BSides Joburg 2026

Lighting the Way to the Server Room
2026-07-25 , Track 2

Physical penetration testing is often reduced to lockpicks, cloned badges, and dramatic stories of breaking into buildings. The reality is far less glamorous and far more interesting.

A successful physical penetration test begins long before anyone approaches a target facility. It starts with reconnaissance, understanding human behaviour, identifying operational weaknesses, navigating legal boundaries, and developing believable pretexts that exploit human trust rather than technology.


Physical penetration testing is often portrayed as lockpicks, badge cloning, and dramatic break-ins. In reality, those activities represent only a small part of a successful engagement. The true challenge lies in understanding how physical security, human behaviour, operational processes, and technical controls intersect to either stop or enable an attacker.

This talk provides a practical walkthrough of a real-world physical penetration test from start to finish. Attendees will follow the complete engagement lifecycle: defining scope and legal boundaries, conducting reconnaissance, developing social engineering pretexts, gaining access to facilities, operating within a target environment, and ultimately reporting findings back to the client.

Drawing from real assessments and industry experience, the session focuses on the decision-making process behind physical testing rather than sensationalized lockpicking demonstrations. We will explore how attackers identify opportunities through open-source intelligence, exploit predictable human behaviours, leverage environmental weaknesses, and navigate physical spaces while balancing operational risk.

Presentation Outline:

Introduction

  • What physical penetration testing actually is and why it remains one of the most effective methods of assessing organisational security.
  • Common misconceptions surrounding physical security assessments.
  • Understanding how physical, human, and digital security controls overlap.

Scoping and Legalities

  • Defining rules of engagement, success criteria, and operational constraints.
  • Authorisation requirements, legal considerations, and jurisdiction-specific concerns.
  • Planning for contingencies, escalation paths, and engagement safety.

Reconnaissance

  • How attackers and physical testers build target intelligence before arriving on site.
  • Using publicly available information to identify entrances, staff routines, security technologies, and potential attack paths.
  • Translating reconnaissance findings into actionable engagement plans.

Breaching the Boundary

  • Common access vectors including tailgating, piggybacking, pretexting, and badge-related weaknesses.
  • Understanding why social engineering remains one of the most effective physical attack techniques.
  • How human psychology influences security outcomes.
  • Building your own toolkit, (custom WIFI Pineapple, custom badge cloner, cheap gadgets to build a bigger toolkit)

Operating Once Inside

  • Prioritising objectives after gaining access.
  • Identifying high-value targets such as boardrooms, network infrastructure, server rooms, and unattended workstations.
  • Leveraging C2 frameworks and Internal Attacks (MITM, ADCS, LLMNR, PTK)
  • Understanding the relationship between physical access and broader cyber compromise opportunities.

Contingency and “What If You're Caught?”

  • Managing encounters with security personnel, facilities staff, or law enforcement.
  • Documentation, communication procedures, and safe disengagement strategies.
  • Lessons learned from real-world physical testing incidents.

Reporting and Debrief

  • Converting observations into meaningful security findings.
  • Demonstrating impact without creating unnecessary risk.
  • Delivering remediation guidance that improves both physical and organisational security.

This talk combines practical field experience, social engineering concepts, and physical security assessment methodologies to provide attendees with a realistic understanding of how physical penetration tests are planned, executed, and reported.

Key Takeaways:

Understanding Physical Attack Methodology
Attendees will gain a clear understanding of how professional physical penetration tests are conducted from initial planning through final reporting.

Recognising Security Weaknesses Beyond Technology
The session demonstrates how human behaviour, organisational processes, and environmental design often create opportunities that technical controls alone cannot prevent.

Improving Defensive Readiness
Security practitioners, facilities teams, and business leaders will learn practical ways to identify and address weaknesses before they are discovered by real adversaries.

I break into networks, applications, and infrastructure to find the critical flaws that automated scanners miss. By simulating real-world adversary tactics, I help organizations see their environment through an attacker's eyes, demonstrating actual risk and providing the blueprint to fix it.