For years, organisations have invested heavily in protecting their digital infrastructure. Identity and Access Management, Multi-Factor Authentication, Zero Trust, Privileged Access Management, Security Operations Centres and continuous monitoring have become standard components of modern cybersecurity. Yet a remarkably simple question remains unanswered in many critical infrastructure environments:
Who can physically open the door?
Not theoretically. Not according to an Excel sheet, a key plan created three years ago or a contractor database that may or may not be current.
Who can open it right now?
That question is becoming increasingly important because the security environment around critical infrastructure has fundamentally changed.
Europe is facing a combination of cyber espionage, sabotage, information manipulation, politically motivated attacks and operations linked to state actors.
The EU’s own description of the current hybrid-threat environment includes cyberattacks, foreign information manipulation and interference, sabotage, damage to undersea infrastructure and other activities intended to destabilise states and institutions. (EEAS)
At the same time, artificial intelligence is dramatically reducing the cost and complexity of offensive cyber operations.
ENISA’s 2026 Threat Landscape reports that organisations across the EU face a combination of cybercrime, cyberespionage and hacktivist activity influenced by geopolitical developments. It also observes increasing use of AI by malicious groups. State-nexus intrusion sets primarily conducted intrusion operations, while AI-generated text, audio and video are increasingly being used for information manipulation. (ENISA)
This matters because the attack surface is no longer limited to networks. The objective of an attacker is not necessarily to compromise a server. The objective may be to disrupt electricity distribution, interfere with rail infrastructure, disable telecommunications, damage water infrastructure, steal sensitive equipment or gain persistent access to a strategically important location.
The cyberattack may simply be the first step. The final target can be physical.
AI makes another development particularly relevant. Attackers increasingly have the ability to automate reconnaissance, generate convincing phishing messages, imitate communication styles, create synthetic identities and conduct social engineering at industrial scale.
ENISA has documented the growing role of AI in phishing and social engineering. Its 2025 Threat Landscape noted widespread use of LLMs to improve phishing and automate social-engineering activities. (ENISA)
State-linked actors are also using information operations and social platforms as part of broader geopolitical campaigns. ENISA has documented campaigns linked to Russian, Chinese, Iranian and North Korean state-nexus actors, while the EU describes foreign information manipulation and interference as part of today’s hybrid-threat landscape. (ENISA)
This creates an uncomfortable reality for critical infrastructure operators. An attacker may not need to hack a sophisticated industrial control system if it is easier to compromise the identity of an employee, contractor or supplier who already has legitimate physical access. And that brings us back to the key.
The €20 key protecting the €20 million asset
Across energy, water, telecommunications, rail, transport and other critical sectors, enormous investments have been made in cybersecurity. But physical access is frequently still managed using processes developed decades ago.
Keys are issued.
Spreadsheets are updated.
Contractors receive access.
Projects finish.
Employees change roles.
Maintenance companies change.
Keys disappear.
Permissions accumulate.
And somewhere in the organisation there is an assumption that the key plan still reflects reality. That is no longer good enough. A mechanical key has one fundamental security limitation: the lock does not know who is holding it.
If the key is copied, transferred, stolen or simply never returned, the organisation may have no reliable mechanism to determine who currently possesses access. In a geopolitical environment characterised by espionage, sabotage and hybrid operations, that is a governance problem.
Electronic locking systems fundamentally change this relationship. A physical key no longer needs to represent permanent access. It can represent an identity-controlled permission. Access can be restricted by person, location, asset, role, time, project, employer, maintenance activity or risk level.
A technician maintaining a transformer station does not necessarily need permanent access to every transformer station in the region.
A contractor working on railway infrastructure does not necessarily need access six months after the contract has ended.
An engineer servicing a water installation does not necessarily need access at 03:00 unless there is an authorised incident.
The question therefore changes from: “Does this key fit this lock?” to:
“Should this identity be allowed to access this asset, for this purpose, at this moment?”
That is a completely different security architecture.
There is, however, an important trap. Replacing mechanical cylinders with electronic cylinders does not automatically solve the governance problem. Without integration with identity systems, organisations can simply create another security silo. Instead of an unmanaged mechanical key database, they now have an unmanaged electronic key database. The technology has changed. The governance problem has not.
This is why electronic locking must be combined with Physical Access Governance. The organisation needs to know:
Identity → Role → Policy → Permission → Key → Asset → Event
That chain must remain intact throughout the entire lifecycle of an employee, contractor or supplier. When somebody joins an organisation, appropriate access can be provisioned. When their role changes, access should change automatically. When a project ends, temporary permissions should disappear. When employment ends, physical access should be revoked as part of the same identity lifecycle that removes access to IT systems. And when an auditor asks who could access a critical installation on a specific date, the organisation should be able to answer from evidence rather than reconstructing the answer from spreadsheets, emails and key cabinets.
The EU Critical Entities Resilience Directive makes the relationship between resilience and physical access explicit. Article 13 requires critical entities to implement appropriate and proportionate technical, security and organisational measures. These include adequate physical protection, monitoring, detection and access controls. It also specifically addresses employee security management, including establishing access rights to premises, critical infrastructure and sensitive information. (Eur-Lex)
Importantly, CER requires organisations to consider not only conventional security incidents but also hybrid threats, sabotage and other antagonistic threats in their risk assessments. (Eur-Lex) This is significant. Physical access management is no longer merely an operational responsibility for the facilities department. It is part of organisational resilience. And resilience requires governance.
Traditional security models often focus on preventing unauthorised people from obtaining access. Modern security architecture should assume that, eventually, somebody will succeed.
A password will be compromised.
A phone will be stolen.
A contractor account will remain active.
A convincing AI-generated message will fool somebody.
An insider may abuse legitimate privileges.
A physical key may disappear.
The security architecture therefore needs a second question:
What can this identity actually access after compromise?
This is where concepts already familiar from cybersecurity should be applied to physical infrastructure. Least privilege. Separation of duties. Role-based access. Attribute-based access. Just-in-time access. Time-limited permissions. Continuous verification. Automated revocation. Audit trails. Risk-based authentication.
These principles should not stop at the firewall. They should continue all the way to the lock cylinder.
Consider a maintenance contractor responsible for 500 infrastructure locations. Historically, operational convenience may have resulted in that contractor receiving a key providing broad access across the estate. From an operational perspective this is efficient. From a security perspective it creates an enormous blast radius.
An identity-driven electronic access model can dramatically reduce that exposure. The contractor can receive access only to the locations required for today’s work order. Access can start shortly before the planned maintenance window and expire automatically afterwards. If the contractor changes employer, loses authorisation or finishes the assignment, access can be withdrawn centrally.
The organisation moves from possession-based security to policy-based security.
That distinction becomes increasingly important as threats become more automated.
There is another misconception around automated key management. Automation is often justified primarily through operational efficiency. Fewer manual processes. Less administration. Fewer helpdesk calls. Faster contractor onboarding.
Those benefits are real, but they are secondary to something more important.
Automation reduces governance latency.
If somebody leaves an organisation today but their physical access remains valid for another three weeks because several departments need to update separate systems, there is a three-week security exposure.
If an IAM or IGA decision automatically propagates to the physical-access environment, that exposure can be reduced dramatically, subject to the delivery characteristics of the underlying locking technology.
The same principle applies when granting access. Access should not exist because somebody once needed it. Access should exist because a current identity, policy and business requirement justify it.
This is the architecture that platforms such as Key2XS are designed to enable. IAM and IGA platforms already govern digital identities. Electronic locking platforms already control sophisticated physical credentials.
The missing layer is often the governance connection between those worlds. Physical Access Governance connects identity decisions to physical-access systems so that organisations can automate provisioning, revocation, policy enforcement and auditability across electronic key infrastructures.
That means the identity platform remains authoritative for who somebody is and what they should be allowed to do, while the electronic locking system remains responsible for executing physical access securely. The governance platform connects the two.
This is ultimately much bigger than replacing mechanical keys with electronic ones.
Europe’s critical infrastructure is increasingly operating in an environment where cyberattacks, espionage, sabotage, AI-assisted social engineering and information operations overlap. The EU is already treating damage to critical infrastructure, cyberattacks and information manipulation as components of a broader hybrid-threat environment. (EEAS)
The European Commission has also warned that recent patterns involving submarine infrastructure suggest that critical infrastructure may increasingly be exposed to deliberate hostile acts. (Eur-Lex)
Against that background, organisations cannot afford a disconnect between sophisticated digital identity governance and poorly governed physical access. You cannot implement Zero Trust for Microsoft 365 while effectively maintaining “Trust Forever” for a transformer station.
You cannot automatically revoke someone’s privileged IT account while allowing the same person to retain physical access to operational infrastructure. And you cannot claim complete access governance if nobody can reliably answer who can enter a critical asset today.
Electronic locking provides the technical foundation. Automated key management provides operational scalability. Identity integration provides lifecycle control.
Physical Access Governance provides accountability.
Together, they turn the lock from an isolated piece of hardware into a controlled endpoint of the organisation’s security architecture. In an era of AI-enabled attacks, geopolitical instability and hybrid threats, that is no longer simply better key management.