Nashville & Middle Tennessee · Security testing

Nashville Physical Penetration Testing Your badge system is fine. Your back door at 7am is not.

Every facility has a policy that works on paper and a reality that works differently at shift change. Watchtower Investigations tests the physical one: whether a stranger can walk in behind an employee, talk past a front desk, reach a server room or a records cabinet, and leave without anyone asking a question. Then we document exactly how, so you can close it.

  • Authorized, scoped testing with a written engagement letter and an escape clause on hand
  • Physical access and social engineering only — we do not test networks or systems
  • Photographic documentation of every point reached and every control that failed
  • A remediation report that prioritizes fixes by what an actual intruder would exploit first

Free scoping call · Written authorization required before any test · Findings reported to leadership only

  • Licensed Tennessee investigators
  • Confidential from the first call
  • Court-ready documentation
  • Backed by Delator Group

Find any Watchtower service

Search all 73 investigation and process serving services by situation, service or city. Every result opens its own page.

Browse all 73 services below

Core services

Specialty casework · 61 case types

Relationship & Domestic Matters4
Covert Surveillance6
Vetting & Records Research7
Digital Privacy1
Business & Corporate Matters11
Defense Case Support4
Employment Disputes3
Security & Readiness Reviews5
People Locating6
Difficult Circumstances4
Property Loss & Theft3
Facility & Care Oversight2
Vehicle & Repair Disputes3
Fraud & Deception2
What physical pen testing is

What a physical penetration test actually tests

A physical penetration test answers one question with evidence rather than opinion: can an unauthorized person get to something that matters? Not whether the badge system is configured correctly, but whether a stranger in a safety vest carrying a ladder gets held at the door or held open for.

Be clear on the boundary. This is physical access and social engineering testing. We do not test networks, applications or systems, and we do not perform anything resembling a cyber penetration test. Those are a different discipline with different qualifications, and an investigator who offers both is overselling one of them. Where a network assessment is what you need, we will say so and point you elsewhere.

What we do test is the part that most organizations never examine: tailgating at the main entrance, propped service doors, the smoking area exit, badge cloning exposure at the reader level, front desk and reception response to a plausible pretext, vendor and delivery impersonation, after-hours cleaning crew access, unsecured records and unattended workstations, and whether anyone reports an encounter with a stranger afterward.

The most valuable finding is usually not the door that opened. It is the number of employees who saw a stranger in a restricted area and said nothing, and whether a single report reached security. A facility where three people challenged the tester is in far better shape than one with a superior badge system and a culture of assuming somebody else checked.

Who we help

Who commissions a physical security test

Four reasons organizations decide to find out for certain.

Businesses with sensitive premises

Companies holding records, inventory, equipment or data whose loss would be material, wanting to know the real exposure.

Organizations after an incident

Leadership responding to a breach, a theft or a near miss who need to know whether the gap was unique or systemic.

Compliance and audit driven

Organizations whose framework or insurer expects periodic physical security assessment with documented findings.

Leadership testing a recent investment

Companies who have just upgraded access control and want independent verification that it works in practice.

What’s included

What we test

Scoped against your facility and what you actually want protected.

01

Perimeter and entry testing

Whether main entrances, service doors, loading areas and secondary exits can be entered without authorization, including tailgating.

02

Social engineering on site

Pretext approaches at reception and to staff: vendor, contractor, delivery, IT support and new-employee scenarios, and how each is handled.

03

Badge and access control testing

Whether credentials can be observed, borrowed, cloned at the reader level or simply not required in practice.

04

Interior movement and target access

Once inside, how far an unauthorized person reaches: server rooms, records storage, executive offices, unattended workstations and unsecured files.

05

After-hours and shift-change testing

Testing during the windows where controls are weakest: early morning, shift change, cleaning crew hours, weekends.

06

Response and reporting assessment

Whether anyone challenged the tester, whether an incident was reported, how long it took and who it reached.

Tennessee law

Authorization, and why it is the whole engagement

The only thing separating a penetration test from a burglary is a written authorization from someone with the authority to grant it. We do not begin without one, for your protection and ours.

What a licensed investigator can do

  • Test only the sites, entry points and scenarios named in the signed authorization
  • Carry a signed authorization letter on the tester's person for the duration of every test
  • Photograph points reached and controls that failed, as evidence for the findings report
  • Interact with staff using approved pretexts, within the boundaries the scope defines
  • Report findings to the named leadership contacts only

What we won’t do, and why it protects you

  • Test any site, system or scenario outside the written scope, however tempting the opening
  • Test networks, applications or systems — this engagement is physical and social only
  • Damage property, force a lock, or defeat a physical barrier destructively
  • Access, photograph or remove actual confidential data, records or property
  • Name individual employees in a way that turns a findings report into a disciplinary instrument

That last point is deliberate and worth stating plainly. If the report becomes a list of which employees failed, the next test gets sabotaged and honest reporting stops. We document what happened by role and control — reception did not verify, the east door was propped — rather than by name. The exception is conduct you would want to know about irrespective of the test, which we raise with leadership directly.

How it works

How a penetration test runs

Authorization, reconnaissance, testing, then the report that makes it useful.

Scoping call

We discuss the facility, what you most want protected, which scenarios are in bounds, and who inside the organization will know the test is occurring.

Free · Leadership only

Written authorization

A signed engagement letter defining sites, dates, permitted scenarios, emergency contacts and the escape clause the tester carries.

Required before any activity

Reconnaissance

Open-source and external observation: shift patterns, entry points, vendor traffic, badge appearance and publicly available organizational information.

Conducted without contact

Testing

Scenarios executed across multiple time windows, with each attempt, outcome and point reached documented photographically.

Typically across several days

Findings and remediation briefing

A report by control and role rather than by employee, prioritized by what an actual intruder exploits first.

Debrief with leadership included
What you receive

What the findings report contains

Written to be acted on, not filed.

  • Every entry attempt with the date, time, method and outcome recorded
  • Photographic evidence of each point reached and each control that failed
  • A record of which pretexts succeeded, which were challenged, and by which role
  • Whether the presence of a stranger was reported, to whom, and how long it took
  • Prioritized remediation, ordered by what an actual intruder would exploit first
  • A leadership debrief, with retest available after remediation is implemented
Pricing

What a physical penetration test costs

Testing is quoted per engagement rather than hourly, because the deliverable is a scoped assessment with a defined report rather than an open-ended investigation. A single-site office test is a different quote from a multi-location engagement with after-hours windows.

Most of the cost sits in reconnaissance and the number of distinct time windows tested, not in the test attempts themselves. A facility tested only during business hours has been partially tested; shift change and after-hours are where the findings usually are, and they take separate visits.

Retests after remediation are quoted at a reduced rate, because the reconnaissance is already done. We recommend one — a fix that was never verified under the same conditions is a fix you are taking on faith.

What moves the cost

  • Number of sites and the size of each facility
  • How many distinct time windows are tested, including after-hours and weekends
  • Whether social engineering scenarios are in scope alongside physical entry
  • How deep into the facility the scope authorizes testing
  • Travel distance for sites outside Middle Tennessee
  • Whether a post-remediation retest is included at the outset
Coverage

Where we test

Middle Tennessee directly from Nashville, with multi-site engagements handled across the state.

Counties we work regularly

  • Davidson County
  • Williamson County
  • Rutherford County
  • Sumner County
  • Wilson County
  • Montgomery County
  • Robertson County
  • Maury County
  • Cheatham County
  • Shelby County
  • Madison County

Cities across Middle & West Tennessee

  • Nashville
  • Brentwood
  • Franklin
  • Murfreesboro
  • Hendersonville
  • Gallatin
  • Mt. Juliet
  • Clarksville
  • Columbia
  • Lebanon
  • Memphis
  • Jackson
13 questions answered

Questions about physical penetration testing

Do you test networks or perform cyber penetration testing?

No, and we want that clear before a scoping call rather than after. This engagement covers physical access and social engineering: doors, badges, reception, vendor impersonation, interior movement and staff response. Network, application and system testing is a separate discipline with separate qualifications, and a firm offering both as one package is usually strong at one and thin on the other. If a network assessment is what you need, we will tell you and help you find the right firm rather than taking the engagement.

Who inside our organization should know the test is happening?

As few people as the situation allows, which is usually two or three: the executive commissioning the test, the security lead, and one emergency contact reachable during the test window. The value of the exercise collapses if the front desk has been told to expect someone, and equally if nobody in the organization can confirm the tester is authorized when a police response occurs. We deliberately do not brief the staff whose behavior is the subject of the test.

What if an employee calls the police during the test?

That is a successful outcome, and we plan for it. The tester carries the signed authorization letter and the emergency contact's number, produces both immediately when challenged by police or security, and does not attempt to continue the pretext once law enforcement is involved. Your emergency contact confirms the engagement by phone. We also notify you promptly, because an employee who correctly escalated deserves to be told they did the right thing rather than left wondering.

Will the report get our employees disciplined?

Not by design, and we structure it specifically to avoid that. Findings are documented by control and role — reception accepted an unverified vendor pretext, the east service door was propped during shift change — rather than by individual name. A report used as a disciplinary instrument guarantees that the next test is sabotaged and that honest reporting stops. The only exception is conduct you would want to know about regardless of any test, which we raise with leadership directly rather than burying in a findings list.

How often should a facility be tested?

Annually is a reasonable baseline for most organizations, with an additional test after any material change: a new access control system, a facility move or expansion, a significant turnover in security or reception staff, or an actual incident. Physical security decays gradually through ordinary convenience — a door propped for a delivery, a badge policy relaxed during a busy period — so the gap between a passing test and a failing one is often a few months of drift rather than a deliberate change.

What is tailgating and why does it matter so much?

Tailgating is following an authorized person through a controlled door, and it defeats badge systems more reliably than any technical attack because it exploits politeness rather than a flaw. Someone carrying boxes, dressed appropriately, walking with purpose, will be held the door for at most facilities. It is also the hardest gap to fix, since the remedy is cultural and physical rather than technological: mantraps and turnstiles where justified, and a staff norm that makes challenging a stranger ordinary rather than rude.

What does a test usually find first?

In most engagements the first successful entry is not the front door. It is a service or loading entrance during a delivery window, a smoking-area door propped with a wedge, or tailgating at shift change. The second common finding is how far someone gets once inside without anyone asking: unattended workstations, unsecured records, and conference rooms with network jacks. The third is that nobody filed a report afterward, which is usually the finding leadership finds most uncomfortable and most worth fixing.

Can you test multiple locations?

Yes, and multi-site engagements often produce the most useful finding of all: which controls hold consistently and which depend entirely on the individuals at a particular site. A company with identical policies across six locations will typically see materially different results at each, and the variance tells you whether you have a policy problem or a local execution problem. Multi-site engagements are scoped together so the methodology is identical and the comparison is meaningful.

How long does an engagement take start to finish?

Generally two to four weeks for a single site. Scoping and authorization take a few days, reconnaissance runs several days without any contact, testing is spread across multiple time windows rather than compressed into one visit, and the report follows about a week after the final test. Multi-site engagements extend proportionally. We resist compressing the testing phase, because testing only during business hours on one day tells you about one window and nothing about the rest.

What does a physical penetration test cost?

It is quoted per engagement rather than hourly, since the deliverable is a defined assessment and report. The main cost drivers are the number of sites, the number of distinct time windows tested, whether social engineering is in scope alongside physical entry, and how deep into the facility testing is authorized. Post-remediation retests are quoted at a reduced rate because the reconnaissance is already complete, and we recommend budgeting for one at the outset.

Should we retest after we fix the findings?

Yes, and we price it to make that easy. A remediation you have not verified under the same conditions is a remediation you are taking on faith, and the common outcome of a retest is that the technical fix held while the human one did not — the door now locks, and reception still accepts the vendor pretext. Retests are faster and cheaper than the original engagement because reconnaissance carries over, and they are the step that converts a findings report into an actual improvement.

Do you work with healthcare, records-sensitive or regulated facilities?

Yes, with the scope adjusted for the regulatory environment. In records-sensitive environments we test whether an area is reachable and whether records are physically unsecured, and we document that finding without accessing, reading, photographing the contents of, or removing any actual record. Proving that a records room could be entered is the finding; handling protected information would create the exposure the test exists to prevent. That boundary is written into the authorization for these engagements.

Find out before someone else does.

The scoping call is free and reaches leadership only. We will tell you what is worth testing at your facility and what a realistic engagement would cost.

Call (629) 310-8667 · Email contact@delatorgroup.com
Watchtower Investigations · Nashville, Tennessee · Delator Group’s Nashville hub

Page last reviewed . Watchtower Investigations is a licensed Tennessee private investigation agency and part of Delator Group. Information on this page is general and is not legal advice; for advice about your case, speak with a Tennessee attorney. Back to top ↑