Physical Penetration Testing
Physical penetration testing across Europe. We try to walk into your building and reach your data, then show you exactly how. Fixed price, full report.
Physical penetration testing answers a question most security programmes skip entirely: can someone simply walk into your building, past reception, through a “secure” door, and sit down at a live network port or an open server room? Digital defences mean little if a stranger in a hi-vis vest can carry your data out of the front door.
Every euro spent on firewalls and endpoint protection assumes the attacker is remote. Plenty aren’t. A confident person with a clipboard, a cloned badge or a propped-open fire exit bypasses all of it, and once they’re inside your walls, they’re inside your network too. We test that reality by trying to get in the way a real intruder would, safely and under written authorisation, then we tell you exactly where and how you let us.
What physical penetration testing covers
The engagement targets the whole physical security chain, from the car park to the server rack, including the people who are supposed to challenge a stranger and usually don’t.
The building is part of your attack surface
Reception, doors, badges, cameras and the staff who use them are security controls, and like any control they can be misconfigured or ignored. A badge reader means nothing if the door next to it is propped open for deliveries. A camera means nothing if no one watches it. We test whether these controls work as a system or only on the plan.
Getting in is usually the easy part
People rarely challenge someone who looks like they belong. A lanyard, a confident stride and a coffee in hand get further than any lock-picking kit. Most of our successful entries come from social engineering at the door, not from defeating hardware, and that’s the uncomfortable finding most clients need to hear.
How we run a physical assessment
This is careful, planned fieldwork carried out under strict authorisation, with a signed authorisation letter our operators carry at all times so that if challenged, the test ends safely rather than with the police involved. Everything is agreed with a small group of people in advance and runs under NDA.
Reconnaissance and planning
We study the target before we ever approach: entrances and exits, delivery and smoking areas, shift patterns, uniform and badge design, and what open sources reveal about the site and its occupants. From this we plan the approach and the pretexts, and we identify the objectives, a specific room, a network port, a document, so success is measurable.
Approach and entry
On the day, our operators attempt entry through the routes the plan identified: tailgating a group returning from lunch, presenting as a contractor or delivery driver, using a cloned badge, or defeating a poorly-fitted lock. We keep detailed notes and photographic evidence of each control we pass, so the report shows precisely where the chain broke.
Badge cloning
Many access-control systems still use legacy proximity cards that can be read from a pocket’s distance and cloned in seconds. Where your badges use this technology, we demonstrate the clone and use it, because “our doors are badge-controlled” is only reassuring if the badges themselves can’t be copied on a busy pavement.
Objectives inside
Once in, we head for what matters. A live network port in an empty meeting room lets us plug in a small device that connects back to our infrastructure, turning a physical breach into a network foothold. An open server room, an unattended logged-in workstation, or a folder of sensitive papers on a desk all prove the same thing: the perimeter was the building, and it failed.
Withdrawal and reporting
We leave cleanly, remove any devices we placed, and account for everything. The report then walks the full journey with photographs, from the car park to the objective, naming each control that should have stopped us and didn’t, alongside the specific, practical fixes.
Physical weaknesses we find most often
Physical security fails in patterns just as digital security does, and the same few issues account for most successful entries.
Tailgating and polite non-challenge
The most reliable way in is to follow someone through a door they’ve just badged open. Politeness does the rest: holding a door for the person behind you is good manners and terrible security. Staff who feel awkward challenging a stranger are the single most common reason we succeed.
Cloneable badges and shared credentials
Legacy proximity cards, badges left on desks, and access credentials shared between staff undermine an otherwise decent access-control system. If a card can be read and copied from a nearby pocket, the whole barrier is theatre.
Unsecured network ports and comms rooms
An active ethernet port in a public or semi-public area is an open invitation. So is a comms cabinet with the key left in the lock or a server-room door held open by a fire extinguisher. These give an attacker the network foothold that the rest of your security spend was meant to prevent.
Clear-desk and screen-lock failures
Sensitive documents left on desks, whiteboards covered in credentials, and workstations left logged in hand an intruder information and access without any technical skill at all. It’s mundane, and it’s everywhere, and it usually costs nothing but discipline to fix once a report puts a photograph of the problem in front of the right people.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Physical and digital as one attack
Real attackers don’t respect the line your org chart draws between physical security and IT security. Physical penetration testing is at its most useful when it flows straight into the network, because that’s exactly how a targeted intrusion unfolds.
From the front door to domain admin
An operator who tailgates in, finds an empty desk and plugs a small implant into a live port has just handed our team a foothold behind every perimeter firewall. From there the engagement can continue as an internal network or Active Directory test, showing you the whole path from the pavement to your most sensitive systems. Run as one exercise, it makes the case for both physical and network controls far more powerfully than either test alone.
Pairing with social engineering
Physical entry and social engineering are close cousins, since most successful entries come from talking past a person rather than defeating a lock. Combining a physical assessment with pretext phone calls and phishing gives a rounded picture of how your people respond to pressure, whether it arrives by email, by phone or in person at the reception desk.
What you get
Evidence that’s hard to argue with, and a clear route to fixing what it shows.
Executive summary with evidence
A concise account for leadership of how far we got and what it would have meant, backed by photographs that make the risk impossible to dismiss. Nothing focuses a board quite like a photograph of one of our testers sitting calmly inside the server room.
Detailed technical report
Every control tested, every one bypassed, with the method, the evidence and a specific remediation, prioritized by how much each fix reduces risk. Where the physical breach led to network access, we document that chain too.
Attestation and retest
An attestation letter for auditors, insurers and clients confirming the assessment and its scope, and a free retest once you’ve made changes to confirm the gaps are genuinely closed.
Compliance and standards
Physical security is an explicit part of the major frameworks, and a physical test provides evidence that policy is matched by reality.
ISO 27001, SOC 2 and PCI DSS
ISO 27001 Annex A includes a full set of physical and environmental security controls covering secure areas, entry controls and equipment protection, and auditors value independent testing of them. SOC 2 assesses physical access as part of its common criteria, and PCI DSS requirement 9 sets specific physical-access requirements for any environment handling cardholder data.
GDPR and NIS2
GDPR Article 32’s expectation of appropriate technical and organisational measures extends to the physical protection of systems holding personal data, and NIS2 pushes essential-service operators to consider physical resilience alongside the digital kind.
Pricing
Cost depends on the number of sites, their size and security maturity, and whether the engagement includes badge cloning, lock bypass and a follow-on network foothold. Here is the typical shape.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Single site | One location, reconnaissance, entry attempts, objective-based access, photographic report and free retest | 3–5 working days | from €2,500 |
| Standard | Larger or higher-security site, badge cloning and lock bypass, network-foothold demonstration, exec and technical reporting | 1–2 weeks | €4,000–€9,000 |
| Multi-site | Several locations or a campus, coordinated approach, detailed control-by-control mapping | 2–3 weeks | €9,000–€18,000 |
| Compliance add-on | Mapping and attestation for ISO 27001 physical controls, SOC 2 or PCI DSS requirement 9 | with any tier | from €800 |
| Custom / large estate | Many sites or a national footprint, scoped after a call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote
FAQ
How much does physical penetration testing cost?
How long does a physical assessment take?
Is this legal, and what if your tester is caught?
What do you actually try to reach inside the building?
Do you test badge and door security specifically?
Will a physical breach lead to a network compromise?
Does this satisfy ISO 27001 or PCI DSS physical requirements?
What makes you different from other physical penetration testing companies?
Related services
Organisations whose premises hold something worth stealing or protecting: data centres and offices with server rooms, retailers and financial firms under PCI DSS requirement 9, businesses with reception and badge-controlled access that has never been tested, and any company that has secured its network but never checked whether a stranger can simply walk in.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.