Penetration Testing – Frequently Asked Questions (FAQs)

Based in Exeter, Devon, the Securious team hear many questions relating to penetration testing (aka pen testing and ethical hacking). Here are 18 of the most common, but if we haven’t answered your question in this article, just send it to us via email at info@securious.co.uk.

1. What is pen testing?

Pen testing, also known as penetration testing or ethical hacking, is an authorised attempt to safely get into your IT systems in order to see if they are vulnerable to attack. The experts carrying out these tests will look for flaws in your systems that cyber criminals could exploit. We have a whole explainer blog on this if you want to read more.

2. When do I need a pen test?

If you’re unsure about how secure your systems are, a pentest is a great way to gain insights into any vulnerabilities before it’s too late. It may also be required for you to carry out a pen test to achieve or maintain compliance with security standards like PCI DSS.

3. How often do I need to have pen tests?

It’s generally agreed that you should have a pen test at least once every 12 months, or after any major technical changes to your environment. Compliance requirements can also dictate the regularity of pen testing.

4. Will a pen test cause any damage?

Pen testing should be carried out under strict rules of engagement, agreed by both parties. If carried out incorrectly, pen tests can cause a number of issues – similar to if your systems were actually hacked, and may well be illegal. Because of this, it’s imperative that you use qualified and experienced professionals, as they should ensure there are approved agreements in place to allow pen test activities, as well as ensuring that no damage is caused to your systems during the pen testing activities. It’s also important that your team knows that a penetration test is going to take place. This allows them to prepare by, for example, whitelisting the IP addresses and other sources of the staged attack environment. See our blog on preparation for a pen test here: Penetration testing – what we need to know from you and why.

5. What’s the difference between a pen test and a vulnerability scan?

Penetration testing goes further than vulnerability scans, as it doesn’t just look and report vulnerabilities, but also investigates weaknesses to see the level of access a hacker could obtain. Additionally, a penetration test is performed manually by a security expert who will utilise their experience and a variety of manual tools. Vulnerability scans are usually automated.

6. What’s the difference between internal and external pen testing?

Internal pen testing looks for vulnerabilities that could be exploited by an employee with access to the organisation’s internal network. It will give the tester the same access as that which someone inside the organisation would have. It may also include verifying any segmented networks within the internal network are configured correctly. Internal pen tests will help you understand how much damage, for example, a malicious employee could cause, as well as meet compliance obligations. External testing looks for vulnerabilities that attackers could exploit on public-facing networks like email, your website, file-sharing systems, messaging platforms and any hosted FTP servers. External pen tests can help you understand the damage an external hacker could cause.

7. How much do pen tests cost?

It’s hard to give a typical cost, since pen tests need to be tailored to your individual needs and circumstances. However, a pentesting project with reporting will normally cost from around £3,000 (+VAT).

8. What do I need to know before a pentest?

Before your pentest, you should ask yourself some important questions. What is your motivation? What are your compliance requirements? Do you want to know for your own peace of mind or do you want to elevate your security posture? Do you need to increase overall security awareness in the business?

9. What should I do to prepare for a pentest?

Your network diagram needs to be up-to-date and you should have a data-flow map for your environment. You should also have a list of active ports on your perimeter security device, which should be as current as possible, as well as what services should be open through your firewall or available through your web application. This isn’t necessarily information that your pentester will need, but it helps to be prepared should they run into an issue or if they require more information. 

10. Are pentesters hackers?

Technically speaking, yes. But not all hackers are the same, and hacking doesn’t always imply bad intentions. Pentesters hack ethically, and are also known as ‘white hat’ hackers. Once authorised, they are allowed to attempt to exploit a company’s system vulnerabilities to highlight where the business can improve its cyber security. A ‘grey hat’ hacker may hack into a business’s network without being asked. They may ask for money in return for highlighting where the business’s cyber security can be improved, or they may threaten to expose sensitive data if they aren’t paid. A ‘black hat’ hacker is a malicious actor who breaks into computer networks with malicious intent. They harm a business rather than help.

11. Do I have to outsource the pen test or can it be an in-house test?

Technically, you can perform an in-house pentest with an internal team. However, they need to have certain skills and experience in order to prevent any damage from being caused and for the test to be effective. Your team will need proficiency in testing, experience in how to explore a network, as well as familiarity with pentesting methodologies and standards, such as OWASP. It would also be beneficial to have some impartiality of the system they are testing. 

12. What is OWASP?

OWASP stands for the Open Web Application Security Project. It is an international non-profit organisation dedicated to web application security. One of OWASP’s core principles is that all of its materials be freely available and easily accessible so that anyone can improve their own web application security. Likely their best-known project is the OWASP Top 10.

13. How can I help with scoping for a penetration test?

Knowing your network will help with scoping. Ask yourself where you want to focus the testing and what the scope should include. Your scope should cover critical systems that may impact security if any data is being stored. For PCI DSS, there are specific areas that you need to pen test. These may include where credit card data is stored, processed or transmitted, along with any systems that could affect the security of those areas. Understanding the internal exposure in your network is equally as important as the outward-facing parts. Communicate all of this to the pentest company so they can scope out the work and give you a good estimate of the time and what’s required to perform an effective and efficient test.

14. What does a tester need to know before starting?

Typically, penetration testers will want to know at least the following:

The list of targets, in detail

What the targets are (Network Infrastructure, Web Application, API, etc.)

In the case of a web application or API, a rough approximation to the number of endpoints/pages

The sensitivity of the data on the systems in scope

Where the systems are situated

If there are any third parties (web hosts, managed service providers)

Who these third parties are, with written permission allowing testing

The level of access you would like the testers to have

15. What are the steps of a pentest?

There are different frameworks that pentesters can follow, we follow the PTES (Penetration Testing Execution Standard) here at Securious:

Planning and reconnaissance: the first step involves planning to simulate the attack. This can be one of the most time-consuming stages. It’s worth noting that the type of information and the depth of the investigation will depend on the objectives set for the test.

Scanning and Intelligence Gathering: based on the findings from the first stage, pentesters use scanning tools to explore the system and find network weaknesses. This stage identifies the system weaknesses that could potentially be targeted by cyber criminals.

Gaining system access (exploitation): after gaining an understanding of the system’s vulnerabilities, pen testers can then infiltrate the infrastructure by exploiting them.

Persistent access: this stage identifies the potential impact of exploiting vulnerabilities. Once the tester has a foothold in the system, they can maintain access and begin to simulate an attack in the same way a malicious hacker might. In this stage they will try to access as many systems as possible and see just how much damage a hacker might be able to cause due to this weakness. This demonstrates the potential consequences that a customer would experience were this a real attack.

Post Exploitation and clean-up: The clean-up process covers the requirements for cleaning up systems once the penetration test has been completed. This will include all user accounts and binaries used during the test.

Analysis and reporting: the security team will then provide a detailed report that describes the entire process. This phase is often the most important. It gives your business an understanding of how secure its system really was, and gives an idea of what actions it could take to improve and harden its systems from attacks. It will also show which areas are suitably secure and protected already.

16. What happens after the penetration test?

Once the test is over you’ll receive a report detailing your vulnerabilities, and we will arrange a debrief call where your pentester will walk you through it. Once the debrief is over, you will have the knowledge to remediate any issues and arrange another pentest to ensure that any highlighted issues are closed down. It is important to learn from the pentest findings and continue to maintain a high level of security within your environment.

17. Can I share the pentest report with outside parties?

It is not a good idea to send the results from your penetration test outside of your company, unless contractually agreed with Trusted Third Parties. A pentest report contains extremely sensitive information about your company’s security, and it should only be shared on a need-to-know basis with trusted parties.

18. How much time is necessary to perform a typical penetration test?

The amount of time it takes overall to test your organisation will depend on the size and complexity of the network, referred to as the pentesting scope. The larger or more complex the scope is, the more effort and therefore time will be required. Generally speaking, four to six weeks is a good estimate for the duration of the entire process – from planning through to final delivery. The actual testing part usually takes less than two weeks.

Need help with penetration testing?

Here at Securious, our penetration testers follow a proven methodology with a series of simulated tests to identify any weaknesses in your defences – whether internally or externally.

Often it is the combination of a series of weaknesses in your systems that allows attacks, rather than a single vulnerability. That’s why our tests combine a series of lower-risk exploits in a particular sequence, to determine whether they would have any effect.

We test in accordance with Nation Cyber Security Centre’s guidelines and, where relevant, against the OWASP top 10. We detail the penetration test findings in a report that highlights the potential risks and recommends where additional resources should be applied to protect your systems.

To learn how we can help with your specific situation, please call now on +44 (0) 1392 247 110, email info@securious.co.uk or fill in the contact form below

To see more of our pentesting resources, click here