Test or assessment?
An assessment asks how well your physical controls are designed and run: what the badges are, how leavers are removed, how visitors are handled. A penetration test asks a narrower question: can someone without authorization get to a specific place? Most organizations get more from an assessment first, then a test of the areas that matter most. Our credential and access control assessment and physical testing can be scoped together or separately.
What a test usually includes
- Reconnaissance from public spaces: entrances, smoking areas, deliveries, badge designs visible in photos.
- Entry attempts: tailgating, propped doors, the loading dock, and doors that do not latch.
- Credential attacks where authorized: reading and copying badges to show whether a copy opens the door.
- Pretexting: posing as a contractor, courier or new starter to reception or facilities.
- Objectives inside: reaching a server room, a records room or an unlocked workstation, and documenting it.
The authorization letter
Every tester on site should carry a signed letter, and it should come from someone who actually has authority over the property. In 2019 two testers were arrested at an Iowa county courthouse during a contracted test because the organization that hired them and the county that owned the building disagreed about who could authorize it. The letter should state:
- The organization, the exact addresses and the areas in and out of scope.
- The dates and hours of testing.
- The names of the testers.
- Who signed it, their authority to do so, and confirmation that the property owner agrees where the client is a tenant.
- Two emergency contacts who will answer the phone during testing, including at night.
Rules of engagement
- What is off limits: forced entry, damage, alarmed doors, specific people or areas.
- What happens if security or police respond, and who calls whom.
- How evidence is handled: photos, copied credential data, anything removed from site.
- When testing stops, and how a critical finding is reported before the final report.
What the report should give you
Not a story about how clever the tester was. You should get each finding with evidence, why it worked, what to change, and a sense of cost, ranked so the cheapest serious fixes come first. Then a re-test once those fixes are in.
For security firms
If you run network or application tests and a client has asked for a physical test, we deliver it under your rules of engagement and in your report. See working with us as a partner.
Last reviewed October 7, 2026.