8 FEBRUARY 2026LATAMIN MYOPINIONTHE URGENT NEED FOR INTEGRATED PHYSICAL AND CYBERSECURITY TEAMSBy Casper Eloff, M.Sc. MBA. CSMP, Head of Corporate Security, The Mosaic CompanyIn an era where security threats and their severity evolve at an unprecedented pace, the traditional silos separating physical security and cybersecurity teams are no longer sustainable. Modern adversaries exploit the seams between these domains, leveraging hybrid attacks that combine physical breaches with digital intrusions to devastating effect. To counter these sophisticated threats, organizations must integrate their physical and cybersecurity teams into a cohesive force capable of holistic threat detection, response and prevention.In many companies globally, cybersecurity teams have been absorbed into the organization's IT Department and, in some cases, buried deep into downward IT layers. The latter is to distaste the cyber function since cyber professionals see themselves as a security function. The same can be said for Physical security teams being buried deep under an organization's Occupational Health and Safety department and in some cases, buried in layers, preventing a direct voice to the organization's leadership--all of the abovementioned hamstring the overall security (physical & cyber) function's effectiveness.The Convergence of ThreatsThe line between physical and cyber threats has become blurred. Consider a scenario where a phishing email grants attackers access to a corporate network, enabling them to turn off physical security cameras or unlock doors remotely. Conversely, a physical breach, such as an intruder gaining access to a server room, compromising sensitive data, or installing malware directly onto critical systems. Recent incidents, like the 2021 Colonial Pipeline ransomware attack, demonstrate how digital vulnerabilities can disrupt physical infrastructure, halting fuel distribution across the U.S. Southeast. Similarly, physical security lapses, such as unmonitored access points, have enabled insiders to steal data or sabotage systems. Not to mention the Duty of Care function, which both security disciplines look after Casper Eloff
< Page 7 | Page 9 >