A physical penetration test is one of the most revealing security assessments an organisation can commission. While digital penetration testing focuses on networks and software, a physical test examines whether an attacker could walk through your front door, bypass your access controls, and reach sensitive areas without authorisation. If you want a complete picture of your security posture, understanding how penetration testing works in the physical world is essential. This guide walks you through the full process, from preparation to final report.
What you need before a physical penetration test
Before any testing begins, you need a solid foundation in place. Skipping this phase leads to wasted effort, legal exposure, and results that do not reflect real-world risk. The preparation stage defines the scope, sets boundaries, and ensures everyone involved is protected.
- Written authorisation: A signed rules of engagement document from the client organisation, explicitly permitting the test. This is non-negotiable and must specify which locations, dates, and times are in scope.
- Scope definition: A clear list of target buildings, floors, or zones to be tested, along with any areas that are strictly off-limits.
- Emergency contacts: Direct contact numbers for a designated point of contact at the organisation who can intervene if a tester is detained or an incident escalates.
- Cover story or pretext: A believable scenario the tester will use, such as posing as a maintenance engineer, delivery courier, or IT contractor.
- Testing toolkit: Depending on scope, this may include lockpicks, RFID cloning devices, camera equipment, and social engineering props like lanyards or branded clothing.
Once these elements are confirmed and documented, you have everything needed to move into the reconnaissance phase. Do not begin any fieldwork without written authorisation in hand.
Conduct reconnaissance on the target location
Reconnaissance is where you gather intelligence on the target before making any direct contact. The goal is to understand the physical layout, identify entry points, observe staff behaviour, and spot weaknesses that can be exploited during the test. Good reconnaissance dramatically increases the success rate of later entry attempts.
- Conduct open-source research using satellite imagery, street view tools, and publicly available floor plans or building permits to map the site layout.
- Perform on-site observation from a distance, noting shift patterns, smoking areas, delivery schedules, and how staff interact with doors and access points.
- Photograph or sketch all visible entry points, including main entrances, loading docks, fire exits, and car park access gates.
- Identify the badge or access control system in use by observing card readers, intercom systems, or turnstiles at entry points.
- Note the dress code and behaviour of employees to refine your pretext and make your cover story more convincing.
After completing reconnaissance, you should have a clear picture of the site’s physical layout, its busiest access points, and the most promising vectors for entry. Use this intelligence to prioritise which techniques to attempt first during the execution phase.
Execute entry attempts and bypass physical controls
With reconnaissance complete, the active testing phase begins. This is where you attempt to gain unauthorised access using the techniques and pretexts developed in earlier stages. The objective is to test whether physical controls such as locked doors, badge readers, and security staff actually prevent an attacker from entering.
Social engineering entry
Tailgating and piggybacking are among the most effective techniques. Follow an employee through a secured door by timing your approach to coincide with theirs, relying on social courtesy to hold the door open. Alternatively, approach the reception desk with a convincing pretext, such as claiming to be a contractor or vendor with a scheduled appointment, and observe whether staff verify your identity before granting access.
Technical bypass methods
If social engineering does not succeed or is not in scope, attempt technical bypass methods. These include using an RFID cloner to duplicate a card signal captured during reconnaissance, using a door shimming tool on poorly fitted door frames, or exploiting request-to-exit sensors that can be triggered from outside a door. Document every attempt, whether it succeeds or fails, as failed attempts reveal the controls that are working correctly.
After each entry attempt, note the method used, the time, the outcome, and any staff responses. This log becomes the backbone of your final report.
Test internal controls once inside the facility
Gaining entry is only half the assessment. Once inside, the next objective is to test how far an attacker could move through the facility and what they could access. Many organisations focus heavily on perimeter security while neglecting internal controls, and this phase reveals that gap.
- Attempt to access server rooms, network closets, or areas marked as restricted to determine whether internal doors have independent access controls.
- Look for unlocked workstations, unattended login sessions, or physical access to network ports where a device could be plugged in.
- Check whether sensitive documents, access credentials, or equipment are left unattended on desks or in open areas.
- Test whether staff challenge or question an unfamiliar person moving through secure areas, or whether you can move freely without being stopped.
- Attempt to photograph or document sensitive information visible on screens, whiteboards, or printed materials as proof of concept for the report.
At the end of this phase, you should have a clear record of how deep into the facility an attacker could realistically penetrate and what assets would be within reach. Every finding, no matter how minor it seems, should be logged with supporting evidence such as photos or timestamps.
Document findings and compile the assessment report
The final step transforms your raw observations and evidence into actionable intelligence for the client. A well-structured report is what gives the test its lasting value. Without clear documentation, even the most thorough physical penetration test delivers little benefit.
Structure your report to include an executive summary written for non-technical stakeholders, a detailed findings section that describes each vulnerability discovered, and a prioritised list of remediation recommendations. For each finding, include the method used, the risk it represents, and a concrete step the organisation can take to address it. Attach photographic evidence where relevant, and ensure all evidence is handled and stored securely before being transferred to the client.
Physical security assessments are most valuable when they lead to real improvements, not just a list of problems. If your organisation wants expert guidance through this process or needs support interpreting your results, contact us and we will help you turn your findings into a stronger security posture.
Frequently Asked Questions
Wat gebeurt er als een medewerker een tester tegenhoudt tijdens de test?
V: Wat gebeurt er als een medewerker een tester tegenhoudt tijdens de test?nA: Als een tester wordt aangehouden, kan hij of zij de noodcontactpersoon van de organisatie bellen om de situatie te verduidelijken. Dit scenario wordt vooraf besproken en vastgelegd in de rules of engagement, zodat zowel de tester als de medewerker beschermd zijn en de test veilig kan worden voortgezet of beëindigd.
Hoe lang duurt een fysieke penetratietest gemiddeld?
V: Hoe lang duurt een fysieke penetratietest gemiddeld?nA: De duur van een fysieke penetratietest hangt af van de omvang van de locatie en het aantal te testen toegangspunten, maar een gemiddelde test duurt tussen één en drie dagen. De voorbereidingsfase en het opstellen van het eindrapport komen daar nog bovenop en kunnen samen nog eens meerdere dagen in beslag nemen.
Waarom is een fysieke penetratietest ook belangrijk als de digitale beveiliging al goed op orde is?
V: Waarom is een fysieke penetratietest ook belangrijk als de digitale beveiliging al goed op orde is?nA: Zelfs de sterkste digitale beveiliging biedt geen bescherming als een aanvaller fysiek toegang krijgt tot een server, werkstation of netwerkaansluiting, omdat hij dan beveiligingsmaatregelen volledig kan omzeilen. Een fysieke test onthult kwetsbaarheden die softwarematige beveiligingstools simpelweg niet kunnen detecteren, zoals onbeheerde apparatuur of medewerkers die deuren openhouden voor onbekenden.
Wanneer is het verstandig om een fysieke penetratietest te herhalen?
V: Wanneer is het verstandig om een fysieke penetratietest te herhalen?nA: Het is verstandig om een fysieke penetratietest te herhalen na grote veranderingen, zoals een verhuizing, verbouwing, uitbreiding van het personeelsbestand of de implementatie van nieuwe toegangscontrolesystemen. Daarnaast is een jaarlijkse herhaling aan te raden om te controleren of eerder geconstateerde kwetsbaarheden daadwerkelijk zijn verholpen en of er geen nieuwe zwakke plekken zijn ontstaan.