Most physical penetration tests have a general objective: get in, see how far you can go, document the failures. This engagement had a specific one. The client wanted to know whether a named, sensitive document stored somewhere on their two-building campus could be located and retrieved by an outside attacker with no badge, no insider knowledge, and no assistance. Two days, two buildings.
Day one I focused on the first building. Tailgating into a facility during business hours is rarely difficult if you time it right. People hold doors, nobody challenges someone who looks like they belong, and a little patience at a busy entry point gets you through. I was inside within a few minutes of arriving. The plan was to stay after close, wait out the last employees, and do a methodical search of the space after hours.
I stayed. I waited. I went through the accessible office areas once the building was clear.
The document was not in that building.
Day two required a different approach. Rather than targeting the main entry, I shifted to the second building and timed my approach around the midday service window, the period when deliveries and vendor traffic pick up and the loading dock area sees enough movement that an additional person does not register. I tailgated through the loading dock entrance when the traffic was right.
From there I worked toward the executive floor. The head of HR's office was unoccupied. The door was unlocked. I went in.
The target document was on the desk.
I photographed it, documented the full access chain, and left the way I came. In the debrief report, the document was included fully redacted, enough that the client could confirm I had found the right one, without unnecessarily re-exposing the contents. The client confirmed the find. They thanked the team for how it was handled.
The access chain that made this possible was not sophisticated. Tailgating worked at two different entry points across two days using two different approaches. No alarm was raised on day one when I was in the building after hours. The executive floor was accessible without any additional authentication. An individual office on that floor was unlocked and unoccupied during business hours. A sensitive document was sitting in plain reach.
Each of those failures is individually common. Together they mean that anyone motivated enough to spend two days trying could have done exactly what I did. The document in question, whatever it contained, was not protected by anything more than the assumption that unauthorized people do not get into the building. That assumption is not a security control.
Physical security failures tend to get underweighted in risk assessments because they feel less technical and therefore less serious. They are not less serious. The access I had inside those buildings was unconstrained in ways that network segmentation and endpoint controls make very difficult to achieve remotely. Physical presence inside a facility, especially in executive spaces, can expose information with consequences that dwarf what most network compromises yield.
The remediation recommendations covered the obvious controls: escort requirements and anti-tailgating procedures at all entry points including service areas, access control on executive office spaces, clean-desk policies for sensitive documents, and after-hours alarm coverage that would flag unauthorized presence rather than just unauthorized entry. None of them are exotic. All of them would have interrupted the chain at some point before I reached the desk.
The client's physical perimeter had never been tested. The assumption was that it was fine. It was not fine.