Physical Penetration Testing: What It Is and What You Learn

Physical penetration testing puts your locks, badges and staff to the test. What engagements cover, the legal and rules-of-engagement basics, what you learn.

Physical penetration testing assesses whether an attacker can gain unauthorised physical access to your buildings, offices, server rooms or restricted areas — and what they can reach once inside. It tests locks, access control, alarms, and crucially the people whose decisions those systems depend on. Digital security is only as strong as the door protecting the server it runs on.

We run physical engagements as part of our social engineering work, because getting through a door is almost always a people problem before it's a lock problem.

What a Physical Engagement Covers

The goal is agreed in advance — typically reaching a specific objective such as a server room, an executive's office, a network port on a sensitive floor, or simply demonstrating that an unaccompanied stranger can roam the building. Techniques a tester uses to get there include:

Tailgating and Piggybacking

Following an authorised person through a controlled door — badging systems mean nothing if someone holds the door open out of politeness. Tailgating is the single most reliable entry method in most offices, precisely because refusing to hold a door for someone carrying a coffee and a laptop bag feels rude.

Impersonation and Pretexting

Arriving as someone who belongs: a contractor, a delivery courier, an IT technician 'here to fix the printers', a fire-safety inspector, a new starter who forgot their pass. A high-vis vest and a clipboard remain remarkably effective props. The pretext is often researched beforehand through OSINT and reconnaissance — knowing a real vendor's name, a manager to 'report to', or an internal project makes the story land.

Access Control Bypass

Where people don't provide the way in, the physical controls are tested directly:

  • Cloning or reading RFID/proximity badges
  • Bypassing latches with under-door tools or shimming
  • Exploiting propped-open fire doors, unsecured loading docks, and smokers' entrances
  • Lock picking where in scope
  • Finding tailgate-friendly turnstiles and unmonitored side entrances

Post-Access Objectives

Getting in is the start. Once inside, a tester might demonstrate impact by locating unlocked workstations, plugging a rogue device into an exposed network port, photographing sensitive documents left on desks, accessing a server room, or planting a marker to prove they reached the objective.

Legal and Rules-of-Engagement Considerations

Physical testing carries real legal and human risk that remote testing doesn't, so the paperwork isn't bureaucracy — it's what keeps everyone safe and out of court.

  • Written authorisation. A signed authorisation from someone with genuine authority over the premises is mandatory. If you lease the building or share it, the property owner or manager may need to consent too.
  • A get-out-of-jail letter. Testers carry a signed document naming the engagement and an emergency contact who can confirm authorisation at any hour, so a detained tester can prove they're not a burglar.
  • Clear scope and boundaries. Which buildings, which floors, which hours, what's explicitly off-limits (data centres with regulatory constraints, other tenants, safety-critical areas).
  • Rules of engagement for people. No physical force, no breaking of locks or windows unless explicitly authorised, defined behaviour if challenged or detained, and an absolute rule to comply immediately and de-escalate with any security guard or police officer.
  • A named emergency contact reachable 24/7 throughout the engagement window.
  • Handling of staff who intervene. A staff member who challenges a tester did the right thing and must never be embarrassed for it — reporting is aggregate and blameless.

Good testers minimise disruption and never put staff, the public, or themselves in danger to make a point. The objective is evidence, not spectacle.

What You Actually Learn

A physical penetration test tells you things no digital assessment can:

  • Whether your access control works in practice, not just on the specification sheet
  • Whether staff challenge strangers — and whether they feel safe doing so
  • How far someone can get on confidence and a lanyard alone
  • Whether sensitive areas, documents and unlocked workstations are reachable once inside
  • Whether an intruder plugging into your network would be noticed — which is where physical and network security meet

That last point is why physical testing pairs naturally with assumed breach testing: a rogue device on an internal network port is one very direct way an attacker establishes the foothold that assumed-breach engagements start from. Physical access is, ultimately, another route to the same internal position — and often the easiest one.

The findings tend to be cultural as much as technical. Better locks help, but the durable improvements are usually around visitor management, badge discipline, challenging unknown people, and clear-desk habits — process and behaviour, reinforced by controls.

FAQ

Is physical penetration testing legal?

Yes, when properly authorised. It requires written authorisation from someone with authority over the premises and a clearly defined scope. Testers carry documentation proving the engagement is sanctioned. Without that, the same actions would be trespass or burglary.

Won't this get our staff in trouble?

No. The point is to test systems and processes, not to punish people. Results are reported in aggregate, staff who challenge testers are praised, and no individual is named or disciplined for a good-faith mistake.

How is this different from social engineering testing?

Physical testing is a form of social engineering focused on in-person access to premises, whereas phishing, vishing and smishing target people remotely. Many attacks combine both, and mature programmes test all of the channels an attacker might use.

If you want to know whether a confident stranger could walk into your office and reach your server room, talk to us. We'll scope a physical engagement in a free call and send a fixed quote within one business day.

Need cybersecurity expertise?

Drop your email and we'll be in touch within one business day.