Episode 142: Learning Covert Entry with Brian Harris

Layer 8 Podcast52mApril 20, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Episode 142: Learning Covert Entry with Brian Harris” inside PodZeus.

AI-Generated Summary

In Episode 142 of the Layer 8 Podcast, host dives deep into the world of covert physical penetration testing with Brian Harris, a seasoned expert with over 20 years of experience in both cyber and physical offensive operations. Harris shares insights from his flagship course, the Covert Access Team (CAT) program, which simulates real-world building intrusions through hands-on training in badge cloning, lockpicking, social engineering, drone reconnaissance, and team-based missions. He emphasizes that physical security is foundational—without it, cybersecurity is meaningless—and argues that the most effective assessments go beyond a single breach to uncover systemic vulnerabilities. Harris stresses the importance of tailoring tests to client needs, whether for budget justification, compliance, or due diligence, and warns against the 'James Bond' mindset of stealthy one-off breaches. Instead, he advocates for thorough audits, ethical data collection, and constant communication with clients. He also highlights the psychological aspect of security: attackers often succeed not through force, but through trust—like the 'box of donuts' social engineering tactic. The episode concludes with a call to action: develop one core skill, master the 'escape clause' of social engineering, and always prioritize the client’s long-term security over a flashy one-time win.

Key Takeaways
1

Physical security is the foundation of all security—no cyber defense matters if an attacker can walk into the building.

2

The most effective physical pen tests go beyond a single breach to uncover systemic weaknesses through comprehensive audits.

3

Social engineering is the most critical skill—never underestimate the power of a friendly smile and a box of donuts.

4

Always communicate with the client during an engagement; unexpected elements like robots or unsecured access cards can derail plans.

5

Most surveillance systems only record for 2–5 days, meaning a breach may leave no trace—making stealth more effective than force.

…and 3 more takeaways available in PodZeus

Chapters
0:00
10 min

Introduction to Brian Harris and the CAT Course

You're going to be cloning badges. You're going to be creating badges. You're going to be picking locks. You're going to be wearing disguises. You're going to be working with drones. You're going to be doing reconnaissance. You're going to be doing social engineering. Like everything that you might do to break into buildings, you're going to be doing it.

Highlight
10:00
10 min

The Psychology of Physical Penetration Testing

You have to realize that most people, it's not their job to be security. And it's really easy. And you know, it's really easy to bamboozle people. You know, confidence, one or two props, you know, that's usually it.

Highlight
20:00
10 min

Beyond the One-Time Breach: The Value of Audits

If you run a pen test, like when you social engineer your way into a building, you may and likely won't find out that, oh, well, by the way, when an employee is fired or they quit their job, we don't actually deactivate their access cards.

Highlight
30:00
10 min

The Legal and Ethical Boundaries of Data Collection

Harris outlines the legal risks of recording audio or video inside buildings, especially under laws like GDPR in Europe. He warns that even if you’re inside a building, recording employees without consent—even if it’s for a report—can lead to serious legal consequences. He recommends using remote PIR sensors for motion detection instead of visual or audio recording.

40:00
10 min

The Real Threat: Insider and Long-Term Infiltration

It's literally that simple. Right? It's what I jokingly refer to as the trusted method of infiltration.

Highlight
High-Impact Quotes
The one skill that is non-negotiable for any infiltration team is an escape clause. And that's social engineering, right? The ability... to talk your way out of any problem.
Brian Harris50:53
Viral: 92.0
You're going to be cloning badges. You're going to be creating badges. You're going to be picking locks. You're going to be wearing disguises. You're going to be working with drones. You're going to be doing reconnaissance. You're going to be doing social engineering. Like everything that you might do to break into buildings, you're going to be doing it.
Brian Harris1:43
Viral: 90.0
It's literally that simple. Right? It's what I jokingly refer to as the trusted method of infiltration.
Brian Harris35:12
Viral: 88.0
Speakers

Host

Host

Guest

Brian Harris
Topics Discussed
covert physical penetration testing95%social engineering tactics90%physical security audits88%insider threats and long-term infiltration87%legal and ethical boundaries in security testing85%client motivation and engagement strategy82%surveillance limitations and data retention80%skill development in security operations78%
People & Brands

Brian Harris

person

12xPositive

Covert Access Team

organization

8xPositive

GDPR

other

4xNegative

HIPAA

other

3xNeutral

DGI Mini Drone

product

2xNeutral

offshore substation

other

2xPositive

Compass CyberGuard

organization

2xNeutral

Layer 8 Conference

organization

2xPositive

F-22 Raptor

product

2xNeutral

White House

other

2xNeutral

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Episode 142: Learning Covert Entry with Brian Harris” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime