SOLUTION

Physical Security

On-site testing — Authorized on-site testing of the controls between a stranger and your network: reception procedure, badge and door controls, tailgating resistance, unattended workstations, and what a visitor can plug in once they are past the lobby. Physical scopes are always custom — the variables are the site, not a checkbox.

WHO THIS IS FOR

Is this the right engagement?

  • You hold sensitive data or systems in offices, labs, data centres or retail sites
  • You have badge access and no evidence that it stops anyone determined
  • You are running a red team and need a physical entry vector
  • An auditor or insurer has asked for physical control validation
When it is notIf you do not control the building or cannot obtain landlord authorization, we cannot test it — shared-tenancy sites need that sorted before scoping.
WHAT YOU RECEIVE

Deliverables

  • Entry narrative documenting every attempt, successful or not, with timestamps and photographic evidence
  • Control findings across perimeter, reception, badge systems, doors and internal segregation
  • Post-entry network access findings where in scope
  • Staff response observations — who challenged us, and who did not
  • Executive summary with prioritized physical control recommendations
  • Live debrief with facilities and security leadership
THE WORK

Engagements in this solution

Each engagement is scoped around what you are actually running. Where pricing is standardized you can estimate it online in a couple of minutes.

METHODOLOGY

How the work is run

The same sequence runs underneath every engagement in this solution — specialised here for physical security.

Scope & authorize

Sites, entry windows, authorized techniques and out-of-bounds areas agreed in writing. Authorization letters issued to every tester before travel.

Reconnaissance

Open-source and on-site observation of access patterns, shift changes, contractors and physical layout.

Attempt entry

Covert entry attempts using the authorized techniques — tailgating, pretexting, badge cloning where authorized — with every attempt logged.

Test post-entry

Where authorized, assessment of what is reachable once inside: network ports, unattended workstations, documents and server areas.

Report & brief

Entry narrative with evidence, control findings, and staff-response observations, walked through with facilities and security.

Remediate & retest

A bounded return visit validates the control changes you make.

TIMELINE

What to expect, and when

Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.

StageDurationWhat happens
Scope & authorize1–2 weeksSites, techniques and authorization agreed in writing, including landlord permission where the site is shared.
Reconnaissance1–3 business daysObservation of access patterns, shift changes and physical layout.
On-site testing1–5 business days per siteAuthorized covert entry attempts and post-entry assessment.
Report & brief3–5 business daysEntry narrative with evidence, control findings and staff-response observations.
Total4–8 weeksFrom signed authorization to debrief, depending on site count and travel.
HOW WE WORK

What you can hold us to

Commitments that are checkable, not adjectives.

Authorization letters carried at all times

Every tester carries signed authorization and named escalation contacts for the duration of the engagement.

Every attempt logged

Failed attempts are reported alongside successful ones — the controls that worked matter as much as the ones that did not.

Staff never named

Response observations are reported by role and location, not by individual.

Immediate stop procedure

A named contact can halt the engagement at any point, for any reason.

Custom scoped

Physical engagements are always scoped per site — we do not publish a rate card for work this variable.

QUESTIONS

Before you ask us

Do we have to tell staff?

No — that is the point. A small number of named contacts know, so the engagement can be stopped if needed.

What if someone calls the police?

Every tester carries a signed authorization letter and your named contacts are reachable throughout. This is exactly why that paperwork is non-negotiable.

Can you test multiple sites?

Yes. Multi-site engagements are scoped together, and travel is quoted transparently.

Scope this engagement with a Pentester.

This work is scoped per engagement. Tell us what you are protecting and we will come back with a scoped proposal.

Choose which optional cookies BNO Security Group may use. You can update this choice at any time.

Necessary cookiesRequired for security, core features, and consent storage.
Always active
Analytics cookiesHelp us understand site traffic and improve the website.
Advertisement cookiesSupport relevant campaign measurement and advertising.