What Happens to Our ‘Zero Trust’ Access Control if the Internet Goes Down?

In the evolving landscape of security, the buzzword on everyone’s lips is “Zero Trust.” For businesses and high-end residential estates in Cape Town, transitioning to a Zero Trust architecture represents the gold standard in protecting assets, data, and people. But as we lean more heavily on cloud-integrated systems, a critical question arises—one that is particularly poignant in the South African context of loadshedding and infrastructure challenges: What happens to our security when the internet goes down?

At B & L Services, we’ve spent 20 years bridging the gap between cutting-edge technology and real-world reliability. In this article, we dive deep into the mechanics of Zero Trust access control, the risks of cloud dependency, and how a professionally designed system ensures you are never locked out (or left vulnerable) during a digital blackout.

Understanding Zero Trust in the Physical World

To understand the impact of an internet outage, we must first define what Zero Trust actually means for physical access control.

Traditional security operated on a “Perimeter” model. Once you had the key to the front gate or the correct RFID badge for the office, the system “trusted” you. Zero Trust flips this script. It operates on the mantra: “Never Trust, Always Verify.”

In a physical security environment, this means that every time a person attempts to open a door, use a lift, or enter a restricted zone, the system verifies their identity, the health of their credentials (e.g., is their mobile phone updated?), and the context of the request (time of day, location, and previous behavior) before granting access.

This verification process often happens in the cloud, where massive databases and AI-driven security engines process the data in milliseconds. But when the “pipe” to that cloud is severed, the system’s “brain” is suddenly miles away and unreachable.

The South African Context: Why This Question Matters

In Cape Town, “the internet going down” isn’t a rare occurrence—it’s a weekly logistical hurdle. Whether it’s a fiber break during roadworks, a service provider outage, or the inevitable fallout of Stage 4 or 6 loadshedding affecting local cell towers and exchange points, our connectivity is under constant pressure.

For a business owner or a body corporate, the fear is twofold:

The “Lock-Out” Scenario: Your staff or residents can’t get into the building because the system can’t “verify” them.

The “Open-Door” Scenario: The system defaults to an “unlocked” state to prevent people from being trapped, leaving the premises wide open to intruders.

Neither is acceptable. This is why the technical design of your access control system—specifically how it handles “Offline Mode”—is the most important part of your security strategy.

The Anatomy of an Offline Zero Trust Event

When the internet connection to your site is lost, a modern, well-installed Zero Trust system doesn’t just “stop.” Instead, it enters a state of Local Autonomy. Here is how the technical layers respond:

A. The Role of the Intelligent Controller (The “Edge”) In a cheap or “dumb” access control setup, the reader at the door is just a pass-through device. It sends data to the cloud and waits for a “Yes” or “No.” If the cloud doesn’t answer, the door does nothing.

B & L Services specializes in Edge-based computing. We install intelligent controllers—devices that sit on-site, usually in a secure server room or inside the door housing—that possess their own processing power and memory. These controllers “download” the rules from the cloud while the internet is active. When the connection drops, the controller takes over, acting as a local backup of the cloud’s logic.

B. Credential Caching How does the system know who is allowed in without checking the main database? The answer is Caching.

Modern Zero Trust systems maintain a “Local Cache” of the most recent and most frequent users. If you work at the office every day, your encrypted ID is stored directly on the local controller. Even if the fiber line is cut, the controller recognizes your badge or smartphone token because it “remembers” you from the last successful cloud verification.

C. Asynchronous Synchronization Once the internet is restored, the system performs a “handshake.” It uploads all the logs of who entered the building during the outage to the cloud and downloads any updates (such as a fired employee whose access was revoked while the system was offline). This ensures that your audit trail remains unbroken.

Fail-Safe vs. Fail-Secure: The Critical Choice

When the internet goes down, and potentially the power goes with it, your hardware has to make a physical choice. This is a distinction we often discuss with our clients during our site assessments.

Fail-Secure (Locked): If power or communication fails, the door remains locked. This is essential for high-security areas like IT server rooms or jewelry safes. You need a physical override (like a manual key) to get in.

Fail-Safe (Unlocked): If power fails, the magnetic locks release, and the door opens. This is a legal requirement for fire escape routes and main exits to ensure that people can flee a building during an emergency.

In a Zero Trust environment, we use intelligent fail-overs. We can program the system to remain “Secure” but allow “Cached” users in, ensuring that business continues as usual without compromising the perimeter.

Potential Vulnerabilities During Outages

While “Local Autonomy” keeps the doors moving, we must be honest about what is lost when the internet goes down. Zero Trust is about continuous verification. Without the internet, the system loses:

Real-Time Revocation: If you terminate an employee’s access in the cloud, but the local controller is offline, that employee might still be able to use their cached credentials for a few hours until the system re-syncs.

Remote Management: You won’t be able to “buzz” someone in via your smartphone app from home if the site’s internet is down.

MFA (Multi-Factor Authentication): Some high-security systems require a push notification to a phone. If the building has no internet and the cell towers are congested due to loadshedding, this second factor may fail.

B & L Services’ Solution: We mitigate these risks by installing redundant communication modules. This can include a 4G/LTE failover that kicks in the second the fiber line goes dark, ensuring that even during a total ISP failure, your “Zero Trust” remains connected to the global security grid.

Engineering for Resilience: The B & L Methodology

At B & L Services, we don’t just “install” a brand; we engineer a solution for the Cape Town environment. When we design a Zero Trust access control system, we follow a strict checklist to ensure internet outages don’t become security breaches:

Battery Backups and UPS Integration Electronic locks and controllers require power. Without a robust UPS (Uninterruptible Power Supply) or inverter system, “Internet Down” usually means “Power Down” too. We ensure your security hardware is the last thing to turn off during loadshedding.

Hybrid Cloud Architecture We recommend systems that offer a “Hybrid” approach—combining the flexibility of the cloud with the ruggedness of an on-site server. This provides the best of both worlds: ease of management and 100% local uptime.

Encrypted Local Storage Zero Trust relies on encryption. We ensure that the “Cached” data on your local controllers is as encrypted and secure as the data in the cloud, preventing hackers from trying to “spoof” the system while it’s in offline mode.

Regular Maintenance and Testing A security system is only as good as its last test. Our maintenance teams perform “simulated outages” to ensure that the controllers transition to offline mode seamlessly and that all cached credentials work as expected.

The Role of CCTV Integration

When the internet goes down, and your access control enters “Offline Mode,” your visibility is often reduced. This is where integrated CCTV comes into play. By using local NVRs (Network Video Recorders) rather than purely cloud-based cameras, B & L Services ensures that your cameras keep recording to a local hard drive even if they can’t stream to your phone.

Once the internet returns, the system “back-fills” the footage to the cloud, allowing you to see exactly what happened during the outage.

Why “Off-the-Shelf” Fails Where We Succeed

There are many “Smart Locks” and DIY access control kits available today. Most of these are “Cloud-Only.” If the internet goes down, these devices often become useless or revert to a simple PIN code that is easily bypassed.

For a commercial facility, a retail store, or a residential estate in the Western Cape, these DIY solutions are a liability. B & L Services leverages 20 years of technical experience to select reputable brands—like Dahua, Hikvision, Impro, and ZKTeco—that are designed for industrial-grade reliability. We understand the specific components that can withstand the power surges and connectivity fluctuations unique to our region.

Future-Proofing: AI and the Offline Frontier

The future of Zero Trust is moving toward even smarter “Edge” devices. We are already seeing AI-powered cameras and readers that can perform facial recognition locally without needing to check a cloud database. This means that even in a “Total Blackout” scenario, your face could be your key, and the system would recognize you with 99.9% accuracy based on local data.

As we subscribe to continuous new product training, B & L Services is at the forefront of bringing these “Edge-AI” solutions to Cape Town.

Conclusion: Peace of Mind in an Unpredictable World

So, what happens to your Zero Trust access control if the internet goes down?

If B & L Services installed it: Nothing changes for your users. The gate will still open for the CEO. The residents will still be able to enter the gym. The warehouse will remain locked to outsiders. Your security continues to function because we build systems that respect the reality of our infrastructure.

Zero Trust is a powerful philosophy, but it requires a practical, technical foundation to work in the real world. You need a partner who understands that “The Cloud” is just someone else’s computer—and that computer is sometimes unreachable.

Is your current security system “Cloud-Dependent” or “Resilient”? Don’t wait for the next fiber break or Stage 6 schedule to find out. Reach out to Brad or Lynn at B & L Services today. We’ll perform a comprehensive assessment of your site and ensure that your access control is as smart as it is stubborn.

Your security IS our business.

Ready to secure your premises? Technical Manager (Brad): 082 3766 043 Office Manager (Lynn): 082 099 1103 Email: info@blserv.co.za Website: blserv.co.za

B & L Services – 20 Years of Technical Security Excellence in Cape Town.