My former company, Gardien Virtuel, used to do this type of testing, and I had so much fun carrying out these mandates, because with each project, there are extraordinary stories, anecdotes that make us understand just how vulnerable employees can be!

Physical intrusion testing?

Locked door – Photo by Sheldon Kennedy on Unsplash

At first, I remember being nervous about playing thief, only to realize that my biggest fear wasn’t their protective measures, but my own imagination!

I’m writing to you today simply to share with those who would like to do this work or would like to hire someone to help them.


Why perform a physical intrusion test?

Corporate threats don’t always come from missing updates, slow backups or missing policies.

Sometimes someone breaks into your home, steals your data and that’s it.

Performing a physical intrusion test means :

  • Assess the reliability of controls (locks, badges, cameras) in the face of an attacker.
  • Measure the effectiveness of procedures (identity checks, visitor management, security rounds).
  • Pinpoint human flaws (social manipulation or tailgating) before a criminal exploits them.

When should I take the test?

1. after a reorganization or move Your accesses change, plumbing plans change, and janitors are not always familiar with the new corridors. A test run just after the transition highlights any configuration oversights or risk points (e.g. temporary badge remaining active).

2. Before certification (ISO 27001, PCI-DSS) To prove your compliance, we need more than a policy report: we need tangible proof that no unauthorized visitors can get into our server room.

In ISO 27001:2022, physical security is covered in Annex A, theme “Physical controls”, and more specifically in clauses A.7.1 to A.7.13. But specifically:

  • A.7.1 – Physical Security Perimeters
  • A.7.2 – Physical Entry Control
  • A.7.3 – Securing Offices, Rooms and Facilities
  • A.7.4 – Physical Security Monitoring
  • A.7.5 – Protecting against Physical and Environmental Threats

3. After an incident After a digital breach, this is the ideal time to test your physical defenses, since an attacker who has infiltrated a workstation can use another entrance.

4. When paranoia increases If you manage sensitive data (R&D, secrets, health records), you don’t want just anyone wandering into your offices. This is the number 1 reason for large companies.

Losing control of access means losing control of assets.

For SMEs, I notice that there’s often a great deal of trust in the teams “All our employees are bona fide!” Except… naivety opens many doors. A physical test reveals these vulnerabilities before a curious trainee or malicious visitor takes advantage of them.

  • An OSINT search

A quick word about the OSINT phase, because before we do the work, we have to do our homework. open source information research, or OSINT(Open Source Intelligence). We check out what’s being said about you, what we can find out about your company, without even having to go anywhere.

We often find interesting things like poorly protected documents on your website, press releases that give too many details, or LinkedIn profiles that explain technologies or directly the photo of an access badget. With this information we have names, schedules, internal procedures and secondary accesses.


Good and not-so-good reasons for testing

Good reasons

  • Real validation: you really want to know if a thief in his clothes can outwit your cameras.
  • Regulatory compliance: To confirm our compliance and sometimes required in certain contexts.
  • Continuous improvement: strengthen your procedures by integrating concrete feedback.
  • Raising awareness: there’s nothing like a “real-life” demonstration to convince management and staff of the importance of physical safety.

Less good reasons

  • Looking good on paper: commissioning a report that nobody will read, just to tick a box.
  • Compare two suppliers: if you just want a price contest, you won’t get any in-depth analysis.
  • One-off” tests with no follow-up: an audit without an action plan is like an alarm without intervention – it’s useless.
  • Too early in the company’s life: if you don’t yet have access control, it’s best to first set up the basics (badges, cameras, policies) before testing their limits.

How to choose a good consultant

  • Proven expertise and references Look for firms specializing in physical testing, not cyber generalists with a “locks” plug-in in their method. Demand a track record of similar mandates (size, sector).
  • Clear methodology Avoid vague descriptions such as “we’ll do a physical Pentest”. You deserve a detailed plan: phases of reconnaissance, social engineering, technical bypass, reporting and re-testing.
  • Transparency about tools and techniques The best consultants explain how they’re going to do it, using pick-locks, badge copying and social manipulation. If they hide their methods, beware: you could be charged for a poor-quality test.
  • Report and follow-up The report must contain :

Description of attacks (how, where, when).

Level of risk (impact + probability).

Concrete recommendations (equipment, procedures, training).

Re-test options to verify implementation.

  • Sharing culture This point is very important to me and my personal values. Choose a partner who doesn’t point the finger at people who have failed, but coaches you, trains your team and offers a real transfer of skills.

What results to expect

A good physical intrusion test does more than just open a door; it reveals the organization’s true security posture:

  • Details of vulnerabilities Precise identification of weak points: poorly locked doors, blind cameras, uncontrolled technical access.
  • Business impact Encrypted scenario, “An attacker was able to reach the payroll server in 10 minutes”.
  • Action plan Prioritization of corrective measures, $0 improvements (changing a protocol) vs investment (installing a turnstile, badge).
  • Raising staff awareness Feedback: your employees discover that a stranger may have walked through the door saying “I forgot my badge”!
  • Resume testing Validate that patches work (ideally two to three months later).

Example

We arrived in a large office, like a downtown office tower, with receptionist, cameras, access cards and so on. The team arrived confidently and simply asked permission to go into the management office under the pretext of needing to “make a small change”.

To our surprise, we were let through with no questions asked, no ID check, no escort.

Once inside, we were left alone for several long minutes.

Long enough to go through the drawers, examine the documents on the desk, take photos of the files, and even leave with a few documents in our bags.

What struck me was how stressed the team was before they started, afraid of being arrested, confronted, denounced, when in the end there was nothing. Even today, the flaws weren’t technological. They were human, under the pretext of good faith.