The card that opens your building, the turnstile reader, the warehouse wristband, the data centre lock. That whole layer was bought years ago, has never been audited and very often still uses technology that can be cloned in seconds with equipment costing under a hundred euros.
Why this matters more than it looks
Physical access control is the first layer under everything else. A data centre with multi-factor authentication is worth little if the door opens with a card cloned in the lift. It is also the route a Red Team takes when the digital perimeter is sound.
What we audit
Low-frequency RFID (125 kHz): legacy cards and fobs with no encryption, readable and clonable at a distance. Still installed in a great many buildings.
NFC and high frequency (13.56 MHz): MIFARE Classic, DESFire and similar. We review which keys are in use, whether they are factory defaults and how they are diversified.
Bluetooth and BLE: locks, readers, medical devices, industrial sensors and peripherals. Pairing, encryption, authentication and service exposure.
Mobile credentials: applications that open doors and how they protect the secret they carry.
Readers and controllers: communication with the central system, legacy protocols and scope for physical tampering.
How we work
1
Technology inventory
What is actually in use at each access point. It is common to find three generations coexisting because the previous one was never removed.
2
Credential analysis
Reading, content analysis and assessment of cryptographic protection, using cards you provide.
3
Cloning and impersonation testing
In a controlled environment and within an agreed scope, we demonstrate whether a credential can be duplicated and a door opened with it.
4
Infrastructure analysis
Readers, controllers and their communication with the management system.
5
Report and roadmap
What to migrate, in what order and at what cost, because replacing every access technology at once is rarely viable.
What you get
Inventory of access technologies by point and by site.
Technical report with the tests performed and their outcome, with evidence.
Risk classification by credential type and by protected zone.
Migration roadmap prioritised by zone criticality and cost.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Questions we get asked
Will you clone our employees’ cards?
Only the ones you hand us for testing, and always with written authorisation. We do not read individuals’ credentials without their knowledge unless it is part of an expressly contracted and scoped Red Team exercise.
Our system is modern. Is it worth auditing?
It is worth checking. A modern system that is badly configured — factory keys, no diversification — offers the same protection as an old one. What we audit is the deployment, not the manufacturer’s brochure.
Is this part of a Red Team?
It can be inside one or stand alone. In a Red Team with physical access in scope, this is one of the most effective entry routes.
Do you audit industrial Bluetooth devices?
Yes. Sensors, actuators and maintenance equipment with BLE are increasingly common on the plant floor and almost never fall within the scope of a conventional audit.
Does your door open with a cloned card?
Half an hour with an auditor to review which technology you have installed and scope the audit.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.

