Physical Penetration Testing for Sites and Premises

Controlled, authorised testing of physical security, access procedures, detection and response.

Find out whether an authorised tester can identify and exploit an agreed weakness before a genuine intruder does.

Written Authority

Every test requires documented client authority, an agreed scope and named points of contact.

Controlled Testing

Activities remain within agreed rules and are planned to avoid damage, unsafe conduct or unnecessary disruption.

Evidence-Based Findings

Observations, timings and permitted photographic evidence are recorded against the test objectives.

Actionable Report

Findings are prioritised with practical recommendations and optional follow-up support.

Test Your Security Before It Is Tested for Real

Physical penetration testing is an authorised attempt to test whether agreed physical, procedural or human security controls can be bypassed under controlled conditions.

Unlike a conventional inspection, the assessment does not only ask whether a fence, gate, camera or procedure exists. It tests whether those measures work together to deter, detect, delay and support an effective response when challenged.

The objective is not to embarrass staff or create a dramatic intrusion. It is to give the organisation reliable evidence about weak points, detection opportunities, escalation procedures and the practical performance of its security arrangements.

What Is Physical Penetration Testing?

A physical penetration test recreates selected aspects of a realistic unauthorised-access attempt within a tightly controlled and legally authorised scope.

The test may examine whether an authorised tester can approach a site without challenge, locate a vulnerable access point, pass through an agreed control, enter a restricted area or remain undetected long enough to demonstrate an exploitable weakness.

Depending on the agreed scope, testing can consider:

  • Perimeter fencing, gates and environmental climbing aids
  • Pedestrian and vehicle access procedures
  • Doors, locks and access-control arrangements
  • Visitor, delivery and contractor verification
  • Staff challenge and escalation procedures
  • CCTV observation, alarm detection and response
  • Restricted internal areas, plant rooms and technical spaces
  • Out-of-hours security arrangements
Perimeter fence being reviewed during an authorised physical penetration test

Written Authority and Rules of Engagement

A professional penetration test must be authorised, controlled and safe. No testing begins until the client and tester have agreed the purpose, boundaries and emergency arrangements.

The Scope Defines

  • The premises, boundaries and areas included
  • The dates and permitted testing window
  • Which methods may and may not be used
  • Whether staff awareness is announced, limited or covert
  • What evidence may be collected
  • Success, stop and abort conditions

Controls Normally Include

  • Written client authority and proof of appointment
  • Named client contacts who can verify the test
  • Emergency and escalation arrangements
  • Protection of confidential information and evidence
  • No destructive entry unless separately and expressly agreed
  • No action that creates an unacceptable safety risk

Requests to “just try to get in” without clear authority, ownership verification and agreed boundaries will not be accepted.

What We Can Test

Each assignment is tailored to the organisation, site and agreed threat scenarios. The following are common areas of assessment.

Gate release control assessed during physical security penetration testing

Access-Control Weaknesses

Pedestrian gates, vehicle entrances, door controls, release buttons, verification procedures and arrangements for deliveries or contractors.

Security tester identifying a gate climbing vulnerability during a controlled assessment

Perimeter and Climbing Routes

Fence condition, gaps, adjoining structures, rails, pipes, skips, stored materials and other features that could reduce the effective perimeter.

Unlocked padlock on a restricted access point identified during penetration testing

Restricted Areas and Key Control

Internal zones, roofs, technical rooms, plant areas, key storage and points where access depends on staff behaviour or local procedures.

Reconnaissance Detection

Whether suspicious observation, repeated approaches or information gathering would be noticed, challenged and reported.

Visitor and Delivery Controls

Identity checks, appointment verification, sign-in procedures, escorts, temporary passes and unexpected arrivals.

Detection and Response

Whether CCTV, alarms, patrols or staff identify the agreed test activity and whether escalation is timely and effective.

Possible Test Scenarios

The final scenarios depend on the risk, site and permission granted. Testing can be limited to one control or combine several stages into an agreed attack path.

Unchallenged Approach

Testing whether suspicious activity near a boundary, entrance or sensitive area is observed and escalated.

Authorised Access Pretext

Testing whether an agreed visitor, contractor or delivery scenario is properly verified before access is allowed.

Tailgating or Piggybacking

Assessing whether controlled access points depend too heavily on courtesy, assumption or another authorised person.

Perimeter Route

Testing a specific boundary weakness, environmental climbing aid or gate vulnerability without causing damage.

Restricted-Zone Access

Testing whether a person who has entered a general area can then move into a more sensitive internal zone.

Out-of-Hours Attempt

Testing an agreed control when staffing, visibility, supervision or response arrangements differ from daytime operations.

Our Physical Penetration Testing Process

1. Initial Discussion

We establish the concern, desired assurance and the decisions the organisation needs the test to support.

2. Scope and Authority

Written authority, boundaries, methods, restrictions, contacts, evidence handling and abort conditions are agreed.

3. Planning

Available plans, procedures, operating hours and relevant site information are reviewed to prepare the permitted scenarios.

4. Controlled Testing

Authorised scenarios are carried out within the rules of engagement and stopped immediately when required.

5. Debrief and Reporting

Findings are reviewed, evidence is secured and the client receives the agreed report and recommendations.

6. Remediation Support

Optional support can help prioritise actions, review proposals and confirm whether corrective work addresses the finding.

What You Receive

Deliverables depend on the scope, but a full assignment may include the following.

  • Agreed scope and rules of engagement
  • Record of the authorised scenarios completed
  • Timeline of significant test activity
  • Permitted photographic or documentary evidence
  • Explanation of successful and unsuccessful test stages
  • Risk-prioritised findings and observations
  • Immediate, short-term and longer-term recommendations
  • Management debrief or findings presentation where agreed
  • Optional remediation planning
  • Optional follow-up or controlled retesting

The report records what was tested and what occurred within that scope. It should not be treated as proof that every possible route, method or future condition has been tested.

Penetration Testing, Security Audits and Consultancy

The three services are closely related but should not be confused.

Physical Penetration Testing

Challenges selected controls through authorised scenarios to establish whether an agreed weakness can be exploited and detected.

Site Security Audits

Inspect existing arrangements, identify visible and procedural weaknesses and provide risk-prioritised recommendations.

View site security audits →

Security Consultancy

Provides wider advice on strategy, procedures, specifications, implementation and the coordination of protective measures.

View security consultancy →

Protective Security and Martyn’s Law

The Terrorism (Protection of Premises) Act 2025 is commonly known as Martyn’s Law. Organisations within scope should follow the applicable legislation and official statutory guidance rather than rely on a single test or report.

A properly scoped physical penetration test may support wider protective-security assurance by testing selected access, detection, staff-awareness and response arrangements. It does not by itself confirm legal compliance, replace the organisation’s risk assessment or remove the need for suitable procedures, training and governance.

Our approach can also be informed by relevant publicly available NPSA and ProtectUK principles, including layered security, fit-for-purpose protective measures, suspicious-activity awareness and effective reporting. We do not claim NPSA approval or accreditation unless this has been expressly granted.

Why Choose MW Global Security Services?

Operational Security Experience

Testing is informed by practical experience of sites, guarding, patrols, CCTV, alarms, access control and response arrangements.

Controlled and Proportionate

The scope is matched to the risk and operating environment rather than designed to create unnecessary drama or disruption.

Clear Evidence and Priorities

Reports explain what happened, why the finding matters and which actions should be considered first.

Support After Testing

Optional consultancy can help review corrective work, supplier proposals and future retesting requirements.

Physical Penetration Testing: Frequently Asked Questions

Is physical penetration testing legal?

It is only undertaken with clear written authority from an appropriate client representative and within agreed boundaries. The scope, permitted methods, contacts and stop conditions must be documented before testing begins.

Is testing safe during live operations?

It can be conducted during live operations where the risk assessment, rules of engagement and site conditions allow it. Testing will not proceed where it would create an unacceptable risk to staff, visitors, the public, the tester or site operations.

Do staff need to know the test is happening?

That depends on the objective. Some tests are announced, while others involve limited staff awareness to assess genuine challenge and escalation behaviour. The client must authorise the approach, and emergency verification contacts remain available.

Will you damage locks, doors or fencing?

The normal service is non-destructive. Any destructive or specialist testing would require separate competence, risk controls and express written authorisation and may fall outside the service offered.

Can you use impersonation or social-engineering scenarios?

Limited access-pretext, visitor, delivery or contractor-verification scenarios may be included when expressly authorised. The scenario, boundaries and prohibited conduct are agreed in advance.

Does a penetration test prove Martyn’s Law compliance?

No. Testing may support wider assurance by examining selected security and response arrangements, but it does not by itself establish compliance with the Terrorism (Protection of Premises) Act 2025 or replace official guidance and the organisation’s wider responsibilities.

Will the report automatically satisfy an insurer or auditor?

Requirements vary. The report can provide evidence of the agreed test and findings, but the client should confirm any required format, standard or acceptance criteria with the insurer, auditor or requesting body before the scope is agreed.

Can you retest after improvements are completed?

Yes, where agreed. A focused retest can examine whether specific corrective work addresses the original finding, although it only provides assurance within the new retest scope.

Physical Penetration Testing Across East Anglia and Wider UK Locations

MW Global Security Services supports suitable projects across Suffolk, Norfolk, Cambridgeshire, Peterborough and surrounding areas. Testing at other UK locations may be available by arrangement following an initial discussion and scope review.

Discuss a Controlled Physical Penetration Test

Tell us what you need to test, why assurance is required and which premises or controls are involved. We will first determine whether a safe, authorised and useful scope can be agreed.

See our 5-star Google reviews.