A penetration test, or pen test, is an authorised, simulated cyberattack on your systems carried out by a skilled tester to find and prove weaknesses before a real attacker does. It is the difference between assuming you are secure and knowing what an attacker could actually reach.
If you are buying one for the first time, this guide explains what a pen test is, how it works, the types available, and what you should expect to receive.
What a penetration test is, in plain terms
A vulnerability scanner tells you what might be wrong. A penetration test tells you what an attacker could actually do about it. Ethical hackers, who are skilled security professionals, use automated tools alongside manual techniques as a testing tool to exploit security vulnerabilities, chain them together, and reach something that matters, such as customer data or administrative control. They may use brute-force attacks, credential stuffing, or chained exploits to reach an external test target or an internal test system. Then they document the real risk with evidence and tell you how to fix it.
It is authorised and scoped, which is what separates it from an actual attack: you agree the targets, the rules of engagement, and the timing in writing before anyone touches a system.
How a penetration test works
A typical engagement follows five phases.
- Scope and rules of engagement. You agree what is in and out of scope, the testing windows, and how a critical finding is escalated, all in writing.
- Reconnaissance. The tester maps your attack surface and identifies the most promising entry points.
- Exploitation. The core of the work: manual attempts to exploit weaknesses, escalate privileges, and chain issues into a full attack path. This is where ethical hackers attempt to gain access to systems and sensitive information the way a malicious attacker would.
- Reporting. Findings are written up with CVSS-aligned ratings, reproduction evidence, business impact, and prioritized remediation.
- Remediation and retest. You fix the findings and the tester retests to confirm they are closed, producing an updated report.
Not sure where your security stands?
Run the free 15-question self-assessment and get an instant readiness score before you scope a test.
The main types of penetration test
You scope a test to your environment by choosing the relevant types: external network, internal penetration test, internal pen test of your internal networks and systems, web application testing, mobile application, API, cloud configuration, wireless networks, and social engineering or phishing. Most buyers start with the assets most exposed to attack or most relevant to a compliance requirement. A firewall or perimeter component should be tested as part of network penetration testing scope.
The type of penetration testing you need varies by environment. A network penetration test covers your perimeter and internal infrastructure; web application testing covers your customer-facing applications. A pen tester or penetration tester working on any type of pen test will agree the target system in writing before starting, which defines what is in and out of scope.
There is also the question of approach: black box (no prior knowledge), grey box (partial access), or white box (full access to code and architecture). White and grey box usually go deeper for the same budget because the pen test tester spends time finding issues rather than discovering your environment.
What you should receive
A real penetration test delivers a report with two layers: an executive summary a non-technical stakeholder can read, and technical detail an engineer can act on the same day. Each finding should carry a CVSS-aligned risk rating, reproduction evidence, and the attack-path context that shows what an attacker could reach, including unauthorized access to sensitive information or data an attacker should not be able to reach. A good engagement also includes a retest within an agreed window. If the deliverable looks like exported scanner output, you bought a scan, not a test.
When you need one
Common triggers are a compliance requirement (PCI DSS requires penetration testing at least annually and after any significant change to the cardholder data environment; SOC 2, ISO 27001, and HIPAA do not mandate a specific frequency but customers and auditors commonly expect evidence of testing), a product launch, a significant architecture change, an enterprise customer's security review, or simply the need to discover vulnerabilities before a real breach. Many organisations run at least one pen test a year and additional tests after major changes. A vulnerability assessment can complement the programme but does not replace the manual exploitation a pen test provides. Networks and systems that handle sensitive data should be tested on a regular cycle, and physical security is sometimes included where the engagement covers a full facilities assessment.
Cybersecurity maturity depends on proactive testing. A penetration test gives you proof of where real-world attacks could compromise your systems, something a firewall rule or a cybersecurity policy alone cannot provide. The testing methodology matters too: credible providers follow OWASP, PTES, or NIST SP 800-115, which means the security controls being tested are comprehensive and the findings are defensible. Penetration testing helps strengthen security measures by revealing gaps that auditors, enterprise customers, and security teams all expect to be addressed.
The bottom line
A penetration test is a controlled, expert security testing and assessment that proves what a real attacker could do using the same tools and techniques they would use, and tells you how to stop them. It is scoped to your environment, follows a recognised methodology, and ends with a report you can act on and a retest that confirms your fixes worked. If you are facing an audit, a launch, or a customer security review, it is how you turn "we think we are secure" into evidence.
How Onyx helps
Onyx delivers manual-led penetration testing run by named testers holding eCPPT, CRTP, and CEH, with CREST-accredited testing available through our CREST-member partner. We follow OWASP, PTES, and NIST SP 800-115, agree the scope and rules of engagement in writing, and deliver a report with an executive summary, CVSS-aligned findings, reproduction evidence, and prioritized remediation. A retest is included within an agreed window.
We do not publish fixed prices because a number not scoped to your environment is meaningless. Every engagement starts with a short scoping call.
Ready to scope your first penetration test?
Tell us your environment and what is driving it and we will build a clear plan on a 30-minute call. No obligation.
See also: how to choose a penetration testing company, penetration testing vs vulnerability scanning, and our penetration testing service. Or start with the free security self-assessment.
FAQ
What is a penetration test?
A penetration test is an authorised, simulated cyberattack on your systems, carried out by skilled ethical hackers who exploit weaknesses by hand to prove what a real attacker could reach, then documents the risk with evidence and fixes. It is scoped and agreed in writing, which separates it from a real attack.
How is a penetration test different from a vulnerability scan?
A vulnerability scan is automated and lists potential weaknesses. A penetration test is performed by ethical hackers who exploit those weaknesses, prove which are real, chain them where possible, and show the business impact including unauthorized access paths. A scan is a useful input; it is not a substitute for a pen test.
How long does a penetration test take?
Most engagements run from a few days to a couple of weeks of active testing, plus reporting, depending on scope and the number of targets. The provider should give you a clear timeline in the scoping document.
What does a penetration test report include?
An executive summary for non-technical stakeholders, technical detail for engineers, a CVSS-aligned rating and reproduction evidence for each finding, the attack-path context, and prioritized remediation. A good engagement also includes a retest and an updated report confirming what was fixed.
How often should I get a penetration test?
PCI DSS requires penetration testing at least annually and after any significant change to the cardholder data environment. SOC 2, ISO 27001, and HIPAA do not mandate a specific frequency; test before major launches, after significant architecture changes, or when a customer's security review requires it. Pair periodic pen testing with continuous vulnerability scanning for ongoing cybersecurity coverage.
