Planning your first penetration test? A practical guide to setting the scope, preparing, and evaluating the report.

GuideAbout 7 min readPenetration testing

What question does a penetration test answer?

A vulnerability scan lists known weaknesses. A penetration test is an authorised expert thinking like an attacker, chaining weaknesses and proving what can really be reached. The question is not “which flaws do I have?” but “what could an attacker reach?”

Types of test

Black box

The tester starts from the outside with no prior knowledge, like a real attacker.

Grey box

Limited knowledge and a user account are provided; authorisation flaws are found more efficiently.

White box

With architecture and source code access, the deepest review is possible.

By target

External network, internal network, web application, API, mobile and wireless tests are separate scopes.

Defining scope and rules

The following should be agreed in writing before the test:

  • Target list: IP ranges, domains, applications
  • Test window and tolerance for disruption
  • Written authorisation and contact persons
  • Limits on prohibited actions (e.g. denial of service, social engineering), if any
  • Procedure if sensitive data is accessed

Pre-test preparation checklist

  • Scope and rules approved in writing
  • Decision made on production vs. test environment
  • Backups of critical systems taken
  • Monitoring/SOC team informed (or a blind test agreed)
  • Test accounts and roles prepared for grey box
  • Tester source IPs allow-listed
  • Emergency stop contact channel defined

How does the test run?

Scope and rulesTargets, time, authority
ReconnaissanceMapping the attack surface
Vulnerability detectionFinding and validating flaws
Controlled exploitationShowing real impact
ReportingFindings, risk, advice
RetestVerifying the fixes

How to read the report

  • Executive summary: overall risk position and the few most important findings
  • For each finding: title, risk rating, impact, evidence and fix recommendation
  • Critical and high findings first; lower ones go to a planned fix list
  • Root-cause recommendations so the same flaw does not recur

Remember: The report is the start, not the end: assign an owner and target date to each finding, then have it retested.

Let’s define your penetration test scope together

We will listen to your goals and recommend the right test type and scope.