Our expertise
Our services
Who we serve
Insights
About us
Digital Threat Digest Insights Careers Let's talk

We tested a client's physical security: Here's what we found

MT
Megan Thomas
Hargreaves Lansdowne photos 04

What happens when someone walks into your office unauthorised?

Organisations in highly sensitive sectors often invest heavily in cyber defences, but physical security needs to be treated as an equally high priority. A big security gap still exists today because social engineering and human behaviour are too often overlooked as serious threats. Even the most mature security programmes can be undone where human behaviour can bypass technical defences entirely.

Our client is a leading organisation in the space sector dedicated to space sustainability. The space industry faces a distinct threat environment where nation state threat actors actively target organisations within the sector. That made testing the resilience of their physical security a top priority in order to identify gaps and strengthen controls.

They engaged us to simulate a realistic physical intrusion exercise (red teaming) to test the resilience of their onsite security and whether a threat actor could gain access to sensitive areas within their premises.

Using a tailored social engineering approach, we were able to assess the effectiveness of the client’s security controls including their employees’ response. We demonstrated how critical assets could still be compromised with existing controls in place.

The engagement highlighted how human behaviour combined with unidentified gaps in physical security can be leveraged to achieve unauthorised access. It provided the client with clear, actionable insight to close social engineering awareness gaps and strengthen their physical security posture.

"From an exercise point of view, there was nothing that could have been improved. The engagement definitely provided value to our organisation. Our internal security outcome provided us with valuable insights to strengthen our controls and address social engineering training gaps."

- Chief Financial Officer