IT glossary

Penetration testing

A penetration test is an exercise where a security specialist is paid to break into your systems the way an attacker would, then writes up what they found.

The output is a report, and the report is the product. A good one lists each finding, explains how it was reached, rates how serious it is, and says what to do about it in enough detail that your IT team can act without a follow-up call. A weak one is a tool’s export with a logo on the cover.

A scan is not a test

This is the distinction that costs people money. A vulnerability scan is automated: software checks your systems against a list of known weaknesses and produces a list. It is cheap, it should be running regularly, and it catches the things that matter most often.

A penetration test is a person. They chain findings together, a low-severity information leak here, a default password there, an over-permissive account somewhere else, into something that a scanner, looking at each item alone, would rate as harmless. That chaining is what you are paying for, and it is why the price difference is large.

Plenty of “penetration tests” sold in the market are scans. Ask how many hours of human testing are included and who is doing them.

Why it matters to you

Two honest reasons. It finds the specific things wrong with your environment rather than the general things wrong with everyone’s. And it produces evidence: for a client questionnaire, an insurer, or a board that has started asking.

When it is premature

If you do not yet have multi-factor authentication everywhere, a current patching routine, monitored endpoints and a tested backup, a penetration test will mostly tell you that. You will pay several thousand dollars to be told the basics are missing, which you already knew.

Fix the basics first. The test is far more valuable once the obvious findings are gone, because then it starts surfacing things you could not have guessed.

What to agree before it starts

Scope, in writing, which systems, which addresses, whether staff are in scope for social engineering. Timing, so nobody mistakes it for a real incident. Whether it is external only, internal, or both. And a retest of the fixes, which is often quoted separately and is the part that turns a report into a result.

happier IT’s team includes Certified Ethical Hacker (CEH) credentials, and we will tell you when a test is not yet the right spend.

Still not sure what you actually need?

That is a normal place to start, and a 30-minute call usually settles it faster than more reading.