Overview
Our team was engaged to perform a physical penetration test at a large, multi-use municipal facility. The eight-storey building houses a combination of public clinics, community support services, courts, and administrative offices. The engagement included preparation, execution of the controlled penetration test, and a final report detailing findings and recommendations to enhance security.
Scope of Work
- Conducted preparation and planning for the penetration test.
- Executed a controlled physical penetration test across multiple access points.
- Documented how access was gained and the techniques used.
- Delivered a report outlining findings and practical recommendations to strengthen security.
Methodology
Preparation & Planning
- Reviewed available site information and coordinated test parameters with the client.
- Defined rules of engagement to ensure safety and minimal operational disruption.
- Planned penetration approaches appropriate for a complex, multi-use facility.
Physical Penetration Test Execution
- Carried out controlled attempts to gain unauthorized access within the building.
- Navigated publicly accessible and restricted areas in accordance with agreed parameters.
- Documented access paths, techniques, and conditions that enabled entry.
Reporting & Recommendations
- Produced a detailed report describing how the building was penetrated.
- Identified contributing factors that allowed access.
- Provided actionable recommendations to enhance physical security and reduce future risk.
Outcomes
- Real-world insight into how the facility could be physically penetrated.
- Clear documentation of penetration methods and security gaps.
- Practical guidance to improve physical security measures and protocols.
Impact
The project provided the client with a realistic understanding of their building’s physical security exposure. The findings and recommendations supported informed decision-making and helped guide improvements to better protect staff, sensitive functions, and the public in a complex, multi-use environment.