People & premises

Physical pentest

An on-site test of whether someone can walk into your building, reach what matters and leave — covering entry points, badges, locks, staff challenge and how your monitoring responds.

8
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

Network controls assume the attacker is remote. Many are not: a visitor badge, a held door and a confident manner still reach server rooms, unlocked workstations and printed records.

Every tester carries a signed authorization letter, and we agree in advance exactly what proves success — a photograph of a rack, a device planted in a meeting room, a document from a desk.

PTES physical testing guidance NIST SP 800-115 MITRE ATT&CK physical access techniques

What we test

  • Perimeter, entry points, loading bays and out-of-hours access
  • Tailgating, piggybacking and visitor processes
  • Reception and pretext entry — contractor, courier, auditor or new starter
  • Badge cloning and access-control weaknesses, at 125 kHz and 13.56 MHz
  • Door hardware and lock bypass on internal doors
  • Sensitive areas: server rooms, wiring closets, records storage and executive offices
  • Clean-desk practice, unattended sessions and exposed network ports
  • Alarm, camera and guard response — whether anyone challenges, and how fast
How it runs

From scoping call to retest, here’s what happens.

Typically two to four days per site, plus reconnaissance.

1

Scope and authorize

We agree sites, dates, objectives and limits, and issue authorization letters each tester carries at all times.

2

Reconnaissance

We observe the site as an attacker would: access patterns, shift changes, deliveries and what is visible from outside.

3

Attempt entry

We work through the agreed approaches, escalating only as far as the rules of engagement allow.

4

Reach the objective

Once inside, we go for the agreed objective and capture evidence without touching live systems beyond scope.

5

Report and debrief

You get a timeline with photographic evidence, what worked, what stopped us, and practical fixes.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

Doors held open as a courtesy, straight past every access control

Badges cloned from a few seconds near an employee in a public space

Server rooms and wiring closets unlocked or secured with a bypassable latch

Unattended, unlocked workstations with a session already signed in

Nobody challenging an unfamiliar face wearing the right clothes

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • Written authorization from someone who can grant site access
  • Site addresses, dates and an emergency contact reachable at all hours
  • Agreement on objectives and on what must never be touched
  • Confirmation of whether local security and staff are to be told

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.