Pillar 03 ยท Monitor

Penetration Testing

A penetration test is an authorised attempt to break into your systems, carried out by people whose job is to think the way an attacker does.

It answers a different question from the rest of our work. An audit tells you what is wrong. Monitoring tells you when something is happening. A penetration test tells you whether someone who tried would be able to get in, and how far they would get once they had.

Scoping
Built around what you need. We do not sell it as a package.
Authorisation
Agreed in writing before anything starts
Window
Agreed, with a named contact on both sides throughout
Excluded by default
Denial-of-service techniques
Reporting
Ranked by exploitability and business impact
Retesting
Available on request once findings are addressed

What Penetration Testing Involves

Five usual areas

External infrastructure

Everything of yours that faces the internet: firewalls, VPN endpoints, mail servers, and remote access. These points act as the front door, and are the first thing a real attacker looks at.

Internal network

What someone could reach by gaining a foothold, whether through a phished account or a visitor's laptop on your network. This is where segmentation either holds or fails.

Web applications

Your customer portal, booking system or anything else you have had custom built. Authentication, access controls, input handling, and whether one customer can see another's data are all tested.

Wireless

Guest network separation, weak encryption, and the access point somebody set up in a back office three years ago.

Social engineering

Phishing, pretexting phone calls and physical access attempts, tested only with clear authorisation and an agreed scope, because this one involves your staff.

Everything, authorised

Agreed and authorised in writing before it starts, including the testing window, the systems in scope and who to call if something breaks.

When You Need One

Five triggers, and one honest exception
  • Before a Cyber Essentials Plus assessment, so problems surface while they are still cheap to fix rather than during the audit.
  • Annually, as assurance for a board, a regulator or an insurer.
  • After a significant change, such as a new application, a cloud migration, an office move, or a merger.
  • Because a client asked. Security questionnaires increasingly ask for evidence of recent testing, and "we have never had one" is a poor answer on a tender.
  • After an incident, to confirm the hole is closed and that nothing else was left open.

If none of those apply and you have never had an audit, start with the audit instead. Testing an environment nobody has assessed tends to produce a long report confirming things you could have found out about more cheaply.

Penetration Testing and Vulnerability Scanning

Used interchangeably, but different things

A vulnerability scan is automated. It compares your systems against a database of known issues and produces a list of missing patches, unsupported software, exposed services, and weak configurations. It is cheap enough to run monthly, and it should be, because it catches the problems that cause most real-world compromises. It is included in our monitoring service.

A penetration test is performed by a person. Where a scanner finds known issues one at a time, a tester chains three minor weaknesses into a serious one, such as an information leak that reveals a username, a weak password policy, and an internal service that trusts anyone on the network. This chaining is what an actual attack looks like, and no scanner does it.

Use both. Scanning for continuous hygiene, testing periodically for depth.

Will It Break Anything?

The usual first question, and a fair one

Testing is deliberately conservative by default. We agree upon a window, agree what is out of scope, and keep a named contact on both sides that is reachable throughout. Denial-of-service techniques are excluded unless you specifically ask for them and accept the risk in writing. Anything with a realistic chance of affecting a live service gets flagged to you before it happens, not after.

Most tests run without anyone in the business noticing. The exceptions tend to be older systems that fall over when something unexpected talks to them, which is itself a finding worth having, and better discovered on a Tuesday afternoon with your team on standby.

Reporting and Remediation

Something you can work from

The output of a test should be something you can work from, not a tool export with a cover page. Findings are ranked by exploitability and business impact rather than by a generic severity score, because a critical-rated issue on a system nobody can reach matters less than a medium-rated one on your customer database. Each finding includes what was done, what it exposed, and specific remediation steps.

You get a technical report for whoever fixes things, and a short summary for whoever needs to understand the results. This is the same two-audience approach we take with audits. We will retest the findings once they are addressed if you would like, so you have evidence the gaps are closed and not simply ticked off.

Common questions

Five questions
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan is automated. It compares your systems against a database of known issues and produces a list of missing patches, unsupported software, exposed services and weak configurations. A penetration test is performed by a person, who chains three minor weaknesses into a serious one. Use both: scanning for continuous hygiene, testing periodically for depth.
How often should we have a penetration test?
Annually is the usual rhythm as assurance for a board, a regulator or an insurer, plus after any significant change such as a new application, a cloud migration, an office move or a merger. Before a Cyber Essentials Plus assessment is also a sensible time, so problems surface while they are still cheap to fix.
Will testing disrupt our systems?
Testing is deliberately conservative by default. We agree a window, agree what is out of scope, and keep a named contact on both sides reachable throughout. Denial-of-service techniques are excluded unless you specifically ask for them and accept the risk in writing. Most tests run without anyone in the business noticing.
Do you retest after we have fixed things?
Retesting after remediation is available on request, so you have evidence the gaps are closed and not simply ticked off.
How much does a penetration test cost?
Testing is scoped to what you need rather than sold as a package, then quoted as a fixed price agreed in writing before work starts. Tell us what is prompting the test and we will tell you what scope would answer it.
Talk to us

Tell us what is prompting the test

Whether that is a certification deadline, a client requirement or a board asking for assurance, we will tell you what scope would answer it.