Service · Physical penetration testing / Black Team Assessment

Physical penetration testing / Black Team Assessment

A controlled and authorised test where we genuinely attempt to gain unauthorised access to your facilities and assets — using the methods a real attacker uses. We don't just test doors. We test the entire attack chain. One service, two names: the method is a physical penetration test, and the way we run it is a Black Team Assessment.

From DKK 40,000 excl. VAT

The question

You have locks, access cards, CCTV and security policies.

But do they work against a determined and well-prepared adversary?

Most security measures are chosen and installed on the basis of how they are meant to work. Rarely on the basis of how someone would try to get around them.

An attacker does not follow your procedures. They look for the place where the procedure is impractical — and where someone has therefore found a shortcut.

The only thing that gives an honest answer is to let someone try. Within agreed limits, with your written permission.

The service

What is a physical penetration test?

It is a controlled, authorised assessment where we attempt to get in — not on paper, but for real.

We start on the outside, with what an attacker can find out about you without anyone noticing. From there we work our way in: observation of routines, a credible reason to be there, access through people, processes or physical weaknesses — and onwards towards the objective we agreed in advance.

We don't just test doors. We test the entire attack chain. A lock can be good and a procedure can be right without the chain holding. It is the joins between the links that an attacker exploits.

Scope and threat scenario are agreed before we start. It can be a fast, unannounced stress test over two to three days, or a multi-phase engagement over several weeks where we combine several attack paths and deliberately stay under the radar.

We never remove or change anything without agreement. Everything we gain access to is documented — and stays with you.

Price

Entry level · short unannounced test fromDKK40,000
Larger engagements By quotation

The entry level starts at DKK 40,000 excl. VAT. Beyond that we do not publish a price list: the level, the scope and the price are set together at the scoping meeting and stated in the quotation, because they follow from your risk profile and the complexity of the engagement. All prices exclude VAT and are index-linked with annual adjustment. Travel, accommodation and equipment are billed as incurred and agreed in advance.

The category

Further than a penetration test

The service carries two names because both are true. A physical penetration test is the method. A Black Team Assessment is the way we run it — as a whole adversary, not as a checklist.

A penetration test typically looks at known vulnerabilities in selected systems. A red team exercise goes further, but is usually bounded in time and scope. A black team takes the next step and combines everything a real adversary would use — reconnaissance, people, physical intrusion and technique — in one continuous engagement.

The difference between a red team and a black team is the domain. Red teams look primarily in the cyber domain: systems, networks and configurations. Black teams work primarily in the physical and human domain — where the lock, the reception desk, the routine and the helpful colleague are the controls. Technique comes along where it makes sense, but it is not the starting point.

The return is concrete. You get an overview of where security breaks down, including the attack methods you have probably not considered yourselves. Management gets a realistic assessment of how the organisation would hold up against a persistent attack. And you get a prioritised plan you can act on.

Red team

Takes on the adversary role and looks primarily for weaknesses in the cyber domain: systems, networks and configurations.

Black team

The same role, but more intense and more realistic. Focused primarily on the physical and human domain — access, behaviour and procedures.

Common to both

Controlled, authorised and agreed in advance. The Rules of Engagement are fixed before we begin.

What we test

Eight areas

Which of them are included depends on the agreed scope and threat scenario. We recommend the combination — you decide it.

External reconnaissance and OSINT

We identify what is publicly available about your organisation, employees, suppliers, technology, facilities and working routines — and what that gives an attacker to work with.

Physical reconnaissance

Observation of entrances, perimeter, employee behaviour, deliveries, contractors, shift changes and other operational patterns. What repeats itself can be planned around.

Social engineering

Realistic pretexts test reception staff, employees, security personnel and the verification procedures you have written down. The purpose is to test the process — not to expose the individual.

Perimeter and access controls

Gates, doors, access cards, visitor processes, tailgating, locks and other physical barriers. We test both the technology and the way it is used day to day.

Supplier and contractor access

Can a trusted third-party role be imitated or exploited? Cleaners, technicians, couriers and contractors often hold an access nobody questions.

Restricted areas

Attempts to reach technical rooms, server rooms, control rooms, production areas, executive offices or other sensitive spaces behind the first barrier.

Internal attack opportunities

Once access has been achieved: can an attacker move further, reach sensitive information or connect equipment to the infrastructure that is available?

Detection and response

Do employees recognise the suspicious behaviour? Is the incident escalated correctly? And how quickly and effectively does the organisation respond when it does?

The attack chain

We test the complete path
— not just a single door

A real attack is a chain of small steps. Here are the seven we work through, depending on the agreed scope and threat scenario.

Step 01

OSINT

We gather publicly available information and build the picture of you: organisation, employees, suppliers, technology, facilities and working routines. All of it without anyone registering it.

Step 02

Reconnaissance

Observation on the ground: entrances, perimeter, employee behaviour, deliveries, contractors and shift changes. We look for the patterns that repeat — those are the ones an attack can be planned around.

Step 03

Pretext

We create a believable reason to be there and to talk to employees. That tests reception, visitor procedures, verification and security culture — under entirely normal circumstances.

Step 04

Physical access

Unauthorised access through people, processes or physical vulnerabilities: tailgating, access cards, locks, visitor processes and other barriers. We use the route that is most realistic — not the most spectacular.

Step 05

Internal movement

Movement through the organisation towards the objective while avoiding detection. Can we reach technical rooms, server rooms, production or executive offices? And can we connect equipment along the way?

Step 06

The objective

We reach and access the agreed objective: the asset, the data or the information. Everything is documented — we never remove or change anything without agreement.

Step 07

Detection and response

Was the intrusion detected? Was it escalated correctly? How quickly and how effectively did the organisation respond? This is often where the biggest learning sits.

We don't just identify weaknesses. We identify realistic attack paths.

The difference matters. A list of weaknesses can be argued over and prioritised away. A documented way in — with times, photographs and the steps we took — is hard to disagree with, and easy to act on.

Scale

The engagement scales with your risk profile

The same service can be a short, unannounced test with minimal preparation — or a months-long engagement in which we behave like a patient adversary who never wants to be noticed. Between the two sit planned, multi-phase simulations built on prior OSINT, and engagements that widen to the suppliers and partners in your value chain.

1

Cold Hit

A short, unannounced physical stress test with minimal preparation. It exposes the most obvious weaknesses and shows how employees react to a sudden attempt.

2–3 days
2

Targeted attack simulation

A planned physical and digital simulation with OSINT beforehand and a prepared, credible cover story. It finds the vulnerabilities that take preparation to exploit.

1–2 weeks
3

Advanced full-scale Black Team

A multi-phase attack by a well-resourced and persistent actor that combines several attack paths — and measures whether your detection and response actually work.

3–4 weeks
4

Unconventional methods

Attack angles beyond the ordinary. Emulates advanced threat actors and insiders, and exposes the blind spots in contingency planning. Every boundary-pushing element is agreed with you individually first.

4–6 weeks
5

Long-running persistent engagement

We act as a patient threat actor that deliberately stays below the radar. The question is not whether we get in, but whether you notice — and how long it takes.

3–6 months
6

Value-chain infiltration

The attack widens to suppliers, contractors and partners — the places where your security depends on other people's. Every third party involved is agreed with you in advance.

several months

The right level follows from your risk profile — not from what sounds most impressive. Most organisations start one rung lower than they expect, and get more out of it. We present the levels at the scoping meeting and state the one we recommend, with scope and price, in the quotation. If you are in doubt, call: a short conversation is usually enough to place you on the ladder, and we are happy to recommend a lower level when that is the right one.

If your security has never been assessed from the outside, the sensible starting point is a baseline rather than an attack. That is what our Security Assessment is for — a documented picture of the whole security posture, which also shows what is worth testing harder.

Any engagement can be extended with targeted technical and organisational tests. They run alongside the main engagement, rarely extend the calendar time, are delivered as separate chapters in the report, and are priced by scope.

Add-ons
  • Network scanning
  • Vulnerability scanning
  • Assume breach
  • Internal and external penetration testing
  • Wi-Fi audit
  • Phishing and vishing
  • Purple team session
  • Tabletop incident workshop

The deliverable

What you receive

The report has to be usable by the security lead, by operations and by management. So it contains both the concrete path in and the decision it ought to lead to.

  • Executive summary and an overall risk assessment
  • Description of the attack scenario and methodology
  • Chronological attack path — step by step
  • Identified vulnerabilities and observations
  • Photographic evidence where appropriate
  • Positive observations — the controls that actually worked
  • Assessment of people, procedures and technical controls
  • Prioritised, actionable recommendations
  • Management debrief with a walkthrough of key findings
Reference framework
  • ISO 27001 (Annex A)
  • CPTED
  • F&P Security Guide
  • NIS2 / CER

The framework

Controlled. Authorised. Safe.

Every engagement is conducted within Rules of Engagement — a written set of rules you approve before we begin.

Scope, techniques, sensitive areas, escalation procedures and safety limitations are defined before testing begins. We agree what counts as acceptable behaviour, which areas are off limits, and who can stop the test at any time.

Formal approvals and legal documents give us permission to carry out the engagement. A small number of named people on your side know about the test, so that a discovery can be verified and escalated correctly — without it ending up as a real alarm.

The purpose is never to disrupt operations or embarrass employees. We strengthen security together.

Next step

Test the assumptions.
Find the way in.

A short conversation is enough to work out whether a Security Assessment or a full penetration test suits you best. It costs nothing and commits you to nothing.