Physical Intrusion Testing
Authorised testing of whether access can realistically be achieved, and what it permits once it is.
View capabilityIndependent protective security consultancy
We assess physical, personnel and procedural security as one system — combining protective security expertise, evidence-led assessment and the perspective of a capable adversary.
Independent
No product or supplier interests.
Evidence-led
Findings supported by documented evidence.
Adversary-informed
Controls considered against credible threat behaviour.
Actionable
Prioritised recommendations for decision-makers.
The distinction
Most reviews establish that controls exist. We establish whether they hold.
Documented arrangements and daily practice diverge over time. Procedures are written for conditions that have since changed, controls are worked around under operational pressure, and responsibility moves without the design moving with it.
We assess security as it is actually practised, establish what the difference permits, and set out what should change. The output supports decisions on risk and on where money is best spent.
How we see it
Physical, personnel and procedural measures fail together far more often than they fail alone. We assess them as one arrangement, from the threat it must withstand to the improvements worth making.
Credible threat
What a capable adversary would realistically attempt, and why.
Assessment and adversarial thinking
Review, survey and interview, with authorised testing where it produces evidence assessment alone cannot.
Evidence
Observations, artefacts and timelines, each traceable to a finding.
Prioritised improvement
Sequenced by the risk reduction achieved against the effort required.
What we do
An independent assessment of how physical, personnel and procedural security work together — establishing where protection is weaker than assumed, what that permits, and which improvements reduce risk most for the effort involved.
This is BlackTrace’s principal assessment service. What it draws on depends on the question being asked and the scope agreed.
Specialist capabilities
Each may form part of a protective security assessment, or be commissioned on its own where an organisation already knows the question it needs answered. No engagement uses every capability, and adversarial testing is carried out only where the agreed scope provides for it.
Adversarial depth
A core specialist strength. The consultants who assess controls also understand how protective security is defeated in practice.
Authorised testing of whether access can realistically be achieved, and what it permits once it is.
View capabilityExtended scenarios showing how separate weaknesses combine into consequence.
View capabilityAssessment and assurance
Assessment of the controls governing who holds access, and on what basis.
View capabilityIndependent review of security governance, management and maturity.
View capabilityMethodology
Five stages applied to every engagement, from a single site to an estate-wide programme. Each produces a defined output the next stage depends on, which is what makes findings comparable between sites and across years.
Establish what must be protected, from whom, and to what standard.
Gather evidence on how security is designed, and on how it is practised.
Establish what each weakness enables, and how weaknesses combine.
Sequence improvement by risk reduction against effort and cost.
Support the change, then evidence that it reduced risk.
Sectors
Our work is particularly relevant to organisations where people, facilities, information or operations require effective protective security. The sectors below are representative rather than exhaustive.
Generation, network and water operators where physical access carries direct operational and regulatory consequence.
Exchanges, transmission sites and distributed estates, many of them remote and unstaffed.
Colocation and enterprise facilities where physical security underpins customer and regulatory commitments.
Departments, agencies and arm's-length bodies requiring independent evaluation against defined standards.
Branch networks, dealing environments and sensitive processing sites.
Production and research sites where disruption, tampering or loss of intellectual property is consequential.
Next step
An initial conversation is exploratory, confidential and carries no obligation. If we do not believe an engagement is warranted, we will say so.