Test or assessment?

An assessment asks how well your physical controls are designed and run: what the badges are, how leavers are removed, how visitors are handled. A penetration test asks a narrower question: can someone without authorization get to a specific place? Most organizations get more from an assessment first, then a test of the areas that matter most. Our credential and access control assessment and physical testing can be scoped together or separately.

What a test usually includes

  • Reconnaissance from public spaces: entrances, smoking areas, deliveries, badge designs visible in photos.
  • Entry attempts: tailgating, propped doors, the loading dock, and doors that do not latch.
  • Credential attacks where authorized: reading and copying badges to show whether a copy opens the door.
  • Pretexting: posing as a contractor, courier or new starter to reception or facilities.
  • Objectives inside: reaching a server room, a records room or an unlocked workstation, and documenting it.

The authorization letter

Every tester on site should carry a signed letter, and it should come from someone who actually has authority over the property. In 2019 two testers were arrested at an Iowa county courthouse during a contracted test because the organization that hired them and the county that owned the building disagreed about who could authorize it. The letter should state:

  • The organization, the exact addresses and the areas in and out of scope.
  • The dates and hours of testing.
  • The names of the testers.
  • Who signed it, their authority to do so, and confirmation that the property owner agrees where the client is a tenant.
  • Two emergency contacts who will answer the phone during testing, including at night.

Rules of engagement

  • What is off limits: forced entry, damage, alarmed doors, specific people or areas.
  • What happens if security or police respond, and who calls whom.
  • How evidence is handled: photos, copied credential data, anything removed from site.
  • When testing stops, and how a critical finding is reported before the final report.

What the report should give you

Not a story about how clever the tester was. You should get each finding with evidence, why it worked, what to change, and a sense of cost, ranked so the cheapest serious fixes come first. Then a re-test once those fixes are in.

For security firms

If you run network or application tests and a client has asked for a physical test, we deliver it under your rules of engagement and in your report. See working with us as a partner.

Last reviewed October 7, 2026.

Contact

Want to know how your sites would hold up?

Twenty minutes is enough to know whether an assessment is worth it. We’ll be honest either way.