Physical Penetration Testing

Most security strategies stop at the network connection. An attacker standing in the server room doesn’t need a vulnerability in your Firewall: they just need thirty seconds alone with a device. We put ourselves in the shoes of potential intruders and assess access controls, building security and the behaviour of your employees – discreetly, professionally and with minimal risk.

Request a trialProcess & Methodology
ONSITE AUDIT
Physical Pentest
Building Security

Test object

Access, buildings, behaviour

Perspective

Unauthorised intruder

Focus

Access Control & Social Engineering

Prerequisites

Written authorisation

What needs to be clarified before the test

A physical pentest is the only type of test where our staff will enter your premises and, if necessary, be stopped by security staff. That is why the framework is set out in writing beforehand, before anything begins.

  • Authorisation – A written authorisation from management or an expressly authorised person. The test will not take place without this document.
  • Proof for the testers – Our staff carry a confirmation document which they can present if approached; this is often referred to as an authorisation letter. It states who commissioned the test and who within the company can confirm that it is taking place.
  • Emergency contact – A person at your organisation who is available throughout the entire test period and can confirm the test is taking place, even at night or at weekends.
  • Scope – Which sites, buildings and areas are included, and which are expressly excluded.
  • Permitted methods – What is allowed and what is not. Common exclusions include damage to doors and locks, approaching customers, and anything that actually disrupts business operations.
  • Termination criteria – When we will terminate the test of our own accord, for example in the event of a genuine emergency in the building or if a situation becomes distressing for those involved.
  • Escalation – How we proceed if the police or security guards are called in. In this case, we reveal our identities and contact your emergency number, rather than continuing to play the part.
  • Circle of those in the know – As small as possible, but not zero. Usually, this comprises management, the person responsible for security and the emergency contact.

One point we address early on: as employee behaviour is being observed, it may be necessary to involve the staff representatives. It is best to clarify this internally with the HR department and legal advice; we will tailor the test framework accordingly.

When a Physical pentest is due

  • A new site or refurbishment has been completed and the access control system has never been tested.
  • ISO 27001 or sector-specific requirements demand evidence of physical security.
  • There is a high volume of public traffic from suppliers, tradespeople, job applicants and visitors.
  • The server room, technical room or archive are located in areas that are openly accessible during the day.
  • Following the loss of hardware or documents, where the route taken remains unclear.
  • The access control system has been modernised and is to be independently audited.
  • An awareness programme is underway and you need a robust baseline assessment.

What we’ll be looking at

Perimeter and outdoor areas
Fences, gates, side entrances, delivery areas, underground car parks, smoking areas and emergency exits. The emergency exit, which is opened from the inside and then held open with a wedge, is one of the most common routes of all.

Access points
Reception, turnstiles, card readers, locking systems, visitor procedures and ID management. We check whether checks are carried out or whether a friendly manner is sufficient.

Interior areas
Unaccompanied routes through the building, access to meeting rooms, separation of floors and the question of whether anyone asks for verification.

Technical rooms
Server room, distribution boards, network cabinets and printer areas. An open network cabinet in the corridor is technically equivalent to an open server room.

Information in the room
Implementation of the ‘clean desk’ policy, unattended and unsecured computers, whiteboards, printed documents, paper disposal and decommissioned data storage media.

Organisation and behaviour
Reaction to unknown individuals, handling of ID cards, reporting procedures and whether a suspicious incident is actually passed on to the relevant authorities.

What we would do

Scenario Procedure
Tailgating Unauthorised tailgating behind an authorised person, without one’s own access card.
Pretexting Posing as a technician, delivery driver, tradesperson, auditor or new colleague, wearing appropriate clothing and presenting a plausible story.
RFID cloning Reading and duplicating unsecured access cards, often from a short distance whilst passing by.
Circumventing access control systems Exploiting technical vulnerabilities in doors, locks and readers, without causing damage and within agreed parameters.
Drop attacks Placing tampered data carriers or cables in locations where they will be found and connected.
Rogue device Connecting one’s own device to a network socket in the meeting room to test network access from the inside.
Access to assets The theft of devices, data storage media or documents – often a matter of minutes.
Paper and Waste Analysing what ends up in wastepaper baskets, waste paper and rejects.

We will agree in advance with you which scenarios will be used.

How a test is conducted

1

Scope & Objectives Definition

Objectives, testing scope, permitted methods, and the legal framework (Rules of Engagement) are defined and confirmed in writing.

2

Remote Reconnaissance (OSINT)

Gathering publicly accessible intelligence: Site layouts, imagery, job listings mentioning security systems, vendor information, and social media photos from inside facilities. These frequently reveal the initial entry scenarios.

3

On-Site Surveillance

We monitor daily operational routines: shift handovers, delivery windows, break times, door usage habits, and areas where personnel pass through without badge verification.

4

Execution

Carrying out the agreed-upon intrusion scenarios. Every action is documented, and each accessed area is logged with exact timestamps.

5

Proof of Access

Instead of disrupting operations, we collect undeniable evidence: photos of sensitive areas reached, route logs, and physical markers left on-site to prove successful access.

6

Debriefing & Roadmap

We walk through the results with your team in a clear, chronological breakdown and derive practical hardening measures from the findings.

How open testing is carried out

Unannounced

Only a very small group of people know about the test. This provides the most realistic picture of behaviour in everyday life, but requires the clearest set of rules in advance.

Announced

Staff know that testing will take place within a certain timeframe, but not when or how. This reduces stress and serves as a good start to an awareness programme.

Assumed Breach

We start with a stage we’ve already reached – for example, gaining access to the visitor area – and continue testing from there. This saves time.

What you need to provide

  • Written authorisation and designation of an emergency contact.
  • List of sites and buildings, including any areas to be excluded.
  • A time slot, with excluded dates where applicable, during which no testing is to take place.
  • Internal clarification of who is to be informed and who is not.
  • Information on whether an external security service is in operation and how they should be dealt with.

That’s all that’s needed. In particular, we do not need floor plans, ID cards or credentials in advance; this would undermine the integrity of the test.

What you’ll take away from this

Chronology of Access Routes: Which intrusion attempt succeeded at what time, and at which specific touchpoints staff or security could have intervened.
Photographic Evidence: Documented proof of secured zones accessed, captured strictly without identifiable individuals.
Risk Assessment per Finding: Required attacker effort weighed against potential operational and data loss impact.
Recommendations in Three Categories: Technical (locking systems, badge readers, CCTV), organizational (visitor workflows, escalation paths), and staff training. Experience shows the highest security return comes from the latter two.

The solution rarely lies in the technology. Often, the door is fine and the person standing in front of it is friendly. This is precisely what can be improved without investing a single euro in hardware.

We do not name any individuals in this report. It is the process that is being assessed, not the colleague who held the door open.

“Physical security vulnerabilities are like open back doors: often overlooked, but with enormous implications.”

Physical Penetration Testing

Let us know the locations and general conditions. We’ll set out all the details in writing before we set foot on site.

  • Non-destructive, with clear termination criteria
  • Tailgating, Pretexting, RFID cloning
  • Timeline with photographic evidence
  • Assesses processes, not individuals

Frequently Asked Questions

What customers want to know before carrying out a Physical pentest.

No. We work using non-destructive methods. Any action going beyond this is expressly excluded.

We will identify ourselves, present the authorisation letter and contact your emergency number. We will cease playing our role at that point.

That’s up to you. Both approaches (unannounced or announced) serve a purpose.

No. The report assesses processes and procedures, not individuals. We do not name any specific individuals in the report.

No. The report assesses processes and procedures, not individuals. We do not name any specific individuals in the report.

That depends on the number of sites, the type of audit and the scope of the work. We will estimate the time required following the preliminary discussion.