The test examines whether the physical protective measures of a site can be circumvented under realistic conditions: perimeter, access and escort processes, protection of server rooms and technical areas as well as the behaviour of employees. NIST SP 800-115 describes physical security testing as a non-technical testing technique in which locks, badge readers and other physical controls are defeated in order to gain unauthorised access to specific systems. ISECOM's OSSTMM 3 assigns such tests to the Physical Security (PHYSSEC) class with its two channels Human and Physical, and requires results that are quantitatively measurable, consistent and repeatable and that contain only facts from the test itself – explicitly without subjective interpretation. The BSI practical guide for IS penetration tests likewise explicitly lists infrastructure facilities such as access control mechanisms and building management as a common test object.
Physical security in the penetration test
How access controls, building processes and on-site behaviour can be verified under realistic attack conditions – controlled, authorised and documented in a traceable way.
In many security programmes, physical security is considered a closed case: there is a perimeter, turnstiles, badge readers and a security service. Whether these measures actually hold up in combination with people and processes only becomes apparent under attack conditions – for instance when someone walks through with a plausible role, a cloned card or simply in the slipstream of a group. A physical penetration test examines exactly that: with a clearly limited scope, written authorisation and defined abort criteria. It thus provides evidence of effectiveness for measures that cannot be reliably assessed through document review alone.
The Essentials at a Glance
Six topic blocks — tap to expand.
Typical attack scenarios
Four routes from the outside area into the building — tap a scenario.
- Tailgating behind authorised persons and pretended roles such as service provider, supplier or auditor (onsite social engineering).
- At the centre is the question of how far an attacker gets inside the building.
- Unsecured secondary routes via goods delivery, underground car park or side entrances.
- Mechanical attacks on locking and latching hardware.
- With the widely used MIFARE Classic, each memory sector is protected by its own 48-bit key of the CRYPTO1 stream cipher.
- Attacks published as early as 2009 require nothing more than radio contact with the card — without access to a genuine reader — and reconstruct a key in less than a second on off-the-shelf hardware, so that the card can be copied immediately.
- USB drops test the last mile on the inside.
- In a field study with 297 USB drives dropped on a campus, the estimated success rate was between 45 and 98 percent; the first drive was plugged in in less than six minutes — predominantly to find the owner.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Technical Guide to Information Security Testing and Assessment (SP 800-115)
Describes physical security testing as a non-technical testing technique and contains, in Appendix B, a template for rules of engagement including an exclusion list and abort criteria.
Ein Praxis-Leitfaden für IS-Penetrationstests, Version 1.2
Names access control mechanisms and building management as a common test object and sets out requirements on the written engagement, the involvement of data protection and employee representatives, test depth, report structure, criticality levels and the repeat cycle.
ISO/IEC 27002:2022 – Information security, cybersecurity and privacy protection – Information security controls
Provides the implementation guidance for the 14 physical controls (7.1 to 7.14) that Annex A of ISO/IEC 27001:2022 lists as A.7.
OSSTMM 3 – The Open Source Security Testing Methodology Manual
Lists Human and Physical as separate testing channels of the Physical Security (PHYSSEC) class and requires quantitatively measurable, consistent and repeatable test results without subjective interpretation.
Users Really Do Plug in USB Drives They Find
Field study with 297 dropped USB drives: estimated success rate 45 to 98 percent, first drive plugged in after less than six minutes.
Wirelessly Pickpocketing a Mifare Classic Card
Shows four attacks that require only radio contact with the card; the most serious one reconstructs a 48-bit CRYPTO1 sector key in under a second on off-the-shelf hardware and allows the card to be copied immediately.
Related Services
Physical protective measures put to the test?
We assess sites, scenarios and framework conditions together with you and clarify in an initial conversation which test scope and which rules of engagement make sense for you.