You can have the best access control system on the market, put CCTV at every entrance and potential blind spots, and staff reception all day. But what happens when the person walking through the door is confident and looks like they belong?
It’s a common pattern behind physical security failures our consultants find during engagements. Not many employees are confident to challenge someone in those situations.
What physical penetration testing checks
Physical penetration tests are authorised, simulated intrusions carried out by a security consultant to find out what a real attacker could do and how far they could get in a building. And it tests whether staff actually challenge someone who shouldn’t be there – whether they look like should be or not.
For BSIA members, that’s the natural complement to the systems you design, install and maintain. The specification proves the system’s capable, the test proves people use it.
Real life example
On one engagement, a Citation Cyber consultant told staff they needed to reissue their access cards under a new lift policy. They were told simply – no card, no lift access. Staff queued up to hand theirs over, some even brought colleagues across to update theirs, too. Within minutes, the tester had everything they needed to clone working credentials and gain access. And all it took was playing on the fact that people wanted the ease of using the lift.
The access control system worked exactly as specified. The issue was nobody checked who was asking them.
Why you need to consider the human element
Adding extra controls is sensible for security, but it can make staff feel safer and less likely to use their judgement. Badge readers, CCTV and reception create the impression someone else has already checked. The stronger the system looks, the less staff feel they have a job to verify everyone.
That’s not to say strong physical security doesn’t matter, it absolutely does. Pairing it with a test of how staff response under pressure proves it holds up under an actual attempt. It gives your client a complete picture of their risk and gives you evidence your recommendation worked in practice.
What a strong physical security setup should include
- Access control and CCTV specified to the actual risk, not just the budget.
- Responsibility for everyone to challenge unrecognised visitors. And training on what to look out for.
- Tailgating treated as a reportable event in the same way phishing clicks are reported to IT.
- Regular testing of staff response. Annually is recommended, more often on higher-risk sites or after any building changes.
A gap worth knowing
The access card example is just one of several tactics Citation Cyber’s consultants use to test well-secured sites. In another example, a consultant accessed an unattended server room unsupervised in under two minutes. You can view the full writeup on Citation Cyber’s blog.
Citation Cyber - here to help
Citation Cyber work with organisations across the security sector to strengthen their resilience. We understand the unique pressures you face, and we're here to help you prepare before pressure becomes crisis.
As a BSIA member, you're entitled to exclusive discounts on our cyber security services. To learn more about incident response planning and tabletop exercises, get in touch using the code BSIAMEMBER or call us on 0345 241 3100.