Physical, virtual or bio security?
Physical as in you need some verification cards or some tokens to get in.
Virtual, something of a password.
Biological stuff, your blood, your DNA, whatever you can think of.
I'm thinking of a door.

I once read somewhere how they bypass a door using some materials that generate heat. That door only opens from inside. In order to bypass it, you need to generate the heat from inside so that it opens automatically. So that fellow, using some common materials, triggered the heat sensor and tada! The door opens. He now has access to great secrets in that room. Without keys, pass or any verification of any sorts. Maybe you can try to think of something that probably disable such products so that it won't be repeated again or prevent such incident from happening.
And about how to start. What factors to consider? Like what percentage of false positive and false negative is allowed? Is it possible to implement it? What kind of things and data are they protecting? Are there any financial considerations? Who are the people affected?
Is there a time limit? As in does this product only lets you access the data or stuffs during a certain time and must be completed within a time frame? If yes, what will happen if they do not do so? How do they get out of that situation?
And bla bla bla..... run out of ideas already.

Sounds so PBL.

Enough to start hor?
