Physical Penetration Testing
In this current climate, many organisations are reviewing and strengthening their physical security measures. Physical Penetration Tests are an effective way of ensuring that your security measures are working effectively.
What is Physical Penetration Testing?
Physical Penetration Testing is the practice of assessing the efficiency of physical security measures across an organisation’s business estate.
Using covert techniques, authorised “attacks” on buildings and offices are conducted in an attempt to penetrate the physical security measures and identify vulnerabilities that could expose the organisation to a loss of sensitive information, unauthorized access to their property, or even malicious activity.
Physical penetration testing can include activities such as attempting to enter a building to gain access to the meeting rooms or to infiltrate a data-centre, and then where possible to move within the building to examine security measures and security culture, testing the staff, manned guarding and security technology.
Why conduct Physical Penetration Testing?
Organisations invest substantially in physical security measures, whether it be electronic controls, alarms, perimeter defenses or manned guarding. But how can we be sure that these measures, and the processes around them, are working effectively and that they’re preventing unauthorized access? Physical Penetration Testing will provide valuable insight into an organisation’s security posture and allow you to address vulnerabilities before these can be exploited.
Key benefits:
- Identify vulnerabilities
- Determine the feasibility of a particular type of breach
- Assess the potential impact of a particular type of breach
- Report findings and make recommendations
- Provide evidence to support investment in security
- Demonstrate good governance
Conducting Physical Penetration Testing will ensure that your organisation’s physical security profile is as robust as possible.
Physical Penetration Testing Approach
Initial Reconnaissance | Passive reconnaissance and open source intelligence used to gather information on the organisation and its business estate. |
Active Reconnaissance & Covert Observations | On the ground surveillance, walk-arounds to identify entrances & exits, surveillance of employed and manned guards, uniforms, IDs, cameras etc, We can make opportunist attempts to breach the security if appropriate. |
Attack Planning / Pretexting | Develop our pretext, arrange IDs/passes etc. |
Targeted Testing | Execute attack using covert techniques to penetrate the physical security, gathering video evidence |
Reporting | Report on vulnerabilities and provide recommendations to the client. |
Our testing teams are experienced intelligence and surveillance specialists, having gained their experience from either Intelligence, Specialist Military or police backgrounds. We work on a strictly confidential basis providing our services to a variety of industries and companies.