Envoy Research Report · 2026

The State of Physical Security & Compliance

Why the enterprise can't say who's in the building

Download the PDF
Illustration of a large padlock with a keyhole in the center, a magnifying glass, a gear, a checklist with checkmarks, and a building, symbolizing security, inspection, and compliance.
1,076 leaders · Two independent studies · Fielded 2026
Key statistics
71%

of enterprises give contractors no single identity across their sites

Compliance study, n=782

92%

of sensitive-workspace organizations miss at least one physical-security basic

Sensitive-workspace study, n=294

44%

cannot confidently say who was in their building yesterday

Sensitive-workspace study, n=294

62%

are sure they would pass an audit today, yet most had an incident

Compliance study, n=782

The big picture

Two studies, the same open door

The average enterprise has automated its visitor logs, hired a security team, and passed its audits. Yet it still cannot tell you, with confidence, who was in its buildings yesterday. That gap, between how secure these organizations feel and how secure they can prove they are, is the subject of this report.

We ran two independent surveys in 2026, and they were designed to tell different stories. One looked at the tooling and compliance machinery of the broad enterprise. The other looked at the threats facing the most sensitive workspaces in the country: frontier AI labs, defense-tech firms, biotech and medical-device R&D. We expected two reports. The data gave us one.

The shared story is simple: these organizations cannot reliably recognize the people inside their own buildings, and most had a real incident this year. The systems meant to control physical access have no shared memory, so a contractor who belongs is recognized in one building and a stranger in the next. 71% of enterprises in the compliance study do not give contractors a single identity that follows them across sites, and 72% of sensitive-workspace organizations keep no single visitor record across their locations. Two different samples, asked two different ways, describing the same blind spot. And confidence in these programs runs well ahead of what they can actually prove.

Throughout, every figure is tagged with the study it came from. The two datasets are analyzed separately and compared, never merged into one blended number. Where they rhyme, and they rhyme often, it is because two different samples answered two different instruments and pointed the same direction. That is the strongest evidence a research program can offer.

Sophisticated cyber posture, 1990s-era physical posture.
The confidence is real. The coverage isn’t.
And someone already walked past the whiteboard.

01 — The confidence gap

They feel secure. Are they?

A shield emblem with a blue top and white bottom containing a green circle with a white question mark, alongside a blue padlock and a user profile icon card on a light blue circular background.
01 — The confidence gap

Ask the leaders doing the most sensitive work in the world whether their program would stop an intruder, and most say yes. Ask what is actually instrumented behind that confidence, and the number drops. A net 58% believe their program would prevent unauthorized physical access, yet only 52% have badge control on sensitive doors and only 47% escort visitors at all times.

The belief is running ahead of the build. And confidence is not universal. The same question that produces a 58% majority also leaves 42% who will not say their program would stop an intruder, including 35% who actively doubt it. The picture splits two ways: a slight majority who feel protected but have not built the controls to be, and a large minority who already know they are exposed.

Source: Sensitive-workspace study, n=294

What lab and R&D leaders believe about their own program

Thinking about your organization’s overall physical security program for sensitive areas, to what extent do you agree with each of the following? (net agree, strongly + somewhat)

Tools well-matched to sensitivity
59%
Program would prevent unauthorized access
58%
Could say who was in the building yesterday
56%
Contractor access revoked in 24 hrs
55%
Physical as mature as cybersecurity
52%
0
20
40
60
80

Look at what these organizations have actually put in place and the confidence looks generous. Badge or key-card control on sensitive doors, the single most basic instrument, is present at just over half. Escorting visitors, capturing a government ID, revoking a terminated employee’s access within a day: each is a coin flip. A single visitor record that persists across all sites, the thing that would let identity follow a person, exists at barely a quarter.

Source: Sensitive-workspace study, n=294

What they’ve actually built

Which of the following are currently part of your physical security program for sensitive areas? Select all that apply. (multi-select, exceeds 100%)

Badge / key card on sensitive doors52%Receptionist or guard verifies ID49%Terminated lose access within 24 hrs48%Visitor escorted at all times47%Government ID captured at check-in46%Visit auditable for 12+ months42%Digital tablet or app sign-in40%Watchlist / denied-party screening37%Contractor access governed as employee35%Single visitor record across all sites28%Paper logbook sign-in19%

In fact, 92% are missing at least one of the five physical-security basics for sensitive work. Programs are being graded on intent, not on what is instrumented.

This is not unique to high-security labs. In the broader compliance study of 782 enterprise leaders, the same overconfidence appears: 62% are very confident they could pass a physical-security audit today with no time to prepare, and another 34% are somewhat confident. Near-total assurance, in a population where most had a real incident this year.

Source: Compliance study, n=782

The broad enterprise is just as sure

If your organization had to pass a physical security compliance audit today, with no time to prepare, how confident are you? (single-select)

96%
confident or better
Very confident62%
Somewhat confident34%
Neutral3%
Not very confident1%
Not at all confident0%
Key insight

58% believe their program would stop an intruder, but the controls that would make that true are present for only about half. The broad enterprise is no more grounded: 96% are at least somewhat sure they would pass an audit today. Across both studies, confidence sits well above coverage. Programs are being graded on intent, not on instrumentation.

02 — Accounting for yesterday

Ask who was here yesterday, and 44% can't answer

A circular chart with a large navy blue center circle showing 44%, surrounded by a ring split into two segments: a larger light blue segment and a smaller green segment, with an icon of a person in a circle containing a white question mark in the top right.
02 — Accounting for yesterday

The cleanest test of a physical security program is a simple one: can you say who was inside yesterday? For 44% of leaders doing some of the most sensitive work across industries, the answer is no. And the lived experience backs it up. Over a third (35%) personally saw someone they didn’t recognize and weren’t sure should be there within the past month, and one in five (19%) still run visitor sign-in on a paper logbook.

Source: Sensitive-workspace study, n=294

Can you account for yesterday

We could tell you exactly who was in our building yesterday. (single-select)

43%
13%
10%
15%
19%
50% midpoint
Strongly agree 43%
Somewhat agree 13%
Neither 10%
Somewhat disagree 15%
Strongly disagree 19%

The number is not an abstraction. It is the difference between being able to investigate an incident and not. When 44% cannot reconstruct a single day, the ability to prove who touched what, or to close a gap they cannot see, goes with it.

Source: Sensitive-workspace study, n=294

When they last saw a stranger inside

When was the last time you personally saw someone in your workplace you didn’t recognize and weren’t sure should have been there? (single-select)

10%
Past week
26%
Past month
22%
Past 3 months
10%
Past 6 months
9%
Past year
13%
1 year+
10%
Never

58% saw an unrecognized person on site within the last three months.

More than half of these leaders saw an unrecognized person inside within the past three months. This is a regular occurrence, not a rare one.

Key insight

If you can’t reconstruct yesterday, you can’t investigate an incident, prove who touched what, or close a gap you can’t see. Nearly half of these leaders are in that position, and many are relying on a paper log that walks out the door with whoever signed it.

03 — When access fails

The stranger didn't stop at the lobby

Icon of a person with a question mark over their face in front of a desk with a computer monitor, with a large green upward arrow above.
03 — When access fails

The unrecognized people aren’t staying in the lobby. Two in five (39%) leaders have personally seen a visitor or contractor reach a restricted physical area, and a fourth (28%) have seen someone view or photograph work-in-progress on whiteboards, screens, or prototypes. Unauthorized people ending up where they shouldn’t be is a regular occurrence, not a rare one.

Source: Sensitive-workspace study, n=294

What leaders have personally witnessed

In the past year, have you witnessed a visitor or contractor doing any of the following? Select all that apply. (multi-select)

39%
Reached a restricted physical area
28%
Viewed or photographed work-in-progress
20%
Accessed lab equipment or hardware
20%
Accessed sensitive documents
19%
Accessed an unattended workstation

“A contractor that was no longer employed accessed employee areas.”

— Sensitive-workspace study respondent

Ask how often it happens and the frequency is striking. Four in five leaders (79%) report at least one unauthorized-access incident in the past year. Only 21% say it never happened.

Source: Sensitive-workspace study, n=294

How often strangers end up inside

How many times have unauthorized or unverified people ended up in workspaces where they shouldn’t be, in the last year? (single-select)

21%
Zero this year
32%
1–3 times
26%
4–6 times
17%
7–12 times
4%
12+ times

79% had at least one unauthorized person inside in the past year.

The broad enterprise reports the same failures, in the same shapes. In the compliance study, the front-door breakdowns are just as common: a visitor who was not properly signed in (29%), an employee who could not identify themselves at check-in (28%), a visitor who could not be verified at all (22%). The specific ways people slip past the entrance are identical whether the building holds a frontier model or a filing cabinet.

Source: Compliance study, n=782

The same failures show up across the whole enterprise

In the past year, has your organization experienced any of the following? (access and verification failures)

Visitor was not properly signed in29%Employee could not identify themselves at check-in28%Visitor could not be verified at check-in22%Visitor escorted into a sensitive area unapproved19%Unauthorized person found in a restricted area13%
Key insight

Four in five sensitive-workspace leaders report at least one unauthorized-access incident in the past year, and the broad enterprise logs the same verification failures at scale. A stranger who reaches a whiteboard or an unattended workstation has, in effect, reached the work itself. The gap from the confidence chapter, made physical, in both populations.

04 — The missing identity layer

One person, ten front doors, no shared memory

Illustration of a user icon in front of a row of five closed doors on a light blue and purple background.
04 — The missing identity layer

If the sensitive-workspace study showed the sharpest edge of this problem, the compliance study shows its breadth. Among 782 enterprise leaders in physical security, compliance, IT, and facilities, the identical structural gap appears: identity does not persist across sites. 71% do not give contractors a single identity across all their locations. In the sensitive-workspace study, asked a different way in a different sample, 72% do not keep a single visitor record that persists across sites. The two figures land one point apart.

Source: Both studies

The same gap in both studies: no identity that follows a person

Share of organizations with no persistent identity or visitor record across all their sites, measured in each study

71%

No single identity across sites (Compliance)

72%

No single visitor record across sites (Sensitive-workspace)

The two studies used different instruments and never shared a respondent, so the near-match is not an artifact of pooling. It is two independent samples describing the same missing layer. The rest of this chapter stays inside the compliance study, where the larger sample lets us see exactly where the gap concentrates.

Source: Compliance study, n=782

How contractors are recognized across sites

When contractors return to a different site, are they recognized as the same person? (single-select)

29%
16%
34%
17%
One identity everywhere 29%
Depends on the role 16%
Some sites, not others 34%
From scratch each site 17%
Not sure 4%

The gap is deepest where the most third parties move through the building. Healthcare gives contractors a single identity just 22% of the time and manufacturing 26%, against financial services at 31%. No industry clears one in three.

Source: Compliance study, n=782

One identity across sites, by industry

Share giving contractors a single persistent identity everywhere, by industry

31%
Financial Services
30%
Technology
26%
Manufacturing
22%
Healthcare

Scale, which you might expect to help, barely does. The largest estates consolidate slightly, but even at twenty or more sites a strong majority still cannot give a contractor one identity.

Source: Compliance study, n=782

Identity continuity barely improves with scale

Share giving contractors one identity across all sites, by number of sites

28%29%32%2–4 sites5–19 sites20 or more sites

Four percentage points separate the smallest multi-site operators from the largest.

The reason is sprawl. 74% of enterprises run two or more visitor-management systems and 46% run six or more. Each site, each acquisition, each lobby brought its own tool, and nobody ever connected them.

Source: Compliance study, n=782

Most enterprises run many visitor systems at once

How many visitor management systems does your organization operate across all sites? (single-select)

23%
1 system
28%
2–5
18%
6–10
14%
11–15
7%
16–20
7%
20+
Key insight

A stack that can’t see itself can’t remember a person. 71% of enterprises have no shared identity layer, and the sprawl that causes it is structural: it appears the moment an organization has more than one site and never resolves on its own. Every downstream failure, the incidents, the audit scramble, the wasted hours, follows from this single fact.

05 — Incidents everywhere

When no one system remembers, the wrong people walk in

Illustration of an open door with a user profile icon next to it and a red circle with a white X, representing denied access or no entry.
05 — Incidents everywhere

The consequence is not hypothetical in the broad enterprise either. 68% of compliance-study organizations had a real physical-security incident in the past year, and in the sensitive-workspace study 78% had an unauthorized person reach a restricted area. Different question, different sample, the same verdict: most organizations had a breach of some kind this year.

Source: Both studies

Most organizations had an incident this year, in both studies

Share reporting at least one incident or unauthorized entry in the past year, measured in each study

68%

Had a real physical-security incident (Compliance)

78%

Had an unauthorized person in a restricted area (Sensitive-workspace)

High security does not buy safety. The frontier AI labs and defense-tech firms in the sensitive-workspace study report incidents at rates even with, or above, the ordinary offices in the compliance study. The sensitivity of what an organization protects does not change the outcome when the identity layer underneath is missing.

The entry-level failures are only half of it. A second cluster of incidents comes from access that should have ended and lingered: a compliance gap surfaced during an audit (24%), a former contractor who kept access after the work ended (21%), a former employee who kept access after leaving (20%). The front door held. The memory behind it lapsed.

Source: Compliance study, n=782

When access outlives the person

In the past year, has your organization experienced any of the following? (access persistence and audit gaps)

Compliance gap discovered during an audit24%Former contractor kept access after work ended21%Former employee kept access after departure20%

That last failure, access that outlives the engagement, shows up at nearly the same rate in both studies. A third of compliance-study organizations logged it as an incident, and a nearly identical share of sensitive-workspace leaders are not confident a departed contractor loses access at all.

Source: Both studies

Departed contractors keep access in both populations

Share reporting retained access by a former contractor or employee, measured in each study

33%

Former contractor or employee kept access (Compliance)

31%

Not confident a departed contractor loses access (Sensitive-workspace)

Key insight

Two studies, two populations, the same result: most organizations had a real incident this year, and the most sensitive ones are no safer. The problem is structural, not situational.

06 — The operational tax

The hidden cost of running security by spreadsheet

Illustration of a calculator with a magnifying glass highlighting a dollar sign, symbolizing financial analysis or cost calculation.
06 — The operational tax

Between the incidents sits the daily tax, the one that never makes it into a board deck because it is invisible until an auditor asks. When the systems don’t talk, a human has to be the integration layer. Pulling access logs in a normal week means reconciling six or more separate systems for 49% of enterprises.

Source: Compliance study, n=782

Systems a team must check just to pull access logs

How many separate systems must your team check to pull physical access logs in a normal week? (single-select)

7%
1 system
44%
2–5
24%
6–10
14%
11–15
7%
16–20
4%
20+

93% must check two or more systems to answer a single access question.

That reconciliation costs real hours. 56% of teams lose six hours a week or more to manual physical-security tracking, before an audit even begins. During an active audit, the burden spikes.

Source: Compliance study, n=782

Hours per week lost to manual tracking

Roughly how many hours per week does your team spend on manual physical-security tracking? (single-select)

9%
Under 1 hr
34%
1–5 hrs
36%
6–10 hrs
15%
11–20 hrs
5%
20+ hrs

“Protocol is to immediately shut down the building, lock all exits and entries, and perform head count, badge count, and screen each employee in the building in each room.”

— Sensitive-workspace study respondent, on responding to an intruder

The pain of audit prep is not the paperwork itself. It is the scramble to assemble evidence that lives in too many places at once.

Source: Compliance study, n=782

The biggest pain in preparing for an audit

What challenges do you experience when preparing for a physical security audit? (multi-select)

Time-consuming: pulls people off other work45%Chasing down records from multiple teams32%Afraid of missing something28%Information scattered across too many sites27%Information scattered across too many systems26%Consequences of failure are stressful25%
Key insight

Some of that “system” is paper and pen, with someone typing the day’s sign-in sheet into a spreadsheet at the end of a shift. It holds up until that person is out, or the volume spikes, or an auditor asks for a record that was never written down.

07 — Confidence vs. evidence

The blind spot hiding behind the confidence

Shield emblem with a star in the center, set against a blue circular background with a brick wall pattern.
07 — Confidence vs. evidence

Here is the part that doesn’t add up. The same leaders watching strangers walk through their buildings are confident those buildings are secure. In the sensitive-workspace study, 58% believe their program would stop an unauthorized person and 83% say their physical-cyber budget balance is about right. In the compliance study, 62% are sure they could pass an audit today with no preparation, even as most had an incident. The witnessed reality and the stated confidence point in opposite directions.

Source: Both studies

Confidence runs high in both studies

Share expressing confidence in their program, across the two studies

62%

Sure they would pass an audit today (Compliance)

83%

Say their physical/cyber balance is right (Sensitive-workspace)

In the compliance study, confidence is highest exactly where exposure should worry leaders most or least in inverse. Single-site organizations, with the least to reconcile, are the most confident. The moment a second site opens, confidence dips, precisely where multi-site fragmentation first appears.

Source: Compliance study, n=782

Audit confidence is highest at single-site orgs, then dips

Share very confident they could pass an audit today with no prep, by number of sites

71%58%63%61%1 site2–4 sites5–19 sites20+ sites

Confidence falls 13 points the moment a second site opens, and never fully recovers.

Ask the specific questions and the confidence thins further. 44% of sensitive-workspace leaders cannot say who was in their building yesterday. Yet 83% still say their budget balance is about right and only 12% admit they underinvest in physical security.

Source: Sensitive-workspace study, n=294

Where the worry concentrates

How concerned are you about each of the following physical security threats? (very + somewhat concerned)

Insider — intentional exposure
67%
Contractors without supervision
66%
Insider mistakes — accidental
66%
Unauthorized visitors in restricted areas
65%
Tailgating
65%
Other unverified individuals
62%
Terminated employees retaining access
56%
Foreign nationals gaining access
56%
40
50
60
70
80

Physical and cyber teams “coordinate closely” at 82% of compliance-study organizations, yet the physical side still runs blind. The threats leaders rank highest, insiders and unsupervised contractors, are the ones their controls handle weakest.

Key insight

The confidence splits two ways, and neither half is reassuring. A slight majority believe their program would stop an intruder, and the coverage data says most of them shouldn’t. The rest already doubt it. Cyber posture is funded for the threats leaders fear. Physical posture is funded for the threats they used to fear.

08 — What's at stake

The open door sits right in front of the crown jewels

 Open safe with a large diamond displayed inside on a pedestal.
08 — What's at stake

This gap would matter anywhere. It matters most here, where teams are developing the most sensitive work in the world. When we asked what these leaders most fear losing, AI models and training data top the list, narrowly ahead of client data and proprietary research. No single asset dominates, which means the physical program has to defend a wide front.

Source: Sensitive-workspace study, n=294

What leaders fear losing first

Which types of IP are you most concerned about protecting? (share ranking each #1)

18%
AI models & training data
17%
Client or customer data
16%
Proprietary research, algorithms
16%
Financial / strategic information
13%
Personnel data
11%
Product roadmaps
8%
Manufacturing / lab processes

And the worry runs inward. Two-thirds are concerned about contractors in spaces unsupervised and about insiders exposing information, whether by intent or by mistake. These are precisely the threats a shared identity layer is built to catch, and precisely the ones today’s disconnected stack misses.

Key insight

67% are concerned about insiders intentionally exposing information and 66% about contractors accessing spaces unsupervised, yet under half revoke terminated-employee access within 24 hours. The threats leaders rank highest are the ones their controls handle weakest. The gap sits directly in front of model weights, customer records, and research methods.

09 — The real barrier

The barrier was never budget. It's visibility.

A large green eye partially obscured by a blue and white striped barrier, set against a blue circular background.
09 — The real barrier

The reason the gap persists isn’t cost. When we asked sensitive-workspace leaders why missing controls weren’t in place, the runaway answer was that they had considered them and never prioritized them: 58% said so, nearly three times the share who cited expense. Another 9% didn’t know the more advanced capabilities were an option at all.

Source: Sensitive-workspace study, n=294

Why the gaps stay open: prioritization, not price

Why haven’t you implemented the solutions you didn’t select? Select all that apply. (multi-select)

Considered but not prioritized58%Lack of resources to implement31%Too expensive21%Don't think we need it20%Tools can't support it13%Didn't know it was an option9%

The compliance study reaches the same conclusion from a different angle. When those leaders rank what’s blocking better physical security, complexity of compliance requirements tops the list at 39%, above budget constraints at 32%. The barrier is not the checkbook.

Source: Compliance study, n=782

What’s blocking better security: complexity leads budget

What’s getting in the way of improving physical security? (share ranking each in their top two)

39%
Complexity of compliance requirement
32%
Budget constraints
26%
Fragmented or outdated tools
25%
Fragmentation across our sites
25%
Leadership doesn't prioritize it
22%
Lack of dedicated staff

Asked what they actually need, teams point straight at the missing layer: real-time visibility into who’s on-site, integration between physical and cyber, and a single identity that persists across sites. The conviction is already there.

Source: Compliance study, n=782

What teams say they need most

What physical security capabilities does your organization need most? (share ranking each in their top two)

Real-time visibility into who's on-site30%Integration between physical and cyber28%Faster incident response27%Automated compliance logging25%Better visitor / contractor ID verification25%A single identity record across all sites25%
Key insight

The case for action is already made inside these organizations. The blocker is prioritization and complexity, not conviction or money. Across seven advanced controls in the sensitive-workspace study, 13 to 16% of leaders didn’t even know the capability existed. You can’t prioritize what you don’t know to ask for.

Close the gap. Know who is in your building.

The conviction is already there. The fix is connecting the front door, not spending more: one visitor record, modern sign-in, watchlist screening, and access that ends the moment someone leaves. Envoy protects the places the world relies on most.

Talk to Envoy →

Who we surveyed

Two independent studies, nearly 1,100 leaders, analyzed separately and compared.

Research powered by
Gather
Compliance study, n=782

Seniority

Senior Director / Director52%C-level / Chief36%VP / SVP10%Head / VP2%

Department

Physical or corporate security49%IT / IT Security26%Compliance, GRC, or risk23%Facilities2%

Industry

Technology26%Financial Services21%Manufacturing19%Other17%Healthcare11%Energy / Utilities3%Government3%

Company size

1,000–4,999 employees56%5,000–24,99934%25,000+10%

Number of sites

5–19 sites43%2–4 sites28%20+ sites22%1 site7%

79% were the primary decision maker for physical security, and 86% described their knowledge of protocols and spend as extensive.

Sensitive-workspace study, n=294

Seniority

C-level53%Director29%Chief5%Head of function4%SVP / EVP4%VP4%

Research domain

Frontier AI / ML41%Applied AI / ML35%Defense / national-security tech9%Medical device R&D7%Other regulated R&D4%Pre-clinical / gene-editing4%

Geography by region

Northeast62%South35%West2%Midwest1%

All respondents worked in technical departments, product and engineering, per the study’s screening criteria, and all held direct physical-security responsibility. 87% operate under formal hybrid or flexible work policies. Company size skewed mid-market to enterprise, with roughly three-quarters at 501 or more employees. Geographic breakdown is drawn from panel-provider data for this sample.

Methodology

This report draws on two independent surveys Envoy commissioned in 2026, analyzed separately and compared rather than pooled. Where both asked a comparable question, the two figures are shown side by side and never combined into a single blended number.

The State of Physical Compliance study surveyed 782 US-based enterprise leaders in physical security, compliance and GRC, IT security, and facilities, fielded June 2–30, 2026. Respondents were Director level or above at organizations with 1,000+ employees operating multiple physical sites, and were the primary decision maker for or a significant influence on physical security tools, vendors, or compliance programs. Cross-tabs are available by team, accountability, industry, company size, and number of sites.

The Sensitive-Workspace Threat study surveyed 294 Director-and-above leaders at US organizations operating labs, R&D, and other high-sensitivity facilities, including frontier and applied AI, defense and national-security technology, and medical-device and pre-clinical research, fielded May 27–June 7, 2026.This study segments by research domain rather than industry.

Percentages reflect unique respondents who selected each option, rounded to whole numbers. Multi-select and ranking questions can sum above 100% and are labeled accordingly; single-select breakdowns sum to 100% within rounding. Net-agree and net-concerned figures combine the top two response options. All numbers trace to the structured survey data.