Home/Services/Physical Penetration Testing
security service

Physical Penetration Testing

Physical penetration testing across Europe. We try to walk into your building and reach your data, then show you exactly how. Fixed price, full report.

Manual, expert-ledEvidence-based findingsFree remediation retest

Physical penetration testing answers a question most security programmes skip entirely: can someone simply walk into your building, past reception, through a “secure” door, and sit down at a live network port or an open server room? Digital defences mean little if a stranger in a hi-vis vest can carry your data out of the front door.

Every euro spent on firewalls and endpoint protection assumes the attacker is remote. Plenty aren’t. A confident person with a clipboard, a cloned badge or a propped-open fire exit bypasses all of it, and once they’re inside your walls, they’re inside your network too. We test that reality by trying to get in the way a real intruder would, safely and under written authorisation, then we tell you exactly where and how you let us.

What physical penetration testing covers

The engagement targets the whole physical security chain, from the car park to the server rack, including the people who are supposed to challenge a stranger and usually don’t.

Tailgating and piggybacking through controlled entrances
RFID and proximity badge cloning and replay
Lock picking, bypass and door-hardware defeats
Pretexting past reception, security and staff
Access to server rooms, comms cabinets and live network ports
Rogue-device drops that phone home to our network
Sensitive documents, logged-in screens and clear-desk failures

The building is part of your attack surface

Reception, doors, badges, cameras and the staff who use them are security controls, and like any control they can be misconfigured or ignored. A badge reader means nothing if the door next to it is propped open for deliveries. A camera means nothing if no one watches it. We test whether these controls work as a system or only on the plan.

Getting in is usually the easy part

People rarely challenge someone who looks like they belong. A lanyard, a confident stride and a coffee in hand get further than any lock-picking kit. Most of our successful entries come from social engineering at the door, not from defeating hardware, and that’s the uncomfortable finding most clients need to hear.

How we run a physical assessment

This is careful, planned fieldwork carried out under strict authorisation, with a signed authorisation letter our operators carry at all times so that if challenged, the test ends safely rather than with the police involved. Everything is agreed with a small group of people in advance and runs under NDA.

Reconnaissance and planning

We study the target before we ever approach: entrances and exits, delivery and smoking areas, shift patterns, uniform and badge design, and what open sources reveal about the site and its occupants. From this we plan the approach and the pretexts, and we identify the objectives, a specific room, a network port, a document, so success is measurable.

Approach and entry

On the day, our operators attempt entry through the routes the plan identified: tailgating a group returning from lunch, presenting as a contractor or delivery driver, using a cloned badge, or defeating a poorly-fitted lock. We keep detailed notes and photographic evidence of each control we pass, so the report shows precisely where the chain broke.

Badge cloning

Many access-control systems still use legacy proximity cards that can be read from a pocket’s distance and cloned in seconds. Where your badges use this technology, we demonstrate the clone and use it, because “our doors are badge-controlled” is only reassuring if the badges themselves can’t be copied on a busy pavement.

Objectives inside

Once in, we head for what matters. A live network port in an empty meeting room lets us plug in a small device that connects back to our infrastructure, turning a physical breach into a network foothold. An open server room, an unattended logged-in workstation, or a folder of sensitive papers on a desk all prove the same thing: the perimeter was the building, and it failed.

Withdrawal and reporting

We leave cleanly, remove any devices we placed, and account for everything. The report then walks the full journey with photographs, from the car park to the objective, naming each control that should have stopped us and didn’t, alongside the specific, practical fixes.

1–2
weeks for a typical single-site assessment
100%
authorised, evidence-backed, safe to stop at any point
Free
retest after you fix the gaps

Physical weaknesses we find most often

Physical security fails in patterns just as digital security does, and the same few issues account for most successful entries.

Tailgating and polite non-challenge

The most reliable way in is to follow someone through a door they’ve just badged open. Politeness does the rest: holding a door for the person behind you is good manners and terrible security. Staff who feel awkward challenging a stranger are the single most common reason we succeed.

Cloneable badges and shared credentials

Legacy proximity cards, badges left on desks, and access credentials shared between staff undermine an otherwise decent access-control system. If a card can be read and copied from a nearby pocket, the whole barrier is theatre.

Unsecured network ports and comms rooms

An active ethernet port in a public or semi-public area is an open invitation. So is a comms cabinet with the key left in the lock or a server-room door held open by a fire extinguisher. These give an attacker the network foothold that the rest of your security spend was meant to prevent.

Clear-desk and screen-lock failures

Sensitive documents left on desks, whiteboards covered in credentials, and workstations left logged in hand an intruder information and access without any technical skill at all. It’s mundane, and it’s everywhere, and it usually costs nothing but discipline to fix once a report puts a photograph of the problem in front of the right people.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Physical and digital as one attack

Real attackers don’t respect the line your org chart draws between physical security and IT security. Physical penetration testing is at its most useful when it flows straight into the network, because that’s exactly how a targeted intrusion unfolds.

From the front door to domain admin

An operator who tailgates in, finds an empty desk and plugs a small implant into a live port has just handed our team a foothold behind every perimeter firewall. From there the engagement can continue as an internal network or Active Directory test, showing you the whole path from the pavement to your most sensitive systems. Run as one exercise, it makes the case for both physical and network controls far more powerfully than either test alone.

Pairing with social engineering

Physical entry and social engineering are close cousins, since most successful entries come from talking past a person rather than defeating a lock. Combining a physical assessment with pretext phone calls and phishing gives a rounded picture of how your people respond to pressure, whether it arrives by email, by phone or in person at the reception desk.

What you get

Evidence that’s hard to argue with, and a clear route to fixing what it shows.

Executive summary with evidence

A concise account for leadership of how far we got and what it would have meant, backed by photographs that make the risk impossible to dismiss. Nothing focuses a board quite like a photograph of one of our testers sitting calmly inside the server room.

Detailed technical report

Every control tested, every one bypassed, with the method, the evidence and a specific remediation, prioritized by how much each fix reduces risk. Where the physical breach led to network access, we document that chain too.

Attestation and retest

An attestation letter for auditors, insurers and clients confirming the assessment and its scope, and a free retest once you’ve made changes to confirm the gaps are genuinely closed.

Compliance and standards

Physical security is an explicit part of the major frameworks, and a physical test provides evidence that policy is matched by reality.

ISO 27001, SOC 2 and PCI DSS

ISO 27001 Annex A includes a full set of physical and environmental security controls covering secure areas, entry controls and equipment protection, and auditors value independent testing of them. SOC 2 assesses physical access as part of its common criteria, and PCI DSS requirement 9 sets specific physical-access requirements for any environment handling cardholder data.

GDPR and NIS2

GDPR Article 32’s expectation of appropriate technical and organisational measures extends to the physical protection of systems holding personal data, and NIS2 pushes essential-service operators to consider physical resilience alongside the digital kind.

Pricing

Cost depends on the number of sites, their size and security maturity, and whether the engagement includes badge cloning, lock bypass and a follow-on network foothold. Here is the typical shape.

Engagement What’s included Timeline Price
Single site One location, reconnaissance, entry attempts, objective-based access, photographic report and free retest 3–5 working days from €2,500
Standard Larger or higher-security site, badge cloning and lock bypass, network-foothold demonstration, exec and technical reporting 1–2 weeks €4,000–€9,000
Multi-site Several locations or a campus, coordinated approach, detailed control-by-control mapping 2–3 weeks €9,000–€18,000
Compliance add-on Mapping and attestation for ISO 27001 physical controls, SOC 2 or PCI DSS requirement 9 with any tier from €800
Custom / large estate Many sites or a national footprint, scoped after a call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote

FAQ

How much does physical penetration testing cost?
Physical penetration testing starts from €2,500 for a single site and is priced by the number and size of locations and the techniques in scope, such as badge cloning or a network foothold. You get a fixed quote after a free scoping call.
How long does a physical assessment take?
A single site typically runs 3–5 working days including reconnaissance and reporting, with multi-site engagements taking two to three weeks. The on-site attempts themselves are often quick; the planning is what makes them realistic.
Is this legal, and what if your tester is caught?
It’s legal because it’s authorised. Our operators carry a signed authorisation letter naming the people who sanctioned the test, so if challenged the exercise stops safely. A small, trusted group at your organisation knows in advance and can halt it at any time.
What do you actually try to reach inside the building?
Objectives agreed with you: a live network port to gain a foothold, a server room or comms cabinet, sensitive documents, or a logged-in workstation. Defining the target up front makes success and failure measurable rather than a story.
Do you test badge and door security specifically?
Yes. We attempt tailgating, clone legacy proximity badges where that technology is in use, and test locks and door hardware for bypass. Access control is only as strong as the weakest door and the easiest badge to copy.
Will a physical breach lead to a network compromise?
Often, yes, and that’s the point. A live ethernet port lets us plant a device that connects back to us, turning a physical entry into a network foothold. We can pair the physical test with internal network testing to show the full chain.
Does this satisfy ISO 27001 or PCI DSS physical requirements?
Yes. The report and attestation support ISO 27001 Annex A physical and environmental controls, SOC 2 physical-access criteria, and PCI DSS requirement 9. Tell us your framework and we align the deliverables.
What makes you different from other physical penetration testing companies?
We work as a European team on manual, evidence-led engagements under NDA, with photographic proof of every control we pass and a free retest. You get a clear chain from the pavement to your data, not a generic checklist that few physical pen testing companies actually walk.

Related services

Who needs this

Organisations whose premises hold something worth stealing or protecting: data centres and offices with server rooms, retailers and financial firms under PCI DSS requirement 9, businesses with reception and badge-controlled access that has never been tested, and any company that has secured its network but never checked whether a stranger can simply walk in.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Physical Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.