Penetration Testing

Physical penetration testing that walks through the front door.

Digital security means nothing if someone can simply walk in. SubRosa tests your facilities the way a real intruder would, access controls, surveillance, and staff awareness, to find the physical gaps before someone else does.

Access control · Tailgating · Surveillance · Data center

Physical penetration testing, defined

What is physical penetration testing?

Physical penetration testing is a real-world breach simulation of your facilities: bypassing locks, badge readers, and surveillance, and using pretexts like posing as a vendor or contractor to get past staff. It proves whether an attacker could reach sensitive areas such as server rooms or executive offices, and shows where your access controls, monitoring, and staff procedures need to improve.

What we test

From the perimeter to the server room.

We test every layer of your physical security posture, from perimeter defenses to internal controls.

Facility & perimeter

Assessment of locks, doors, perimeter, and environmental controls for the weaknesses an intruder would exploit to get inside.

Access control systems

Testing of card readers, biometric systems, keypad locks, and badge cloning to find bypasses in your access control.

Physical social engineering

Tailgating, pretexting, and manipulation of security personnel to test how staff verify and challenge unfamiliar people.

Surveillance & response

Evaluation of CCTV, alarms, and monitoring for blind spots, plus testing of how your team detects and responds to a physical intrusion.

How the engagement runs

How a physical test actually runs.

Physical testing carries risks the digital kind does not — a tester can be detained. The controls that prevent that are agreed before anyone approaches your building.

  1. 01

    Scoping, rules and authorisation letter

    We agree which sites, which entrances, what is off limits and which hours. Every tester carries a signed authorisation letter, and we agree who at your organisation can verify it at any hour, because the point at which someone calls the police is the point that letter matters.

  2. 02

    Reconnaissance

    Publicly observable detail first: entry points, badge readers, camera placement, delivery and contractor routines, smoking areas, shift changes. Most successful intrusions exploit a routine rather than a lock.

  3. 03

    Covert entry attempts

    Tailgating, badge cloning, unsecured secondary entrances, delivery access and lock bypass are attempted within the agreed rules. We record what worked and, more usefully, what was noticed but not challenged.

  4. 04

    Once inside

    Reaching the inside is rarely the objective. We test what an intruder could do once there: unattended unlocked workstations, network ports in meeting rooms, documents left out, server room access, and how long presence goes unquestioned.

  5. 05

    Staff and response testing

    This is where the finding usually is. Did anyone challenge an unfamiliar face? Was a badge checked or waved through? Did anyone report it afterwards? Response behaviour is what determines whether a physical control is real.

  6. 06

    Reporting and debrief

    Findings arrive with photographic evidence and a route-by-route account of what worked, plus recommendations separated into physical fixes and staff-process changes, with a live debrief for facilities and security together.

Why SubRosa

The gap between digital and physical.

Real breach simulation

We attempt genuine, safe entry rather than a clipboard walkthrough, so you see what a determined intruder could actually achieve.

People and technology

We test the technology and the people together, because attackers exploit whichever is weaker on the day.

Path to the crown jewels

We chain physical access into what it unlocks, server rooms, workstations, and data, showing the full business impact of a breach.

Every gap, tracked to closed.

From walkthrough to remediation.

Your physical assessment findings land in Sable, prioritized, assigned, and tracked from open to retested, so the fixes to doors, controls, and procedures actually happen and stay verified.

Physical findings in Sable
Physical findingsFacility breach
  • Critical
    Tailgated into server room
    Data center
    Open
  • High
    Cloned badge grants access
    Lobby
    In progress
  • High
    Loading dock left unlocked
    Perimeter
    Retested
  • Medium
    CCTV blind spot at side entry
    Surveillance
    Open
Access · surveillance · staffPrioritized · assigned

Common questions

What is physical penetration testing?
Physical penetration testing is a real-world breach simulation of your facilities: bypassing locks, badge readers, and surveillance, and using pretexts like posing as a vendor or contractor to get past staff. It proves whether an attacker could reach sensitive areas such as server rooms, and shows where your access controls, monitoring, and staff procedures need to improve.
Is physical penetration testing safe and authorized?
Yes. Every engagement is fully authorized, scoped, and conducted under a rules-of-engagement agreement with designated points of contact and get-out-of-jail documentation. SubRosa's testers attempt genuine but safe entry, coordinated so there is no disruption to operations or risk to staff.
Is physical penetration testing legal, and what protects your testers?
It is legal when properly authorised, and the authorisation is the critical control. Every tester carries a signed letter naming the sites, the dates and the agreed activities, and we agree in advance who at your organisation can verify it at any hour. Without that in place a test can end with a tester detained and a genuinely difficult conversation, which is why we will not run one without it.
Will you damage anything, or break locks?
No. Testing is non-destructive by default: tailgating, cloned or borrowed credentials, unsecured secondary entrances, and bypass techniques that leave no damage. Destructive entry is excluded unless you specifically request it and we agree the terms in writing.
Should staff know a physical test is happening?
Almost never beyond a very small authorised group. The most valuable finding is behavioural — whether an unfamiliar person is challenged, whether a badge is actually checked, whether anyone reports it afterwards — and none of that can be measured if people are expecting a test.
What do you deliver afterwards?
A report with photographic evidence and a route-by-route account of what worked, separated into physical remediation and staff-process change, plus a live debrief with facilities and security together. Reporting is aggregate rather than naming individuals — the goal is a better-prepared team, not a disciplinary file.

Test what happens at the front door.

Book a physical penetration test and find out whether an intruder could reach your most sensitive areas, and how to stop them.