Locked cabinet housing a Cisco Catalyst switch and Hikvision NVR for physical-layer security.

Network Security Starts at the Cable Plant

Physical layer security controls for cabling systems.

Access Cabling EditorialSeptember 1, 20258 min read

Network security architecture usually starts one layer too high. Firewalls, segmentation, and identity are essential, but the physical layer is where a locked cabinet, a labeled jack, and a bonded ground actually prevent the most common breaches — an unauthorized device plugged into an unlocked drop. Physical-layer security is unglamorous and non-negotiable.

Key takeaways
  • Every telecom room and MDF should have card-access and video coverage.
  • Unused ports at the outlet and the switch should be shut, not just unpatched.
  • 802.1X on wired ports; MAB with allow-list on legacy devices.
  • Cable pathways above locked ceilings are still accessible from other spaces — plan for that.

Executive summary

A defensible network security posture treats the cable plant as a controlled asset. Card-access on all telecom spaces, per-port 802.1X on the switch, disabled unused ports, and monitored physical alarms on cabinets and telecom rooms make the difference between an infrastructure that can be audited and one that cannot.

The physical layer nobody thinks about

Auditors ask for firewall configs and identity policy; they rarely ask who has the key to the MDF. Every credible incident-response engagement we have seen included at least one entry point that a physical-layer control would have prevented — a live jack in a public area, an unlocked cabinet, or an abandoned demarc room.

Controls to implement

  • Card-access on every MDF, IDF, and any cabinet containing switches or network equipment.
  • Video coverage of MDF/IDF entry with 30-day retention minimum.
  • 802.1X authentication on wired ports; MAB with allow-list where 802.1X is not supported.
  • Sticky MAC or port security with 1 MAC per port for legacy devices.
  • Shutdown of unused switch ports and outlet jacks.

Common mistakes

  • Access-control on the MDF door but not on the drop ceiling above it.
  • Guest Wi-Fi on the same VLAN as building automation.
  • Legacy 'jack the phone into the conference room' pattern — every unused outlet is a threat.
  • No monitoring on the environmental sensors — a door propped open in the MDF should alert.

Best practices

  1. Physical security controls parity between MDF and every IDF.
  2. 802.1X for all wired ports; documented exceptions with quarterly review.
  3. Disable unused ports at the switch and at the wall.
  4. Environmental monitoring reporting to the SIEM, not just the facility helpdesk.
  5. Annual physical-security audit alongside the annual network audit.

Cabinet and closet baseline

Physical baseline
  • Card-access with unique credential per person
  • Camera with view of the doorway
  • Cabinet lock separate from room lock
  • Environmental sensor (temp/door)
  • TGB with bonded rack and equipment

When to call a professional

Any organization subject to HIPAA, PCI, SOC 2, or CMMC benefits from a physical-layer security assessment alongside its annual audit. A licensed low-voltage contractor familiar with access control and structured cabling can bring the two disciplines to the same table.

Related resources

Explore the services and projects behind this article

Need this done in your city?

Access Cabling installs from five California offices. Pick your market for local crews, licensing details and direct phone numbers.

Get Started

Build the commercial network your business actually deserves.

28 years, thousands of sites, one accountable contractor. Get a free site survey and an itemized quote in 48 hours.