A physical penetration test is an authorized attempt to get inside your buildings and reach something that matters, using the social, procedural and mechanical weaknesses a real intruder would use, and it ends the instant a tester is properly challenged. It is not a facilities audit, a camera survey or a locksmith's report. It answers one question a board can act on: if someone walked in tomorrow carrying a delivery box and wearing a lanyard, how far would they get, and would anyone stop them?
Buyers reach that question after commissioning a new head office or data center, after an insurer or regulator asks about physical access to systems, or after a board member asks whether the badge readers would stop a stranger. What follows is what happens on a real engagement, written so you can draft your own scope document. Stingrai runs these as physical security assessments delivered by senior human testers.

What a physical test is, and what it is explicitly not
It is adversarial and bounded at once. Testers try to defeat controls, but inside written prohibitions designed so nobody is hurt, nothing is broken, and no employee is left feeling ambushed. A provider who blurs that line creates legal exposure for you, not themselves.
In scope | Explicitly excluded |
|---|---|
Entry attempts using pretext, timing and procedural gaps | Forced entry damaging doors, locks, fences or glazing |
Testing badge, visitor and escort processes as they run on the day | Interference with life-safety systems, egress hardware or exit routes |
Social pretexts aimed at reception, facilities, guards and staff | Impersonating police, fire services or any public official |
Measuring alarm response, camera coverage and guard challenge behavior | Physical contact, restraint, or anything provoking an unsafe reaction |
A physical-to-digital pivot from inside, where authorized in writing | Entering another tenant's space without that tenant's consent |
Recovering one proof item under a logged chain of custody | Reading or removing HR, medical or other personal data |
Placing an inventoried test device, retrieved before close | Removing equipment the business needs to operate |
A useful screening question: ask what a provider will refuse to do. One who answers "anything you authorize" has not thought about the fire door.
The control layers a physical assessment tests
A serious assessment treats the building as layers, each with a different owner, and reports on each separately so remediation lands on the right team.
Control layer | What the team probes |
|---|---|
Perimeter and approach | Fences, gates, loading docks, smoking-area doors, car parks, roof and plant routes |
Access control and credentials | Credential technology, reader-to-controller link, anti-passback, door-held-open and door-forced-open alarms, badge issuance and termination |
Reception and visitor process | Identity verification, host confirmation, badge issuance, escort rules, contractor and delivery handling |
Tailgating resistance | Doors, turnstiles, interlocks and mantraps at shift change and lunch peaks |
Server rooms and comms cabinets | Data hall and IDF closet doors, rack and cage locks, key control, live patch ports |
Clean desk and workstations | Unlocked domain-joined machines, credentials on notes, whiteboards, printer trays, exposed screens |
Waste and document handling | Waste segregation, shredding, recycling, skips, media disposal |
Alarm, camera and monitoring | Whether events fire, whether anyone watches, how fast a response comes |
Guard force procedure | Challenge culture, patrol timing, escort discipline, sign-in enforcement, handover |
Two layers are chronically underinvested. Credential technology is a procurement decision with a long tail: legacy 125 kHz proximity cards broadcast a static identifier with no cryptographic challenge, so a card presented within read range can be captured and replayed, and possession stops being proof of identity. If readers still speak Wiegand to the controller rather than OSDP with secure channel, guard training does not compensate. And a camera nobody watches is forensics, not a control.
Covert, overt, or hybrid: choosing the mode
This decision changes everything else, including the price. Neither mode is superior; they answer different questions.
Mode | What it proves | When it is right | Trade-off |
|---|---|---|---|
Covert (unannounced, few insiders aware) | Whether people, procedure and monitoring detect and respond to a real intruder | The board or an insurer asks "would we actually notice?" | One route in can end the test, leaving layers unexercised; needs the most legal care |
Overt (announced, escorted) | Whether controls are designed and configured correctly | New site commissioning, pre-occupancy review, or a large estate | Proves design, not human response, because everyone knows |
Hybrid (covert window, then overt walkthrough) | Both detection performance and design coverage, in one report | Most first-time buyers, and anyone needing a board answer plus a backlog | Longer, and the covert phase must close cleanly first |
One nuance separates mature providers. If a covert team is not detected at a low noise level, it should deliberately escalate visibility until detected, and record that threshold. "We were never caught" means nothing unless somebody tested at a level that should have triggered a response. That ladder and its stopping point belong in the rules of engagement.
Objectives beat checklists
A checklist tells you a door has a lock. An objective tells you whether the assembled system of locks, people, cameras and procedure stops someone who wants in. Write the objectives first; the scope document follows.
Objective | What success proves | What failure proves |
|---|---|---|
Reach a named server room or data hall floor | An outsider can walk from street to critical equipment | The layering held, and you learn which layer stopped the team |
Connect an authorized test device to a live port and reach the internet | Physical access converts directly into network access | Port security, network access control or egress filtering held |
Obtain a working building credential | Issuance or supervision can be manipulated | Issuance and host verification function |
Remove a marked document from a specified area | Sensitive material can leave undetected | Document handling and desk discipline are enforced in practice |
Photograph a named asset such as a rack label or whiteboard | Visual exposure exists without any removal | Sightlines and screen policy are controlled |
Trigger a defined alarm at an agreed time and measure the response | A hard response-time number to hold a guarding contract against | Monitoring and guard response meet specification |
That last objective is the most underused and often the most valuable, because it produces a measured number rather than an anecdote. Objectives should map to your crown jewels exactly as they do network-side.
The legal and safety scaffolding required before anyone goes on site
Physical testing is the one discipline where a mistake ends with a tester in a police car or an employee genuinely frightened. A serious provider refuses to begin until every item below exists in writing, and a vendor offering to start next week without it is disqualifying itself.
The authorization letter. Every tester carries a signed hard copy at all times, not a PDF on a phone. It states the authorizing entity and the signatory's name, title and signature; exact addresses, floors and areas; dates and permitted hours; every authorized tester and the photo ID each carries; permitted and prohibited actions; and two client contacts with mobile numbers reachable 24 hours a day who can confirm the engagement at 3am to a guard or police officer.
Authority to authorize. The signatory must actually control the premises. Leased and multi-tenant buildings normally need written landlord consent before anyone tests a shared lobby or car park. A colocation provider must consent in its own right; your contract almost certainly forbids you from authorizing a third party to attempt entry.
Scope boundaries and prohibited actions. Name what is out of scope and why: occupied medical rooms, laboratories with material hazards, trading floors during market hours, privileged legal files, other tenants. Name the prohibitions explicitly: no property damage, no interference with life-safety systems, no impersonation of public officials.
Challenge, stand-down and duress protocol. Agree what a challenged tester does: comply immediately, identify themselves, produce the letter, call the primary contact. Agree who can call a stand-down, the safe word they use, how fast the team confirms it, and how a genuine emergency is handled so your responders never chase a ghost.
Notification. Where local practice supports it, notify the police service covering the site so an alarm call does not escalate. Notify the guarding contractor at executive level only, since the guards on duty are part of what is tested. Record who was told and when.
Insurance, safety and images. Ask for current professional indemnity and public liability certificates before signing. Set a two-person minimum on site, a check-in cadence for out-of-hours work, and no roof access, confined spaces or work at height unless separately arranged. Photographs will contain employees and sometimes personal data, so agree redaction, retention and destruction terms up front.
What actually happens, day by day
The visible part is short. Most of the work happens before anyone approaches a door.
Phase | Elapsed time | What the team does |
|---|---|---|
Pre-engagement | Two to four weeks before | Scoping, objectives, authorization letter, landlord or colocation consent, contacts and stand-down protocol, insurance evidence |
Remote reconnaissance | Two to four days | Public imagery, planning filings, supplier and uniform identification, delivery patterns, photographs revealing badge design, job adverts naming building systems |
Passive observation | One to two days | Entry and exit patterns from public space, shift changes, loading dock behavior, patrol timing, camera placement |
First approach | Half a day | A low-risk probe: enter the lobby, ask a plausible question, watch the visitor process without defeating it |
Objective attempts | One to four days | Pretext entries, tailgating and piggybacking attempts, escalation toward the objectives, placement of an authorized test device where in scope |
Deliberate detection test | Half a day | If still undetected, escalate visibility on the agreed ladder until challenged, recording the threshold |
Overt walkthrough and debrief | One day | Escorted inspection of what covert did not reach, then a same-week debrief with facilities, security and IT |
The debrief matters more than buyers expect. Half the remediation is procedural and costs nothing: change the escort rule, move a bin, switch on an alarm you already license, brief reception on host confirmation.
The findings that realistically come back
Physical findings are not exotic. They repeat, because the causes repeat: convenience, staff turnover, contractor churn, and controls configured once at handover and never revisited.
Finding class | Why it matters | Severity |
|---|---|---|
Tailgating or piggybacking succeeds at a primary entrance | Defeats the whole access control investment at the busiest hour | High to Critical |
Legacy credentials, or Wiegand rather than OSDP secure channel | A card in read range can be captured and replayed, so possession is not identity | High |
Visitor process not enforced: no host confirmation, no ID check, live expired contractor badges | Makes the front desk the easiest path past every other control | High |
Comms cabinet or IDF closet accessible, with live patch ports | Physical access becomes network access | High to Critical |
Unattended, unlocked, domain-joined workstation | Direct use of an authenticated session with real entitlements | Critical |
Alarm fires but nobody responds, or response exceeds the contracted time | Detection without response is not a control, and it is measurable | High |
Records, diagrams or credentials in general recycling or an external skip | Requires no entry skill, and often no entry at all | Medium to High |
Camera blind spots at docks, stairwells or fire exits, or retention too short | Removes the ability to reconstruct what happened | Medium |
No challenge culture: unbadged testers cross occupied floors unquestioned | Your cheapest control, a colleague asking a polite question, is not operating | High |
Severity should follow what the access enabled, not how clever the entry was. An unlocked side door onto a car park is low. The same door onto a corridor with a live network port and an open comms cabinet is critical. Insist findings are graded on consequence and that each carries a named owner.
What the deliverable contains, including photographic evidence
A physical report has a different shape from a network report. Specify that shape before signing.
Objective statement and outcome. Each objective, whether it was met, and by which route. The section your board reads.
Timestamped attack narrative. A chronological, plain-language account with times, because it will be used like an incident timeline.
Detection and response timeline. What was observed, by whom, when, what followed, and where the chain broke. The highest-value page, and the one weak providers omit.
Per-finding entries. Control layer, severity with justification, evidence, root cause, and remediation split into procedural, configuration and capital fixes.
Control-layer scorecard. Layer by layer, so each owning team sees its own backlog.
Evidence, handled properly. Images captured on managed devices, faces and personal data redacted before delivery, encrypted transfer, stated retention and destruction dates, and a chain of custody record for anything removed and returned. A placed test device is logged with serial, placement and retrieval times.
Remediation roadmap and retest scope. Sequenced by risk reduction per unit of cost, separating what is free this week from what belongs in the next capital cycle.
Judge that shape against the same bar you would apply to any penetration test report.
Duration, cost drivers, and what you need to prepare
A single-site hybrid assessment is commonly a one to two week engagement end to end, with scoping and authorization starting two to four weeks earlier. Multi-site estates are scoped per site, often sampling sites that share a design and a guarding operator.
Cost driver | Why it moves the price |
|---|---|
Number and type of sites | Each needs its own reconnaissance, approach and evidence set |
Shift coverage | Nights, weekends and handovers are where guard and alarm findings live |
Covert versus overt | Covert needs observation time and allows fewer attempts per day |
Number of testers | Two on site is the professional minimum for safety and witnessing |
Objective difficulty | A lobby is not a caged data hall behind an interlock |
Travel and lodging | Best shown as a transparent line item, not buried in a day rate |
Physical-to-digital pivot | Adds a network-capable tester and a post-access phase |
Debrief depth | A joint purple-team style debrief takes preparation |
Physical engagements are therefore scoped and quoted individually. The packages on the Stingrai pricing page cover web application testing; for physical, social engineering, network, Active Directory and Wi-Fi work, ask for a scoped quote. Get a quote in 24 hours or book a scoping call.
What to prepare: a signed authorization letter plus landlord or colocation consent; a site list with addresses and floors; two contacts reachable 24 hours a day and an escalation tree; an out-of-scope list; who internally is briefed, usually three to six people; whether guarding is in-house or contracted; confirmation you can pull door and badge audit logs afterwards; and your camera retention window.
Six questions that separate a real engagement from a clipboard walkthrough
What will you refuse to do, and what is on your prohibited actions list?
Does your sample report contain a detection and response timeline, or only a list of open doors?
If you are not detected, how do you escalate visibility, and where does that ladder stop?
Who signs the authorization letter, and how do you handle a multi-tenant or colocation site?
How are photographs of employees redacted, retained and destroyed?
Who is physically on site, and is any part subcontracted?
Stingrai delivers physical work with senior human testers on the ground: a CREST-accredited penetration testing service provider at firm level, founded 2021, head office in Toronto with a London office, 18 published CVEs, 5.0 out of 5.0 across 19 Clutch reviews, and OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP and CRTO among team certifications. Snipe, the autonomous agent, covers web applications only; a vendor claiming an automated product can assess your lobby is selling something else.
Physical results are strongest when they connect to the rest of the attack path. An entry that ends at a live network port is where a physical security assessment meets the wider social engineering practice and, for organizations ready for it, a red team engagement in which physical entry is one initial access vector among several.
On compliance: ISO/IEC 27001:2022 groups physical controls under Annex A theme 7, the SOC 2 Trust Services Criteria cover physical access to facilities and protected assets under CC6, and PCI DSS v4.0.1 Requirement 9 restricts physical access to cardholder data. None mandates a physical penetration test. An assessment adds operating evidence that those controls function under adversarial conditions, supporting an ISO 27001, SOC 2 or PCI DSS program.
Frequently Asked Questions
What is physical penetration testing?
Physical penetration testing is an authorized, objective-driven attempt to defeat the controls that keep unauthorized people out of your buildings and away from your equipment. Testers use pretext, timing and procedural gaps the way a real intruder would, inside written prohibitions covering property damage, life-safety systems and employee wellbeing. It stops the moment a tester is properly challenged.
What does a physical penetration test actually test?
A professional assessment reports separately on nine control layers: perimeter and approach, access control and credentials, the reception and visitor process, tailgating resistance, server rooms and comms cabinets, clean desk and unattended workstations, waste and document handling, alarm and camera response, and guard force procedure. Layer-by-layer reporting matters because remediation crosses facilities, security operations and IT.
What is the difference between a covert and an overt physical assessment?
A covert assessment is unannounced, with only a handful of people internally aware, and tests whether your staff and monitoring actually detect and respond to an intruder. An overt assessment is escorted and announced, and inspects every control layer to test whether controls are designed correctly. Most first-time buyers get the best value from a hybrid of the two.
Do we need a written authorization letter for a physical penetration test?
Yes, and a reputable provider will refuse to go on site without one. Every tester should carry a signed hard copy naming the authorizing entity and signatory, the sites, floors and permitted hours, the authorized testers, the prohibited actions, and two client contacts reachable 24 hours a day who can confirm the engagement to a guard or police officer. Leased and multi-tenant buildings normally need landlord consent too.
How long does a physical penetration test take?
A single-site hybrid assessment is commonly a one to two week engagement end to end, covering remote reconnaissance, passive observation, the objective attempt window, an overt walkthrough and reporting. Scoping and authorization normally begin two to four weeks earlier. Multi-site estates are scoped per site.
How much does a physical penetration test cost?
Physical engagements are scoped and quoted individually because the drivers vary so widely: the number and type of sites, shift coverage, covert versus overt mode, the number of testers, objective difficulty, travel, and whether a physical-to-digital network pivot is in scope. Stingrai's published packages cover web application testing, so for a physical assessment ask for a scoped quote.
What happens if a tester is caught or the police are called?
That outcome is planned for before the engagement starts. A challenged tester complies immediately, identifies themselves, produces the signed authorization letter and calls the primary client contact, who must be reachable at any hour. Where local practice supports it the police service covering the site is notified in advance, and the guarding contractor only at executive level, since the guards on duty are part of what is tested.
Does ISO 27001, SOC 2 or PCI DSS require a physical penetration test?
No. ISO/IEC 27001:2022 groups physical controls under Annex A theme 7, the SOC 2 Trust Services Criteria cover physical access to facilities and protected assets under CC6, and PCI DSS v4.0.1 Requirement 9 restricts physical access to cardholder data, but none mandates a physical penetration test. An assessment provides operating evidence that those controls work under adversarial conditions.



