A physical security assessment tests whether an intruder could get into your premises and, through that, to your systems and data — because physical access defeats most digital controls. Our testers attempt tailgating, badge cloning, lock bypass, access-control evasion and pretext entry, then see how far they can reach: a server room, a live network port, an unlocked workstation, sensitive documents. It is fully authorised, scoped and bounded by rules of engagement, with testers carrying an authorisation letter. Often combined with social engineering and wireless testing in one on-site visit, and a natural component of a full red team.
// 01 What is a physical security assessment?
A physical security assessment tests the controls that protect your buildings, and through them your digital assets. The premise is simple and often overlooked: most of an organisation's security spending goes on digital defences, while an attacker who can simply walk in bypasses almost all of them. So a physical assessment sends skilled testers to attempt exactly that — to get past the perimeter, the reception, the locked doors and the access controls — and then to demonstrate what an intruder could achieve once inside, whether that is reaching a server, plugging into the network, or walking out with sensitive material.
It is the physical-world counterpart to a penetration test, and for organisations with offices, data centres, or sensitive facilities it closes a gap that purely digital testing leaves wide open.
// 02 Why physical security is a cyber issue
Physical access is the ultimate bypass. An intruder who reaches an unlocked, logged-in workstation has whatever access that user has, no password required. One who plugs a device into an exposed network port is inside your network perimeter instantly. One who steals a laptop or a stack of documents exfiltrates data without touching a single digital control. Firewalls, MFA and monitoring are all designed to stop a remote attacker — and all of them are irrelevant to someone standing in your server room. Physical and digital security are not separate disciplines; they are two halves of protecting the same assets, and testing only one leaves the other unverified.
// 03 Techniques we use
Tailgating & piggybacking
Following authorised staff through controlled doors — the simplest and most reliable entry, exploiting politeness and routine.
Badge cloning & access bypass
Cloning or replaying access-card credentials, and bypassing or manipulating electronic access controls.
Lock & door bypass
Defeating physical locks and doors through manipulation and known bypass techniques where scoped.
Pretext entry
Social engineering — assuming a plausible identity (contractor, delivery, visitor) to talk past reception and staff.
Once inside, and only within the agreed rules of engagement, testers attempt to reach high-value targets: server and comms rooms, live network ports, unlocked or unattended devices, printed sensitive documents, and restricted areas — demonstrating the real impact of a physical breach.
// 04 What we commonly find
Tailgating into secure areas
Controlled doors, including to server rooms, routinely held open or entered by following staff — no challenge, no verification.
Exposed live network ports
Accessible network ports in meeting rooms, lobbies or unmanned areas that place an attacker directly on the internal network.
Unlocked, unattended workstations
Logged-in machines left unlocked, giving instant access to a user's session, email and files.
Cloneable access badges
Legacy access-card technology that can be read and cloned from a short distance, defeating the badge system.
// 05 Fully authorised and controlled
Physical testing demands even more careful governance than digital testing, because it involves people, premises and the risk of a tester being challenged or detained. We handle it accordingly: every engagement is authorised in writing, tightly scoped with agreed targets, boundaries and off-limits areas, and bounded by rules of engagement that account for staff safety and business disruption. Testers carry an authorisation letter — the "get-out-of-jail" letter — to present immediately if challenged by security or staff, and we agree escalation and abort procedures in advance. The objective is always to identify and fix weaknesses, never to cause harm, distress or genuine disruption. Physical assessments are frequently combined with wireless and social engineering testing in a single on-site visit, and form a core element of a full-scope red team.
// 06 Frequently asked questions
What is a physical security assessment?
A test of whether an intruder could physically access your premises and, through that, your systems and data — tailgating, badge cloning, lock bypass and pretext entry, then reaching high-value targets.
Why does it matter for cybersecurity?
Physical access defeats digital controls — an unlocked workstation or a network port bypasses firewalls and authentication entirely.
What techniques do you use?
Tailgating, badge cloning, lock bypass, access-control evasion and pretext social engineering, then attempting to reach servers, ports, devices and documents.
Is it safe and authorised?
Yes — fully authorised in writing, scoped, bounded by rules of engagement, with testers carrying an authorisation letter and agreed abort procedures.