Skip to content

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Editorial team 2 min read

A penetration test is an authorised, time-boxed attempt to reach a stated objective by the means a real attacker might use. That definition carries three constraints people routinely forget.

Time-boxed

A tester has days; an attacker has as long as they like. A clean report means "nobody found a way in within the time and scope agreed", not "there is no way in". Treat the absence of findings as weak evidence, and ask what the tester did not get to.

Objective-driven

"Test everything" produces shallow coverage. A good objective is concrete: reach customer records from an unauthenticated position, move from a developer laptop to production, or obtain domain administrator. The objective decides the technique, and makes the result meaningful to people who do not read security reports.

Authorised

Scope, timing, data handling and contacts are agreed in writing before anything starts. Without that, the activity is indistinguishable from an intrusion — legally as well as operationally.

What it is not

It is not a vulnerability scan. A scan enumerates known weaknesses across many hosts; a test chains a few of them into an outcome. Both are useful and they answer different questions.

It is not an assessment of your controls either. A test tells you whether a path exists today. A control assessment tells you whether the practices that would close such paths are working, which is why mature programmes run both.

It is not a substitute for fixing what you already know about. If your last three reports share findings, another test is not what you need.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025

Cyber security Guide · 2 min

The OWASP Web Security Testing Guide

A shared checklist for testing web applications, and how to use it without turning testing into box-ticking.

Cyber security 2 min read 21 May 2025