What is a penetration test?
A penetration test is a controlled security assessment in which specialists carry out realistic attack techniques within an agreed scope. The test establishes which vulnerabilities can actually be exploited and which attack paths follow from them. A penetration test shows what is exploitable at the time of testing.
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan uses automated tooling to identify known vulnerabilities and configuration weaknesses. A penetration test adds manual analysis, exploitation and attack-path validation. It determines whether a weakness can be used in practice, how separate findings can be chained and what level of access or impact an attacker could achieve.
When does an organisation need a penetration test?
A penetration test is appropriate when new systems go live, after a significant change to the environment and when clients, insurers or supply chain partners require one. Obligations arising from NIS2, DORA, ISO 27001 and BIO2 also lead to periodic technical testing. A penetration test provides independent technical evidence, but does not demonstrate compliance by itself.
How often should a penetration test be carried out?
For most organisations an annual penetration test is the starting point, supplemented by a test after every significant change. New applications, migrations to cloud or identity platforms, changes to network segmentation and acquisitions alter the attack surface immediately. A fixed interval alone is therefore insufficient, because risk moves with the environment.
Which systems can be included in a penetration test?
The scope can include web applications, APIs, mobile applications, external infrastructure, internal networks, Active Directory, Microsoft Entra ID, cloud environments, wireless networks, endpoints and OT environments. Combined scopes can be used to examine attack paths across applications, identities, infrastructure and network boundaries.
What is the difference between black box, grey box and white box testing?
A black box test starts without credentials or internal documentation. A grey box test uses limited access or technical context to test authenticated functionality and internal attack paths in greater depth. A white box test includes extensive information such as source code, architecture and configurations. Grey box testing provides the strongest balance between realistic attacker behaviour and technical coverage for most assessments.
Can a penetration test be performed safely in production?
Yes, provided that the scope, rules of engagement, stop conditions and escalation procedures are defined in advance. Techniques that could affect availability are restricted or coordinated separately. OT, healthcare and other safety-critical environments require additional controls and may rely on passive analysis or carefully selected active tests.
How long does a penetration test take?
Duration depends on the size, complexity and required depth of the scope. A limited application or infrastructure assessment may require one or a few test days. Complex environments with multiple roles, networks, cloud platforms or OT systems may require several days up to one or more weeks. The required effort is established during technical scoping during the intake call.
What does a penetration test report contain?
The report contains the agreed scope, methodology, validated findings, affected assets, technical evidence, attack paths, impact analysis and remediation guidance. Findings are scored using CVSS and interpreted within the operational context of the environment. Critical findings are communicated during the test rather than held until final reporting.