External infrastructure
Everything of yours that faces the internet: firewalls, VPN endpoints, mail servers, and remote access. These points act as the front door, and are the first thing a real attacker looks at.
Pillar 03 ยท Monitor
A penetration test is an authorised attempt to break into your systems, carried out by people whose job is to think the way an attacker does.
It answers a different question from the rest of our work. An audit tells you what is wrong. Monitoring tells you when something is happening. A penetration test tells you whether someone who tried would be able to get in, and how far they would get once they had.
Everything of yours that faces the internet: firewalls, VPN endpoints, mail servers, and remote access. These points act as the front door, and are the first thing a real attacker looks at.
What someone could reach by gaining a foothold, whether through a phished account or a visitor's laptop on your network. This is where segmentation either holds or fails.
Your customer portal, booking system or anything else you have had custom built. Authentication, access controls, input handling, and whether one customer can see another's data are all tested.
Guest network separation, weak encryption, and the access point somebody set up in a back office three years ago.
Phishing, pretexting phone calls and physical access attempts, tested only with clear authorisation and an agreed scope, because this one involves your staff.
Agreed and authorised in writing before it starts, including the testing window, the systems in scope and who to call if something breaks.
If none of those apply and you have never had an audit, start with the audit instead. Testing an environment nobody has assessed tends to produce a long report confirming things you could have found out about more cheaply.
A vulnerability scan is automated. It compares your systems against a database of known issues and produces a list of missing patches, unsupported software, exposed services, and weak configurations. It is cheap enough to run monthly, and it should be, because it catches the problems that cause most real-world compromises. It is included in our monitoring service.
A penetration test is performed by a person. Where a scanner finds known issues one at a time, a tester chains three minor weaknesses into a serious one, such as an information leak that reveals a username, a weak password policy, and an internal service that trusts anyone on the network. This chaining is what an actual attack looks like, and no scanner does it.
Use both. Scanning for continuous hygiene, testing periodically for depth.
Testing is deliberately conservative by default. We agree upon a window, agree what is out of scope, and keep a named contact on both sides that is reachable throughout. Denial-of-service techniques are excluded unless you specifically ask for them and accept the risk in writing. Anything with a realistic chance of affecting a live service gets flagged to you before it happens, not after.
Most tests run without anyone in the business noticing. The exceptions tend to be older systems that fall over when something unexpected talks to them, which is itself a finding worth having, and better discovered on a Tuesday afternoon with your team on standby.
The output of a test should be something you can work from, not a tool export with a cover page. Findings are ranked by exploitability and business impact rather than by a generic severity score, because a critical-rated issue on a system nobody can reach matters less than a medium-rated one on your customer database. Each finding includes what was done, what it exposed, and specific remediation steps.
You get a technical report for whoever fixes things, and a short summary for whoever needs to understand the results. This is the same two-audience approach we take with audits. We will retest the findings once they are addressed if you would like, so you have evidence the gaps are closed and not simply ticked off.
Whether that is a certification deadline, a client requirement or a board asking for assurance, we will tell you what scope would answer it.