DataCentreNews India - Specialist news for cloud & data centre decision-makers
India
Zero Trust drives biometrics in physical access security

Zero Trust drives biometrics in physical access security

Mon, 3rd Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Organisations are applying Zero Trust principles to physical access security, according to Boon Edam Australia, as biometrics and layered entry controls become more widely used.

Mike Fisher, Managing Director at Boon Edam Australia, said the old assumption that people could be trusted once inside a site no longer fits current risk models. Identity, credentials and context now need to be checked repeatedly, whether someone is trying to enter a network or a building.

"Traditional security models often relied on a perimeter approach - once someone had passed through the front door, trust was largely assumed," Fisher said.

"Zero Trust changes that thinking. Every access decision needs to be verified, whether that access is to a digital system or a physical location."

This reflects a broader shift in how companies secure sensitive sites such as data centres, telecommunications facilities and government buildings. In these settings, physical access controls are increasingly treated as part of the same risk framework as cyber defences.

Fisher said organisations create a gap in their protections when they invest heavily in digital security but leave buildings or restricted rooms exposed to unauthorised entry. Cyber and physical security should be treated as connected issues rather than separate disciplines.

"Organisations are leaving a blind spot if they invest in the strongest digital security systems in place, but an unauthorised person can physically enter a facility and access critical assets," he said.

"Cybersecurity and physical security are increasingly two sides of the same challenge."

Biometric shift

Biometric identification has a long history in formal security systems, beginning with fingerprint use in criminal investigations in the late 19th century. More recently, it has become familiar to the public through phones, payment systems and other consumer devices that use face or fingerprint recognition.

Australia adopted biometric passports in 2005, using embedded chips containing personal information to help verify identity. Fisher said that familiarity has made biometric tools more acceptable in commercial and institutional settings where identity verification is critical.

"People are now familiar with using their face or fingerprint to unlock a device, make payments, or access information," he said.

"The security industry has taken those same principles and applied them to environments where identity verification is critical - including data centres, telecommunications facilities, government buildings and other high-value assets."

Biometric systems can include fingerprint recognition, facial recognition, iris and retina scanning, and hand geometry. Unlike cards, keys or passwords, they are tied directly to the physical characteristics of the individual seeking entry.

That distinction matters because conventional credentials can be borrowed, shared, stolen or lost. Fisher said biometrics create a stronger link between the person at the door and the identity approved for access.

"Credentials can be lost, stolen, or shared," he said.

"Biometric authentication provides a much stronger link between the person requesting access and the identity that has been authorised."

Layered entry

Fisher said biometric tools work best as part of a broader physical security design rather than as a single control on a standard door. Identity confirmation alone may not stop tailgating, where another person follows an authorised user through an opening.

"A biometric reader installed on a standard door can confirm identity, but it may not prevent someone else from following an authorised person through the opening," he said.

"That is why the physical entrance itself is so important. High-security portals combine identity verification with controlled movement, ensuring that only the authorised individual is permitted through."

Such systems can include mantrap portals, speed gates, standard access control systems and monitoring tools. The aim is to increase checks as the sensitivity of an area rises, creating several points where a person's identity and right to enter can be tested.

Fisher described this as the physical version of Zero Trust. Rather than relying on a single measure, organisations build multiple checks on the understanding that any one control could fail or be bypassed.

"Layered security is effectively the physical manifestation of Zero Trust principles," he said.

"Rather than relying on one security measure, organisations create multiple verification points, recognising that any individual control could potentially be bypassed."

In a typical portal arrangement, a user first presents a credential such as an access card. Additional systems then check that the person is alone and that the biometric data matches the identity linked to the credential.

"Dual authentication makes it significantly harder for someone to use another person's access credentials," he said.

"The system is not just asking 'does this person have the right card?' It is asking 'is this the right person using that credential?'"

Boon Edam Australia also referred to three-dimensional detection systems that assess movement, shape and volume to identify piggybacking attempts involving more than one person. These tools are designed to work without being affected by lighting or reflections.

Beyond restricted sites

Fisher said biometric security is not limited to highly restricted sites. Medium-security settings such as office buildings can also use the technology to tighten access control while keeping movement through entrances quick and straightforward.

"Biometrics are not only for hyperscale data centres or highly sensitive locations," he said.

"They can provide significant benefits in medium-security environments, such as office buildings, where organisations need secure access without compromising convenience or user experience."

He added that organisations need systems that can expand or adapt as threats change and facilities grow.

"For organisations with critical assets to protect, the future of security will be built around continuous verification, intelligent technology, and a layered approach that combines people, processes and physical solutions."