main logo icon

Published on

August 7, 2026

|

11 min read

Physical Penetration Testing: What Actually Happens During an Assessment

What happens on a physical penetration test: the control layers in scope, covert versus overt mode, how objectives are set, the authorization letter and safety scaffolding required before anyone goes on site, the findings that come back, and cost drivers.

Arafat Afzalzada

Arafat Afzalzada

Founder

Social Engineering

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

A physical penetration test is an authorized attempt to reach a named objective inside your buildings, using the social, procedural and mechanical weaknesses a real intruder would use, and it stops the moment a tester is properly challenged. Objective-based scoping ("reach the server room", "connect an authorized test device to a live network port", "remove a marked document") tells you far more than a checklist confirming that doors have locks. Covert engagements test whether your people and monitoring actually notice; overt engagements test whether the controls are designed correctly, and most first-time buyers get more from a hybrid of the two. No reputable provider goes on site without a signed authorization letter carried in hard copy by every tester, named client contacts reachable 24 hours a day, agreed scope boundaries and a stand-down procedure. The deliverable that matters is not a list of unlocked doors but a timestamped attack narrative set beside a detection and response timeline showing what your staff, guards and cameras actually did. Cost is driven by site count, shift coverage, covert versus overt mode, tester count and travel, so physical engagements are scoped and quoted individually rather than bought from a price list. Physical assessments are delivered by senior human testers on the ground, not by software.

A physical penetration test is an authorized attempt to get inside your buildings and reach something that matters, using the social, procedural and mechanical weaknesses a real intruder would use, and it ends the instant a tester is properly challenged. It is not a facilities audit, a camera survey or a locksmith's report. It answers one question a board can act on: if someone walked in tomorrow carrying a delivery box and wearing a lanyard, how far would they get, and would anyone stop them?

Buyers reach that question after commissioning a new head office or data center, after an insurer or regulator asks about physical access to systems, or after a board member asks whether the badge readers would stop a stranger. What follows is what happens on a real engagement, written so you can draft your own scope document. Stingrai runs these as physical security assessments delivered by senior human testers.

Physical Penetration Testing What Actually Happens Hero

What a physical test is, and what it is explicitly not

It is adversarial and bounded at once. Testers try to defeat controls, but inside written prohibitions designed so nobody is hurt, nothing is broken, and no employee is left feeling ambushed. A provider who blurs that line creates legal exposure for you, not themselves.

In scope

Explicitly excluded

Entry attempts using pretext, timing and procedural gaps

Forced entry damaging doors, locks, fences or glazing

Testing badge, visitor and escort processes as they run on the day

Interference with life-safety systems, egress hardware or exit routes

Social pretexts aimed at reception, facilities, guards and staff

Impersonating police, fire services or any public official

Measuring alarm response, camera coverage and guard challenge behavior

Physical contact, restraint, or anything provoking an unsafe reaction

A physical-to-digital pivot from inside, where authorized in writing

Entering another tenant's space without that tenant's consent

Recovering one proof item under a logged chain of custody

Reading or removing HR, medical or other personal data

Placing an inventoried test device, retrieved before close

Removing equipment the business needs to operate

A useful screening question: ask what a provider will refuse to do. One who answers "anything you authorize" has not thought about the fire door.

The control layers a physical assessment tests

A serious assessment treats the building as layers, each with a different owner, and reports on each separately so remediation lands on the right team.

Control layer

What the team probes

Perimeter and approach

Fences, gates, loading docks, smoking-area doors, car parks, roof and plant routes

Access control and credentials

Credential technology, reader-to-controller link, anti-passback, door-held-open and door-forced-open alarms, badge issuance and termination

Reception and visitor process

Identity verification, host confirmation, badge issuance, escort rules, contractor and delivery handling

Tailgating resistance

Doors, turnstiles, interlocks and mantraps at shift change and lunch peaks

Server rooms and comms cabinets

Data hall and IDF closet doors, rack and cage locks, key control, live patch ports

Clean desk and workstations

Unlocked domain-joined machines, credentials on notes, whiteboards, printer trays, exposed screens

Waste and document handling

Waste segregation, shredding, recycling, skips, media disposal

Alarm, camera and monitoring

Whether events fire, whether anyone watches, how fast a response comes

Guard force procedure

Challenge culture, patrol timing, escort discipline, sign-in enforcement, handover

Two layers are chronically underinvested. Credential technology is a procurement decision with a long tail: legacy 125 kHz proximity cards broadcast a static identifier with no cryptographic challenge, so a card presented within read range can be captured and replayed, and possession stops being proof of identity. If readers still speak Wiegand to the controller rather than OSDP with secure channel, guard training does not compensate. And a camera nobody watches is forensics, not a control.

Covert, overt, or hybrid: choosing the mode

This decision changes everything else, including the price. Neither mode is superior; they answer different questions.

Mode

What it proves

When it is right

Trade-off

Covert (unannounced, few insiders aware)

Whether people, procedure and monitoring detect and respond to a real intruder

The board or an insurer asks "would we actually notice?"

One route in can end the test, leaving layers unexercised; needs the most legal care

Overt (announced, escorted)

Whether controls are designed and configured correctly

New site commissioning, pre-occupancy review, or a large estate

Proves design, not human response, because everyone knows

Hybrid (covert window, then overt walkthrough)

Both detection performance and design coverage, in one report

Most first-time buyers, and anyone needing a board answer plus a backlog

Longer, and the covert phase must close cleanly first

One nuance separates mature providers. If a covert team is not detected at a low noise level, it should deliberately escalate visibility until detected, and record that threshold. "We were never caught" means nothing unless somebody tested at a level that should have triggered a response. That ladder and its stopping point belong in the rules of engagement.

Objectives beat checklists

A checklist tells you a door has a lock. An objective tells you whether the assembled system of locks, people, cameras and procedure stops someone who wants in. Write the objectives first; the scope document follows.

Objective

What success proves

What failure proves

Reach a named server room or data hall floor

An outsider can walk from street to critical equipment

The layering held, and you learn which layer stopped the team

Connect an authorized test device to a live port and reach the internet

Physical access converts directly into network access

Port security, network access control or egress filtering held

Obtain a working building credential

Issuance or supervision can be manipulated

Issuance and host verification function

Remove a marked document from a specified area

Sensitive material can leave undetected

Document handling and desk discipline are enforced in practice

Photograph a named asset such as a rack label or whiteboard

Visual exposure exists without any removal

Sightlines and screen policy are controlled

Trigger a defined alarm at an agreed time and measure the response

A hard response-time number to hold a guarding contract against

Monitoring and guard response meet specification

That last objective is the most underused and often the most valuable, because it produces a measured number rather than an anecdote. Objectives should map to your crown jewels exactly as they do network-side.

Physical testing is the one discipline where a mistake ends with a tester in a police car or an employee genuinely frightened. A serious provider refuses to begin until every item below exists in writing, and a vendor offering to start next week without it is disqualifying itself.

The authorization letter. Every tester carries a signed hard copy at all times, not a PDF on a phone. It states the authorizing entity and the signatory's name, title and signature; exact addresses, floors and areas; dates and permitted hours; every authorized tester and the photo ID each carries; permitted and prohibited actions; and two client contacts with mobile numbers reachable 24 hours a day who can confirm the engagement at 3am to a guard or police officer.

Authority to authorize. The signatory must actually control the premises. Leased and multi-tenant buildings normally need written landlord consent before anyone tests a shared lobby or car park. A colocation provider must consent in its own right; your contract almost certainly forbids you from authorizing a third party to attempt entry.

Scope boundaries and prohibited actions. Name what is out of scope and why: occupied medical rooms, laboratories with material hazards, trading floors during market hours, privileged legal files, other tenants. Name the prohibitions explicitly: no property damage, no interference with life-safety systems, no impersonation of public officials.

Challenge, stand-down and duress protocol. Agree what a challenged tester does: comply immediately, identify themselves, produce the letter, call the primary contact. Agree who can call a stand-down, the safe word they use, how fast the team confirms it, and how a genuine emergency is handled so your responders never chase a ghost.

Notification. Where local practice supports it, notify the police service covering the site so an alarm call does not escalate. Notify the guarding contractor at executive level only, since the guards on duty are part of what is tested. Record who was told and when.

Insurance, safety and images. Ask for current professional indemnity and public liability certificates before signing. Set a two-person minimum on site, a check-in cadence for out-of-hours work, and no roof access, confined spaces or work at height unless separately arranged. Photographs will contain employees and sometimes personal data, so agree redaction, retention and destruction terms up front.

What actually happens, day by day

The visible part is short. Most of the work happens before anyone approaches a door.

Phase

Elapsed time

What the team does

Pre-engagement

Two to four weeks before

Scoping, objectives, authorization letter, landlord or colocation consent, contacts and stand-down protocol, insurance evidence

Remote reconnaissance

Two to four days

Public imagery, planning filings, supplier and uniform identification, delivery patterns, photographs revealing badge design, job adverts naming building systems

Passive observation

One to two days

Entry and exit patterns from public space, shift changes, loading dock behavior, patrol timing, camera placement

First approach

Half a day

A low-risk probe: enter the lobby, ask a plausible question, watch the visitor process without defeating it

Objective attempts

One to four days

Pretext entries, tailgating and piggybacking attempts, escalation toward the objectives, placement of an authorized test device where in scope

Deliberate detection test

Half a day

If still undetected, escalate visibility on the agreed ladder until challenged, recording the threshold

Overt walkthrough and debrief

One day

Escorted inspection of what covert did not reach, then a same-week debrief with facilities, security and IT

The debrief matters more than buyers expect. Half the remediation is procedural and costs nothing: change the escort rule, move a bin, switch on an alarm you already license, brief reception on host confirmation.

The findings that realistically come back

Physical findings are not exotic. They repeat, because the causes repeat: convenience, staff turnover, contractor churn, and controls configured once at handover and never revisited.

Finding class

Why it matters

Severity

Tailgating or piggybacking succeeds at a primary entrance

Defeats the whole access control investment at the busiest hour

High to Critical

Legacy credentials, or Wiegand rather than OSDP secure channel

A card in read range can be captured and replayed, so possession is not identity

High

Visitor process not enforced: no host confirmation, no ID check, live expired contractor badges

Makes the front desk the easiest path past every other control

High

Comms cabinet or IDF closet accessible, with live patch ports

Physical access becomes network access

High to Critical

Unattended, unlocked, domain-joined workstation

Direct use of an authenticated session with real entitlements

Critical

Alarm fires but nobody responds, or response exceeds the contracted time

Detection without response is not a control, and it is measurable

High

Records, diagrams or credentials in general recycling or an external skip

Requires no entry skill, and often no entry at all

Medium to High

Camera blind spots at docks, stairwells or fire exits, or retention too short

Removes the ability to reconstruct what happened

Medium

No challenge culture: unbadged testers cross occupied floors unquestioned

Your cheapest control, a colleague asking a polite question, is not operating

High

Severity should follow what the access enabled, not how clever the entry was. An unlocked side door onto a car park is low. The same door onto a corridor with a live network port and an open comms cabinet is critical. Insist findings are graded on consequence and that each carries a named owner.

What the deliverable contains, including photographic evidence

A physical report has a different shape from a network report. Specify that shape before signing.

  • Objective statement and outcome. Each objective, whether it was met, and by which route. The section your board reads.

  • Timestamped attack narrative. A chronological, plain-language account with times, because it will be used like an incident timeline.

  • Detection and response timeline. What was observed, by whom, when, what followed, and where the chain broke. The highest-value page, and the one weak providers omit.

  • Per-finding entries. Control layer, severity with justification, evidence, root cause, and remediation split into procedural, configuration and capital fixes.

  • Control-layer scorecard. Layer by layer, so each owning team sees its own backlog.

  • Evidence, handled properly. Images captured on managed devices, faces and personal data redacted before delivery, encrypted transfer, stated retention and destruction dates, and a chain of custody record for anything removed and returned. A placed test device is logged with serial, placement and retrieval times.

  • Remediation roadmap and retest scope. Sequenced by risk reduction per unit of cost, separating what is free this week from what belongs in the next capital cycle.

Judge that shape against the same bar you would apply to any penetration test report.

Duration, cost drivers, and what you need to prepare

A single-site hybrid assessment is commonly a one to two week engagement end to end, with scoping and authorization starting two to four weeks earlier. Multi-site estates are scoped per site, often sampling sites that share a design and a guarding operator.

Cost driver

Why it moves the price

Number and type of sites

Each needs its own reconnaissance, approach and evidence set

Shift coverage

Nights, weekends and handovers are where guard and alarm findings live

Covert versus overt

Covert needs observation time and allows fewer attempts per day

Number of testers

Two on site is the professional minimum for safety and witnessing

Objective difficulty

A lobby is not a caged data hall behind an interlock

Travel and lodging

Best shown as a transparent line item, not buried in a day rate

Physical-to-digital pivot

Adds a network-capable tester and a post-access phase

Debrief depth

A joint purple-team style debrief takes preparation

Physical engagements are therefore scoped and quoted individually. The packages on the Stingrai pricing page cover web application testing; for physical, social engineering, network, Active Directory and Wi-Fi work, ask for a scoped quote. Get a quote in 24 hours or book a scoping call.

What to prepare: a signed authorization letter plus landlord or colocation consent; a site list with addresses and floors; two contacts reachable 24 hours a day and an escalation tree; an out-of-scope list; who internally is briefed, usually three to six people; whether guarding is in-house or contracted; confirmation you can pull door and badge audit logs afterwards; and your camera retention window.

Six questions that separate a real engagement from a clipboard walkthrough

  1. What will you refuse to do, and what is on your prohibited actions list?

  2. Does your sample report contain a detection and response timeline, or only a list of open doors?

  3. If you are not detected, how do you escalate visibility, and where does that ladder stop?

  4. Who signs the authorization letter, and how do you handle a multi-tenant or colocation site?

  5. How are photographs of employees redacted, retained and destroyed?

  6. Who is physically on site, and is any part subcontracted?

Stingrai delivers physical work with senior human testers on the ground: a CREST-accredited penetration testing service provider at firm level, founded 2021, head office in Toronto with a London office, 18 published CVEs, 5.0 out of 5.0 across 19 Clutch reviews, and OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP and CRTO among team certifications. Snipe, the autonomous agent, covers web applications only; a vendor claiming an automated product can assess your lobby is selling something else.

Physical results are strongest when they connect to the rest of the attack path. An entry that ends at a live network port is where a physical security assessment meets the wider social engineering practice and, for organizations ready for it, a red team engagement in which physical entry is one initial access vector among several.

On compliance: ISO/IEC 27001:2022 groups physical controls under Annex A theme 7, the SOC 2 Trust Services Criteria cover physical access to facilities and protected assets under CC6, and PCI DSS v4.0.1 Requirement 9 restricts physical access to cardholder data. None mandates a physical penetration test. An assessment adds operating evidence that those controls function under adversarial conditions, supporting an ISO 27001, SOC 2 or PCI DSS program.

Frequently Asked Questions

What is physical penetration testing?

Physical penetration testing is an authorized, objective-driven attempt to defeat the controls that keep unauthorized people out of your buildings and away from your equipment. Testers use pretext, timing and procedural gaps the way a real intruder would, inside written prohibitions covering property damage, life-safety systems and employee wellbeing. It stops the moment a tester is properly challenged.

What does a physical penetration test actually test?

A professional assessment reports separately on nine control layers: perimeter and approach, access control and credentials, the reception and visitor process, tailgating resistance, server rooms and comms cabinets, clean desk and unattended workstations, waste and document handling, alarm and camera response, and guard force procedure. Layer-by-layer reporting matters because remediation crosses facilities, security operations and IT.

What is the difference between a covert and an overt physical assessment?

A covert assessment is unannounced, with only a handful of people internally aware, and tests whether your staff and monitoring actually detect and respond to an intruder. An overt assessment is escorted and announced, and inspects every control layer to test whether controls are designed correctly. Most first-time buyers get the best value from a hybrid of the two.

Do we need a written authorization letter for a physical penetration test?

Yes, and a reputable provider will refuse to go on site without one. Every tester should carry a signed hard copy naming the authorizing entity and signatory, the sites, floors and permitted hours, the authorized testers, the prohibited actions, and two client contacts reachable 24 hours a day who can confirm the engagement to a guard or police officer. Leased and multi-tenant buildings normally need landlord consent too.

How long does a physical penetration test take?

A single-site hybrid assessment is commonly a one to two week engagement end to end, covering remote reconnaissance, passive observation, the objective attempt window, an overt walkthrough and reporting. Scoping and authorization normally begin two to four weeks earlier. Multi-site estates are scoped per site.

How much does a physical penetration test cost?

Physical engagements are scoped and quoted individually because the drivers vary so widely: the number and type of sites, shift coverage, covert versus overt mode, the number of testers, objective difficulty, travel, and whether a physical-to-digital network pivot is in scope. Stingrai's published packages cover web application testing, so for a physical assessment ask for a scoped quote.

What happens if a tester is caught or the police are called?

That outcome is planned for before the engagement starts. A challenged tester complies immediately, identifies themselves, produces the signed authorization letter and calls the primary client contact, who must be reachable at any hour. Where local practice supports it the police service covering the site is notified in advance, and the guarding contractor only at executive level, since the guards on duty are part of what is tested.

Does ISO 27001, SOC 2 or PCI DSS require a physical penetration test?

No. ISO/IEC 27001:2022 groups physical controls under Annex A theme 7, the SOC 2 Trust Services Criteria cover physical access to facilities and protected assets under CC6, and PCI DSS v4.0.1 Requirement 9 restricts physical access to cardholder data, but none mandates a physical penetration test. An assessment provides operating evidence that those controls work under adversarial conditions.

0 views

0

X

Related reading

Red Team Rules of Engagement: What to Demand Before You Sign
Network SecuritySocial Engineering

Red Team Rules of Engagement: What to Demand Before You Sign

A buyer's checklist of the red team rules of engagement clauses to demand before you sign, plus a clear answer on whether testing can break production.

17 min read

Which Threat Group Should Your Red Team Emulate? A Buyer Guide by Industry
AdvisoriesSocial Engineering

Which Threat Group Should Your Red Team Emulate? A Buyer Guide by Industry

A sourced, MITRE ATT&CK-mapped buyer guide to which threat group your red team should emulate, by industry, from finance to critical infrastructure.

11 min read

Scattered Spider Identity Takeover: A Buyer's Guide to Account Recovery Red Teaming
Social EngineeringAdvisories

Scattered Spider Identity Takeover: A Buyer's Guide to Account Recovery Red Teaming

How to buy a red team that tests your account-recovery and help-desk workflows against Scattered Spider social engineering, plus a resilience checklist.

11 min read

Contents

X