Penetration testing – frequently asked questions

More and more companies are contacting us because they require pentesting, either as a one-time event or on a monthly basis. 

Third parties often drive this need, for example, because they are part of a supply chain or must meet a given compliance standard in order to tender for projects, and pen testing (or a pen testing report) is a required deliverable. 

When clients come to us, they frequently have a lot of questions about pen testing, especially if they haven’t done it previously. In this blog, we’ve answered the top seven most common questions our team gets asked. 

1) What is pen testing?

Pen testing, also known as penetration testing or ethical hacking, is an attempt to safely get into your IT systems in order to see if they are vulnerable to attack. 

It usually involves a set of tests carried out by experts known as penetration testers or pentesters. They’ll look for flaws in your systems that cyber criminals could take advantage of. 

It’s the equivalent of having a security consultant walk through your home, inspecting windows and doors, and seeing where they can get access to, before reporting back to you with what they found so you can rectify it before a criminal takes advantage. 

We have a whole explainer blog on this if you want to read more.

2) When do I need a pen test?

 If you are concerned about the security of your systems, a pentest is one of the best ways of understanding what issues you have before it is too late. 

If a pen test identifies any vulnerabilities in your system, you will be able to address them and harden your defences before cyber criminals exploit them.

Increasingly, you will also need to provide a pen test report to achieve or maintain compliance and recognised security standards such as PCI DSS  

3) How often do I need to have pen tests?

This is often dictated by compliance requirements, but a generally-agreed rule of thumb is at least once every 12 months, or after any major change. 

However, many modern businesses focused on rapid growth will opt to test monthly or even up to once a week. 

A fundamental weakness with pen testing is that they are only concerned with the point in time when the test is conducted. It is therefore possible that a test might have given all- clear last week, but a new vulnerability has since been introduced into your system. 

This is why we at Securious are advocates for continuous monitoring of devices and environments to ensure you have 24/7 visibility of vulnerabilities. You can read more about this on our Managed Detection and Response (MDR) page. 

4) Will a pen test cause any damage?

You need to make sure you use qualified and experienced professionals because handled incorrectly, pen tests can cause a number of issues, just like if your systems were hacked.   

An incompetent or reckless pen tester can cause things to break or expose sensitive data, but professional pen testers should ensure there is no damage caused at all. 

It is also important that your team knows that a penetration test is going to take place and from where so they can, for example, whitelist the IP address. 

5) What’s the difference between a pen test and a vulnerability scan or assessment?  

Vulnerability scans look for known vulnerabilities in your systems and report potential issues. Penetration tests go further and investigate weaknesses in your network to see the level of access a hacker could obtain. 

A common analogy is that a vulnerability scan is similar to approaching a door, checking to see if it is unlocked, and then stopping. A penetration test goes a step further, not only checking to see if the door is unlocked, but also opening the door and walking right in. 

In addition, a vulnerability scan is usually automated, but a penetration test is a manual test performed by a security expert. 

6) What’s the difference between internal and external pen testing?  

Internal testing checks internal networks and looks for vulnerabilities that could be exploited internally by an employee with access to the organisation’s internal network.   

An internal pen test will therefore give the tester the same access that someone from inside the organisation would have. It can help you understand how much damage, for example, a malicious employee could cause. 

By contrast, external penetration testing looks for vulnerabilities that attackers could exploit on public networks like email, your website, file-sharing systems, messaging platforms and FTP servers. 

External pen testing therefore helps you understand the damage an external hacker could cause. 

7) How much do pen tests cost?

Pen tests need to be tailored to your individual needs and circumstances, so it’s really hard to give a benchmark cost. However, a pentesting project with reporting will normally cost from about £3,000 (+vat) including report. 

If you’d like to learn more, or we haven’t answered your question, please email info@securious.co.uk