Physical security · OSINT · Black teaming

Locks · Access cards · Cameras But do they hold against someone who wants in?

Black Team tests your physical security the way a real attacker would — with reconnaissance, social engineering and physical intrusion. You don't get a list of theoretical vulnerabilities. You get the way in we actually found.

We don't just test doors. We test the entire attack chain.

A lock can be good. A procedure can be sound. An employee can be alert. Attacks rarely succeed because one single link failed.

Small weaknesses. Normal routines. Practical workarounds. Combined, they can create a viable attack path — and that path is hard to see from the inside.

So we test the chain from open-source intelligence to the point where the objective is reached — and whether anyone noticed at all.

Services

Four ways to know where you stand

The services build on each other. Start with a complete picture of your security level, or go straight to a realistic intrusion. The scope is always agreed in advance.

The attack chain

We test the whole way in
— not just one door

A real attack is a chain of small steps. These are the seven we work through, depending on the agreed scope and threat scenario.

Step 01

OSINT

We gather publicly available information to prepare the attack: the organisation, employees, suppliers, technology, facilities and working routines.

Step 02

Reconnaissance

Observation of entrances, the perimeter, employee behaviour, deliveries, contractors and shift changes. We identify routines, patterns and potential weaknesses.

Step 03

Pretext

We create a believable reason to interact with employees or gain initial trust — and in doing so we test reception, verification procedures and security culture.

Step 04

Physical access

Unauthorised access through people, processes or physical vulnerabilities: tailgating, access cards, locks, visitor processes and other barriers.

Step 05

Internal movement

Movement through the organisation towards the objective while avoiding detection. Can we reach technical rooms, server rooms, production or executive offices?

Step 06

The objective

We reach and access the agreed objective: the asset, the data or the information. Everything is documented — we never remove or alter anything without agreement.

Step 07

Detection and response

Was the intrusion detected? Was it escalated correctly? How quickly and how effectively did the organisation respond? This is often where the biggest lessons sit.

0+

control points reviewed systematically in a Security Assessment

0

categories scored as a percentage, so you can measure improvement over time

0

steps in the attack chain — we don't stop at the first door

0+

years of experience from the Danish Frogman Corps sit behind the method

How we measure

Eight categories, one score

Each category is scored as a percentage. That gives you an objective baseline you can use to track improvement over time — and to prioritise where the money does the most good.

CPTED
Access control
Visitor management
CCTV & surveillance
Interior security
Information security
Personnel security
Cyber-physical convergence

Scope

The test scales with your risk profile

A physical penetration test comes at six levels. We increase preparation, creativity and persistence according to how capable an adversary you want to measure yourselves against. The level is agreed at the scoping meeting and stated in the quotation.

1

Cold Hit

An unannounced stress test with minimal preparation. It exposes the most obvious weaknesses.

2–3 days
2

Targeted attack simulation

A planned engagement with OSINT beforehand and a prepared, credible cover story.

1–2 weeks
3

Advanced full-scale Black Team

A multi-phase attack by a well-resourced actor combining several attack paths.

3–4 weeks
4

Unconventional methods

Attack angles beyond the ordinary. It exposes the blind spots in your response.

4–6 weeks
5

Long-running persistent engagement

We deliberately stay below the radar. The question is not whether you notice, but when.

3–6 months
6

Value-chain infiltration

The attack widens to suppliers and partners with legitimate access to your buildings.

several months

See what each level covers

Behind Black Team

Two decades of getting into the right places

Black Team was founded by Christian Tang Mathiasen, who has over 20 years of service in the Danish Frogman Corps (Frømandskorpset) behind him.

The experience comes from intelligence work, clandestine operations and OSINT — and from protecting Danish diplomats and securing embassies. These are environments where security is not an exercise, and where the cost of an overlooked detail is real.

The same thinking sits behind every engagement: if I were the adversary, how would I get in? Not to break in for the sake of breaking in, but to find the weaknesses before someone with worse intentions does.

The aim is not to make anyone paranoid. It is to make security something that works day to day — including when nobody is watching.

Read the whole story

Fast and flexible

Rapid scoping and execution tailored to your objectives.

Experienced people

An operational background from an environment where security was never theory.

Actionable

Clear findings and prioritised recommendations, not a list without direction.

Discreet and secure

Strict confidentiality. Your data and your objectives are always protected.

Next step

Test the assumptions.
Find the attack paths.

A short conversation is enough to work out whether a Security Assessment or a full penetration test is the better fit. It costs nothing and commits you to nothing.