Physical Security Guide
Physical Security Guide
Section titled “Physical Security Guide”Every software control can be bypassed by someone who walks through the door. Physical security covers the attack surface that targets the building, the badge, and the person — and it’s frequently the weakest link in an otherwise hardened organization. This guide is written for defenders: it explains how physical penetration testers think so you can close the gaps, not a how-to for breaking in.
Access control and where it fails
Section titled “Access control and where it fails”Electronic access control can be defeated without touching the credential — a digitally secure building can be physically trivial. Defenders should audit for the classic gaps: egress (REX) sensors that can be triggered from outside, gaps under or beside doors, maglocks that release on power loss, and propped or unmonitored secondary doors. The lesson: a badge reader on the front door means little if the side door is propped open.
Tailgating and piggybacking
Section titled “Tailgating and piggybacking”The most reliable entry is social: following an authorized person through a door (“tailgating”) or being waved in (“piggybacking”). Technical controls (mantraps/access control vestibules, anti-passback) help, but the durable defense is culture — staff who are comfortable challenging an unbadged stranger, backed by policy that makes doing so expected rather than rude.
Lock security (awareness)
Section titled “Lock security (awareness)”Mechanical locks vary enormously in resistance. Conceptually, techniques like raking, bump keys, and single-pin picking exploit tolerances in standard pin-tumbler locks — which is why a cheap key-in-knob lock is not a security boundary. Defenders should know the outcome: upgrade exterior and sensitive doors to deadbolts and high-security, pick-resistant cylinders (with key control to prevent unauthorized duplication) rather than relying on commodity hardware.
Badge cloning risk
Section titled “Badge cloning risk”Proximity badges are a common weak point:
| Tech | Frequency | Risk |
|---|---|---|
| Legacy prox (e.g. HID Prox) | 125 kHz | Trivially cloneable — no real authentication |
| MIFARE Classic | 13.56 MHz | Broken crypto; cloneable |
| MIFARE DESFire EV2/EV3, Seos | 13.56 MHz | Modern, encrypted/mutually-authenticated — the upgrade target |
Inexpensive tools (Flipper Zero, Proxmark) make cloning legacy credentials a real, low-skill threat. The fix isn’t secrecy — it’s migrating off 125 kHz prox and MIFARE Classic to encrypted smartcard credentials.
Cameras: coverage, not theater
Section titled “Cameras: coverage, not theater”Cameras deter and provide evidence only if they actually cover the right geometry and retain footage. Audit for blind spots (especially entries, secondary doors, and server rooms), confirm retention meets your investigation needs, and verify the recording path can’t be trivially disabled. A camera nobody monitors and whose footage rolls off in 24h is theater.
Visitor management
Section titled “Visitor management”A mature visitor program is a strong control: pre-registration, ID verification, distinct temporary badges that visibly expire, mandatory escort in sensitive areas, and sign-out. Attackers exploit the gaps — unescorted “contractors,” reused visitor badges, reception that doesn’t verify. Make the secure path the easy path.
Physical pen testing methodology
Section titled “Physical pen testing methodology”An authorized physical assessment scopes targets and objectives, carries written authorization, attempts entry within the agreed rules, and delivers a report: what succeeded, the indicators that should have stopped it, and prioritized fixes. It pairs naturally with red team tradecraft and the OPSEC framework.
Counter-surveillance
Section titled “Counter-surveillance”For high-risk individuals, recognizing physical surveillance (and using surveillance detection routes) is part of personal security — see the safe-meeting practices in OPSEC for Activists and Journalists.
Related
Section titled “Related”- Red Team Tradecraft — physical entry as part of full-scope engagements
- OPSEC Framework — the methodology behind physical OPSEC
- Physical Security (offensive testing) — the existing testing-focused page
- OPSEC for Activists and Journalists — personal physical-security and counter-surveillance