Contact
Illuminated keyboard representing penetration testing

Library

Penetration testing for businesses

Share via

In brief

A penetration test shows whether security measures work in practice. Not based on assumptions, policy or a scan report, but by safely and deliberately testing what an attacker could actually achieve.

For businesses, a penetration test is especially valuable when something changes in the environment, when customers or auditors ask for evidence, or when the organisation wants to know whether existing controls provide sufficient protection against realistic attack paths.

What is penetration testing for businesses?

A penetration test is a controlled attack against a defined part of the digital environment. The test is performed by ethical hackers who try to identify vulnerabilities, combine them and, where possible, safely demonstrate their impact. This shifts the question from what could theoretically go wrong to what is actually exploitable in practice.

For businesses, the scope may include web applications, APIs, external infrastructure, internal networks, cloud environments, Microsoft 365, mobile applications, Wi-Fi or OT. The right scope depends on the attack surface, the business processes and the risks the organisation wants to validate.

Why is a penetration test different from a vulnerability scan?

A vulnerability scan identifies known vulnerabilities, missing updates and common configuration issues. That is useful, but limited. A scan usually does not assess whether multiple weaknesses together lead to a working attack path.

A good penetration test looks at context and connection. A weak configuration, excessive permission, test environment or forgotten integration may seem limited on its own. In combination with other findings, it can still lead to access to sensitive data, administrative privileges or disruption of a critical process.

That is why human expertise remains important. Tooling helps map the attack surface and identify low-hanging fruit. Assessing business logic, authorisation, segmentation, identity, logging and real impact requires senior specialists who understand how systems function together.

When does a business need a penetration test?

A penetration test is useful when an organisation wants confidence that its security measures work. This applies after the delivery of a new application, after a migration to cloud or Microsoft 365, after a network change, when suppliers are connected, or when growth has made an environment more complex.

Commercial and organisational reasons also play a role. Customers, auditors, insurers and regulators increasingly ask for demonstrable technical validation. A penetration test helps show not only that controls have been implemented, but also that they are effective under realistic conditions.

For mature organisations, a penetration test is not a one-off check. The environment continuously changes through new systems, updates, permissions, integrations and users. Periodic technical validation prevents the risk picture from slowly becoming outdated.

Which attack surfaces are relevant?

The relevant attack surface differs per business. A SaaS provider will often start with web applications, APIs and cloud configuration. An organisation with many employees and locations will more likely look at internal networks, Active Directory, Entra ID, Wi-Fi and management interfaces. In production and industrial environments, the separation between IT and OT is also important.

The most important question is not which type of penetration test is common, but which attack path is most relevant to the organisation. A black-box penetration test can show which systems are reachable from the internet. An internal test shows what happens when an attacker, employee or supplier is already present inside the network. A cloud or identity test makes clear whether permissions, policies and integrations are configured correctly.

A suitable scope therefore reflects the actual risks. It should not be too narrow, because important relationships may remain out of sight. It should not be too broad either, because the test may become superficial and lack depth on the areas that matter most. The relevant angle also differs by sector, for example in IT and technology, the financial sector, healthcare or energy and critical infrastructure.

What determines the quality of a penetration test?

The quality of a penetration test is not determined by the number of pages in the report or the number of tools used. Quality lies in the depth of the assessment, the experience of the testers, the way findings are validated and the translation to risk and remediation priority.

A good penetration test distinguishes between individual vulnerabilities and attack paths. The tester considers how an attacker would move further, which permissions are needed, which data is reachable and which security layers do or do not respond. That gives management and technical teams a usable view of actual resilience.

Independence and demonstrable quality are important. Certification, peer review, clear scope definition, safe test agreements and a retest ensure that the outcome is reliable and that remediation is actually verified.

Black box, grey box or white box?

The amount of prior knowledge partly determines the nature of the penetration test. In a black-box penetration test, the tester receives little or no information upfront. This resembles the perspective of an external attacker and is suitable for assessing the public attack surface, OSINT and initial access paths.

In a grey-box penetration test, the tester receives limited information such as accounts, documentation or scope details. This often provides more depth, because less time is spent on prerequisites and more time is available for substantive analysis. For web applications, APIs and internal networks, this is often the most efficient form.

In a white-box penetration test, the tester receives extensive access to documentation, configurations, source code or architecture. This is particularly valuable when the organisation seeks specific assurance around authorisation, cryptography, segmentation, cloud configuration or complex business logic.

Is a penetration test mandatory?

Not every business has a general legal obligation to perform penetration testing. Under the Dutch Cybersecurity Act, the focus is on the duty of care: organisations that fall within the scope of the law must manage risks to their network and information systems with appropriate technical, operational and organisational measures. A penetration test can help demonstrate that those measures work in practice.

Outside the Dutch Cybersecurity Act, customers, auditors, insurers, sector rules or standards may also ask for technical validation. Examples include ISO 27001, NEN 7510 or, for financial institutions, DORA. In those cases, a penetration test is particularly valuable as independent evidence of actual resilience. For translating these requirements into governance and demonstrable control, compliance and governance may also be relevant.

What does a penetration test deliver?

A penetration test provides insight into vulnerabilities that are actually exploitable. The report describes what was found, how this was demonstrated, what the impact is and which measures are needed to reduce the risk. This creates a concrete remediation agenda for technical teams and a clear risk picture for management.

The value is not only in finding vulnerabilities. A penetration test also shows which security measures work well. Examples include segmentation, logging, endpoint protection, access management and hardening. That combination helps organisations direct investments more effectively.

A retest completes the cycle. After remediation, the findings are checked again to determine whether the vulnerabilities have truly been resolved and whether any residual impact remains. This prevents findings from being closed administratively while the technical risk still exists.

How does DeepBlue approach penetration testing?

DeepBlue performs penetration tests with senior specialists and a strongly manual approach. Automated tooling is used where it adds value, for example for inventory, recognition of known vulnerabilities and checks for common configuration issues. The core of the assessment remains manual.

Every penetration test starts with a clear scope and practical testing agreements. We then map the attack surface, investigate vulnerabilities and assess whether they can be safely exploited. Findings are assessed based on technical impact, business risk and remediation priority.

Before finalising the engagement, we discuss the key findings with the organisation so there is no uncertainty about context, impact or remediation direction. The final report contains a management summary and technical details with evidence, risk assessment and concrete recommendations. After remediation, we perform a retest to verify that the measures work.

How does a business prevent a penetration test from becoming a checkbox exercise?

A penetration test becomes valuable when the scope is linked to real business risks. Do not test only because a standard requires it. Determine which scenario would be most harmful, such as access to customer data, disruption of services, abuse of administrative privileges or movement towards critical systems.

The organisation must also be ready to work with the results. A report has limited value if ownership, priority and remediation capacity are missing. The right technical and responsible teams should therefore be involved upfront, with clear agreements on follow-up.

Finally, a penetration test should fit within a broader cycle of risk management. Vulnerability management, configuration management, logging, detection, incident response and periodic validation reinforce one another. A penetration test then becomes a technical reality check within the security programme, rather than a separate control point.

Frequently asked questions

How often should a business perform a penetration test?

That depends on the risk profile, how quickly the environment changes and external requirements from customers, auditors or regulators. Many organisations test annually or after major changes. Critical applications and environments often require more frequent or more targeted testing.

Can a penetration test disrupt production?

A penetration test is agreed in advance to prevent unnecessary disruption. Testers make clear agreements on scope, time windows, contacts and excluded activities. Where needed, higher-risk actions are discussed before they are performed.

What is the difference between a penetration test and red teaming?

A penetration test examines a defined scope and focuses on finding, validating and reporting vulnerabilities. Red teaming is broader and often tests detection, response and decision-making against a realistic attack scenario.

What does a business need to provide for a penetration test?

That depends on the test type. Typical input includes scope details, test accounts, IP ranges, architecture information, contact persons and any test limitations. In a black-box penetration test, prior knowledge is deliberately limited. In grey-box and white-box tests, more information is shared to enable deeper testing.

Conclusion

A penetration test gives businesses concrete insight into their digital resilience. Not as an abstract maturity model, but as a practical assessment of what an attacker can actually achieve. That makes the outcome useful for remediation, prioritisation and accountability.

The most value is created when the penetration test reflects the most relevant attack paths, is performed by experienced specialists and is followed up with remediation and retesting. In this way, technical validation becomes a fixed part of risk management rather than a one-off checkbox.

Want to know which penetration test fits your organisation? View our page on penetration testing by DeepBlue or contact the specialists at DeepBlue Security & Intelligence via info@deepbluesecurity.nl or +31 (0) 70 290 6 290.

Last content review: 23 July 2026.

← Back to library

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.