In a physical pentest, the security of your physical infrastructure is tested. The best IT security is of little use when the door to the company stands physically open to any attacker . Of particular interest, therefore, are all interfaces between the IT department and other departments.
Exploiting vulnerabilities in access control or in processes and the awareness of employees often provides a way to access the physical spaces of a company.
On this basis, the following targets are possible:
The customer can decide how much social engineering is used in the assessment. As with all projects involving an amount of social engineering, SySS abides strictly by its social engineering code of ethics (see SySS White Paper, Section 3.3).
The physical pentest provides several insights. The assessment can, for example, be used to answer the following questions:
These findings can then provide further means by which to expand or introduce processes. Further awareness measures can similarly be derived from the lessons learned.
Steffen Stepper
steffen.stepper@syss.de
redteam@syss.de
+49 7071 407856-6157
PGP Key
Physical pentests are carried out ideally over several days and by at least two consultants . The assessment is based on the following project phases:
Ihr direkter Kontakt zu SySS +49 7071 407856-9107 oder anfrage@syss.de | Sie haben einen Cybersicherheitsvorfall? +49 7071 407856-99
Ihr direkter Kontakt zu SySS +49 7071 407856-9107 oder anfrage@syss.de
Sie haben einen Cybersicherheitsvorfall? +49 7071 407856-99
Direkter Kontakt
+49 7071 407856-9107 oder anfrage@syss.de
Sie haben einen Cybersicherheitsvorfall?