Every business has security weaknesses. The question is whether you find them first — or an attacker does.
Penetration testing (also called pen testing or ethical hacking) is how you find out. A security professional — one you authorise and hire — attempts to break into your systems using the same techniques a real attacker would use. The difference: they hand you a detailed report instead of stealing your data.
This guide explains exactly what penetration testing is, how it works, the types available, and whether your business actually needs it.
What does a pen tester actually do?
A penetration tester uses the same tools, tactics, and techniques as a malicious hacker — but with your knowledge and permission. During a test, they might:
- Try to access systems using stolen, guessed, or phished credentials
- Exploit known vulnerabilities in your software or web applications
- Attempt to intercept unencrypted network traffic
- Send phishing emails to your employees to test awareness
- Look for misconfigurations in cloud environments, firewalls, or servers
- Try to escalate privileges after gaining initial access
The goal isn’t just to find a weakness — it’s to exploit it the same way a real attacker would. That’s what makes a pen test different from a basic vulnerability assessment, which only identifies potential issues without testing whether they can actually be used.
Why do businesses need penetration testing?
Three reasons drive most businesses to book a pen test:
1. Compliance requirements
Many regulatory frameworks — including PCI DSS, ISO 27001, SOC 2, and HIPAA — either require or strongly recommend regular penetration testing. If you process card payments or handle sensitive data, you may not have a choice.
2. Proactive risk reduction
The average cost of a data breach in 2024 was $4.88 million (IBM Cost of a Data Breach Report). A pen test typically costs a fraction of that — and finding a critical vulnerability before attackers do can prevent a breach entirely.
3. Proving security to customers and partners
Enterprise buyers increasingly require vendors to demonstrate security assurance before signing contracts. A recent pen test report — especially from an independent third party — is one of the fastest ways to satisfy that requirement.
How penetration testing works: the 5 phases
Every professional pen test follows a structured methodology. Here’s what happens at each stage:
Phase 1 — Planning
Before anything begins, you and the pen testing provider agree on scope: which systems are in scope, what testing methods are permitted, testing windows (to avoid disrupting production), and rules of engagement. Everything is documented and signed off.
Phase 2 — Reconnaissance
The tester gathers information about your environment — domain names, IP addresses, employee names, technologies used, publicly exposed services. This mirrors exactly what an attacker would do before launching an attack.
Phase 3 — Scanning
Using specialised tools, the tester maps your network: open ports, running services, software versions, and known vulnerabilities. This builds a picture of potential entry points.
Phase 4 — Exploitation
This is the active testing phase. The tester attempts to exploit the vulnerabilities identified — trying to gain access, escalate privileges, move laterally across the network, and reach sensitive data. All activity is logged.
Phase 5 — Reporting
You receive a detailed report covering every vulnerability found, evidence of exploitation, risk ratings, and specific remediation recommendations. Most providers also offer a debrief call to walk through findings.
Types of penetration testing
Not all pen tests are the same. The right type depends on what you’re trying to protect:
| Type | What it tests | Typical duration |
|---|---|---|
| Network pen test | Firewalls, routers, internal network | 3–5 days |
| Web application test | Websites, portals, APIs | 3–7 days |
| Social engineering | Employee susceptibility to phishing | 1–2 weeks |
| Cloud security test | AWS / Azure / GCP configuration | 3–5 days |
| Red team exercise | Full attack simulation across all vectors | 2–4 weeks |
What happens after a pen test?
A good pen testing provider doesn’t just hand you a list of vulnerabilities and disappear. After the test, you should receive:
- An executive summary — a non-technical overview of risk for leadership and board-level stakeholders
- A technical findings report — full details of every vulnerability, how it was exploited, and evidence
- Risk ratings — critical, high, medium, low, and informational findings prioritised by impact
- Remediation guidance — specific steps to fix each issue, not just a list of problems
- A debrief call — a walkthrough of findings with your technical team
Once your team has remediated the critical and high findings, many providers offer a re-test to verify the fixes worked.
How often should your business do a pen test?
- Annually as a minimum — for most businesses, one comprehensive test per year is the baseline
- After major changes — a new product launch, cloud migration, or acquisition warrants a targeted test
- Before compliance audits — PCI DSS requires annual pen testing; booking one ahead of your audit gives you time to remediate findings
- Quarterly for high-risk environments — financial services and healthcare organisations often test more frequently
Penetration testing vs vulnerability scanning: what’s the difference?
A vulnerability scan is automated software that checks your systems against a database of known vulnerabilities. It’s fast, relatively cheap, and useful — but it only identifies potential weaknesses without attempting to exploit them.
A penetration test is manual, expert-led, and goes further. A tester doesn’t just flag that a vulnerability exists — they prove it can be exploited, show what data or access could be reached, and demonstrate the business impact.
Think of a vulnerability scan as a checklist and a penetration test as a live fire exercise. See our vulnerability assessment service for more on how the two work together.
If you operate in a regulated industry, penetration testing requirements may be even more specific. See our guides for financial services cybersecurity and healthcare cybersecurity for industry-specific context.
Frequently asked questions
Will a pen test take down our systems?
A professional pen test should not cause downtime. Before testing begins, scope and rules of engagement are agreed — including which systems are off-limits and acceptable testing windows. Most tests are conducted outside business hours to further reduce risk. That said, you should always have a backup and know your incident response contacts before any test.
How much does penetration testing cost?
A typical network or web application pen test runs between $5,000 and $30,000 depending on scope, environment size, and depth of testing. Red team exercises are more involved and can run higher. See our pen testing cost guide for a full breakdown.
Do small businesses need penetration testing?
Yes — and attackers agree. Small businesses are increasingly targeted precisely because they tend to have fewer security controls. If you handle customer data, process payments, or provide services to larger organisations, a pen test is worth considering. Many SMB-focused tests are scoped to keep costs manageable.
What’s the difference between a pen test and a red team exercise?
A penetration test targets specific systems or applications within a defined scope. A red team exercise is a broader, scenario-based simulation of a full attack — covering network, physical access, and social engineering in combination — with no pre-defined scope. Red team engagements are longer, more expensive, and better suited to organisations with a mature security posture already in place.
How do we prepare for a pen test?
You don’t need to clean up your environment first — that defeats the purpose. What you should do: make sure your team knows the test is happening, have a contact list ready in case something unexpected is discovered, and ensure your test provider has signed an NDA and rules of engagement before work begins.
Ready to find your vulnerabilities before attackers do?
garrisonOne’s penetration testing team uses real-world attack techniques to expose weaknesses in your network, applications, and cloud environment — then helps you fix them.
Explore our pen testing services →