// 08 · PHYSICAL PENETRATION TEST
Physical penetration test
A physical penetration test is an attempt to break into your premises, not a review of locks and cameras. We try to get inside through the reception desk, on someone else’s access card, or by following an employee through the door, and from there to reach your data or your network. Internally we call it physical red teaming; it is another name for the same work.
// 01
What a physical penetration test is and what it isn’t
It is an attempt to get into your premises without the knowledge of the people on site, carried out on your order and under rules agreed in writing. It is not a physical security audit, that is, a walk-through of the building with a list of what could be improved, and it is not a security guard service. The difference is that an audit assesses the measures on paper, while the test tries to get around them.
The practical consequence: from an audit you leave with a list of recommendations, from a test with a record of who let us in, at what time, and what we managed to do inside. Both make sense, but they answer different questions and they cost different amounts.
// 02
The scenarios we use
Social engineering at the reception desk: we arrive as a job applicant, a courier, or a visitor arranged with someone who happens to be away. That checks whether reception announces visitors and whether it asks to see identification. A technician or supplier visit is the same principle with work clothes and a pretext, that is, an invented but believable reason for being there.
Tailgating means walking through a door behind an employee who has just tapped their card. That tests a habit, not the technology: the door stops anyone without a card, but not the politeness of someone who holds it open for the next person. A dropped USB drive and a QR poster check what an employee does with a find: whether they plug the USB in and whether they scan the code.
Which access media we try depends on what you use. With older contactless cards, the work builds on the fact that their contents can be read from a short distance, because their encryption has been publicly broken since 2008. With newer systems the more interesting part is card management: how many extra cards are issued, whether they are taken back when an employee leaves, and what the cleaning staff’s card opens.
// 03
What happens when we get inside
The goal isn’t a photo in the server room but demonstrable access to something of value. We check whether there is an empty meeting room with a network socket, whether workstations are locked when people walk away from them, whether documents are sitting in the printer, and whether it is possible to leave with a laptop without anyone noticing.
Access gained to the network is the beginning, not the goal. What follows is the continuation of the attack in the network, the cyber part, where one socket becomes a path to the data. If you want that continuation, say so at the start, because it changes the scope and the length.
Inside we keep to the rules as strictly as outside. We don’t open other people’s deliveries, we don’t enter the premises of other tenants, and we don’t take anything away permanently. When we borrow something as evidence, we return it the same day and it is in the report.
// 04
The rules we don’t start without
Four things, all in writing. An authorization letter for the test signed by an officer authorized to sign for the company. A definition of the areas, sites, and time windows in which we may work. A list of the people going on site, by name. And an emergency contact reachable throughout the test, including at night if testing runs into the evening.
On top of that, a document to identify ourselves with if someone detains us; in the jargon it is called a get out of jail free card. It contains the tester’s name, the scope of the authorization, the name and phone number of the responsible person on your side, and the signature of the signing officer. Every member of the team carries it physically at all times.
If you don’t own the building, we also need the consent of the landlord or the building manager. The test cannot avoid the common areas and the building’s access system, which are not yours to decide about. The same goes for premises shared with other tenants. Have your own lawyer assess the legal framework; we don’t rule on the lawfulness of a particular test.
// 05
What if security guards detain us
Being detained isn’t a failure of the test; it is one of the results, and we record it with the time. The procedure is always the same: the tester stops playing the pretext, identifies themselves with the authorization letter, and asks for the contact for your responsible person. That person calls back and confirms the test was ordered. We never run and we never pretend it is something else.
That is why we need an emergency contact who picks up the phone even at 10 p.m. The risk isn’t being detained as such; it is that nobody can reach the responsible person at that moment and the situation escalates for no reason. We also agree in advance whether the security company should be told about the test, or whether it is the security company that is being tested.
// 06
What you get as the deliverable
The entry timeline: when we arrived, what we identified ourselves with, who let us in, how far we got, and at what time someone challenged us. Along with that, photo documentation as evidence, a description of how security guards and staff reacted, and a proposed set of measures ordered by what actually closes a path, not by price.
We handle the records carefully. We photograph spaces and evidence, not people, and if someone does end up in a shot, we cover the face in the report. We hand the material only to the responsible person, we delete our copies after handover, and we agree on the deletion deadline in advance. The brief also includes a list of the testers by name, so you know in advance who from the team goes on site.
// 07
When a physical test makes sense
Most of all in operations where physical access has a direct impact on manufacturing or on data: factory floors, healthcare facilities, data centers, branch networks, and offices shared with other tenants. What they have in common is that people nobody knows personally come in every day, from cleaning staff to service technicians. The number of sites and the range of permitted scenarios are also what decides the scope of a physical intrusion.
The team that goes on site is put together to fit the scenario. Radio systems call for one specialty, lock opening another, access control systems another, and social engineering another, so the team is assembled according to what the test is meant to try. At each site we spend at least 6 days: the scenario is built from observing who comes into the building, in what rhythm, and what nobody there finds strange, and that can’t be worked out in one afternoon. Reconnaissance, preparation, and evidence processing are added separately for each visit; the report is written once for the whole operation.
It makes no sense where you haven’t yet dealt with the basic entry rules, that is, when you have no visitor log and no cards. The test would confirm the expected. And if what interests you most is how employees behave on the phone and over email, vishing and remote scenarios are a cheaper and faster route.
The physical test is one of the two layers of a red team operation and can be ordered on its own or as part of a larger scenario. How it fits into the whole red team operation is described on the red teaming page.
// 08
How we classify findings
| Severity | CVSS | Handling |
|---|---|---|
| Critical | 9.0 – 10.0 | Immediate escalation |
| High | 7.0 – 8.9 | Summary within 24 hours |
| Medium | 4.0 – 6.9 | Included in the final report |
| Low | 0.1 – 3.9 | Remediation recommendation |
// 09
Frequently asked questions
// INCLUDED WITH EVERY ENGAGEMENT
Free one-time data leak check
With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.
How continuous leak monitoring works// NEXT STEP
A break-in starts with planning, not with showing up at the building.
Give us your email address and we’ll get back to you: on the call we find out how many sites you have, who will know about the test, and which officer authorized to sign for the company will sign the authorization letter. We don’t set out for the building without it.