Exercise one: Response time

Most front desks sit just steps from the front door. Before reading any further, let's do a small practical exercise. The point is not to test how fast you can move. The point is to experience how time feels when a simple defensive action has to happen immediately. 

Sit in a chair 20 feet from your front door. Get a stopwatch, and when you're ready, start the timer. Stand up and walk, do not run, to your front door and lock it completely, deadbolts included. If you have an alarm, go through your full alarm process. Return to your starting position, sit back down and stop the timer. Hold on to that time. 

An incident that changed how we see physical security 

According to public reporting, on July 28, 2025, at 6:26:52 p.m. ET, early warning detection cameras began tracking an assailant who later targeted a corporate headquarters in Midtown Manhattan, New York City. The suspect was captured on security cameras double-parking his vehicle, then crossing the plaza carrying a weapon. The building's threat-detection software reportedly flagged the suspect as he crossed the plaza, triggering an alert for security personnel approximately one minute before police were first notified. 

By approximately 6:28 p.m. ET, the suspect entered the building, gained access to the elevators and made his way to the upper floors. The incident ended within minutes, with multiple lives lost. 

Not every question about the response has been answered, but the incident raises a larger one: when an alert is generated, what has to happen next? Detection, by itself, is not the same as prevention. Without coordinated action, an alert may become observation rather than protection. 

Now look at your time from the exercise. Was it under a minute? If so, you just proved the point: meaningful defensive action can happen quickly when the task is clear, the authority exists, and the response has been rehearsed. 

That is what makes the incident so important. The question is not whether one minute is enough time to do everything. It is whether an organization has a connected, rehearsed process that can turn a warning into action. 

Incidents like this can involve a breakdown in communication, whether between systems, people or both. In many cases, technology becomes an evidentiary source that helps explain what happened, what may have been missed and where a response window may have existed. The harder question is not whether technology can detect a threat. It is whether detection can reliably become action. 

What is physical security, and why hasn't it kept up? 

Physical security is the discipline of protecting people, property and assets from physical threats, whether criminal, environmental or accidental. It includes access control, surveillance, security personnel, perimeter design and emergency response. At its core, physical security answers one question: how do we prevent, detect and respond to a threat before it causes harm? 

That question has existed as long as buildings have had front doors, but the tools and thinking behind it have changed dramatically. 

Physical security has evolved from locks, guards and fences to electronic access control, networked cameras, cloud storage, AI-powered video analytics, counter-drone systems and integrated platforms capable of processing thousands of signals at once. The discipline has evolved, but the operating model behind it often has not. 

The challenge is that many organizations adopted these tools incrementally but never redesigned their operating model to determine how those tools should work together or what should happen when one of them generates an alert. That is where the gap starts to show. 

If the first exercise showed how much can happen in a short response window, the second asks a different question: does your workplace actually create that window? 

Exercise two: Pressure test 

This time, stay seated. Mentally walk through your office, your building or your campus. On paper, the environment may feel secure: cameras record, badges control access, doors lock, guards are present and policies exist. But assumptions change under pressure. If someone were moving with speed, surprise, intent and physical capability toward a specific point, which controls would actually slow them down, who would be alerted and what response would begin before they got there? 

This is not a critique of your security team. It is a defensive planning exercise based on a simple security reality: when intent, access and delayed intervention overlap, risk increases. The goal is to separate the feeling of security from the mechanics of protection. 

The variable within your control is the ability to create time, distance and action. Control the controllables.  

The convergence of physical and cybersecurity 

Structurally merging physical and cybersecurity functions is called convergence, and it is not a new concept. In the traditional model, physical security and cybersecurity typically operate through separate tools, separate teams and separate approval processes, even when their work affects the same people, facilities, systems and risks. 

This creates a fragmented security model where each team may make sound decisions within its own lane, but no one has a complete view of how those decisions interact across the organization. Threats do not stay in one lane. Your response cannot either. 

The gap is not only between physical and cyber teams. It is between what systems see and what people do next. Closing that gap, from the moment a system identifies a threat to the moment a prepared team responds, is the real goal of convergence. 

The next stage is not simply placing both teams under the same reporting structure or connecting more systems together. True convergence means creating a genuine partnership between the two functions: shared risk language, pooled technology, coordinated response processes and clear lines of accountability. That is the shift from convergence to holistic security. 

Why AI makes this urgent 

AI adds urgency to that shift. As physical security platforms become more automated, the question is no longer only whether the technology works. In the corporate headquarters incident, the detection technology appeared to work. The larger question is whether detection can trigger a coordinated response in time to matter. 

Security maturity is no longer only about structure or technology. It is about outcomes, governance and accountability across both human and machine-driven decisions. An AI system that detects a threat and generates an alert that no one acts on may not make an organization safer. It has only made the organization faster at creating evidence after the fact. 

What this looks like in practice 

Modern physical security tools now include executive digital protection, narrative intelligence and disinformation monitoring, AI-driven access control, video analytics and counter-drone solutions. These capabilities matter most when they expand the time available to assess, decide and act. 

Return to the corporate headquarters incident. Activity before the suspect arrived on property raises an important point: the strongest security model is not one that collects every possible signal. It is one that uses approved indicators responsibly, governs them within appropriate privacy, legal and civil-liberties frameworks and connects them to clear decision-and-action pathways. When that happens, the opportunity to intervene can expand. 

At arrival, that preparation matters. Doors may lock automatically based on approved protocols. Security personnel may be notified through established escalation paths. Business continuity plans may already define who acts, who communicates and what happens next. The response is not improvised in the moment; it is the execution of a plan that has already been tested. 

That is not a scenario from a crime drama. These are real, current and achievable capabilities. When they converge with a mature cybersecurity practice and a proven operating model, the outcome shifts from faster reaction to earlier intervention. 

Is one minute enough time to take proper defensive action? It depends on what is ready before the timer starts. With the right tools, governance and operating model, one minute can become enough time to act. 

How WWT can help 

World Wide Technology's Physical Security practice helps organizations determine whether their tools, teams and operating model work together before a real incident tests them. We bring together physical security, cybersecurity, identity, networking and AI technologies in realistic environments, then evaluate how they operate as a system. 

That includes the full signal-to-decision-to-action workflow: AI threat detection, alert escalation, access control response and coordinated team action. WWT can help evaluate whether AI recommendations are trustworthy and auditable, and whether the operating model creates a more usable response time under conditions that reflect the customer's environment. 

That is the difference between systems that detect threats and a security model that helps protect people. If you are ready to move from fragmented security operations to a model you have proven in practice, reach out to the Physical Security team at wwt.com.