Physical Penetration Testing: How Investigators Test Whether Someone Can Walk Into Your Building

Short answer: A physical penetration test is an authorized, controlled attempt to get into a building, restricted area, or sensitive asset the way a real intruder would, so the owner can find and fix weaknesses before someone with bad intentions does. Testers probe doors, badges, locks, cameras, reception procedures, and employee behavior such as tailgating and helpfulness toward strangers. Every test runs under a signed scope and written authorization from someone with legal authority over the property, and ends with a report showing what worked, what failed, and how to fix it.

Last updated October 2026 · Watchtower Investigations, Middle & West Tennessee

Key takeaways

  • Physical penetration testing measures real-world security, not just whether policies exist on paper.

  • The most common failures are human: tailgating, propped doors, unchallenged visitors, and staff who help a confident stranger.

  • Written authorization from the right person, a defined scope, and emergency contacts are non-negotiable. Testing without proper authorization can be a crime.

  • A good test produces evidence (photos, timelines, badge logs) and specific, prioritized fixes, not a list of embarrassments.

  • Physical testing pairs naturally with IT security work, because many network breaches start with someone walking in and plugging something into a port.

What is the difference between a physical penetration test and a security assessment?

A security assessment is a walkthrough and review: a consultant inspects doors, locks, lighting, camera coverage, access control settings, and policies, then compares them to good practice. It is cooperative and announced.

A physical penetration test goes further by actually attempting entry under realistic conditions, usually without front-line staff knowing a test is underway. It answers a question an assessment cannot: if a determined person tried today, would they get in, and how far would they get? Many organizations start with an assessment and follow with a penetration test once obvious gaps are closed.

What do physical penetration testers actually try?

Every engagement is scoped to the client, but common objectives and techniques include:

  • Tailgating and piggybacking. Following an employee through a badge-controlled door, often while carrying boxes or coffee so the employee holds the door.

  • Social engineering at reception. Posing as a vendor, delivery driver, inspector, or new hire to get signed in or escorted to a restricted area.

  • Perimeter and door testing. Checking for unlocked side doors, propped smoking-area exits, loading docks left open, and doors that do not latch.

  • Badge and access control weaknesses. Testing whether lost or cloned credentials still work, whether badge readers are bypassable, and whether access is revoked when it should be.

  • Lock and hardware weaknesses. Identifying hardware that can be defeated quickly, under-door gaps, exposed request-to-exit sensors, and weak latches.

  • Objective capture. Reaching a target such as a server room, records storage, an executive office, or a network port, and documenting it with a photo or a planted "flag" rather than taking anything.

  • After-hours and camera coverage tests. Determining whether alarms, guards, and cameras detect and respond to a real intrusion attempt.

Why does authorization matter so much?

In 2019, two security professionals were arrested while testing an Iowa courthouse under a contract that the people who signed it may not have had authority to grant over that building. The charges were eventually dropped, but the incident became the industry's standard cautionary tale. The lesson is simple: the person authorizing the test must have legal authority over the specific property, and every party with a stake, including building owners, landlords, and sometimes local law enforcement, must be accounted for in planning.

A professional engagement includes:

  • A written scope listing the exact addresses, buildings, floors, and objectives in scope, plus anything explicitly out of scope.

  • A signed authorization letter carried by every tester, naming the client contacts who can verify the test 24 hours a day.

  • Rules of engagement on what techniques are allowed, such as whether lock bypass is permitted, whether testers may enter after hours, and how to handle confrontation.

  • Confirmation of who owns the building if the client leases it, since a tenant may not be able to authorize testing of shared or landlord-controlled areas.

  • A stop procedure if anyone, including staff or police, challenges the tester.

Which organizations in Middle and West Tennessee benefit most?

  • Healthcare organizations with patient records, pharmacies, and controlled substances.

  • Financial institutions and credit unions with branches, vaults, and data rooms.

  • Law firms and professional services firms that store confidential client files.

  • Logistics and distribution facilities, especially around Nashville's I-24 and I-40 corridors and the Memphis freight hub, where yard and dock access matters.

  • Data centers, studios, and tech companies with valuable equipment and unreleased intellectual property.

  • Schools, churches, and venues that need to know how their access control holds up during events and normal days.

What does the final report include?

A useful report reads like an investigative report, because that is what it is. It should include an executive summary, a timeline of each attempt, photos and supporting evidence, which controls worked and which failed, root causes (for example, a door closer that does not fully latch, or a culture where nobody challenges strangers), and prioritized recommendations ranked by risk and cost. A good tester also debriefs leadership, and when appropriate, helps design staff training that focuses on behavior rather than blame. Employees who held the door were usually being polite, which is exactly what attackers count on.

How does physical testing connect to cybersecurity?

Many technical breaches begin physically: a rogue device plugged into an open network port in a conference room, a laptop taken from an unlocked office, or a sticky note with a password on a monitor. Combining physical testing with network and social engineering testing gives a realistic picture of how an attacker would chain small weaknesses together. Watchtower's penetration testing services can be scoped to include physical, digital, or both.

Frequently asked questions

Is physical penetration testing legal in Tennessee?

Yes, when it is authorized in writing by someone with legal authority over the property and conducted within the agreed scope. Without that authorization, the same actions could be trespass, burglary, or other crimes.

Will our employees know about the test?

Usually only a small group of decision-makers knows, so the test reflects normal behavior. Testers carry authorization letters and verification contacts in case they are stopped.

How long does a physical penetration test take?

Planning and reconnaissance usually take several days to a couple of weeks. Field testing for a single site is often completed over one to several days, including after-hours attempts if they are in scope. Reporting follows within a short period.

What if a tester gets caught?

Getting caught is a good result for the client because it means a control worked. The tester stops, presents the authorization letter, and the verification contact confirms the test. The report records the detection.

Do you take anything during the test?

No. Objectives are documented with photographs or harmless flags. Nothing is removed, damaged, or accessed beyond what the scope permits.

How often should we test?

Many organizations test annually, after significant facility changes, after a security incident, or after a change in access control systems.

Find out how your building holds up

Watchtower Investigations conducts authorized physical security assessments and penetration tests across Middle and West Tennessee, backed by the statewide resources of Delator Group. Contact us to discuss scope and authorization for your facility.

Previous
Previous

Davidson County Court Records Research: Where Nashville Records Live and Why an Online Search Isn’t Enough

Next
Next

Music Industry Investigations in Nashville: Due Diligence, Missing Co-Writers, and Royalty Disputes