Planning your first penetration test? A practical guide to setting the scope, preparing, and evaluating the report.
What question does a penetration test answer?
A vulnerability scan lists known weaknesses. A penetration test is an authorised expert thinking like an attacker, chaining weaknesses and proving what can really be reached. The question is not “which flaws do I have?” but “what could an attacker reach?”
Types of test
The tester starts from the outside with no prior knowledge, like a real attacker.
Limited knowledge and a user account are provided; authorisation flaws are found more efficiently.
With architecture and source code access, the deepest review is possible.
External network, internal network, web application, API, mobile and wireless tests are separate scopes.
Defining scope and rules
The following should be agreed in writing before the test:
- Target list: IP ranges, domains, applications
- Test window and tolerance for disruption
- Written authorisation and contact persons
- Limits on prohibited actions (e.g. denial of service, social engineering), if any
- Procedure if sensitive data is accessed
Pre-test preparation checklist
- Scope and rules approved in writing
- Decision made on production vs. test environment
- Backups of critical systems taken
- Monitoring/SOC team informed (or a blind test agreed)
- Test accounts and roles prepared for grey box
- Tester source IPs allow-listed
- Emergency stop contact channel defined
How does the test run?
How to read the report
- Executive summary: overall risk position and the few most important findings
- For each finding: title, risk rating, impact, evidence and fix recommendation
- Critical and high findings first; lower ones go to a planned fix list
- Root-cause recommendations so the same flaw does not recur
Remember: The report is the start, not the end: assign an owner and target date to each finding, then have it retested.
Let’s define your penetration test scope together
We will listen to your goals and recommend the right test type and scope.