Logo webu

Physical Security: The Forgotten Attack Vector

4. 10. 2023 | 5 min read | author: Chris Cowling

With ransomware, a constant stream of new vulnerabilities and the emergence of AI, it is easy to forget some of the basics of what it takes to secure your business. In a world where we continue to harden our network defences, deploy the latest system to protect our employees from phishing or updating to the latest Quantum-computing resistant cryptography many attackers are reverting to the seemingly forgotten “old ways” of gaining a foothold in your environment.

Physical security is still one of the most overlooked and underfunded areas for major organisations.

Chris Cowling is a Red Team Operator and Penetration Tester. With over 20 years of experience across Blue Chip companies and Formula1, Chris brings a wealth of knowledge and expertise to axelum.

With his extensive experience in Industrial Control Systems securing and attacking systems across the globe, Chris is uniquely placed to help secure your process. As one of the few people globally certified in the Covert Method of Entry, Chris is one of our lead Entry Specialist for Physical Engagements and Red Team engagements.

"Given physical access to an office, the knowledgeable attacker will quickly be able to find the information needed to gain access to the organisation's computer systems and network."

Gregory White, 2003

Assessing the Weaknesses

For a start, the attack surface is bigger if someone physically comes to one of your sites. They can attack the WiFi networks, steal physical documents (or ideally, the secure destruction bags with all the goodies already inside), dig through your refuse, manipulate employees directly, take photographs and capture audio/video footage of meetings and/or conversations that would never make it into the digital realm.

Additionally, they may look to insert devices on the network to gain remote access, install hardware key-loggers on people's machines to steal passwords, place hidden camera devices to record what goes on or drop USB devices with malware on for unsuspecting staff to pick up and insert in their machines.

When it comes to attacking your premises, understanding how buildings work and where an attacker can find dead space in which to hide or gain entry to sensitive areas, attacking the apparently sophisticated PACs system or access badges, bypassing doors and windows, picking locks, fooling or disabling alarms or using Software Defined Radio (SDR) to open barriers or doors are all part of the toolbox.

Hollywood vs. Reality

Many people have a romanticised view from the films that an attacker is going to immediately pick the locks on a door in order to gain access in the depths of the night. It is, unfortunately, the case that there are many ways to bypass the locks entirely to gain access and lock picking is considered a slow, noisy and sometimes time-consuming attack that sits way down the list of things an attacker will try.

A good example is the use of an under-the-door tool. As shown in the video, an attacker can bring or craft a tool that will reach under a door and open it by pulling on the handle on the inside. This handle typically has to open the door to allow people to exit in the event of a fire.

In addition to testing the physical aspects of the building, a physical penetration test offers an opportunity to see how your employees will hold up in a real-life social engineering scenario. It will test security providers and identify any gaps in processes and procedures.

If your employees are just waving at the pizza delivery guy or ignoring someone because they're wearing a high visibility jacket, not monitoring security cameras, wedging doors open or not following proper procedures for verifying someone's identity, then you may have bigger problems than poorly fitted doors and windows.

Simulating the Actions of a Real Attacker

At axelum, we are fortunate to have an experienced team of physical penetration testers, some of whom are even part of a small group of testers worldwide and are certified as Covert Entry Specialists. In addition to understanding how a facility should be segmented to protect your physical assets, they are just as likely to steal your access badge subtly by sitting near you in the cafeteria or standing in line behind you at a coffee shop or reproducing your keys from a photo or mold taken within seconds of leaving them unattended.

This is exactly what our advanced Red Team events look like, where we simulate real attacks or conduct purely physical penetration tests or consultations. As a result, axelum boasts one of the best teams in the EMEA region.

As part of business, we are increasingly also performing examinations for senior executives at their private properties. As these executives represent a potential target due to the nature of the knowledge they possess, have access to or actions they can authorise many companies feel it is worth us visiting these properties to assess and provide advice on how their security posture can be improved in order to protect the executives and their families. This also increases the company's security by knowing they are protected when they have let their guards down at home, away from the regular office environment and the gatekeepers and personal assistants that help shield them.

The Uncertainty of Lock Security Standards

It is a little-known fact that there is no international standard that defines how difficult a lock is to pick. Most standards focus on how long it would take a burglar with regular tools, e.g. hammer, crow-bar, drill to get past the lock. In some cases, like in the video, a simple dynamic attack can quickly be effective against certified level-4 locks.

For those of us who have these skills, we endeavour to utilise them only to help make our world a safer place and never perform such actions without written legal consent (known as an out-of-jail letter). Whilst sometimes gaining access can be mundane, there are times when you are running down a rear staircase with a backpack full of IP or a symbolic hard drive of data that you wouldn’t change your job for any other in the world.

Microsoft’s Michael Meyers notes that "the best network software security measures can be rendered useless if you fail to physically protect your systems," since an intruder could simply walk off with a server and crack the password at his leisure.

What about you? Are you ready to find out how secure your premises are?

Right in Your Inbox

Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.

All infosec
We are an information security company. Our purpose is to safeguard the clients' most valuable information and protect their business.

© 2026 Axelum s.r.o.

Contact

Axelum s.r.o.

CIN: 25639056

VAT ID: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Created by uuWebKit
document_check.svg
We use cookies on this website to ensure its functionality and to personalise ads, solely with your consent and in accordance with our Cookies Policy.

By clicking on the "Accept cookies" button, you consent to the use of selected cookies and agree to the transfer of behavioural data for the display of targeted advertising on social and advertising networks. You can choose which information you want to share with us by clicking on the Cookie settings button.