The power of an unexpected moment
A security penetration test often begins inconspicuously. At the entrance to a client’s premises, a man in a yellow vest walks behind a truck. His stride is relaxed, as if he walks around here every day. The driver checks in with the security guard as usual; the guard recognizes him and exchanges a few words. In that brief moment, the man behind him slips inside almost automatically. No badge, no check-in, and no official business on the premises. Just a demeanor that cleverly takes advantage of the morning rush.
Situations like these rarely stand out. They are part of the daily hustle and bustle of a workday where many things happen at once. As visitors check in, suppliers arrive, and employees coordinate with one another, there are brief moments when an unauthorized person might try to slip in. It is precisely these moments that reveal just how vigilant security is in its day-to-day operations.
Tailgating—following an authorized person—is one of the most common forms of unauthorized access. It occurs in offices, distribution centers, port areas, and municipal buildings. A visitor who has forgotten their badge, a technician who says they “just need to check something,” or an employee who holds a side door open a little longer than is prudent. These incidents may seem minor, but they require vigilance—especially when events unfold rapidly.
Why conduct a penetration test for your security?
Organizations want to know how their security systems respond when an unexpected situation arises—not in a training room, but in the middle of a workday. Penetration tests provide insight into that moment. They show how processes behave when a scenario doesn’t go according to plan and how security personnel respond when someone unexpectedly tries to gain access.
SERIS conducts approximately 50 of these tests each year. We perform them at locations where we provide security personnel ourselves, as well as at organizations that work with other security providers. The latter category is no exception. After all, a client who wants to have their own security partner evaluated benefits from an independent perspective. The butcher doesn’t inspect his own meat. SERIS can fulfill that role: with no stake in the outcome, focused purely on what the site reveals.
The test focuses on security as a whole, not on the individual. It examines how processes work, how people act, and how quickly anomalies are detected. The results are immediately actionable. A penetration test reveals where security is strong and where there is room for improvement. Sometimes it comes down to details in behavior. Sometimes it involves structural elements in the security protocol. In all cases, the client gains a clear picture of the current reality.
How SERIS designs a penetration test
An effective penetration test begins with understanding the target. SERIS examines the daily activities at a location: how employees enter the premises, when visitor traffic peaks, which entrances are frequently used in practice, and where routines develop that could create vulnerabilities. Based on this analysis, we determine which scenario makes sense and is therefore realistic to test.
No two tests are the same. Each scenario is tailored to the specific situation at the location and the associated risks. This could be a classic tailgating scenario, in which a tester slips in behind a group of employees during the morning rush hour. It could also involve a fake technician who tells the receptionist that he was called in for a malfunction and politely asks if he can come in. In other cases, we test how a location responds when someone presents an ID that’s just slightly off but confidently states that the rest of the group is already inside. Or an evening scenario where we assess how vigilant security remains when visitor traffic is low but attention levels also drop. Sometimes it’s purely social manipulation: a convincing story, the right tone, and a seemingly logical context through which someone tries to pass through an entrance without anyone really giving it a second thought.
This variation is intentional. Security measures that always anticipate the same type of situation have, in effect, only learned to respond to that one pattern. By structuring each scenario differently, even the less obvious vulnerabilities become apparent.
Some clients choose to discuss the scenario in advance. This is valuable, especially when a test is part of a broader training cycle. More often, however, the test itself comes as a surprise—and not just the scenario. The timing of the test is also a surprise. It could take place early in the morning, in the middle of a busy delivery period, or on a quiet Wednesday afternoon. After all, in real life, a genuine threat doesn’t give itself away in advance.
How a debriefing enhances security
After each penetration test, the tester and the security professional involved hold a discussion. This discussion takes place immediately, while the situation is still fresh in everyone’s mind. They discuss what was observed, what raised concerns, and why certain decisions were made. The discussion is professional and aimed at enhancing professional expertise.
Security guards, whether they work for SERIS or another security organization, often say that these are valuable moments. They can see exactly how they reacted, which cues they did or did not pick up on, and where their strengths lie. The differences often lie in small details: a glance, a posture, a phrase that doesn’t quite fit with the visitor’s story. By discussing these details, insight into one’s own actions grows.
This also benefits clients. They gain a clear understanding of the extent to which security guards reflect on their work, ask questions, and contribute ideas for improvement. That attitude plays a major role in determining the effectiveness of the security process.
Reporting: Improving processes, not evaluating people
Following the test and the debriefing, a detailed written report is provided. It outlines what was tested, how the situation unfolded, what decisions were made, and what the outcome was. The report is specific and actionable. It is not a generic summary, but a concrete picture of what actually happened at that location, at that moment.
A key principle here is that the report focuses on processes and procedures, not on individual security guards. That distinction is essential. The goal is not to assess whether someone is doing their job well or poorly, but to understand how a security system functions as a whole. Where do vulnerabilities arise? Which instructions prove to be unclear in practice? At what point in the protocol is there a lack of guidance?
The report answers those questions. Based on this information, our clients can implement targeted changes. Sometimes this involves a minor procedural adjustment. Sometimes it involves changing the flow of visitors or suppliers. Sometimes the report confirms that a team is performing exceptionally well and acting exactly as the situation requires. In all cases, it provides a clear and honest picture of the reality.
What clients notice after a penetration test
Organizations that commission penetration tests find that their security improves significantly. This isn’t because security personnel suddenly start doing things differently, but because awareness increases. After multiple tests, security personnel recognize unusual situations more quickly and ask more targeted questions during access control.
Clients see this reflected in their day-to-day work. The intake process is more structured, suppliers are registered more consistently, and site security is implemented more rigorously. Sometimes a test leads to a minor process adjustment or a technical change. Other times, it confirms that a team is performing exceptionally well.
Clients appreciate that SERIS takes an independent look at the process, regardless of which party provides the security. This makes the results useful as a basis for process improvement, contract management, or training.
What Penetration Testing Means for Security Professionals
Penetration testing brings the security profession to life. The test reveals how someone performs under real-world conditions and identifies areas for improvement. The evaluation focuses not on the individual, but on the team as a whole. This makes it fair and professional. Security professionals appreciate this. They receive immediate feedback that is relatable and actionable. New employees quickly learn which situations commonly arise in practice. Experienced security guards maintain their sharpness and make conscious decisions when routines follow one another in rapid succession. In this way, teams build a shared standard of alertness and professionalism.
Security that proves itself
A security process that only looks good on paper isn’t security. The proof lies in what happens on an ordinary weekday morning, at an entrance everyone knows, at a time when no one expects anyone to try. Penetration tests reveal that moment. Not as a punishment, but as an honest reflection of how strong the security really is.
SERIS conducts these tests for clients we work with directly, as well as for organizations that use other security providers. The results are valuable in both cases: they provide concrete insights into what is working well, what could be improved, and how processes and procedures can be strengthened. This ensures that your security isn’t just perceived as reliable, but actually proves it.
Would you like to know how a penetration test can benefit your organization? Visit www.seris.nl or contact us for a no-obligation consultation.




