Posted 24 May 2021 - 06:27 PM
In the past we were contracted to run breach exercises and unfortunately most of the clients failed the exercise but most certainly learned from them.
I would go outside your company locations and get a friend to see how far they can penetrate without being stopped and most certainly forensic record everything.
I actually got into a food manufacturer in Los Angeles by not even showing an ID at the "highly" secure gate by simply saving I was with the FDA and then entered thru a dock door with a lab coat on and can of soda in my pocket and a clipboard in my hand.
While a couple of people said hello only one asked me who I was, I said FDA and he said have at it.
I ended up sitting in the presidents office after breaching production, the lab, maintenance, general offices and was even able to sit my head in the security office to ask where the exwcutive bathroom was.
All without anyone asking for an ID.
Best if you give the person free reign as to when they are going to run an attempt and also a get out of jail letter.
All the Best,
All Rights Reserved,
Without Prejudice,
Glenn Oster.
Glenn Oster Consulting, LLC
Consultants for SQF, ISO-certified payment systems, Non-GMO, BRC, IFS, Lodging, F&B
http://www.GlennOster.com -- 774.563.6161