Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

Physical Penetration Test

Physical Security can often be overlooked. A malicious actor who can bypass physical security controls can easily gain a foothold on the network. This physical breach campaign simulates a real-world attack scenario while identifying personnel training gaps and physical security issues.

Contact a Specialist Read More About Schellman's Approach

What Happens During a Physical Penetration Test?

Our testers will collaborate with you to determine an effective and realistic physical security scenario. A Rules of Engagement (ROE) letter will then be drafted detailing information regarding testing times, entry methods, and other requirements. The testers will travel to the physical site and attempt to gain access to the facility while remaining undetected.
During the engagement, photos and videos are taken as evidence, which are included in the report as a demonstration and to aid your security teams in understanding the identified security vulnerabilities and how to remediate them. The end goal of the physical penetration test is to gain unauthorized access to the designated facility and a foothold on the organization's internal corporate network.

A Physical Pen Test Can Help You

https://www.schellman.com/hubfs/improve-security.png

Prepare for real-world attacks against your facilities

A physical penetration test identifies gaps and shows what the impact and cost of that access is to your organization. This could include unauthorized access to sensitive data, setting up malicious devices to grant persistent access to your network, or introducing ransomware.

https://www.schellman.com/hubfs/staff-awareness.svg

Raise security awareness amongst your staff

Discover how many of your employees can identify suspicious or unknown employees/contractors. Identify habits of employees such as holding doors and not using electronic access control.

https://www.schellman.com/hubfs/meet-compliance-requirements.png

Validate Your Security Process Implementation

This type of assessment will examine how well your procedures are designed for physical security best practices and where or not they are strictly followed.

https://www.schellman.com/hubfs/improve-security-posture-2.svg

Improve your security posture

A physical penetration test can reveal a lot regarding your more unique, less tech-focused aspects of cybersecurity and reduce the risk of these kinds of attacks, increasing your overall security.

Schellman’s Physical Penetration Methodology

Schellman will attempt to physically enter your facility as an external attacker. We’ll begin with information gathering regarding your environment through methods including, but not limited to, Internet research, site observation, and wireless reconnaissance. Using the information we discover, we’ll craft scenarios for social engineering, determine where entry points are, identify internal security mechanisms, and acquire the necessary equipment. 

When the time arrives, we’ll attempt to gain access to the target location via the designed pretexts, unsecured points of entry, or other non-destructive means of entry before providing you with a deliverable that walks through each aspect of the project.

Schellman’s Methodology Flow:

  • Goals for the physical penetration test are defined and agreed upon. A “Get Out of Jail Free Card” is signed by authorized personnel. 
    Information gathering including photos of each defined location and entry points of facilities.
  • Travel accommodations are defined and agreed upon included in the total cost of the assessment.
  • Execution begins starting with reconnaissance of in scope locations and defining all entry points, attempting to gain unauthorized access to each location.

Is Schellman the Right Firm for You?

Schellman does perform password strength assessments—our Penetration Testing Team continues to grow and is currently comprised of individuals from different backgrounds including former developers, system administrators, and lifelong security professionals. Our team is incredibly experienced, and collectively holds the following professional certifications, among others: 

Frequently Asked Questions

How long will a physical penetration test take?

What does a physical pen test campaign cost at Schellman?

How often should I have a physical penetration test performed?

How do I decide on a specific goal for this engagement?

What happens to the photos and videos taken during the engagement?

What happens if the local authorities show up during the engagement?

What should you look for when choosing your physical pen test provider?

Take the first step towards protecting your facility from external attackers

Our team of practice leaders, not sales, are ready to talk and help determine your best next steps.

Start Scoping Your Penetration Test Contact a Specialist