• Home
  • Blog
  • Facebook
  • LinkedIn
  • Twitter
Menu

Peter Cavicchia

Street Address
City, State, Zip
Phone Number

Your Custom Text Here

Peter Cavicchia

  • Home
  • Blog
  • Facebook
  • LinkedIn
  • Twitter

When the Threat Comes from Above: Drones and the Corporate Campus

August 14, 2026 Pete Cavicchia

Physical security has long been thought of in two dimensions. Fences, gates, guard posts, and cameras have been designed around a single assumption: that a threat must cross a line on the ground to reach a facility. That assumption no longer holds. Corporate campuses now face a threat that never touches the perimeter at all, because it simply flies over it.

A recent piece from AeroDefense, lays out the problem. Corporate campuses hold enormous amounts of valuable data and intellectual property. Most have invested heavily in the physical and cyber protections needed to keep bad actors out at ground level. What they have not accounted for is the three dimensional challenge that drones introduce. A small, inexpensive quadcopter can now be used for corporate espionage, surveillance of secure areas, and in ways that traditional ground based security simply was not designed to detect.

According to the FAA's Center of Excellence for UAS Research, drone sightings across the country grew by nearly 20 percent in the first three quarters of 2025 compared to the year before, with the highest concentrations in California, Florida, Illinois, Texas, and New York. Writing for Security Management, industry analysts have described drone activity as an accelerating trend in high density and critical infrastructure environments, one that security practitioners can no longer treat as an edge case.

The International Security Journal recently observed that drones are becoming an everyday corporate security problem rather than one confined to major public events and stadiums. The article notes that a drone does not need to enter a building, land on a roof, or carry a payload to create risk. It only needs to observe, record, or appear at the wrong moment, whether that means mapping a logistics yard's delivery schedule or capturing footage of a facility most companies would rather keep private.

Regulators are beginning to respond. In June of 2025, two executive orders directed federal agencies to help the private sector detect, monitor, and respond to unauthorized drone activity, with the FAA tasked with restricting flights over critical infrastructure and the Department of Homeland Security tasked with issuing guidance for facility owners deploying detection systems. New Remote ID requirements are being phased in as well, giving law enforcement more information about who is flying what and where. But as the International Security Journal piece points out, regulation should not be confused with protection. Rules only help when operators comply with them, and plenty of the drones that matter most to security teams belong to people who have no intention of doing so.

For corporate security leaders, the response must mirror what already happened at the ground level a generation ago: layered, technology enabled detection paired with a clear plan for what happens next. That increasingly means radar and RF detection systems that can flag an unauthorized aircraft the moment it enters a campus's airspace, paired with protocols for verifying intent and, where legally permitted, responding. Just as important is treating the airspace above a facility as a formal part of the risk assessment rather than an afterthought bolted on after an incident occurs.

The perimeter fence was never meant to protect a building from the sky. As drones become cheaper, more capable, and more common, corporate campuses that continue to plan security in two dimensions will find themselves defending only half the problem.

Tags Drones, security

The Overlooked Risk in Every Layoff: Physical and Data Security

August 7, 2026 Pete Cavicchia

Layoffs are a human resources problem. But a growing body of security literature makes the case that they are just as much a security problem.

Global Risk Solutions, a firm that specializes in reduction in force security planning, publishes many resources on the subject. Workplace violence incidents, targeted threats against HR personnel and leadership, access control failures that allow terminated employees to re-enter secured areas, and broader operational disruption are all outcomes of layoffs they cite that were not supported by adequate security planning. The firm's research also notes that the danger does not end the moment an employee walks out the door. The post termination period is consistently identified as a window of elevated risk, particularly when employees feel the process was handled without transparency or respect.

The numbers behind this are sobering. While not every incident traces back to a termination, job loss, perceived injustice, and financial stress are well established behavioral triggers. A mass layoff compresses all three of those triggers into a single, high pressure event, which is exactly what makes it a distinct security challenge rather than a routine HR exercise.

The insider threat dimension deserves equal attention. Control Risks has written about how mass layoffs create conditions for sabotage, data theft, and fraud, not only among employees who are being let go but among those who remain. Survivors of a layoff often absorb heavier workloads under more uncertainty, which the firm notes can lead to circumventing security processes and compromising sensitive data simply out of exhaustion rather than malice.

Some of the most practical guidance comes from firms that specialize in executive and workplace protection. Guidepost Solutions recommends that companies have a plan ready to implement enhanced monitoring, and where warranted, a security presence at the workplace for several days following a termination. Specific threats against HR staff, executives, or colleagues should be treated seriously and coordinated with law enforcement rather than absorbed internally.

On the access side, the standard playbook still holds: disable network, email, and application access, retrieve or remotely wipe company devices, and remove departing employees from distribution lists and recurring meetings, all timed to coincide with the notification itself rather than trailing behind it.

There is also a simpler, more human element to this that keeps showing up in the research. A recent piece in HR Executive described the "pathway to violence" model that threat assessment professionals use, which traces how a person moves from internal distress toward destructive action through a series of observable steps. HR sits closer to those early signals than almost any other function in a company, from a finance manager mentioning financial strain to an employee who stops engaging with colleagues after a difficult personal event. The risk, as the piece notes, is that those signals almost never make their way to security.

None of this is a case for treating every departing employee as a threat. It is a case for building the infrastructure, coordination between HR and security, behavioral awareness, and access controls calibrated in advance, so that when the difficult day comes, safety is not something a company is improvising in real time.

Tags Corporate layoffs, workplace violence

Protecting Executives on the Move: A Practical Guide to Personal Security in 2026

June 15, 2026 Pete Cavicchia

Executive travel has always carried risk, but the nature of that risk continues to evolve. Increased visibility, real-time information sharing, and a more unpredictable global environment have raised the stakes. Protection is no longer just about reacting to threats. It is about anticipating them.

Preparation begins well before travel. Advance work remains one of the most effective tools available. Understanding the destination, identifying potential risks, and establishing clear movement plans sets the foundation. This does not need to be overly complex, but it does need to be deliberate.

Situational awareness is equally important, and it extends beyond the executives themselves. Drivers, assistants, and security personnel must all operate with a shared understanding of risk. Small details matter. Route familiarity, crowd dynamics, and changes in behavior can signal developing issues.

Hotels present a unique set of challenges. They are public spaces by design, which makes control difficult. Room selection, discreet check-in procedures, and limiting public exposure within the property can significantly reduce risk. Elevators, lobbies, and hotel bars are common points of vulnerability.

Technology plays an expanding role in executive protection, but it should be used thoughtfully. Location tracking, secure communication tools, and real-time intelligence provide value when properly managed. However, over-reliance on digital tools can create new vulnerabilities, especially if those systems are not secure.

Ultimately, personal security is about layering defenses. No single measure is sufficient. Physical awareness, careful planning, and appropriate use of technology work together to reduce exposure.

Executives do not need to operate in fear, but they do need to operate with awareness. The goal is not to eliminate risk entirely. It is to manage it intelligently.

Tags Executive protection, security

The Security Blind Spots in Hybrid Work Environments

June 8, 2026 Pete Cavicchia

Hybrid work did not just change where people work. It changed how facilities behave. Occupancy became unpredictable. Patterns disappeared. And with that shift, many traditional assumptions about security effectiveness broke down.

Security programs have long relied on consistency. Badge access patterns, employee presence, and predictable staffing made it easier to detect anomalies. Hybrid schedules erode that baseline. When fewer people are present and schedules constantly fluctuate, unusual activity becomes harder to distinguish from normal behavior.

One of the most overlooked issues is unmonitored access. When offices operate at partial occupancy, there is often less scrutiny at entry points. Tailgating becomes easier. Visitors blend in more easily. A quiet office can create a false sense of security while reducing accountability.

There is also the issue of space utilization. Entire floors may sit empty for large portions of the week yet remain accessible. This creates environments where unauthorized presence is less likely to be noticed. Physical security depends not just on controls, but on visibility. Empty space reduces both.

Hybrid work also complicates incident response. If an alert is triggered in a lightly occupied building, response times may be slower. On-site personnel may be limited. Coordination becomes harder. The assumption that someone will see something no longer holds.

Effective hybrid security requires a shift in mindset. Instead of relying on presence, organizations need to rely on systems that adapt to variability. Access controls should reflect dynamic occupancy, not static permissions. Monitoring should focus on anomaly detection tied to behavior rather than schedules.

Just as importantly, communication between security and workplace teams becomes critical. Understanding how spaces are used day to day is no longer optional. It is foundational.

Hybrid work is not inherently less secure. But it exposes gaps that were previously hidden by routine. Those gaps are where attention should be focused.

Tags Safe offices, Security

The Physical Security Checklist Every Small Business Owner Needs

April 24, 2026 Pete Cavicchia

Physical security conversations tend to orbit large enterprises — corporations with dedicated security teams, enterprise-grade surveillance infrastructure, and budgets to match. But the small business owner who runs a two-location retail operation, a professional services firm, or a medical practice faces many of the same physical threats with a fraction of the resources. And in some respects, they face greater risk: smaller organizations are frequently seen as softer targets precisely because their defenses are assumed to be thinner.

The good news is that effective physical security does not require an enterprise budget. It requires intentional planning, consistent execution, and an understanding of the most impactful investments a business of any size can make. The checklist below is designed as a practical starting point — not an exhaustive technical manual, but a grounded assessment of what every small business should have in place.

Start With a Risk Assessment

Before spending a dollar on security equipment, every business owner should spend time honestly assessing their specific vulnerabilities. What are your highest-value assets — cash, inventory, equipment, client data stored on physical servers? What are the realistic threats in your location and industry? What security measures do you already have, and where are the obvious gaps? A clear-eyed risk assessment is the foundation upon which everything else is built, and it ensures that security investments are targeted where they will actually make a difference.

Access Control: Who Gets In and Where

Every entry point to your facility should be secured and monitored. This includes not just front doors but emergency exits, loading docks, windows on lower floors, and any interior doors leading to sensitive areas like server rooms, cash storage, or document archives. Modern keypad and keycard access systems are well within reach for small businesses, and they offer the critical advantage of revocability — when an employee leaves, their access can be terminated immediately without the need to change physical locks.

Inside the facility, apply the principle of least access: employees should only be able to reach the spaces genuinely required for their roles. This is as relevant for a small retail operation — where not every employee needs access to the back office — as it is for a larger company.

Surveillance: Placement Is Everything

A security camera system is only as good as its coverage. The most common mistake small businesses make is installing cameras at obvious entry points while leaving blind spots that a would-be intruder can use to their advantage. A basic but effective surveillance setup covers all exterior entry and exit points, parking areas, cash handling areas or point-of-sale stations, and any interior spaces containing high-value assets. Lighting matters too — a camera pointed at a poorly lit area provides limited useful footage. Ensuring that all camera locations are well-lit, whether through existing fixtures or added motion-activated lighting, substantially improves the utility of your surveillance investment.

Alarm Systems and Verified Monitoring

A basic alarm system is a minimum baseline, not a complete solution. As has been noted in the physical security industry, roughly 95% of triggered alarms are false positives — a rate that has led some police departments to adopt no-response policies for unverified alarms. The practical implication for small businesses is to consider monitored alarm systems that offer verified response capabilities, where a monitoring center can assess the situation before dispatching emergency services. This dramatically improves response reliability and ensures your alarm investment translates into actual protection.

Employee Training and Protocols

Technology is only as effective as the people operating around it. Employees are often the first line of defense against both external intrusions and insider risks, and they need clear, practical guidance on what to do when something looks wrong. Training should cover visitor verification procedures, how to handle tailgating situations at secure doors, the proper procedure for reporting suspicious activity, and what steps to take in an emergency. These protocols do not need to be elaborate — they need to be clear, practiced, and consistently applied.

When to Bring in a Professional

For many small businesses, the most valuable security investment is a professional consultation. A qualified physical security consultant can assess your facility with an informed, objective eye — identifying vulnerabilities that are invisible to someone who walks the same space every day. They can also help you prioritize investments so that limited budgets are directed at the highest-impact improvements first. Physical security does not need to be perfect on day one; it needs to be improving, and a professional assessment gives you a clear roadmap for doing just that.

Sources

• New Era Tech – Physical Security Checklist: Seven Must-Haves for Every Business Facility
• Deep Sentinel – The Ultimate Business Security Checklist
• Belfry Software – Physical Security Audit: Checklist and Best Practices for 2025

Insider Threats: Why Physical Security Risks Don't Always Come from Outside

April 17, 2026 Pete Cavicchia

Most physical security strategies are built around a common mental model: the threat comes from outside. A company invests in perimeter surveillance, access control at entry points, and security personnel positioned to intercept bad actors trying to get in. That model is not wrong — external threats are real and must be addressed. But it leaves a significant and growing category of risk almost entirely unexamined: the threat that already has a badge.

Insider threats — whether from malicious employees, negligent staff, compromised contractors, or disgruntled former workers — are rising in frequency and cost, and they represent one of the most underappreciated vulnerabilities in organizational security. According to the 2024 Insider Threat Report from Cybersecurity Insiders, 83% of organizations reported experiencing at least one insider attack in the past year. That is not a niche problem. It is a near-universal one.

The Scale of the Problem

The financial toll is equally striking. The 2025 Cost of Insider Risks Global Report by the Ponemon Institute found that the average total annual cost of insider threat incidents has climbed to $8.8 million per organization — up from $7.2 million just a year prior. And critically, the longer these incidents go undetected, the more expensive they become. Incidents that took more than 91 days to contain averaged $18.7 million in total costs, while those resolved in under 31 days averaged $10.6 million. Speed of detection is not just an operational concern — it is a financial one.

It is also worth noting that not all insider threats are the product of malicious intent. The Ponemon data shows that insider negligence — employees who inadvertently expose sensitive areas, fail to follow access protocols, or share credentials — accounts for the majority of incidents. In a physical security context, this might mean a well-meaning employee propping open a secured door for a colleague, bypassing a visitor log for someone they recognize from a previous meeting, or allowing a vendor access to a restricted area without proper verification.

Why Physical Security Must Be Part of the Answer

The insider threat conversation tends to be dominated by cybersecurity framings — data exfiltration, privilege misuse, credential theft. But the physical dimension is equally important and often less rigorously managed. An insider with legitimate building access can facilitate external actors getting in, tamper with equipment or records, remove physical assets, or simply observe and gather intelligence over extended periods precisely because their presence raises no alarms.

Addressing this requires a different security posture than the standard perimeter-defense model. Access tiering — ensuring that employees can only reach the spaces genuinely required for their roles — is one of the most effective and underutilized tools in physical security. The principle of least privilege, long applied in cybersecurity contexts, translates directly: a marketing associate does not need access to a server room, and a junior employee does not need unsupervised entry to executive offices or financial records storage.

Detection, Not Just Prevention

Prevention is only part of the equation. Organizations also need detection capabilities that can identify anomalous behavior before it escalates. This means integrating physical access logs with broader security monitoring, so that unusual patterns — an employee badging into a restricted area outside normal hours, a contractor accessing the same secure space multiple times in quick succession — can be flagged for review. The 2025 Insider Risk Report from Cybersecurity Insiders found that physical access controls are actively monitored by 57% of organizations, which means a meaningful portion of businesses have essentially blind spots in this area.

Employee offboarding is another area where physical security controls frequently break down. Revoking digital access when an employee departs is now fairly standard practice, but ensuring that physical access — building badges, parking passes, access to shared storage — is simultaneously revoked is less reliably executed. A disgruntled former employee who retains physical access to a facility is a serious and entirely preventable risk.

Building a culture of security awareness, where employees understand why access controls exist and feel empowered to raise concerns when protocols are not followed, is the final layer. Technology and policy can only go so far. Ultimately, the most resilient organizations are those where security is understood as a shared responsibility — not just the province of the security team.

Sources

• IBM – 83% of Organizations Reported Insider Attacks in 2024
• Syteca – Insider Threat Statistics: Facts and Figures
• Cybersecurity Insiders – 2025 Insider Risk Report
• ISACA – Why So Many Organizations Underestimate Insider Threats

Tags Insider Threats

Securing High-Rise Office Spaces: Unique Physical Security Challenges in Vertical Buildings

April 3, 2026 Pete Cavicchia

When we talk about physical security for businesses, the conversation often defaults to a relatively horizontal frame of reference — perimeter fencing, front door access control, camera placement in parking lots. But for the millions of workers who spend their days in high-rise office buildings, the security calculus looks fundamentally different. Vertical environments introduce a set of challenges that simply do not exist in a single-story facility, and addressing them requires a distinct, layered approach.

The rapid return to in-office work across corporate America has put a renewed spotlight on this issue. High-rise buildings in dense urban centers — the kind that house dozens of different companies across hundreds of floors — are simultaneously trying to provide a frictionless environment for authorized tenants and a hardened perimeter against unauthorized access. Those two goals are in natural tension and managing that tension is the central challenge of high-rise security.

The Multi-Tenant Complexity Problem

In a single-tenant building, security is relatively straightforward: one organization, one set of policies, one chain of command. In a multi-tenant high-rise, the dynamics are far more complicated. A building might house a law firm on floors three through seven, a financial services company on floors eight through twelve, and a tech startup on the floor above that — each with its own access requirements, visitor protocols, and security priorities. The lobby and elevator banks that all of these tenants share become critical choke points that no single tenant fully controls.

Security experts note that managing diverse user groups in these environments — balancing permanent tenants, employees, contractors, delivery personnel, and visitors — is among the most operationally intensive aspects of building management. Without a unified, scalable access control system, these buildings face significant risks: unauthorized individuals tailgating through secure doors, unvetted visitors reaching sensitive floors, and a general lack of visibility into who is in the building at any given moment.

The Overlooked Vulnerabilities

Lobbies and main entrances receive the bulk of security attention in most high-rise facilities, but several critical vulnerabilities tend to be underinvested. Stairwells are a prime example. In an emergency, they are the primary evacuation route for thousands of people; in a non-emergency, they are often the least-monitored access pathway in the building. Elevators present a similar paradox: they are the main arteries of a vertical building, but without floor-specific access restrictions, they can carry an unauthorized visitor straight to any floor without challenge.

Parking garages represent another frequently underestimated vulnerability. Attached to the main building but often managed with a lighter security touch, they can serve as a backdoor for individuals seeking to bypass lobby screening. Service entrances and loading docks — which see constant traffic from vendors, delivery services, and maintenance crews — are similarly high-risk if not properly managed.

Building Security Into the Structure

The most effective high-rise security strategies share a common characteristic: they treat the building itself as a security asset, not just a container for security equipment. This means thinking carefully about how physical design, access control technology, and trained human personnel work together. Floor-specific elevator access restrictions, for example, ensure that a visitor credentialed for one company cannot simply press a button and land on a competitor's floor. Integrated visitor management systems log every arrival and connect that record to a specific tenant and time window.

Emergency preparedness is a dimension that deserves particular emphasis in high-rise environments. Research has found that a significant portion of high-rise residents and tenants remain unaware of basic building safety systems — evacuation routes, designated assembly points, and emergency communication protocols. In a building where an incident on one floor can immediately affect dozens of others, that knowledge gap is a serious liability. Regular drills, clear signage, and direct coordination with local emergency services are not optional — they are essential components of any credible high-rise security plan.

As the return-to-office trend continues to bring more workers back into these vertical environments, high-rise security deserves the same level of strategic attention that organizations have long given to their digital defenses. The threats are real, the vulnerabilities are well-documented, and the solutions — when thoughtfully deployed — are well within reach.

Sources

• GardaWorld – Best Practices for Securing High-Rise Buildings
• Shield Corporate Security – High-Rise Building Security: Strategic Layered Protection
• Gallagher Security – Enabling Multi-Tenancy Security with Access Control Solutions
• LiveSecure – High-Rise Building Security Strategies

Tags Security for High-Rise Buildings

The Rise of Biometric Access Control: Balancing Convenience, Security, and Privacy

March 27, 2026 Pete Cavicchia

Fingerprint scanners, facial recognition systems, and iris readers are no longer the exclusive province of government facilities and spy thrillers. Across healthcare campuses, corporate headquarters, schools, and even mid-sized office buildings, biometric access control is rapidly becoming the go-to solution for organizations looking to tighten their physical security posture. But as with any powerful technology, the benefits come paired with serious questions that every organization must wrestle with before deployment.

The numbers make the growth trend undeniable. According to industry analysts, the global biometric access control market was valued at $11.1 billion in 2025 and is projected to reach $15.2 billion by 2029. That is a substantial investment signal, and it reflects a genuine shift in how businesses think about verifying who walks through their doors. Traditional access methods — keycards, PIN codes, physical keys — all share a common vulnerability: they authenticate an object or a piece of knowledge, not a person. Biometrics flips that equation entirely. A fingerprint, a face, an iris pattern — these belong to an individual and cannot easily be transferred, shared, or stolen in the way a keycard can.

Why Organizations Are Making the Switch

The practical advantages of biometric systems are compelling. Beyond enhanced security, they offer meaningful operational benefits. Employees no longer face the all-too-familiar frustration of a forgotten access badge or a misplaced key fob. Entry logs become automatically tied to a verified identity, creating reliable audit trails that are invaluable during security reviews or incident investigations. And in high-traffic facilities, the speed of a biometric scan — typically less than a second — keeps entry points moving efficiently without sacrificing oversight.

There is also a scalability argument. A biometric system installed at a ten-person startup can grow alongside the organization without requiring a wholesale replacement of infrastructure. Modern platforms allow administrators to add, adjust, or revoke access from a centralized dashboard, whether they are on-site or working remotely. This kind of operational flexibility matters enormously in a business environment where the workforce is increasingly mobile and distributed.

The Privacy Imperative

None of this means the technology is without risk — far from it. Biometric data is categorically different from other forms of identification because it is permanent. If a password is compromised, you change it. If a keycard is stolen, you deactivate it. If a person's facial geometry or fingerprint data is exposed in a breach, there is no corrective action that can undo the damage. That immutability is precisely what makes biometrics so effective for security — and precisely what makes mishandling it so consequential.

Workplace environments add another layer of complexity. When employees are required to submit biometric data as a condition of employment, that raises legitimate ethical and legal questions. Are workers being adequately informed about how their data is stored and who has access to it? Are there non-biometric alternatives for those with concerns? These are not merely theoretical considerations. In the United States, more than 20 states have enacted or proposed biometric privacy laws as of 2025, with Illinois leading the way through its Biometric Information Privacy Act (BIPA), which mandates written consent, clear retention policies, and secure storage, with significant penalties for violations.

Best Practices for Responsible Deployment

Organizations considering biometric access control should approach deployment with the same philosophy that has been championed in broader data privacy discussions: collect only what you need, protect what you collect, and be transparent with the people whose data you hold. This aligns with the well-established Privacy by Design framework — the principle that privacy protections should be built into systems from the outset, not tacked on after the fact.

On the technical side, modern biometric platforms are increasingly built with privacy-preserving architectures in mind. On-device processing — where biometric matching occurs locally without raw data ever leaving a terminal — is gaining traction. Encrypted templates replace stored images of fingerprints or faces, meaning there is no reversible data to expose if a system is breached. These are the kinds of safeguards that responsible vendors are building in, and they are the right questions to ask when evaluating providers.

The bottom line is this: biometric access control, implemented thoughtfully, represents a genuine step forward for physical security. But it demands a level of organizational maturity and legal awareness that not every business has yet developed. The technology is ready. The question is whether the policies, consent workflows, and data governance practices are ready to go along with it.

Sources

• Newmark Security – The Rise of Biometrics in Access Control
• Parabit – Biometric Privacy Laws in 2025
• Security Force – Advancements in Biometric Security: What to Expect in 2025
• Bipartisan Policy Center – Prevalence of Biometric Data and Security Concerns 

Tags Biometric access control, security
Older Posts →