Service
Scope

What we test, review, and validate.

Outcome of this engagement

A Physical Security Assessment helps your team understand where physical security controls, processes, people, and facility safeguards may create risk, and what should be improved to better protect people, operations, sensitive information, and restricted areas.

Threat risk assessment

  • Risks to people, equipment, operations, and critical assets
  • ASIS and CPTED-informed assessment approach
  • Threat considerations such as theft, unauthorized entry, and insider risk

Site & control review

  • Site grounds, entry points, access zones, and restricted areas
  • CCTV, intrusion, duress, intercom, and related safeguards
  • Security staffing, visitor processes, and incident history

Controlled access testing

  • Open-source and onsite reconnaissance
  • Approved attempts to bypass or manipulate physical safeguards
  • Restricted-area and sensitive-information controls, where in scope
What You Receive

Physical security findings your team can act on.

  • Executive summary for non-technical stakeholders
  • Summary of physical security assessment methods
  • Summary of physical security findings by in-scope site
  • Overview of online and onsite survey results
  • Detailed findings and remediation recommendations
  • Observations related to physical security controls, processes, policy, and infrastructure
  • Threat risk assessment observations, where included in scope
  • Likelihood and impact ratings for relevant risks
  • Criticality ratings for recommendations, graded from high to low
  • Supporting attachments, examples, and relevant observations
Beyond THE REPORT

Physical security should be tested against how access actually happens.

Methodology Preview

A controlled process from scope to evidence.

01
Define
02
Review
03
Assess
04
Test
05
Report
See Full Methodology
Why Canary Trap

Physical testing led by people who understand restraint.

Controlled execution

Testing is led by experienced offensive security professionals, not handed off to junior operators following a script.

Real-world perspective

Every engagement is scoped with stakeholder sign-off, approved techniques, safe-word protocol, authorization documents, and named escalation contacts.

Practical recommendations

Photo and video evidence is captured only with explicit authorization and handled according to agreed evidence and chain-of-custody requirements.

Recognized assessment principles

Findings include practical recommendations for security, facilities, IT, operations, and leadership teams.

Clear stakeholder coordination

Every engagement includes clear communication, defined expectations, stakeholder alignment, and controlled escalation paths.

Focused reporting

Where included, validation helps confirm that improved controls or processes are working, not just documented.

Trust signals

Canary Trap is SOC 2 Type II certified, maintains an NPS above 95, and specializes in offensive security testing.

Related Services

Physical access often connects to broader security risk.

Red Team Exercise

Social Engineering Assessment

Wireless Security Assessment

FAQ

Physical security assessment questions, answered plainly.

Next Step

Ready to scope a Physical Security Assessment?

Book a Scoping Call