Physical Security
On-site testing — Authorized on-site testing of the controls between a stranger and your network: reception procedure, badge and door controls, tailgating resistance, unattended workstations, and what a visitor can plug in once they are past the lobby. Physical scopes are always custom — the variables are the site, not a checkbox.
Is this the right engagement?
- You hold sensitive data or systems in offices, labs, data centres or retail sites
- You have badge access and no evidence that it stops anyone determined
- You are running a red team and need a physical entry vector
- An auditor or insurer has asked for physical control validation
Deliverables
- Entry narrative documenting every attempt, successful or not, with timestamps and photographic evidence
- Control findings across perimeter, reception, badge systems, doors and internal segregation
- Post-entry network access findings where in scope
- Staff response observations — who challenged us, and who did not
- Executive summary with prioritized physical control recommendations
- Live debrief with facilities and security leadership
Engagements in this solution
Each engagement is scoped around what you are actually running. Where pricing is standardized you can estimate it online in a couple of minutes.
How the work is run
The same sequence runs underneath every engagement in this solution — specialised here for physical security.
Scope & authorize
Sites, entry windows, authorized techniques and out-of-bounds areas agreed in writing. Authorization letters issued to every tester before travel.
Reconnaissance
Open-source and on-site observation of access patterns, shift changes, contractors and physical layout.
Attempt entry
Covert entry attempts using the authorized techniques — tailgating, pretexting, badge cloning where authorized — with every attempt logged.
Test post-entry
Where authorized, assessment of what is reachable once inside: network ports, unattended workstations, documents and server areas.
Report & brief
Entry narrative with evidence, control findings, and staff-response observations, walked through with facilities and security.
Remediate & retest
A bounded return visit validates the control changes you make.
What to expect, and when
Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.
| Stage | Duration | What happens |
|---|---|---|
| Scope & authorize | 1–2 weeks | Sites, techniques and authorization agreed in writing, including landlord permission where the site is shared. |
| Reconnaissance | 1–3 business days | Observation of access patterns, shift changes and physical layout. |
| On-site testing | 1–5 business days per site | Authorized covert entry attempts and post-entry assessment. |
| Report & brief | 3–5 business days | Entry narrative with evidence, control findings and staff-response observations. |
| Total | 4–8 weeks | From signed authorization to debrief, depending on site count and travel. |
What you can hold us to
Commitments that are checkable, not adjectives.
Every tester carries signed authorization and named escalation contacts for the duration of the engagement.
Failed attempts are reported alongside successful ones — the controls that worked matter as much as the ones that did not.
Response observations are reported by role and location, not by individual.
A named contact can halt the engagement at any point, for any reason.
Physical engagements are always scoped per site — we do not publish a rate card for work this variable.
Before you ask us
Do we have to tell staff?
No — that is the point. A small number of named contacts know, so the engagement can be stopped if needed.
What if someone calls the police?
Every tester carries a signed authorization letter and your named contacts are reachable throughout. This is exactly why that paperwork is non-negotiable.
Can you test multiple sites?
Yes. Multi-site engagements are scoped together, and travel is quoted transparently.