The power of an unexpected moment

A security penetration test often begins inconspicuously. At the entrance to a client’s premises, a man in a yellow vest walks behind a truck. His stride is relaxed, as if he walks around here every day. The driver checks in with the security guard as usual; the guard recognizes him and exchanges a few words. In that brief moment, the man behind him slips inside almost automatically. No badge, no check-in, and no official business on the premises. Just a demeanor that cleverly takes advantage of the morning rush.

Situations like these rarely stand out. They are part of the daily hustle and bustle of a workday where many things happen at once. As visitors check in, suppliers arrive, and employees coordinate with one another, there are brief moments when an unauthorized person might try to slip in. It is precisely these moments that reveal just how vigilant security is in its day-to-day operations.

Tailgating—following an authorized person—is one of the most common forms of unauthorized access. It occurs in offices, distribution centers, port areas, and municipal buildings. A visitor who has forgotten their badge, a technician who says they “just need to check something,” or an employee who holds a side door open a little longer than is prudent. These incidents may seem minor, but they require vigilance—especially when events unfold rapidly.

Why conduct a penetration test for your security?

Organizations want to know how their security systems respond when an unexpected situation arises—not in a training room, but in the middle of a workday. Penetration tests provide insight into that moment. They show how processes behave when a scenario doesn’t go according to plan and how security personnel respond when someone unexpectedly tries to gain access.

SERIS conducts approximately 50 of these tests each year. We perform them at locations where we provide security personnel ourselves, as well as at organizations that work with other security providers. The latter category is no exception. After all, a client who wants to have their own security partner evaluated benefits from an independent perspective. The butcher doesn’t inspect his own meat. SERIS can fulfill that role: with no stake in the outcome, focused purely on what the site reveals.

The test focuses on security as a whole, not on the individual. It examines how processes work, how people act, and how quickly anomalies are detected. The results are immediately actionable. A penetration test reveals where security is strong and where there is room for improvement. Sometimes it comes down to details in behavior. Sometimes it involves structural elements in the security protocol. In all cases, the client gains a clear picture of the current reality.

How SERIS designs a penetration test

An effective penetration test begins with understanding the target. SERIS examines the daily activities at a location: how employees enter the premises, when visitor traffic peaks, which entrances are frequently used in practice, and where routines develop that could create vulnerabilities. Based on this analysis, we determine which scenario makes sense and is therefore realistic to test.

No two tests are the same. Each scenario is tailored to the specific situation at the location and the associated risks. This could be a classic tailgating scenario, in which a tester slips in behind a group of employees during the morning rush hour. It could also involve a fake technician who tells the receptionist that he was called in for a malfunction and politely asks if he can come in. In other cases, we test how a location responds when someone presents an ID that’s just slightly off but confidently states that the rest of the group is already inside. Or an evening scenario where we assess how vigilant security remains when visitor traffic is low but attention levels also drop. Sometimes it’s purely social manipulation: a convincing story, the right tone, and a seemingly logical context through which someone tries to pass through an entrance without anyone really giving it a second thought.

This variation is intentional. Security measures that always anticipate the same type of situation have, in effect, only learned to respond to that one pattern. By structuring each scenario differently, even the less obvious vulnerabilities become apparent.

Some clients choose to discuss the scenario in advance. This is valuable, especially when a test is part of a broader training cycle. More often, however, the test itself comes as a surprise—and not just the scenario. The timing of the test is also a surprise. It could take place early in the morning, in the middle of a busy delivery period, or on a quiet Wednesday afternoon. After all, in real life, a genuine threat doesn’t give itself away in advance.

How a debriefing enhances security

After each penetration test, the tester and the security professional involved hold a discussion. This discussion takes place immediately, while the situation is still fresh in everyone’s mind. They discuss what was observed, what raised concerns, and why certain decisions were made. The discussion is professional and aimed at enhancing professional expertise.

Security guards, whether they work for SERIS or another security organization, often say that these are valuable moments. They can see exactly how they reacted, which cues they did or did not pick up on, and where their strengths lie. The differences often lie in small details: a glance, a posture, a phrase that doesn’t quite fit with the visitor’s story. By discussing these details, insight into one’s own actions grows.

This also benefits clients. They gain a clear understanding of the extent to which security guards reflect on their work, ask questions, and contribute ideas for improvement. That attitude plays a major role in determining the effectiveness of the security process.

Reporting: Improving processes, not evaluating people

Following the test and the debriefing, a detailed written report is provided. It outlines what was tested, how the situation unfolded, what decisions were made, and what the outcome was. The report is specific and actionable. It is not a generic summary, but a concrete picture of what actually happened at that location, at that moment.

A key principle here is that the report focuses on processes and procedures, not on individual security guards. That distinction is essential. The goal is not to assess whether someone is doing their job well or poorly, but to understand how a security system functions as a whole. Where do vulnerabilities arise? Which instructions prove to be unclear in practice? At what point in the protocol is there a lack of guidance?

The report answers those questions. Based on this information, our clients can implement targeted changes. Sometimes this involves a minor procedural adjustment. Sometimes it involves changing the flow of visitors or suppliers. Sometimes the report confirms that a team is performing exceptionally well and acting exactly as the situation requires. In all cases, it provides a clear and honest picture of the reality.

What clients notice after a penetration test 

Organizations that commission penetration tests find that their security improves significantly. This isn’t because security personnel suddenly start doing things differently, but because awareness increases. After multiple tests, security personnel recognize unusual situations more quickly and ask more targeted questions during access control.

Clients see this reflected in their day-to-day work. The intake process is more structured, suppliers are registered more consistently, and site security is implemented more rigorously. Sometimes a test leads to a minor process adjustment or a technical change. Other times, it confirms that a team is performing exceptionally well.

Clients appreciate that SERIS takes an independent look at the process, regardless of which party provides the security. This makes the results useful as a basis for process improvement, contract management, or training.

What Penetration Testing Means for Security Professionals

Penetration testing brings the security profession to life. The test reveals how someone performs under real-world conditions and identifies areas for improvement. The evaluation focuses not on the individual, but on the team as a whole. This makes it fair and professional. Security professionals appreciate this. They receive immediate feedback that is relatable and actionable. New employees quickly learn which situations commonly arise in practice. Experienced security guards maintain their sharpness and make conscious decisions when routines follow one another in rapid succession. In this way, teams build a shared standard of alertness and professionalism.

Security that proves itself

A security process that only looks good on paper isn’t security. The proof lies in what happens on an ordinary weekday morning, at an entrance everyone knows, at a time when no one expects anyone to try. Penetration tests reveal that moment. Not as a punishment, but as an honest reflection of how strong the security really is.

SERIS conducts these tests for clients we work with directly, as well as for organizations that use other security providers. The results are valuable in both cases: they provide concrete insights into what is working well, what could be improved, and how processes and procedures can be strengthened. This ensures that your security isn’t just perceived as reliable, but actually proves it.

Would you like to know how a penetration test can benefit your organization? Visit www.seris.nl or contact us for a no-obligation consultation.

Frequently Asked Questions About Penetration Testing

A security penetration test is a controlled, realistic attempt to gain unauthorized access to a location. It assesses how effectively security procedures and personnel respond to situations that might arise in real-world scenarios, such as tailgating, social engineering, or taking advantage of crowds at entry points.

SERIS conducts penetration tests to provide an independent assessment of security quality. These tests are performed both at locations where SERIS operates and at organizations that work with other security firms. The result is an unbiased assessment of how robust processes and access control are in practice.

No. A penetration test focuses on the overall security process, and the report is designed to improve procedures, not to evaluate individual employees. The test shows how the facility’s security works as a whole, which areas are strong, and where improvements can still be made. The goal is always to strengthen the organization’s security.

A security audit assesses processes, documentation, and compliance with guidelines. A penetration test goes a step further: it tests how those processes perform in practice under realistic conditions. Both are valuable, but a penetration test reveals what actually happens when it really matters.

That depends on the client’s preference. Some organizations choose to discuss the scenario in advance so that the test can be part of a broader training cycle. More often, however, the test comes as a surprise, including the timing of its execution. This provides the most realistic picture of how security functions in practice.

Share this article

Related articles

  • Become a Security Guard

    Becoming a Security Guard, Part 1: What Happens Between Your Job Application and Your First Shift

    Becoming a security guard is easier than you think: no prior degree required, and you’ll start earning a salary from your very first shift. The training program ... read more

    9.9 min readPublished on: September 8, 2026
  • Security Continuity

    Security Continuity: How to Safeguard On-Site Knowledge

    That One Audit Question That Reveals Continuity in Security The auditor calmly goes through his checklist and asks a ... read more

    6.2 min readPublished on: July 15, 2026
  • security measures for vacant properties

    Security During Vacancies and Renovations: Staying in Control of a Changing Site

    Sixty hours with no one watching At a redevelopment site in Rotterdam-Zuid, the last one leaves around 5:30 p.m. on Friday afternoon... read more

    6-minute readPublished on: July 15, 2026