Do You Need Physical Penetration Testing? A Buyer’s Guide

by Rebecca Sutton

Physical penetration testing puts a real person, not a scanner, up against your locks, badges, cameras and reception desk. The goal is simple: see if they can talk, tailgate or pick their way into a building you thought was secure. If they succeed, you find out through a report instead of an incident.

Business owners often ask why this matters once they already pay for network and web application testing. Here is the short answer: a determined intruder who reaches a network port or an unlocked server room inside your office has bypassed every firewall rule you own. They did it without writing a line of code.

What problem does it actually solve?

Digital testing tells you how strong your perimeter is on paper. It says nothing about whether a stranger with a parcel can walk in behind an employee. It says nothing about whether reception would challenge a stranger wearing an official-looking lanyard. Those are physical control gaps. They only surface when someone actually tries them.

Assessment type What it tests Typical finding
Network penetration test Firewalls, servers, VPNs Unpatched service, weak segmentation
Web application test Your website or portal’s code Injection flaw, broken access control
Physical penetration testing Doors, badges, staff behaviour, on-site network access Tailgating success, cloned badge, exposed network jack

How does physical penetration testing actually work?

Techniques vary by target, but the same handful come up again and again in professional engagements:

  • Tailgating. Walking in behind someone who has already badged through, often while carrying something bulky so holding the door feels natural. Triaxiom Security describes it plainly as “the most common way to break into a building” (Triaxiom Security).
  • Cloning access badges. Cheap RFID cloning devices, sometimes under $1,000, can copy a badge’s signal from a short distance away. A queue at a nearby café is close enough (Triaxiom Security).
  • Picking or bypassing locks. Standard mechanical locks have changed little in decades, and a shim or a squirt of compressed air through a door gap can beat a motion sensor.
  • Pretexting. A form of social engineering where the tester poses as a courier, engineer or new employee to be waved through without a proper check.
  • Digging through rubbish. Bins outside an office frequently hold printed passwords, old contracts or network diagrams that make the rest of the attack easier.

Research firm PurpleSec catalogues thirteen such techniques in total, from mapping entrances to intercepting wireless signals. A typical engagement takes two to six weeks. Pricing usually falls between $8,000 and $20,000, since scope and site count drive most of the cost (PurpleSec: 13 physical intrusion testing methods).

Is any of this legal?

Only when the organisation being tested has given clear, written permission first. In the UK, the Computer Misuse Act 1990 makes unauthorised computer access a criminal offence. It covers anyone who causes a computer to perform a function with that intent. A specific target does not need to be in mind (legislation.gov.uk). The same principle extends to the premises housing those systems.

Every legitimate tester carries a signed authorisation letter naming the sites, dates and techniques in scope. It also names an emergency contact who can confirm the engagement is genuine if security or the police intervene. Ask to see this before any work starts; a provider that hesitates to produce one is not one to hire.

What actually happens on the day

  1. Scope and authorisation are agreed and signed in advance.
  2. The tester researches the site: entrances, shift patterns, badge systems, sometimes from public information alone.
  3. They attempt entry using the agreed techniques, logging each attempt with photos where possible.
  4. Once inside, they note what they could reach, a server room, an unlocked desk, a network point, without touching or removing anything.
  5. A written report ranks the findings and recommends fixes in order of priority.

Industry coverage of the discipline in the UK points to the same shape. It generally recommends repeating the test annually, or every six months for higher-risk sites, and again after any significant change to a building’s access control (Security Journal UK: testing physical security controls).

Do you actually need one?

If your premises hold customer data, cash, stock or client files, physical penetration testing is worth at least scoping. You do not need the scale of a large enterprise engagement to get value. A single-site test focused on your main entrances and server room can be enough to expose the obvious gaps. It often makes most sense as one strand of a wider penetration testing programme rather than a one-off exercise. What matters more than size is choosing a provider who scopes the test to your actual risk rather than selling a standard package.

Look for CREST accreditation when comparing providers. It signals that the firm’s preparation, scoping, execution and reporting have been independently checked against a defined standard, rather than taking their word for it.

Common findings and how to close them

Most reports come back with a similar shortlist of gaps, and most of them are cheap to fix once you know they exist:

  • Doors held open out of politeness. Staff training on challenging unbadged visitors, without making reception feel confrontational, closes this quickly.
  • Old badge systems with no cloning protection. Newer access control readers support encrypted credentials that resist cheap cloning devices.
  • Unattended meeting rooms with live network ports. Disabling ports that aren’t in active use, or putting them on an isolated guest network, removes an easy foothold.
  • No visitor sign-in or escort policy. A simple log and an escort rule for anyone without a permanent badge stops casual walk-ins.
  • Sensitive paperwork left on desks or in open bins. A clear-desk policy and locked confidential waste bins deal with most of this.

None of these fixes require a large budget. The value of physical penetration testing is knowing which of them actually apply to your building, rather than guessing.

Frequently asked questions

Will our staff be told in advance?

Generally no, apart from the small group holding the authorisation letter. The point is to see how people behave under normal conditions, and advance warning would defeat that.

Could a tester be arrested during physical penetration testing?

It is possible if security or police are called before the authorisation letter is checked. That is exactly why testers carry it along with a named emergency contact who can confirm the engagement immediately.

Does physical penetration testing also check our IT systems?

Often yes. Once inside, testers frequently plug into an exposed network jack or try an unlocked workstation, so they can show what a real intruder could reach digitally as well as physically.

How much does it cost in the UK?

Pricing depends heavily on the number of sites, their size and the techniques included. As a benchmark, PurpleSec’s research puts typical physical engagements at $8,000 to $20,000. UK penetration test pricing generally follows a similar day-rate basis to other manual testing work.

What is the difference between this and a fire safety audit?

A fire safety audit checks regulatory compliance. A physical penetration test, though, checks whether an uninvited person could bypass your access controls, a security question rather than a compliance one, even though findings sometimes overlap.

If you want to talk through what proportionate physical penetration testing would look like for your buildings, get in touch. We can scope it around your actual sites and risk, not a generic package.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like