Introducing The State of Physical Security & Compliance: What 1,076 leaders told us

New Envoy research reveals where physical security gaps emerge and whether organizations can prove their controls are working.
Sep 22, 2026
Shannon Sweetser
Shannon Sweetser
Content & Social Lead
Introducing The State of Physical Security & Compliance: What 1,076 leaders told us

Organizations have invested heavily in physical security. They have access controls, visitor systems, security teams, policies, and compliance programs.

But there’s a more fundamental question underneath all of that infrastructure: Can you actually prove who was in your building, what they were authorized to access, and whether the right controls were followed?

For many organizations, the answer is less certain than their overall confidence suggests.

That’s the central finding of Envoy’s new research, The State of Physical Security & Compliance. Across two separate 2026 studies of 1,076 security, compliance, and operational leaders, we found a persistent gap between how protected organizations feel and what their systems can actually prove.

The research included 782 enterprise compliance leaders alongside 294 leaders at frontier AI labs, defense technology companies, and biotech and medical R&D organizations, some of the organizations with the most to protect.

Here’s what we learned.

Many organizations still can’t answer a basic security question: Who was here?

Physical security depends on knowing who is inside your facilities. Yet 44% of leaders at high-security workplaces can’t confidently say who was in their building yesterday.

Percentages reflect unique respondents who selected each option, rounded to whole numbers.

That visibility gap isn’t hypothetical. 79% report at least one unauthorized or unverified person entering a workspace where they shouldn’t have been in the past year.

The problem is bigger than whether someone signed in at the front desk. Identity may be verified in one system, authorization determined in another, access granted somewhere else, and presence recorded separately. When those signals don’t connect, teams are left reconstructing what happened after the fact.

Security teams may know what should have happened. Proving what did happen is harder.

Contractors remain one of the biggest identity gaps

Contractors create a particularly difficult challenge because they move between locations, projects, teams, and systems.

Across both studies, 71–72% of organizations give contractors no single identity that follows them across locations. And the problem persists regardless of industry or scale.

Healthcare organizations give contractors a single identity across sites only 22% of the time. Manufacturing comes in at 26%, technology at 30%, and financial services at 31%. No industry clears even one in three.

Scale doesn’t solve the problem either. Even among organizations operating 20 or more sites, only 32% give most contractors a persistent identity across locations.

Without persistent identity, each new site can effectively become a reset. Security teams have a harder time maintaining a continuous record of who someone is, where they’ve been, what they’re authorized to access, and whether required policies and credentials are current.

Confidence is running ahead of coverage

One of the clearest themes in the research is the disconnect between confidence and the controls underneath it.

62% of leaders say they’re very confident they could pass a compliance audit today with zero preparation. Yet the same research reveals significant gaps in identity, access, and presence data.

The pattern becomes even clearer in sensitive workplaces. 58% of leaders believe their security program would stop an unauthorized person from entering, yet only 52% have badge control on sensitive doors and just 47% escort visitors at all times.

There’s also a scale problem. In the enterprise compliance study, audit confidence peaks among single-site organizations, where 71% are very confident they could pass an audit without preparation. Add a second location and that figure falls to 58%.

The more complex the physical environment becomes, the harder it is to maintain a connected record of identity, authorization, access, and presence.

In sensitive workplaces, the stakes go well beyond compliance

For organizations working with intellectual property, regulated information, proprietary research, or national security-related technology, gaps in physical security can have consequences far beyond a failed audit.

Among leaders in sensitive workplaces, 39% have personally seen a visitor or contractor reach a restricted area. Another 28% have seen someone view or photograph work in progress on whiteboards, screens, or prototypes.

The assets leaders are worried about losing reflect what’s at stake. AI models and training data top the list of intellectual property they fear losing at 18%, followed by client data at 17% and proprietary research at 16%.

At the same time, 67% are concerned about intentional insider exposure and 66% about unsupervised contractors, the exact kinds of risks that become harder to manage when identity, access, and presence are disconnected.

As Tim Carr, Senior Security Manager at Attalon, one of more than 16,000 workplaces that use Envoy to support security and compliance, puts it:

"In our facilities, we're not just protecting a building but protecting technology that has national security implications. Knowing exactly who's on-site at any given moment, and being able to prove it after the fact, isn't a compliance checkbox for us, it's core to how we operate. This research confirms what we see every day: confidence in a security program means nothing if you can't actually account for who came through the door."

For organizations protecting highly sensitive work, visibility into identity and presence isn’t just about maintaining a cleaner audit trail. It’s part of protecting the work itself.

From security controls to connected evidence

The takeaway from the research isn’t that organizations lack security controls. In many cases, they have plenty of them.

The challenge is that those controls don’t always operate as a continuous chain.

Identity may be verified in one system, authorization determined in another, access granted somewhere else, and presence recorded separately. Organizations need to connect those signals so they can answer four critical questions: Who was here? Were they authorized to be here? Where did they actually go? Can we prove the right controls were followed?

That’s what turns a collection of security systems into something more useful: evidence.

Because confidence matters, but when an incident happens or an auditor starts asking questions, security teams need more than confidence. They need to be able to prove what happened.

Get the full report

These findings are only part of the picture. The State of Physical Security & Compliance digs deeper into how physical security gaps change across industries and organizational complexity, where sensitive workplaces are most exposed, and what the data reveals about the disconnect between confidence and coverage.

Download: The State of Physical Security & Compliance

And on October 7, we’re taking the conversation further. Join Bridget Scott Akinc, VP of Strategy & Enablement, and Peter McLaughlin, Director of Customer Success, for The State of Physical Security & Compliance: Are You as Protected as You Think? They’ll unpack the research, explore where these gaps emerge, and share real-world examples of what stronger physical security and compliance look like in practice.

Register for the webinar

Smiling woman with blonde hair wearing black top and geometric earrings on pink to yellow background.
AUTHOR BIO
Content & Social Lead

Shannon Sweetser is the Content & Social Manager at Envoy, where she leads content strategy and social storytelling for one of the workplace technology industry's leading brands. She partners with executives, product, and marketing teams to bring the company's story to life through thought leadership, product launches, customer stories, and data deep dives.

Read more

Learn how to run a workplace tornado drill, choose safer shelter areas, account for everyone onsite, and improve your emergency response plan.

A strong fire evacuation plan goes beyond exit routes. Here’s how to plan for alerts, muster points, accountability, response roles, accessibility, and everyone who may be onsite.

This guide breaks down the key response roles every workplace should define, from incident leads and wardens to communications, accountability, and backup coverage.

Active shooter drills should build preparedness without creating unnecessary fear. Here’s how to test communication, decision-making, accountability, and response roles with a safer, more thoughtful exercise.

A successful fire drill is about more than getting people out fast. Here’s how to test evacuation routes, muster points, accountability, and communication so your team is better prepared when it counts.

Find out why we built Envoy Response and how it helps teams turn emerging threats into faster, more coordinated action.