Cold Hit
A short, unannounced physical stress test with minimal preparation. It exposes the most obvious weaknesses and shows how employees react to a sudden attempt.
Service · Physical penetration testing / Black Team Assessment
A controlled and authorised test where we genuinely attempt to gain unauthorised access to your facilities and assets — using the methods a real attacker uses. We don't just test doors. We test the entire attack chain. One service, two names: the method is a physical penetration test, and the way we run it is a Black Team Assessment.
From DKK 40,000 excl. VAT
The question
You have locks, access cards, CCTV and security policies.
But do they work against a determined and well-prepared adversary?
Most security measures are chosen and installed on the basis of how they are meant to work. Rarely on the basis of how someone would try to get around them.
An attacker does not follow your procedures. They look for the place where the procedure is impractical — and where someone has therefore found a shortcut.
The only thing that gives an honest answer is to let someone try. Within agreed limits, with your written permission.
Price
The entry level starts at DKK 40,000 excl. VAT. Beyond that we do not publish a price list: the level, the scope and the price are set together at the scoping meeting and stated in the quotation, because they follow from your risk profile and the complexity of the engagement. All prices exclude VAT and are index-linked with annual adjustment. Travel, accommodation and equipment are billed as incurred and agreed in advance.
The category
The service carries two names because both are true. A physical penetration test is the method. A Black Team Assessment is the way we run it — as a whole adversary, not as a checklist.
A penetration test typically looks at known vulnerabilities in selected systems. A red team exercise goes further, but is usually bounded in time and scope. A black team takes the next step and combines everything a real adversary would use — reconnaissance, people, physical intrusion and technique — in one continuous engagement.
The difference between a red team and a black team is the domain. Red teams look primarily in the cyber domain: systems, networks and configurations. Black teams work primarily in the physical and human domain — where the lock, the reception desk, the routine and the helpful colleague are the controls. Technique comes along where it makes sense, but it is not the starting point.
The return is concrete. You get an overview of where security breaks down, including the attack methods you have probably not considered yourselves. Management gets a realistic assessment of how the organisation would hold up against a persistent attack. And you get a prioritised plan you can act on.
Takes on the adversary role and looks primarily for weaknesses in the cyber domain: systems, networks and configurations.
The same role, but more intense and more realistic. Focused primarily on the physical and human domain — access, behaviour and procedures.
Controlled, authorised and agreed in advance. The Rules of Engagement are fixed before we begin.
What we test
Which of them are included depends on the agreed scope and threat scenario. We recommend the combination — you decide it.
We identify what is publicly available about your organisation, employees, suppliers, technology, facilities and working routines — and what that gives an attacker to work with.
Observation of entrances, perimeter, employee behaviour, deliveries, contractors, shift changes and other operational patterns. What repeats itself can be planned around.
Realistic pretexts test reception staff, employees, security personnel and the verification procedures you have written down. The purpose is to test the process — not to expose the individual.
Gates, doors, access cards, visitor processes, tailgating, locks and other physical barriers. We test both the technology and the way it is used day to day.
Can a trusted third-party role be imitated or exploited? Cleaners, technicians, couriers and contractors often hold an access nobody questions.
Attempts to reach technical rooms, server rooms, control rooms, production areas, executive offices or other sensitive spaces behind the first barrier.
Once access has been achieved: can an attacker move further, reach sensitive information or connect equipment to the infrastructure that is available?
Do employees recognise the suspicious behaviour? Is the incident escalated correctly? And how quickly and effectively does the organisation respond when it does?
We don't just identify weaknesses. We identify realistic attack paths.
The difference matters. A list of weaknesses can be argued over and prioritised away. A documented way in — with times, photographs and the steps we took — is hard to disagree with, and easy to act on.
Scale
The same service can be a short, unannounced test with minimal preparation — or a months-long engagement in which we behave like a patient adversary who never wants to be noticed. Between the two sit planned, multi-phase simulations built on prior OSINT, and engagements that widen to the suppliers and partners in your value chain.
A short, unannounced physical stress test with minimal preparation. It exposes the most obvious weaknesses and shows how employees react to a sudden attempt.
A planned physical and digital simulation with OSINT beforehand and a prepared, credible cover story. It finds the vulnerabilities that take preparation to exploit.
A multi-phase attack by a well-resourced and persistent actor that combines several attack paths — and measures whether your detection and response actually work.
Attack angles beyond the ordinary. Emulates advanced threat actors and insiders, and exposes the blind spots in contingency planning. Every boundary-pushing element is agreed with you individually first.
We act as a patient threat actor that deliberately stays below the radar. The question is not whether we get in, but whether you notice — and how long it takes.
The attack widens to suppliers, contractors and partners — the places where your security depends on other people's. Every third party involved is agreed with you in advance.
The right level follows from your risk profile — not from what sounds most impressive. Most organisations start one rung lower than they expect, and get more out of it. We present the levels at the scoping meeting and state the one we recommend, with scope and price, in the quotation. If you are in doubt, call: a short conversation is usually enough to place you on the ladder, and we are happy to recommend a lower level when that is the right one.
If your security has never been assessed from the outside, the sensible starting point is a baseline rather than an attack. That is what our Security Assessment is for — a documented picture of the whole security posture, which also shows what is worth testing harder.
Any engagement can be extended with targeted technical and organisational tests. They run alongside the main engagement, rarely extend the calendar time, are delivered as separate chapters in the report, and are priced by scope.
The deliverable
The report has to be usable by the security lead, by operations and by management. So it contains both the concrete path in and the decision it ought to lead to.
Next step
A short conversation is enough to work out whether a Security Assessment or a full penetration test suits you best. It costs nothing and commits you to nothing.