01 / Physical security

Facility testing and audit.

The building itself, assessed the way an intruder would approach it — from the perimeter fence to the server room door.

CSG-01

Facility security assessment

On-site review of perimeter, entry points, reception, secure areas, loading docks, and sensitive zones such as data centers and control rooms.

CSG-02

Surveillance & CCTV gap analysis

Camera placement, coverage mapping, blind spots, recording quality, and retention compliance.

CSG-03

Guard-force & procedure review

Covert and overt assessment of guarding, visitor management, challenge protocols, patrols, and incident readiness.

CSG-04

Security design & planning

Security requirements for new builds and fit-outs — protection designed in from the start, where it costs least.

02 / Social engineering

Testing people and process.

The best controls can be bypassed by a confident stranger at reception. We test your people the way real adversaries do.

Physical impersonation

Covert access under false pretexts — contractor, delivery, inspection, and maintenance scenarios.

Tailgating & piggybacking

Controlled entry-point bypass testing: challenge behavior, door-hold culture, anti-tailgate measures.

Vishing

Telephone social engineering against reception, helpdesk, and facilities staff.

Pretexting & elicitation

Posing as tenants, auditors, or inspectors to test information-disclosure controls.

Waste & OSINT review

What your bins and your public footprint give an attacker before they ever arrive on site.

Susceptibility reporting

Department-level breakdowns and targeted training recommendations.

03 / Training

Testing finds the gaps. Training closes them.

CSG-05

Social engineering prevention

Scenario-based workshops that teach staff to recognize and resist impersonation, tailgating, vishing, and pretexting. On-site or virtual, tailored to your threat profile.

CSG-06

All-staff security awareness

A structured programme covering the physical security every employee owns: badge and visitor etiquette, clean desk, spotting suspicious behavior, and incident reporting.

Delivered as a one-time engagement after an assessment, or as a recurring programme — quarterly refreshers, new-starter inductions, annual updates — under a retainer.

04 / Access control

Who can go where — and whether your systems enforce it.

Access control systems audit

Card readers, door controllers, turnstiles, mantraps, biometrics — including firmware, default credentials, and fail-safe configuration.

Key & lock management

Mechanical and electronic locks, master-key hierarchies, issuance and lost-key protocols.

Visitor & contractor management

Sign-in procedures, escort policies, temporary passes, and contractor vetting.

Joiner / mover / leaver controls

Whether access rights are correctly granted on hire, updated on role change, and fully revoked on departure.

05 / Flagship

e-Government & national identity.

For governments, physical security reaches every facility — and every credential those facilities produce. We secure both the buildings and the documents, from passport issuance to ministerial offices. Independent and vendor-neutral throughout.

Government & public buildings

Ministerial offices, embassies, courts, and citizen-facing sites — aligned to national protective security standards.

ePassport & smart card security

Issuance, encoding, and blank-stock controls that prevent cloning and fraudulent provisioning. ICAO Doc 9303 aligned.

Secure issuance facilities

The bureaus where credentials are produced — secure printing, chip encoding, supply-chain control.

Critical national infrastructure

Utilities, transport, energy, and telecommunications — supporting CNI protection frameworks.

ICAO Doc 9303ISO/IEC 7816 · 14443eIDASNPSA
Discuss a programme
06 / Strategy

A security function, not a stack of reports.

Policy development

Physical security policies and procedures aligned to ASIS and NPSA guidance.

Maturity assessment

Benchmarking against industry frameworks, with a prioritized, costed roadmap.

Incident response planning

Playbooks for intruder, bomb threat, and hostile actor scenarios — written, then exercised.

07 / Questions

Asked often.

A physical security audit is a structured assessment of how well your buildings, perimeter, access controls, and procedures protect your people and assets against real-world intrusion. Calibre Security Group reviews every layer — from the perimeter fence to the server-room door — and delivers a prioritized, costed list of gaps and fixes.

An audit evaluates your controls against best practice; a physical penetration test actively attempts to defeat them. Our testers try to gain unauthorized access the way a real attacker would — tailgating, impersonation, lock bypass, and social engineering — to prove which weaknesses are genuinely exploitable rather than just theoretical.

A facility security assessment covers perimeter protection, entry points and reception procedures, CCTV coverage and blind spots, access control and key management, secure areas such as data centers and control rooms, guard-force performance, and visitor and contractor handling. You receive a single report mapping every finding to a clear remediation step.

Most organizations benefit from a full physical security assessment annually, with interim reviews after major changes — a new site, a refit, a merger, or a shift in threat profile. High-risk environments such as data centers and critical infrastructure often run more frequent, targeted testing as part of an ongoing retainer.

Yes. Testing reveals where your people are vulnerable; training closes the gap. We deliver scenario-based social engineering prevention workshops and a structured all-staff security awareness program covering tailgating, vishing, badge etiquette, and incident reporting — available standalone or as part of a retainer.

We work with global enterprises, data centers, critical national infrastructure, government and public-sector buildings, and regulated industries. Engagements are aligned to recognized standards such as CPNI/NPSA and ASIS, and tailored to each site’s threat profile and compliance requirements.

Contact

Not sure where to begin?

Tell us about your sites. We'll point you at the highest-priority gaps — even if that means a smaller engagement than you expected.