Physical penetration testing that walks through the front door.
Digital security means nothing if someone can simply walk in. SubRosa tests your facilities the way a real intruder would, access controls, surveillance, and staff awareness, to find the physical gaps before someone else does.
Access control · Tailgating · Surveillance · Data center
What is physical penetration testing?
Physical penetration testing is a real-world breach simulation of your facilities: bypassing locks, badge readers, and surveillance, and using pretexts like posing as a vendor or contractor to get past staff. It proves whether an attacker could reach sensitive areas such as server rooms or executive offices, and shows where your access controls, monitoring, and staff procedures need to improve.
From the perimeter to the server room.
We test every layer of your physical security posture, from perimeter defenses to internal controls.
Facility & perimeter
Assessment of locks, doors, perimeter, and environmental controls for the weaknesses an intruder would exploit to get inside.
Access control systems
Testing of card readers, biometric systems, keypad locks, and badge cloning to find bypasses in your access control.
Physical social engineering
Tailgating, pretexting, and manipulation of security personnel to test how staff verify and challenge unfamiliar people.
Surveillance & response
Evaluation of CCTV, alarms, and monitoring for blind spots, plus testing of how your team detects and responds to a physical intrusion.
How a physical test actually runs.
Physical testing carries risks the digital kind does not — a tester can be detained. The controls that prevent that are agreed before anyone approaches your building.
- 01
Scoping, rules and authorisation letter
We agree which sites, which entrances, what is off limits and which hours. Every tester carries a signed authorisation letter, and we agree who at your organisation can verify it at any hour, because the point at which someone calls the police is the point that letter matters.
- 02
Reconnaissance
Publicly observable detail first: entry points, badge readers, camera placement, delivery and contractor routines, smoking areas, shift changes. Most successful intrusions exploit a routine rather than a lock.
- 03
Covert entry attempts
Tailgating, badge cloning, unsecured secondary entrances, delivery access and lock bypass are attempted within the agreed rules. We record what worked and, more usefully, what was noticed but not challenged.
- 04
Once inside
Reaching the inside is rarely the objective. We test what an intruder could do once there: unattended unlocked workstations, network ports in meeting rooms, documents left out, server room access, and how long presence goes unquestioned.
- 05
Staff and response testing
This is where the finding usually is. Did anyone challenge an unfamiliar face? Was a badge checked or waved through? Did anyone report it afterwards? Response behaviour is what determines whether a physical control is real.
- 06
Reporting and debrief
Findings arrive with photographic evidence and a route-by-route account of what worked, plus recommendations separated into physical fixes and staff-process changes, with a live debrief for facilities and security together.
The gap between digital and physical.
Real breach simulation
We attempt genuine, safe entry rather than a clipboard walkthrough, so you see what a determined intruder could actually achieve.
People and technology
We test the technology and the people together, because attackers exploit whichever is weaker on the day.
Path to the crown jewels
We chain physical access into what it unlocks, server rooms, workstations, and data, showing the full business impact of a breach.
From walkthrough to remediation.
Your physical assessment findings land in Sable, prioritized, assigned, and tracked from open to retested, so the fixes to doors, controls, and procedures actually happen and stay verified.
- CriticalOpenTailgated into server roomData center
- HighIn progressCloned badge grants accessLobby
- HighRetestedLoading dock left unlockedPerimeter
- MediumOpenCCTV blind spot at side entrySurveillance
Common questions
- What is physical penetration testing?
- Physical penetration testing is a real-world breach simulation of your facilities: bypassing locks, badge readers, and surveillance, and using pretexts like posing as a vendor or contractor to get past staff. It proves whether an attacker could reach sensitive areas such as server rooms, and shows where your access controls, monitoring, and staff procedures need to improve.
- Is physical penetration testing safe and authorized?
- Yes. Every engagement is fully authorized, scoped, and conducted under a rules-of-engagement agreement with designated points of contact and get-out-of-jail documentation. SubRosa's testers attempt genuine but safe entry, coordinated so there is no disruption to operations or risk to staff.
- Is physical penetration testing legal, and what protects your testers?
- It is legal when properly authorised, and the authorisation is the critical control. Every tester carries a signed letter naming the sites, the dates and the agreed activities, and we agree in advance who at your organisation can verify it at any hour. Without that in place a test can end with a tester detained and a genuinely difficult conversation, which is why we will not run one without it.
- Will you damage anything, or break locks?
- No. Testing is non-destructive by default: tailgating, cloned or borrowed credentials, unsecured secondary entrances, and bypass techniques that leave no damage. Destructive entry is excluded unless you specifically request it and we agree the terms in writing.
- Should staff know a physical test is happening?
- Almost never beyond a very small authorised group. The most valuable finding is behavioural — whether an unfamiliar person is challenged, whether a badge is actually checked, whether anyone reports it afterwards — and none of that can be measured if people are expecting a test.
- What do you deliver afterwards?
- A report with photographic evidence and a route-by-route account of what worked, separated into physical remediation and staff-process change, plus a live debrief with facilities and security together. Reporting is aggregate rather than naming individuals — the goal is a better-prepared team, not a disciplinary file.
Test what happens at the front door.
Book a physical penetration test and find out whether an intruder could reach your most sensitive areas, and how to stop them.