Case Study: Physical Security Audit
Physical security is the first trust boundary protecting people, information, equipment and digital systems. Badge readers, doors and cameras can appear effective in isolation while everyday behaviour, disabled locks, weak visitor practices and passive monitoring create a practical route around them.
This case study outlines a ProCheckUp Physical Security Audit of a multi-floor town hall and connected civic offices. The engagement combined covert unauthorised-access testing, controlled social engineering, authorised inspection of building controls, and review of how staff, facilities processes, CCTV and access records responded to suspicious activity.

Overview
A local government authority commissioned ProCheckUp to determine whether an unfamiliar and unauthorised person could enter its town hall, move beyond public areas, reach the Mayor’s office area and other restricted council environments, and access information, devices or assets before being detected and contained.
The physical programme covered three covert testing days followed by two days of authorised inspection and validation. During the covert phase, testers used ordinary appearance, tailgating and simple verbal explanations rather than forced entry or specialist disguise. They achieved full access within the agreed multi-floor testing scope and were challenged on three occasions, with the strongest responses coming from Reception and Facilities personnel.
The assessment identified six High-severity physical-security findings, supported by additional weaknesses affecting doors, visitor procedures, confidential waste, key storage, perimeter controls, pass-card alerting and security ownership. The result was not simply a list of defective controls: it was an evidence-led view of how human trust, operational convenience and passive monitoring could combine into a complete access path.
Engagement at a glance
- - Five-day physical-security programme: three covert days and two authorised review days
- - Public approaches, staff entrances, lifts, stairs and restricted council areas assessed
- - Mayor’s office area, civic-leadership spaces and sensitive operational areas included in the authorised risk model
- - Staff challenge, badge display, visitor collection and incident escalation tested
- - Doors, barriers, emergency releases, perimeter controls, CCTV and pass-card records reviewed
- - Information, workstations, keys, confidential waste and portable assets considered
Challenge
A town hall is a mixed-access environment. Members of the public, councillors, employees, contractors, visitors and service users may all move through different parts of the same building. Physical assurance therefore had to test whether controls remained effective when a plausible stranger behaved as though they belonged there.
Human trust crossed designed boundaries
Staff were naturally helpful and often accepted simple explanations without independently confirming identity, sponsorship or access rights. Doors were held open, requests for assistance were granted, and an unbadged person could sometimes blend into ordinary office activity.
Convenience weakened control design
Some doors were left unlocked, did not reliably latch or had access controls disabled to simplify training, visitor movement or routine circulation. These practices undermined the intended separation between public space, operational floors and civic-leadership areas.
Recorded activity did not always become response
CCTV and pass-card systems captured useful data, but limited real-time monitoring, camera-health assurance, anomaly alerting and central incident correlation reduced their ability to interrupt an intrusion while it was occurring.
Testing had to remain safe and non-disruptive
All activity was authorised, non-destructive and designed not to harm staff or damage property. One especially sensitive service area was excluded from covert access attempts beyond a controlled walk-through. Testers did not remove equipment, retain confidential papers or claim downstream actions that had not been performed.
Assessment Scope
The public case study generalises the original town-hall layout and department names. Testing concentrated on the following physical trust boundaries:
- - External approach and entry: public doors, staff entrances, perimeter fencing, gates and release controls
- - Badge and visitor management: visible identification, forgotten passes, host collection, escorting and challenge procedures
- - Internal movement: reception barriers, lifts, stairs, tailgating and movement between public, operational and restricted council zones
- - Doors and release systems: locks, latches, closers, emergency-release devices, under-door exposure and doors intentionally left unsecured
- - Monitoring and response: CCTV availability, coverage, access logs, anomaly alerting, after-hours oversight and incident escalation
- - Information and assets: unattended workstations, clear-desk practice, documents, lockers, confidential waste, physical keys and portable equipment
Solution
ProCheckUp combined covert behavioural testing with authorised inspection of the physical control environment. This allowed observed access paths to be linked to the people, process and technology conditions that made them possible.
The assessment followed four stages:
- 1. Observe: establish normal patterns of badge use, door holding, visitor handling, staff movement, desk hygiene and challenge behaviour.
- 2. Exercise: attempt authorised tailgating, social engineering, barrier bypass and movement through lifts, stairs and restricted doors without forced entry.
- 3. Inspect: review locks, door releases, perimeter controls, key storage, CCTV, pass-card records and alerting with authorised access.
- 4. Translate: correlate human, process and hardware weaknesses into immediate containment, engineering work and sustained governance.
Manual validation was central. The assessment distinguished a confirmed access path from an observed exposure, and an observed exposure from a potential consequence. This prevented credible risk from being understated while avoiding claims that theft, data exfiltration or a genuine compromise had occurred.
High-Severity Findings
Six High-severity findings showed how ordinary interactions and control exceptions could permit unauthorised movement through the town hall.
Social engineering and employee-trust exploitation — High
Simple explanations, including claims of carrying out external support work, were frequently accepted without formal identity or sponsorship checks. Staff sometimes opened doors or provided assistance to testers who were not displaying identification.
Recommendation: require independent identity verification, make challenge behaviour an explicit organisational expectation, support employees who challenge appropriately and repeat controlled exercises to measure improvement.
Unauthorised access to the Mayor’s office area and restricted council environments — High
Tailgating, unsecured doors and trust-based interactions enabled authorised testers to reach civic-leadership offices, sensitive council departments and IT-related areas without valid access rights. In several locations they remained for extended periods before challenge.
Recommendation: introduce layered zoning between public, operational, civic-leadership and high-security areas; keep restricted rooms access-controlled; escort visitors and alert on unusual access attempts.
Doors frequently left unlocked or bypassed — High
Some doors were deliberately left unlocked for convenience, some access controls had been disabled, and certain doors did not reliably latch. Entrance barriers could also be bypassed when the area was not actively supervised.
Recommendation: repair or reactivate every faulty or disabled lock, prohibit convenience-based bypass, monitor doors held open, test closers and latches regularly, and act on barrier alarms.
Unattended workstations and device exposure — High
Unlocked workstations, active sessions, laptops and handwritten notes were found in unattended areas. In one authorised scenario, a staff member permitted use of a laptop without independently verifying identity, exposing internal configuration information.
Recommendation: enforce automatic screen locking, clear-screen practice and secure handling of portable devices; prohibit device access without verification; conduct periodic workstation spot checks.
CCTV monitoring and camera availability — High
Some cameras were unavailable, recordings were primarily reviewed after events, and intelligent detection features were not in active use. Pass-card records were retained, but suspicious or unauthorised attempts did not generate effective real-time alerts.
Recommendation: restore camera availability, perform routine health checks, improve coverage at high-risk points, enable proportionate alerting where lawful, and define rapid access to footage during an incident.
Insecure storage of personal and confidential information — High
Documents, handwritten notes and personal information were accessible on desks, in shared areas and within unsecured storage. The exposure meant material could potentially be photographed, copied or removed without immediate detection.
Recommendation: enforce clear-desk standards, secure papers and lockers when unattended, use controlled printing where appropriate, and include physical information protection in routine compliance checks.
Additional Physical-Control Weaknesses
Further findings reinforced the principal access path and widened the potential impact:
- - Confidential waste: papers could be retrieved from a secure-disposal container, and the bin could be moved without challenge
- - Key storage: an externally accessible drop box allowed a physical key and identification tag to be retrieved using a simple improvised method
- - Door closure: several security doors could appear closed while remaining unlatched and unsecured
- - Portable assets: valuable equipment was stored in an unlocked room without physical anchoring or secure cabinets
- - Visitor procedures: hosts sometimes left controlled doors unlocked rather than collecting visitors from reception
- - Under-door bypass: a simple tool opened a secured door and could activate selected release mechanisms
- - Perimeter controls: fencing and a gate-release control could be bypassed with limited effort
- - Governance: pass-card alerting, central incident reporting, after-hours monitoring and dedicated ownership required improvement
Authorised Intrusion Path
The following sequence separates confirmed testing evidence from potential downstream impact:
- 1. Public approach — confirmed: testers entered or approached the town hall using normal public and staff-access routes.
- 2. Tailgating or unlocked-door access — confirmed: doors held by staff and convenience-based access practices crossed the first restricted boundary.
- 3. Movement through the town-hall core — confirmed: barriers, lifts and stairs enabled movement between floors and office zones.
- 4. Restricted council and mayoral areas — confirmed: testers reached the Mayor’s office area, civic-leadership offices and sensitive operational environments within the agreed scope.
- 5. Accessible information and assets — observed: workstations, papers, keys, confidential waste and portable equipment were within reach.
- 6. Delayed or inconsistent response — observed: passive CCTV, limited alerts and variable challenge behaviour reduced timely containment.
- 7. Wider harm — potential: a genuine intruder could attempt theft, data access, impersonation, disruption or persistence.
This is an authorised risk model, not evidence of a completed real-world intrusion. Access and exposure were validated; information and equipment were not removed, and potential downstream actions were not represented as performed.
Control Effectiveness and Assessment Boundaries
Positive controls observed
- - Public-facing desks, drawers, meeting rooms and printers were clear during the initial closed-building review
- - The temporary-pass process required photographic identification and missing badges could be disabled
- - Pass-card events and CCTV recordings were available to support investigation
- - Reception personnel challenged and pursued suspicious activity in selected scenarios
- - Facilities personnel demonstrated persistent observation, escalation and coordinated containment during the strongest response
Limitations and publication boundaries
- - Testing was non-destructive and designed not to harm staff or damage property
- - One especially sensitive service area was not subjected to full covert access testing
- - Testers did not remove assets, retain confidential information or execute harmful post-access activity
- - Selected examples of strong staff behaviour should not be interpreted as consistent performance across the whole authority
- - The source material did not confirm that the complete remediation programme was later implemented or independently retested
The assessment proved that authorised unbadged testers could gain extensive access within the agreed scope, reach restricted areas, encounter exposed information and assets, and bypass selected controls using simple techniques. It did not prove that a real attacker had previously done so or that theft, data loss or operational compromise had occurred.
Outcome
The engagement converted a broad concern about town-hall security into a prioritised and evidence-based improvement programme. The customer received a clear view of where access depended on goodwill, where hardware could be bypassed, where detection failed to become response and which positive staff behaviours could be used as the benchmark for a stronger security culture.
Facilities, security, HR, IT and civic-leadership stakeholders were given a common order of action. Active access paths — unlocked doors, weak badge enforcement, exposed information, insecure waste or keys, and unavailable cameras — could be addressed before longer-term investments in anti-tailgating, integrated monitoring and dedicated security ownership.
The assessment also demonstrated that physical security cannot be owned by one control alone. Effective defence requires people to challenge, doors to close, visitors to be escorted, cameras and access records to be usable, and incidents to trigger a coordinated response.
Publication boundary: this case study does not state that every recommendation was subsequently implemented or independently retested.
Remediation Priorities
Immediate containment
- - Repair and reactivate faulty, disabled or unreliable doors and locking mechanisms
- - Enforce visible identification, visitor collection, escorting and challenge procedures
- - Keep the Mayor’s office area, civic meeting rooms and sensitive council spaces locked when unattended
- - Secure workstations, documents, lockers, confidential waste, physical keys and portable assets
- - Restore non-functional cameras and coverage at high-risk access points
Engineering and process hardening
- - Introduce anti-tailgating measures and layered access zones
- - Add door sweeps, shielding and stronger tamper-resistant locking hardware
- - Strengthen external fencing, gates and release-button protection
- - Enable pass-card anomaly alerting, door-status monitoring and routine CCTV health checks
- - Implement digital visitor tracking and formal physical-incident response playbooks
- - Define a secure chain of custody for confidential waste and key management
Sustained physical-security governance
- - Assign clear ownership for physical security, monitoring and incident coordination
- - Establish proportionate onsite or remote monitoring during higher-risk and after-hours periods
- - Integrate CCTV, access control, alerts and central incident reporting
- - Include physical security in onboarding, recurring awareness and leadership communications
- - Measure badge compliance, challenge behaviour, response times and repeat findings
- - Conduct periodic independent physical intrusion and social-engineering exercises
The Core Security Lesson
Physical security is a connected trust-boundary problem, not merely a door-lock problem.
A badge reader cannot compensate for a door held open. A camera cannot protect an area if nobody can respond. A visitor policy cannot work where controlled doors are disabled for convenience. Strong assurance requires the human, physical and monitoring layers to hold at the same time.
The correct question is not simply:
“Do we have locks, badges and CCTV?”
It is:
“Can an unfamiliar person move from public space to sensitive council areas before people and controls act together?”
How ProCheckUp Helps
ProCheckUp’s Physical Security Audit service tests the complete route from public approach to restricted-area response. Support can include:
- - Covert and overt physical-access testing
- - Tailgating, badge, reception and visitor-process assessment
- - Controlled social-engineering scenarios
- - Door, lock, latch, barrier and release-system review
- - Perimeter, gate and external-access testing
- - CCTV coverage, camera-health and monitoring-process assessment
- - Pass-card logging, alerting and incident-response review
- - Clear-desk, workstation, document, key and asset-protection testing
- - Confidential-waste and physical chain-of-custody assessment
- - Prioritised remediation planning and verification testing
Related services include Physical Security Audit, Social Engineering and Red Teaming.
Conclusion
This engagement demonstrated that extensive access can arise without forced entry or advanced tools when trust, convenience and passive monitoring weaken several boundaries at once. The decisive risks were not isolated defects: they were the interaction between staff behaviour, doors and barriers, visitor processes, information handling and delayed response.
By enforcing challenge and escorting, restoring physical controls, protecting information and assets, connecting CCTV and access events to action, and repeating realistic testing, local authorities can materially reduce the likelihood that a town hall becomes an easy route to sensitive council operations.
To discuss a Physical Security Audit, controlled social-engineering exercise or wider adversary simulation, contact ProCheckUp.
For More Information Please Contact Us
ACCREDITATIONS
