staffed lobby line.

Manufacturing and Distribution

High personnel throughput, frequent shift changes, and large bay doors make single-person enforcement impractical and tailgating routine. The risk concentrates at the transition between public yard and secured production or inventory space, where an unaccounted entry can precede theft or a safety event. Camera-based counting scales across the many secondary doors a plant cannot vestibule.

Across all four, the common structure holds: a small number of portals warrant a physical barrier, and a much larger number of doors warrant a detection layer over the existing camera. The analytic mistake is to secure the front entrance, declare the problem solved, and leave the side doors counting on courtesy. Tailgating concentrates precisely where the strong control was too expensive to install.

Building tailgating into a physical-access risk program

Tailgating belongs in the same risk register as forced entry and credential compromise, and it should be assessed door by door rather than facility-wide. A defensible program treats the threat as a layered control problem: physical barriers where consequence is highest, detection coverage everywhere a camera already looks, and awareness as the thin top layer it actually is rather than the primary defense it is often mistaken for.

The sequence that works in practice starts with classification. Rate each controlled portal by the consequence of an unauthorized entry behind it, and by the volume of legitimate traffic through it. High-consequence, low-volume portals, a data hall, an infant unit, a vault, are vestibule candidates where the throughput penalty is acceptable. High-volume portals, where a vestibule would create unworkable congestion, are where AI video analytics earns its place, supplying the count the access log cannot. The integration that closes the loop is the correlation between the door's access event and the camera's body count, which is why tailgating detection sits naturally alongside the broader perimeter control and unauthorized-access detection a facility already runs, and upstream of the response workflows it has already built.

Two cautions keep the program honest. Detection is a layer, not a barrier; it tells you a tailgating event occurred and lets a responder act, but it does not physically stop the entry the way a vestibule does, so the highest-consequence portals still warrant the physical control. And detection quality depends on camera placement and field of view at the threshold; a program that bolts analytics onto cameras aimed at the wrong angle will under-count and lose trust. Treated with those constraints in mind, the badge-to-body reconciliation layer turns the most preventable breach in physical security into one the facility can finally see, which is the same proactive posture IntelliSee details in its perimeter intrusion briefing on the narrow window that decides a security outcome.

Frequently asked questions about tailgating and AI detection

What is the difference between tailgating and piggybacking in physical security?

Tailgating is when an unauthorized person follows an authorized individual through a controlled door without that person's knowledge, slipping in before the door closes. Piggybacking is the cooperative version, where the authorized person knowingly holds the door or waves the follower through, usually as a courtesy. The distinction matters because awareness and signage can reduce piggybacking but cannot stop tailgating, which depends on the authorized person never noticing the follower.

Why can't a badge reader or access control system detect tailgating on its own?

A card reader and door strike are designed to verify a credential and release a lock. They have no sensor that counts how many people pass through during the open-and-close cycle, so the access log records a single authorized entry regardless of how many bodies actually went through. Tailgating happens in the interval between unlock and relatch, which is precisely the interval the credential layer cannot observe. The log is not just incomplete; it affirmatively shows one entry when two or more occurred.

Does anti-passback prevent tailgating?

No. Anti-passback prevents a single credential from being used to enter twice without an intervening exit, which stops credential sharing. It does nothing against tailgating because the tailgater never presents a credential at all. Anti-passback governs the logical use of a badge; tailgating occurs in the physical space the badge logic never observes. The two are frequently confused, which leads programs to believe they have addressed a threat they have not touched.

How does AI video analytics detect a tailgating event?

A computer vision model analyzes the camera feed already covering a controlled door, detects and counts each person crossing the doorway zone, and compares that count against the number of credentials presented in the same window. When more bodies pass through than badges were used, the system flags the discrepancy as a tailgating event in real time. It detects that a person crossed the threshold without computing who that person is, so there is no facial recognition involved.

Does tailgating detection require facial recognition?

No. The detection is object-level and motion-level: the model identifies and counts people crossing a defined zone. It does not build a biometric template, match a face, or determine identity. IntelliSee performs detection based on what is happening at the door, not who is present, which is what allows the capability to be deployed in privacy-sensitive environments such as healthcare and behavioral health units without introducing an identity-matching layer.

Is a security vestibule or mantrap still necessary if we deploy AI detection?

For the highest-consequence portals, yes. A vestibule physically enforces single-person passage and stops the entry; AI detection alerts that a tailgating event occurred and lets a responder act, but it does not physically block the door. The practical model is layered: vestibules at the small number of high-consequence, low-traffic portals where NIST PE-3(8) is justified, and AI video analytics across the much larger number of doors where a vestibule is impractical but a camera already exists.

Where does tailgating pose the greatest risk?

The consequence is highest in data centers and critical infrastructure, where a single unauthorized entry can mean access to hardware. The frequency is highest wherever legitimate traffic and courtesy culture are dense, such as healthcare corridors, corporate stairwells and freight entries, and manufacturing shift-change doors. The common pattern is that organizations secure the primary entrance and leave secondary doors relying on awareness, which is exactly where tailgating concentrates.

Continue the research

This briefing covers tailgating as a physical-access failure mode and the detection layer that closes it. For deeper reading on adjacent pieces of the threat surface:

Primary and authoritative sources cited in this briefing: NIST SP 800-53 Rev. 5, control PE-3(8) Access Control Vestibules; CISA, Defining Insider Threats; IBM Cost of a Data Breach Report 2025.

Request a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment