Social Engineering & Physical: Breaching the Human Perimeter
Some of the most serious findings I deliver never touch a line of code — they come from people, buildings, and trust. I run full-scope social engineering and physical assessments: the kind that answer, honestly, “could someone talk and walk their way into your business?” This is the shape of that work and, above all, how an organization shuts it down.
What we're actually testing
A full-scope engagement treats the whole organization as the attack surface — not just its firewalls, but its people, its front desk, its car park, and its Wi-Fi. The client sets the objective (reach a restricted area, obtain a specific piece of information, get a device onto the network) and the boundaries; I prove whether it's possible, safely and without disruption. The point is never to embarrass staff — it's to find the gap before someone with bad intent does.
The desk phase
The engagement is largely won before I go anywhere near the target. Working only from public information, I build a detailed picture of the organization and the people in it — structure, routines, relationships, and the small human details that make a later approach credible. It's methodical, patient work, and it's remarkable how much a determined outsider can assemble from what's already out in the open.
The takeaway for a defender isn't the method — it's the volume. Your organization and your team leak far more publicly than anyone realizes, and that exposure is the raw material for everything that follows.
Reading people, earning trust
This is the core of the craft and the part I won't break down in detail. In short: I read how people and situations actually behave, match the approach to the person, and — when the engagement calls for it — work as a small, coordinated team so the pieces fit together naturally. The goal is a moment where a helpful person, wanting to do the right thing, shares something they shouldn't.
It takes time, patience, and a lot of preparation. Being genuinely likeable and reading a room are the sharpest tools here — which is exactly why no product defends against them. Only trained, empowered people do.
Getting in, and what waits inside
Where the scope allows on-site work, I assess the building the way a real intruder would: how it's watched, where it's soft, and how a stranger with the right story and the right props becomes invisible. Access controls — badges, doors, and the human habit of holding them open — get tested end to end.
Once someone is inside, the risk isn't theoretical: an unlocked workstation, an unattended port, or an unmonitored room is enough to leave something behind that a real attacker would use for persistent access. Proving that path — cleanly, and within scope — is usually the finding that changes how a company thinks about its front door.
The perimeter you can't see
Not every approach needs a physical presence. The wireless edge of a building leaks information about who's there and when, and the same rapport built during reconnaissance can be delivered remotely — a message that looks exactly like a colleague, a partner, or a client, arriving through the channels people already trust. Phishing and look-alike outreach turn one convincing message into a foothold.
Why it matters
No exploit, no malware, no alert — and yet the objective is met: a restricted area reached, a critical credential obtained, a device on the internal network. Every technical control the organization paid for is bypassed by a held door, a friendly voice, or a well-timed message. That's the uncomfortable finding these assessments deliver: the human layer is usually the weakest, and it's the one nobody thinks to patch.
Closing the human perimeter
This is the part worth spending money on — and where I put the real detail, because defending is what actually protects a business:
- Security awareness, done well — regular, realistic training so staff recognize pretexting and phishing — and a culture, backed by management, where politely challenging a stranger (“can I see your badge?”) is expected, not rude.
- Reduce public exposure — review what the organization and key staff publish; tighten profiles, remove sensitive operational detail, and treat OSINT reduction as an ongoing hygiene task.
- Visitor & escort policy — sign-in, photo badges, mandatory escorts, and verification of contractors against the vendor — a hi-vis vest should never be a skeleton key.
- Physical access controls — encrypted smartcards with mutual authentication (never unencrypted prox), anti-tailgating measures (turnstiles / mantraps), and controlled, logged access to server rooms and critical spaces.
- Endpoint & port control — block unknown USB/HID devices, auto-lock idle workstations, a clean-desk policy, and no unattended machines left unlocked.
- Wi-Fi & email hardening — WPA3-Enterprise with client isolation and rogue-AP detection; SPF/DKIM/DMARC, external-sender banners, and easy one-click phishing reporting.
- MFA everywhere — so that a stolen credential, a cloned badge, or a dropped device is never enough on its own to become a foothold.
Seeing it when it happens
Prevention isn't perfect, so I hand the blue team what to watch for:
- Badge-in without a matching badge-out, and the same credential used in two places — the signatures of tailgating and cloning.
- USB device-insertion telemetry: a new input device appearing on a machine that already has one is a red flag worth alerting on.
- Reception and visitor logs reconciled against badge and CCTV events, with attention to the soft entries (deliveries, smoking areas, side doors).
- Rogue / look-alike Wi-Fi near the premises, and unusual client associations on the guest network.
- Phishing reports trending up, and mail from look-alike domains — a reporting culture turns every employee into a sensor.
Did it stick?
A follow-up engagement is the real test of the fixes. After awareness training and physical controls, the same approach gets challenged at the door; after device control, a dropped implant is dead plastic; after email hardening, the look-alike message lands in quarantine. When the same playbook stops working, the controls are real — not just words in a policy nobody reads.
You can spend a fortune on firewalls and still be undone by a held door and a confident smile. This work takes patience, preparation, and the nerve to see it through — but the finding it delivers is priceless: the human is the perimeter. Train it, and it becomes the strongest layer instead of the weakest.