Tailgating is one of the oldest and simplest physical security attacks: an unauthorised person follows an authorised person through a controlled door. It requires no technical skill, no specialist equipment, and no exploitation of a software vulnerability. It exploits something far harder to patch — human politeness.
What tailgating is
Tailgating (sometimes called piggybacking) occurs when an attacker gains physical access to a restricted area by following closely behind someone who has legitimate access. The authorised person badges in, opens the door, and the attacker walks through behind them — often without the authorised person even realising what has happened.
The distinction between tailgating and piggybacking is sometimes drawn as follows:
- Tailgating: The authorised person is unaware that someone has followed them through.
- Piggybacking: The authorised person knowingly allows the other person through, usually out of politeness or the assumption that they belong.
In practice, both achieve the same result: an unauthorised person inside a controlled area.
Why it works
Tailgating is effective because it exploits deeply ingrained social behaviours:
Holding the door. In most cultures, holding a door open for someone behind you is automatic. It is considered rude not to. An attacker who times their approach to arrive at a door just as someone else is going through will almost always benefit from this reflex.
Assumed belonging. If someone looks like they belong — they are dressed appropriately, carrying a laptop bag, walking with purpose — most people will not question their presence. The assumption is that if they are here, they must have a reason to be.
Conflict avoidance. Challenging a stranger requires a degree of confrontation that most people find uncomfortable. Even security-aware employees may hesitate to ask “excuse me, do you have a badge?” because it feels impolite or confrontational.
Group entry. When a group of employees enters a building together — at the start of the day, after a fire drill, returning from lunch — individual badge scans are often skipped. Doors are held open, people stream through, and the access control system registers only the first person’s badge.
Common tailgating scenarios
Tailgating can happen at any controlled entry point, but certain situations are particularly vulnerable.
Main entrance during peak times. The morning rush, lunchtime, and end of day are high-traffic periods when doors are opened frequently and staff are focused on getting where they need to be, not on who is behind them.
Smoking areas and side doors. Employees stepping out for a cigarette often use side doors that they prop open or hold for others returning. These doors may lack the active reception oversight that the main entrance has.
Loading bays and service entrances. Delivery and service entrances are designed for throughput, not individual authentication. An attacker carrying a box or wearing a high-visibility vest can blend in with legitimate deliveries.
After-hours access. A single employee entering the building in the evening may hold the door for someone arriving behind them without a second thought, particularly if the other person seems to be in a rush.
Stairwells and internal doors. Even once inside the building, controlled doors between floors or zones can be tailgated in the same way.
Tailgating as part of a security assessment
Tailgating is a standard technique in both physical penetration testing and social engineering assessments. During a test, the assessor will:
- Observe the target building to identify the highest-probability entry points and the times when tailgating is most likely to succeed.
- Prepare a persona that fits the environment: business attire for a corporate office, a high-vis vest for a warehouse, a lanyard with a generic badge for a multi-tenant building.
- Attempt entry by timing their approach to coincide with a legitimate employee. The assessor notes whether they were challenged, whether the door had anti-tailgating features, and how far into the building they were able to travel.
- Document everything. Photographs, timestamps, the entry point used, and whether anyone challenged them. This evidence feeds into the report.
The results often demonstrate that tailgating is trivially easy, even at organisations that consider their physical security to be strong.
Defending against tailgating
Effective defence requires a combination of physical controls, technology, and culture.
Physical controls
Mantraps and turnstiles. A mantrap (airlock) allows only one person to pass at a time — the first door must close before the second opens. Turnstiles and speed gates achieve a similar effect in higher-throughput environments, ensuring each person individually authenticates.
Revolving doors with anti-tailgating sensors. Sensor-equipped revolving doors detect when more than one person is in the compartment and can lock or alarm.
Separate entry and exit. Designing entry points so that inbound and outbound traffic are separated reduces the opportunity for tailgating through doors held open by departing employees.
Technology
Anti-tailgating detection. Sensors (infrared, weight-based, or camera-based) can detect when multiple people pass through a controlled door on a single badge scan. These systems can trigger an alarm, lock a subsequent door, or notify security.
Badge-in, badge-out. Requiring a badge scan both on entry and exit (anti-passback) creates accountability and makes it easier to identify when tailgating has occurred.
CCTV at entry points. Cameras at controlled doors, reviewed in real time or triggered by anti-tailgating alerts, provide evidence and deterrence.
Culture
Challenge culture. The single most effective defence against tailgating is a workplace culture where employees feel empowered and expected to challenge unfamiliar individuals. This requires active support from management and regular reinforcement through training.
Awareness training. Staff should understand what tailgating is, why it matters, and what they should do if they suspect it. Training should normalise the act of politely asking “do you have a badge?” and reassure staff that doing so is expected, not rude.
Visitor management. Robust visitor procedures — sign-in at reception, issue a visible visitor badge, escort at all times, sign-out on departure — ensure that anyone without a permanent badge is immediately identifiable.
Reporting. Employees should have a simple way to report suspected tailgating incidents. Even if the report turns out to be benign, the data is valuable for identifying patterns and high-risk entry points.
The broader picture
Tailgating is often dismissed as a minor risk — after all, it is just someone walking through a door. But the consequences of that unauthorised access can be severe: access to server rooms, sensitive documents, executive offices, or anywhere else the attacker chooses to go once they are inside.
Testing for tailgating resilience — and building the physical, technical, and cultural defences to prevent it — is a fundamental part of any physical security programme.