APOLLOSEC

Physical penetration testing

Through the front door, past reception and into the building. We test whether someone could walk in, plug in, and walk out with your data.

That pizza delivery guy? That was us, and we left with your CE’s laptop as a ‘ti’.

Firewalls do not stop a confident visitor

Firewalls do not stop someone who walks into the office carrying a box and asks for the IT room. Physical access bypasses most technical controls: an unlocked screen, a live network port in a meeting room or a server cabinet with the key in the lock is all it takes.

Physical testing shows how your site security, reception processes and staff respond to an intruder, and what that intruder could do once inside. It is often combined with social engineering and red team engagements.

What we test

  • Perimeter and entry

    Doors, gates, car parks, loading bays and fire exits.

  • Access control

    Proximity card cloning, tailgating, and weaknesses in locks and readers.

  • Reception and pretexts

    Arriving as a contractor, delivery driver, auditor or new starter.

  • Inside the building

    Unlocked screens, open network ports, sensitive papers and unattended devices.

  • Secure areas

    Server and comms rooms, records stores and executive offices.

  • Planted devices

    Optionally, whether a small network device or rogue USB stick could be left behind and connect out unnoticed.

How the engagement runs

  1. Authorise

    We agree sites, objectives, timing and boundaries. Consultants carry signed letters of authority naming a contact who can confirm the test.

  2. Reconnoitre

    We observe entrances, staff movement and badges, from outside and from public sources.

  3. Attempt entry

    We attempt entry using the agreed pretexts and techniques, and record evidence of what we reached.

  4. Report

    A timeline with photographic evidence, the controls that worked and those that failed, and practical fixes.

What you get

  • A timeline of the intrusion with photographic evidence.
  • Findings across physical controls, processes and awareness.
  • Practical, proportionate fixes for each weakness.

When to commission it

  • When opening or moving into new premises.
  • If you hold sensitive data or equipment on site, such as server rooms or records.
  • After changing access control, guarding or reception arrangements.
  • As part of a red team engagement.

Questions we get asked

What happens if your consultant is caught?

That is a good result and goes in the report as a control that worked. The consultant follows an agreed process, shows the letter of authority, and your named contact confirms the test.

Do you test outside working hours?

We can. Out-of-hours tests look at alarms, guarding and locking up. In-hours tests focus on reception, tailgating and staff awareness. Many clients do both.

We share a building. Who needs to agree?

Usually the landlord or building management as well as you. We help you get that authorisation before we start.

Will you damage anything?

No. We do not force entry or damage property, and techniques such as lock picking are only used where agreed in advance.

Find out whether someone could just walk in.

Talk to us