Approach

How an engagement actually runs

A test is never better than the agreement it rests on. Here is the whole engagement — what we do, when we do it, and what is settled before anyone goes anywhere near your building.

The method is the same every time. The scenario never is.

A black team works in the physical and human domain. We have no access to internal knowledge of your systems, and we operate under the same lack of information as a real adversary.

That sets us apart from a classic penetration test, which goes after known vulnerabilities in selected systems — and from a red team, which operates primarily in the cyber domain.

Which is why the framework around an engagement matters as much as the engagement itself. Everything is agreed in writing, everything is documented, and everything can be verified afterwards.

The engagement

Six phases in every engagement

A Cold Hit over two days and a full-scale Black Team engagement over four weeks share the same structure. The phases are the same. What changes is the depth.

  1. 01

    Initial conversation and scoping No obligation

    We start with the question, not with the product.

    What are you worried about? Which locations, assets or processes matter most? What has already been tested, and what never has? From there we set the purpose, the threat scenario, the scope and the level. You get a price and a timeline before you decide — the first conversation costs nothing and commits you to nothing.

  2. 02

    Rules of Engagement and written agreement Before anything else

    No test begins without a signature.

    We draw up clear guidelines for how the test may be carried out: acceptable behaviour, permitted and expressly forbidden techniques, off-limits areas, time windows and the safety limitations that apply. On top of that comes formal written authorisation from someone in your organisation with the mandate to give it. Without it, there is no engagement.

  3. 03

    OSINT and preparation Remote

    We look at you the way an adversary would.

    We map your digital exposure from open sources: organisation, employees, suppliers, technology, facilities and working routines. That material becomes realistic attack scenarios and believable pretexts. It is also where we find what you have published yourselves without thinking about it — and that is often a finding in its own right.

  4. 04

    Execution On-site

    Where the assumptions are put to the test.

    Reconnaissance on the ground, pretext, attempts at physical access and movement inside towards the agreed objective — followed by the question that often matters most: did anyone notice, and what happened next? We stay inside the agreement the whole way and log time, place and action as we go, so the engagement can be reconstructed afterwards.

  5. 05

    Report and documentation 1–2 days

    Findings, evidence and a prioritised plan.

    You get a chronological attack path, the specific findings with photographic evidence where appropriate, a risk assessment — and the controls that actually worked. Recommendations are split into immediate, tactical and strategic, so it is clear what needs doing this week and what belongs in next year's budget.

  6. 06

    Management briefing and follow-up 45–60 min

    So the report does not simply sit there.

    We go through the key findings and recommendations with your management and answer the questions while the material is still fresh. After that we agree whether to follow up: a retest of the gaps you have closed, a workshop with operations, or a new measurement in a year, so you can see the development in numbers rather than in impressions.

What an engagement costs follows the level: a Security Assessment from DKK 47,500 and a Cold Hit from DKK 40,000 — all prices excl. VAT.

Safety and ethics

Controlled. Authorised. Safe.

A physical penetration test is an authorised act that looks like an unauthorised one. The difference is the paperwork — and that everyone involved knows the limits before anyone starts. It is the most important part of the whole engagement.

Every engagement is conducted within a set of Rules of Engagement that you have approved in writing. It is not a formality. It is the document that separates a security test from a crime, and it is at the same time what protects your employees, your operations and us.

Scope, techniques, sensitive areas, escalation procedures and safety limitations are defined before testing begins. Named points of contact are appointed in your organisation who can confirm that the test is authorised if an employee or a guard stops us. And if we are stopped, that is exactly what we were hoping for.

The purpose is never to disrupt operations or embarrass employees. We strengthen security together. When someone stops us, that is a result — not a defeat — and it goes into the report as one of the findings that matter most.

Everything is documented. Time, place, method and outcome are logged as we go, so the engagement can be verified afterwards: by you, by your auditor, by your insurer or by a regulator. Methodology and limitations are described in the report, so it is just as clear what was not tested as what was.

Settled before we begin

  • The purpose and threat scenario for the engagement
  • Locations, assets and systems in scope — and those that are not
  • Permitted techniques and expressly forbidden techniques
  • Off-limits areas: production, laboratories, archives, rooms holding personal data
  • The time windows in which the test may take place
  • Named points of contact and the authority they hold
  • Escalation path and stop condition — who we call, and when we stop
  • Handling, storage and deletion of the material we collect

The limits

What we do not do

We take nothing with us

We never remove or alter anything without agreement. Once the objective is reached, we document it and put things back the way we found them.

We do not target individuals

The test is aimed at the organisation's controls, not at the individual. No names in the report and no photographs of employees.

We do not use your data for anything else

Material from the engagement is stored encrypted, is never shared with third parties, and is deleted after the period we have agreed in writing.

We do not test outside the agreement

If an obvious opportunity appears outside scope, we note it and ask. We do not exploit it, and we do not widen the engagement along the way.

Working together

What we need from you

Not very much — and deliberately as little as possible. The more you hand us, the less the test resembles a real attack.

We do not need access cards, building drawings or internal knowledge of your systems. Everything we use, we find ourselves. That is the whole point: an adversary is not handed anything either.

  • A decision-maker with the mandate to approve the Rules of Engagement
  • A trusted point of contact who knows the test is happening and can confirm it
  • Notice of planned events in the period: building work, audits, major deliveries
  • An agreement on who may be told — and when the rest of the organisation finds out
  • A recipient for the report and a date for the management briefing

Reference framework

We work from recognised frameworks

Our assessments start from established frameworks, so the findings translate directly into the language your auditor, your insurer or your regulator already uses.

It is a frame of reference — not a certification. Black Team is neither certified nor accredited under any of them, we are not a member of any industry scheme, and we do not issue certificates. What you get is an assessment structured so it can be held up against the requirements.

We work from
  • ISO 27001 (Annex A)
  • CPTED
  • F&P Sikringsguiden
  • NIS2 / CER
  • NIST SP 800-115

Next step

Test the assumptions.
Find the attack paths.

A short conversation is enough to establish whether a Security Assessment or a full penetration test is the better fit. It costs nothing and commits you to nothing.