Skip to main content

Physical Penetration Testing

Tailgating, cloned badges, an unattended meeting room and a network socket. What a physical assessment tests, why the Indian shared-tenancy office moves the boundary outside your control, and the authorisation that has to exist first.

By Siddarth G
August 19, 2026 Last updated 5 min read

Most security spending assumes the attacker is remote. A physical assessment tests the assumption that they have to be.

The question is simple: can someone get inside your premises, and once inside, what can they reach?

What happens before anyone approaches the door

The entry attempt is the short part. Ahead of it the team builds a picture of the site: shift patterns and the times the lobby is busiest, which doors are staffed and which are card-only, where people go to smoke, what the delivery routine looks like, which uniforms and lanyards are normal, and what a visitor badge actually looks like at a distance.

Much of this is available without going near the building. Photographs posted by staff, job advertisements naming the facilities team, the building's own marketing material, a listing for an office on the same floor. The reconnaissance is itself a finding, and it is usually the first thing a client asks to see.

How people get in

Rarely by defeating a lock. Almost always by defeating a person.

  • Tailgating. Following someone through a controlled door. Carrying two coffees and a laptop bag makes it easier, because holding the door is politeness and challenging a stranger is confrontation.
  • Pretext. Arriving as a contractor, an auditor, a courier, a fire-safety inspector. A visible jacket and a clipboard outperform most technical attacks.
  • Credential cloning. Many access cards still use formats that can be read at conversational distance and rewritten to a blank.
  • The unlocked route. A propped fire door, a smoking area entrance, a loading bay, a shared-tenancy floor with one weak neighbour.

Every one of these deceives a member of your staff, which raises questions about how the individuals involved are treated in the report. The position is set out in social engineering assessments and the consent they require.

What matters is what happens next

Getting in is usually the easy half. The assessment's value is in what is reachable afterwards, and that is where most organisations are surprised:

  • Network sockets in meeting rooms and reception areas, live and unfiltered.
  • Unlocked workstations. A walk through an open-plan floor at lunch usually finds several.
  • Printed material on desks, in trays, in unshredded bins.
  • Wiring cupboards and server rooms with the same badge that opened the front door, or with no lock at all.
  • Whether anyone challenges a stranger. Frequently nobody does for hours. That is a finding about culture.

The Indian office, where the boundary is somebody else's

Three arrangements are common here and each one moves the security boundary outside your control.

Shared tenancy in a business park. The guards at the gate and in the lobby are employed by the building, not by you, and they are measured on keeping people moving. Your access control begins at your own floor, and everything before it is a service you buy and cannot instruct.

Co-working and managed offices. The provider issues the credentials, the provider's staff hold the master card, and the neighbouring member on the same floor has the same access to the shared corridor as you do. Testing here needs the provider's agreement in writing and is frequently the reason a scope shrinks.

The delivery and facilities routine. Housekeeping, pantry restocking, water deliveries and equipment maintenance move through the office on a predictable schedule, usually with a lanyard nobody inspects. It is the most reliable pretext in the market and the hardest to close without making the building unpleasant to work in.

A data centre or colocation suite is a separate case again. The operator controls entry, and testing anything before your own cage door requires their written consent, obtained by you, well in advance.

Authorisation

Everything here would otherwise be trespass, and possibly worse. Before anyone approaches a building:

  • A signed authorisation letter each tester carries, naming the premises, the dates, the scope, and a person who will confirm it. It should be signed by somebody with actual authority over the site, which is not always the person commissioning the engagement.
  • That person reachable at any hour, with a phone that is answered. A tester detained by your own security at midnight needs someone who picks up.
  • Written permission from the building owner where you do not own it. A tenancy agreement is not authorisation to test shared areas.
  • An agreement on what happens when they are caught. Being caught is a successful outcome, and the exercise should end with a conversation, not with the police.

Landlords, shared receptions and neighbouring tenants are where this most often goes wrong, and they need settling in writing before the engagement.

What comes back

A timeline with photographs: entered at this time by this route, reached this floor, plugged into this socket, obtained this, left at this time, challenged by nobody or by someone at this point.

It is the most immediately persuasive report in security, because it needs no translation. A photograph of a tester sitting at an unattended desk in your office argues for itself.

What to do with it

The persuasiveness is a trap if the report stops there. The findings divide cleanly and the two halves have different owners.

Engineering. Ports in public areas moved onto a guest network or disabled, network access control so an unknown device gets nothing, comms rooms on a separate access group from the front door, screen locks enforced by policy instead of by habit, card formats reviewed where cloning succeeded.

People and process. A challenge procedure staff are actually willing to use, which means telling them explicitly that challenging a stranger is expected and that nobody will be embarrassed for doing it. Visitor handling that assumes the badge might be false. A clear-desk expectation that survives the month after the report. Guards briefed on what a tailgate looks like and empowered to stop someone.

The second half is the one that decays. Re-testing six months later measures whether the change held, and it is markedly cheaper than the first engagement because the reconnaissance is already done.

What it does not tell you

A physical assessment is one route, on one day, at one site. Failing to get in on a Tuesday afternoon is genuine evidence about that door at that hour, and it is not evidence that the building is secure at two in the morning or that the other four offices are the same. Scope it against the sites that matter and read the result for what it is.

Where it fits

Physical testing usually sits inside a wider red team as one initial-access route, and is bought on its own less often. See what a red team assessment involves and how red teams get in. Standalone is right when the question is specifically about premises: a new office, a data centre, a site handling something sensitive.

It is the most expensive access route to include. It needs people travelling and on the ground, and it carries real personal risk for them. See what a red team engagement costs.

About the author

Siddarth G

Practice Director โ€” Cybersecurity

Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.