What happened: The man spent 45 minutes in the server room with your junior IT staff member present. He connected a laptop, took photos of rack configurations, and reviewed server labels. He said everything looked routine and left. Six days later, Meridian Capital's threat intelligence feed flagged exfiltration of customer data from a server the individual had accessed. Your IT team pulled the visitor access logs — the man was never scheduled. You called your Grant & Associates liaison: no one from their firm had visited Meridian Capital that day, or any day that week.
The attack: The individual had researched your active audit engagement from public records and prepared a convincing pretext. Physical presence, a business card, a clipboard, and the social pressure of having "waited 20 minutes" bypassed your access control protocol entirely.
// WHAT WENT WRONG
• No credential verification — a business card and lanyard are not access credentials
• No appointment confirmation — "the calendar invite probably didn't go through" was accepted as an explanation
• Urgency and social pressure ("he's been waiting 20 minutes") overrode normal access protocol
• Escorted access was assumed to be safe — but the escort was a junior staff member who had no authority to refuse requests once inside
Correct action: The correct response was to request verification before granting any access: ask your assistant to request the individual's ID and call Grant & Associates' main number from your records — not from his business card. Verification takes 10 minutes. Server room access cannot be un-granted.