Skip to content

Physical

Physical
Penetration Testing

On-site intrusion testing across the New York metro

From $6,800 for one NYC-metro site, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When an office needs a physical penetration test

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • You have badge readers, a reception desk, and a server room, and nobody outside the building has ever tried to walk past them.
  • A data room, trading floor, or lab holds something an intruder would target, and you need to know if they could reach it.
  • An enterprise customer, regulator, or auditor asked for evidence that physical access controls are tested, not just documented.
  • You are fitting out a new NYC office and want the access control, doors, and reception procedures tested before they set.
  • You run a red team program and want the physical entry vector measured as a standalone assessment first.

Definition

What is a physical penetration test?

A physical penetration test is an authorized attempt to get inside your building the way a real intruder would: tailgating through a controlled door, cloning a badge, talking past reception, bypassing a lock, and reaching the desks, server room, and network jacks beyond. It answers a question a document review cannot: can someone who does not belong here actually get in, and how far do they reach?

Testing is on-site in the New York metro, with two operators over up to three days, from $6,800 for one site. Everything runs under a signed authorization letter and agreed rules of engagement, with no forced entry and no damage. It is the physical vector of a red team, sold as a standalone assessment of one site.

Authorization

How a physical test stays safe and lawful

On-site testing only works when the paperwork is right first. These are the controls that protect your staff, your building, and our operators.

Signed authorization letter

Every operator carries a signed authorization letter naming the engagement, the dates, and the people to call. If a tester is stopped by staff, security, or police, the letter and your named contacts confirm the operation is real and authorized.

Rules of engagement

Agreed in writing before anyone arrives: which sites and areas are in scope, business hours only unless an after-hours attempt is in scope, and hard limits. No forced entry, no damage, no denial of service, and no touching anything the rules exclude.

Building and landlord consent

In shared or multi-tenant NYC buildings, consent from the landlord or building management is a scoping step we confirm with you before the on-site days, so the test never affects a neighbor or common area you do not control.

Captured evidence is handled under NDA, and the report is written by control, not by name.

What we look for

Physical weaknesses we test for

A determined intruder does not pick a lock if the door is held open for them. We test the controls in the order a real attacker would try them, from the easy social path to the technical bypass, and prove what each one is worth.

Tailgating and access control

The most common way in: walking through a controlled door behind someone, or past a reader that was never enforced.

We test for

  • Tailgating and piggybacking through controlled entrances
  • Turnstile, mantrap, and anti-passback bypass
  • Propped, unlatched, and poorly aligned doors
  • Loading docks, side entrances, and stairwells
  • Elevator and floor-access controls

Badge cloning and credentials

Proximity cards that can be read and copied from a pocket, and the readers that trust them without question.

We test for

  • Reading and cloning proximity and smart cards
  • Low-frequency and default-configuration badge attacks
  • Visitor-badge and temporary-access abuse
  • Shared and never-revoked credentials
  • PIN and keypad observation

Lock, door, and barrier bypass

The mechanical controls, bypassed with the same non-destructive techniques a real intruder uses.

We test for

  • Latch and strike bypass (under-the-door, loiding)
  • Request-to-exit sensor and motion-sensor abuse
  • Padlock and cabinet-lock weaknesses
  • Window, gate, and perimeter checks
  • No forced entry and no damage, by rule of engagement

Reception and pretexting

The human controls at the front desk, tested with a convincing story rather than a crowbar.

We test for

  • Reception and visitor-management pretexts
  • Delivery, contractor, and vendor impersonation
  • Escort and sign-in policy gaps
  • Piggybacking on scheduled visits and events
  • Help-desk and building-management pretexts

Interior exposure once inside

What an intruder reaches after the door: the desks, screens, and rooms that assume everyone inside belongs there.

We test for

  • Unattended, unlocked workstations
  • Clean-desk failures: passwords, documents, and devices left out
  • Server-room and network-closet access
  • Printer, mail, and records-room exposure
  • Sensitive areas reachable without a second check

Rogue device and network foothold

The bridge from physical access to a network breach: a small device left plugged in behind a desk or in a closet.

We test for

  • Placing a rogue network implant on an open port
  • Network jacks live in lobbies, meeting rooms, and common areas
  • Whether the planted device reaches the internal network
  • Handing the foothold to an internal test
  • Wireless reach from outside the building

Coverage

New York metro, and beyond

Invadel is headquartered in Manhattan, so a physical test of a New York metro office is a calendar invite, not a travel budget. That covers offices in Manhattan, Brooklyn, Queens, Long Island, Westchester, and the rest of the metro. Sites farther away are tested too, quoted with the travel agreed up front.

Pairing the physical test with the internal network test from the planted device shows the full path from the front door to Domain Admin.

Pricing

How physical penetration testing is priced

Physical scopes are sized by the site, not by the hour. The price is fixed in writing before anyone arrives.

One NYC-metro site

One office of up to about two floors, up to three on-site days, two operators, business-hours entry attempts: $6,800.

Guarded or two-site

A site with lobby security, turnstiles, or encrypted badges, or two nearby sites, with up to five on-site days and one after-hours attempt: $10,500.

Campus or multi-site

Three or more sites, a campus, or a covert multi-week engagement built around one objective, quoted from the scope and still fixed before work begins.

Travel inside the NYC metro is included in the price.

Methodology

Physical penetration testing methodology

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your physical penetration testing runs through.

  1. 01

    Authorization & rules

    A signed authorization letter, named emergency contacts, and rules of engagement agreed in writing: no forced entry, no damage.

  2. 02

    Reconnaissance

    A day of surveillance and OSINT: entrances, shift patterns, badge types, vendors, and the pretexts that would work.

  3. 03

    Entry attempts

    Business-hours attempts over the on-site days: tailgating, pretexting, badge and lock bypass, each documented with evidence.

  4. 04

    Interior & foothold

    Once inside, unattended workstations, the server room, and one attempt to plant a rogue network device.

  5. 05

    Debrief & retest

    A facilities, HR, and security debrief, a report with the timeline and photos, and a free re-check of the controls you fix.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping physical penetration testing.

Still have questions? 
01What is a physical penetration test?

It is an authorized, on-site attempt to enter your building the way a real intruder would: tailgating through controlled doors, cloning a proximity badge, talking past reception, bypassing a lock without force, and reaching the workstations, server room, and network jacks inside. Two operators run it over up to three on-site days for one site, and the report shows exactly what was reached, which controls held, and how to fix the ones that did not.

02Will our staff be told it is a test?

You decide. Usually only a small control group on your side knows, so the results reflect how the building and its people really respond. The objective is to measure and improve physical security, not to catch individuals out, so findings are reported by control rather than by name.

03What happens if a tester is stopped or challenged?

That is a good outcome, and we document it. Every operator carries a signed authorization letter naming the engagement, the dates, and the people to call, so staff, security, or police can confirm on the spot that the operation is authorized. Your named emergency contacts are reachable throughout the on-site days for exactly this.

04Do you force entry or damage anything?

No. The rules of engagement, agreed in writing before anyone arrives, forbid forced entry and any damage. We use the non-destructive techniques a real intruder would use, such as tailgating, badge cloning, and latch bypass, and we stop at proof. Anything the rules exclude stays untouched.

05What about the building or landlord in a shared office?

In shared or multi-tenant New York buildings, consent from the landlord or building management is a scoping step we confirm with you before the on-site days, so the test only ever affects space you control and never a neighboring tenant or a common area you do not.

06Do you test offices outside the New York metro?

Yes. Invadel is headquartered in Manhattan, so metro sites carry no travel line. Sites outside the metro are tested too, with travel arranged and agreed in the quote up front.

07How much does a physical penetration test cost?

One NYC-metro site of up to about two floors, with two operators over up to three on-site days, is $6,800, fixed before work begins. A guarded or turnstiled site, or two nearby sites with one after-hours attempt, is $10,500. Three or more sites, a campus, or a covert multi-week engagement are quoted from the scope. Starting prices for every service are on our pricing page.

08Can you combine it with an internal network test?

Yes, and it is the most complete way to run it. Once an operator plants a rogue network device on an open port, that foothold hands straight to an internal network test, which shows how far the physical breach reaches into Active Directory and your sensitive systems. The two are scoped together so the report tells one story, from the front door to Domain Admin.

Ready to test your defenses?

Talk to our team about scoping physical penetration testing.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.