1. Learn
  2. Align
  3. Perform
  4. Review

Perform7 min read

The Badge Swipe and the Log Entry Belong to the Same Investigation

By J Damien Scott, Trusted Advisor

A badge log and a data loss alert can describe the same person on the same afternoon and still end up in two different case files. Convergence gets endorsed in a mission statement and then quietly reverts to two departments that report through different chains, hold different budgets, and keep different records.

Why the Split Persists

A badge log and a data loss alert can describe the same person on the same afternoon and still end up in two different case files. Picture the pattern: an employee badges into a data center after hours, a visit that is unusual but not unheard of, and Physical Security logs it without much thought. Three weeks later, a data loss prevention tool flags a large file transfer to a personal cloud account from that same employee’s login, and the Security Operations Center opens a ticket. Nobody connects the two events, because nobody is looking at both of them. Physical Security closed its file after the after-hours visit resolved itself administratively. Cybersecurity is now investigating a data exfiltration event with no knowledge that the same person was alone in a sensitive space three weeks earlier. Two partial pictures. No complete one.

Every reason the split exists is individually rational. Physical Security and Cybersecurity typically sit in different budget lines, often under different executives, which means each optimizes its own tooling and its own metrics rather than a shared outcome. Each has its own case management system, so a physical access anomaly and a digital anomaly rarely land in the same record even when they describe the same person. Legal review of a personnel matter usually engages after one side or the other has already escalated internally, which means the case has often taken its shape before anyone with authority over both domains has seen the whole picture.

None of that is misconduct. It is what happens when nobody owns the seam between two competent, well-run functions.

What Convergence Actually Means

The Cybersecurity and Infrastructure Security Agency treats insider threat mitigation as an inherently multidisciplinary function, combining physical security, cybersecurity, personnel awareness, and information handling into a single program rather than three adjacent ones (CISA, 2020). CISA’s January 2026 guidance on assembling a multidisciplinary insider threat management team structures the effort around a four-phase Plan, Organize, Execute, and Maintain framework built explicitly around cross-functional membership rather than a single department’s ownership (CISA, 2026).

The financial sector arrived at a version of this conclusion on its own. A 2018 best practices guide from the Securities Industry and Financial Markets Association, prepared with Sidley Austin LLP, put it plainly: insider threat is as much a human problem as a technology one, and effective programs require cross-organizational participation that goes beyond Information Technology to include Human Resources and Internal Audit (SIFMA, 2018). Carnegie Mellon’s CERT National Insider Threat Center, which has built its research program on a database of more than 3,000 real insider incidents, draws its indicators from the same multidisciplinary set: Human Resources, Legal, Physical Security, Information Technology, and Information Security together, not in sequence.

The Ponemon Institute’s most recent global insider risk research found that containment taking longer than 90 days carried an average cost of $21.9 million, against $14.2 million when containment happened in under 30 days (Ponemon Institute, 2026). That gap is not a technology gap. It is a coordination gap, and coordination is exactly what a converged case record buys back.

The Unit Is the Case, Not the Team

Three things make a case genuinely converged, and none of them require a reorganization. First, a shared indicator set: Physical Security and Cybersecurity need a jointly agreed definition of what counts as a concern worth cross-checking, in both directions. An unusual after-hours access and an unusual data transfer should each be a prompt to ask what the other domain’s records show for the same person, not a private data point that stays inside one system.

Second, a single case record of authority. When both domains hold information about the same individual, one record has to be the record, with both contributions logged into it, rather than two systems that happen to reference the same name.

Third, one escalation path that ends at a person. Convergence fails quietly when the escalation path ends at a committee rather than a named decision owner who can see the whole file and act on it.

Evidence Handling Across the Seam

Badge access logs and video are typically retained as ordinary business records under a records retention schedule. Digital forensic evidence, once a case moves toward referral, subpoena, or termination, has to meet a higher bar. The international standard for handling digital evidence requires that identification, collection, acquisition, and preservation each be performed so that an independent third party could reconstruct the entire process, using verified copies rather than originals and cryptographic hashing to prove nothing was altered along the way (ISO/IEC 27037:2012).

A badge swipe log was never built to that standard, and it does not need to be, until the moment a case crosses from internal review into something that might end up in front of a regulator or a court. The organization that has not decided, in advance, when that threshold is crossed will make that decision badly, under pressure, in the middle of an active case.

Bank examiners and internal audit are increasingly less interested in what happened during an incident and more interested in who owned the decision and how it was documented. A converged case file answers that question cleanly. Two partial files, each defensible in isolation, do not, and the gap between them is exactly where an examiner’s next question will land.

GRC & OperationsConverged SecurityInsider ThreatPhysical-Digital IntegrationCase ManagementISO/IEC 27037

Originally published on LinkedIn. Read it there

Field Notes · by email

One email when a new article publishes. Nothing else.

Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes