Glossary
Penetration testing
Penetration testing is an authorized, controlled simulated attack on a system, application, network or facility in which vulnerabilities are actually exploited to demonstrate their real impact.
Testing is performed within an agreed scope and under written rules of engagement that set out the objectives, target systems, time window, permitted and prohibited techniques, points of contact and the procedure for unexpected events. Written authorization from the system owner is a legal precondition: the same actions without it constitute the criminal offense of attacking an information system.
A typical engagement covers reconnaissance, scanning and enumeration, exploitation, post-exploitation work — privilege escalation, lateral movement, access to data — and then reporting and retesting once fixes are in place. By the amount of information disclosed, tests are run with no prior knowledge, partial knowledge, or full access to documentation and source code; by subject, they cover external and internal networks, web and mobile applications, wireless networks, physical entry and social engineering.
A sound test follows established methodologies such as the OWASP testing guidance for applications, NIST SP 800-115, PTES or OSSTMM, and is repeatable. The main deliverable is a report that gives, for each finding, the evidence, the steps to reproduce it, a severity rating, the business impact and a concrete remediation recommendation. An executive summary translates the technical findings into organizational risk.
A penetration test is a snapshot of one scope at one point in time. It does not prove that a system has no vulnerabilities; it shows what could be achieved during the test window. It is therefore repeated periodically and after significant changes, and complemented by continuous vulnerability management.
Ready to strengthen security across your organization?
Contact us to see how our turnkey solutions can build a safer, more resilient organization.
