Book an Appointment

Physical security in the penetration test

How access controls, building processes and on-site behaviour can be verified under realistic attack conditions – controlled, authorised and documented in a traceable way.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

93controls in Annex A of ISO/IEC 27001:2022
14of them physical controls (A.7.1 to A.7.14)
45–98percent estimated success rate — field study with 297 dropped USB drives
48bit CRYPTO1 key of the MIFARE Classic — reconstructed in less than a second

In many security programmes, physical security is considered a closed case: there is a perimeter, turnstiles, badge readers and a security service. Whether these measures actually hold up in combination with people and processes only becomes apparent under attack conditions – for instance when someone walks through with a plausible role, a cloned card or simply in the slipstream of a group. A physical penetration test examines exactly that: with a clearly limited scope, written authorisation and defined abort criteria. It thus provides evidence of effectiveness for measures that cannot be reliably assessed through document review alone.

The Essentials at a Glance

Six topic blocks — tap to expand.

Typical attack scenarios

Four routes from the outside area into the building — tap a scenario.

Entry
  • Tailgating behind authorised persons and pretended roles such as service provider, supplier or auditor (onsite social engineering).
  • At the centre is the question of how far an attacker gets inside the building.
TailgatingService providerSupplierAuditorOnsite social engineering

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

National Institute of Standards and Technology (NIST) · 2008

Technical Guide to Information Security Testing and Assessment (SP 800-115)

Describes physical security testing as a non-technical testing technique and contains, in Appendix B, a template for rules of engagement including an exclusion list and abort criteria.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2016

Ein Praxis-Leitfaden für IS-Penetrationstests, Version 1.2

Names access control mechanisms and building management as a common test object and sets out requirements on the written engagement, the involvement of data protection and employee representatives, test depth, report structure, criticality levels and the repeat cycle.

ISO/IEC · 2022

ISO/IEC 27002:2022 – Information security, cybersecurity and privacy protection – Information security controls

Provides the implementation guidance for the 14 physical controls (7.1 to 7.14) that Annex A of ISO/IEC 27001:2022 lists as A.7.

ISECOM (Institute for Security and Open Methodologies) · 2010

OSSTMM 3 – The Open Source Security Testing Methodology Manual

Lists Human and Physical as separate testing channels of the Physical Security (PHYSSEC) class and requires quantitatively measurable, consistent and repeatable test results without subjective interpretation.

IEEE Symposium on Security and Privacy (Tischer et al.) · 2016

Users Really Do Plug in USB Drives They Find

Field study with 297 dropped USB drives: estimated success rate 45 to 98 percent, first drive plugged in after less than six minutes.

IEEE Symposium on Security and Privacy (S&P '09) – Garcia et al., Radboud University Nijmegen · 2009

Wirelessly Pickpocketing a Mifare Classic Card

Shows four attacks that require only radio contact with the card; the most serious one reconstructs a 48-bit CRYPTO1 sector key in under a second on off-the-shelf hardware and allows the card to be copied immediately.

Physical protective measures put to the test?

We assess sites, scenarios and framework conditions together with you and clarify in an initial conversation which test scope and which rules of engagement make sense for you.