Skip to content
Service 14

Physical Penetration Testing

On-site testing of buildings, badges, and desks — tailgating, cloning, and unlocked rooms that skip every network control you own.

The attack that skips the firewall

The expensive stack in the rack does not matter if someone walks past it. A held door, a cloned badge, or an unlocked workstation is a foothold that required none of the skill a remote compromise does — and it lands an attacker on the side of every control you spent the year tuning.

We test that path under written rules of engagement: which sites, which hours, what we are allowed to touch, and who can call it off. The goal is not theatre. It is to show you which physical control actually failed, and what an attacker could reach from there.

What we test

Tailgating and reception. Whether a stranger with a plausible reason — a delivery, a visitor badge, hands full — gets through a controlled entrance without ever authenticating.

Badges and access control. Whether a badge can be cloned, whether a reader fails open, and whether the zones you think are locked actually are.

Once inside. Unlocked screens, visible credentials, an open comms room, a desk that is still logged in. The finding that changes the conversation is rarely the door. It is the workstation on the other side of it.

Detection and response. Whether anyone challenged us, how long it took, and whether the process you have written down was the process that ran.

We have written this out before, including why physical testing gets skipped and why the breach often skips the Wi-Fi. This page is the engagement those posts describe.

How it sits next to other tests

On a red team, physical access is one way in, not the whole point. The objective might be domain compromise or a specific data set; the door is a means.

On a social engineering campaign, in-person pretext can be in scope without a full building test. If you want email and voice first, start there.

If the question is “can someone walk into this site and sit down at a desk,” this is the test.

What you receive

A site-by-site account of what worked, what was challenged, and what an attacker would have gained had they kept going — plus the specific control changes that would have stopped us. We do not name the employees who held the door unless you require it. The process is the finding.

Common questions

Physical Penetration Testing — what clients ask

Will you force doors or damage anything?
No. The engagement is designed so it does not. We agree hard boundaries in writing — which sites, which hours, which rooms are off limits, and what “caught” looks like. Destructive entry, alarms we cannot reset, and anything that endangers people is out of scope by default. If a check carries real operational risk, we stop and ask.
Does the whole company know we are coming?
Usually not, beyond a small group of authorized approvers who can confirm the activity is ours if security or police get involved. The value of the exercise is watching a genuine response. Those approvers must be reachable throughout, because an unannounced test mistaken for a real incident wastes everyone’s night.
How is this different from a red team or a phishing test?
This engagement is about the building: doors, badges, reception, comms rooms, and the workstation an attacker sits down at once they are inside. A [red team](/services/red-teaming/) uses physical access as one thread of a larger objective. [Social engineering](/services/social-engineering/) covers phishing, vishing, and in-person pretext without making the site itself the target. If you only want to know whether someone can walk in, start here.

Strengthen your defenses.

Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.

Request a quote