Hero

WE ARE

HACKIFY

What is a penetration test? Pentest explained

Icon of a penetration test

Almost everything an organisation does today runs over the internet. Customer data, email, invoicing, collaboration with suppliers: it all sits in systems that are permanently reachable. That is convenient, but it also means a malicious hacker can reach it over that same internet. Cyberattacks are a daily reality and no company seems self-evidently safe anymore.

The good news is that you can get ahead of this. A pentest (short for penetration test) maps the weak spots in your security before an attacker finds them. You get concrete advice with it, so you can fix those vulnerabilities at a moment you choose yourself.

On this page we tell you everything about the penetration test: what it is, which forms exist, how such an investigation works and roughly what costs you can expect.

What is a penetration test?

A penetration test is an investigation in which an ethical hacker identifies weak spots in the security of computer systems, networks or applications. Pentesting is also called ethical hacking or white hat hacking. The pentester steps into the role of an attacker and uses the same tools and techniques as a real cybercriminal.

The difference lies in the intent and the agreements. A malicious hacker attacks systems for personal gain or to cause damage. An ethical hacker always works with written permission from the organisation and within a predefined scope. They stop as soon as they have demonstrated a vulnerability, document it in a report and give advice for improvement. Without that permission, the same work would be a criminal computer intrusion.

A pentest does not have to be limited to a single system. It can concern a single web application, but equally the complete IT infrastructure: firewalls, network equipment, Active Directory, cloud environments and your employees’ workstations.

A pentest is different from a vulnerability scan. A vulnerability scan is a largely automated check that looks for known vulnerabilities, and thus a good means of continuously keeping an eye on the gaps. A pentest goes further: a human actually tries to break in and can find complex attack chains that an automated scan misses. The two complement each other.

Black box, grey box and white box

Pentests come in different forms. The amount of information you share in advance determines the pentester’s approach and how realistic the test is. During the intake conversation we choose together the variant that fits your question. There are three main forms based on the information you share, and in addition the timeboxed pentest, where the available time is the deciding factor.

Black box pentest

Icon of a black box pentest

In a black box pentest the pentester gets little to no information about the test object, often only a domain name or an IP address. They take on the role of an uninformed attacker from outside and follow the same paths a real hacker would.

This is the most realistic scenario for an attack from the internet and it shows what is publicly visible and reachable. The downside is that it is less thorough than the other forms. The pentester does not know your functionality and cannot be certain whether all important components have been covered. It also takes more time, because a lot of reconnaissance is needed. This form suits organisations that want to know how far an outsider gets.

Grey box pentest

Icon of a grey box pentest

In a grey box pentest the pentester has partial knowledge of the system. They receive, for example, the login details of an ordinary user or a rough network diagram.

This is the most chosen variant, because it offers a good balance between realism and efficiency. The pentester wastes no time on basic reconnaissance and can focus on the most important risk areas. The test shows what is possible when an attacker has access to a user account, for instance after an employee fell for a phishing email. The picture of your security level is therefore more complete than with a black box test.

White box pentest

Icon of a white box pentest

In a white box pentest, also called crystal box, you share all available information: access to the source code, infrastructure documentation, admin accounts and the network topology.

This yields the most thorough assessment. Because the pentester can reach everything, they also find complex logical flaws and design weaknesses that remain invisible from the outside. It is therefore a logical choice when you want a source code review or need to comply with a standard such as ISO 27001 or PCI DSS. The test is less realistic for an external attacker and, due to the deeper analysis, usually somewhat more expensive.

Timeboxed pentest

Icon of a timeboxed pentest

In a timeboxed pentest the pentester tests as much as possible within a predetermined number of days. The emphasis is on the most critical systems and the most obvious vulnerabilities. It is a good and affordable way to quickly get a first impression of your security, for example on a limited budget or as a stepping stone to a more extensive investigation.

The difference with the other forms lies not in the amount of information shared, but in the available time. Because the test is bound to a fixed size, there is no guarantee that the entire environment is covered. For compliance purposes such as PCI DSS or ISO 27001, a full pentest with a defined scope is therefore required.

How does a penetration test work?

A professional pentest follows a fixed, structured approach. We work according to recognised methodologies such as those of OWASP and the Penetration Testing Execution Standard. An investigation usually consists of the following steps.

  1. Intake conversation. Together we discuss your wishes, the scope of the investigation, the desired test form and the planning. On that basis we draw up a quote.
  2. Reconnaissance. The pentester gathers information about the target, partly through public sources (OSINT) and partly through scanning.
  3. Vulnerability assessment. They map the possible weak spots and determine which are worth investigating further.
  4. Exploitation. The pentester actually tries to abuse the vulnerabilities found, just like a real attacker.
  5. Post-exploitation. They investigate how far access reaches and what impact a successful attack would have, for example whether lateral movement to other systems is possible.
  6. Reporting. You receive a report in plain English with a management summary and the technical findings, including advice for improvement.
  7. Retest. Optionally we later check whether the implemented fixes actually resolve the vulnerabilities.

A pentest remains a snapshot in time. The investigation shows how resilient your systems were at the moment of testing. If something changes in your infrastructure or applications, the picture can shift. That is why we advise repeating a pentest periodically.

What gets tested?

A pentest can be carried out on almost any system or network where security plays a role. Which components we investigate exactly, we determine together in the intake conversation. These are the most common types.

  • Corporate network pentest: your complete IT network, both external (from the public internet, targeting VPNs, firewalls, web servers and email) and internal (from the position of a malicious insider or a workstation compromised via phishing).
  • Web application pentest: your websites and web applications, tested for vulnerabilities from the OWASP Top 10 such as SQL injection, Cross-Site Scripting and weak authentication.
  • Active Directory pentest: whether an attacker can escalate from an ordinary user account to Domain Admin via Kerberos attacks, NTLM-relay and privilege escalation.
  • Cloud pentests for Azure, AWS and GCP: the configuration and access management of your cloud environment.
  • Mobile application pentest: iOS and Android apps, tested according to the OWASP Mobile Security Testing Guide.
  • WiFi pentest: your wireless network, the encryption and the separation between guest and corporate network. This happens on location, because the pentester needs to be within range of the signal.
  • API pentest and code review for those who specifically want the interfaces or the source code investigated.

Which components are useful for you depends on your situation. Your security is only as strong as the weakest link, so there is little point in exhaustively testing one well-secured system while another component stays out of view. The pentester is happy to advise you on a suitable scope.

What does a penetration test cost?

The cost of a pentest strongly depends on the scope and complexity of what you have tested. A small web application takes less time than an extensive enterprise environment. As a guideline:

  • A web application pentest starts around €2,000 for a small website and rises to €8,000 or more for a complex application.
  • A corporate network pentest starts around €4,000 for an internal test; a combination of external and internal is higher.
  • A cloud pentest starts around €3,600 for a Microsoft 365 environment and rises as the environment grows.
  • An Active Directory pentest starts around €4,000 for a single domain.

If you have a limited budget, a timeboxed pentest is an option. The pentester then tests as much as possible within an agreed number of days, with the emphasis on the most critical systems and the most obvious vulnerabilities. It is a good way to quickly get a first impression, but there is no guarantee that the entire environment is covered. For compliance purposes, such as PCI DSS or ISO 27001, a full pentest with a defined scope is required.

We only name a precise amount after the intake conversation, when the scope is clear. That way you pay for what you actually need.

Why have a penetration test carried out?

The costs of a successful cyberattack are considerable. Besides direct recovery and possible downtime, you may face reputational damage, loss of customers and fines when personal data ends up on the street. Set against those amounts, a pentest is a manageable expense. You would rather know in advance where your weak spots are than have an attacker point them out.

A pentest also gives you certainty about investments you have already made. Do that new firewall, the EDR solution or the awareness training really work as you hope? A realistic test shows it. In addition, various standards and laws require periodic pentests, including ISO 27001, PCI DSS, NIS2 and NEN 7510 for healthcare.

The general recommendation is to pentest at least annually, and more often after major changes, after a security incident or for systems that are extra critical.

Ready for a pentest?

We are happy to think along about the right scope, the type of pentest and the approach that fits your organisation. Request a no-obligation conversation.

Get in touch

Or email us directly at [email protected]