An authorized breach is where the CEO or person in charge gives us permission to attempt an unauthorized entry into their building or business for the purpose of discovering weak spots or flaws in their security. We’ve done dozens of these types of breaches in all sorts of settings (commercial office buildings, large residential buildings, hospitals, hotels, casinos, manufacturers, even high security intelligence agencies). Sadly, in most all cases, with one exception, we were able to gain unauthorized access into the building without much trouble at all.
In one case, we simply threw around the name of the person in charge and the building staff allowed us entry without checking with him as was required in their procedures manual.
In another case, we entered their underground parking garage. Someone was leaving and the garage door was open for a few minutes. We knew that all entrance doors from the garage into the building had a card reader so we just struck up a conversation with someone walking toward the entrance door and walked right in with him while we continued to talk. We then went on the elevator with him and now had access to the entire building.
In still another we found an external door that was not fully closed and simply walked into the building through that door, which now gave us access to the entire building.
In one case we made a bet with the Director of Security that we could get in. He felt his security was so tight that they would not allow us entry without a building pass. So we jumped onto the service elevator. The elevator operator did question us and he did tell us that we would need ID in order for him to take us up into the building. So we took out some fancy looking badge that anyone can buy on the Internet and said (in an authoritative voice) “this is the only ID we need.” That intimidated him and he took us up. When we arrived we called for the Security Director. As he walked down the hallway toward us he put his head down shaking it and said, “how did you do it?” So we said, “you train your security staff well, but you exclude the service elevator operator, because he’s not part of security. So now he’s the weak link in the chain. You need to train all the building staff, not just the security staff.”
Here’s a scary one. This is the one we mentioned where we failed to gain entry. However, we did win another bet. This facility belonged to a Top Secret Intelligence Agency. When we tried throwing our contacts name around it didn’t work. They would not allow us entry. So we said, “call him on the phone and let us talk to him.” So, the armed guard at the security booth called him and said, “Go inside the booth, he wants to talk to you.” So we went inside to talk to our client and he said, “looks like you lose.” We said, “but the bet was that we could compromise your security.” So he said, “but you were refused entry.” So we said, “Yes, but we weren’t refused entry into your guard booth. And right now we are reading all your memos labeled “Top Secret” and plastered on the wall about what your procedures are if someone runs the gate, which is classified information.” So he said, “he shouldn’t have those documents taped to a wall like that.” Naturally, after our “breach” they cleaned up that chink in their armor.
In a prior blog post titled “Think Like a Criminal – or a Terrorist,” we described how you can do your own “breach” without having to hire someone like us to do it for you. Just use your intimate knowledge of your building and/or business and ask yourself, “if we were a criminal trying to gain unauthorized access into this building, how would we do it?” Chances are high that the method you come up with will be the same method the criminal comes up with too. It’s not rocket science. Give it a try and see what you come up with.
