Part of our ongoing series on choosing a penetration testing company.
Last month I spent four days at our booth at Black Hat USA in Las Vegas with the Raxis team. We really enjoyed speaking with so many security-minded folks. With such a focus on AI tools, I found that a lot of the people who stopped by our booth were excited to find that Raxis performs full-fledged physical penetration testing.
And, yes, I’m talking about in person, onsite in your lobby, at your badge readers, in your stairwells, and sometimes in your server room holding a cup of coffee we borrowed from your break area.
The surprise was understandable. A lot of penetration testing firms have quietly dropped physical testing from their menus. Some never offered it, and others moved to fully remote models over the past few years and have never looked back. So, when IT managers at Black Hat heard that Raxis still sends real testers to real buildings, their excitement was palpable. Several told us they had been searching for exactly this engagement model and kept coming up empty.
That tells me two things. First, there is real demand for physical pentesting, also known as physical social engineering or PSE for short. Second, a lot of people are not sure how to evaluate the companies that claim to offer it. For this next installment in our ongoing series on choosing a penetration testing company, I’d like to talk about how to choose one for the physical side.
Why Physical Testing Still Matters
It is tempting to think of building security as a facilities problem rather than a security problem. Your firewalls are tuned, your EDR is humming, your cameras are recording (is anyone monitoring them?), and the front door has a badge reader (is it vulnerable to badge cloning?), so everything must be fine, right?
The data says otherwise. In an ASIS International survey of more than 1,000 security professionals, 92% of organizations reported an access control failure within just six months, and 61% named tailgating or piggybacking as their most prevalent problem. Polite employees hold doors. Front desks accept plausible stories. Contractors prop open side entrances. Legacy badge systems get cloned with hardware anyone can buy online.
Once someone is inside, your perimeter defenses stop mattering. An open network port in an empty conference room or an unlocked workstation in a quiet cubicle is all an intruder needs because physical access cascades into digital compromise quickly.
The Pitfalls of Picking the Wrong Company
Not all physical testing is created equal. Here are three gotchas to watch for:
- The walkthrough disguised as a test. Some vendors send a consultant to stroll the property with a checklist and confirm that your doors have the proper badge readers and your file cabinets are locked. That is an audit of what exists on paper. While Raxis is happy to perform these assessments as well, they are a starting point and not a true test of how your physical controls hold up against a motivated intruder.
- Social-only or technical-only testing. A tester who can charm their way past your receptionist but cannot clone a badge or bypass a lock is only telling you half the story because they don’t see the whole attack surface. Real adversaries’ tactics are well-rounded and targeted, so your physical pentest should reflect that threat model.
- No proof, no path forward. If the report says “we gained access to the third floor” without photos and a clear narrative of how each control fell short, you won’t know what to fix, making it difficult to convey real-world risk to stakeholders.
What a Solid Physical Pentest Looks Like
At Raxis, PSE engagements pair human ingenuity with capable technology because that is how real intrusions work.
On the social side, our testers tailgate through controlled doors, build pretexts that get them welcomed into secure areas, impersonate vendors and new hires, and test whether anyone actually challenges an unfamiliar face. Spoiler: they rarely do, and, even if they do, they rarely follow through with an escalation to security or leadership.
On the technical side, we clone badges, pick locks and bypass barriers to entry, defeat sensors, evade cameras, and plant devices that give our remote team a foothold on your network. Every engagement follows a documented process aligned to MITRE ATT&CK and PTES, from OSINT reconnaissance and infiltration through escalation and reporting backed by visual evidence. You can read more about the full methodology on our physical social engineering page.
An employee’s actions tend to reflect the greater security culture within an organization. When we show you exactly how a friendly stranger walked out with domain credentials, you get a training story that swaps complacence for vigilance.
Let me tell you a secret. The most secure companies we’ve tested are the ones that test each year and embrace change. The most vigilant employees are the ones who attended training after a physical penetration test and realized that they were empowered to protect the organization.
Questions to Ask Any Physical Pentest Vendor
If you are evaluating providers, a few questions will separate the pros from the pretenders:
- Do your testers perform both social engineering and technical bypass techniques while onsite?
- Can you show me a sample report that shows the types of (sanitized) evidence your team provides?
- How do you handle authorization and scoping?
- Are your testers part of your full pentesting team? Do they hold cybersecurity certifications? What is their background and experience level?
- Does your team connect physical findings to secondary compromises so that risk is articulated at the business level?
If a vendor hesitates on any of these, it may be a sign to keep looking.
The Bigger Picture: Red Teaming
Physical social engineering is powerful on its own, but it truly shines as one piece of a full red team assessment. Picture a coordinated operation where a phishing campaign, a cloned badge, a planted device, and expert pentesters quietly working your internal network all unfold as a single simulated breach. That is how sophisticated adversaries operate, and it’s our flagship service as well.
For that, you need a partner with genuine technical depth and real skill in the field. Plenty of firms have one or the other. The people who stopped by our booth at Black Hat understood the value and were looking for both.
We would love to show you more. Reach out to Raxis or schedule a meeting with our team, and let’s talk about what a real-world test of your facility would look like.