What is physical penetration testing?
Physical penetration testing tests whether someone can walk into your premises and reach your systems, offices or data. Incursion carries out covert and overt physical assessments for UK organisations, delivered by named consultants, and includes on-site interaction with your staff such as attempting to talk past reception or security.
What we test
Perimeter and entry: doors, gates, locks, access control systems and how they are actually used day to day.
Reception and visitor handling: whether a confident stranger with a plausible story gets through.
Tailgating and badge controls: following staff through doors, cloning or borrowing credentials.
Inside the building: access to server rooms, network points, unattended desks, printers and documents.
On-target staff interaction: talking through security staff, asking to be let in, posing as a contractor or visitor. We do not include email or phone phishing campaigns in physical testing.
Covert testing (staff do not know) or overt testing (a walkthrough with your facilities and security team), or both.
Why it matters
A locked-down network is no use if the server room door is propped open or a friendly stranger can be walked to a desk. Physical findings are usually cheap to fix and embarrassing to leave, and they are the findings that make security real to people who do not read network diagrams.
How we run it
Scoping. Your account manager and an active penetration tester work with you to agree the scope of your test on a scoping call. The quote is fixed to it.
Testing. A named, suitably qualified consultant does the work, and you get a direct line to them before, during and after the engagement. Critical and high-risk issues are verified and reported immediately.
Reporting. Easily digestible summaries sum up the whole engagement and support detailed technical findings, written so your team can replicate and fix them. Delivered within 5 working days.
Free retesting. One day of free retesting for every five days of consultancy, taken within 90 days of report delivery, so you can be sure the fixes worked.
Scoping notes
Covert testing needs a signed authorisation letter that the tester carries, a named contact who knows the dates, and clear rules on what is off limits. We agree in advance how far to go once inside, and we stop and identify ourselves the moment it is appropriate. Physical testing is often combined with wireless or internal testing in the same visit.
What you get
A named consultant with a UK Cyber Security Council professional title, who scoped the work and delivers it.
A report within 5 working days: executive summary, technical summary, and observation, impact and remediation for every finding.
Immediate notification of critical and high-risk issues, once we have verified them.
Free retesting: one day for every five days of consultancy, within 90 days of the report.
A walkthrough call with the consultant for your team, on request, at no extra cost.
Frequently asked questions
Is this the same as social engineering?
It includes in-person social engineering on site: talking your way past reception, posing as a contractor, tailgating. It does not include phishing emails, phone pretexting or online campaigns; those are scoped separately if you want them.
What if our staff challenge the tester?
Good. In a covert test the tester carries a signed authorisation letter and identifies themselves when challenged; in an overt test your organisation already knows we are on site. A challenge is a positive finding and goes in the report.
Covert or overt, which should we choose?
Covert tells you what actually happens; overt tells you what is possible and lets your team learn during the test. Many clients do both: covert first, then an overt walkthrough to show the team what was found.
Ready to scope a test?
Book a call. Our sales team will set it up and handle the proposal; an active penetration tester agrees the scope with you. No obligation.