Almost everything an organisation does today runs over the internet. Customer data, email, invoicing, collaboration with suppliers: it all sits in systems that are permanently reachable. That is convenient, but it also means a malicious hacker can reach it over that same internet. Cyberattacks are a daily reality and no company seems self-evidently safe anymore.
The good news is that you can get ahead of this. A pentest (short for penetration test) maps the weak spots in your security before an attacker finds them. You get concrete advice with it, so you can fix those vulnerabilities at a moment you choose yourself.
On this page we tell you everything about the penetration test: what it is, which forms exist, how such an investigation works and roughly what costs you can expect.
A penetration test is an investigation in which an ethical hacker identifies weak spots in the security of computer systems, networks or applications. Pentesting is also called ethical hacking or white hat hacking. The pentester steps into the role of an attacker and uses the same tools and techniques as a real cybercriminal.
The difference lies in the intent and the agreements. A malicious hacker attacks systems for personal gain or to cause damage. An ethical hacker always works with written permission from the organisation and within a predefined scope. They stop as soon as they have demonstrated a vulnerability, document it in a report and give advice for improvement. Without that permission, the same work would be a criminal computer intrusion.
A pentest does not have to be limited to a single system. It can concern a single web application, but equally the complete IT infrastructure: firewalls, network equipment, Active Directory, cloud environments and your employees’ workstations.
A pentest is different from a vulnerability scan. A vulnerability scan is a largely automated check that looks for known vulnerabilities, and thus a good means of continuously keeping an eye on the gaps. A pentest goes further: a human actually tries to break in and can find complex attack chains that an automated scan misses. The two complement each other.
Pentests come in different forms. The amount of information you share in advance determines the pentester’s approach and how realistic the test is. During the intake conversation we choose together the variant that fits your question. There are three main forms based on the information you share, and in addition the timeboxed pentest, where the available time is the deciding factor.
In a black box pentest the pentester gets little to no information about the test object, often only a domain name or an IP address. They take on the role of an uninformed attacker from outside and follow the same paths a real hacker would.
This is the most realistic scenario for an attack from the internet and it shows what is publicly visible and reachable. The downside is that it is less thorough than the other forms. The pentester does not know your functionality and cannot be certain whether all important components have been covered. It also takes more time, because a lot of reconnaissance is needed. This form suits organisations that want to know how far an outsider gets.
In a grey box pentest the pentester has partial knowledge of the system. They receive, for example, the login details of an ordinary user or a rough network diagram.
This is the most chosen variant, because it offers a good balance between realism and efficiency. The pentester wastes no time on basic reconnaissance and can focus on the most important risk areas. The test shows what is possible when an attacker has access to a user account, for instance after an employee fell for a phishing email. The picture of your security level is therefore more complete than with a black box test.
In a white box pentest, also called crystal box, you share all available information: access to the source code, infrastructure documentation, admin accounts and the network topology.
This yields the most thorough assessment. Because the pentester can reach everything, they also find complex logical flaws and design weaknesses that remain invisible from the outside. It is therefore a logical choice when you want a source code review or need to comply with a standard such as ISO 27001 or PCI DSS. The test is less realistic for an external attacker and, due to the deeper analysis, usually somewhat more expensive.
In a timeboxed pentest the pentester tests as much as possible within a predetermined number of days. The emphasis is on the most critical systems and the most obvious vulnerabilities. It is a good and affordable way to quickly get a first impression of your security, for example on a limited budget or as a stepping stone to a more extensive investigation.
The difference with the other forms lies not in the amount of information shared, but in the available time. Because the test is bound to a fixed size, there is no guarantee that the entire environment is covered. For compliance purposes such as PCI DSS or ISO 27001, a full pentest with a defined scope is therefore required.
A professional pentest follows a fixed, structured approach. We work according to recognised methodologies such as those of OWASP and the Penetration Testing Execution Standard. An investigation usually consists of the following steps.
A pentest remains a snapshot in time. The investigation shows how resilient your systems were at the moment of testing. If something changes in your infrastructure or applications, the picture can shift. That is why we advise repeating a pentest periodically.
A pentest can be carried out on almost any system or network where security plays a role. Which components we investigate exactly, we determine together in the intake conversation. These are the most common types.
Which components are useful for you depends on your situation. Your security is only as strong as the weakest link, so there is little point in exhaustively testing one well-secured system while another component stays out of view. The pentester is happy to advise you on a suitable scope.
The cost of a pentest strongly depends on the scope and complexity of what you have tested. A small web application takes less time than an extensive enterprise environment. As a guideline:
If you have a limited budget, a timeboxed pentest is an option. The pentester then tests as much as possible within an agreed number of days, with the emphasis on the most critical systems and the most obvious vulnerabilities. It is a good way to quickly get a first impression, but there is no guarantee that the entire environment is covered. For compliance purposes, such as PCI DSS or ISO 27001, a full pentest with a defined scope is required.
We only name a precise amount after the intake conversation, when the scope is clear. That way you pay for what you actually need.
The costs of a successful cyberattack are considerable. Besides direct recovery and possible downtime, you may face reputational damage, loss of customers and fines when personal data ends up on the street. Set against those amounts, a pentest is a manageable expense. You would rather know in advance where your weak spots are than have an attacker point them out.
A pentest also gives you certainty about investments you have already made. Do that new firewall, the EDR solution or the awareness training really work as you hope? A realistic test shows it. In addition, various standards and laws require periodic pentests, including ISO 27001, PCI DSS, NIS2 and NEN 7510 for healthcare.
The general recommendation is to pentest at least annually, and more often after major changes, after a security incident or for systems that are extra critical.
We are happy to think along about the right scope, the type of pentest and the approach that fits your organisation. Request a no-obligation conversation.
Get in touchOr email us directly at [email protected]