●  Credential & access control assessment

Your perimeter ends at a reader anyone can clone.

We test the badges, readers and records that decide who gets into your offices and data centers. Then we tell you what to replace them with, and put a price range on every finding.

Twenty minutes. No obligation.

Sample findingFormat, not a client
F-014Critical

Site badges readable and writable with off-the-shelf hardware

The credentials in use at rely on a technology with no mutual authentication between card and reader. A working duplicate was produced from a badge presented in the lobby, in under two minutes, with a handheld tool that costs a few hundred dollars.

RemediationMigrate to DESFire EV3 or SEOS
Cost bandBudget
StandardISO/IEC 27001 A.7
The problem

The gap between the SOC and the door.

A visitor presenting a credential at a lobby speedgate while a second person passes through behind her.
Fig. 01Controlled lobby entry — one credential, two people through

Your identity provider is hardened and your SOC is watching. Then a card technology from the 1990s opens the data hall, and a badge revoked in the IdP still works at the reader.

The cyber team stops at the IdP. The integrator starts at the panel it sold you. We assess what falls between them.

The assessment

Six areas. One fixed fee. One report.

Credentials

What your cards and readers actually are, and how easily they clone.

Deprovisioning

Whether a badge dies when the person leaves.

Escort & contractor

Who walks in with whom, and whether the record survives.

Tailgating & anti-passback

Mantraps, turnstiles, the loading dock, the propped door.

Cage & cabinet

Separation inside shared and colocation space, down to the rack.

Chain of custody

Media from the rack to the shredder.

On site in daylight and after dark, plus a review of your access recordsday & night
Every finding prioritized, with a price range and the technology to move tonamed
A fixed fee, agreed in writing before we startquoted up front
How it works

Three steps. The first one is free.

Step 01

Scoping callFree

Twenty minutes, free. If an assessment isn’t worth the money, we’ll say so.

Step 02

Assessment

On site, day and night. Where authorized in writing, we test the controls instead of describing them.

Step 03

Report and re-test

Findings your team can work from, then a re-test once the fixes are in.

Why Calibre
Physical security only.Not a line bolted onto a cyber practice.
Paid by you, and only by you.No referral fee or commission on anything we recommend.
Founder-led.MS in Cybersecurity from NYU, and enterprise security audit at Goldman Sachs.

Findings mapped to ISO/IEC 27001 A.7 · SOC 2 CC6.4 · ASIS · NPSA · TIA-942

Contact

Tell us about your sites.

Twenty minutes is enough to know whether an assessment is worth it. We’ll be honest either way.