Skip to main content

Physical Penetration Testing

Tailgating, cloned badges, an unattended meeting room and a network socket. What a physical assessment actually tests, and the authorisation that has to exist before anyone walks in.

3 min read

Most security spending assumes the attacker is remote. A physical assessment tests the assumption that they have to be.

The exercise is straightforward to describe and uncomfortable to watch: can someone get inside your premises, and once inside, what can they reach?

How people get in

Rarely by defeating a lock. Almost always by defeating a person.

  • Tailgating. Following someone through a controlled door. Carrying two coffees and a laptop bag makes it easier, because holding the door is politeness and challenging a stranger is confrontation.
  • Pretext. Arriving as a contractor, an auditor, a courier, a fire-safety inspector. A visible jacket and a clipboard outperform most technical attacks.
  • Credential cloning. Many access cards still use formats that can be read at conversational distance and rewritten to a blank.
  • The unlocked route. A propped fire door, a smoking area entrance, a loading bay, a shared-tenancy floor with one weak neighbour.

What matters is what happens next

Getting in is usually the easy half. The assessment's value is in what is reachable afterwards, and it is here that most organisations are surprised:

  • Network sockets in meeting rooms and reception areas, live and unfiltered.
  • Unlocked workstations, which on a walk through an open-plan floor at lunch are rarely absent.
  • Printed material — on desks, in trays, in unshredded bins.
  • Wiring cupboards and server rooms with the same badge that opened the front door, or with no lock at all.
  • Whether anyone challenges a stranger. Frequently nobody does for hours, and that finding is about culture rather than controls.

The authorisation is not a formality

Everything here would otherwise be trespass, and possibly worse. Before anyone approaches a building:

  • A signed authorisation letter each tester carries, naming the premises, the dates, the scope, and a person who will confirm it.
  • That person reachable at any hour, with a phone that is answered. A tester detained by your own security at midnight needs someone who picks up.
  • Written permission from the building owner where you do not own it. A tenancy agreement is not authorisation to test shared areas.
  • An agreement on what happens when they are caught — because being caught is a successful outcome, and the exercise should end with a conversation rather than the police.

Landlords, shared receptions and neighbouring tenants are where this most often goes wrong, and they need settling in writing before the engagement, not during it.

Where it fits

Physical testing is often an initial-access route inside a wider red team rather than a standalone purchase — see what a red team assessment involves. Standalone is right when the question is specifically about premises: a new office, a data centre, a site handling something sensitive.

It is the most expensive access route to include, because it needs people travelling and on the ground, and it carries real personal risk for them — which is part of why it is priced the way it is. See what a red team engagement costs.

What comes back

A timeline with photographs: entered at this time by this route, reached this floor, plugged into this socket, obtained this, left at this time, challenged by nobody or by someone at this point.

It is the most immediately persuasive report in security, because it needs no translation. A photograph of a tester sitting at an unattended desk in your office argues for itself.