Physical penetration testing in Canada
This is the engagement where a stranger walks into your building and tries to reach the server room. It is also the engagement most likely to be commissioned by someone who does not have the authority to commission it.
A physical penetration test in Canada costs between $8,000 and $25,000 CAD plus travel and runs three to six tester days across reconnaissance, entry attempts and reporting. If you rent an office in a multi-tenant building and everything of value lives in a cloud tenancy, you probably cannot lawfully authorise most of this test, and it would not tell you much if you could. The organisations for which it is worth the money own their premises, or keep something in them that matters more than a laptop.
3 to 6 days Tester days, of which one to two are reconnaissance before anyone approaches the building
What is actually being tested
The target is rarely a lock. It is the set of assumptions your building makes about who belongs in it, and almost every one of those assumptions is enforced by a person rather than by hardware.
Access control and credentials
Whether a badge can be copied, whether a copied badge works, whether the system notices two uses of the same credential in different places, and whether anybody reviews the logs. The technology in the badge decides how hard the first question is, and the spread between the common options is enormous.
- 125 kHz proximity cards
- The beige legacy cards still on thousands of Canadian doors. They broadcast a fixed number with no encryption and no challenge. A reader in a bag copies one from a pocket at conversational distance, and a blank card is written in seconds. If this is what you issue, assume every badge is copyable and treat the finding as an estate replacement project rather than a surprise.
- 13.56 MHz MIFARE Classic
- Higher frequency and a real cryptographic scheme, but one that was broken publicly years ago and stays broken. Practically closer to the legacy cards than to modern ones.
- Modern encrypted credentials
- Current generation cards that use properly implemented cryptography and mutual authentication with the reader. Cloning stops being the route. Findings move to the enrolment process, the visitor badges, and the reader wiring, which is often still an unencrypted protocol running through a ceiling.
- Mobile credentials
- A phone rather than a card. Strong against copying, and it moves the question to whether the enrolment link can be obtained by asking, which is a social engineering problem covered on social engineering testing.
Entry without a credential at all
Tailgating behind an employee, which works in most buildings on most days. Under-door tools that reach a lever handle or a motion sensor on the inside. Latch shimming on doors whose deadbolt is never thrown. Loading bays and smoking-area doors propped open. Ceiling voids above walls that stop at the suspended tile. None of it requires expensive equipment, and the fix is usually procedural rather than capital.
What happens after entry
Reaching a desk is not a finding. Reaching a desk, plugging into a live network port in a meeting room and getting a DHCP address on the corporate network is a finding, and it turns into the lateral movement work described on network penetration testing. Other targets worth scoping: the server room or comms cupboard, unlocked workstations, printed material left on desks and in bins, and whether an unattended laptop can be taken out of the building past reception.
The paperwork, which is not optional
Physical testing is the one engagement where getting the authorisation wrong can end with a tester in the back of a police car and your company explaining itself to a landlord. The letter the tester carries, usually called an authorisation letter, is the document that stops that. Work through this order before anyone books a flight.
- Confirm you have the legal right to authorise entry to every area in scope. If you lease, you almost certainly do not have that right for lobbies, lifts, stairwells, parking or loading bays.
- Get written landlord or property manager agreement for any common area you want tested, naming the dates and the firm.
- Have the authorisation letter signed by an officer of the company, not by the IT manager. It needs to be from someone whose authority a police officer will accept at face value.
- Put the specifics in it: the tester's legal name, the client's legal name and address, the exact addresses in scope, the exact dates and hours, and what techniques are authorised.
- Name two internal contacts with mobile numbers, reachable at any hour, who can confirm the engagement is real.
- Brief building security and your own physical security lead, in writing, and keep them out of the tested population if the point is to test the guards.
- Agree the stop condition in advance: what ends the test immediately, and what the tester does the moment they are challenged by police rather than by staff.
Two copies, and one of them is not on paper
The tester should carry a signed original and a photograph of it, and your named contacts should hold a copy where they can find it at three in the morning. A letter locked in the tester's car while the tester is inside a building being detained is a letter that does not exist. Reputable firms will insist on this arrangement without being asked, and a firm that treats the authorisation letter casually is telling you how it treats everything else.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
If you lease, read this before you buy
Most Canadian companies buying a physical test are tenants in a multi-tenant building. Tenancy is a constraint, not a formality. You can authorise testing of your own demised premises: your suite, your doors, your server cupboard if it is inside your suite. You cannot authorise testing of the lobby, the security desk, the lift, the fire stairs or the loading dock, because they are not yours and the people working in them do not work for you.
That matters because the interesting part of the attack path usually runs through exactly those areas. A test scoped only to your own suite door, starting from inside a lobby the tester was escorted into, answers a much smaller question than the one you were asking. Either negotiate landlord participation, which is slow and often refused, or accept the narrower scope and price it accordingly. Firms that quote a full building engagement without asking who owns the building have not thought about it, which is one of the checks on questions to ask a vendor.
What it costs
| Scope | Typical range | What drives it |
|---|---|---|
| Single site, tenant suite only, one tester | $8,000 to $12,000 | One or two entry attempts, limited reconnaissance |
| Single site, full building with landlord agreement | $12,000 to $18,000 | Longer reconnaissance, multiple pretexts, two testers |
| Multiple sites or a data centre | $18,000 to $25,000 | Travel, staged attempts, higher tester seniority |
| Combined with social engineering and network follow-through | $25,000 and up | Becomes a scenario engagement rather than a physical test |
Two testers rather than one is worth paying for on anything past the smallest scope. Entry attempts are safer and more effective in pairs, and one person can hold a conversation while the other works. Travel is billed on top in every case, and how it is billed differs by firm, so compare that line specifically. The general arithmetic behind day rates is on penetration testing cost in Canada.
Who should not buy this
A software company with fifty staff, a leased floor, laptops that are encrypted and a product that runs entirely in a cloud account should not buy a physical penetration test. The plausible outcome is a report saying somebody tailgated through your suite door and photographed a whiteboard, which is true, costs $10,000 CAD to learn, and is fixed by a conversation about badge discipline. The same money spent on an authenticated test of your product finds the flaws that would actually lose customer data, which is the argument made on web application security testing.
The cases where it earns its price are specific. You operate your own data centre or a colocation cage. You hold physical assets that matter: cash, pharmaceuticals, controlled equipment, evidence, original records. You run manufacturing or utilities where reaching a control panel is reaching the process. You are a public body with a statutory duty over records held on premises. Or a customer contract or an insurer has asked for it by name, which happens more often in financial services and defence supply chains than elsewhere. Check whether what your insurer is asking for is really this engagement.
Check whether you can authorise it
Tell us what you occupy and what is in the building, and we will say whether this test is available to you and worth commissioning.
Get matchedCommon questions
Is physical penetration testing legal in Canada?
Yes, when it is authorised by someone with the legal right to permit entry to the areas being tested. The legality turns entirely on that authority, which is why tenancy matters so much. Entering a landlord's common areas or another tenant's space without their agreement is trespass regardless of what your own company signed, and no letter from your chief executive cures it.
Will our staff get in trouble if the tester gets in?
They should not, and you should say so in writing before the engagement starts. Someone will hold a door open, because holding doors open is normal behaviour that your building has trained them into. Reports that name the individual who let a tester through produce worse security, because the next person to notice something unusual will decide it is not their problem.
Do we need to tell building security?
Tell the head of building security in writing and keep the guards on duty unaware, if testing the guards is part of the point. Someone senior on the landlord side needs to know the engagement is real so that a challenge escalates to a phone call rather than to the police. Telling nobody at all is how these engagements go badly, and reputable firms will refuse to proceed on that basis.
Can it be combined with a network test?
Yes, and it is usually better value that way. Physical entry that ends at a network port is only interesting if somebody then uses the port, so scoping the internal network work as a continuation of the physical entry gives you one narrative instead of two disconnected reports. That combined shape is closer to a red team assessment, and it is priced accordingly.
How often should a physical test be repeated?
Every two to three years for most organisations that need one at all, or after you change premises, change access control technology or change security provider. Physical controls do not drift the way software does, so an annual repeat generally finds the same procedural weaknesses you did not finish fixing. The broader argument about test frequency is on how often you should test.