Double Check Security Group logo

What is physical penetration testing and which UK businesses need one?

Do you need a physical penetration test for your premises?

Physical penetration testing is authorised premises security testing: we agree the scope, then check whether someone could reach a site, room, asset or process they should not access. A full test suits premises with sensitive data, restricted areas, valuable assets, public footfall or repeated access concerns. Low-risk sites may only need a lighter review.

A penetration tester standing outside a building looking for weaknesses - Illustrative Image

A penetration tester standing outside a building looking for weaknesses – Illustrative Image

i 3 What Do We Cover In This Article?

Physical penetration testing tests real access under agreed limits

Physical penetration testing checks whether your physical access controls work in practice. We use the term for authorised access testing, where the aim is to test real barriers and routines under agreed conditions, including doors, visitor procedures, access cards, CCTV response, reception routines and secure areas.

A good physical pen test does not need drama. Its value sits in the gap between what your policy says and what happens on a normal working day. Someone may have a valid visitor badge but still walk into a restricted corridor. A door may lock properly, yet staff may hold it open for a person they do not recognise. CCTV may record an event, although nobody acts on it at the time.

The National Cyber Security Centre describes penetration testing as gaining assurance by attempting to breach security using tools and techniques similar to those an adversary might use. Applied to premises, that means testing access in a controlled way, then reporting what worked, what failed and how serious each issue is.

One limit matters. A physical penetration test proves only what was tested at that point in time. It gives useful assurance, but it does not prove that a site will stay secure after staff change, access rights drift or routines become loose.

A security audit and a pen test prove different things

Security audits, risk assessments and physical penetration tests overlap, but they answer different business questions. We see buying decisions go wrong when a business orders the most intrusive exercise before it has worked out what decision it needs to make.

Here is the cleanest way to separate them.

Exercise What it proves Where it fits
Physical security audit Whether expected controls exist and are being managed A broad review of doors, CCTV, visitor logs, keys, access rights and site routines
Security risk assessment Where exposure and likely harm sit across the premises Planning budgets, policies, public access arrangements and management priorities
Routine access control check Whether permissions and records are up to date Checking leaver access removal, card permissions and access rights records
Physical penetration test Whether selected controls can be bypassed under agreed conditions Testing high-risk routes, restricted areas, reception routines and staff challenge habits

A written policy might say that visitors must be signed in and escorted. An audit checks whether that rule exists and whether reception has a process for it. A physical penetration test checks whether a person can get past reception in practice under the agreed rules of the test.

Data protection adds another reason to take physical controls seriously. The Information Commissioner’s Office expects organisations processing personal and special category information to protect entry points with appropriate physical controls and to test those controls regularly for assurance. Under the UK General Data Protection Regulation, known as UK GDPR, this sits within appropriate security for personal data, including areas such as server rooms, records storage and systems that hold sensitive information.

Buying the right exercise matters because a broad audit can find management gaps that a narrow pen test would miss. Equally, a well-scoped test can expose a real weakness that a tidy audit document would never reveal.

A penetration test gaining access to a building - Illustrative Image

A penetration test gaining access to a building – Illustrative Image

Pro Tip: A physical penetration test is most useful when the findings can be tied straight back to access rights, visitor control and staff routines. That makes follow-up action easier to assign and track.
Joe Bugner

Director, DCS Group Ltd

Full testing belongs where exposure is real

A small office with staff-only access and low-value contents has a different case from a public-facing site with back-of-house areas, shared access routes and systems that keep the business running. Size matters less than consequence.

At Double Check Security Group, we look at the premises as an operating environment. Guarding, access control, CCTV, reception procedures and site routines all affect whether a weakness is theoretical or live. Full physical security testing is most proportionate where one or more of these risk triggers applies:

  • Public entry with restricted back areas. Retail, hospitality and residential buildings can have legitimate visitors close to stock rooms, plant areas, service corridors or tenant-only spaces.
  • Sensitive information or data-bearing equipment is held on site, especially where server rooms, records stores or secure offices rely on staff challenge and access control.
  • Valuable assets or stock. Warehouses, logistics spaces and high-value retail sites may need to test delivery routes, contractor access and out-of-hours routines.
  • Previous unauthorised access, suspected tailgating or repeated access concerns have already shown that normal controls are not giving you enough confidence.
  • Shared buildings with cleaners, contractors, tenants, visitors and security staff moving through the same entrance need clear rules that work under real pressure.

Small businesses should not dismiss physical penetration testing just because they are small. If a premises holds client data, expensive stock or access to client systems, the risk case may be stronger than the headcount suggests. On the other side, a site with simple access, low public exposure and no restricted area may get better value from a premises security review before considering a full test.

Martyn’s Law also needs careful handling. ProtectUK confirms that Martyn’s Law is now the Terrorism (Protection of Premises) Act 2025 and received Royal Assent in April 2025. The current guidance says the Government intends an implementation period of at least 24 months after Royal Assent before requirements come into force, and there is no requirement to comply until the legislation comes into force. Standard tier premises cover 200 to 799 people and are not required to put physical security measures in place. Enhanced tier premises cover 800 or more people and have further duties to consider and, where appropriate, take steps to reduce vulnerability to terrorism.

That does not turn every venue into a candidate for a physical pen test. Public protection planning and premises security testing can support each other, but they are separate decisions.

A penetration tester looking about to test the security of a building

A penetration tester looking about to test the security of a building

Legal scope matters more than clever tactics

A tester trying to tailgate into your office is useful only if tailgating was authorised in advance. Without written authority and a clear scope, the exercise stops being a managed test and starts creating avoidable legal, safety and operational risk.

Scope should be plain enough that your leadership, site team and tester all know the boundaries. We expect it to cover the site, test window, permitted techniques, areas excluded from testing, escalation contact and stop conditions. If social engineering is allowed, the scope needs to say what form it can take. If out-of-hours access attempts are in scope, the right people need to know how an unexpected escalation will be handled.

Controlled realism, not theatrical risk, is the standard that makes testing useful. A tester should not be rewarded for going outside the agreed rules, and your business should not be left managing confusion because nobody set limits at the start.

Staff welfare also belongs in the scope. A test can check whether staff challenge an unknown person without putting them under unfair pressure or creating a scene in a public area. Evidence capture should be agreed as well, because photographs, logs and notes need to support the findings without causing new problems for your business.

Good scoping turns physical security testing into a business exercise. Poor scoping turns it into a story that people remember for the wrong reasons.

Pro Tip: Shared entrances, contractor movements and back-of-house routes often reveal the clearest gaps. These areas deserve careful attention when a site has public footfall or mixed access arrangements.
Andy Bannon

Director, DCS Group Ltd

The report only counts when operations change

A report that lists weaknesses but leaves ownership unclear has limited value. The better outcome is a set of findings that turn into changed access rights, cleaner reception instructions, stronger leaver access removal, updated CCTV checks, clearer guarding instructions or staff training that matches the real weakness found.

The National Cyber Security Centre is clear that penetration testing validates the tested systems against known issues at the time of the test, so it should not replace normal security testing and vulnerability management. For premises, that point matters because people, routines and access permissions change. A pass today does not remove the need for management tomorrow.

At Double Check Security Group, we connect findings back to day-to-day operations, including guarding, key holding, access control, CCTV, reception and site management. That link matters because a physical penetration test report should not sit apart from the way the building is actually run.

Severity ratings help you decide what gets fixed first. A missed visitor badge may need a process correction. An active access card for a leaver, a weakly controlled server room or a contractor route into a restricted area needs firmer ownership and faster action. Follow-up can then check whether the fix has landed, without pretending that every site needs the same testing cycle.

One approach treats physical penetration testing as a one-off attempt to beat the site. The stronger approach uses controlled evidence to tighten the way access works every day. That gives you a better long-term result because it changes the operating habits that allowed the weakness in the first place.

A penetration tester scoping out the external security measures of a building - Illustrative Image

A penetration tester scoping out the external security measures of a building – Illustrative Image

Questions we get asked about physical penetration testing

Can a physical penetration tester try to tailgate into our office?

A tester can try to tailgate only if that tactic is agreed in the written scope. The scope should also set limits on staff interaction, escalation and what happens if the attempt causes concern.

Does a physical pen test replace a security audit?

A physical pen test does not replace a security audit because the two exercises answer different questions. An audit checks the wider control environment, and a pen test checks whether selected controls can be bypassed under agreed conditions.

How often should a business run physical security testing?

Frequency depends on your risk, site changes, client requirements and the weaknesses found last time. We would be cautious about any fixed answer that ignores your premises, public exposure and access arrangements.

Will staff know that a test is taking place?

Some staff may know, and others may not, depending on the agreed scope. Senior authorisation and safe escalation routes should always be in place, even where the test is partly unannounced to frontline staff.

What should happen after the report is issued?

Findings should be prioritised, assigned to owners and turned into practical changes. Useful follow-up focuses on whether access rights, visitor procedures, CCTV use and staff routines have actually changed.

This is general information, not professional advice.

Need help today?

Speak to our team

Fast response, no long waits.

020 3794 8182 Message Us Online

DCS Group Ltd
Unit 6, Skyline business Village, London E14 9TS

020 3794 8182

Find us on Google Maps

Get Your Quick Quote

Recieve a free no obligation quotation

p

We will not share or sell your data. By clicking submit you agree to us contacting you and our privacy policy's terms and conditions.

Sales Enquiries

Free, no obligation advice for potential clients

Just complete the form below with some basic details and we will get back to you.

p

We will not share or sell your data. By clicking submit you agree to us contacting you and our privacy policy's terms and conditions.