Penetration testing (also called a pentest or ethical hacking) is an authorised, simulated attack on your systems by security professionals, carried out to find and prove exploitable weaknesses before real attackers do. Unlike an automated scan, a penetration test shows what an attacker could actually achieve — such as reading other customers' data, taking over admin accounts or moving from a laptop to your domain controller.
Why organisations run penetration tests
- Find real, exploitable risk — including logic flaws scanners can't detect.
- Meet compliance requirements — PCI DSS, SOC 2, ISO 27001, HIPAA and many regulators expect regular testing. See compliance requirements.
- Win enterprise deals — customers' security questionnaires routinely ask for a recent third-party pentest report or attestation.
- Validate security investments — check that your WAF, EDR and monitoring actually detect and stop attacks.
- Before major releases — test new products and significant changes before attackers do.
Black box, grey box and white box
| Approach | What testers get | Best for |
|---|---|---|
| Black box | Nothing beyond a target (URL, IP range) | Simulating an outside attacker; external perimeter |
| Grey box | User accounts, some documentation | Most web/API tests — best depth per budget |
| White box | Source code, architecture, admin access | High-assurance applications, crypto, critical logic |
Main types of penetration testing
Web application
Authentication, access control, injection, business logic and client-side issues. Our service.
API
REST, GraphQL and gRPC endpoints — authorization (BOLA), mass assignment, rate limits.
Mobile
iOS/Android apps, local storage, certificate pinning, and the APIs behind them.
Network (external / internal)
Exposed services, patching, segmentation and Active Directory attack paths.
Cloud
IAM escalation, storage exposure, Kubernetes and serverless. Our service.
Wireless
Wi-Fi encryption, rogue access points, guest network isolation.
Social engineering
Phishing, vishing and physical intrusion to test people and process.
Red teaming
Objective-based, stealthy, multi-week adversary simulation testing detection and response.
The phases of a penetration test
- Scoping & rules of engagementAgree targets, exclusions, test windows, contacts and legal authorisation.
- ReconnaissanceMap the attack surface: subdomains, endpoints, technologies, users and exposed services.
- Vulnerability discoveryCombine automated tools with manual analysis to identify weaknesses.
- ExploitationSafely prove impact — access data, escalate privileges, chain issues together.
- Post-exploitationAssess lateral movement, persistence and business impact within agreed limits.
- Reporting & debriefExecutive summary, risk-rated findings, reproducible evidence and remediation guidance.
- RetestVerify fixes and issue an updated report or attestation.
Standards and methodologies
Reputable penetration testing companies align their work with recognised frameworks:
- OWASP Web Security Testing Guide (WSTG) and OWASP Top 10 / API Security Top 10 for applications
- OWASP MASVS / MASTG for mobile applications
- PTES (Penetration Testing Execution Standard) for overall engagement structure
- NIST SP 800-115, the technical guide to information security testing and assessment
- OSSTMM for operational security testing
- MITRE ATT&CK for mapping red team techniques to real adversary behaviour
How often should you pentest?
At minimum annually and after significant changes — a new product, major feature, infrastructure migration or acquisition. Fast-moving SaaS teams increasingly add lighter, continuous testing between annual deep-dives.
What you receive at the end
A professional engagement delivers a written report with an executive summary, technical findings rated by risk, proof-of-concept evidence, remediation advice, a debrief call and, after retesting, an attestation letter you can share with customers or auditors.
Next: learn how to choose a pentest company or see what a pentest costs.