What happens between physical security controls?

2 min read

Written the 23 Sept 2026, 11:44:05 by , Security Advisor. Read the article in Danish here, m8.

Your organisation may have access control systems, CCTV cameras, security guards, locks, and alarm systems in place. These controls are important, but they do not necessarily stop an attacker from gaining access. The real risk often exists between the controls. An attacker looks for the gaps: the open door, the busy reception desk, or the helpful colleague who does not ask the extra question.

Even strong physical security controls can be ineffective when human behaviour creates opportunities for unauthorised access.

In this article, we look at how a physical penetration test can show whether people, procedures, and security controls perform effectively against a realistic attacker. We call it a Black Team Engagement.

 

Physical security is also about human behaviour

Workplaces are built on trust, collaboration, and established routines. Those things help daily operations run smoothly. However, the same strengths can also create opportunities for an attacker to gain unauthorised access.

It does not take advanced equipment to take advantage of these situations. An unauthorised person can follow an employee through a door, pretend to be a supplier or technician, or claim that their access card has been forgotten. When things are busy, that person can blend in more easily among employees and external partners.

Physical security is only effective when people, procedures, and controls work together to prevent and detect unauthorised access.

 

Controls are only effective when they work together

Access control will not stop an unauthorised person if someone holds the door open. A camera can document an incident, but it cannot prevent it. And if the organisation discovers or reports an incident too late, relevant video footage may be more difficult to use during an investigation.

That is why the question is not only whether each security control works on its own. What truly matters is what happens between the controls and whether the organisation detects and responds when an unauthorised person tests the boundaries.

 

From assumption to proven security

A traditional Physical Security Audit typically examines whether controls and procedures are in place. A Black Team Engagement takes a different approach: We try to bypass those controls and see what an attacker could actually achieve. This can reveal weaknesses that are difficult to identify through a traditional audit.

When we conduct a Black Team Engagement, our Black Team simulates realistic attack scenarios and evaluates how security controls, procedures, and organisational practices perform under real-world conditions.

The goal is to understand what an attacker could actually do, where they could gain access, and which security controls they could bypass.

Our team uses social engineering and techniques for bypassing security controls to gain unauthorised access. The Black Team investigates the building and selected critical areas for security weaknesses. This may include attempting to access or remove sensitive documents, gaining access to restricted areas, or cloning access cards to gain long-term access to the building.

Hear real-world stories and discover how our team works in this webinar (in Danish).

Sign up for the webinar here 

 

What do you gain from a Black Team Engagement?

  • A realistic picture of your risk: You gain insight into how a real attacker may attempt to infiltrate your organisation.

  • Weaknesses you can act on: You identify concrete gaps before they can be exploited by malicious actors.

  • A shared direction for improvement: Management, security teams, IT, and operations receive a documented basis for prioritising the next steps.

  • Practical recommendations: You receive actionable recommendations that can strengthen your defences and reduce risk exposure.

Trust is good. Validation is better.

Many organisations have invested in relevant physical security controls. However, an investment alone does not prove that those controls work effectively in a busy day-to-day environment. Even strong controls lose their effectiveness if procedures are not followed consistently.

A Black Team Engagement goes beyond a traditional audit by testing security through realistic attack scenarios. You gain a documented understanding of where security is working, where weaknesses exist, and which improvements should be prioritised. This gives you a stronger foundation for protecting information, assets, and operations.

Get your physical security tested, m8

Skal vi tage en snak?

Udfyld formularen, så kontakter vi dig.