Physical security controls are part of many requirements – we support you with audit-ready evidence.
KRITIS
Protection of critical infrastructure against physical attacks – we assess on-site access and security.
NIS 2
Extended requirements for network and information security – including physical control of IT locations.
DORA
For financial and technology companies: the physical resilience of systems becomes mandatory.
CER
The directive on the resilience of critical entities requires physical security measures along the entire value chain.
ISO 27001
The international standard for information security contains explicit requirements for physical barriers and controls.
TISAX
In the automotive sector, TISAX requires physical security measures at development and production sites.
uncontrolled access points
cameras without active monitoring
social engineering success
successful attacks
Clearly define targets, risk areas, and approvals.
Analyze buildings, processes, and visitor flows – without intrusion.
Social engineering, tailgating, lockpicking – controlled and logged.
Evidence photos, risk ratings, and clear recommendations for action.
Quick fixes, awareness, and process updates – then a new cycle.
Lessons learned, gap analysis, and planning of the next cycle.
🔄 The goal is to repeat the physical pentest over several years until we fail.