A physical penetration test places a team on-site at your premises with a defined objective — reaching a restricted area, accessing a specific system, or retrieving defined assets — using the same approaches a real intruder would use. Unlike network testing, the interaction happens in the same physical space as your staff. What we find on physical assessments reflects both the technical controls in place and the human patterns that develop around them — the ways in which security measures are absorbed into normal working life in ways that quietly undermine their effectiveness.
Tailgating through access-controlled entry points
The most common physical security finding is also the most straightforward: following an authorised person through an access-controlled door without presenting credentials. Staff in most organisations will hold a door open for someone approaching behind them. Challenging a person who appears to belong — dressed appropriately, carrying equipment, walking with purpose — is socially uncomfortable, and most people avoid it instinctively.
This is not a failure of individual employees. It is the predictable consequence of normal social behaviour in the absence of reinforced challenge culture and clear procedures. We routinely access restricted areas on the first attempt through tailgating alone, with no bypass of electronic access controls. The card reader and the access control system work correctly; the human element around them does not.
Unlocked workstations and active sessions
Unattended workstations are found unlocked in most environments we assess. Automatic screen lock policies exist in many organisations, but timeout periods are typically set long enough — fifteen minutes or more — that workstations left briefly during a meeting, a comfort break, or a conversation at a colleague's desk are accessible. In environments where automatic lock is not consistently enforced, or where staff have disabled it for convenience, the situation is worse.
An unlocked workstation in a shared or semi-accessible space provides immediate access to the logged-in user's session, files, email, browser sessions with saved credentials, and any applications that are open. It provides this access without any authentication. The physical location — an open-plan office, a workstation near a printer, an unlocked office — is often more accessible than the IT policy assumes.
Sensitive information left unsecured
Physical information security — the handling of documents, the management of whiteboards, the disposal of printed material — is an area where policies exist and practice diverges. Printed documents left on desks containing customer data, financial information, or internal communications. Whiteboards in meeting rooms with sensitive content from the previous occupant still displayed, sometimes including network diagrams, project names, or access credentials written up during a working session. Confidential documents in general waste rather than cross-cut shredding. Passwords, system names, and access codes written on sticky notes.
The volume of useful information available through a walk through a typical office environment — without opening any system or bypassing any digital control — is consistently higher than the organisations we test expect. Each piece individually may appear low risk; in aggregate they accelerate an attacker's ability to operate within the environment significantly.
Network access in accessible locations
Active network sockets in reception areas, meeting rooms, corridors, and other spaces accessible to visitors and contractors provide unauthenticated access to the internal network. In environments without 802.1X port-based authentication or guest network segmentation, connecting a device to an accessible socket provides the same network position as a domain-joined workstation — and from that position, the internal network testing findings described in this series apply in full.
Meeting rooms are the most common location for this finding. They are designed to accommodate external visitors, the network infrastructure installed in them is intended for legitimate business use, and it is rarely treated differently from the infrastructure in controlled areas. A visitor left briefly unattended in a meeting room, or a contractor with access to a building for legitimate reasons, has network access that was never intended.
Social engineering of front-of-house and operational staff
Reception and operational staff in most organisations receive minimal security awareness training specific to physical and social engineering scenarios. A caller presenting a plausible story — a supplier, an IT engineer, a delivery requiring authorisation — will in many cases be assisted without verification that goes beyond checking a name against a diary or asking who the person is there to see. Password resets obtained through IT helpdesk impersonation, with a convincing enough pretext, succeed in environments where the verification procedures are not robust or are not consistently followed.
These outcomes are not the result of incompetent staff. They are the result of staff trying to be helpful in situations where the security consequence of their decision is not immediately apparent, the social cost of refusal feels disproportionate, and the training they have received did not prepare them for this specific scenario. Physical security is as much a people programme as it is a controls programme, and testing it requires assessing both.
A physical penetration test identifies the gaps between your physical security policy and what actually happens when that policy is tested by someone trying to get in.
Penetration Testing