Physical Penetration Testing
Also known as:Physical Pentest · Physischer Pentest
Physical Penetration Testing is the authorized, methodical assessment of an organization’s physical security controls. Testers attempt to gain unauthorized access to buildings, restricted areas, server rooms, and sensitive assets using techniques that real intruders employ: tailgating, badge cloning, lock picking, social engineeringSocial EngineeringManipulates people to bypass security controls or obtain information. at reception desks, dumpster diving, and USB drop attacks. Where traditional penetration testingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do. targets digital systems, a physical pentest targets the tangible infrastructure that protects them.
Who commissions this test?
Chief Security Officers (CSOs), facility managers, CISOs, corporate security departments, and compliance teams are the typical stakeholders. Organizations pursuing ISO 27001 certification (Annex A physical controls), SOC 2 physical security criteria, or sector-specific regulations (financial services, critical infrastructure, government) frequently commission physical pentests. Mergers and acquisitions due diligence, insurance risk assessments, and corporate security reviews also drive demand.
Test objectives
The goal is to determine whether an attacker can gain physical access to sensitive areas, assets, or systems by bypassing or defeating existing controls. Testers evaluate perimeter security, access control systems, surveillance coverage, visitor management procedures, employee security awareness, clean desk policy enforcement, and the effectiveness of security personnel. Each successful bypass is documented with evidence and rated by impact.
What is tested?
Testing covers the full physical attack surface: perimeter barriers (fences, gates, bollards), building entry points and door security (locks, access cards, mantraps), RFID/NFC badge systems (cloneability, default credentials), reception and visitor management procedures, tailgating resistance at controlled entrances, elevator and stairwell access controls, server room and network closet physical security, clean desk policy compliance, printer and document security, dumpster and recycling bin contents, CCTV coverage and monitoring effectiveness, security guard procedures and response times, and USB port accessibility on unattended workstations for BadUSBBadUSBAn attack in which USB firmware causes a device to appear as a malicious input or network component. drop attacks.
Common findings
Typical findings include successful tailgating through secured doors (often the single highest-success-rate attack), easily cloneable RFID/NFC badges using off-the-shelf equipment, poor visitor management allowing testers to move freely after initial entry, unlocked server rooms or network closets, sensitive documents left on desks, printers, or in unlocked drawers, door locks that can be bypassed with shimming or basic picking, missing CCTV coverage at key entry points or blind spots in camera placement, USB devices accepted and executed by unattended workstations, social engineering success at reception (pretexting as maintenance, delivery, or IT support), propped-open fire doors and emergency exits, lack of challenge culture (employees not questioning unfamiliar individuals), and inadequate security guard patrol patterns.
Typical engagement workflow
A physical penetration test follows the standard pentest process with critical legal and safety adaptations.
Interest and initial inquiry — the client reaches out, describing the premises to be tested, the security controls in place, and the business reason (compliance, post-incident, security program maturity assessment).
Scoping discussion — testers and the client discuss the physical environment: number of buildings, floors, entry points, access control technology, security personnel presence, CCTV systems, and any areas that are strictly off-limits (e.g., active manufacturing lines, hazardous material storage). The tester’s appearance, cover stories (pretexts), and interaction boundaries are discussed in detail.
Proposal and approval — a formal proposal outlines scope, methodology, timeline, and deliverables. Physical pentests require explicit approval from senior leadership — often at C-suite or board level — because the test involves physical presence, potential confrontation with staff, and legal risk.
Scope definition — targets are documented with precision: specific buildings and floors, which entry methods are permitted (tailgating, lock picking, badge cloning, social engineering), time windows, whether after-hours testing is in scope, and any absolute restrictions.
Letter of Engagement — this document is critical. The tester carries it at all times during the engagement. It must identify the tester by name and photo, authorize the specific testing activities, list emergency contacts, include the client’s legal authorization, and provide a 24/7 phone number for immediate verification if the tester is confronted or detained. Trespassing laws apply — without proper authorization, the tester risks criminal charges.
Additional authorizations — depending on jurisdiction, local law enforcement may need to be pre-notified to prevent emergency responses to a perceived break-in. Building management or landlords may require separate notification. If the premises are shared with other tenants, their notification status must be clarified.
Information provisioning — depending on the approach, the client provides building floor plans, access control system details, security guard schedules, CCTV layouts, badge samples for cloning analysis, or nothing at all (pure Black-Box). The chosen approach significantly affects the test’s realism and duration.
Kick-off call — alignment on safety protocols, communication channels, and escalation procedures. A safe word or code is established for situations where the tester needs to immediately de-escalate (e.g., if confronted aggressively). The tester confirms they understand the legal boundaries and physical safety considerations.
Execution with ongoing communication — the tester attempts to breach physical security using the agreed methods. Photographic and video evidence is captured discreetly. Critical successes (server room access, workstation compromise) are reported immediately. The tester maintains constant communication readiness in case of confrontation or emergency.
Vulnerability collection and rating — findings are documented with timestamps, photos, video evidence, and a description of how each control was bypassed. Severity considers the sensitivity of the area accessed, the ease of the bypass, and the potential impact (data center access vs. general office space).
Final report — comprehensive documentation including an executive summary, a narrative timeline of the assessment, detailed findings with photographic evidence, risk ratings, and remediation recommendations covering physical controls, procedures, and security awareness.
Presentation — results are presented to security leadership, facility management, and often executive leadership. Physical pentest presentations are particularly impactful because photographic evidence of a tester inside a server room or holding sensitive documents makes the risk tangible.
Project closure — the engagement concludes with remediation priorities, verification that all test artifacts (cloned badges, planted devices) have been removed or returned, and scheduling for a retest after control improvements are implemented.
Who should commission this test — and when?
Organizations with physical premises housing sensitive assets — data centers, corporate headquarters, research facilities, financial institutions, critical infrastructure — should commission physical penetration tests. Key triggers include ISO 27001 certification or recertification (Annex A physical controls), after office moves or building renovations, after access control system changes or upgrades, annually as part of a comprehensive security program, following a physical security incident or breach, and during mergers and acquisitions. Organizations in regulated industries (finance, healthcare, government, critical infrastructure) face additional physical security requirements that periodic testing validates.
Related concepts
- Penetration TestingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do.: The broader discipline of authorized security testing across all domains.
- Social EngineeringSocial EngineeringManipulates people to bypass security controls or obtain information.: Manipulating people to bypass security controls, a key technique in physical pentests.
- Shoulder SurfingShoulder SurfingObserving confidential inputs or screen contents from close proximity.: Observing confidential inputs or screen contents from close proximity.
- BadUSBBadUSBAn attack in which USB firmware causes a device to appear as a malicious input or network component.: Malicious USB devices that impersonate keyboards to execute commands on target systems.
- Rules of EngagementRules of EngagementBinding rules that define authorization, boundaries, communication, and stop conditions for a security test.: The agreed boundaries and permissions that govern a security assessment.