
The Cyber-Physical Convergence Has Arrived. Is Your Security Program Ready?
It started with a phishing email to an HR manager in Cincinnati. Within 72 hours, the attacker had pivoted from the corporate email server to the building management system, disabled three access control zones on the executive floor, and looped 40 minutes of archived camera footage to cover their tracks. No alarm triggered. No one noticed until Monday morning.
This isn't a hypothetical. Variants of this attack pattern have been documented across critical infrastructure, corporate campuses, and healthcare facilities throughout 2024–2025. If your physical security and cybersecurity teams still operate in separate silos, you are not running two security programs. You are running zero.
The Old Model Is Broken
For decades, organizations relied on a legacy model where physical security (guards, cameras, and badge readers) was managed by a facilities or corporate security team, while cybersecurity was the domain of IT. These departments operated with different budgets, leadership, vendors, and incident response playbooks.
Today, that wall has dissolved. We now see IP-connected cameras feeding into cloud VMS platforms, badge readers integrated with Active Directory, and HVAC, elevators, and lighting on building automation systems (BAS) connected directly to corporate networks. Visitor management systems are synced with HR databases, and SIEM platforms are increasingly ingesting physical access logs alongside network logs.
The critical point to understand is that every one of these integrations is a lateral movement opportunity for an attacker. According to the SIA Security Megatrends 2025, IT-OT convergence is no longer a future trend. It is a top industry force.
How Attackers Are Actually Exploiting This
Modern attackers follow a sophisticated, composite attack chain that bridges the digital and physical worlds.
Stage 1 - Initial Access via Cyber The breach often begins with a phishing email or a vulnerability exploit hitting an IT endpoint. This stage is now heavily AI-assisted, as attackers use Large Language Models (LLMs) to craft hyper-personalized spearphishing at scale, dramatically lowering the barrier to entry.
Stage 2 - Lateral Movement to Physical Systems From the compromised IT endpoint, the attacker enumerates the network to find poorly segmented VMS servers, access control databases, or BAS controllers running legacy firmware.
Stage 3 - Physical World Impact Once inside these systems, the attacker can unlock doors or disable turnstiles to enable a physical intrusion. They may loop or corrupt camera feeds to blind security operators, or trigger false alarms to cause alert fatigue and mask a real intrusion. They can even exfiltrate sensitive building floor plans, personnel schedules, and camera coverage maps.
Stage 4 - Persistence and Exfiltration The attacker now possesses both digital persistence through a backdoor on the IT network and physical intelligence regarding building layouts and blind spots. This classic Advanced Persistent Threat (APT) behavior is now accessible even to mid-tier threat actors because AI has leveled the skills gap. As noted in recent trends, phishing and vulnerability exploitation lead straight to physical systems.
The Governance Gap: Why Most Organizations Are Exposed
Despite widespread awareness, most organizations still have structurally siloed security governance. Physical security often reports to Facilities or Legal, while OT systems like the manufacturing floor are managed by Engineering or Operations, both typically outside the CISO’s visibility. Budgets remain separate, yet unified security platforms require joint investment that neither team can own alone. Furthermore, incident response plans often fail to account for cross-domain scenarios.
The data highlights this vulnerability:
● The WEF Global Cybersecurity Outlook 2026 reports that 45% of organizations cite a skills shortage as a top-three resilience barrier. ● Only a small minority of organizations are at "mature" cyber readiness per Cisco’s 2025 Cybersecurity Readiness Index. ● Interestingly, 52% of CEOs at highly resilient organizations actively prioritize integrated threat intelligence, compared to just 13% at their less resilient peers.
The governance gap can be summarized with one question: Who owns the incident when the attacker entered through email and exited through the loading dock? If your answer requires a meeting to figure out, you have a gap.
Where Does Your Program Stand?
You can’t secure what you haven’t mapped, and you certainly can’t bridge a gap you haven’t first acknowledged. To move from a fragmented, siloed setup toward a truly integrated shield, you need an honest look in the mirror. Use the Cyber-Physical Maturity Model below as your diagnostic tool. This three-stage framework is designed to help you identify existing blind spots and prioritize the necessary investments for convergence.
| Stage 1: Siloed (Immature) | Stage 2: Converging (Developing) | Stage 3: Unified (Mature) | |
|---|---|---|---|
| Team Structure | Separate physical and IT teams; no shared governance. | Joint working group; shared leadership emerging. | Converged ops; single owner (CISO/CSO) for physical + cyber. |
| Technology | Standalone VMS/Access control; no IT integration. | VMS/Access integrated with SIEM; some segmentation. | Fully unified platform: VMS, Access, Intrusion, visitor management, BAS, SIEM. |
| Incident Response | Two separate playbooks; no cross-domain scenarios. | Cross-domain scenarios in tabletop exercises. | Single integrated playbook; automated cross-domain alerts. |
| Visibility | Physical events not in SIEM; no cross-triggering. | Physical access logs fed into security dashboards; partial unified view. | Real-time unified operational picture. AI analytics active across all physical entry points. |
| AI/Analytics | Little to none; reactive camera review. | AI video analytics for real-time threat detection. | Proactive/predictive anomaly, behavior recognition and weapon detection, all integrated. |
| Risk Posture | High - blind spots at every integration point. | Medium - major gaps closed, but OT/BAS still partially exposed. | Low - continuous monitoring with rapid human-in-the-loop escalation. |
Currently, most mid-market organizations sit between Stage 1 and Stage 2. The goal for 2026 is completing the move to Stage 2 while building the roadmap to Stage 3.
What a Converged Program Looks Like in Practice
In a Stage 3 "Unified" environment, a security operator's day-to-day experience is transformed. A single dashboard might surface a physical anomaly, such as tailgating at a secure door, alongside a simultaneous IT alert for an unusual login using those same employee credentials from a different city. AI video analytics flags this behavior in real-time, rather than during a post-incident review. The operator receives a verified, context-rich alert instead of a flood of false positives, allowing them to act in seconds. Finally, the full event chain is logged automatically across both physical and cyber domains for forensics.
This kind of integrated, real-time situational awareness is exactly what AI video analytics platforms like Scylla are built for. By combining weapon detection, behavior anomaly recognition, and access control integration into a single operational layer, Scylla bridges the physical-cyber gap from the camera outward, offering up to a 99.95% reduction in false alarms.

Final Takeaway
Threat actors have already converged. They move fluidly between your email server and your loading dock. Your security program must do the same. Achieving convergence doesn't require a "rip-and-replace" of your entire infrastructure. It starts with integration, updated governance, and deploying AI-powered visibility across your existing systems. The "Unified Shield" is not just a technological goal. It is a fundamental requirement for resilience in an interconnected world.
About the Author

Albert Stepanyan
President and CEO, Scylla AI
Albert Stepanyan is the Co-Founder and CEO of Scylla AI, bringing a rare combination of military service, global security consulting, and technology leadership to the company he built from the ground up in 2018. Before founding Scylla, he served as CTO at Allianz X, held senior engineering roles at Elsevier and Oracle, and spent nearly a decade as an AI and security consultant operating across the US, Europe, and Latin America. Under his leadership, Scylla has grown into a globally recognized AI video analytics platform trusted by enterprise security teams, law enforcement agencies, and US military installations.
Learn MoreStay up to date with all of new stories
Scylla Technologies Inc needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.
Related materials

Beyond AI snake oil: Red flags in vendor claims
Not every ‘self-learning’ or anomaly detection company is telling the truth. Many hide behind buzzwords, fake metrics, and overblown claims of perfection. This article from Scylla AI cuts through the noise, revealing how to identify real-world performance and spot snake oil before it costs you.
Read more
What Is AI Snake Oil?
Learn how to spot the difference between real, game-changing AI video analytics and overhyped and unreliable tech.
Read more
What All Security Directors Should Understand About AI Bias and Surveillance Compliance
Explore the regulatory landscape surrounding AI surveillance to better address AI bias and ensure your video surveillance systems are both effective and compliant with global standards.
Read more