ESSENTIAL GUIDANCE · COMPLETE GUIDE · 16 min read

Part of Validate insights

Penetration testing: scope, process, costs and what happens after the report

A buyer's guide to penetration-test scope, methodology, provider selection, reporting, remediation, retesting and continuous assurance.

A buyer's guide to penetration-test scope, methodology, provider selection, reporting, remediation, retesting and continuous assurance.

Need an acronym translated?Open the cyber glossary →

What a penetration test should prove

A penetration test is an authorised, controlled assessment in which skilled testers investigate whether weaknesses can be exploited and what that could allow an attacker to achieve. It is more than a scan and should be more than a compliance artefact. A useful engagement supports a decision: whether an application is ready to launch, whether an exposed environment can be compromised, whether segmentation works or whether important customer data is adequately protected.

Start with the decision, then define the scope

A list of IP addresses or URLs is necessary but not sufficient. Good scoping identifies the business purpose of the system, important data and workflows, user roles, technology, environments, interfaces and the assurance driver. It also records exclusions, test accounts, operating windows, communication routes and stop conditions. Scope should be large enough to answer the question but controlled enough for testers to investigate meaningfully within the available time.

Scanning and testing answer different questions

Automated scanning provides fast, repeatable breadth across known patterns. It can identify candidate weaknesses but may create false positives, miss bespoke business logic or fail to understand how several modest conditions combine. Testers validate results, challenge authentication and authorisation, investigate unusual behaviour and safely chain weaknesses. Mature programmes use both: automation for coverage and expert investigation where the risk, uncertainty or business consequence demands deeper proof.

Common types of penetration test

Testing can cover web applications, APIs, mobile applications, external and internal infrastructure, Active Directory, cloud environments, wireless networks, client software and connected devices. Black-box testing begins with limited knowledge; grey-box testing uses agreed accounts or architecture information; white-box testing provides deeper internal detail. The right approach depends on the question. Artificially withholding information can consume time without producing a more useful assurance outcome.

How a defensible engagement runs

The lifecycle normally includes planning, reconnaissance, structured coverage, manual investigation, controlled exploitation, evidence capture, quality assurance and reporting. Material findings should be communicated during testing rather than held until the final document. Testers need clear escalation and deconfliction routes, particularly in production. Every conclusion should be supported by reproducible evidence, stated limitations and a proportionate explanation of impact.

What a useful report contains

Technical teams need affected components, evidence, reproduction steps, severity rationale and specific remediation guidance. Leadership needs an accurate explanation of business exposure, systemic themes and priority. A useful report distinguishes confirmed vulnerabilities from observations and makes testing limitations explicit. Live findings can shorten the time to remediation, but the final report and closure evidence remain important for customers, auditors and governance teams.

Costs and provider selection

Price depends on scope size, roles, endpoints, technology, complexity, environment and tester time. Compare providers on relevant accreditation, consultant experience, methodology, quality assurance, reporting, communication, remediation support and retesting—not only day rate. Ask what is included, when critical findings will be raised and who will perform the work. A fixed price is valuable when it rests on a precise scope; a low quote built on assumptions often creates change requests or shallow coverage.

Remediation and retesting complete the test

The report identifies work; it does not prove that risk has reduced. Assign owners and deadlines while the engagement context is fresh. Fix root causes where possible, rather than only the demonstrated symptom. Retesting should verify material changes and check that an alternative path has not remained. Closure evidence creates a defensible record for customers and auditors and provides a clearer baseline for later testing.

Move from annual testing to change-led assurance

Annual testing remains a useful baseline, particularly for customer or compliance commitments, but applications and cloud estates can change weekly. Define events that trigger additional validation: major releases, new internet-facing services, identity changes, acquisitions and important remediation. Pentesys Validate combines vulnerability assessment, AI-assisted coverage and CREST-aligned human testing, with confirmed findings, owners and retesting maintained in the Pentesys Portal.

Ready for the Pentesys point of view?

This guide covers the essentials. Continue into our technical analysis for a firmer position, practical implications and recommended action.

Read “Modern penetration testing should create decisions, not just findings” →
TALK TO PENTESYS

Apply this guidance to your environment.

Tell us what you need to understand, test or prove. We'll help you choose a proportionate next step—without forcing the conversation into a predefined package.

Apply this to my environment Explore Validate

Keep reading

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.