Penetration Testing
Service description
Penetration testing, also known as "pen testing" or "ethical hacking", is an authorized, simulated cyberattack on a customer's computer system to identify vulnerabilities and assess security. It's a proactive measure used to find weaknesses that attackers could exploit, allowing organizations to strengthen their defenses. Reasons for this service include: (i) Identify computer system weaknesses: Helps uncover vulnerabilities that might be missed by automated vulnerability scans. (ii) Prioritize remediation: Helps organizations understand which vulnerabilities pose the greatest risk and should be addressed first. (iii) Improve security posture: By fixing identified vulnerabilities, organizations can reduce the risk of successful cyberattacks. (iv) Meet compliance requirements: Penetration testing is often a requirement for various compliance standards. (v) Test Incident Response: Evaluate the effectiveness of an organization's incident response plan.
Common industries
Applies to any business with online systems or customer data, especially regulated ones.
ROI
Closing gaps proactively is far cheaper than a breach — and is often expected by customers, insurers, or security frameworks such as SOC 2.
Benefit
Ethical hackers simulate real-world attacks on your systems to find and prioritize vulnerabilities before criminals do.
Why get it
A test shows what an attacker could actually reach, so fixes go to the weaknesses that matter most. Customers, insurers and some regulators ask for proof of testing.
When you benefit
Usually a scheduled engagement of days to weeks, repeated yearly or after major system changes.
What it costs
Typically a project fee.
When you pay
Providers usually quote a fixed fee per engagement, scaled to how many systems, applications or locations are tested and how deep the test goes. A retest to confirm fixes is often priced separately.
Other costs
Staff time to support the tester, the cost of fixing what is found, and any retest after fixes.
Risks to know
Testing a system without written permission can violate the Computer Fraud and Abuse Act, so scope and authorization must be in writing. Tests can also disrupt live systems. Financial institutions covered by the FTC Safeguards Rule must conduct annual penetration testing, unless they use continuous monitoring.
When risks arise
Disruption can happen during the test itself. Findings surface in the final report, and an unfixed weakness stays open until it is fixed, so the risk persists after the test ends.
The process
The provider and business agree on scope, rules and timing in writing. The provider then tests the systems, tries to exploit weaknesses and documents what it finds. The business receives a report ranking the findings by risk, with fix guidance, and the provider usually retests once fixes are made.
Your commitment
The business defines which systems are in scope and signs a written authorization naming the tester, the targets and the testing window. It should name a contact for emergencies, check whether its hosting and cloud providers require notice, and set aside time to fix findings.
Documents to gather
- Network diagram or asset list
- Past test reports or vulnerability scans
- List of applications and hosting providers
- Customer or compliance requirements that call for testing
Helpful reading
- SP 800-115, Technical Guide to Information Security Testing and Assessment — NIST
- OWASP Web Security Testing Guide — OWASP Foundation
- Penetration testing — National Cyber Security Centre (UK)
Further research
Not open yet
Penetration Testing isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.