Get AI-Powered + Human Validated Pen Testing!

Physical Red Team Rules of Engagement: The 7 Rules Every Engagement Needs

Table of Contents

By Jaysinh Dabhi, Red Team Operations Head at Bluefire Redteam. 5+ years leading physical and digital red team operations across BFSI, data centre, and critical-infrastructure environments. Connect on LinkedIn

Physical red team rules of engagement are the written agreement that defines exactly what a red team is authorised to do inside your facilities, where the boundaries sit, and how the test stops if something goes wrong – before a single door gets tested.

At Bluefire Redteam, we don’t run a single physical engagement without one. A rules-of-engagement (RoE) document is what separates a controlled security test from an actual break-in with better intentions and physical testing raises the stakes, because it simulates real crime: tailgating, badge cloning, lock bypass, and on-site network access.

Summary – The 7 rules a physical red team RoE must cover

  1. Written legal authorisation: the signed “get out of jail free” letter
  2. Defined scope & boundaries: which facilities, floors, and systems (and what’s out of bounds)
  3. Emergency stop protocol: a kill switch that halts the test instantly
  4. Evidence & data-handling limits: what’s collected, stored, and destroyed
  5. Communication & escalation chain: who to contact, and when
  6. Physical safety boundaries: force limits, hazardous areas, third parties
  7. Post-engagement disclosure terms: who sees findings, under what confidentiality

Built collaboratively with your security and legal stakeholders – never a boilerplate template.

Looking for a physical red teaming engagement?

Book a Call with Bluefire Redteam

Why Rules of Engagement Matter Before Testing Begins

A physical red team rules of engagement document exists because physical and digital intrusion testing simulates real crime – tailgating, badge cloning, lock bypass, network access – and simulation only stays legal and safe when everyone agrees on the limits in writing first.

We’ve seen what happens when this step gets rushed. During an engagement scoping call for a fintech client based in Singapore, the client initially wanted us to “just see how far you get” without a written boundary on which floors were in scope. We refused to proceed until that was formalized, because an undefined physical red team ROE leaves both the client and the tester exposed – legally, physically, and reputationally.

Rule 1: Written Legal Authorization

Every ROE must start with signed, written authorization from someone with the legal authority to grant it – not a verbal go-ahead from a facilities manager or IT lead. This document, sometimes called a “get out of jail free letter,” is what a tester carries during a physical engagement in case local security or law enforcement is called.

Without this, even a fully consensual test can be treated as an actual break-in under local law. We require this signed before any reconnaissance phase begins, referencing frameworks like the one outlined by SANS Institute’s penetration testing guidelines for how authorization scope should be documented.

Rule 2: Defined Scope and Boundaries

A strong physical red team ROE names the exact facilities, floors, systems, and departments that are in scope – and just as importantly, what’s explicitly out of scope. During a compromise assessment for a logistics client operating out of Toronto, we excluded an adjacent leased floor occupied by a third-party tenant, because that space wasn’t the client’s to authorize testing on.

Scope boundaries also cover time windows (business hours only, or 24/7), which employees are aware of the test (usually only 1-2 executive sponsors), and whether digital lateral movement is included once physical access is achieved.

Rule 3: Emergency Stop Protocol

The agreement needs a kill switch – a pre-agreed phrase, contact, or signal that immediately halts the engagement if a real safety issue arises, such as an actual medical emergency or a genuine security response that escalates beyond the test’s intent.

This protocol protects everyone: the tester, the client’s staff, and any third party who might be affected. We treat this rule as non-negotiable, since a physical test without a clear stop condition is a liability, not a security exercise.

Rule 4: Evidence and Data Handling Limits

The rules of engagement must specify exactly what evidence a red team can collect – photographs, badge logs, physical artifacts – and how that evidence is stored, encrypted, and eventually destroyed after the engagement report is delivered.

For clients in regulated industries, this section typically maps directly to compliance frameworks like ISO/IEC 27001 Annex A physical security controls, since evidence handling during a test needs to meet the same data protection bar the client is being audited against.

Rule 5: Communication and Escalation Chain

A physical red team ROE document names specific points of contact on both sides, along with defined escalation steps if the test needs to pause, adjust scope, or address an unexpected discovery mid-engagement – such as finding an active, unrelated security incident already underway.

We’ve encountered this once: during a badge access review, we found evidence an ex-employee’s credentials were still active and had been used recently. The rules of engagement we’d agreed on told us exactly who to notify immediately, without needing to pause and figure out the right escalation path mid-test.

Rule 6: Physical Safety Boundaries

Physical testing carries real-world risk that digital testing doesn’t – lock bypass, forced entry simulation, or navigating unfamiliar facilities. A proper physical red team ROE sets explicit limits on force (no destructive entry unless separately authorized), off-limits hazardous areas, and protocols if a tester encounters unrelated third parties like cleaning staff or security guards during the test.

Rule 7: Post-Engagement Disclosure Terms

Finally, the rules of engagement define how findings get disclosed – to whom, in what format, and under what confidentiality terms. This typically includes non-disclosure obligations covering vulnerabilities discovered, since a physical security gap report is sensitive material that shouldn’t circulate beyond the agreed stakeholder list.

How We Builds Rules of Engagement Into Every Physical Test

Every physical red team engagement we run at BFRT starts with a ROE document built collaboratively with the client’s security and legal stakeholders – not a boilerplate template. This process typically takes 3-5 business days before testing begins, and it’s non-negotiable regardless of how urgent the client’s timeline feels.

This is also where our blended physical-and-digital methodology matters: our rules of engagement explicitly define whether physical access authorization extends into digital lateral movement, which we mapped out in detail in our breakdown of the physical red team kill chain. If your engagement includes badge cloning as an infiltration vector, it’s worth reviewing our dedicated guide on RFID badge cloning attacks to understand exactly what that authorization needs to cover.

For a broader look at industry-standard methodology references, ASIS International’s physical security guidelines are a useful benchmark we cross-check our own rules of engagement templates against.

Understanding red team rules of engagement isn’t just a legal formality – it’s the foundation that makes every other stage of a physical red team engagement safe, defensible, and useful to your organization. If your team is planning a physical or blended red team assessment and needs a rules of engagement framework built around your specific facilities and risk profile, our physical red team engagements are built on exactly this framework — we can walk you through how we structure ours around your facilities.”

FAQ: 7 Essential Documents for a Secure Physical Red Team

  • It's a written agreement defining the legal authorization, scope, boundaries, and safety protocols for a physical red team engagement before testing begins.
  • Someone with legal authority over the tested facility or systems - typically a CISO, facilities director, or legal counsel, not just an IT manager.
  • Yes, but only through the pre-agreed escalation and communication process defined in the original document, never informally.
  • Yes - for blended physical and digital engagements, the rules of engagement must explicitly state whether physical access authorization extends into network or system access.
  • Physical RoE adds real-world safety boundaries a digital test doesn't need — force limits, off-limits hazardous areas, a "get out of jail free" authorisation letter to carry on site, and protocols for encountering third parties like security guards or cleaning staff.

Get started Instantly!

Get started in no time!

Before You Leave...

What are you looking?

Trusted by customers in 7+ countries!