Skip to content

Physical Security Guide

Every software control can be bypassed by someone who walks through the door. Physical security covers the attack surface that targets the building, the badge, and the person — and it’s frequently the weakest link in an otherwise hardened organization. This guide is written for defenders: it explains how physical penetration testers think so you can close the gaps, not a how-to for breaking in.

Electronic access control can be defeated without touching the credential — a digitally secure building can be physically trivial. Defenders should audit for the classic gaps: egress (REX) sensors that can be triggered from outside, gaps under or beside doors, maglocks that release on power loss, and propped or unmonitored secondary doors. The lesson: a badge reader on the front door means little if the side door is propped open.

The most reliable entry is social: following an authorized person through a door (“tailgating”) or being waved in (“piggybacking”). Technical controls (mantraps/access control vestibules, anti-passback) help, but the durable defense is culture — staff who are comfortable challenging an unbadged stranger, backed by policy that makes doing so expected rather than rude.

Mechanical locks vary enormously in resistance. Conceptually, techniques like raking, bump keys, and single-pin picking exploit tolerances in standard pin-tumbler locks — which is why a cheap key-in-knob lock is not a security boundary. Defenders should know the outcome: upgrade exterior and sensitive doors to deadbolts and high-security, pick-resistant cylinders (with key control to prevent unauthorized duplication) rather than relying on commodity hardware.

Proximity badges are a common weak point:

TechFrequencyRisk
Legacy prox (e.g. HID Prox)125 kHzTrivially cloneable — no real authentication
MIFARE Classic13.56 MHzBroken crypto; cloneable
MIFARE DESFire EV2/EV3, Seos13.56 MHzModern, encrypted/mutually-authenticated — the upgrade target

Inexpensive tools (Flipper Zero, Proxmark) make cloning legacy credentials a real, low-skill threat. The fix isn’t secrecy — it’s migrating off 125 kHz prox and MIFARE Classic to encrypted smartcard credentials.

Cameras deter and provide evidence only if they actually cover the right geometry and retain footage. Audit for blind spots (especially entries, secondary doors, and server rooms), confirm retention meets your investigation needs, and verify the recording path can’t be trivially disabled. A camera nobody monitors and whose footage rolls off in 24h is theater.

A mature visitor program is a strong control: pre-registration, ID verification, distinct temporary badges that visibly expire, mandatory escort in sensitive areas, and sign-out. Attackers exploit the gaps — unescorted “contractors,” reused visitor badges, reception that doesn’t verify. Make the secure path the easy path.

An authorized physical assessment scopes targets and objectives, carries written authorization, attempts entry within the agreed rules, and delivers a report: what succeeded, the indicators that should have stopped it, and prioritized fixes. It pairs naturally with red team tradecraft and the OPSEC framework.

For high-risk individuals, recognizing physical surveillance (and using surveillance detection routes) is part of personal security — see the safe-meeting practices in OPSEC for Activists and Journalists.