> be me
> first time going onsite for a high-assurance financial & physical security audit
> logical side is heavy: HSMs, cryptographic keys, air-gapped zones, Zero Trust
> time to walk the floor for the physical compliance checklist
> "Are badge readers installed?" [x] Yes
> "Are secure doors locked?" [x] Yes
> "Are visitor logs kept?" [x] Yes
> Everything checked out. 100% compliant on paper.
> but my IoT/hardware hacker brain couldn't rest
> walking the floor, I'm not seeing checkboxes, I'm seeing attack surface
> standard compliance will only asks if a lock exists or a badge is issued
> it never asks how that hardware behaves under 45 seconds of someone actually trying to get past it
> a facility can pass every line on the checklist and still fold to a ₦15,000 RF cloner or a door left a few mm out of true
> compliance would only measures whether the hardware exists on paper
> so I've been spending my evenings building APCAF - Adversarial Physical Control Assessment Framework
> MITRE ATT&CK for physical & hardware-layer security
> quick, non-invasive site checks.
Check out what I'm building:
🔗