A report by the Information Systems Audit and Control Association (ISACA) shed light on the issue in its report: Physical Penetration Testing: The Most Overlooked Aspect of Security. According to them, despite the relevance of physical penetration testing to the security of an organization, it is often underestimated in security strategies.
“Technological advancements and variability in where organizational work is performed increases the difficulty securing sensitive data and assets. Enterprises cannot overlook the risks associated with physical access,” said Jon Brandt, director of professional practices and innovation at ISACA.
“Physical security predates information security and while it may remain overshadowed by cyberthreats, the benefits of physical penetration testing are numerous and will strengthen any organization’s overall security posture.”
Recommended reading
- Forget Gen Z, Fintech Firms Look to Attract Tech-shy ‘Boomers’
- Scottish Veterans to be Reskilled to Fill Cybersecurity Skills Gap
- Digital Catapult and Ofcom Unveil Open RAN Testing Facilities
The paper outlines various testing methods such as:
- Social Engineering: Where human psychology is exploited to manipulate individuals into releasing confidential information.
- Physical/Technical Bypass: Where penetration testers attempt to circumvent physical security controls, such as locked doors, surveillance systems, and access card systems, using technical means or physical tools.
- Destructive vs. Non-destructive Testing: While some tests involve destructive actions to assess the robustness of physical barriers, others focus on non-destructive methods to identify vulnerabilities without causing damage.
- Advanced Persistent Threats (APTs): This refers to simulated attacks where penetration testers emulate the tactics, techniques, and procedures of a persistent and sophisticated adversary seeking unauthorized access.
The advantages of physical penetration testing are undoubtedly numerous, including regulatory compliance, personnel safety, and data protection. However, challenges such as cost, time, legal and ethical considerations, armed guard misunderstandings, off-limits areas/assets, and personnel lacking the right skills for penetration testing are also acknowledged in the paper.





