Glossary
Penetration test
Definition
An authorised, goal-driven simulated attack run to demonstrate what somebody could actually achieve against a system.
A penetration test is an authorised, timeboxed attempt to compromise a system the way a real attacker would. It is goal-driven. The tester works towards an objective, such as reaching a particular set of records or escalating from an ordinary account to an administrative one, chains several weaknesses together where the objective demands it, and demonstrates impact rather than merely reporting that a weakness is present. Scope, rules of engagement and written authorisation form part of the definition rather than paperwork bolted onto it.
The phrase gets attached to three different products, and the differences are commercial. A vulnerability scan is automated and finds issues that are already catalogued. A structured application security assessment reviews a system methodically against a framework and reports what it finds with reproduction steps attached. A penetration test asks how far somebody could get, and where it is bought to satisfy a contract, an insurer or a certification scheme, it normally has to come from an accredited testing body with an attestation attached to the deliverable.
We do the middle one. Our security work is an OWASP-led assessment: methodical coverage, every finding reproduced by hand, and a report written so an engineer can act on it without a follow-up meeting. We hold no accreditation, we issue no attestations, and where a requirement names a certified penetration test we will say plainly that this is not it, before anything gets signed rather than afterwards.
Questions worth asking before buying one
- What is the objective? A test with no goal degrades into a scan with somebody watching it run.
- Is the result needed for a certification or an insurance requirement? If it is, who accredits the supplier, and does the deliverable carry the attestation that requirement expects?
- What is in scope and what is explicitly out? Production systems, third-party services and anything hosted by somebody else all need permission that may not be yours to give.
- What happens after the report? A list of findings with no retest afterwards is an expensive document rather than a security improvement.
The label matters more than usual on this one, because two suppliers can use the same word for work with different methods, different deliverables and an order of magnitude between the prices.
Related
Contact
Have a project in mind?
Tell us what you are building — or what keeps breaking. You will get a considered reply from an engineer, not an autoresponder.