When you’re responsible for keeping a facility safe and running, you’re already managing more than most people realize between compliance requirements, aging infrastructure, and budget constraints.
Most organizations in that position have ended up treating physical security and cybersecurity as two separate problems with separate budgets and teams. The IT department handles the network. The security team handles the cameras and doors. And the gap between them is exactly where things go wrong.
A physical breach and a cyber breach aren’t always separate events. One often triggers the other. And for commercial businesses and organizations across the Pittsburgh and Tri-State area, understanding that connection isn’t optional anymore.
When a Physical Breach Opens the Digital Door
Think about what an intruder actually has access to once they’re inside your building.
An unlocked server room is a direct entry point to your network. If someone slips in through an open door, they can plug a device into an open Ethernet port and sit quietly on your network for weeks. A USB drive inserted into a workstation in an area that should require a key card can push malware straight past every firewall you’ve got.
The global average cost of a data breach hit $4.88 million in 2024, the biggest single-year increase since the pandemic, according to IBM’s 2024 Cost of a Data Breach Report. That gets even more expensive in some fields like healthcare, where that cost climbs to $9.77 million per incident.
IBM also found that stolen or compromised credentials were the most common initial attack vector, present in 16% of all breaches, and those breaches took nearly 10 months on average to detect and contain. Credentials don’t only get stolen through phishing emails. They get stolen because someone propped a door open, shared a badge, or walked away from a workstation in a space that should have been locked down. Sometimes, a physical security failure and a cybersecurity failure are the same event.
When a Cyberattack Takes Down Physical Security
Most people think of cyberattacks as a data problem, but they don’t consider what can happen when someone is inside the building.
Your access control systems, video surveillance systems, and alarm platforms all run on networks now. They’re IP-addressed, remotely managed, and vulnerable to the same attacks as anything else on your network. A ransomware attack that locks up your servers can take your video surveillance systems offline at the same time.
An intrusion into your badge management software can let an attacker walk through doors your own staff can’t open or lock everyone out entirely. A phishing email clicked on a Monday morning can quietly give someone the ability to pull records from your access control systems without ever setting foot in the building.
This happened about 30 miles from Pittsburgh. In November 2023, Iranian-backed hackers took control of an industrial control device at the Municipal Water Authority of Aliquippa. The attack physically shut down a booster station regulating water pressure for two nearby townships.
Staff switched to manual operation in the middle of the night while the FBI, CISA, and the EPA opened investigations. The same group had hit other water utilities across the country using the same method, according to CBS Pittsburgh News.
“If you told me to list 10 things that would go wrong with our water authority, this would not be on the list,” as Matthew Mottes, chairman of the Municipal Water Authority of Aliquippa, told WESA reporters.
That’s the mindset most organizations are operating from until they become the example. Our community sometimes operates as if it’s not a primary target, but it is.
Pennsylvania Organizations Are Actively Being Targeted
In August 2023, a ransomware attack forced emergency room closures and ambulance diversions at Crozer-Chester Medical Center in Upland and Taylor Hospital in Ridley Park. Staff reverted to paper systems. Patient care was disrupted for days while IT teams worked to restore operations, according to CBS Philadelphia.
Public institutions like schools are also attractive targets. In July 2024, the Pennsylvania State Education Association was hit by ransomware. The investigation took months to complete. Security Magazine reported that more than 517,000 people learned that their Social Security numbers, bank account information, health data, and passport numbers had been taken.
Healthcare systems. Schools. Manufacturing facilities. Municipal utilities are all learning the importance of working with security providers every day. The threat is not abstract and it is not distant.
Why Siloed Security Creates the Opening
When your physical security team and your IT team operate in separate silos, you can end up with security plans full of gaps neither team can see.
Your security cameras might be sitting on the same network segment as your patient records or your financial systems. Your badge readers might share credentials with the same server that runs your accounting software. Nobody planned it that way, most organizations built their security infrastructure in phases over years, buying what made sense at the time with the budget and vendors available. The result is a pieced together system that works well enough day to day, but has gaps noone notices until something goes wrong.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a Cybersecurity and Physical Security Convergence Action Guide specifically because this gap is so common and serious. Organizations that keep these functions separate are less prepared to detect and respond to threats that cross the cyber-physical line. The physical security team and the IT team are working together from the same plan. CISA defines this fix as “formal collaboration between previously disjointed security functions.”
What Integrated Security Actually Looks Like in Practice
When you are responsible for the safety of your organization, integrated security systems mean your physical and digital defenses are designed to work together and your network is built to support that safely.
In practice, that means:
- Your video surveillance systems and access control systems run on a properly segmented network, isolated from your core business systems.
- Your computer networking infrastructure was designed with security in mind from the start, not bolted on after the fact. The switches, access points, and configurations reflect exactly where your cameras, badge readers, and alarm panels live on that network.
- Your team gets alerts that cross both systems. If someone badges into a server room at 2 a.m. and there’s no matching camera activity, that generates a notification. It doesn’t sit in two separate logs that nobody compares until after something goes missing.
- When something does go wrong, there’s a clean, connected chain of evidence that holds up for insurance claims, compliance audits, and law enforcement.
This kind of coordinated infrastructure isn’t an upgrade. It’s what the current environment actually requires.
The Network Is the Foundation
Often managers overlook the network their security systems use. Instead, they focus on the individual parts like cameras, alarms, and badge readers. All of it is sitting on a flat network originally set up for office computers and never updated to account for what’s on it now.
When that’s the case, even well-chosen security hardware becomes a liability. An attacker with a foothold on that network could be through a phishing email, a compromised vendor login, or a device left plugged in. Then they don’t have to work hard to move from a camera to a server.
This is the core of what the computer networking services at 2 Krew Security and Surveillance address. We look at the infrastructure everything depends on, and make sure it was built to hold up under real conditions.
2 Krew Security and Surveillance has proudly served commercial businesses, healthcare facilities, schools and campuses, manufacturers, and multi-site organizations across the Pittsburgh and Tri-State area for over 15 years.
If your current setup has the kinds of gaps described here, that’s worth a conversation. Site assessments give you a clear picture of where your physical and cyber exposure points actually are. Reach out to schedule a consultation.





